devrives (hereinafter referred to as "the Company") complies with relevant laws and regulations, including the Personal Information Protection Act (PIPA, South Korea), the General Data Protection Regulation (GDPR, EU), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA, USA), to protect the freedom and rights of data subjects. This Privacy Policy applies to all users worldwide who use the newsletter service, website, and product landing pages (including Waitlist) provided by the Company, including devrives.com and its subdomain sites such as tickmark.devrives.com (Tickmark watch faces).
Apps distributed through Google Play and similar stores (such as Safe-Life and the watch faces) are also covered by each product's own privacy policy.
Data Controller Information
- Company Name: devrives
- Privacy Contact: [email protected]
- The Company acts as the Data Controller and is responsible for the processing of your personal information.
Article 1: Purpose of Processing Personal Information and Legal Basis
The Company processes personal information for the following purposes with specific legal bases. Personal information being processed will not be used for purposes other than those listed below, and if the purpose of use changes, necessary measures such as obtaining separate consent will be implemented in accordance with relevant laws.
1. Service Provision and Contract Fulfillment
- Newsletter delivery and subscription management (necessary for contract performance)
- Server hosting, traffic management, and system security maintenance (necessary for contract performance)
2. New Product Notifications and Waitlist Management
- Managing pre-launch Waitlist registrations
- Notifying launch announcements and providing early access information
3. Marketing and Advertising
- (With explicit consent) Development of new services/products and provision of customized services
- Providing event and promotional information and participation opportunities
4. Analytics and Service Improvement
- Website and landing page visit statistics analysis via Google Analytics
- Service quality improvement and user experience optimization
Article 2: Personal Information Collected and Collection Methods
The Company collects the minimum amount of personal information necessary to provide services. To comply with GDPR's purpose limitation principle and PIPA's requirement to specify collection sources, we provide detailed information below.
Detailed Personal Information Collection
| Collection Point | Items Collected | Collection & Use Purpose | Retention Period |
|---|---|---|---|
| When signing up for product waitlist on landing pages | Email address | Sending launch notifications and providing product-related information | 2 years from the last newsletter sent, or until consent withdrawal, whichever is earlier |
| When subscribing to newsletter | Email address | Delivering the newsletter and, with optional consent, marketing information | 2 years from the last newsletter sent, or until unsubscription, whichever is earlier |
| Automatically collected during website use | IP address, Cookies, Device information including operating system and browser version | Analyzing service usage patterns and preventing illegal or fraudulent activities | Configured to 14 months according to Google Analytics settings, or until account deletion |
Collection Items
- Required: Email address
- Automatically Collected: Cookies, access IP information, service usage records, device information including OS type, browser version, and device model - for security and analytics purposes
Collection Methods
- Newsletter subscription form on homepage
- Waitlist registration form on product landing pages
- Automatic collection through web analytics tools and cookies
Article 3: Retention and Usage Period of Personal Information
The Company retains and uses personal information within the period of retention and use in accordance with laws or the period consented by the data subject at the time of collection. We follow CCPA/CPRA requirements to specify clear retention periods.
- Newsletter/Waitlist Subscribers: Until the earlier of two years after the last newsletter sent or unsubscription. On unsubscription, subscriber data and email delivery records are deleted. The minimum pseudonymized audit record needed for legal compliance and dispute handling is retained separately for the period stated below. Re-subscription is treated as a new subscription.
- Analytics Data: 14 months as configured in Google Analytics, after which data is automatically deleted or anonymized
Article 4: International Transfer and Processing Outsourcing of Personal Information
The Company outsources personal information processing to the following entities to improve service quality and fulfill contractual obligations. Personal information may be transferred internationally during this process.
