Article 1 (Collected Information)
The Company processes information collected from members (customer representatives) and from End-Users through Publishers separately.1.1. Member Information (Customer Representatives)
Information collected directly when Publishers and Advertisers create accounts, enter into service agreements, or submit inquiries.- Mandatory Items: Email address (ID), password, name (or nickname), company name (organization)
- Automatically Collected: IP address, cookies, access logs, service usage records, device information (OS, browser type and version)
- Payment & Settlement (if applicable): Bank name, account number, account holder name, business registration certificate, credit card information (processed via payment gateway providers)
- Inquiry Information: Name, email address, company name, contact number, and inquiry content (collected via the website inquiry form, coffee chat requests, or referral program applications; retained for 12 months after the purpose is achieved, then destroyed)
1.2. End-User Information
Information collected indirectly through the A.drop SDK integrated into the Publisher’s app/web. The specific scope depends on the permissions requested by the Publisher’s app/web and the End-User’s consent. If the Publisher sets its own user identifier (e.g., member ID) in the SDK, direct identifiers may be included. a. Advertising Identifiers and SDK Identifiers- ADID (Android Advertising Identifier), IDFA (iOS Advertising Identifier, subject to ATT approval)
- SDK-generated identifier: An internal identifier (ULID) generated by the A.drop SDK on first execution. Stored per device and used for service quality maintenance, ad frequency capping, and fraud prevention even when advertising identifiers are disabled.
- Device manufacturer, device model, OS version, language settings, timezone
- IP address (incidental to transmission)
- Carrier information (Android only: MCC/MNC codes and carrier name)
- Screen size and resolution, screen orientation, system theme (light/dark)
- User-Agent string
- Package name (Android) or Bundle ID (iOS)
- App version, SDK version
- App signing certificate SHA-1 fingerprint (Android only)
- Debug mode status
- Ad request, impression, click status and timestamp
- Ad unit identifier (Unit ID)
- Advertiser and campaign identifiers
- Mediation and backfill routing information (name of network passed through, etc.)
- Publisher-Provided User ID: A user identifier set by the Publisher via the SDK’s
setUidAPI. The Company requires Publishers to use hashed values or arbitrary internal identifiers instead of direct identifiers such as email or phone number. The Publisher bears responsibility if direct identifiers are provided. - Demographic Properties: Age (AGE), date of birth (BIRTH, yyyyMMdd format), and gender (GENDER) set by the Publisher via the SDK’s
AdropMetrics.setPropertyAPI. - Custom Properties: Up to 256 key-value properties defined by the Publisher.
- Custom Events: Arbitrary event names and parameters transmitted by the Publisher via the SDK’s
sendEventAPI.
- End-User marketing consent status and consent timestamp collected by the Publisher through the SDK.
- Cookies and local storage set by ad creatives (web content)
- Interaction data within ad creatives (scroll, touch, etc.)
1.3. Company Website Visitor Information
When visiting the Company’s website (adrop.io), cookies, IP address, access date and time, and visit history are collected. The Company uses Google Analytics to analyze website usage. Visitors may refuse this via the methods described in Article 7.Article 2 (Purpose of Processing)
The Company uses collected information solely for the following purposes.2.1. Service Operation and Management
Management of A.drop integrated accounts, distribution of advertising platforms, revenue settlement and tax processing, customer support (CS), incident response, and system stability.2.2. Ad Optimization and Reporting
Ad performance measurement and analysis (Attribution), frequency capping, daily impression/click management for pacing, ad fee calculation and revenue settlement by pricing model, ad request validation and invalid traffic filtering (per Article 13(7) of the A.drop Terms of Service), fraud detection and prevention, audience targeting, contextual targeting and audience-based personalized ad delivery, and mediation optimization.2.3. Service Improvement
Analysis of access frequency, statistical analysis for feature improvement, and data analysis for new ad product development.2.4. Collection and Use of Behavioral Information
The Company processes behavioral information for personalized ad delivery as follows.- Items Collected: Advertising identifiers (ADID/IDFA), SDK-generated identifier (ULID), ad request/impression/click history, user properties and events provided by the Publisher, contextual information of the placement where ads are shown
- Method of Collection: Automatically collected via the A.drop SDK integrated into the Publisher’s app/web
- Purpose: Personalized ad delivery, frequency capping, performance measurement, and fraud detection
- Retention Period: Per Article 3(2)
- User Control: Users may refuse the collection of advertising identifiers and personalized ads via device settings as described in Article 7, and may use the consent withdrawal mechanisms provided by individual app/web services.
