ImReport 개인정보처리방침
(주)샐러드랩(이하 "회사")은 ImReport(이하 "서비스") 이용자의 개인정보를 중요시하며, 「개인정보 보호법」, 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 및 Google API Services User Data Policy를 포함한 관계 법령·정책에 따라 이용자의 개인정보가 보호되도록 최선의 노력을 다하고 있습니다.
1. 수집하는 정보
회사는 서비스 제공에 필요한 최소한의 정보를 수집하며, 항목은 다음과 같습니다.
- Google 계정 이메일 주소 (로그인 식별)
- Google 스프레드시트 내용 (사용자가 ImReport를 설치한 시트에 한함)
- 광고 플랫폼 API 인증 정보 (네이버 검색광고, 카카오 모멘트, 메타 광고, 구글 광고, GA4 — 사용자가 직접 입력)
- 서비스 이용 기록 (수집 실행 이력, 플랜·이용 통계)
- 결제 정보 (유료 플랜 결제 시 — 빌링키·카드번호 뒤 4자리·결제 이력(금액·일시·결제주기). 전체 카드번호 등 상세 카드정보는 결제대행사가 보관하며 회사는 보유하지 않습니다)
- 도입 상담 문의 정보 (회사명·이메일·연락처·문의 내용 — imreport.io 문의 폼 제출 시)
- 마케팅 정보 수신 동의 여부 및 동의 일시
회사는 사상·신념, 건강, 정치적 성향 등 인권을 침해할 우려가 있는 민감정보 및 고유식별정보(주민등록번호 등)를 수집하지 않습니다.
2. 정보 사용 목적
- 광고 데이터 수집 및 스프레드시트 자동 업데이트
- 자동 갱신 스케줄 실행 (매시간 또는 하루 1회)
- 사용자 식별 및 라이선스·플랜 관리
- 서비스 장애 대응 및 고객 지원
- 도입 상담 문의 접수 및 응대
- 서비스 개선을 위한 이용 통계 분석 (식별 불가 형태)
- 마케팅 정보 수신에 동의한 이용자에 한해, 회원가입·도입 문의 등 전환 행동에 따른 제품 소식·기능 업데이트·도입 혜택 등 광고성 안내 메일 발송 (수신 동의는 선택 사항이며, 동의 후에도 메일 내 수신거부 링크 또는 imreport@saladlab.co 로 언제든 철회 가능)
3. 정보 저장 위치 및 보유기간
- Google Cloud Firestore (asia-northeast3, 서울 리전) — 설정·구독·진행상태
- Google Cloud Storage (asia-northeast3, 서울 리전) — 광고 실적 캐시(JSON)
- 결제 정보 — 빌링키·카드 뒤 4자리·결제 이력은 Firestore(서울 리전)에, 상세 카드정보는 결제대행사(아임포트·나이스페이먼츠)에 저장됩니다.
- 모든 사용자 데이터는 `userId + spreadsheetId + mediaId` 3차원으로 격리 저장됩니다.
| 항목 | 보유 기간 |
|---|---|
| 회원 정보 | 회원 탈퇴 시까지. 탈퇴 요청 후 30일 내 파기 |
| 광고 실적 캐시 | 광고계정 연동 해제 시 함께 삭제, 그 외에는 서비스 제공 기간 동안 보관 |
| 결제·거래 기록 | 「전자상거래 등에서의 소비자보호에 관한 법률」에 따라 5년 보관 후 파기 (회원 탈퇴 시에도 식별정보를 익명화한 뒤 법정 기간 동안 보관) |
| 도입 상담 문의 정보 | 응대 완료 후 1년 보관, 이후 파기 (또는 이용자 삭제 요청 시 즉시) |
파기 절차·방법: 보유기간이 경과하거나 처리 목적이 달성된 개인정보는 지체 없이 파기합니다. 전자적 파일 형태의 정보는 복구·재생이 불가능한 방법으로 영구 삭제하며, 출력물 등은 분쇄 또는 소각합니다.
