Privacy Policy

Effective 16 September 2026

This policy describes what information UnitDeck Cloud, the hosted service at app.unitdeckstudio.com (the "Service"), handles, why, where it is kept, and what you can do about it. The Service is operated by UnitDeck Studio ("we", "us").

The marketing site at unitdeckstudio.com and the UnitDeck Local desktop app have their own privacy policy at unitdeckstudio.com/privacy. UnitDeck Local does not send planning data to the Service, and this policy does not cover it.

1. Two kinds of data, two roles

The Service holds two kinds of personal data, and our role differs for each.

Account and billing data - who has an account, who pays, how the Service is used - is collected by us for our own purposes. For that data we are the controller.

Workspace content - everything a customer's members enter: projects, tasks, work records, files, and the people, roles, departments, availability and assignments that the customer records about its own staff - is entered by the customer for the customer's purposes. For that data the customer organisation is the controller and we are its processor. We handle it only to run the Service for that customer, on its instructions, and a person whose details appear in a workspace should direct questions about them to the workspace owner first. We will help the customer answer.

2. What we collect

Account data, when an account is created for you or by you:

  • Email address, display name, and a hashed form of your password. We never store the password itself.
  • Your role in each workspace, the departments and projects you belong to, and preferences such as language, navigation favourites and appearance.

Sign-in and session data, generated when you use the Service:

  • Each sign-in attempt: the email used, the time, whether it succeeded, the IP address and browser identifier. Used to throttle repeated failures and to lock an account under attack.
  • Active sessions: a random token held in a cookie, with the IP address and browser identifier at sign-in, the last time it was used, and when it expires.

Workspace content, entered by members of your workspace:

  • Projects, tasks, checklists, comments, work records, recurring work, reminders and dependencies.
  • People and other resources: names, roles, departments, contact details if entered, availability, holidays, assignments and workload.
  • Files attached to tasks, comments and boards, and images used as resource icons.
  • The audit log: who did what to which record, and when, kept for the workspace's administrators.

Billing data, when an organisation subscribes:

  • Organisation name, plan, seat count, storage used, subscription status and period.
  • The customer and subscription identifiers Paddle assigns, and the events Paddle sends us about payments. Paddle collects your name, email, billing address, tax number where relevant and payment details for the purchase; we receive what is needed to know that a payment was made, and never your card number.
  • For organisations invoiced by contract: the invoices we issue and their payment status.

Support communications, when you write to support@unitdeckstudio.com: your email address, name, the content of your message and any files you attach. Please do not send passwords, verification codes, or workspace data unless a sanitised sample has been specifically requested.

We do not use advertising or behavioural analytics on the Service, and we do not buy data about you from anyone.

3. How we use it

  • To provide the Service: signing you in, showing you the workspaces you belong to, storing and displaying what your workspace records, computing schedules, workload and reports.
  • To keep the Service safe: throttling and locking sign-ins, expiring sessions, keeping workspaces separated, and keeping an audit log.
  • To bill: knowing which organisation has which plan, counting seats and storage against it, and matching Paddle's payment events to the organisation they belong to.
  • To support you: answering your messages and investigating problems you report.
  • To tell you things you need to know: renewal, payment failure, changes to terms or prices, security incidents. We do not send marketing email.
  • To meet legal obligations, such as keeping tax records.

4. Cookies

The Service sets two cookies of its own, both strictly necessary:

  • unitdeck-session: identifies your signed-in session. It expires after 12 hours without activity and in any case 30 days after sign-in, and is removed when you sign out.
  • A locale cookie that remembers the language you chose.

When you open the checkout from the Billing page, Paddle's checkout runs in the page and sets cookies of its own, described in Paddle's privacy policy at paddle.com/legal/privacy. No advertising, analytics or tracking cookies are set by the Service.

