iisacc logo

Docs

Privacy Policy

Scope of Personal Information Collection and Use

iisacc.com (the “Website”) offers optional passwordless account access. The only account attribute requested is an email address. The Website does not request or create a password, name, telephone number, postal address, date of birth, or public profile. Amazon Cognito stores the email address, an internal random user identifier, email-verification state, token state, and authentication security metadata on the Operator’s behalf, while Amazon Simple Email Service processes the destination address to deliver the six-digit one-time code. Cognito verifies that code and maintains the resulting session. Mere access to and viewing of the Website does not create an account; an account is created only after a user explicitly requests a code for a new email address and submits the matching code. If the Vincent direct-purchase flow is enabled, the Website separately maintains a limited transaction-entitlement record so that payment confirmation, revocation, expiry, download limits, version access, and installer integrity can be enforced. That record contains the payment provider name, provider transaction and any applicable captured-payment identifiers, transaction currency, total and post-credit grand total, a random entitlement identifier, token expiry, download-link count and timestamps, revocation state, and the applicable retention deadline. Paddle’s purchaser email is additionally stored with delivery status, bounded attempt metadata, Amazon SES message ID, and timestamps solely to send and audit the order-specific download-page link. These operational records are not analytics inputs and do not contain payment-card or payment-account credentials, billing country, address lines, city, region, or postal code.

A visitor may separately choose to preregister for WeUs by providing an email address and checking the dedicated consent box for one launch message containing the official download link. This does not create an iisacc or WeUs account. The Website stores the normalized address, consent version and timestamps, form source, request count, delivery state, bounded attempt count, claim timestamp, any Amazon SES message ID and error category, and record-retention deadlines. To limit automated registrations, the server temporarily processes the requester network address with a WeUs-specific HMAC secret in AWS Secrets Manager and stores only the resulting pseudonymous key and hourly count; the raw network address and HMAC secret are not stored in the signup record or exposed to the browser.

Analytics

The Website uses first-party, anonymous, aggregate behavioral analytics. Its purpose is to improve product presentation, navigation, sales copy, marketing material, and page performance, not to identify visitors.

Eligible public pages separately offer optional analytics and advertising measurement. Google Tag Manager remains unloaded until a visitor explicitly grants at least one category. Analytics & experience can enable Google Analytics, Microsoft Clarity, and Hotjar. Advertising measurement can enable Google Ads, TikTok Pixel, and LinkedIn Insight Tag. Meta Pixel is excluded and the Website contains no connect.facebook.net loader, fbq() call, Meta Pixel ID, Meta event, advanced matching field, or Meta Conversions API integration. Global Privacy Control or Do Not Track blocks both optional categories. The Website contains no external advertising placement or advertising iframe.

For eligible public pages, a small first-party client may report only an allowlisted route template, a fixed Website-defined call-to-action identifier, a coarse scroll-depth milestone, a coarse 8-by-6 pointer-grid count, an engagement-duration bucket, a performance bucket, a document or internal-navigation exit classification, and an aggregate count. The first-party analytics contract expressly forbids names, email addresses, telephone numbers, resident registration or other government identifiers, passport numbers, card or payment credentials, precise or coarse location, medical or health information, biometric information, dates of birth, postal addresses, account or session identifiers, cookie or storage values, IP addresses, user agents, device classes, languages, screen dimensions, full URLs, query strings, hashes, referrers, form or input values, DOM text, CSS selectors, error text, transaction or entitlement identifiers, access tokens, and free text. Unknown or additional fields are rejected. The client stores no analytics cookie or persistent browser identifier, cannot calculate unique visitors, and cannot create or join a visitor-level history. Requests use a cookie-free same-origin fetch and the analytics server route does not resolve account sessions or inspect network or browser identity fields. It measures Website surfaces, not people.

Account pages, Color Workbench at /Solutions/ColorWorkbench and color.app.iisacc.com, Vincent checkout completion at and below /Store/Vincent/Checkout, Paddle transaction links at and below /Store/Vincent/Paddle, private downloads at and below /Store/Vincent/Download, unsubscribe paths, API paths, and private paths send no browser analytics request. The Account browser sends no first-party analytics request. The server authentication flow separately increments fixed daily counters only when it receives a valid-form Continue submission and when Cognito verification succeeds; those counters contain no email, code, account, cookie, device, network, or failure-reason field and are not unique-person counts. The Website does not serialize or observe form fields, game controls, private tokens, or user-created content for analytics. AWS Amplify necessarily receives ordinary connection metadata to deliver HTTPS, but the analytics application does not read, copy, hash, persist, or join that metadata into its dataset.

The first-party AWS client does not use cookies, local storage, IndexedDB, or a visitor identifier. Browser storage used by a local-first solution for the user’s own solution data, such as a Color Workbench palette, is not used for analytics and is not transmitted to the Operator.