4. 제3자 제공 및 처리 위탁
ImReport는 사용자 데이터를 제3자에게 판매, 공유, 임대하지 않습니다.사용자가 등록한 광고 플랫폼 API 호출은 해당 플랫폼에 접근하는 목적으로만 이루어지며, 이는 사용자가 명시적으로 승인한 데이터 수집 동작에 한정됩니다.
서비스 운영을 위해 아래 기관에 일부 처리 업무를 위탁합니다. 위탁 시 관계 법령에 따라 개인정보 보호 의무를 계약에 명시합니다.
| 수탁자 | 위탁 업무 |
|---|---|
| Google LLC (Google Cloud Platform) | 서비스 인프라(Cloud Functions, Firestore, Cloud Storage) 운영 — 서울 리전(asia-northeast3) |
| 아임포트(PortOne) | 유료 플랜 결제 처리 및 정기결제 연동 (결제대행) |
| 나이스페이먼츠(주) | 유료 플랜 신용카드 결제 처리 및 카드정보 보관 (결제대행) |
5. 국외 이전 및 분석 도구
회사는 imreport.io 웹사이트 운영·개선을 위해 아래 분석 도구를 사용하며, 이 과정에서 일부 비식별 정보가 국외로 이전될 수 있습니다. 서비스의 광고 데이터·인증 정보는 서울 리전에 저장되며 본 항목의 국외 이전 대상이 아닙니다.
| 이전받는 자 | 국가 | 이전 항목 · 목적 |
|---|---|---|
| Google LLC (GA4 · Google Tag Manager) | 미국 | 쿠키·기기/브라우저 정보·페이지 이용 기록 (비식별) · 웹사이트 이용 통계 분석 |
| Microsoft Corporation (Clarity) | 미국 | 쿠키·세션 이용 기록 (비식별) · 웹사이트 사용성 분석 |
이용자는 브라우저 쿠키 차단 또는 Google Analytics 차단 부가기능으로 위 수집을 거부할 수 있습니다.
6. Google API Services User Data Policy 준수
ImReport's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
ImReport가 요청하는 Google API 스코프의 용도는 아래와 같으며, 이 외의 목적으로 데이터를 사용하지 않습니다.
| Scope | 사용 목적 |
|---|---|
userinfo.email | 사용자 이메일 식별 (로그인·라이선스) |
spreadsheets | ImReport 설치된 시트에 수집 데이터 쓰기 및 캐시 읽기 |
script.external_request | 자사 Cloud Functions 백엔드 호출(데이터 수집·진행 상태 폴링) |
script.container.ui | Google Sheets™ 사이드바 UI 표시 |
auth/adwords | 사용자 본인의 Google Ads 광고 계정·캠페인·지표 read-only 조회 (별도 OAuth 동의로 연결, 광고 생성·수정·삭제 없음) |
auth/analytics.readonly | 사용자 본인의 GA4 속성·지표 read-only 조회 (별도 OAuth 동의로 연결) |
회사는 Google API를 통해 수신한 정보를 다음 목적으로만 사용하며, AI/ML 모델 학습, 광고 타겟팅, 제3자 데이터 브로커에의 이전 등 Limited Use가 금지하는 용도로 사용하지 않습니다.
7. 데이터 삭제 요청
이용자는 「개인정보보호법」 제36조에 따라 언제든지 본인의 개인정보 및 서비스 내 데이터의 정정·삭제를 요구할 수 있습니다. 회사는 요구 접수 후 지체 없이 (영업일 기준 10일 이내)처리하고 완료 시 이메일로 안내드립니다.
