Privacy Policy
Last updated: 2026-07-03
Article 1 (General & BYO-data Principle)
Retengo ("the Company") provides a D2C retention and review-request automated email service ("the Service"). The Company does not collect or storea merchant's (store operator's) order and customer data in its own database; it retrieves and processes such data in real time, only at the moment an email needs to be sent, via the commerce platform (Cafe24, Shopify) the merchant has connected (BYO-data).
Article 2 (Personal Data We Process)
- Beta signup information: store name, store URL, contact email, contact phone (collected directly at the time of submission via the homepage signup form)
- Merchant (customer company) information: contact name, email, phone, billing information
- Authentication information: Cafe24/Shopify OAuth authentication tokens (stored encrypted — Cafe24 uses access/refresh tokens, Shopify uses non-expiring offline access tokens), store ID/domain, granted scopes
- End-user (store shopper) information: name, email, order history, marketing consent status — not stored; processed transiently only at send time
- Send logs: recipient email, send status, send timestamp (for analysis/visibility purposes), unsubscribe list
Article 3 (Purpose of Use)
Extracting and sending automated retention/review-request emails, managing send results, operating the Service and responding to inquiries, and billing.
Article 4 (Minimal Access & Security)
- We always request read-only access — mall.read_order / mall.read_customer for Cafe24, read_orders / read_customers for Shopify.
- Authentication tokens are stored encrypted with AES-256-GCM, never in plaintext.
- Emails are sent over TLS-encrypted channels.
- Tokens are refreshed automatically before expiry; refresh/call failures are logged.
Article 5 (Third-party (Sub-)Processing)
To provide the Service, we entrust personal data processing to the vendors below, each under a data processing agreement (DPA). We do not currently integrate a separate payment processor (the Service is free during the beta period; this section will be updated and disclosed if we move to a paid plan).
- Resend — email delivery infrastructure (recipient email, message body)
- Vercel — application hosting
- Turso — managed database (encrypted auth tokens, consent status, send logs)
Article 6 (Retention & Deletion)
Beta signup information is deleted once its purpose (confirming pilot participation) has been fulfilled. Authentication tokens and consent-status data are deleted immediately when a merchant disconnects. Send logs (recipient email, send status, send timestamp) are retained for 1 year from the most recent send for analysis and legal-dispute purposes, then deleted. Merchants may disconnect at any time from the Connections screen, which immediately deletes tokens and consent data.
Article 7 (Data Subject Rights)
Data subjects may request access, correction, deletion, processing suspension, or withdrawal of consent. End users can stop receiving marketing emails at any time via the unsubscribe link at the bottom of every marketing email — clicking it immediately excludes them from future sends. For other rights requests such as deletion, please email us using the contact below and we will process it without delay.
Article 8 (Privacy Officer / Contact)
Company: Retengo · CEO: Haeun Lee · Business Registration No.: 285-58-00543
Address: 8F-804, 124 Unjung-ro, Bundang-gu, Seongnam-si, Gyeonggi-do, South Korea (13466) · Email: hello@retengo.io · Inquiries are accepted by email only.
Address: 8F-804, 124 Unjung-ro, Bundang-gu, Seongnam-si, Gyeonggi-do, South Korea (13466) · Email: hello@retengo.io · Inquiries are accepted by email only.