Modern Web Labs
Privacy Policy
Effective
Modern Web Labs (represented by Bora Lee, "Modern Web Labs") operates www.modernweblabs.com (the "site"). This policy explains how the site handles personal data, as required by Article 30 of the Personal Information Protection Act of the Republic of Korea.
The site has no sign-up or login for visitors. The only account is the founder's administrator account used to manage content. Visitor data is collected only when a visitor enters it directly, for example to request a consultation, subscribe to the newsletter, or report a problem. Data that is recorded automatically to operate the service is described separately.
1. Data we collect, why, and for how long
The table below lists data that visitors enter themselves. Each item is used only for the stated purpose.
| When | Data | Purpose | Retention |
|---|---|---|---|
| Consultation request form | Company or organization, contact name, email, phone (optional), areas of interest, audience size (optional), preferred timing (optional), request details | Reviewing and replying to the request, scheduling a consultation | 3 years from receipt (deleted at the first quarterly review after that). Deleted immediately on request |
| Newsletter subscription | Email, language (Korean or English), where you subscribed and the article that led you there, confirmation time, per-issue delivery, open and click events | Sending the biweekly newsletter and managing bounces and unsubscribes | Until you unsubscribe. The record is then kept for 1 year to recognize re-subscriptions and preserve delivery history, and deleted at the first quarterly review after that. Deleted immediately on request |
| Tutorial email verification | Email, 6-digit verification code (stored only as a hash, expires after 10 minutes), the tutorial where verification started | Confirming access to full tutorials. A completed verification registers a newsletter subscription | Same as the newsletter subscription |
| Site feedback | Your message, the page address you reported, email (optional), browser information (User-Agent) | Investigating and fixing the problem, replying if needed | 1 year after the report is handled (deleted at the first quarterly review after that) |
| Client-only content access | Per-client access code, client name, daily aggregate counts of code use and reads (per client, not per person) | Providing premium tutorials to members of contracted clients and reporting usage | Until the contract ends. At the first quarterly review after that, the access codes, client name and usage aggregates are deleted |
Consultation requests and site feedback are not stored in the database. Consultation requests are kept in the inbox (sent through Resend, see section 4) and the internal notification channel (Discord); site feedback is kept only in that notification channel (Discord).
A newsletter subscription is complete only after you click the link in the confirmation email. The link expires after 24 hours. Unconfirmed requests are never used for sending and are deleted at the quarterly review after the link expires, or promptly on request.
The following items are recorded automatically while operating the service, without any input from you.
- IP address (hashed): to block automated form submissions, the IP address of consultation, subscription, tutorial email verification, feedback and access-code requests is stored as a SHA-256 hash. The original address is never stored, and hashes are deleted automatically after 30 days.
- Automatic image error reports: when an image fails to load, the page address (including its query string), image address and browser information are sent to the operations channel. Nothing you typed, such as a name or email, is included, and authentication-related parameters are stripped from the page address on the server. Like site feedback, these reports are deleted at the first quarterly review one year after they are handled.
- Hosting access logs: the hosting provider (Vercel) temporarily records IP address, request time and browser information under its own policy.
- Text you enter into the tokenizer tool in Lab is processed on the server and discarded immediately. It is neither stored nor sent to any external service. The legacy GET form of the API carries the text in the URL, so it can remain in browser history and hosting access logs.
2. Cookies and browser storage
These are the cookies and browser storage entries the site sets itself. All of them serve site functions; cookies set by the analytics and affiliate tools that run after consent are described in section 3.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| mwl_email | Cookie | Marks that tutorial email verification is complete | 1 year |
| mwl_premium | Cookie | Client-only content access (signed access code) | 90 days |
| mwl_premium_hint | Cookie | Lets the page send personalization requests only when access exists | 90 days |
| mwl_announcements_dismissed | Cookie | Keeps dismissed announcement banners closed | 1 year |
| NEXT_LOCALE | Cookie | Language preference (Korean or English) | Browser session |
| mwl_admin_hint | Cookie | Set only in a browser signed in on the admin path. Decides whether admin shortcuts are shown | 1 year |
| cookie-consent-v2 | localStorage | Your decision on analytics cookies | Until you delete it |
| tutorial-series-overview:* | localStorage | Whether a tutorial series overview is expanded | Until you delete it |
| mwl-reported-image-errors | sessionStorage | Prevents duplicate image error reports | Until the tab is closed |
The administrator session cookie is created only under the admin path. It is never set in a regular visitor's browser.
