시행일: 2026년 8월 18일
오어앤코(Ore&Co, 사업자등록번호 830-03-02579, 대표 전예리, 이하 "회사")는 이용자의 개인정보를 중요시하며, 「개인정보 보호법」, 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 등 관계 법령을 준수합니다. 회사는 이 개인정보처리방침을 통해 이용자가 제공한 개인정보가 어떠한 목적과 방식으로 처리되고, 개인정보 보호를 위해 어떠한 조치가 이루어지는지 안내합니다.
제1조 (수집하는 개인정보 항목 및 수집방법)
1) 회원가입(Google 소셜 로그인) 시
- 수집 항목: [필수] 이메일, 이름/프로필 이미지(Google 계정 제공 정보)
- 수집 방법: Google OAuth 인증(Supabase 경유)
- 이용 목적: 회원 식별, 서비스 제공 및 이용자 문의 대응
2) 서비스 이용 중 생성되는 정보
- 프로젝트 경험 입력 내용(경력정보), Pins 저장 데이터
- 입력 문서(채용공고·제안요청서 등) 붙여넣기 입력값
- 업로드 파일(경력기술서 등 pdf/docx) 및 첨부 이미지·참고 링크
3) 결제 시
- 수집 항목: 결제수단 정보는 원칙적으로 결제대행사(PG사)가 직접 수집·저장하며, 회사는 결제 승인 결과(결제일시, 금액, 이용권 종류)만 보관합니다. 카드번호·유효기간·비밀번호는 회사가 수집하지 않으며, 이용자가 결제대행사의 결제창에 직접 입력합니다.
- 정기결제를 선택한 경우 추가 수집 항목: 결제대행사가 발급한 빌링키(카드번호가 아니라 결제 요청에만 쓰이는 식별 토큰), 화면 표시용 카드사명 및 카드번호 끝 4자리
- 이용 목적: 이용권 결제 처리, 결제 내역 제공, 환불 처리, 정기결제 갱신 청구
- 보유 기간: 빌링키는 정기결제 해지 또는 회원탈퇴 시 지체 없이 파기하며, 결제대행사에도 폐기를 요청합니다.
4) 서비스 이용에 따라 자동 수집되는 정보
- 접속 IP, 쿠키, 서비스 이용기록(방문일시, 접속기기·브라우저 정보), 부정이용 방지 기록
5) 문의·상담 시
- 이메일 주소, 문의 내용
제2조 (개인정보의 수집 및 이용목적)
1. 서비스 제공: 프로젝트 카드 생성, Pins 관리, 입력 문서 분석(Match), Insights 등 서비스 핵심 기능 제공
2. 회원관리: 회원 식별, 부정이용 방지, 고지사항 전달, 탈퇴 의사 확인
3. 결제 및 정산: 이용권 결제 처리, 결제내역 제공, 환불 처리, 관련 법령상 기록 보존
4. AI 분석: 이용자가 입력한 프로젝트 경험·입력 문서 텍스트를 AI 모델(Anthropic Claude API)에 전송하여 구조화·분석 결과 생성
제3조 (개인정보의 처리위탁 및 제3자 제공)
회사는 서비스 제공을 위해 아래와 같이 개인정보 처리를 위탁하고 있으며, 위탁계약 시 관계 법령에 따라 개인정보가 안전하게 관리되도록 필요한 사항을 규정하고 있습니다.
- Anthropic (Claude API) — 위탁업무: 이용자 입력 텍스트(프로젝트 경험, 입력 문서)의 AI 구조화·분석 / 처리 정보: 이용자가 입력한 경력·입력 문서 텍스트(결제정보·비밀번호 등은 전송하지 않음)
- Supabase — 위탁업무: 회원 인증 및 서비스 데이터 저장 / 처리 정보: 계정 정보, Pins 데이터
- Google — 위탁업무: OAuth 소셜 로그인 인증 / 처리 정보: 이메일, 프로필 정보
- 주식회사 코리아포트원(PortOne) — 위탁업무: 결제 연동 및 결제 정보 중계 / 처리 정보: 결제수단 정보, 결제 승인 내역
- 엔에이치엔케이씨피 주식회사(NHN KCP) — 위탁업무: 국내 결제 대행 및 결제 승인 처리 / 처리 정보: 결제수단 정보, 결제 승인 내역
- PayPal Pte. Ltd. — 위탁업무: 해외 결제 대행 및 결제 승인 처리 / 처리 정보: 결제수단 정보, 결제 승인 내역
- Functional Software, Inc.(Sentry) — 위탁업무: 서비스 오류 수집 및 원인 분석 / 처리 정보: 오류 메시지와 발생 위치, 접속한 페이지 주소, 브라우저·기기 종류, 회원 식별자
- Plus Five Five, Inc.(Resend) — 위탁업무: 안내 메일 발송(결제 완료, 이용권 만료·자동갱신 사전 안내) / 처리 정보: 이메일 주소, 이용권 종류와 결제 예정 금액
회사는 이용자의 동의 없이 위 목적 범위를 초과하여 개인정보를 제3자에게 제공하지 않습니다. 다만 법령의 규정에 의거하거나 수사기관의 적법한 요구가 있는 경우는 예외로 합니다.
