返回首页

隐私政策

Last updated: September 16, 2026

TOTARO International Co., Ltd. (the "Company") values user privacy. This policy explains what information the service processes and how it is used.

Article 1 (Information We Process)

Account and company information

  • Required: email address, password, company name, contact name
  • Supplier accounts: business registration number
  • Optional: phone number, company location, company description

When you send an inquiry, brand connection request, quote request, or sample request

  • Required: company name, contact name, email address, phone number
  • Optional: delivery address (where samples should be sent)
  • The importer registration number (EORI, VAT, EIN, business registration number, and similar) is not collected at the request stage. It is entered by our manager when preparing a quote.
  • Request content: your message
  • Order details (destination country and city, quantity and unit, requested delivery date, distribution channel) are not collected at the request stage. They are entered by our manager when preparing a quote, based on what is agreed after the introduction.
  • These requests are accepted without an account. A request sent while signed out is not linked to any account.

If you choose to connect Gmail

  • Google Account identifier, Gmail address, encrypted OAuth refresh token, and a short-lived cached access token
  • Message and thread IDs, sender and recipient addresses, sender name, subject, snippet, labels, received time, and read and work-related status
  • Message bodies are fetched from Gmail when you open them and are not stored in the Company database. Reply content is sent to the Gmail API for delivery; only non-body metadata is stored after sending.

When you use AI consultation

  • Consultation messages and searches, conversation history, AI-generated answers, and supplier search results
  • Name, format, size, and contents of files you choose to attach
  • Linked consultation records such as quote requests and supplier selections

Automatically collected and analytics data

  • IP address, cookies, access logs, browser and device data, page URL, and performance data
  • User ID and email for signed-in users, and feature events such as searches, results, and quote activity

Do not enter government identifiers, passport numbers, health data, other sensitive personal data, or confidential information that is not needed for the consultation.

Personal data processed without consent, and its legal basis

Of the items above, the Company processes information collected with an inquiry, brand connection request, quote request, or sample request without a separate consent step. The basis is Article 15(1)4 of the Personal Information Protection Act of Korea (necessary to take steps at the request of the data subject in the course of entering into a contract) — asking us to connect you with a brand, or for a quote or a sample, is itself that request.

  • The required items (company name, contact name, email, phone number) are the minimum needed to accept the request, contact you, and connect you with the brand.
  • Optional items may be left blank and the request is still accepted. The delivery address is used only to send samples and issue the quote; the importer registration number is used only to issue the quote and prepare customs paperwork.

All other items (account information, Gmail connection data, analytics and advertising data) are processed only within the scope you have consented to.

Article 2 (Purposes of Processing)

  • Account administration, identity verification, and security
  • Supplier-buyer matching and processing quote requests and responses
  • Synchronizing, viewing, replying to, and notifying you about work email in Gmail you connect
  • Generating AI answers, searching and recommending suppliers, and providing conversation history
  • Preventing errors and misuse, measuring performance, analytics, and service improvement
  • Responding to inquiries and resolving disputes

Article 3 (Retention)

  • Account and company information: while you use the service
  • AI conversations and attachments: until you delete the conversation or close your account
  • Gmail connection data and message metadata: until you disconnect Gmail or delete the supplier account. If remote revocation cannot be confirmed, the encrypted token remains in a secure cleanup queue until revocation is confirmed and is then deleted.
  • Analytics events and session replay: for the retention period configured in the PostHog project. You may ask the Privacy Officer for the current setting or request deletion.
  • Access logs: for the retention period of the runtime logs kept by our hosting provider (Vercel) — 1 day on our current plan. These are not subject to any statutory retention requirement, and we do not extend their retention.
  • Administrator access records: 1 year. These record what our staff did on screens that handle personal data (identifier, time, source address, scope processed, and operation performed), retained under Article 8(1) of the Korean standards for securing the safety of personal information.
  • Information that must be retained by law is segregated and retained for the required period.
  • Contract and withdrawal records: 5 years (E-Commerce Act)
  • Consumer complaint and dispute records: 3 years (E-Commerce Act)

Retention for inquiries and applications

  • Inquiries that led to a quote: 5 years, under the statutory period above, as records relating to a contract.
  • Inquiries with no quote issued: 1 year. These are not subject to statutory retention, so they must be destroyed once the purpose (replying to you) is fulfilled. One year is the period the Company sets to allow for follow-up questions and disputes.
  • Contact details in supplier applications: 1 year after the review closes. The company and trade terms are kept; the contact details are erased.
  • Request records kept to prevent abuse (including IP addresses): 30 days.

