1. Overview
GBFCIP team LLC (“we”, “us”) operates ActsLala. This Privacy Policy explains what information we process when you use gbfcip.net and how we use it. We design chat to minimize retention; member and payment data are processed only as needed to provide the Service.
GBFCIP team LLC (“we”, “us”) operates ActsLala. This Privacy Policy explains what information we process when you use actslala.com and how we use it. We design chat to minimize retention; member and payment data are processed only as needed to provide the Service.
2. What we collect
2.1 Casual chat (no member account)
- Temporary session identifier and nickname you choose
- Chat messages and metadata for delivery, subject to short TTL deletion (see PolicyTech)
- Technical data: IP address, browser/device type, timestamps (for abuse prevention and operations)
2.2 Member account (recharge / wallet)
- Email address or phone number and hashed PIN
- lala balance, expiry, and transaction history tied to your member record
2.3 Invite email address book (room owner)
- Room owners may store invitee email addresses solely to send an ActsLala room invite link
- Invitee emails are stored in plaintext on our server only for SMTP delivery; owner-only list/add/remove, rate limits, and ResidualCleanup TTL (about 90 days) apply
- Invite address books are keyed by the logged-in member account (not by chat room). The same owner keeps one list across rooms. Member signup/login is required; paying for a recharge is optional
- If the room owner opts in (checkbox next to My email), that owner email may be shown in the invite message as “Inviter.” If unchecked, the owner email is not shown in the invite body
- Invite delivery in production is planned via Amazon SES from
invite@gbfcip.net. Until SES is enabled, owners can import/store emails but Send is rejected. Cafe24 SMTP from poc@actslala.com is the contact form (and recharge notices) only — not bulk room invites. We do not send invites via the owner’s Gmail or the Gmail API
This section is the product-specific disclosure for Google user data obtained through OAuth / the Google People API. App: ActsLala (https://actslala.com/). Operator: GBFCIP team LLC.
This section is the product-specific disclosure for Google user data obtained through OAuth / the Google People API. App: ActsLala (https://gbfcip.net/). Operator: GBFCIP team LLC.
- Owners may connect their Google account via OAuth to import email addresses from Google Contacts
- We request only the Google scope
https://www.googleapis.com/auth/contacts.readonly (read-only access to the owner’s contacts). We do not use Gmail send, the Gmail API, or any other Google scope for this feature
- After Google authorization, contact names and email addresses are loaded temporarily into a selection UI in ActsLala for the room owner. We do not silently copy the entire Google address book into long-term storage
- Only emails the owner explicitly confirms (and, for select-all, only after an additional confirmation prompt) are saved to the invite address book described in §2.3
- Google OAuth tokens are stored on our Cafe24-hosted application server, linked to the owner’s session/member context (hashed session identifier), solely to call Google’s People API for this import feature; owners can disconnect Google from the invite Contacts modal (Disconnect Google), which deletes stored tokens and best-effort revokes them at Google. Unused token records are also pruned after about 7 days
- We do not sell Google user data. We do not use Google Contacts or other Google user data for advertising, retargeting, or interest-based ads
- We do not use Google user data to develop, improve, or train AI and/or ML models (including non-personalized models). Google user data from this scope is not used for AI/ML training
- Google user data from
contacts.readonly is used only to provide the owner-facing invite picker described here (Limited Use: providing a user-facing feature in ActsLala)
Sharing / transfer / disclosure of Google user data
This clause states with whom we share, transfer, or disclose Google user data. We do not transfer or disclose your information to third parties for purposes other than the ones provided.
- Google — required to complete OAuth (token exchange / refresh / revoke) and to read the owner’s contacts via the People API under
contacts.readonly. See Google’s Privacy Policy.
- Cafe24 (hosting) — ActsLala is hosted on Cafe24. Application data on that server, including OAuth tokens and the owner’s invite address book, is processed on Cafe24’s hosting infrastructure as needed to run the website. Cafe24 is not given a separate dump of the owner’s Google Contacts. Cafe24 SMTP from
poc@actslala.com is used for the public contact form (and recharge notices), not for bulk Google-contact invites.
- Selected invite recipients only — if (and only if) the owner chooses specific emails and invite send is enabled (Amazon SES from
invite@gbfcip.net), an invite may be delivered to those addresses. The recipient sees the invite (room link and, if the owner opted in, the inviter’s email). Recipients do not receive the owner’s full Google contact list, unselected contacts, or OAuth tokens. Chat participants cannot access Google Contacts import (owner-only).
- No other third parties. We do not sell, rent, or transfer Google user data to advertising platforms, data brokers, information resellers, or analytics/ads vendors. Payment processors (for example FastSpring) do not receive Google Contacts or Google OAuth tokens.Payment processors (for example Lemon Squeezy) do not receive Google Contacts or Google OAuth tokens. We do not share Google contact dumps with Amazon SES; if invite send is later enabled, SES receives only the selected recipient address plus the invite message, not the owner’s full Contacts list.
- Google user data never leaves ActsLala + Cafe24 except: (1) the OAuth/API calls back to Google needed to import contacts, and (2) the invite email sent to a recipient the owner selected (when SES invite send is enabled). That is the complete list of sharing, transfer, and disclosure.
- We may disclose data if required by applicable law, or if needed to investigate abuse of the Service. We do not otherwise allow humans to browse owners’ Google contact lists.
Data protection mechanisms for sensitive data
This clause specifies data protection mechanisms for sensitive data (Google OAuth tokens and contact data obtained under contacts.readonly). Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information in transit (HTTPS/TLS between the user’s browser and ActsLala, and TLS when our server talks to Google).