[개인정보의 국외 이전]
위 수탁사는 모두 국외에 서버를 두고 있어, 위탁 처리 과정에서 개인정보가 국외로 이전됩니다.
- 이전받는 자 / 이전되는 국가 / 이전 항목 / 이전 일시 및 방법 / 이용 목적 / 보유 기간
- Anthropic, PBC / 미국 / 이용자가 입력한 경력·문서 텍스트 / AI 기능 이용 시 네트워크를 통한 전송 / AI 구조화·분석 / Anthropic의 상용 API 정책에 따라 원칙적으로 최대 30일 이내 삭제
- Supabase, Inc. / 미국 / 계정 정보, Pins 데이터 / 서비스 이용 시 네트워크를 통한 전송 / 회원 인증 및 데이터 저장 / 회원 탈퇴 시까지
- Google LLC / 미국 / 이메일, 프로필 정보 / 소셜 로그인 시 네트워크를 통한 전송 / OAuth 인증 / 회원 탈퇴 시까지
- Functional Software, Inc.(Sentry) / 미국 / 오류 기록, 접속 페이지 주소, 브라우저·기기 종류, 회원 식별자 / 오류 발생 시 네트워크를 통한 자동 전송 / 오류 원인 파악 및 개선 / 수집일로부터 30일
- Plus Five Five, Inc.(Resend) / 미국(메일 발송 서버는 일본 도쿄) / 이메일 주소, 이용권 종류와 결제 예정 금액 / 안내 메일 발송 시 네트워크를 통한 전송 / 결제·갱신 안내 메일 발송 / 위탁 목적 달성 시까지
이용자는 개인정보의 국외 이전을 거부할 수 있습니다. 다만 위 이전은 서비스 제공에 필수적이므로, 거부하시는 경우 해당 기능의 이용이 제한될 수 있습니다.
※ 오류 수집 관련 안내: 서비스에 오류가 발생하면 원인을 파악하기 위해 오류 기록이 Sentry로 자동 전송됩니다. 전송 전에 이메일 주소와 전화번호는 가려지며, 이용자가 입력한 프로젝트 내용 등 본문 데이터와 접속 IP는 전송 대상에서 제외합니다. 수집된 오류 기록은 30일이 지나면 자동 삭제됩니다.
※ AI API 전송 관련 안내: 이용자가 서비스에 입력한 프로젝트 기록 및 입력 문서 텍스트는 AI 분석을 위해 Anthropic의 Claude API로 전송됩니다. Anthropic의 상용 API 정책상 입력과 출력은 모델 학습에 사용되지 않으며, 회사가 별도의 Zero Data Retention 계약을 체결하지 않은 경우 API 데이터는 원칙적으로 최대 30일 이내 삭제됩니다. 재직 중이거나 재직했던 회사의 기밀정보, 영업비밀, 특정인을 식별할 수 있는 민감한 정보는 입력하지 않으시길 권고합니다.
제4조 (개인정보의 보유 및 이용기간)
1. 회원탈퇴 시 또는 개인정보 수집·이용목적이 달성된 후에는 지체 없이 파기합니다.
2. 다만 관계 법령에 따라 보존이 필요한 경우 아래 기간 동안 보관합니다.