The optional tag path runs only on the canonical production origin, an allowlisted public route, and a URL without a query string or fragment. Its data layer contains only the canonical query-free pathname, an allowlisted route template, and the two consent states. It does not receive account, name, email, telephone, form, purchase, payment, transaction, entitlement, free-text, DOM-text, exact-location, user-provided-data, or hashed-identifier fields. The Website does not issue a purchase-conversion receipt or send a transaction ID to GTM. Advertising personalization, enhanced conversions, advanced matching, and server-side conversion APIs remain disabled.

When a visitor grants an optional category, the selected providers necessarily receive ordinary network and browser metadata when their scripts are downloaded and may set cookies under their own policies. Those provider datasets are not joined to the first-party AWS aggregate dataset. Withdrawing consent sends denial state, expires known first-party vendor-cookie names, and reloads the page when necessary. The Website always expires the _fbp and _fbc cookie names and removes an in-page fbq value without reading or transmitting it. Storage located solely on a third party’s domain remains subject to that provider’s deletion controls.

Anonymous event batches and the two fixed authentication counters for the first-party AWS path remain in an encrypted Amazon SQS buffer for no more than six hours during ordinary processing; failed batches remain in an encrypted dead-letter queue for no more than one day. AWS Lambda immediately increments fixed daily counters in Amazon DynamoDB without storing the individual event or a visitor identifier. Those counters are marked to expire after 180 days and DynamoDB then removes them asynchronously. Operational CloudWatch logs contain status and error categories only and must not contain analytics request bodies. Because SQS delivery is at least once, a rare retry may increment a counter more than once; the counters are directional Website signals, not exact people or transaction totals. Operator reports suppress exact-route and authentication values below five and do not read or join account, order, purchase, country, device, network, form, or third-party data.

Passwordless account access uses a signed, HttpOnly, SameSite Strict challenge cookie for no more than ten minutes and separate HttpOnly, SameSite Lax ID-token and refresh-token cookies. The ID token expires after one hour and the refresh token after 30 days; signing out revokes the refresh token and deletes both browser cookies. These cookies authenticate the requested account and are not available to client-side scripts. When a purchaser explicitly starts Vincent checkout, the server sets a separate random HttpOnly, SameSite checkout-security cookie for that checkout for up to seven days. Independent cookies keep purchases opened in parallel tabs distinguishable and are used only to bind each Paddle transaction to the browser that started it. A browser already presenting 12 valid active checkout cookies cannot start another checkout, although requests already in flight may finish. Successful browser reconciliation deletes the matching cookie only; webhook-first issuance leaves that cookie until browser reconciliation or expiry. The server temporarily records each state’s SHA-256 hash, Product and Price IDs, catalog currency and base amount, security timestamps, and an HMAC-pseudonymized requester network address to limit abuse and prove that the server issued the state. None of those operational fields enters analytics or advertising. Paddle.js may use checkout storage, cookies, device and network information as necessary to display and secure the payment form under Paddle’s own notices. When an order access link is opened, its fragment token is removed from the address bar. An active token is exchanged for a separate HttpOnly, SameSite Strict download-access cookie; a valid revoked, expired, or limit-reached token displays its read-only status without being stored. The active-token cookie contains the signed order token, is scoped to /Store/Vincent/Download, expires with the entitlement or after 30 days at the latest, and can be deleted with the page’s “Forget access” action. The iisacc authentication, checkout-security, and download-access cookies are not used for analytics or advertising.

Third-Party Services and Payment Processing

Where the Website offers paid solutions, Paddle acts as the merchant of record and processes payment credentials, billing details, payment authentication, tax calculation, receipts, customer credit, refunds, and chargebacks in Paddle Checkout. The Website receives a client-side completion notice for user experience only; entitlement issuance requires a completed Paddle transaction verified through Paddle’s server API or a signed transaction.completed webhook. The Vincent entitlement record deliberately persists only the Paddle transaction, any applicable captured-payment, customer, price, currency, total, post-credit grand total, and webhook-event identifiers together with the limited delivery fields described above. It does not request or persist card numbers, payment-account passwords, billing country, postal addresses, address lines, city, region, precise location, passport or government identifiers, or medical information. AWS hosts the Website and server routes and processes email-only account authentication, code delivery, Vincent purchase-link delivery, the separately requested WeUs launch/download message, and anonymous aggregate web analytics through AWS Amplify, encrypted Amazon SQS queues, AWS Lambda, Amazon DynamoDB, and Amazon CloudWatch. AWS also processes the private installer objects, checkout-state and requester-pseudonym records, entitlement records, purchaser email-delivery records, WeUs preregistration and abuse-limit records, payment-event identifiers, revocation records, and download-event timestamps on the Operator’s behalf through AWS Amplify, Amazon Aurora PostgreSQL, Amazon S3, AWS Secrets Manager, and EventBridge Scheduler. A private S3 object is disclosed only through a short-lived presigned URL after the entitlement and release checks pass. No account, purchaser, support, preregistration, payment, or delivery field is provided to the Website analytics pipeline or an advertising provider.