- 광고계정 연동 해제: Google Sheets 사이드바에서 해당 광고계정 삭제 (그 계정의 데이터·캐시 즉시 삭제)
- 회원 탈퇴: imreport.io 내 계정 페이지의 "회원 탈퇴" (회원 정보·인증 토큰·전체 데이터 삭제 — 단, 「전자상거래법」 등 법령상 보관 의무가 있는 결제·거래 기록은 익명화 후 해당 기간 동안 보관)
- 이메일 요청: imreport@saladlab.co
- 자세한 절차: 데이터 삭제 안내 페이지
8. 광고 플랫폼 OAuth 토큰 — 보관 위치 및 삭제 처리
회사는 Meta / Kakao Moment / Google Ads / GA4 자동 갱신을 위해 사용자가 부여한 OAuth 인증 토큰을 회사 측 Google Cloud Firestore (서울 리전) 에 단일 저장합니다. 서버측 Cloud Functions 가 모든 매체 API 호출 시 Firestore 의 토큰만 사용하므로, 이용자 삭제 요청 접수 시 회사 측에서 즉시 완전 삭제 가능합니다 (단일 통제 지점).
| 매체 | 저장 위치 | 접근 통제 |
|---|---|---|
| Naver Search Ads | Firestore (`naverSa/{userId}/sheets/{ssId}/accounts/{customerId}`) | 회사 IAM 단일 통제 |
| Meta Ads | Firestore (`metaAds/{userId}/sheets/{ssId}/accounts/{accountId}.metaToken`) | 회사 IAM 단일 통제 |
| Kakao Moment | Firestore (`kakaoMoment/{userId}/sheets/{ssId}/accounts/{accountId}.businessToken`) | 회사 IAM 단일 통제 |
| Google Ads | Firestore (`googleAds/{userId}/credentials/oauth.refreshToken`) | 회사 IAM 단일 통제 |
| GA4 | Firestore (`ga4/{userId}/credentials/oauth.refreshToken`) | 회사 IAM 단일 통제 |
| Naver Trends | (앱 단위 환경변수 — 사용자별 OAuth 없음) | 해당 없음 |
삭제 처리 흐름
- 이용자 삭제 요청 접수 (imreport.io 내 계정 페이지 "회원 탈퇴", Google Sheets 사이드바 광고계정 삭제, 또는 이메일 imreport@saladlab.co)
- 회사 측 Firestore 에 보관 중인 해당 OAuth 토큰 및 사용자 데이터 삭제 — 삭제 즉시 회사의 매체 API 호출이 중단됩니다
- 광고 플랫폼 계정 자체에 부여된 접근 권한은 이용자가 각 플랫폼의 보안 설정에서 직접 해제할 수 있습니다 (Google 계정 권한 관리, Meta 비즈니스 통합 설정, Kakao 계정 연결 관리)
- 삭제 완료 후 이메일로 통지
9. 이용자(정보주체)의 권리
이용자는 「개인정보보호법」 제35조~제37조에 따라 언제든지 본인 개인정보에 대하여 다음 권리를 행사할 수 있습니다.
- 열람 요구 — 수집된 본인 개인정보의 항목·이용 내역 조회
- 정정·삭제 요구 — 오류 정정 또는 삭제
- 처리정지 요구 — 개인정보 처리의 정지
- 동의 철회 — 마케팅 수신 등 선택 동의의 철회
권리 행사는 imreport@saladlab.co, imreport.io 내 계정 페이지의 "회원 탈퇴", 또는 Google Sheets 사이드바의 광고계정 삭제를 통해 가능하며, 회사는 요구 접수 후 지체 없이(영업일 기준 10일 이내) 처리합니다. 이용자는 개인정보 수집·이용 동의를 거부할 권리가 있으며, 다만 서비스 제공에 필수적인 정보의 동의를 거부하는 경우 서비스 이용이 제한될 수 있습니다.
10. 보안
- 모든 통신은 HTTPS (TLS 1.2 이상)로 암호화
- 사용자별 데이터 격리 — `userId + spreadsheetId + mediaId` 3차원 키 기반
- Google Cloud IAM 기반 접근 제어 (최소 권한 원칙)
- 광고 플랫폼 인증 토큰은 Google Cloud Firestore 에 저장되며, Google Cloud 의 기본 저장 데이터 암호화(encryption at rest)가 적용됩니다 (제8조 보관 위치 참조)
- 주요 변경 이력 감사 로그 상시 기록 (Audit Log)
- 관리자 계정의 고위험 작업은 TOTP 기반 다중 인증(MFA)으로 보호
- 개인정보 취급 담당자 최소화 및 접근 권한 차등 부여
11. 쿠키의 운영
ImReport 서비스(Google Sheets™ Add-on)와 imreport.io 웹사이트는 자체적으로 쿠키를 통해 이용자 정보를 수집하지 않습니다. 웹사이트 로그인 상태는 쿠키가 아닌 브라우저 로컬 저장소(localStorage)를 사용하여 유지됩니다.
