nbase (엔베이스) (trade name: NBASE KOREA Co., Ltd. (엔베이스코리아 주식회사); the “Company,” “we” or “us”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act (개인정보 보호법, PIPA) in order to protect the personal information of users of the StageVPN service (“data subjects” or “members”) and to handle related complaints promptly and smoothly. This Policy applies to the StageVPN mobile apps (iOS and Android), StageVPN for Chrome, the desktop apps (Windows and macOS), the business VPN and the website (stagevpn.com).
Key Privacy Labels
Account information, subscription and payment records, device and app information, VPN usage information, connection logs required by law, customer inquiries
Communication content (the content of pages visited, messages, entered values, files), card numbers, resident registration numbers, sensitive information
Kept for 93 days under the Protection of Communications Secrets Act (통신비밀보호법), then deleted automatically. Provided only in response to lawful requests (Learn more)
None as a rule. Limited to the cases in Article 6, such as requests made under law and business customers (member management)
Servers (Vultr), payments (Stripe, Apple, Google), app notifications and error analysis (Google Firebase), text messages and email (NAVER Cloud), etc.
Chief Privacy Officer privacy@stagevpn.com
Article 1 (Purposes of Processing Personal Information)
We process personal information for the following purposes and do not use it for any other purpose. If a purpose of use changes, we will take the necessary measures, such as obtaining separate consent under Article 18 of PIPA.
- Member registration and management: confirming the intention to register, identification and authentication (email, mobile phone number, social login), account maintenance and management, prevention of fraudulent registration, and various notices and notifications
- Provision of the VPN service: configuring VPN connections (WireGuard key registration, tunnel IP assignment), server selection and connection management, proxy authentication for the Chrome extension, usage limit management, and responding to service failures
- Provision of paid services and settlement of fees: subscription payments and automatic renewal, confirming payment results, withdrawals and refunds, plan changes, handling failed payments, and billing business customers
- Compliance with legal obligations: retaining connection logs and responding to lawful requests for data under the Protection of Communications Secrets Act, and retaining transaction records under the Act on the Consumer Protection in Electronic Commerce (전자상거래법, the “E-Commerce Act”)
- Service protection and prevention of fraudulent use: checking the country of access, detecting and responding to account takeover, attack traffic and usage policy violations, and security audits
- App quality management: analyzing the causes of errors (crashes), checking app stability, and analyzing service usage statistics
- Customer support: receiving and handling inquiries and complaints, informing members of the results, and resolving disputes
- Operation of the business VPN: managing business customer contracts, inviting and managing members, and operating the admin console and its audit logs
- Sending advertising information (optional): information about events and offers. We send it only to members who have separately consented.
Article 2 (Items of Personal Information Processed and Legal Bases for Processing)
1. Personal information processed without the data subject’s consent
We process the following personal information without consent to the extent necessary for concluding and performing a contract (Article 15(1)(4) of PIPA), complying with legal obligations (Article 15(1)(2)) and pursuing our legitimate interests that clearly override the rights of the data subject (Article 15(1)(6)).