When you close your account, your name, email, phone number, delivery address, and importer registration number are erased from transaction records. The company name identifying the counterparty is retained on a statutory basis, but it is moved to storage segregated from other personal data, kept for the periods above, and then destroyed.

Article 4 (Destruction of Personal Information)

The Company destroys personal information without delay once the retention period has passed or the processing purpose has been achieved and the information is no longer needed.

  • Procedure: the Company identifies the personal information subject to destruction and destroys it with the approval of the Privacy Officer.
  • Method: electronic files are permanently deleted by means that prevent recovery or reconstruction; printed records are shredded or incinerated.
  • Timing: personal data past its retention period is destroyed automatically once a day. A record of each destruction run (time and counts) is kept separately.
  • Information that must be retained by law is stored separately from other personal information for the period stated in Article 3 and then destroyed. In that case retention is limited to contract and withdrawal records and dispute records.

Article 5 (Disclosure to Third Parties)

The Company does not disclose personal information to third parties without prior consent. It discloses the following to deliver a service you request:

  • Recipient: the supplier you send a quote request or order to
  • Purpose: receiving and answering quote requests, fulfilling orders, and handling related inquiries
  • Data: company name, contact name, email address, and the contents of your request such as product, quantity, and delivery date
  • Retention: until the end of the transaction and any retention period required by law

The Company may otherwise disclose information within the scope permitted by law where required by statute or a lawful request. The providers listed in Article 6 are not third-party recipients — they process information on the Company's behalf to deliver the service.

Article 6 (Processors and International Processing)

The cloud services below may process information outside Korea. Data is transmitted over encrypted connections when you use the relevant feature. Processing regions and provider retention can vary by deployment configuration and contract.

Provider / serviceProcessing and dataInternational processing / retention
Supabase Inc.Authentication, database, and storage of AI conversations and attachmentsThe region configured for the Company's Supabase project / subject to service and backup settings
Google LLC (Gmail API / Google OAuth)Supplier-selected Gmail connection, synchronization, viewing, and replies: Google Account identifier, Gmail address, OAuth tokens, message metadata, and replies the user sendsGoogle's global infrastructure / subject to Google policy and account settings while connected; Company-held data follows Article 3
Google LLC (Google Cloud Vertex AI / Gemini API)Generating AI answers and supplier searches from consultation input, attachments included in the request, and conversation contextThe configured Vertex AI region (the application default is global) or Gemini API infrastructure / subject to the applicable product configuration and contract
PostHog Inc.Product analytics and session replay: user ID and email, page and feature events, device and performance data. Input values, rendered text, and element attributes are globally masked in replay.The configured PostHog host (a US endpoint when unset) / subject to the project's retention setting
Google LLC (Google Ads)Advertising conversion measurement: cookies and online identifiers, IP address, page and referrer URLs, device data, and ad interactionsGoogle's global infrastructure / subject to the Google Ads account and product retention settings and contract

The Company's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. The Company uses this information only to provide or improve the Gmail features you request and does not sell, use, or transfer it for advertising, retargeting, credit assessment, or training general-purpose AI models. Processing otherwise occurs only within policy-permitted limits for user-consented features, security, or legal duties.

Article 7 (Cookies and Other Automatic Collection, and How to Refuse Them)

The Company uses essential cookies to keep you signed in. Product analytics and session replay (PostHog), and advertising conversion measurement (Google Ads), are loaded only after you consent through the cookie banner.

  • Chrome: Settings > Privacy and security > Third-party cookies
  • Safari: Settings > Privacy > Cookies and website data
  • Edge: Settings > Cookies and site permissions > Manage cookies and site data

You can refuse or change analytics and advertising consent at any time using "Cookie settings" in the page footer, or on your Settings screen once signed in. Refusing these cookies does not limit core service features, but blocking essential cookies in your browser may prevent sign-in. Contact the Privacy Officer below to request deletion of information already collected.

Article 8 (Your Rights)

You may request access, correction, deletion, or suspension of processing.

You can delete an AI conversation using the service or contact the Privacy Officer below. The Company handles requests in accordance with applicable law.

Article 9 (Privacy Officer)

Name: Taejun Yoon

Title: CEO

Email: totaro@totaro.co.kr

Phone: +82-10-9427-2659

Article 10 (Security Measures)

  • Access controls and minimization of access rights
  • SSL/TLS encryption for data in transit
  • Masking input values, rendered text, and element attributes in PostHog session replay
  • Security systems designed to prevent external intrusion

This Privacy Policy is effective as of August 6, 2026.