Detailed Outsourcing Information
| Processor (Country) | Items Transferred | Transfer Timing & Method | Outsourced Tasks | Retention Period | Contact |
|---|---|---|---|---|---|
| Cloudflare, Inc. (United States and global network) | IP address, access logs, HTTP request information, device and browser information | Transferred electronically in real time when the website is accessed | DNS, CDN, DDoS protection, security, and traffic delivery | For the period defined by Cloudflare's contract and retention policy | cloudflare.com/privacypolicy |
| Contabo GmbH (Germany) | Email address, waitlist registration information, newsletter subscription data, access logs, entire email database | Electronically transmitted via network at the time of service use | Cloud server hosting, database storage and backup, newsletter system hosting and data storage | During service use period | [email protected] |
| Resend Inc. (USA) | Email address | Real-time transmission via network when sending emails | Transactional email delivery only (no tracking or analytics) | Until user unsubscribes from mailing list or service agreement termination | [email protected] |
| Google LLC (USA) | Access logs, cookies, IP address | Automatically transmitted when using the service | Website visitor analysis using Google Analytics | Configured to 14 months or until opt-out | privacy.google.com |
International Data Transfer Rights and Options
The following describes overseas transfers and refusal methods under PIPA Article 28-8. Refusing a transfer required for core infrastructure may limit the relevant feature; optional analytics transfers can be withdrawn at any time in cookie settings:
Server Hosting (Contabo)
- •Purpose: Essential infrastructure for cloud hosting and database management
- •Effect of Refusal: Newsletter subscription and waitlist registration features become unavailable
- •Method: Click the 'Do Not Sell or Share My Personal Information' link at the bottom of our website
- •Procedure: Click the 'Do Not Sell or Share My Personal Information' link at the bottom of our website
Email Delivery (Resend)
- •Purpose: Sending service-related emails
- •Effect of Refusal: You will not receive service emails
- •Method: Click the unsubscribe link in any email footer or contact [email protected]
- •Procedure: Select 'Unsubscribe' in any email or reach out to support
Analytics (Google Analytics)
- •Purpose: Website traffic analysis and service optimization
- •Effect of Refusal: No impact on service functionality
- •Method: Adjust browser cookie settings, enable 'Do Not Track', or modify website privacy settings
- •Procedure: Browser settings or website cookie preferences
Article 5: Use of Cookies and Session Storage
The Company uses the following technical tools to improve user convenience.
1. Session Storage
- Purpose: To prevent loss of user-entered content (email, etc.) when users navigate between pages or refresh, providing convenience.
- Storage Period: Maintained only until the browser tab or window is closed, and permanently deleted upon closure. Not transmitted to servers.
2. Local Storage
- Purpose: Remembering your cookie consent choice (with its time and policy version) and your language preference, so we do not ask again on every visit.
- Storage Period: Kept in your browser until you clear site data. Not transmitted to our servers.
3. Google Analytics 4 - Prior Consent
We use Google Analytics 4 to analyze website usage. The analytics script and related data transfers start only after you explicitly consent to analytics cookies.
The Same Prior-Consent Rule in Every Region
Analytics is disabled by default regardless of inferred location, and Google Analytics is not loaded before an explicit choice:
For EU/UK/EEA Users (Basic Consent Mode - GDPR Strict Compliance)
- Before Consent: No data collection, no cookies, no GA4 script loading
- After Consent: Full analytics tracking with cookies (_ga, _ga_*)
- Legal Basis: GDPR Article 6(1)(a) - Explicit consent required
For Users in Other Regions (Prior Consent)
- Before Consent: No analytics transfer, no analytics cookies, and no GA4 script
- After Consent: Full analytics tracking with cookies
- Processing Basis: Your explicit choice to consent
Data Collected
- EU/UK (Consent Denied): No data collected
- Other Regions (Before Consent or Denied): No analytics data collection
- All Regions (Consent Granted): Full analytics data including cookies, session duration, user interactions, conversion tracking
Cookies Used (When Consent is Granted)
- _ga: Unique user identifier (expires: 2 years)
- _ga_*: Session and campaign tracking (expires: 2 years)
Data Retention
Analytics data is configured to be retained for 14 months, after which it is automatically deleted or anonymized by Google.