- 계약 또는 청약철회 등에 관한 기록: 5년 (전자상거래 등에서의 소비자보호에 관한 법률)
- 대금결제 및 재화 등의 공급에 관한 기록: 5년 (전자상거래 등에서의 소비자보호에 관한 법률)
- 소비자 불만 또는 분쟁처리에 관한 기록: 3년 (전자상거래 등에서의 소비자보호에 관한 법률)
- 약관·개인정보 처리방침 동의 기록(동의 일시·동의 문서 버전·접속 IP·기기 정보): 5년 (계약에 관한 기록에 준함)
- 공개 페이지 신고 및 처리 기록: 3년 (분쟁처리에 관한 기록에 준함)
- 웹사이트 방문기록(접속 로그): 3개월 (통신비밀보호법)
제5조 (개인정보의 파기절차 및 방법)
보유기간이 경과하거나 처리목적이 달성된 개인정보는 지체 없이 파기합니다. 전자적 파일 형태의 정보는 복구·재생이 불가능한 기술적 방법으로 삭제하며, 그 외 형태의 기록물은 분쇄 또는 소각하여 파기합니다.
제6조 (이용자 및 법정대리인의 권리와 행사방법)
이용자는 언제든지 본인의 개인정보에 대해 열람, 정정, 삭제, 처리정지를 요청할 수 있습니다. 마이페이지에서 직접 확인·수정하거나, 서비스 내 문의 채널로 요청하시면 지체 없이 조치합니다. 만 14세 미만 아동의 경우 법정대리인이 동일한 권리를 행사할 수 있습니다.
제7조 (회원탈퇴 및 동의철회)
회원은 마이페이지 또는 서비스 내 문의 채널을 통해 언제든지 회원탈퇴(동의철회)를 요청할 수 있습니다. 탈퇴 시 계정은 즉시 비활성화되며, 개인정보는 제4조에 따른 법정 보존 항목을 제외하고 즉시 파기합니다. Pins 등 서비스 이용기록은 탈퇴 즉시 삭제를 원칙으로 하되, 결제내역은 관계 법령상 보존기간(5년) 동안 별도 보관합니다.
제8조 (쿠키의 운영)
회사는 서비스 이용 편의 및 이용 통계 분석을 위해 쿠키를 사용할 수 있습니다. 이용자는 웹 브라우저 설정을 통해 쿠키 저장을 거부할 수 있으며, 이 경우 서비스 이용에 일부 제약이 있을 수 있습니다.
제9조 (개인정보의 안전성 확보 조치)
회사는 개인정보 보호를 위해 접근권한 관리, 인증(Google OAuth) 기반의 접근 통제, 관리적·기술적 보호조치를 취하고 있습니다. 다만 인터넷을 통한 데이터 전송은 100% 안전을 보장할 수 없으므로, 이용자는 본인의 계정 정보를 안전하게 관리해야 합니다.
제10조 (개인정보보호책임자)
- 개인정보 보호책임자: 전예리 (오어앤코 대표)
- 연락처: privacy@pinbo.today
개인정보 열람·정정·삭제·처리정지 요구는 위 연락처 또는 서비스 내 문의 채널로 접수하시면, 접수일로부터 10일 이내에 처리하고 결과를 알려드립니다.
제11조 (권익침해 구제방법)
개인정보 침해에 대한 신고나 상담이 필요한 경우 아래 기관에 문의할 수 있습니다.
- 개인정보침해신고센터: (국번없이) 118, privacy.kisa.or.kr
- 개인정보분쟁조정위원회: 1833-6972, kopico.go.kr
- 대검찰청 사이버범죄수사단: 02-3480-3571, spo.go.kr
- 경찰청 사이버수사국: (국번없이) 182, ecrm.police.go.kr
제12조 (고지의 의무)
이 방침을 변경하는 경우 변경 사유 및 적용일자를 명시하여 적용일자 10일 전(중요한 사항의 경우 30일 전)부터 서비스 초기화면에 공지합니다.
제13조 (언어)
이 방침은 한국어본을 정본으로 합니다. 영문본은 이용자의 편의를 위해 제공되는 번역본이며, 양자의 의미가 다른 경우 한국어본이 우선합니다.
부칙
이 방침은 2026년 8월 18일부터 시행합니다.
Effective: 18 August 2026
(This Policy is based on a commonly used form of privacy policy. This English text is a translation provided for convenience; see Article 13.)
Ore&Co (business registration number 830-03-02579, representative Jeon Yeri; the "Company") takes the protection of users' personal data seriously and complies with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc., and other applicable law. Through this Privacy Policy the Company explains for what purposes and by what means the personal data provided by users is processed, and what measures are taken to protect it.
Article 1 (Items of Personal Data Collected and Methods of Collection)
1) On sign-up (Google social login)
- Items collected: [required] email address, name and profile image (information provided by the Google account)
- Method: Google OAuth authentication (via Supabase)
- Purpose: identifying members, providing the Service and responding to enquiries
2) Information generated during use of the Service
- Project experience entered (career information) and data saved to Pins
- Text pasted in as submitted documents (job postings, requests for proposal and the like)
- Uploaded files (career statements and similar, in pdf/docx) and attached images and reference links
3) On payment
- Items collected: payment method details are, in principle, collected and stored directly by the payment gateway; the Company retains only the payment approval result (date and time, amount, plan type). The Company does not collect card numbers, expiry dates or passwords; the user enters these directly into the payment gateway's own window.
- Additional items where recurring payment is selected: the billing key issued by the payment gateway (a token used only to request payment, not a card number), and the card issuer name and last four digits for display.
- Purpose: processing plan payments, providing payment records, handling refunds, charging recurring renewals
- Retention: the billing key is destroyed without delay when the subscription is cancelled or the member withdraws, and the Company also requests its deletion at the payment gateway.
4) Information collected automatically through use of the Service
- Access IP address, cookies, service usage records (date and time of visit, device and browser information), records used to prevent abuse
5) On enquiry or consultation
- Email address, content of the enquiry
Article 2 (Purposes of Collection and Use)
1. Providing the Service: core features such as project card generation, Pins management, submitted-document analysis (Match) and Insights
2. Member management: identifying members, preventing abuse, delivering notices, confirming intent to withdraw
3. Payment and settlement: processing plan payments, providing payment records, handling refunds, retaining records required by law
4. AI analysis: transmitting project experience and submitted-document text entered by the user to an AI model (Anthropic Claude API) to generate structured analysis
Article 3 (Entrustment of Processing and Provision to Third Parties)
The Company entrusts the processing of personal data as set out below in order to provide the Service, and its entrustment contracts stipulate what is necessary under applicable law to keep personal data safe.
- Anthropic (Claude API) — entrusted work: AI structuring and analysis of text entered by the user (project experience, submitted documents) / data processed: career and submitted-document text entered by the user (payment details, passwords and the like are not transmitted)
- Supabase — entrusted work: member authentication and storage of service data / data processed: account information, Pins data
- Google — entrusted work: OAuth social login authentication / data processed: email address, profile information
- Korea PortOne Inc. (PortOne) — entrusted work: payment integration and relay of payment information / data processed: payment method details, payment approval records
- NHN KCP Corp. — entrusted work: domestic payment processing and payment approval / data processed: payment method details, payment approval records
- PayPal Pte. Ltd. — entrusted work: overseas payment processing and payment approval / data processed: payment method details, payment approval records
- Functional Software, Inc. (Sentry) — entrusted work: collection of service errors and root-cause analysis / data processed: error messages and where they occurred, the page address accessed, browser and device type, member identifier
- Plus Five Five, Inc. (Resend) — entrusted work: sending notification emails (payment confirmation, plan expiry and advance notice of auto-renewal) / data processed: email address, plan type and the amount to be charged
The Company does not provide personal data to third parties beyond the purposes above without the user's consent, except where required by law or upon a lawful request from an investigative authority.
[Cross-border Transfer of Personal Data]
All of the processors above operate servers outside Korea, so personal data is transferred abroad in the course of entrusted processing.
- Recipient / Country / Items transferred / Time and method of transfer / Purpose / Retention period
- Anthropic, PBC / United States / career and document text entered by the user / transmitted over the network when AI features are used / AI structuring and analysis / deleted within 30 days at the latest, in line with Anthropic's commercial API policy
- Supabase, Inc. / United States / account information, Pins data / transmitted over the network when the Service is used / member authentication and data storage / until withdrawal of membership
- Google LLC / United States / email address, profile information / transmitted over the network at social login / OAuth authentication / until withdrawal of membership
- Functional Software, Inc. (Sentry) / United States / error records, page address accessed, browser and device type, member identifier / transmitted automatically over the network when an error occurs / identifying and fixing the cause of errors / 30 days from collection
- Plus Five Five, Inc. (Resend) / United States (mail-sending servers in Tokyo, Japan) / email address, plan type and the amount to be charged / transmitted over the network when a notification email is sent / sending payment and renewal notification emails / until the entrusted purpose is fulfilled
Users may refuse the cross-border transfer of their personal data. However, these transfers are essential to providing the Service, so refusal may limit use of the relevant features.
