Privacy Policy

Last Updated: January 31, 2026

1. Introduction

Rebalance Analytica ("we," "our," or "us"), operated by Rebalance Analytica in the Republic of Korea, respects your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our website. We process your data in compliance with the Personal Information Protection Act (PIPA) of Korea and applicable international privacy laws, including the California Consumer Privacy Act (CCPA/CPRA).

2. Information We Collect

  • Information You Provide: Email address (via newsletter subscription), name, and any information submitted through contact forms.
  • Google Account Information: When you sign in using Google OAuth, we receive and store your Google account name, email address, profile picture URL, and a unique user identifier. This information is used solely for authentication and account management purposes.
  • Automatically Collected Information: IP address, device identifiers, browser type, pages visited, time spent on site, and referring URLs.
  • Cookies: We use cookies to enhance user experience and maintain your login session. You may refuse cookies through your browser settings, though some features may be limited.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. Account Information and Deletion

When you create an account using Google Sign-In, we store the following information:

  • Your name as provided by Google
  • Your email address
  • Your profile picture URL
  • A unique user identifier
  • Account creation timestamp

Account Deletion:

  • You may delete your account at any time by clicking the "Delete Account" button in your user menu.
  • Upon deletion, all your personal data stored on our servers will be permanently removed.
  • To revoke our access to your Google account, visit your Google Security Settings.

4. Legal Basis and Purpose of Use

We process your information for the following purposes:

  • To provide and maintain our ETF data tracking service.
  • To authenticate your identity and manage your user account.
  • To send newsletters and marketing communications (only with your explicit consent).
  • To analyze service usage and improve user experience (using anonymized data).
  • To comply with legal obligations and respond to lawful requests from authorities.

5. Data Retention and Destruction

  • Retention Period: We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy or as required by law (e.g., 5 years for service records under Korean law).
  • Destruction: Once the retention period expires or the purpose is achieved, we will promptly destroy your data in a non-recoverable manner.

6. International Data Transfers

As we are located in the Republic of Korea, your information will be transferred to and processed on servers located in Korea and potentially other countries where our service providers operate.

In accordance with Korea's PIPA, we inform you that your data may be transferred to the following:

  • Supabase (United States): Authentication and database services for user account management.
  • Google (United States): OAuth authentication services.
  • Mailchimp (United States): Newsletter delivery services.

By using the Service, you consent to this cross-border transfer. We ensure that such transfers comply with applicable privacy laws through standard contractual clauses or equivalent protections.

7. Third-Party Sharing

We do not sell your personal information. We only share data with:

  • Google: For OAuth authentication. We receive your name, email, and profile picture when you sign in with Google.
  • Supabase: For user authentication and account data storage.
  • Mailchimp: For newsletter delivery (email address only, with your consent).
  • Google Analytics: For anonymized website usage analysis.
  • Legal Requirements: If required by law, subpoena, or court order.

8. Your Rights (Regional Notices)

Depending on your location, you have specific rights:

  • For California Residents (CCPA/CPRA): You have the right to know what data is collected, the right to delete, and the right to opt-out of the "sale" or "sharing" of personal information. We do not sell or share your personal information.
  • For Korean Residents (PIPA): You have the right to access, correct, or delete your data and request the suspension of processing.
  • For EU/UK Residents (GDPR): You have the right to data portability and the right to object to certain processing activities.

To exercise these rights, please contact us at support@rebalanceanalytica.com.

9. Children's Privacy

Our Service is not directed to individuals under the age of 13 (in compliance with Google's age requirements) or 18 in jurisdictions where the age of majority is higher. We do not knowingly collect personal data from children. If we become aware of such collection, we will take immediate steps to delete the data.

10. Security

We implement technical, administrative, and physical safeguards (e.g., encryption, access controls) to protect your data. Authentication is handled through secure OAuth protocols provided by Google and managed by Supabase. However, no electronic transmission or storage is 100% secure.

11. Privacy Officer (Contact Information)

In accordance with Korea's PIPA, we have designated a Privacy Officer to oversee data protection: