Identity verification, account maintenance, fraud prevention, notices, and complaint resolution.
Order processing, payment settlement, and provision of custom print services.
Domestic and international shipping, delivery status notifications.
Creation and retention of design proof approval records, chargeback dispute resolution, and fraud prevention.
Identity verification of the inquirer, investigation, and notification of results.
Development of new services, promotional information, and service usage statistics. Marketing communications are sent only with the user's separate consent.
Required: email, password, name, phone number, company name
Order number, payment records, card information (processed directly by payment service providers)
Recipient name, shipping address, contact number
Proof approval records (consent text, timestamp), IP address, device identifiers, service usage logs
IP address, cookies, access timestamps, browser information, service usage logs
| Data Retained | Retention Period | Legal Basis |
|---|---|---|
| Payment and order snapshot (order number, proof approval log, shipping address, tracking number) | 540 days from the date of delivery completion | International card network (Visa/Mastercard) chargeback dispute period |
| Contracts and subscription withdrawal records | 5 years | Korea Electronic Commerce Act |
| Payment and supply records | 5 years | Korea Electronic Commerce Act |
| Consumer complaint and dispute records | 3 years | Korea Electronic Commerce Act |
| Access logs | 1 year | Korea Protection of Communications Secrets Act |
| Service | Partner | Scope |
|---|---|---|
| Domestic payments | Toss Payments Co., Ltd. | Payment processing |
| International payments | Airwallex | International card and digital payment processing |
| Printing and production | Partner print facilities (varies by order) | Product manufacturing and domestic shipping |
| Domestic delivery | CJ Logistics, Hanjin, Lotte Global Logistics | Parcel delivery |
| International delivery | DHL | International shipping |
Under Articles 35 through 37 of the Personal Information Protection Act (PIPA), you have the right to request access, correction, deletion, and suspension of processing of your personal data.
Additional rights may be available under the data protection laws of your region of residence (such as Brazil's LGPD, Japan's APPI, or Mexico's LFPDPPP). To exercise any such rights, please contact us at cs@naple.co.kr.
The Company conducts internal audits on a quarterly basis to ensure the security of personal data handling.
Access to personal data is restricted to designated personnel only.
The Company has established and implements internal management plans for the secure processing of personal data.
Security software is installed and regularly updated to prevent data breaches caused by hacking or malware. Systems are installed in access-controlled zones and monitored continuously.
User passwords are encrypted for storage and management. Critical data is protected through file and transmission encryption.
Access logs to personal data processing systems are retained for a minimum of one year.
Access to database systems containing personal data is controlled through the granting, modification, and revocation of access rights. Intrusion prevention systems are used to block unauthorized external access.
Snapshot data retained for dispute resolution purposes after account deletion is stored in a separate, isolated database (Legal Vault) accessible only to authorized legal, compliance, and fraud prevention personnel.
You may lodge a complaint with the Data Protection Authority in your country of residence. A list of supervisory authorities is available on the EDPB website.
Please contact the relevant data protection authority in your region of residence, or reach out to us at cs@naple.co.kr.
Copyrightⓒ2021 (C)NAPLE All Rights Reserved.