Article 3 (Retention Period, Usage, and Destruction)
The Company destroys personal information without delay once the purpose of collection and use has been achieved.3.1. Member Information Retention
a. Retention per Company Policy- Upon Member Withdrawal: Retained for 3 months to prevent fraudulent use and respond to disputes, then destroyed
- Service Usage Logs (access IP, access time): Retained for 12 months per internal policy, then destroyed
- Records on contracts or withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records on payment and supply of goods: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records on consumer complaints or dispute settlement: 3 years (Act on Consumer Protection in Electronic Commerce)
- Records on books and supporting documents: 5 years (Framework Act on National Taxes, Value-Added Tax Act)
3.2. End-User Data Retention
3.3. Destruction Procedures and Methods
Personal information for which the destruction cause has occurred is destroyed in a manner that makes recovery impossible.- Electronic Files: Permanently deleted using technical methods (e.g., Low-Level Format) that make recovery and reproduction impossible.
- Paper Documents: Destroyed by shredding or incineration.
Article 4 (Third-Party Provision and Ad Network Integration)
The Company does not sell End-User personal information to external parties for monetary consideration. However, the minimum data necessary for advertising service provision is transferred to the ad networks below, which may constitute “Sharing for Cross-Context Behavioral Advertising” under CPRA (see Article 6.3). Use for purposes other than those listed below is prohibited.4.1. Bidding Backfill Ads and Mediation Networks
The following networks are included in the Publisher’s app only when the Publisher integrates the A.drop SDK’s backfill module.
※ For specific personal information processing by each network, please refer to the respective network’s privacy policy.
4.2. Rewarded Ad Verification (SSV, Server-Side Verification)
When a rewarded ad view is completed, the userId and customData set by the Publisher in the A.drop SDK are transmitted to Google’s server (USA), and Google returns them signed to the Company’s server. The Company stores the returned verification data (userId, customData, ad unit ID, transaction ID, reward information) and provides it to the Publisher to determine reward eligibility. The retention period follows Article 3. The Publisher decides what values to set for userId and customData; the Company recommends that no personal information be included in those values.4.3. Ad Player JS Hosting (Automatic Access to External Resources)
When rendering ad creatives, the End-User’s device directly connects to the jsDelivr CDN to download JavaScript resources. During this process, the IP address and User-Agent are automatically transmitted to the CDN. jsDelivr is a global CDN that responds from nodes near the user’s location; the Company does not directly transfer personal information in this process. This constitutes automatic transmission incidental to network usage, not third-party provision of personal information.Article 5 (Processing Delegation and International Transfer)
The Company delegates personal information processing tasks to the following vendors for smooth service provision. Due to the global nature of the service, some data may be stored on cloud servers located abroad.5.1. Vendors and Delegated Tasks
In addition to the table above, the Company delegates processing of payment and settlement information to Toss Payments Co., Ltd. (Republic of Korea) and Stripe, Inc. (USA) for Advertiser card payments and Publisher revenue disbursement. Additions or changes to vendors will be reflected in this policy and disclosed.
5.2. Sub-Delegation
- If the Company additionally delegates processing to a third party (sub-delegation) beyond the vendors listed in Article 4 and Article 5.1, the Company will obtain the Publisher’s prior approval or specify it in the delegation agreement and provide separate notification.
- When vendor changes (additions/replacements) occur, the Company will notify Publishers in advance, and Publishers may object or terminate the delegation agreement.
- The Company imposes the same level of privacy protection obligations on sub-delegates as those in this policy and the delegation agreement.
5.3. International Transfer of Personal Information (Overview)
The following protective measures apply to data transferred internationally as described in Article 4 and Article 5.1.- Legal Basis: Article 28-8 of the Personal Information Protection Act, Articles 44-49 of GDPR (EU Standard Contractual Clauses (SCC) or adequacy decisions)
- Safety Measures: Encryption in transit (TLS 1.2 or higher), encryption at rest, access control
- Countries: As listed in Article 4 and Article 5.1
- Items Transferred: As listed in Article 1
- Transfer Time and Method: Transmitted via network as needed during service usage
- Retention Period: As listed in Article 3
5.4. Right to Refuse International Transfer
Users may refuse international transfer by notifying the Company’s privacy department (contact@adrop.io) in writing or by email. The Company will notify the result of the processing within 10 days of receiving the refusal request. End-Users may also express their refusal through the relevant app/web service (Publisher). However, refusal of delegation or storage essential for service provision may result in restricted use of the service.Article 6 (End-User Data and Global Compliance)
Since the Service processes End-User data through the Publisher’s app/web, the Company acts as a ‘Processor’.6.1. Status as a Processor
- GDPR / CPRA Roles: The Publisher is the ‘Data Controller’ or ‘Business’ that determines the purpose and means of data collection. The Company is the ‘Data Processor’ or ‘Service Provider’ that processes data on behalf of the Publisher.
- Responsibility for Consent: The Publisher is solely responsible for obtaining lawful consent from End-Users regarding data collection and use (e.g., for personalized ads). The Company processes only the data transmitted by the Publisher through lawful procedures.
- Consent Setting Guidance: After obtaining lawful consent from End-Users for personal information collection/use and personalized ads, the Publisher must convey the result to the SDK’s consent gating feature. When consent is set to “not agreed,” custom events and user properties (age, date of birth, gender, etc.) are not transmitted to the Company’s server. The Publisher bears responsibility for data transmitted while the consent result has not been conveyed.
