Privacy Policy
This policy explains how Genu.ID (the website at https://genu.id, the “Genu.ID” mobile app, and the operator console) collects, uses, retains, deletes, and shares personal information.
Operator information
- Effective: 2026-08-13
- Operator: Green Planet Pack Co., Ltd. (초록별팩 주식회사)
- Representative: Hyeonho Kim
- Business address: 75, Malgeunnae-gil, Uiwang-si, Gyeonggi-do, Republic of Korea
- Business registration number: 182-88-00936
- Data Protection Officer: Hyeonho Kim / cs@palettecorp.kr
1. Information We Collect
We collect only what we need. Consumers can verify authenticity without creating an account or signing in; in that mode, we do not collect information that directly identifies you, such as your name or contact details. However, to prevent misuse and detect counterfeits, we store a hash of the visitor-identification cookie issued by our server together with scan records (the cookie value itself is not stored).
1-1. Guest users (no sign-in)
- Device OS / model / app version — compatibility and diagnostics (automatic)
- Service logs (scan request/response timing) — service operation (automatic)
- Location coordinates and accuracy — optional; collected only if you allow location access
- Hash of the visitor-identification cookie — fraud prevention and counterfeit detection (automatic; the cookie value itself is not stored)
- Camera image — not stored, decoded in memory only
Location is optional, and you can verify authenticity without it. Coordinates are not combined with information that directly identifies you, such as your name or contact details. They are stored together with a hash of the visitor-identification cookie issued by our server; the cookie value itself is not stored.
1-2. Signed-in users (distributors and store staff)
- Email, password (one-way hashed), store/affiliation — account identity
- Issuance, sale, store-location records — operator features
- Push notification token — only if notifications are enabled (optional)
1-3. What we do not collect
We do not collect address-book contacts, stored photos/videos, payment information, advertising identifiers (IDFA / GAID), or third-party advertising-tracking identifiers.
2. Purposes of Collection and Use
- Providing authenticity verification (QR validation, result delivery)
- Detecting and warning about suspected tampering/counterfeiting
- Service operation, incident response, and performance improvement
- For signed-in users: account authentication and operator features (issuance, sale, store-location records)
- Optional: location data, used for (1) more accurate counterfeit detection (detecting suspected tampering or counterfeiting), (2) distribution analysis (regional authentication status and distribution routes for each brand), and (3) for signed-in users of the distributor app, recording the distribution route when scanning shipments, sales, and similar steps
- Optional: sending alerts about suspicious results
We do not use collected information for any purpose beyond those above.
3. Sharing with Third Parties
We do not sell, share, or otherwise transfer your personal information to third parties. The following processors are engaged solely to operate the service:
- Cloud infrastructure provider (e.g., AWS) — server and database hosting, domestic region preferred
- Apple Push / Google FCM — notification routing, only if notifications are enabled
We may disclose information to law enforcement when required by a lawful legal request.
4. Retention and Deletion
- Guest scan logs: up to 12 months from collection, then automatic deletion
- Signed-in account information: deleted on account closure (except items required by law)
- Issuance / sale / store records: the period required by applicable law (commerce, tax)
- Location coordinates (when allowed): same as scan logs (up to 12 months)
- Push tokens: discarded on notification opt-out or app uninstall
Electronic data is deleted using non-recoverable methods; printed materials are shredded or incinerated.
5. Your Rights
You may at any time:
- Request access to your personal information
- Request correction or deletion
- Request restriction of processing
- Withdraw consent (location and notification permissions can be revoked from your OS settings)
How to request: email cs@palettecorp.kr. After identity verification, we will respond within 10 business days. We hold no information that directly identifies guest users, such as a name or contact details. Their scan records and location coordinates are deleted automatically once the retention period in Section 4 ends, and we will delete them earlier on request.
6. Cookies and Similar Technologies
The website (https://genu.id) uses:
- Essential cookies — required to deliver the service, such as maintaining a login session.
- Visit analytics — Google Tag Manager and Google Analytics 4 aggregate visit and usage records, used for statistics only and not to identify individuals.
- Referral source — to see how an inquiry reached us, referral details (search terms, ad source) are stored in browser localStorage (
genuid_attr). You can clear it at any time from your browser settings. - Visitor-identification cookie — a signed cookie issued by our server (HttpOnly, Secure, valid for 90 days). It tells repeat scans from the same device apart, which helps prevent misuse and detect counterfeits. The cookie holds only its issue time and a random value, with no personal information, and our server stores only a hash of it.
- Consent record — whether and when you agreed to the pre-scan notice is stored in browser localStorage (
genu-id-consent-v1). You can clear it at any time from your browser settings.
The mobile app stores authentication material in the device's secure store (iOS Keychain / Android Keystore).
7. Children
8. Security Measures
- Encrypted transport (TLS / HTTPS)
- One-way hashing of passwords
- Mobile credentials stored in the device secure store
- Least-privilege access control and operations log review
- Periodic vulnerability assessments
9. Changes to This Policy
10. Contact
- Privacy / general inquiries / technical support: cs@palettecorp.kr
- Mail: 75, Malgeunnae-gil, Uiwang-si, Gyeonggi-do, Republic of Korea — Green Planet Pack Co., Ltd.
Regulatory remedies (Republic of Korea)
- Personal Information Dispute Mediation Committee — 1833-6972, www.kopico.go.kr
- Korea Internet & Security Agency Privacy Center — 118, privacy.kisa.or.kr
- Supreme Prosecutors' Office Cyber Investigation — 1301
- National Police Agency Cyber Bureau — 182