Privacy Policy
This English translation is provided for convenience only. If it conflicts with the Korean version, the Korean version prevails.
Barracks (the “Company”) complies with the Personal Information Protection Act and other applicable laws when operating the Snap Wedding service (the “Service”) and values the protection of users’ personal information. This Privacy Policy explains what information the Company collects and uses, why it is processed, how it is retained and deleted, and the rights available to users.
1. Personal Information Processed and Collection Methods
The Company processes the following personal information to provide the Service.
1) Registration and login
The Company supports registration and login only through Google or Kakao and collects and uses the minimum information required to identify Members and connect their accounts.
- Registration method (Google or Kakao)
- Social login account information (email address, name or nickname, and profile image)
- Service Member identifier and login provider information
2) Information created or stored while using the Service
The Service allows Members to create Events, Guest Uploaders to upload photos or videos through a QR code or link, and Members to view, select, and download that content. The following information may therefore be stored and processed while operating the Service:
- Event information, including Event name, Event date, active/inactive status, and creation time
- Event membership and invitation information
- Uploaded Content (images and videos)
- Nicknames entered directly by Guest Uploaders
- File metadata, including file name, type, size, dimensions, duration, capture time, upload time, and storage path
- QR code, upload link, and download job information
- Service usage records, including upload and download history
3) Paid Plan payments
The Company processes payments through the Toss Payments payment widget and processes the following information. Payment-method authentication information, such as card or bank account numbers, is handled directly by Toss Payments and is not stored on the Company’s servers.
- Member identifier, name, and email address
- Order ID, order name, Plan, amount, and currency
- Payment key, payment status, approval or failure time, failure code, and failure reason
4) Information that may be generated or collected automatically
The following information may be collected automatically for Service operation, security, troubleshooting, and traffic analysis through PostHog:
- Access logs, IP address, cookies, browser information, device information, operating system information, Service usage records, page visits, and usage behavior
2. Purposes of Processing Personal Information
The Company processes personal information for the following purposes:
- Member identification, registration, and login
- Creation, editing, activation, deactivation, and management of Events
- Creation and provision of QR codes or upload links
- Photo and video uploads by Guest Uploaders
- Storage, sorting, viewing, selection, and download of Uploaded Content
- Different storage, retention, watermark removal, and other features by Plan
- Paid Plan payment, payment approval, refunds, and dispute handling
- Customer support, notices, dispute resolution, Service operation, and security
- Prevention of misuse, response to infringement, error analysis, Service improvement, and statistical analysis
3. Processing and Retention Period
The Company processes and retains personal information within the period prescribed by law or agreed to by the user, as follows.
1) Member account information
- Member identifier, registration method, email address, name or nickname, and profile image: Until account deletion or completion of an account deletion request
2) Events and Uploaded Content
Under the current Plan policy, Events remain accessible for the following periods. If an Event is created or a Plan is upgraded after the Event date has passed, the period starts at creation or upgrade.
- Basic Plan: 7 days
- Standard Plan: 30 days
- Premium Plan: 90 days
Existing Members subject to the previous Plan policy may see periods of 7, 90, or 180 days in the Service. Members must download and back up required photos and data before the displayed expiration date. At expiration, access to the Event is restricted. Expiration alone does not automatically permanently delete stored files and related records. They are permanently deleted when a deletion request is processed or during operational cleanup. Information subject to a legal retention obligation may be stored separately for the required period.
3) Download job information
- Download files remain accessible for 24 hours after creation. Job records and files are not automatically deleted when access expires; they are deleted when a deletion request is processed or during operational cleanup.
