This Privacy Policy describes how XIRA ("we," "us," or "our"), a sole proprietorship registered in the Republic of Korea operating the Lyne.bio service, collects, uses, stores, and protects your personal information. By using our service, you agree to the practices described in this policy.
For questions or concerns regarding this policy, please contact us at xira.life@gmail.com.
1. Information We Collect
1.1 Information You Provide
- Account Information: When you create an account, we collect your name, email address, and authentication credentials (password hash or third-party OAuth tokens from providers such as Google).
- Profile Information: Display name, bio, avatar image, and any other content you add to your Lyne.bio page, including links, text, images, and embedded media.
- Payment Information: When you subscribe to a paid plan, payment is processed by our third-party payment provider, Polar (polar.sh). We do not directly store your credit card numbers or banking details. We receive and store a transaction reference, subscription status, plan tier, and billing email from Polar.
- Communications: If you contact us via email or other channels, we retain the contents of those communications.
1.2 Information Collected Automatically
- Analytics Data: We collect page views, click events, referrer URLs, and engagement metrics related to your Lyne.bio page and its blocks. This data is used to provide the analytics features of the service.
- Log Data: Our servers automatically record information such as your IP address, browser type, operating system, device type, timestamps, and referring/exit pages when you access the service.
- Cookies & Local Storage: We use essential cookies to maintain your session and authentication state. We do not use third-party advertising or tracking cookies. You may disable cookies in your browser settings, but some features of the service may not function correctly.
1.3 Information from Third Parties
- OAuth Providers: If you sign in through Google or another OAuth provider, we receive your name, email address, and profile picture from that provider, as authorized by you during the sign-in flow.
- Payment Provider: Polar may share transaction status, subscription events, and billing-related data with us via webhooks.
2. How We Use Your Information
- Provide and maintain the service: To create and manage your account, render your Lyne.bio page, and process subscriptions.
- Analytics: To display page view counts, click-through rates, and other engagement metrics to you in your dashboard.
- Communicate with you: To send transactional emails (account verification, password resets, subscription receipts) and, only with your consent, marketing or product update emails.
- Improve the service: To analyze usage patterns, diagnose technical issues, and develop new features.
- Comply with legal obligations: To meet applicable Korean and international laws and regulations.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), our legal basis for processing your personal data includes:
- Contract performance: Processing necessary to provide you with the Lyne.bio service.
- Legitimate interests: Service improvement, security, and fraud prevention.
- Consent: Where you have given explicit consent, such as for marketing communications.
- Legal obligation: Where processing is required to comply with applicable law.
4. Data Sharing & Disclosure
We do not sell your personal information. We may share data in the following limited circumstances:
- Service Providers: We share data with third-party providers who perform services on our behalf (hosting, payment processing via Polar, email delivery). Each provider is contractually obligated to protect your data.
- Legal Requirements: We may disclose information if required by law, regulation, subpoena, court order, or other governmental request.
- Business Transfers: In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred as part of that transaction. We will notify you via email or a prominent notice on the service before such a transfer.
- With Your Consent: We may share information with third parties when you explicitly authorize us to do so.
5. Data Storage & Security
- Your data is stored on servers located in secure data centers managed by our hosting providers. We use industry-standard security measures including TLS/SSL encryption in transit, encryption at rest, and access controls.
- Passwords are never stored in plain text; they are hashed using strong one-way hashing algorithms.
- While we take reasonable precautions to protect your data, no method of transmission over the Internet or method of electronic storage is 100% secure.
6. Data Retention
- Active Accounts: We retain your personal information for as long as your account is active or as needed to provide you the service.
- Deleted Accounts: When you delete your account, we permanently delete or anonymize your personal data (including profile information, page content, and analytics data) within 30 days. Backups containing your data are purged within 90 days.
- Legal Retention: We may retain certain information for longer periods as required by applicable law (e.g., financial transaction records for tax compliance under Korean tax regulations for up to 5 years).
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (subject to legal retention requirements).
- Portability: Request a machine-readable copy of your data.
- Restriction: Request that we limit our processing of your data in certain circumstances.
- Withdrawal of Consent: Where processing is based on consent, withdraw that consent at any time.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, email us at xira.life@gmail.com. We will respond within 30 days.
8. Korean Personal Information Protection Act (PIPA)
In compliance with the Korean Personal Information Protection Act (PIPA), we disclose the following:
- Personal Information Protection Officer: XIRA (xira.life@gmail.com)
- Purpose of Collection: As described in Section 2 above.
- Items Collected: As described in Section 1 above.
- Retention Period: As described in Section 6 above.
- Entrustment of Processing: Personal data processing is entrusted to Polar (polar.sh) for payment processing and to our hosting providers for service delivery.
- Destruction Procedure: When personal data reaches the end of its retention period or the purpose of processing is achieved, it is destroyed without delay. Electronic data is deleted using technical methods that make recovery impossible. Printed materials are shredded or incinerated.
9. International Data Transfers
Your data may be transferred to and processed in countries other than the Republic of Korea, including countries where our hosting providers operate. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions, to protect your data in accordance with applicable law.
10. Children's Privacy
Lyne.bio is not intended for users under the age of 14 (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without appropriate consent, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the service or sending an email to the address associated with your account at least 7 days before the changes take effect. Your continued use of the service after such changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Business Name: XIRA (Sole Proprietorship)
- Email: xira.life@gmail.com
- Country: Republic of Korea