Privacy Policy

This English translation is provided for convenience. If there is any discrepancy, the Korean version prevails.

The operator of VRL.KR (the "Service") establishes this Privacy Policy under the Personal Information Protection Act to protect users' personal data and handle related concerns promptly.

1. Personal data collected and purposes

CategoryDataPurpose
Registration and account managementEmail, password (stored encrypted), name, phone (optional), company / job title / bio (optional)Identity verification, account management, notices and support replies
Short URL creationOriginal URL, creation time, hash of the requesting IP address (the original IP is not stored)Providing links, abuse prevention (rate limiting)
Click statisticsAccess time, IP hash, country (estimated from IP), device / OS / browser type, referrerStatistics for the link owner, abuse detection
Reports, inquiries, custom link requestsName, organization (optional), phone, email, messageHandling and replying to requests
API useAPI key (stored hashed), request time and countAuthentication, rate limiting

The Service does not collect payment information and does not use social login.

2. Retention period

  • Account data: until the account is closed. Deleted without delay after closure; a hash of the email address may be kept for 30 days to prevent abuse.
  • Short URLs and click statistics: until the link is deleted. Links created without an account are retained according to service policy.
  • Reports, inquiries, and requests: 1 year after completion.
  • Access logs (server logs): 3 months under the Protection of Communications Secrets Act.

3. Provision to third parties

The operator does not provide users' personal data to third parties, except where required by law or lawfully requested by investigative authorities.

4. Outsourcing of processing

ProcessorTask
Oracle CloudServer and database hosting
Kakao (Daum Mail)Sending verification codes and reply emails
MaxMindIP-to-country database (IP addresses are not transmitted; lookups happen on our server)

5. Your rights and how to exercise them

You may request access to, correction or deletion of, or suspension of processing of your personal data at any time. Members can edit their profile or close their account on the My account page; other requests sent to [email protected] are handled within 10 days.

6. Destruction of personal data

Personal data is destroyed without delay once the retention period ends or the purpose of processing is achieved. Electronic files are deleted in a way that prevents recovery.

7. Security measures

  • Passwords and API keys are stored as irreversible hashes.
  • Visitor IP addresses are never stored in original form; only a salted hash is kept.
  • All traffic is encrypted with HTTPS, and a firewall allows access to the servers only through the proxy.
  • The database is backed up regularly and access rights are kept to a minimum.

8. Cookies and analytics

The Service uses essential cookies to keep you signed in. Google Analytics or Naver Analytics may be used for visitor statistics; you can refuse cookies in your browser settings.

9. Data protection officer

10. Changes to this policy

Additions, deletions, or changes to this policy are announced in the Notices at least 7 days before they take effect.

Effective date: September 5, 2026