5. Where it is kept and who helps us keep it

The Service is run on infrastructure operated by the following providers, each of which holds data only to provide its service to us and under a contract that binds it to confidentiality and security:

  • Vercel Inc. (United States): hosts the application. Requests are served from a region in Northern Virginia, United States, and Vercel processes the standard access data of every request - IP address, time, URL, browser identifier - for security and operation of its platform.
  • Supabase Inc. (United States): hosts the PostgreSQL database that holds account data, workspace content other than files, and billing data. The database is located in the AWS us-east-1 region, Northern Virginia, United States. Supabase provides the database host and nothing else; the Service holds no Supabase API keys and uses none of its other products.
  • Cloudflare Inc. (United States): stores attached files, resource icons and workspace exports in its R2 object storage, in buckets placed in eastern North America, with a daily backup copy in a second bucket in the same region; and provides DNS and email routing for our domain. Files are served to your browser directly from storage through short-lived signed links.
  • Paddle.com Market Ltd (United Kingdom) and Paddle.com Inc. (United States): merchant of record for subscriptions. Paddle collects and holds payment and billing details, issues receipts and invoices, and tells us the outcome of each payment.

Your data is therefore stored and processed in the United States. The Service is operated from the Republic of Korea, so the people who run it access it from there. For customers in the European Economic Area or the United Kingdom this is a transfer outside those areas; where it applies we rely on the contractual safeguards those providers offer, including the standard contractual clauses approved by the European Commission. We do not promise storage in any other country. A list of the providers current at any time is available on request.

We do not sell personal data, and we share it with nobody else except where the law requires us to, or to protect the Service, our customers or the public from harm.

6. How long we keep it

  • Account data: for as long as the account exists. An account is deleted at the request of the workspace owner, or when the last workspace it belongs to is deleted.
  • Sign-in attempt records: 30 days.
  • Sessions: until they expire, at most 30 days after sign-in, and shortly afterwards the record is removed.
  • Workspace content and the audit log: for as long as the organisation's trial or subscription lasts. After it ends, the workspace is kept read-only for 90 days so that it can be exported or reactivated, and may then be deleted. A workspace owner may ask for earlier deletion, which we complete within 30 days of confirming the request.
  • Workspace exports: the archive and its links expire 7 days after they are created.
  • Files uploaded but never attached to a record: removed automatically.
  • Backups: the database is backed up daily and backups are rotated out on a schedule, so a deleted record leaves the backups within 35 days of its deletion.
  • Billing and tax records: five years, as Korean tax and electronic commerce law require, and longer only where a dispute or legal obligation makes it necessary.
  • Support correspondence: three years from the last message, so that a problem that recurs can be traced.

7. How we protect it

Connections to the Service are encrypted. Passwords are stored hashed with a slow, salted algorithm. Sign-in is throttled and accounts lock after repeated failures. Sessions expire. Every query the Service runs is scoped to the workspace of the signed-in member on the server, so that no client request can name a workspace it does not belong to; the database additionally carries row-level policies. Significant actions are written to an audit log that workspace administrators can read. Files are reachable only through signed links that expire within minutes. Data at rest is encrypted by the providers named above. Access to production systems is limited to the people who operate the Service.

If we become aware of a breach that affects your personal data we will tell the affected workspace owners without undue delay, and the authorities where the law requires.

8. Your rights

Depending on where you live, you may have the right to ask what personal data we hold about you, to have it corrected or deleted, to receive a copy of it, to restrict or object to how it is used, and to complain to a supervisory authority. In the Republic of Korea these rights arise under the Personal Information Protection Act; in the European Economic Area and the United Kingdom under the GDPR and UK GDPR.

For account and billing data, write to us at support@unitdeckstudio.com from the email address on the account. For data about you that a customer has recorded in its workspace, please contact that organisation, which decides what its workspace holds; if you do not know who that is, write to us and we will pass the request on. We respond within 30 days, and sooner where the law requires.

Workspace owners and administrators can export their whole workspace from the Service at any time without asking us.

9. Children

The Service is for organisations and their staff. It is not directed at children, and we do not knowingly hold data about anyone under 14, or under 16 where the local law sets that age. If you believe such data has reached the Service, tell us and we will remove it.

10. Changes

We will update this policy before we change what the Service collects or whom we share it with - for example before adding analytics, a new provider, or a new region. The effective date at the top shows the current version, and material changes are announced by email to workspace owners and on the Billing page.

11. Contact

  • Privacy inquiries and requests: support@unitdeckstudio.com
  • Privacy officer: Kim Heejeong
  • Controller for account and billing data: UnitDeck Studio
  • Address: 602, 148, Hyeonam-ro, Suji-gu, Yongin-si, Gyeonggi-do, 16880, Republic of Korea