Version 2026.09.03-r1 · Last updated 3 September 2026
coralwake -- PRIVACY POLICY
This Privacy Policy explains how UNITEDSOFT ("we", "us", or "Operator") collects, uses, and shares information when you use coralwake websites and applications, including coralwake.com, the Manager (app.coralwake.com), Player (play.coralwake.com), API (api.coralwake.com), and related services (the "Service").
If you do not agree with this Policy, do not use the Service.
1. WHO WE ARE
Controller / operator: UNITEDSOFT
Address: 511, 21, Magokjungang 6-ro, Gangseo-gu, Seoul 07801, Republic of Korea
Contact: https://coralwake.com/contact
Email: support@coralwake.com
For payment transactions processed by Paddle as Merchant of Record, Paddle also acts as an independent controller (or equivalent) for payment data under Paddle's privacy notice.
2. INFORMATION WE COLLECT
2.1 Account information
- Email address, name or display name (if provided), password or authentication secrets (stored hashed/secured), locale preferences, and account settings.
2.2 Service and device information
- Display / Unit identifiers and names, pairing and connection status, Player/runtime telemetry needed to operate screens (for example online/offline, last seen, basic playback health), content library metadata, Studio layouts, schedules, and publish state.
- Technical and account-activity logs such as request timestamps, abbreviated user agent, security-oriented IP fingerprints (hashed; we do not keep raw IP addresses in member activity records), and approximate country or broader region derived from network/CDN signals or IP lookup databases. We do not use device GPS or browser location permission to locate you.
- Optional product-use tags you choose to provide (for example business category) when we offer that step.
2.3 Billing-related information
- Plan tier and entitlement flags stored on your account (for example Free / Pro).
- Billable unit capacity and subscription state synced from Paddle via webhooks.
- Paddle customer and subscription identifiers returned by Paddle so we can unlock paid features and show Account status.
- We do not store full payment card numbers on coralwake servers. Card and tax invoicing data for checkout are handled by Paddle.
2.4 Communications
- Messages you send through https://coralwake.com/contact or other support channels (name, email, subject, message body).
- Legal acceptance records (which Terms/Privacy version you accepted, when, and source such as signup).
2.5 Marketing and product analytics (first-party)
- Limited first-party events such as CTA clicks on marketing pages when enabled, used to understand funnel performance. We do not sell personal information.
2.6 Cookies and similar technologies
- Essential cookies or local storage for session, authentication hints, and locale (for example nexus_locale).
- We may use additional analytics cookies only if disclosed and, where required, consented. If not enabled, this Policy will be updated before introduction.
3. HOW WE USE INFORMATION
We use information to:
(a) provide, operate, secure, and improve the Service;
(b) authenticate users and enforce plan entitlements;
(c) process and support billing status with Paddle;
(d) respond to inquiries and provide support;
(e) detect abuse, fraud, and security incidents;
(f) comply with law and enforce our Terms;
(g) send service notices (for example security or material Terms changes). Optional marketing email is sent only where permitted and with unsubscribe where required.
4. LEGAL BASES (WHERE APPLICABLE)
If GDPR/UK GDPR or similar laws apply, we rely on: contract performance (providing the Service); legitimate interests (security, product improvement, limited analytics); consent (where required); and legal obligation.
5. HOW WE SHARE INFORMATION
We share information with:
(a) Infrastructure processors (hosting, database, email delivery, CDN) under contracts that restrict use to our instructions;
(b) Paddle for checkout, subscriptions, invoices, taxes, and refunds;
(c) Professional advisors or authorities when required by law or to protect rights and safety;
(d) A successor entity in connection with a merger, acquisition, or asset transfer, subject to appropriate safeguards.
We do not sell personal information. We do not share Customer Content publicly except as you configure for playback on your own displays or via links you create.
6. INTERNATIONAL TRANSFERS
We may process data in countries where we or our processors operate. Where required, we use appropriate transfer mechanisms (for example standard contractual clauses).
7. RETENTION
Unless a longer period is required by law or a documented legal hold:
(a) Account profile and Service configuration data: while your account is active, and for a reasonable period afterward for backups, dispute resolution, and legal compliance.
(b) Approximate country / region summary stored on your account: while your account is active (updated when we see new sign-in or comparable events); removed or anonymized when the account is deleted, subject to legal holds.
(c) Detailed member activity events (for example successful or failed sign-in, selected billing or support context events): up to 90 days, then deleted from primary storage after roll-up into daily aggregates where used.
(d) Daily activity aggregates (counts by day and category, without raw IP): up to 24 months, then deleted or further anonymized.
(e) Device / Player operational telemetry logs retained in our operations tools: typically up to 7 days.
(f) Inquiry (support) records: for an operational period after the case is closed, then deleted or archived as needed for disputes.
(g) Legal acceptance records: for a reasonable audit and dispute period.
We do not retain raw IP addresses in member activity records under our standard practice (hashed fingerprints and derived region codes only). You may request deletion subject to Section 9 and legal holds.
8. SECURITY
We implement administrative and technical measures appropriate to the nature of the Service (access controls, transport encryption where applicable, hashed credentials). No method of transmission or storage is 100% secure.
9. YOUR RIGHTS
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of personal data, and to object to certain processing. To exercise rights, use https://coralwake.com/contact. You may also lodge a complaint with a supervisory authority where applicable.
You can update certain account fields in-product. You may close your account through available flows or by contacting us.
10. CHILDREN
Account eligibility under our Terms requires that you be at least 18 years old (or the age of majority in your place of residence). Separately, this section addresses children's personal data: the Service is not directed to children under 16 (or a higher age required by local law). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps.
11. THIRD-PARTY LINKS AND MEDIA
If you embed or link third-party media (for example YouTube or Vimeo), those providers process data under their own policies when content is fetched or played.
12. CHANGES
We may update this Privacy Policy. The version label and date on https://coralwake.com/privacy will change when a new version is published. Material changes will be highlighted via the Service or signup flows where appropriate.
13. CONTACT
Privacy questions: https://coralwake.com/contact
Email: support@coralwake.com
Operator: UNITEDSOFT
Address: 511, 21, Magokjungang 6-ro, Gangseo-gu, Seoul 07801, Republic of Korea
END OF PRIVACY POLICY