Third-Party Data Transfer
- Recipient: Google LLC (Mountain View, California, USA)
- Safeguards: EU-US Data Privacy Framework certified, Standard Contractual Clauses (SCCs)
- Purpose: Analytics processing and reporting
Your Rights and How to Exercise Them
- Withdraw Consent: Click "Cookie settings" in the page footer and change your preferences. Each site (e.g. devrives.com, tickmark.devrives.com) stores its choice separately, so change it on each site you visited
- Opt-out Tool: Install Google Analytics Opt-out Browser Add-on
- Browser Settings: Configure your browser to block third-party cookies
- Data Access/Deletion: Contact [email protected] to request access or deletion of your analytics data
Country Information Used for Language Selection
When Cloudflare includes a country code in a request, we use it only to select the initial display language. We do not send IP addresses to a separate geolocation API, and location does not change the analytics consent rule.
Regulatory Compliance
- GDPR (EU/UK): We operate consent and data-subject request procedures with reference to Articles 6, 7, and the data-subject rights provisions.
- PIPA (Korea): We process data using the principles for consent, overseas-transfer notice, and data minimization.
- ePrivacy Directive: EU users have no tracking scripts loaded until consent is granted.
Why Do We Require Prior Consent Everywhere?
- Data minimization: No analytics request is sent before your choice
- Predictability: Location inference errors cannot change how analytics data is handled
- Withdrawal: Changing cookie settings stops subsequent analytics storage and transfer
Article 6: Collection of Behavioral Information and Right to Refuse
The Company collects behavioral information to analyze user patterns and improve services. Users have the right to refuse such collection.
1. Web Log Analysis Tool (Google Analytics)
The Company uses Google Analytics to analyze website visit history and user behavior. Users may refuse data collection by:
- Adjusting browser settings to reject cookies
- Installing the Google Analytics Opt-out Browser Add-on
- Using the cookie settings feature on our website
2. Emails (No Open or Click Tracking)
Emails sent by the Company (newsletter, waitlist and service notices) are delivered through Resend for delivery purposes only. They contain no tracking pixels (web beacons) and no click-tracking links, so we do not collect behavioral information such as whether or when you open an email or which links you click. You can manage the emails you receive as follows:
- Unsubscribe at any time using the "Unsubscribe" link at the bottom of every email
- Contact [email protected] to request deletion of your email address
Note: Delivery status information that is technically necessary to send an email (such as delivered or bounced) may be processed by Resend, but it is not used to analyze your behavior.
Article 7: Rights of Data Subjects
Users may exercise the following rights depending on their region of residence:
Right to Access and Data Portability (GDPR/PIPA/CCPA)
You may request access to and obtain a copy of your personal information held by the Company.
Right to Erasure (Right to be Forgotten)
You may request deletion of your personal information, except where retention is required by law.
Right to Restrict Processing and Withdraw Consent
You may cancel your waitlist registration or withdraw your newsletter subscription consent at any time through the 'Unsubscribe' link at the bottom of emails.
Right to Opt-Out of Sale/Sharing (CCPA/CPRA)
California residents have the right to refuse the sharing of personal information with third parties. Although we do not sell your personal information, you may opt-out of data sharing resulting from the use of analytics tools (Google Analytics). You can exercise this right through the 'Do Not Sell or Share My Personal Information' link at the bottom of our website.
How to Exercise Your Rights
To exercise any of the above rights, please contact us at [email protected]. We will respond to your request without undue delay and within the timeframes required by applicable law (typically within one month for GDPR and 45 days for CCPA/CPRA).
Article 8: Measures to Ensure Safety of Personal Information
The Company takes the following technical, managerial, and physical measures necessary to ensure safety in accordance with Article 29 of the Personal Information Protection Act.
