Privacy Policy
Last updated: 2026-10-01
1. Who We Are
DIGIRAY Corp. (주식회사 디지레이) ("the Company") operates the THOR service at https://thor.savethelife.io and is the controller of the personal data described in this policy. This policy explains what we collect, why, how long we keep it, and your rights under the Personal Information Protection Act of the Republic of Korea and other applicable laws.
2. Information We Collect
- Account: email address, password (stored as a one-way hash), nickname, optional profile image, referral code, and age group if you provide it.
- Social login: account identifier and email provided by Google when you sign in with Google.
- Store orders: recipient name, shipping address, postal code, country, phone number and email.
- Payment: order number, amount, currency, payment method type, approval code and masked card number (first 4 and last 4 digits) returned by our payment provider. Full card numbers are never collected or stored by us.
- Service usage: attendance, mission and referral activity, credits, notifications, and preferences such as language and display mode.
- Technical data: IP address, approximate country derived from IP, device and browser information, access logs and cookies needed to keep you signed in.
3. How We Use Information
- To create and manage your account and authenticate you.
- To process orders, take payment, deliver products and handle cancellations, returns and refunds.
- To operate attendance, mission, referral and ranking programs and to prevent abuse.
- To respond to customer inquiries and send service notices.
- To comply with legal obligations, including record-keeping under e-commerce and tax law.
- To analyze aggregated, de-identified usage statistics to improve the Service.
4. Sharing With Third Parties & Processors
We share personal data only as needed to provide the Service:
- Eximbay Co., Ltd. (payment gateway): order number, amount, buyer name, email and phone for payment processing and fraud prevention. Card data is entered directly on Eximbay's secure page.
- Delivery partners (international couriers): recipient name, address, postal code, country and phone number for shipment and customs clearance.
- Infrastructure and email providers that host the Service and send transactional emails on our behalf.
- Authorities where disclosure is required by law or a valid legal request.
We do not sell personal data. Where data is transferred outside your country (for example to a courier in the destination country), we take steps to ensure it is protected as required by applicable law.
5. Data Retention
We keep personal data while your account is active and delete or anonymize it when you close your account, except where retention is required by law:
- Records on contracts and withdrawal of offers: 5 years (Act on Consumer Protection in Electronic Commerce).
- Records on payment and supply of goods: 5 years (same Act).
- Records on consumer complaints and dispute resolution: 3 years (same Act).
- Website access logs: 3 months (Protection of Communications Secrets Act).
6. Cookies & Local Storage
We use strictly necessary cookies to keep you signed in and browser storage to remember preferences such as language and display mode. We do not use third-party advertising cookies. You can clear cookies in your browser settings; doing so will sign you out.
7. Security
We protect personal data with encryption in transit (TLS), hashed passwords, access controls limited to authorized staff, and server monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your Rights
You may access, correct, download or delete your personal data, withdraw consent, or object to or restrict processing by contacting us at uvoli@digiray.co.kr. You can also update profile details and delete your account from the Settings page. We respond within the period required by applicable law (generally within 10 days under Korean law). You have the right to lodge a complaint with the Personal Information Protection Commission of Korea or your local supervisory authority.
9. Children
The Service is not directed to children under 14. We do not knowingly collect personal data from children under 14 without verifiable parental consent. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be announced in the Service at least 7 days before they take effect (30 days for changes that significantly affect your rights).
11. Privacy Contact
Data protection officer: DIGIRAY Corp. (주식회사 디지레이)
Email uvoli@digiray.co.kr · Tel +82-31-8073-9294
#825, 142 Ilsan-ro, Ilsandong-gu, Goyang-si, Gyeonggi-do, Republic of Korea (일산로 142, 825호)