You can block or delete cookies in your browser settings. If you do, tutorial email verification and client-only content access will not persist.
3. Analytics tools and external scripts
The tools below run only after you choose "Accept" in the cookie notice at the bottom of the site. Their scripts are not loaded before consent.
| Tool | Provider | Data collected | Purpose |
|---|---|---|---|
| Google Analytics 4 | Google LLC (United States) | Cookie identifier, pages visited, time on page, device and browser information | Visit statistics |
| Microsoft Clarity | Microsoft Corporation (United States) | Cookie identifier, page layout with click and scroll behavior, device and browser information. The consultation, subscription, tutorial verification, client access code and feedback forms carry a masking attribute (data-clarity-mask) so typed content is not recorded, and the tool does not run on administrator screens | Session replay and heatmaps to improve usability |
| impact.com tracking tag | Impact Tech, Inc. (United States) | Cookie identifier, page impressions, affiliate link clicks | Measuring affiliate program performance. Rewrites advertiser links into tracking links |
When KakaoTalk sharing is enabled for the deployment, pages with a share button (insights, tutorials and Lab) load the Kakao JavaScript SDK (Kakao Corp., Republic of Korea). The SDK file is fetched from Kakao's servers when the page opens, so that request's connection data (IP address, browser information) reaches Kakao. Pressing the share button takes you to Kakao's service, and Kakao's privacy policy applies from there. Kakao is a domestic provider, so this is not an international transfer.
These tools set their own cookies after consent: Google Analytics uses _ga and _ga_* (2 years), Microsoft Clarity uses _clck (1 year) and _clsk (1 day), and impact.com cookies follow impact.com's policy. To withdraw consent, delete the cookie-consent-v2 entry from the site data in your browser. The cookie notice will appear again on your next visit and you can choose "Decline". Cookies the tools have already set must be removed with your browser's cookie deletion as well. Google Analytics can also be disabled with the Google Analytics opt-out browser add-on.
4. Processors and international transfers
Modern Web Labs entrusts the tasks below to the listed providers. Where a provider's servers are outside Korea, personal data is transferred abroad. The legal basis is Article 28-8(1)(3) of the Personal Information Protection Act (outsourcing and storage required to provide the service). Analytics tools transfer data only after consent, under Article 28-8(1)(1).
| Processor (contact) | Task | Data transferred | Country | When and how | Retention |
|---|---|---|---|---|---|
| Vercel Inc. (privacy policy) | Hosting and server execution | Access logs (IP address, request time, request URL with query string, browser information) | Servers run in the Republic of Korea (Seoul region). Access logs are stored in the United States | Over the network when you access the site | Per Vercel's log retention policy |
| Supabase Inc. (privacy policy) | Database | Newsletter subscription data, tutorial email verification data (code hash, expiry, attempt count, the tutorial where verification started), delivery, open and click events, client access codes and usage aggregates, IP hashes | Republic of Korea (Seoul region). No international transfer | Stored on entry | As in section 1 |
| Resend Inc. (privacy policy) | Email delivery and subscriber list | All consultation request fields (company, contact name, email, phone, areas of interest, audience size, preferred timing, request details) in the intake email to Modern Web Labs, only the contact name and request details in the confirmation email to the requester, tutorial verification code (verification email), newsletter subscriber email with delivery, open and click events | United States | Via API when an email is sent | On unsubscribe the contact is marked as not to be sent to; it is deleted at the first quarterly review one year after unsubscribing, or on request |
| Discord Inc. (privacy policy) | Intake notifications (internal operations channel) | All consultation request fields (request details up to 1,200 characters), feedback message with the reported page address, email and browser information, automatic image error reports with page address, image address and browser information, new subscriber email with language, subscription source and referring article | United States | Via webhook immediately on receipt | As in section 1 |
| Google LLC (privacy policy) | Visit statistics (with consent) | Data listed in section 3 | United States | While browsing after cookie consent | Per Google Analytics retention settings |
| Microsoft Corporation (privacy policy) | Session replay and heatmaps (with consent) | Data listed in section 3 | United States | While browsing after cookie consent | Per Microsoft Clarity retention policy |
| Impact Tech, Inc. (privacy policy) | Affiliate performance measurement (with consent) | Data listed in section 3 | United States | While browsing after cookie consent | Per impact.com retention policy |
If you do not want the data you enter to be transferred abroad, do not use the consultation form, newsletter subscription, tutorial email verification or site feedback. Choosing "Decline" in the cookie notice prevents transfers to the analytics tools. Hosting access logs are recorded whenever you open the site, and an automatic image error report (section 1) is sent only when an image fails to load, so the only way to avoid those is not to use the site. The rest of the site remains available if you skip those features.