- Managerial Measures: Establishment of internal management plans, regular employee training
- Technical Measures: Access control to personal information processing systems, encryption of unique identifying information (HTTPS/TLS), installation of security programs
- Physical Measures: Access control to data centers (Contabo)
Article 9: CAN-SPAM and Email Delivery Compliance
The Company complies with the following when transmitting advertising information:
- Consent Confirmation: Sent only to users who explicitly consented (newsletter and waitlist subscribers)
- Unsubscribe Function: All emails include 'Unsubscribe' links, and unsubscribe requests are processed within 10 business days as required by CAN-SPAM Act
- Sender Information: Each email displays the sender information required by applicable law and the contact address [email protected]
Article 10: Privacy Officer and Inquiries
• Privacy contact office: devrives Privacy Desk
• Email: [email protected]
Article 11: Data Breach Notification
In the event of a data breach that compromises your personal information, we will notify affected users in accordance with applicable laws.
- GDPR (EU/UK): If a breach is likely to result in a high risk to rights and freedoms, we will notify affected data subjects without undue delay under GDPR Article 34.
- CCPA/CPRA (California): We will notify California residents without unreasonable delay in accordance with California Civil Code Section 1798.82.
- PIPA (Korea): We will notify affected data subjects according to the applicable scope, content, and deadline in PIPA Article 34 and Article 39 of its Enforcement Decree.
- Notification Method: We will notify you via email to the address you provided, and post a notice on our website if the breach affects a large number of users.
- Breach Information: Our notification will include the nature of the breach, the types of information involved, measures taken to mitigate harm, and recommended steps you should take to protect yourself.
Article 12: Risk Assessment and Data Protection Impact Assessment (DPIA)
We conduct regular risk assessments to evaluate data processing activities that may present privacy risks to users.
- Risk Assessment Process: We assess data processing activities for potential risks to user privacy, security vulnerabilities, and compliance requirements. High-risk activities undergo enhanced review.
- DPIA Requirement (GDPR Article 35): Currently, our processing activities do not require a formal Data Protection Impact Assessment as we do not engage in large-scale systematic monitoring, processing of special categories of data, or systematic evaluation/scoring of individuals.
- We review our data processing activities quarterly to ensure continued compliance with privacy regulations and to identify any changes that may trigger DPIA requirements.
Revision history
Every earlier version stays available. Open one to read it as it was in force, or see what changed between versions.
Version 1.52026-10-08Current
Added a note, with a link, that apps distributed through Google Play and similar stores (such as Safe-Life and the watch faces) are also covered by each product's own privacy policy. How personal information is processed has not changed.
Version 1.42026-10-08
Corrected the retention period for newsletter and waitlist subscribers to match what the signup form states: 2 years from the last newsletter sent, or until unsubscription. Clarified the newsletter purpose as delivering the newsletter and, with optional consent, marketing information.
Version 1.32026-10-08
Article 6 §2 now states that emails sent by the Company contain no tracking pixels or click-tracking links, so no open or click information is collected, and explains how to unsubscribe via the link in every email or request deletion via [email protected]. Article 10 contact details cleaned up to the privacy contact office and email, with the mailing address item removed. Fixes text that previously failed to display on the page (Article 6 §2 and Article 10).
Version 1.22026-10-07
Scope now explicitly covers devrives.com and its subdomain sites such as tickmark.devrives.com (Tickmark watch faces). Article 5 adds a Local Storage item (cookie consent choice with time and policy version, and language preference) and renumbers the GA4 item to 3. Consent withdrawal now points to "Cookie settings" in the page footer and notes that each site stores its choice separately.
Version 1.12026-08-09
GA4 moved from region-based hybrid consent mode to the same prior-consent rule in every region (no analytics transfer, cookies or script before consent). Region detection text replaced by use of the Cloudflare country code for initial language selection only. Cloudflare, Inc. added to the outsourcing table. International transfer notice now cites PIPA Article 28-8. Subscriber retention clarified: deletion on unsubscription, with a minimum pseudonymized audit record kept separately. Breach notification text revised to GDPR Article 34 and PIPA Article 34 / Enforcement Decree Article 39, and compliance wording softened. Operator name and mailing address removed from Article 9 sender information and Article 10 (2026-09-06, without a version bump).
Version 1.02025-12-19
Initial version.