※ Note on error collection: when an error occurs in the Service, an error record is sent automatically to Sentry so the cause can be identified. Email addresses and phone numbers are masked before transmission, and body text such as project content entered by the user, together with the access IP address, is excluded. Collected error records are deleted automatically after 30 days.
※ Note on transmission to the AI API: project records and submitted-document text entered into the Service are transmitted to Anthropic's Claude API for AI analysis. Under Anthropic's commercial API policy, inputs and outputs are not used to train models, and unless the Company has a separate Zero Data Retention agreement, API data is deleted within 30 days at the latest. We recommend that you do not enter confidential information, trade secrets or sensitive information identifying a specific person belonging to a current or former employer.
Article 4 (Retention and Use Period)
1. Personal data is destroyed without delay upon withdrawal of membership or once the purpose of collection and use has been achieved.
2. Where retention is required by law, however, data is kept for the following periods:
- Records on contracts or withdrawal of subscription: 5 years (Act on the Consumer Protection in Electronic Commerce, Etc.)
- Records on payment and the supply of goods: 5 years (Act on the Consumer Protection in Electronic Commerce, Etc.)
- Records on consumer complaints or dispute handling: 3 years (Act on the Consumer Protection in Electronic Commerce, Etc.)
- Records of consent to the Terms and this Privacy Policy (time of consent, document version, IP address, device information): 5 years (treated as records on contracts)
- Reports on public pages and their handling: 3 years (treated as records on dispute handling)
- Website visit records (access logs): 3 months (Protection of Communications Secrets Act)
Article 5 (Procedure and Method of Destruction)
Personal data whose retention period has passed or whose processing purpose has been achieved is destroyed without delay. Data in electronic file form is deleted by technical means that make recovery or reproduction impossible; records in other forms are shredded or incinerated.
Article 6 (Rights of Users and Legal Representatives, and How to Exercise Them)
Users may at any time request access to, correction of, deletion of, or suspension of processing of their personal data. You can check and edit it yourself on the account page, or make a request through the Service's support channel and we will act without delay. For children under 14, a legal representative may exercise the same rights.
Article 7 (Withdrawal of Membership and Withdrawal of Consent)
Members may request withdrawal of membership (withdrawal of consent) at any time through the account page or the Service's support channel. On withdrawal the account is deactivated immediately and personal data is destroyed immediately, except for items subject to statutory retention under Article 4. Service usage records such as the Pins are deleted immediately upon withdrawal as a matter of principle; payment records are kept separately for the statutory retention period (5 years).
Article 8 (Use of Cookies)
The Company may use cookies to make the Service easier to use and to analyse usage statistics. Users may refuse the storage of cookies through their web browser settings, in which case some parts of the Service may be restricted.
Article 9 (Measures to Ensure Security)
The Company applies access rights management, authentication-based access control (Google OAuth), and administrative and technical safeguards to protect personal data. However, data transmission over the internet cannot be guaranteed to be 100% secure, so users must keep their own account information safe.
Article 10 (Personal Data Protection Officer)
- Personal data protection officer: Jeon Yeri (representative of Ore&Co)
- Contact: privacy@pinbo.today
Requests to access, correct, delete or suspend the processing of personal data may be submitted to the contact above or through the Service's support channel; we will act on them and inform you of the outcome within 10 days of receipt.
Article 11 (Remedies for Infringement of Rights)
If you need to report or discuss an infringement of your personal data rights, you may contact the following bodies in Korea:
- Personal Information Infringement Report Centre: 118 (no area code), privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972, kopico.go.kr
- Supreme Prosecutors' Office Cybercrime Investigation Division: 02-3480-3571, spo.go.kr
- National Police Agency Cyber Bureau: 182 (no area code), ecrm.police.go.kr
Article 12 (Duty of Notification)
If this Policy is changed, the reasons for the change and the effective date will be posted on the initial screen of the Service from 10 days before the effective date (30 days for material changes).
Article 13 (Language)
The Korean-language version of this Policy is the authoritative text. This English version is a translation provided for the user's convenience; if the two differ in meaning, the Korean version prevails.
Addendum
This Policy takes effect on 18 August 2026.