- Access control: Google Contacts import, contact list load, token disconnect, and invite-address-book changes require an authenticated room-owner session and a logged-in member account. Participants cannot call these APIs.
- OAuth token storage: Access and refresh tokens are stored server-side only (not in the browser as the system of record). Tokens live in a server data directory that is blocked from public HTTP access (web-server deny rules /
.htaccess). Client secrets in *.local.php are likewise blocked from HTTP. Tokens are keyed to a hashed session identifier, not published at a public URL, and are not kept longer than needed for the owner’s import sessions (disconnect deletes them; unused records are pruned after about 7 days).
- No public contact dump: Unselected people from Google Contacts are not written into the long-term invite address book. Contact JSON and token files are not exposed as public website pages.
- Retention / deletion: Confirmed invite emails follow §2.3 and §4 (owner remove, ResidualCleanup TTL about 90 days, and room/TTL cleanup of related session context). Disconnect Google removes stored tokens and attempts revocation at Google.
- Logging: We do not publish contact lists in public logs. Operational error logs may contain technical messages; they are not a public contacts directory.
- We do not claim disk encryption-at-rest as a Cafe24 standard, and we do not claim SOC 2 or similar third-party certifications. Protections above are the mechanisms we actually operate.
한국어 (사용자용) — Google 연락처 불러오기
개설자는 Google OAuth로 본인 연락처를 읽기 전용(contacts.readonly)으로만 연결할 수 있습니다. Gmail 발송·Gmail API는 쓰지 않습니다. 문의 폼 SMTP는 Cafe24 poc@actslala.com입니다. 초대 메일 발송은 이후 Amazon SES(invite@gbfcip.net)로 켜질 예정이며, 지금은 주소 저장만 되고 Send는 거절됩니다. 연락처는 선택 화면에 잠시 보여 주고, 개설자가 확인한 이메일만 초대 주소록에 저장합니다. Google 사용자 데이터로 광고하지 않고, 판매하지 않으며, AI/ML 모델 학습에도 사용하지 않습니다.
Google 사용자 데이터의 공유·이전·공개: Google(OAuth·People API), Cafe24(호스팅), 그리고 개설자가 선택한 수신자에게 보내는 초대 메일(SES 활성화 후)뿐입니다. 수신자는 초대장만 받으며 전체 연락처 목록은 받지 않습니다. 그 외 제3자에게 Google 연락처·토큰을 넘기지 않습니다.
민감 데이터 보호: 전송 구간 HTTPS/TLS 암호화, 개설자 세션·회원 인증으로 접근 제한, 토큰은 서버에만 저장하고 HTTP로 공개되지 않게 차단, 연결 해제·약 7일 미사용 시 토큰 삭제, 선택하지 않은 연락처는 장기 저장하지 않음, 초대 주소록은 약 90일 TTL·개설자 삭제. Cafe24 디스크 암호화(at rest)나 SOC 2는 주장하지 않습니다.
2.4 Payments
- Order IDs, amounts, payment method type, fulfillment status
- For card payments: FastSpring processes card data; we receive transaction references and custom order metadata, not full card numbers
- For card payments: Lemon Squeezy processes card data; we receive transaction references and custom order metadata, not full card numbers
- For bank transfer: deposit memo, amount, and confirmation records
3. How we use information
- Provide chat, translation, video, and lala wallet features
- Allow room owners to store invite emails and, when SES is enabled, send room invite links (including optional Google Contacts pick-list import)
- Process purchases and prevent duplicate or fraudulent fulfillment
- Respond to support requests and legal obligations
- Enforce Terms, block abuse (e.g. session/fingerprint blocks), and maintain security
4. Retention/Deleted
- Chat messages: Deleted per ephemeral policy (e.g. after read timeout, room idle destruction, link expiry).
- Invite email address book: Each stored invite email is deleted after about 90 days (ResidualCleanup TTL), or earlier when the room owner removes it.
- Google OAuth tokens (Contacts import): Kept only while needed to refresh access for the owner’s import sessions; removed when the owner disconnects or when associated session/token records are purged.
- Member and payment records: Retained as long as needed for accounting, disputes, chargebacks, and legal requirements.
5. Third-party processors
- Google — OAuth and Google People API when an owner imports contacts (Google Privacy Policy). See §2.3.1 for sharing and protection of Google user data
- Cafe24 — website hosting and contact-form / recharge SMTP from
poc@actslala.com
- Amazon SES — planned transactional invite email from
invite@gbfcip.net when enabled (not currently used for invites)
- FastSpring — payment processing and Merchant of Record (FastSpring Privacy). FastSpring does not receive Google Contacts or Google OAuth tokens
- Lemon Squeezy — payment processing and Merchant of Record (Lemon Squeezy Privacy). Lemon Squeezy does not receive Google Contacts or Google OAuth tokens
6. Your rights
Depending on your jurisdiction, you may request access, correction, or deletion of personal data we hold about you, or object to certain processing. Contact Email. We may need to verify your identity via your registered contact.
Deleting a member account may not erase records we must keep for legal or payment dispute purposes.
7. International transfers
Our servers and processors may be located in the Republic of Korea and other countries. By using the Service, you acknowledge that data may be processed in those locations with appropriate safeguards where required.
8. Children
The Service is not directed at children under 14 (or the minimum age in your country). We do not knowingly collect data from children. Contact us to request deletion if you believe a child has provided data.
9. Changes and contact
We may update this Policy. The “Last updated” date will change when we do. Material changes may be announced in the app.
Data controller: GBFCIP team LLC · 340-15-02889 · Registered address and Contact form