Privacy
Privacy notice
Last updated: 24 August 2026
Who I am
Yunseon Hong, a sole developer. ondelva is a personal project, not a registered company. I am the controller for the personal data described here. You can reach me at im@ondelva.com, and I will give a postal address on request. Korean law wants a named person accountable for how personal data is handled; on a one-person project that is the same person, so it is me at the same address.
What this notice covers
This site, ondelva.com: the tools that run on it, the blog, and any mail you send me. Hot Deal Sheet lives on its own domain, so once you follow that link you are on a different site and this notice stops applying.
The tools themselves collect nothing
The QR code generator runs entirely in the tab in front of you. What you type into it, a link, a Wi-Fi password, a contact card, is turned into a code by JavaScript on your own device and is never sent to me or to anyone else. An image you drop in as a logo is read by the browser and drawn straight into the code rather than uploaded. There is no server side to any of this, which is also why there is nothing for me to keep, lose, or be asked to hand over.
The same is true of the two PDF tools. A file you drop into the PDF merger or the PDF to PNG converter is read by your own browser, joined or redrawn there, and handed back from that same tab. It is never uploaded, so no copy of it exists anywhere for me to hold. You can watch your browser's network panel while you use either one and see for yourself that nothing leaves.
What the site collects, and why
| Data | Why | Lawful basis | Kept for |
|---|---|---|---|
| Page views: the page, where you came from, browser, operating system, device type, and the country your address resolves to | To see which tools and posts are actually used, so I know what to keep working on | Legitimate interests (GDPR Art. 6(1)(f)) | Held by Umami under its own retention; I keep no separate copy |
| Your IP address, in transit | Cloudflare needs it to route the page to you and to turn away hostile traffic. Umami reads a country from it | Legitimate interests (Art. 6(1)(f)) | Cloudflare's own log retention. It is not stored by me, and Umami states it stores no personally identifiable information |
| Email correspondence, if you write to me | To answer you | Legitimate interests (Art. 6(1)(f)) | 24 months |
There is no account to make, no signup form, and no mailing list, so nothing here asks for your name. I run no advertising, I do not sell personal data, and I do not share it for anyone else's marketing. That is how things stand today rather than a promise about next year; if it changes, this page changes before the change goes live.
Cookies
The site sets no cookies and the analytics script does not use any, which is why you are not being asked to dismiss a banner. One thing is stored on your device: an entry called monograph-theme in local storage, holding whether you picked light or dark mode. It never leaves your browser and it is only there because you asked for it, so it needs no consent either. Clearing site data removes it.
Who else sees it
- Cloudflare, Inc. serves this site and every request for a page passes through it. Processor.
- Umami Software, Inc. counts page views. Cookieless, and it says it stores nothing that identifies a person and does not track anyone across sites. Processor.
- Google hosts my mail, so any message between us sits in that mailbox. Processor.
Where it is processed
I am in South Korea, so that is where anything you send me is read and acted on. Both the UK and the EU have decided that South Korea offers an adequate level of protection, which means that leg needs no further safeguard: the European Commission's adequacy decision of 17 December 2021, and the Data Protection (Adequacy) (Republic of Korea) Regulations 2022 on the UK side.
The processors sit elsewhere, and Korean law asks me to set each one out in full rather than in summary, so here they are.
| Who | Where, and how it gets there | What is sent | Why, and for how long | Transfer rests on |
|---|---|---|---|---|
| Cloudflare, Inc. legal@cloudflare.com | United States, and the edge locations it runs worldwide. Sent automatically the moment your browser asks for a page | IP address, time of the request, the page requested, browser and device details | To serve the site and turn away hostile traffic. Held under Cloudflare's own log retention while the arrangement lasts | EU Standard Contractual Clauses and the UK Addendum, in its data processing addendum |
| Umami Software, Inc. hello@umami.is | United States and the EU. Sent when the analytics script runs on a page you open | The page address, where you came from, browser, operating system, device type and screen size, and the country read from your IP address. On the tool pages, also that a result was taken away, with a count or a setting alongside it: which kind of QR code was downloaded or copied and whether it carried a logo, how many files and pages went into a merge, how many pages came out of a PDF to PNG conversion and at which resolution. Never what you typed into a form, and never a file name or anything from inside a file | To count page views and see which tools get used. Held under Umami's own retention | EU Standard Contractual Clauses and the UK Addendum, in its data processing addendum |
| United States and other countries it runs data centres in. Sent when either of us emails the other | Your email address, and whatever the message and its attachments contain | To send, receive and hold mail. 24 months from receipt | The Cloud Data Processing Addendum, with the European terms applied |
If you would rather none of this happened. Cloudflare cannot be refused separately, because it is how the page reaches you at all; not visiting the site is the only way to avoid it. Umami you can refuse by blocking cloud.umami.is in any content blocker, and the tools keep working when you do, because the encoder is a different file that never talks to it. Google you avoid by not emailing me. Refusing costs you nothing beyond the thing refused.
Your rights
You can ask me for a copy of the data I hold about you, ask me to correct or delete it, object to how I use it, or withdraw consent. Given the scale of this, the fastest route is to email me and I will act on it. I have to respond within one month.
Korean law gives you the same set in its own words, since that is where I am: under the Personal Information Protection Act you may ask to see what I hold, have it corrected or deleted, or have the processing stopped. I answer within ten days there rather than a month, so that is the deadline I work to for everyone.
If you are unhappy with how I handle it, you can complain to the supervisory authority in your own country, to the Information Commissioner's Office (ico.org.uk) in the UK, or to the Personal Information Protection Commission in South Korea (pipc.go.kr).
Using the tools
The closest thing here to terms, and it is short. The tools are offered as they are, with no warranty and no promise that a given result is fit for what you need it for. A QR code is cheap to test and expensive to reprint, so scan the one you made before you commit it to paper. Do not use anything here to encode a link you would not want traced back to you: malware, phishing, or anything else unlawful where you are. If a tool is going to start costing money or go away, its own page says so before it happens.
Changes
The date at the top moves when this changes. If a change affects what leaves your browser rather than just the wording, the tool page it affects says so too.