4) Payment, usage, and access records
The following records may be retained for a certain period for Service operation, security, dispute response, and prevention of misuse:
- Retention under the Act on Consumer Protection in Electronic Commerce:
- Contracts and cancellations: 5 years
- Payments and supply of goods or services: 5 years
- Consumer complaints and dispute handling: 3 years
- Service access records under the Protection of Communications Secrets Act: 3 months
4. Provision of Personal Information to Third Parties
The Company does not generally provide users’ personal information to external parties, except:
- When the user gives prior consent
- When required by a specific legal provision or necessary to comply with a legal obligation
- When a lawful request is received from an investigative or other competent authority
5. Outsourcing of Personal Information Processing
The Company may outsource personal information processing as follows to provide the Service efficiently. The Company reflects personal information protection requirements in its outsourcing agreements and supervises processors under Article 26 of the Personal Information Protection Act.
- Supabase Inc.
- Member authentication, account connection, and database operation
- Google LLC (Google Cloud Platform)
- Service hosting; storage and processing of photo, video, and download files; and operation of task queues and schedulers
- PostHog Inc.
- Analysis of page visits and designated product events
- Toss Payments Co., Ltd.
- Payment methods, payment approval, cancellation, refunds, and payment result notices
During provision of the Service, the Company may outsource processing to or transfer personal information to businesses located outside Korea. The Company reviews requirements under applicable law and endeavors to use secure transmission methods.
- Recipients/processors: Supabase Inc., Google LLC, and PostHog Inc.
- Countries and regions: The primary data regions for Supabase and Google Cloud are in Seoul, Republic of Korea. The Service uses PostHog’s United States region.
- Timing and method: Information may be transferred and processed electronically when it is generated or entered during use of the Service.
- Information transferred: Member account information, Service usage records, uploaded and download files and their processing metadata, and access statistics
- Purpose and retention: Processed for Member authentication, database operation, Service hosting, file storage and processing, access analysis until each processing purpose is achieved or the applicable contract ends
6. Deletion Procedures and Methods
When personal information is no longer necessary because its retention period has expired, its purpose has been achieved, the Service has ended, or an account deletion request has been processed, the Company deletes it after checking applicable law and the actual storage structure. When an Event expires, access is first restricted. Stored files are not automatically permanently deleted by expiration alone; they are permanently deleted when a deletion request is processed or during operational cleanup.
Deletion procedure
The Company identifies personal information subject to deletion and deletes it under internal policies and applicable law.
Deletion method
- Electronic files: Deleted using technical methods that prevent recovery or reproduction
- Printed and other physical records: Destroyed by shredding, incineration, or a similar method
7. Rights of Users and Legal Representatives
Users may exercise the following rights concerning their personal information at any time:
- Request access to personal information
- Request correction or deletion
- Request suspension of processing
- Withdraw consent or request account deletion
Users may exercise these rights through customer support. After verifying the requester’s identity, the Company will act as required by applicable law. The Service does not currently provide automated account deletion.
8. Security Measures
The Company takes the following measures to protect personal information:
- Minimization of access privileges
- Access control and authentication management
- Encryption in transit and other technical safeguards
- Security measures against hacking and malware
- Retention and review of processing records
- Management and supervision of employees and processors
9. Cookies and Automatic Collection Technologies
The Company may use cookies or similar technologies for access analysis, security, and related purposes. PostHog may collect page visits, designated product events, and device and browser information. Users may reject cookies through browser settings, but some Service features may then be limited.
10. Privacy Officer and Contact Information
The Company appoints the following privacy officer to oversee personal information processing and handle privacy inquiries, complaints, and requests for relief:
- Name: Chaeun Lee
- Title: Privacy Officer
- Email: support@snapwedding.app
11. Remedies for Infringement
Users may contact the following Korean institutions for reports or consultation concerning infringement of personal information:
- Personal Information Infringement Report Center: 118 / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 / www.kopico.go.kr
- Supreme Prosecutors’ Office: 1301 / www.spo.go.kr
- Korean National Police Agency Cyber Bureau: 182 / ecrm.cyber.go.kr
12. Changes to this Privacy Policy
If the Company changes this Privacy Policy, it will provide advance notice through a notice in the Service or on the website.
Effective date: July 24, 2026