| Category | Items processed | Legal basis |
|---|---|---|
| Member registration and management (email sign-up) | Email address, password (stored as an irreversible hash), name or display name, records of sending and confirming email verification codes | Performance of contract |
| Member registration and management (mobile phone sign-up and verification) | Mobile phone number, records of sending and confirming verification codes | Performance of contract |
| Member registration and management (social login) | Member identifier from the social login provider (such as Google, Apple, Kakao, Naver or LINE), the email address and name passed on by that provider (where the member consented to their provision), and, for Sign in with Apple, the Apple authorization token used to disconnect the account when the member deletes it (stored encrypted) | Performance of contract |
| Subscriptions and payments | Plan, subscription status and period, payment channel, payment amount, currency and date and time, withdrawal and refund history, App Store transaction identifiers and identifiers for account linking, Google Play purchase tokens and order numbers, Stripe customer, subscription and payment identifiers, email address for receipts | Performance of contract; legal obligation (E-Commerce Act) |
| VPN service use (apps) | WireGuard public key, assigned tunnel IP address, servers and countries used, session start and end times, amount of data sent and received | Performance of contract |
| VPN service use (Chrome extension) | Proxy session identifier, session start and expiry times, server used, connecting IP address from which the session was started | Performance of contract |
| Connection logs (apps) | Connection start time, tunnel IP address, protocol (TCP, UDP, ICMP), destination IP address and port, source port, IP address and port from which the member connected to the VPN server | Legal obligation (Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement Decree) |
| Connection logs (Chrome extension) | Connection start time, account and session identifiers, member’s connecting IP address, destination host name and port, destination IP address, number of bytes sent and received, connection duration | Legal obligation (Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement Decree) |
| Fraud prevention and security | IP address used to access the service and the country determined from it, VPN key issuance and revocation records (email, public key, action and reason, IP address), audit logs of service setting changes, API request logs (connecting IP, app and browser information, request path, result, date and time) | Legitimate interests (service protection and prevention of fraudulent use); performance of contract |
| Device and app information | Push notification token, app version, operating system type and version, device model | Performance of contract (service notifications and compatibility checks) |
| Error analysis (Firebase Crashlytics) | Error information at the time of an app crash (stack trace), device state (memory, storage space, etc.), installation identifier, app and operating system versions | Legitimate interests (ensuring app stability) |
| Usage statistics (Firebase Analytics) | App instance identifier, basic usage events such as app launches and screen views, device and operating system information, country- or region-level location estimated from the IP address | Legitimate interests (improving service quality). We do not combine this information with members’ names or email addresses. |
| Customer inquiries | Email address, name, content of the inquiry and attachments, device and app information provided by the member, consultation and handling records | Performance of contract; legal obligation (records of handling consumer complaints and disputes) |
| Business VPN (business customers) | Company name and legal entity name, business registration number, contact person’s name, email and phone number, email address for invoices, contract information such as contract term, number of users and dedicated IPs, billing and payment records | Performance of contract |
| Business VPN (members and administrators) | Member email addresses and display names, invitation records (inviter, invitation and acceptance dates and times, status), membership status, admin console account information (email, name, permissions), admin console login and activity audit logs (actor, action, target, date and time, values before and after the change) | Performance of contract (member management under the contract with the business customer) |
| Browser sign-in (web sign-in from the apps and extension) | One-time sign-in code and app verification value (discarded once sign-in completes). We do not set our own cookies on the sign-in page (see the Cookie Policy). | Performance of contract |
2. Personal information processed with the data subject’s consent
| Category | Items processed | If consent is refused |
|---|---|---|
| Receiving advertising information (optional) | Email address, mobile phone number, push notification token, date and time of consent to receive | Your use of the service is not affected, but you will not receive information about offers. |
3. Methods of collecting personal information
- Entered or provided directly by the data subject during sign-up, login, payment and customer inquiries
- Received from social login providers (such as Google, Kakao and Naver), app marketplace operators (Apple, Google) and our payment processor (Stripe) to the extent the data subject has consented or requested
- Automatically generated and collected by the apps, the Chrome extension and servers in the course of service use (connection logs, session information, error information, etc.)
- Entered by a business customer’s administrator when inviting members
4. Information we do not process
- Communication content: the content of web pages visited, the paths and search terms of full URLs, messages, values entered in forms, and files sent or received
- Payment method information such as card numbers (processed directly by Apple, Google and Stripe)
- Unique identification information such as resident registration numbers, sensitive information, and precise device location information such as GPS
We do not process pseudonymized information. If we begin to do so, we will disclose the details in this Policy.
Article 3 (Processing and Retention Periods of Personal Information)
(1) We process and retain personal information within the retention period prescribed by law or the retention period consented to by the data subject, and destroy it without delay when the retention period ends or the purpose of processing has been achieved.