다만 imreport.io 웹사이트에 적용된 웹 분석 도구(Google Analytics 4, Microsoft Clarity)가 통계 분석을 위해 쿠키를 사용할 수 있습니다. 해당 쿠키의 수집 항목·목적 및 거부 방법은 제5조(국외 이전 및 분석 도구)를 참조하세요. 이용자는 브라우저 설정에서 쿠키 저장을 거부할 수 있습니다.
12. 만 14세 미만 아동의 개인정보
ImReport는 광고·마케팅 실무자를 위한 B2B 도구로, 만 14세 미만 아동을 대상으로 하지 않으며 아동의 개인정보를 의도적으로 수집하지 않습니다. 만 14세 미만 아동의 정보가 수집된 사실을 인지하는 경우 회사는 지체 없이 해당 정보를 파기합니다.
13. 개인정보 침해 신고·상담
개인정보 침해에 대한 신고나 상담이 필요한 경우 아래 기관에 문의할 수 있습니다.
- 개인정보침해신고센터 (한국인터넷진흥원 KISA) — 국번없이 118, privacy.kisa.or.kr
- 개인정보분쟁조정위원회 — 1833-6972, kopico.go.kr
- 대검찰청 사이버수사과 — 1301, spo.go.kr
- 경찰청 사이버범죄 신고시스템(ECRM) — 182, ecrm.police.go.kr
14. 개인정보 보호책임자 및 연락처
개인정보 보호책임자: (주)샐러드랩 (StudioMX 브랜드)
이메일: imreport@saladlab.co
주소: 서울특별시 강남구 테헤란로 78길 14-11, 6층 · 8층
사업자등록번호: 249-88-00700
15. 개인정보 처리방침의 변경
본 처리방침이 변경될 경우 변경 사항은 시행 7일 전부터 서비스 내 공지사항을 통해 안내합니다. 이용자에게 불리한 변경의 경우 시행 30일 전부터 공지합니다. 본 방침은 2026년 5월 20일부터 시행되며, 종전 방침(2026-04-22)은 본 방침으로 대체됩니다.
ImReport Privacy Policy
Saladlab Inc. ("the Company") values the privacy of users of ImReport ("the Service") and strives to protect user information in accordance with applicable laws — including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection — and the Google API Services User Data Policy.
1. Information We Collect
The Company collects the minimum information necessary to provide the Service:
- Google account email address (for login identification)
- Contents of the Google Spreadsheet in which ImReport is installed
- Advertising platform API credentials (Naver Search Ads, Kakao Moment, Meta Ads, Google Ads, GA4 — entered directly by the user)
- Service usage records (collection execution history, plan and usage statistics)
- Payment information (for paid-plan billing — billing key, last 4 digits of the card number, and payment history (amount, date, billing cycle). Full card details are held by the payment gateways, not by the Company)
- Sales inquiry information (company name, email, contact, message — when submitting the imreport.io contact form)
- Marketing communication consent status and consent timestamp
The Company does not collect sensitive information (ideology, health, political views, etc.) or unique identifiers (such as resident registration numbers).
2. How We Use Information
- Collecting advertising data and writing results into the user's spreadsheet
- Executing scheduled automatic refreshes (hourly or daily)
- User identification and license/plan management
- Troubleshooting and customer support
- Receiving and responding to sales inquiries
- Aggregate usage analytics in non-identifiable form for service improvement
- For users who have opted in to marketing communications, sending promotional emails — such as product news, feature updates, and onboarding offers — following conversion actions such as sign-up or inquiry. Marketing consent is optional, and may be withdrawn at any time via the unsubscribe link in each email or by contacting imreport@saladlab.co.
