Ktown4u Privacy Policy
- General Provisions
① Ktown4u (hereinafter referred to as the “Company”) complies with all applicable laws and regulations related to the protection of personal information, including the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and the Communications Secrets Protection Act.
② The Company does not use users’ personal information for purposes other than those for which it was originally collected. Personal information is processed and retained within the period stipulated by applicable laws or agreed upon by the user at the time of collection.
- Personal Information Collected and Purpose of Use
The Company collects and uses personal information for the following purposes. If the purpose of use changes, necessary measures such as obtaining additional consent will be taken.
The Company does not collect or use personal information of children under the age of 14.
| Legal Basis | Category | Purpose | Items | Retention Period |
|---|---|---|---|---|
| Personal Information Protection Act Article 15(1)4 (Contract execution) | Membership Registration | Use of Ktown4u website, mileage accumulation and usage, provision of information related to services (notices, inquiries, complaint handling, etc.), verification of whether the user is under 14 | (Required) Email (ID), Password, Name, Date of Birth | Until membership withdrawal |
| Personal Information Protection Act Article 15(1)1 (Consent) | App Users | Device identification and app push notifications (advertising) | (Optional) Device ID | Until membership withdrawal or withdrawal of consent to receive advertising information |
| Personal Information Protection Act Article 15(1)4 (Contract execution) | Services | Orders, delivery, returns, after-sales service (AS) | (Required) Orderer name, Recipient name, Shipping address, Phone number, Email | 5 years from completion of service provision and payment/settlement |
| Personal Information Protection Act Article 15(1)4 (Contract execution) | Payment | Payment processing, refunds | (Required) Bank account information, Payment information | 5 years from completion of service provision and payment/settlement |
| Personal Information Protection Act Article 15(1)1 (Consent) | Events | Participation in Ktown4u events | (Required) Name, Date of Birth, Phone number, Email, Address, KakaoTalk ID, WeChat ID | |
| (Optional) Photo including ID (sensitive identification numbers are masked) | Within 90 days after delivery of event-related products |
- Outsourcing of Personal Information Processing
The Company entrusts the processing of personal information to external parties as follows in order to provide better services and enhance customer convenience.
When entering into outsourcing agreements, the Company specifies in written contracts matters such as prohibition of processing personal information beyond the scope of the entrusted purpose, implementation of technical and administrative safeguards, restrictions on re-outsourcing, supervision and management of the entrusted party, and liability including compensation for damages, in accordance with Article 26 of the Personal Information Protection Act. The Company also supervises whether the entrusted parties handle personal information securely.
| Purpose of Outsourcing | Service Provider |
|---|---|
| Payment processing for ordered products | KG Inicis, Toss Payments, Eximbay, ICB, PayPal |
| Email service | |
| Stibee | |
| SMS service | BloomAI, HumusOn |
| Customer support (CS) | Channel Corporation |
| Product delivery | CJ Logistics, FBK Co., Ltd. (Subcontractors: Sagawa, SF Express, Korea Post, ACI, Doora Logistic, YTO Express, UPS, FedEx), DHL |
| Data storage and infrastructure management | Amazon Web Services, Inc. |
- Provision of Personal Information to Third Parties
The Company may provide users’ personal information to third parties in accordance with applicable laws and regulations, either with the user’s consent or where there are special provisions under other laws, following lawful procedures prescribed by such laws.
In addition, in cases of emergencies such as disasters, infectious diseases, incidents or accidents posing imminent risks to life or physical safety, or urgent threats of property loss, the Company may provide personal information to relevant authorities without the user’s consent.
The status of third-party provision of personal information is as follows:
| Recipient | Purpose of Provision | Information Provided | Retention and Use Period |
|---|---|---|---|
| Event organizers | Event application and participation | Name, Date of Birth, Phone number | Within 30 days after the end of the event |
- Overseas Transfer of Personal Information
The Company transfers personal information overseas as described below in order to enhance user convenience and provide services.