(2) The retention periods for each item are as follows.
| Item | Retention period | Basis |
|---|---|---|
| Account information | Until account deletion | Performance of contract |
| Records of contracts, withdrawal, etc. | 5 years | Article 6 of the Enforcement Decree of the E-Commerce Act |
| Records of payments and supply of goods, etc. | 5 years | Article 6 of the Enforcement Decree of the E-Commerce Act |
| Records of handling consumer complaints or disputes (customer inquiries) | 3 years | Article 6 of the Enforcement Decree of the E-Commerce Act |
| Records of labeling and advertising | 6 months | Article 6 of the Enforcement Decree of the E-Commerce Act |
| Connection logs (apps, Chrome extension) and records of connecting IPs and ports | 93 days from creation (deleted automatically) | Article 41 of the Enforcement Decree of the Protection of Communications Secrets Act (at least 3 months). Because 3 months is at most 92 days, we set the period at 93 days. |
| VPN session history (server, tunnel IP, start and end times, amount of data) | Until account deletion. However, the parts needed for matching against connection logs are kept even after account deletion until 93 days have passed from creation | Performance of contract; Protection of Communications Secrets Act |
| Chrome extension proxy session records | 93 days from creation (deleted automatically) | Article 41 of the Enforcement Decree of the Protection of Communications Secrets Act |
| VPN key issuance and revocation records | 90 days (deleted automatically) | Legitimate interests (prevention of fraudulent use) |
| Audit logs of VPN service setting changes | 180 days (deleted automatically) | Legitimate interests (security audits) |
| API request logs (server logs) | 30 days (deleted automatically) | Legitimate interests (incident response and security) |
| Notification delivery history | 30 days (deleted automatically) | Performance of contract |
| Records of received payment events (original notifications from app marketplaces and Stripe) | 90 days (deleted automatically). Payment results are kept for 5 years as part of the transaction records above | Performance of contract |
| Push notification tokens | Until account deletion or until the token expires or is renewed | Performance of contract |
| Error analysis information (Crashlytics) | 90 days from collection | Google Firebase retention policy |
| Usage statistics (Analytics) | The data retention period set in Google Analytics ([Analytics retention period]) | Legitimate interests |
| Business customer contract and billing information | 5 years after the contract ends | E-Commerce Act, Framework Act on National Taxes (국세기본법) and other relevant laws |
| Business member information | Until the member is removed or the business contract ends | Performance of contract |
| Business admin console audit logs | 3 years from creation (deleted automatically) | Performance of contract; handling of disputes |
| Records of consent to receive advertising information | Until consent is withdrawn or the account is deleted | Consent of the data subject |
(3) Even after a member deletes their account, information that paragraph (2) requires to be retained under law is stored separately from other information for the applicable period and is not used for any purpose other than those prescribed by law.
(4) In accordance with the amended PIPA that took effect on 15 September 2023, we do not operate a system that uniformly destroys or separately stores the personal information of accounts that have not used the service for a certain period (the so-called personal information validity period system). Account information is retained until the member deletes their account, and members may delete their account in the app at any time. We may send security notices to accounts that have not logged in for a long time.
Article 4 (Retention and Provision of Connection Logs)
(1) As a telecommunications business operator, we retain the connection logs described in Article 2 for 93 days under Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement Decree, in order to cooperate with requests from investigative agencies and others for communication confirmation data.
(2) Connection logs do not include the content of communications. We do not use connection logs for advertising, user profiling or sale, and use them only for the purposes stated in this Policy, such as responding to requests made under law, protecting the service and investigating fraudulent use.
(3) We provide the minimum data necessary only in response to requests that meet the requirements and procedures prescribed by law, such as a court permit. Details of the items retained and the disclosure procedure are available in the Connection Log Retention Notice.