Information Voluntarily Provided by Users

Public reading does not require personal information. A user who chooses account access provides an email address solely for code delivery, identity verification, and session continuity. A Vincent purchaser’s Paddle email is processed separately for transactional fulfillment, access recovery, and delivery audit, not for account creation or marketing. A WeUs preregistration address is provided under its own unchecked consent and is used only for the single requested launch message and official download link; it is not reused for a newsletter, another product, account access, advertising, resale, or behavioral profiling. Account, purchaser, support, and WeUs preregistration addresses are not substituted for one another. Vincent one-to-one outreach uses separately reviewed public professional contact points only where the applicable law and channel rules permit that contact. The private operator ledger retains the contact point, public-source URL, relevance note, message state, provider evidence, and bounce or opt-out state. The suppression service stores only a SHA-256 recipient/channel key protected by an HMAC-signed unsubscribe link, channel, request source, count, and timestamps, not the address, handle, message, or research note. The Operator uses these records only to document relevant outreach, prevent duplicate messages, honor opt-outs, and suppress bounced contacts, and does not create a behavioral profile. A user may also voluntarily provide information via explicit contact channels when submitting inquiries, bug reports, or refund requests. In such cases, the Operator processes the voluntarily provided information solely for the purpose of responding to the request and resolving the issue. The Operator retains such information only for the period necessary to complete the request and, unless retention is required by applicable law, deletes or anonymizes it without undue delay after the purpose has been fulfilled. The Operator does not use account or support information for marketing, resale, behavioral profiling, or disclosure to third parties beyond those purposes.

Retention Period and Deletion of Personal Information

The Cognito email account remains until the user requests deletion or the Operator removes an inactive account under an announced retention rule. Authentication challenge sessions expire within minutes, ID tokens after one hour, and refresh tokens after 30 days. Cognito and AWS security logs may be retained for the applicable AWS service log-retention period to prevent abuse and investigate authentication failures. First-party anonymous analytics retain no user-level history: encrypted transient event buffers expire within six hours or one day for failed delivery, and fixed daily aggregate counters are marked for asynchronous deletion after 180 days. The optional-tag preference expires after no more than 180 days. Data created by a consented optional provider is subject to that provider’s published retention and deletion controls; withdrawing Website consent stops future Website loading but cannot itself delete storage located solely on the provider’s domain. Checkout-state and requester-pseudonym records carry a 30-day retention deadline whether or not payment completes. A WeUs preregistration address is retained until the WeUs launch message is sent or for 24 months after the latest consent, whichever occurs first; after the requested message is sent, the address and delivery audit are deleted within 30 days. WeUs requester HMAC rate-limit windows are deleted after 24 hours. A withdrawal request deletes the preregistration address without waiting for those deadlines. Vincent order, payment-confirmation, supply, and purchaser email-delivery records carry a five-year retention deadline from creation so the Operator can maintain transaction evidence and purchaser access within the period applicable to contract, payment, and supply records. Outbound contact and research fields are removed when they are no longer needed to audit the outreach, but bounce and opt-out suppression is retained while Vincent outreach remains possible so the same contact channel is not approached again. Complaint or dispute material may be retained for the period required to resolve the matter and for any mandatory legal period. After the applicable deadline and any legal hold end, the records are deleted or anonymized. Download-event and email-delivery records follow the parent entitlement’s lifecycle. Voluntarily provided support information is retained only as long as necessary to complete the request unless a mandatory retention obligation applies.

User Rights

Users, as data subjects, may have statutory rights under applicable data protection laws, including rights relating to access, correction, deletion, or restriction of processing. An account request should be made from the relevant verified email address so that the Operator can locate the Cognito account without disclosing another user’s information. A WeUs preregistrant may request withdrawal from the registered address through the contact method posted with the form; the address is then removed from the launch queue. A purchaser should provide the Paddle transaction or payment identifier and sufficient proof of the requester’s relationship to the transaction so that the Operator can locate the limited entitlement record. Deletion or restriction may be limited where transaction preservation, dispute handling, fraud prevention, or another mandatory legal obligation applies.

Inquiries and Handling Principles

The Operator handles privacy-related inquiries in accordance with this Privacy Policy and applicable law. Any communications regarding privacy matters shall be submitted through the contact method posted on the Website, and the Operator will respond within a reasonable period where a response is necessary. The Operator will not disclose an entitlement or transaction record unless the request can be reasonably matched to the relevant purchaser.

Legal Compliance and Policy Updates

The Operator complies with applicable data protection laws, including the Personal Information Protection Act of the Republic of Korea, to the extent relevant to the Website’s operating model. This Privacy Policy is intended to describe, in definitive terms, the scope and limits of personal information processing based on the Website’s actual operation. If laws change or the Website’s functions or processing practices change, this Privacy Policy may be amended. Any material additions, deletions, or modifications will be announced on the Website prior to taking effect within a reasonable notice period. This Privacy Policy is effective as of July 25, 2026.