Privacy Policy
Effective 1 August 2026
Tagloft is a web service for registering the assets an organization owns and tracking their check-out, return and maintenance history. The operator of the service ("we") complies with the Personal Information Protection Act of the Republic of Korea and other applicable law. This policy explains what we collect, why, and how we protect it.
1. Two kinds of information
The personal information this service handles falls into two categories. We state this first because how you exercise your rights depends on which one applies.
- Account information — information about you as a registered user of the service. We are the controller of this information.
- Organization data — information you enter to run your own organization: your staff and customer directories, asset photographs, and so on. Your organization is the controller of this data; we are a processor acting on its instructions.
We do not use organization data for any purpose other than delivering the service and responding to faults. To correct or delete information about you that is held inside an organization, contact that organization's administrator.
2. What we collect
| Category | Items | How it is collected |
|---|---|---|
| Account (required) | Email address, password | Entered by you at sign-up |
| Account (optional) | Display name | Entered by you at sign-up |
| Account (only if you choose Google sign-in) | Email address, name, profile picture URL | Provided by your Google account |
| Organization | Organization name, logo, currency, time zone | Entered by you |
| Organization data — staff | Name, employee number, job title, department, phone, email address, photograph | Entered by you or uploaded as CSV |
| Organization data — customers and vendors | Name, company, phone, mobile, email address, postal address, photograph | Entered by you or uploaded as CSV |
| Organization data — history | A record of who checked out, returned or serviced which asset, and when | Generated automatically from your actions |
| Automatic | IP address, browser type, time of access | Collected automatically while you use the service |
Passwords are stored one-way hashed, so we cannot read them. We do not collect national identification numbers or any comparable unique identifier in any field.
3. Why we process it
- To identify you and keep you signed in
- To provide asset management within your organization
- To send email about upcoming returns, overdue assets and expiring leases
- To prevent abuse and diagnose faults
- To answer enquiries and improve the service
We do not use this information for advertising or marketing. The service carries no analytics package and no advertising tracker.
4. How long we keep it
| Item | Retention |
|---|---|
| Account information | Until you close your account, then destroyed immediately |
| Organization data | Thirty days after a deletion request — a grace period to recover from an accidental deletion — then destroyed |
| Alert delivery records (recipient address, date sent) | One year, to prevent duplicate notices |
| Server access logs | Up to thirty days |
Where the law requires a different retention period, we keep the data for that period and then destroy it.
5. Disclosure to third parties
We do not disclose your personal information to third parties. The exception is a lawful demand from a law enforcement authority following due process; unless the law forbids it, we will tell the affected user that such a demand was made.
6. Processors and cross-border transfer
We use the following providers to operate the service. All are outside Korea, so this table also serves as the disclosure of cross-border transfer. In every case the transfer happens over the network at the moment you use the service.
| Recipient | Country | Items transferred | Purpose | Retention |
|---|---|---|---|---|
| Supabase Inc. | United States (data is stored in the AWS Seoul region, ap-northeast-2) | All account information and organization data | Database, authentication and file storage | Until the processing agreement ends |
| Cloudflare, Inc. | United States and its global edge network | IP address, request contents | Web hosting and content delivery | Until the processing agreement ends |
| Plus Five Five, Inc. (Resend) | United States | Recipient email address, contents of the notification | Sending notification email | Until the processing agreement ends |
| Google LLC | United States | Email address, name, profile picture URL | Google sign-in (only if you choose it) | Until the processing agreement ends |
Your asset data itself is stored in the Seoul region. These providers are headquartered in the United States and may access it in the course of support, which is why it is listed as a cross-border transfer.
Separately, the web fonts used in the interface are fetched from Google Fonts (fonts.googleapis.com, fonts.gstatic.com) and jsDelivr (cdn.jsdelivr.net). Your IP address and browser details reach those providers as part of that request. The service sends no other personal information with it.
You may refuse cross-border transfer, but these transfers are essential to delivering the service, so refusing means the service cannot be used.
7. Cookies
The service sets the following cookies to keep you signed in and to remember your display settings.
| Name | Purpose | Type |
|---|---|---|
| sb-… (Supabase auth cookies) | Keeps your session signed in | Strictly necessary |
| tl_org | Identifies the organization you are working in | Strictly necessary |
| tl_locale | Your chosen display language | Functional |
| tl_theme, tl_font, tl_scale | Theme, typeface and text size | Functional |
| tl_columns | Which columns the asset list shows, and in what order | Functional |
There are no advertising or analytics cookies, and no third-party tracking cookies. You can block cookies in your browser, but blocking the authentication cookies makes signing in impossible.
8. Your rights and how to exercise them
You may at any time ask to see, correct, delete or restrict the processing of your personal information.
- Account information — view and change it on the account screen after signing in. You can close your account from the same screen.
- Organization data — ask the administrator of that organization. We act as a processor and do not alter or delete it without the organization's instruction.
- Taking your data with you — you can export every asset and every history record to CSV at any time. Your data is not held hostage by the service.
For anything those screens do not cover, write to tagloft@ourhertz.com. We respond within ten days of receiving the request. A legal representative or an authorised agent may make the request on your behalf.
9. Destruction of personal information
Once the retention period ends or the purpose is fulfilled, we destroy the information without delay. Electronic files are deleted by a method that prevents recovery; printed material, if any, is shredded or incinerated.
10. Security measures
- All traffic is encrypted with HTTPS (TLS).
- Passwords are stored one-way hashed and cannot be read by us.
- The database enforces row level security, so data belonging to another organization cannot even be queried. If the application ever forgot a filter, the database would still refuse.
- Asset photographs and documents are held in private storage. Only an authorised request receives a short-lived signed link; knowing the address is not enough to open the file.
- Administrative access is kept to a minimum, and no key capable of bypassing database permissions is present in the application.
11. Contact
For questions, complaints or remedies relating to the handling of personal information, contact us at the address below. We reply without delay.
| Role | Contact |
|---|---|
| Data protection officer | Tagloft operator · tagloft@ourhertz.com |
12. Redress
If you need help with a privacy complaint, the following Korean authorities can assist.
| Body | Telephone | Web |
|---|---|---|
| Personal Information Dispute Mediation Committee | +82-1833-6972 | www.kopico.go.kr |
| Privacy Infringement Report Centre | +82-118 | privacy.kisa.or.kr |
| Supreme Prosecutors’ Office, Cyber Investigation | +82-1301 | www.spo.go.kr |
| National Police Agency, Cyber Bureau | +82-182 | ecrm.police.go.kr |
13. Changes to this policy
We may revise this policy as the law or the service changes. We will post any change in the service at least seven days before it takes effect, and at least thirty days before if the change is to your disadvantage.