Privacy Policy

LunePay processes the minimum information needed to provide the Service. This policy describes only what the Service currently collects, uses, and stores.

Document version
v1.1
Effective date
2026-09-01

1. Controller and contact

The operator's identity, privacy officer, and contact details are published in the public footer and in the operator information block at the end of this document.

Requests to access, correct, delete, or suspend processing of personal information, and any privacy enquiry, can be sent to those contacts.

2. Information collected

  • Account: email, name, social login provider and provider identifier (Kakao, Google), profile image URL, last login time.
  • Workspace business details: business registration number, trade name, representative, address, business type/category, and contact person (when using cash receipt or tax invoice features).
  • Bank account details: the bank, account number, and account holder registered for deposit monitoring.
  • Orders: order number, amount, depositor name, customer email and phone, memo, and the identifier entered for cash receipt issuance (when provided).
  • Deposits: the raw bank notification SMS, amount, depositor name, and deposit time.
  • SMS collection logs: receiving number, sender, raw message, parsing result, and collecting device identifier.
  • Notification settings: the mobile number that receives notifications and its verification record.
  • Operational logs: webhook delivery records, access and usage records, and the reason entered on account deletion.

3. Purposes of use

  • Automatic matching of bank deposit messages against order records, and delivery of the results.
  • Member identification, account and workspace management, and permission checks.
  • Processing optional features the customer enables, such as cash receipt and tax invoice issuance.
  • Sending deposit and matching notifications when the customer configures them.
  • Incident response, abuse prevention, and service quality improvement.

4. Processors and third parties

  • Popbill: receives the transaction and business information needed to issue cash receipts and tax invoices when the customer uses those features.
  • Kakao AlimTalk: receives the recipient number and message content needed to send notifications the customer has configured.
  • Kakao and Google: used for authentication when the customer chooses social login.
  • NICEPAY: receives the card verification values needed to register a payment method (billing-key issuance) when the customer registers one.
  • Any other disclosure to third parties occurs only with the customer's separate consent or on a legal basis.

5. Payment data boundary

LunePay is not a payment gateway and neither authorizes nor processes payments inside the Service.

The card number, expiry date, birth date (or business number), and first two digits of the card password entered when registering a payment method are forwarded through a protected registration request to the payment provider (NICEPAY) and used only to register that payment method. LunePay stores none of those values in its database, logs, analytics, or support records.

After registration, LunePay retains only the payment method reference, masked display data such as the issuer name and the last four digits, and the registration status and registration/revocation times.

6. Retention and deletion

Information is retained while it is needed to provide the Service, and is deleted when the workspace or the account is deleted.

Records that law requires to be preserved for a set period are stored separately for the period that law prescribes and then destroyed. LunePay sets no fixed retention period of its own beyond those legal requirements.

7. Data subject rights

Customers may request access to, correction of, deletion of, or suspension of processing of their personal information.

Items that can be viewed, edited, or deleted directly in the dashboard can be handled there; other requests can be sent to the contact published in the footer.

8. Security measures

  • Key fields — name, business details, order records, depositor name and amount, and collected raw messages — are stored encrypted in the database.
  • Workspace-scoped access control prevents access to another workspace's data.
  • Traffic is encrypted with HTTPS, and administrative functions require a separate permission check.

9. Changes to this policy

If this policy changes, the effective date and the changes will be announced in the Service.