3. Storage Location and Retention
- Google Cloud Firestore (asia-northeast3, Seoul region) — configuration, subscriptions, progress state
- Google Cloud Storage (asia-northeast3, Seoul region) — raw advertising data cache (JSON)
- Payment information — the billing key, last 4 card digits, and payment history are stored in Firestore (Seoul region); full card details are stored by the payment gateways (PortOne, NICE Payments).
- All user data is isolated by a three-dimensional key:
userId + spreadsheetId + mediaId.
| Data | Retention Period |
|---|---|
| Account information | Until account deletion. Purged within 30 days of request. |
| Advertising performance cache | Deleted when the corresponding advertising account is disconnected; otherwise retained for the duration of service provision |
| Payment and transaction records | Retained for 5 years then destroyed, as required by the Act on Consumer Protection in Electronic Commerce (kept in anonymized form for the statutory period even after account withdrawal) |
| Sales inquiry information | 1 year after response is completed, then purged (or immediately upon user deletion request) |
Destruction procedure: Personal information whose retention period has expired or whose processing purpose has been achieved is destroyed without delay. Electronic files are permanently erased by irrecoverable means; printed materials are shredded or incinerated.
4. Third-Party Sharing and Processing Entrustment
ImReport does not sell, share, or lease user data to any third party. Calls to the advertising platform APIs registered by the user are made solely for the purpose of data collection explicitly authorized by that user.
For service operation, the Company entrusts specific processing tasks to the following processors, with data protection obligations stipulated in the contract:
| Processor | Entrusted Task |
|---|---|
| Google LLC (Google Cloud Platform) | Service infrastructure (Cloud Functions, Firestore, Cloud Storage) — Seoul region (asia-northeast3) |
| PortOne (iamport) | Paid-plan payment processing and recurring-billing integration (payment gateway) |
| NICE Payments Co., Ltd. | Paid-plan credit-card payment processing and card-data storage (payment gateway) |
5. Cross-Border Transfer and Analytics Tools
For operating and improving the imreport.io website, the Company uses the analytics tools below; certain non-identifiable information may be transferred overseas in this process. The Service's advertising data and credentials are stored in the Seoul region and are not subject to the cross-border transfer described here.
| Recipient | Country | Items · Purpose |
|---|---|---|
| Google LLC (GA4 · Google Tag Manager) | USA | Cookies, device/browser info, page usage records (non-identifiable) · website usage analytics |
| Microsoft Corporation (Clarity) | USA | Cookies, session usage records (non-identifiable) · website usability analytics |
Users may opt out by blocking browser cookies or installing the Google Analytics Opt-out Add-on.
6. Compliance with Google API Services User Data Policy
ImReport's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.
The purpose of each Google API scope requested by ImReport is described below. The Company does not use this data for any purpose other than those stated.
| Scope | Purpose |
|---|---|
userinfo.email | User identification for login and licensing |
spreadsheets | Writing collected data and reading cache within the installed spreadsheet |
script.external_request | Calling our own Cloud Functions backend for data collection and progress polling |
script.container.ui | Rendering the ImReport sidebar UI within Google Sheets™ |
auth/adwords | Read-only access to the user's own Google Ads accounts, campaigns, and performance metrics (granted via a separate OAuth consent; no creation, editing, or deletion of ads) |
auth/analytics.readonly | Read-only access to the user's own GA4 properties and metrics (granted via a separate OAuth consent) |
Data received via Google APIs is never used for AI/ML model training, advertising targeting, or transfer to third-party data brokers, in accordance with Limited Use requirements.
7. Data Deletion Requests
Users may request deletion of their personal information and service data at any time. Requests are processed without delay (within 10 business days), and users are notified by email upon completion.
