UrbanDream B2B processes only the personal information needed for buyer accounts, private consultation, shared 3D product review, quotation preparation, and reviewed payment guidance.
Last updated: 2026-07-29UrbanDream B2B
UrbanDream verified its public seller information and contact details on July 29, 2026. These policies reflect the current operating model. Automated checkout remains locked until the owner completes the final payment-policy review and provider checkout, webhook, cancellation, and refund workflows pass testing.
1. Information we process
Account data: email address, name, profile image, provider identifier, and password or verification-code hashes where the relevant login method is used.
Room data: messages, attached images, file names and sizes, download records, and the shared 3D Viewer state.
Quotation and payment-preparation data: quote versions, quantity, amount, currency, payment purpose, and payment-instruction release history.
Security and operations data: IP address, browser or device metadata, access records, request time, authorization outcomes, and audit-event metadata.
2. Purposes and legal basis
To create and secure buyer accounts and private consultation rooms.
To provide shared 3D product review, reference-image review, messages, files, and quotation workflows.
To perform requested services, prepare or manage transactions, and comply with accounting, tax, consumer-protection, and dispute obligations.
To prevent misuse, investigate security incidents, maintain audit records, and protect UrbanDream and its users.
Where consent is the applicable basis, the relevant screen explains the purpose and the effect of refusing consent before collection.
3. Retention
Account data is kept until account withdrawal or completion of the purpose, unless a legal duty or active dispute requires limited separate retention.
The initial operating schedule keeps closed-room messages, attachments, and staff notes for three years and security or audit logs for five years.
Where Korean e-commerce law applies, advertising records are kept for six months; contract or withdrawal records for five years; payment and supply records for five years; and consumer complaint or dispute records for three years.
A longer mandatory period for quotation, transaction, tax, accounting, or legal evidence takes precedence.
4. Destruction
When the retention period expires or the purpose is completed, data is separated from legally retained records and destroyed without undue delay.
Electronic files are securely deleted so they are not reasonably recoverable. Paper records are shredded or incinerated.
Where an individual backup copy cannot be removed immediately, access is restricted and the copy is permanently removed at the end of the backup rotation.
5. Processors and disclosures
UrbanDream does not sell personal information or disclose it to an unrelated third party without consent. Where disclosure is required by law, consent, or transaction performance, the recipient, purpose, fields, and retention period will be explained in advance.
Amazon Web Services (AWS): Seoul-region Lightsail hosting, the separate B2B database, and private attachment storage. Service, account, consultation, and access data is processed until the service arrangement ends or the relevant retention purpose is completed.
Cloudflare: DNS, TLS, traffic security, bot control, and DDoS protection. IP addresses, request or device metadata, and security cookies are processed for the service and applicable security-log period.
Google LLC: Google sign-in and Cloud Translation. Sign-in processes email, name, profile, and provider identifiers; translation processes message text and source or target language codes.
Plus Five Five, Inc. (Resend): delivery of email verification codes and password-reset messages. Email address, message content, and delivery events are processed for delivery and security purposes.
A payment provider, carrier, or customs service will be disclosed separately before payment or transfer once the actual provider and processing scope are selected for an order.
6. Overseas processing and automatic translation
Google sign-in (Google LLC, United States and countries where Google subprocessors operate): when a user chooses Google sign-in, email, name, profile, and provider identifiers are processed through encrypted authentication requests.
Google Cloud Translation (Google LLC, United States and countries where Google subprocessors operate): message text and source or target language codes are transferred through an encrypted HTTPS API when translation is requested. Images, attachments, 3D models, and payment information are excluded.
Cloud Translation Basic uses a global endpoint, so UrbanDream cannot designate one processing country. Google states that submitted text is held temporarily in memory to return the translation and is not used to train or improve translation models.
Plus Five Five, Inc. (Resend, United States and countries where its subprocessors operate): email address and verification or reset-message content are transferred through HTTPS when the message is sent. Resend states that customer data is deleted within 90 days after termination of its agreement.
Cloudflare (global network): IP addresses, request or device metadata, and security cookies are processed through encrypted networks during site access and attack prevention for the applicable security purpose or provider retention period.
Users may disable automatic translation and continue in the original language. Users who do not want email verification may use another available sign-in method, such as Google sign-in.
7. Your rights
You may request access, correction, deletion, or restriction of your personal information.
Immediate deletion may be limited where transaction evidence, dispute handling, security records, or another legal obligation requires retention.
Requests may be submitted through a consultation room, by email at gusdnrlrk93@gmail.com, or by phone at 010-5833-7975.
UrbanDream verifies the requester's identity and responds or explains any lawful limitation under the applicable procedure and time limit.
8. Safeguards
Administrative areas require separate authentication and use role-based access controls.
Buyer attachments are stored outside public paths and are served only after room-membership authorization.
Secrets are held in environment variables, sensitive payment-card data is not stored, and provider webhooks must be signature-verified before a payment state is accepted.
Inputs, file types, file sizes, request rates, logs, and security events are restricted or reviewed according to their risk.
9. Privacy contact and policy changes
Privacy officer: 이현우.
Published contact: gusdnrlrk93@gmail.com / 010-5833-7975.
Requests may also be submitted through a consultation room or the official inquiry form.
The published privacy contact has been confirmed by the owner.
A material policy change will be announced before it takes effect through the site or another reasonable electronic channel, with prior versions and their effective periods retained for reference.