(4) Because of the statutory retention obligation, connection logs within the retention period cannot be deleted before the period ends, even if the data subject requests deletion.
Article 5 (Procedures and Methods for Destroying Personal Information)
(1) When personal information is no longer needed, such as when the retention period ends or the purpose of processing has been achieved, we destroy it without delay.
(2) Personal information that must be preserved under law is stored by moving it to a separate database or storage space or by separating access rights.
(3) The procedures and methods of destruction are as follows.
- Destruction procedure: We select personal information for which grounds for destruction have arisen and destroy it under the supervision of the Chief Privacy Officer. Records with a fixed retention period are deleted automatically when the period expires, using the database’s automatic expiry function.
- Destruction method: Electronic files are permanently deleted in a manner that makes them impossible to recover or reproduce, and paper documents are shredded or incinerated. Information remaining in backup data is also deleted according to the backup retention cycle.
Article 6 (Provision of Personal Information to Third Parties)
(1) We process data subjects’ personal information only within the scope of the purposes in Article 1, and provide it to third parties only in cases falling under Articles 17 and 18 of PIPA, such as with the data subject’s consent or under special provisions of law.
(2) We provide personal information in the following cases.
| Recipient | Purpose of provision | Items provided | Retention period |
|---|---|---|---|
| The business customer (administrator) to which the member belongs | Managing business VPN members and checking usage | Member email, name (display name) and department, invitation and membership status, whether currently connected and time of last connection, per-session usage records for connections made in the business capacity (connection and disconnection times, duration, amount of data, name and country of the server used, and the business dedicated IP used) and their totals (the member’s source IP address, communication content such as sites visited, and information on use in a personal capacity are not provided) | The period set by the business customer, or until the business contract ends (per-session usage records can be viewed for up to 93 days after the session ends) |
| Investigative agencies and other bodies with legal authority | Responding to requests under the Protection of Communications Secrets Act, the Criminal Procedure Act (형사소송법) and other laws | Connection logs and subscriber information within the scope stated in the request | The retention period prescribed by law for the requesting agency |
(3) When a member accepts a business invitation, the information in the first row of the table in paragraph (2) is provided to that business customer, and we notify the member of this on the invitation acceptance screen.
(4) For requests for subscriber information (통신자료) under Article 83 of the Telecommunications Business Act (전기통신사업법), we review the lawfulness and necessity of the request and respond only to the minimum extent necessary.
Article 7 (Outsourcing of Personal Information Processing)
(1) To provide the service smoothly, we outsource (entrust) personal information processing tasks as follows.
| Processor | Outsourced tasks |
|---|---|
| Vultr Holdings, LLC | Operating the infrastructure for VPN servers and proxy servers for the Chrome extension (data centers in multiple countries) |
| [Database hosting provider] | Hosting the service database and cache servers |
| NAVER Cloud Corp. | Sending SMS verification codes, sending email, file storage (Object Storage) |
| Stripe, Inc. and its affiliates | Processing web payments (card payments and recurring payments) and preventing payment fraud |
| Google LLC (Firebase) | Sending app push notifications (Firebase Cloud Messaging), app error analysis (Crashlytics), app usage statistics (Analytics) |
(2) When entering into an outsourcing contract, we specify in the contract or other documents, in accordance with Article 26 of PIPA, the prohibition of processing for purposes other than performing the outsourced tasks, technical and managerial safeguards, restrictions on re-outsourcing, management and supervision of the processor, and responsibilities such as compensation for damages, and we supervise whether the processor processes personal information securely.
(3) If a processor or an outsourced task changes, we will disclose the change through this Policy without delay.
Article 8 (Overseas Transfer of Personal Information)
(1) We transfer personal information overseas as follows under Article 28-8(1)(3) of PIPA, for the outsourcing of processing and storage necessary to conclude and perform contracts with data subjects.
| Recipient (contact) | Destination country | Items transferred | Purpose of transfer | Timing and method of transfer | Retention and use period |
|---|---|---|---|---|---|
| Vultr Holdings, LLC (Privacy contact) | United States (headquarters) and the countries where the VPN servers selected by the member are located (as listed in the app’s server list) | Communications passing through VPN and proxy servers and related processing information: connecting IP and port, tunnel IP, destination IP, port and host name, amount of data transferred, WireGuard public key, proxy authentication information | Operating VPN and proxy servers | Transmitted in real time over the network when the service is used | Stored temporarily on the servers for transmission to our database in 1-minute batches, then deleted (if transmission fails, kept until it is retransmitted). Our retention periods are set out in Article 3 |
| [Database hosting provider] | [Database server country] | All member, payment and service usage information described in Article 2 | Database and cache hosting | Transmitted over the network and stored when the service is used | The retention periods in Article 3 |
| Stripe, Inc. and its affiliates (Privacy contact) | The United States and other countries where Stripe processes data | Email address, payment amount and currency, plan, Stripe customer and subscription identifiers, payment method information (entered directly into Stripe by the member) | Web payments and recurring payments, preventing payment fraud | Transmitted through the payment page and API when making a web payment | Our retention periods are set out in Article 3; Stripe retains data under its own policies and applicable laws |
| Google LLC (Privacy contact) | United States | Firebase: push notification token, app instance and installation identifiers, device, operating system and app versions, error information, app usage events / Google Play: purchase token and order number / Google Sign-In: login token | Push notifications, error analysis, usage statistics, Google Play payment verification and subscription status checks, Google Sign-In verification | Transmitted through SDKs and APIs when using the app, making payments or logging in | The retention periods in Article 3 (e.g., 90 days for error information); tokens until they expire |
| Apple Inc. (Privacy contact) | United States | App Store transaction identifiers, identifier for account linking (random UUID), subscription status | App Store payment verification, checking subscription status and refunds | Transmitted through APIs at payment and renewal and when receiving status notifications from Apple | Our retention periods are set out in Article 3 |
| Supplementary IP country lookup services: ipwho.is, GeoJS, IPinfo, country.is | [Country of IP lookup services] | Connecting IP address | Determining the country of access. Used only when the country cannot be determined with the IP database on our servers | One IP address sent via an HTTPS API when a lookup is needed | Purpose achieved immediately upon lookup. Subject to each provider’s policies |
(2) Because overseas transfer is essential to providing the service, including operating VPN servers and processing payments, a data subject who does not want their personal information transferred overseas may stop using the service and delete their account. In that case, the service cannot be used. Questions about refusing the transfer can be directed to the Chief Privacy Officer listed in Article 14.
(3) To protect personal information transferred overseas, we take the safeguards prescribed by PIPA, such as encryption in transit, access control and protective measures under our contracts with processors.
Article 9 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)
(1) Data subjects may at any time request access to, correction or deletion of their personal information, suspension of its processing, or withdrawal of consent, and may request the transmission of their personal information where the requirements set out in relevant laws are met.
(2) Rights may be exercised by the following methods. We will act without delay (within 10 days for access requests) and inform you of the result.
- Account screen in the app: viewing and editing member information, withdrawing consent to receive advertising information, deleting your account
- Email: privacy@stagevpn.com or the customer center at support@stagevpn.com
- In writing or by phone: the Chief Privacy Officer or the responsible department listed in Article 14
(3) Rights may also be exercised through a legal representative or a person authorized by the data subject. In this case, a power of attorney in the form set out in the Notice on Personal Information Processing Methods (개인정보 처리 방법에 관한 고시) must be submitted.
(4) We verify that the person making a request is the data subject or a legitimate representative, and may ask for verification through the registered email address or mobile phone number for this purpose.
(5) Deletion of information that other laws require to be retained (such as the transaction records and connection logs in Article 3) cannot be requested before the retention period ends, and access and suspension of processing may be restricted under Article 35(4) and Article 37(2) of PIPA. In such cases, we will inform you of the reasons.