Modern Web Labs uses Anthropic's API to translate and summarize published articles. Only the article's content and metadata such as its title and excerpt are sent. No visitor or subscriber data is ever sent to an AI service.
5. Disclosure to third parties
Modern Web Labs does not sell personal data and does not disclose it to third parties beyond the processors in section 4 and the connection data passed when the external script (Kakao SDK) in section 3 is requested, except where required by law or by a lawful request from an investigative authority.
6. Your rights and how to exercise them
You may exercise the following rights over your personal data at any time.
- Access
- Correction and deletion
- Suspension of processing
- Withdrawal of consent
Send your request to contact@modernweblabs.com. We reply with the outcome within 10 days of receipt. Where identity must be confirmed, we verify through the email address used in the request. A representative must include a letter of authorization.
Every newsletter issue carries an unsubscribe link that removes you from sending immediately. One-click unsubscribe in email clients is also supported.
The legal guardian of a child under 14 may exercise the same rights on the child's behalf.
7. Deletion
Personal data whose retention period has ended or whose purpose is fulfilled is deleted by the procedure stated in this policy (automatic deletion, or manual deletion at the quarterly review). Deletion requests are handled without delay regardless of that schedule. Data that another law requires us to keep is stored separately for that period and then deleted.
- Database records are deleted irreversibly. On a deletion request, Modern Web Labs also deletes the matching contact by hand in the processor's (Resend) dashboard.
- Consultation, feedback and new-subscriber messages in the inbox and the operations channel are not purged automatically, so Modern Web Labs reviews them every quarter and deletes those past their retention period by hand.
- IP address hashes are purged automatically by the database every day once they are 30 days old.
8. Security measures
Modern Web Labs takes the following measures to keep personal data from being leaked or damaged.
- Row-level security is enabled on every database table, and the visitor-data tables described in this policy (subscribers, verification, client codes, IP hashes) can be read only through the administrator session or the server-side key.
- Tutorial email verification codes and IP addresses are stored as hashes, never in the original form.
- The client-only content cookie (mwl_premium) is signed to prevent forgery, and the cookies that grant access (mwl_premium, mwl_email) are flagged HttpOnly so scripts cannot read them. The hint cookies (mwl_premium_hint, mwl_admin_hint) are script-readable but grant no access.
- All traffic is encrypted with HTTPS. The administrator account is used by the founder alone and protected by a password.
- Request rates are limited to block automated form submissions.
- Authentication-related parameters are stripped on the server from page addresses sent with feedback.
9. Children's data
The site is intended for companies and practitioners, not for children under 14. If we learn that we have collected a child's data, we delete it without delay.
10. Privacy officer
The person responsible for personal data processing, inquiries and complaints is listed below. There is no separate department or telephone desk. Every request, including access, correction, deletion and suspension requests, is received at the email address below.
- Name: Bora Lee (Founder, Modern Web Labs)
- Email: contact@modernweblabs.com
You may also contact the following Korean authorities to report or discuss a privacy violation.
11. Changes to this policy
This policy takes effect on September 18, 2026. Changes are posted on this page together with their effective date. Changes that affect your rights, such as new data items or new processors, are announced on the site at least 7 days before they take effect.