- Advertising account disconnection: remove the account in the Google Sheets sidebar (that account's data and cache are deleted immediately)
- Account withdrawal: the "Withdraw" option on the imreport.io My Account page (deletes account info, credentials, and all data — except payment and transaction records subject to statutory retention obligations, which are kept in anonymized form for the required period)
- Email: imreport@saladlab.co
- Detailed procedure: Data Deletion Guide
8. Advertising Platform OAuth Tokens — Storage and Deletion
For automatic refresh of Meta / Kakao Moment / Google Ads / GA4, the Company stores OAuth tokens granted by the user in a single location — the Company's Google Cloud Firestore (Seoul region). Server-side Cloud Functions use only these Firestore tokens for all platform API calls, so deletion requests are fully honored at a single control point.
Deletion flow
- User submits a deletion request (the "Withdraw" option on the imreport.io account page, advertising-account removal in the Google Sheets sidebar, or email to imreport@saladlab.co)
- The relevant OAuth tokens and user data held in the Company's Firestore are deleted — the Company's platform API calls stop the moment deletion occurs
- Any access permission remaining on the advertising platform account can be revoked by the user directly in each platform's security settings (Google account permissions, Meta Business Integrations, Kakao connected-app management)
- Completion is notified by email
9. Rights of the Data Subject
Under Articles 35–37 of the Korean Personal Information Protection Act, users may exercise the following rights regarding their personal information at any time:
- Access — review the items and usage history of their personal information
- Correction / Deletion — correct errors or request deletion
- Suspension of processing
- Withdrawal of consent — for optional consents such as marketing communications
Rights may be exercised via imreport@saladlab.co, the "Withdraw" option on the imreport.io account page, or advertising-account removal in the Google Sheets sidebar; the Company processes requests without delay (within 10 business days). Users may refuse consent to the collection and use of personal information, though use of the Service may be limited if consent to information essential for service provision is refused.
10. Security
- All traffic encrypted via HTTPS (TLS 1.2+)
- Per-user data isolation by
userId + spreadsheetId + mediaId - Google Cloud IAM with least-privilege access control
- Advertising platform tokens stored in Firestore with Google Cloud's default encryption at rest
- Audit Log of key state changes
- High-risk administrator operations protected by TOTP-based MFA
- Personnel handling personal information minimized, with tiered access permissions
11. Cookies
The ImReport Service (Google Sheets™ Add-on) and the imreport.io website do not collect user information through cookies of their own. Website login state is maintained using the browser's local storage (localStorage), not cookies.
However, the web analytics tools applied to the imreport.io website (Google Analytics 4, Microsoft Clarity) may use cookies for statistical analysis. The items, purpose, and opt-out methods for such cookies are described in Section 5 (Cross-Border Transfer and Analytics Tools). Users may also disable cookie storage via browser settings.
12. Children's Personal Information (Under Age 14)
ImReport is a B2B tool for advertising and marketing professionals. It is not directed to children under the age of 14 and does not knowingly collect their personal information. If the Company becomes aware that information of a child under 14 has been collected, it destroys such information without delay.
13. Reporting Privacy Infringements
For reports or consultation regarding privacy infringement, users may contact the following authorities (Republic of Korea):
- Personal Information Infringement Report Center (KISA) — 118, privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee — 1833-6972, kopico.go.kr
- Supreme Prosecutors' Office Cyber Investigation Dept. — 1301, spo.go.kr
- National Police Agency Cybercrime Report System (ECRM) — 182, ecrm.police.go.kr
14. Data Protection Officer and Contact
Data Protection Officer: Saladlab Inc. (operator of the StudioMX brand)
Email: imreport@saladlab.co
Address: 6F·8F, 14-11 Teheran-ro 78-gil, Gangnam-gu, Seoul, Republic of Korea
Business Registration: 249-88-00700
15. Changes to This Policy
Changes to this privacy policy will be announced in-product at least 7 days prior to the effective date, or 30 days prior if the change is materially adverse to users. This policy is effective from May 20, 2026, and supersedes the prior policy (effective 2026-04-22).
Google Sheets™, Google Ads™, and Google Analytics™ are trademarks of Google LLC.
ImReport is an independent product and is not endorsed by or affiliated with Google LLC.