6.2. Exercise of End-User Rights
- End-Users must primarily contact the relevant app/web service (Publisher) to exercise their rights to access, correct, delete, or restrict the processing of their personal information.
- Upon receiving a request for data deletion (Right to Erasure) or restriction of processing from the Publisher, the Company will technically support and fulfill it within 30 days. If the Company receives a request directly from an End-User, it will promptly forward the request to the relevant Publisher, notify the requester, and directly process it within the scope required as a Processor under the Personal Information Protection Act.
6.3. CPRA “Sell” and “Share” Measures
- The Company does not sell End-User personal information for monetary consideration.
- However, the ad network integration in Article 4.1 may constitute “Sharing for Cross-Context Behavioral Advertising” under CPRA. The Company contractually and technically supports Publishers in providing Opt-Out mechanisms to End-Users.
Article 7 (Management of Cookies and Advertising Identifiers)
The Company uses cookies and advertising identifiers to improve user convenience and provide personalized services. Users may refuse these via device settings.7.1. How to Opt-Out
- Web: Browser Settings → Privacy → Block Cookies
- App (iOS): Settings → Privacy & Security → Tracking → Turn off “Allow Apps to Request to Track”
- App (Android): Settings → Google → Ads → Delete Advertising ID or Opt out of Ads Personalization
Article 8 (Security Measures for Personal Information)
The Company takes the following measures to prevent loss, theft, leakage, forgery, alteration, or damage of users’ personal information.8.1. Administrative Measures
Establishment and implementation of internal management plans, regular employee training, and other measures to raise security awareness.8.2. Technical Measures
Management of access rights to personal information processing systems, installation of access control systems, encryption during transmission (TLS 1.2 or higher) and storage (AES-256) of unique identification information, and installation/update of security programs.8.3. Physical Measures
Control of physical access to server rooms and data storage rooms. (The Company complies with AWS data center physical security policies.)Article 9 (Response to Personal Information Breach Incidents)
9.1. Incident Notification and Reporting
If a personal information breach incident occurs, the Company will, within 72 hours of becoming aware of it, (1) report to the Personal Information Protection Commission (or relevant supervisory authority) and (2) notify affected users (members and, under agreements, End-Users) of the following:- Items of personal information leaked
- Time of the breach and the circumstances
- Measures users can take to minimize potential harm
- Company’s response measures and remedy procedures
9.2. Notification Duty as a Processor
As a Processor, when the Company becomes aware of a data breach, it will notify the relevant Publisher (data controller) without delay and cooperate with investigations and responses requested by the Publisher.Article 10 (Data Handling upon Publisher Contract Termination)
Upon termination of a service agreement with a Publisher, the Company follows these procedures.- Choice of Return or Deletion: Within 30 days from the contract termination date, the Publisher may request the return or complete deletion of End-User data stored by the Company.
- Default Handling: In the absence of a separate request from the Publisher, data is destroyed sequentially according to the retention periods in Article 3.
- Export of Publisher-Owned Data: Upon the Publisher’s request, the Company will export data belonging to the Publisher (e.g., campaign information and ad performance reports) in a commonly used file format and provide reasonable transition support.
- Destruction Certificate: Upon the Publisher’s request, the Company will provide proof of destruction within 30 days.
- Exception: Information required to be retained by relevant laws is stored separately for the required period, then destroyed.
Article 11 (Personal Information of Children Under 14)
The Company does not directly collect personal information from children under 14. If a Publisher operates an app/web primarily targeting children, the Publisher must obtain consent from legal guardians and apply COPPA (Children’s Online Privacy Protection Act) and child-directed service settings in the SDK. The Company processes only the data transmitted by the Publisher through lawful procedures.Article 12 (User Rights and Exercise (Members))
Members and their representatives may exercise the following rights regarding their personal information.- Right to Access: Request access to member information.
- Right to Correction and Deletion: Request correction or deletion of erroneous information, except where retention is required by relevant laws.
- Right to Restriction: Request suspension of personal information processing.
- Exercise Method: Contact the department listed in Article 13 by email (contact@adrop.io). The Company will take necessary measures within 10 days and reply with the result.
Article 13 (Privacy Officer and Contact Information)
The Company operates a dedicated department to protect user privacy and handle related grievances promptly.13.1. Department and Contact
- Privacy Officer: Yusin Kim / CEO / 02-6011-7707 / contact@adrop.io
- Department: A.drop Privacy Team
13.2. Remedies for Rights Infringement
For reports or consultations regarding personal information infringement, please contact the following organizations:- Personal Information Infringement Report Center (privacy.kisa.or.kr / 118)
- Supreme Prosecutors’ Office Cyber Investigation Division (spo.go.kr / 1301)
- Korean National Police Agency Cyber Investigation Bureau (ecrm.cyber.go.kr / 182)