(6) Data subjects must not infringe their own or others’ personal information or provide false information.
Article 10 (Automated Decisions)
We do not currently make decisions, as referred to in Article 37-2 of PIPA, that significantly affect the rights or obligations of data subjects using fully automated systems. Suspension of use because a subscription period has expired or a payment has failed is simply the application of contract terms the member has agreed to. If we begin making automated decisions in the future, we will disclose the criteria, the procedures and how personal information is processed in this Policy, and explain how data subjects can refuse such decisions or request an explanation.
Article 11 (Measures to Ensure the Safety of Personal Information)
We take the following measures in accordance with Article 29 of PIPA and the Standards for Ensuring the Safety of Personal Information (개인정보의 안전성 확보조치 기준).
- Administrative measures: establishing and implementing an internal management plan, minimizing the number of personal information handlers and training them regularly, and managing and supervising processors
- Technical measures: granting and managing differentiated access rights to personal information processing systems, access control and retention and review of access logs (for at least the period prescribed by relevant laws), encryption in transit (TLS), one-way encrypted storage of passwords, encrypted storage of app authentication tokens in the device’s secure storage, security updates and vulnerability checks
- Physical measures: using the physical security systems, such as access control, of the hosting providers that operate the data centers
Article 13 (Personal Information of Children Under 14)
We do not accept sign-ups from children under the age of 14 and do not knowingly collect children’s personal information. If we learn that the personal information of a child under 14 has been collected, we will terminate the account and destroy the personal information without delay. Legal representatives should notify us through the contacts in Article 14.
Article 14 (Chief Privacy Officer and Complaint Handling Department)
(1) We designate the Chief Privacy Officer as follows to oversee our processing of personal information and to handle data subjects’ complaints and remedies for damage.
| Category | Details |
|---|---|
| Chief Privacy Officer | Name: [Chief Privacy Officer name] · Title: [Chief Privacy Officer title] · Phone: [Chief Privacy Officer phone] · Email: privacy@stagevpn.com |
| Privacy department (receiving and handling access requests) | [Privacy team] · Customer center: [Customer center phone] ([Customer center hours]) · Email: support@stagevpn.com |
(2) Data subjects may direct any privacy-related inquiries, complaints, requests for remedies, access requests and the like arising from their use of the service to the contacts above, and we will respond and handle them without delay.
Article 15 (Remedies for Infringement of Rights)
To obtain remedies for infringement of their personal information, data subjects may apply for dispute resolution or consultation to the agencies below. These agencies are independent of the Company. Please contact them if you are not satisfied with the result of our own handling or need more detailed help.
| Agency | Phone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | (no area code) 1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center (KISA) | (no area code) 118 | privacy.kisa.or.kr |
| Supreme Prosecutors’ Office | (no area code) 1301 | www.spo.go.kr |
| Korean National Police Agency | (no area code) 182 | ecrm.police.go.kr |
Article 16 (Changes to This Privacy Policy)
(1) This Privacy Policy applies from 1 October 2026.
(2) If we change this Policy, we will post the changes and their effective date on the website and in the app at least 7 days before they take effect. For changes that are material to data subjects’ rights, such as adding items collected, changing the purposes of processing or providing information to third parties, we will post notice at least 30 days before they take effect and obtain consent again where necessary.
(3) The content and effective periods of previous versions of this Policy are available in the revision history below.
Revision history
| Version | Published | Effective | Summary of changes |
|---|---|---|---|
| 1.0 | 29 September 2026 | 1 October 2026 | Initial version |
Questions about this document
Send questions about our terms and policies, or requests to exercise your rights, to the contacts below. We respond without undue delay.
- Customer center: [Customer center phone] ([Customer center hours])
- Email: support@stagevpn.com
- Chief Privacy Officer: privacy@stagevpn.com