KOREAN ORIGINAL CONTROLS
This is an explanatory English translation. Nunchi processes only the data needed for accounts, payments, ranking operations, and abuse prevention.
Google, Kakao, and Naver login may provide a provider subject ID, display name, avatar, and verified email. We use these for account access and explicit identity linking.
Order ID, amount, wallet, status, provider transaction reference, legal versions, and consent time are used for confirmation, refunds, disputes, and statutory records.
A Redis session lasts 14 days and is linked by a Secure, HttpOnly, SameSite=Lax cookie. A guest lookup token stays in same-tab sessionStorage for payment claiming and is not put in ordinary server logs.
Anonymous first-party sessions and a daily rotating HMAC are used for online presence and click deduplication. Raw IP addresses are not retained as analytics records.
You may reject or delete cookies in browser settings. Rejecting the essential session cookie disables login and My Payments, but public rankings remain readable.
A Secure HttpOnly first-party cookie and privacy-safe HMAC softly limit random credit to one draw per browser. Coupon codes are stored as HMAC-SHA256 hashes and plaintext is only provided in the one-time generation CSV.
Data is deleted when no longer needed, except Korean e-commerce records: advertisements for 6 months, contracts and payments for 5 years, and consumer complaints or disputes for 3 years. Account data remains until deletion or the end of a legal hold.
Nunchi does not sell or disclose personal data to third parties without consent or another lawful basis.
Payment, cloud, object storage, database, session, and email vendors may process data. The production notice will identify the actual provider, country, transferred fields, timing, method, and retention period before checkout is opened.
Electronic data is securely deleted and backups expire through their rotation cycle. Paper records are shredded or incinerated.
You may request access, correction, deletion, suspension, or withdrawal of consent. Requests are submitted to the privacy contact and processed after identity verification, subject to law.
Nunchi uses encryption in transit, least privilege, secret separation, request and audit records, rate limits, and SSRF controls. OAuth access and refresh tokens are not retained as Nunchi account data after callback processing.
The privacy officer and contact appear in operator information. Production payment remains blocked until mandatory contact details and legal review are complete.
OPERATOR