Users may refuse the collection of information and the overseas transfer of personal information; however, refusal may result in restrictions on the use of certain services.
| Legal Basis | Items Transferred | Transfer Method | Recipient Country & Company | Purpose of Transfer | Retention Period | Method of Refusal |
|---|---|---|---|---|---|---|
| Personal Information Protection Act Article 28-8(1)3 (Outsourcing/Storage) | IP address, Device ID, Device model name, OS information, Service usage information, Access records | Transferred from time to time via information and communications networks during service provision | (USA) Google Inc. / Google LLC Privacy Team | |||
| googlekrsupport@google.com | Analysis of user behavior and identification of promotion targets, Improvement of application functionality | Until membership withdrawal or termination of service agreement | Consent may be withdrawn through the methods described in “9. Installation, Operation, and Refusal of Automatic Collection Devices.” Refusal may result in limitations on promotion-related services. | |||
| Personal Information Protection Act Article 28-8(1)1 (Consent) | Payment information (Name, Email, Address, Country, Phone number) | Transmitted in real time via encrypted internet API at the time of overseas payment | (USA) PayPal | |||
| paypal@generalagent.co.kr | Use of overseas payment services | Up to 5 years from the transaction completion date | Personal information is not transferred overseas unless overseas payment is made. Refusal is possible; however, overseas payment will not be available. | |||
| Personal Information Protection Act Article 28-8(1)3 (Outsourcing/Storage) | Order information (Name, Email, Address, Country, Phone number)) | Transmitted in real time via encrypted internet API upon completion of overseas order | (China) YTO Express | |||
| 032-573-9555 | ||||||
| (Japan) SAGAWA | ||||||
| 03-4221-4290 | ||||||
| (Germany) DHL | ||||||
| koreabill@dhl.com | ||||||
| (USA) UPS | ||||||
| customer.service@ups.com | ||||||
| (China) SF-EXPRESS | ||||||
| kr_privacy@sf-express.com | Overseas product delivery | Up to 5 years from the transaction completion date | Personal information is not transferred overseas unless an overseas order is made. Refusal is possible; however, overseas delivery will not be available. |
- Retention and Use Period of Personal Information
The Company retains and uses users’ personal information for the period disclosed and agreed upon by the user.
Personal information will be destroyed in such a way that it cannot be accessed or used once the purpose of collection and use has been fulfilled, the retention period has expired, or consent has been withdrawn.
However, in cases where prior consent has been obtained from the data subject or where retention is required under applicable laws and regulations, personal information may be retained for a certain period as follows.
In the event of withdrawal of consent or membership termination, such information will be stored separately.
| Retained Items | Retention Period | Relevant Laws |
|---|---|---|
| Service usage records, access logs, access IP information, cookies | 3 months | Communications Secrets Protection Act |
| Records related to display/advertising | 6 months | Act on Consumer Protection in Electronic Commerce, etc. |
| Records related to consumer complaints or dispute resolution | 3 years | |
| Records related to contracts or withdrawal of subscription | 5 years | |
| Records related to payment and supply of goods | 5 years |
- Procedures and Methods for Destruction of Personal Information
① The Company will promptly destroy personal information in accordance with “6. Retention and Use Period of Personal Information” when such information becomes unnecessary due to the expiration of the retention period or the achievement of the purpose of processing.
② Personal information printed on paper will be destroyed by shredding or incineration, and personal information stored in electronic file form will be deleted using technical methods that prevent the records from being restored.
③ In cases where the retention period agreed upon by the data subject has expired or the purpose of processing has been achieved, but the personal information must be retained in accordance with other applicable laws, such information will be transferred to a separate database (DB) or stored in a different location and retained accordingly.
- User Rights and Methods of Exercise
① Users may access or modify their registered personal information at any time and may also request membership withdrawal.
For access or modification, users may use the “Edit Personal Information” (or “Account Settings”) menu. For membership withdrawal, users may click “Withdraw Membership” and complete the identity verification process to directly view, correct, or delete their information.
In addition, in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, users may request access, transmission, correction, deletion, suspension of processing, or withdrawal of consent regarding their personal information via written request, telephone, or email. Such requests may be processed through the department below.
▶ Department for Handling Requests Related to Personal Information Rights
Department: Management Team
Address: Trade Tower #305-1, 511 Yeongdong-daero, Gangnam-gu, Seoul, Korea
Contact: +82-2-552-9855 / privacy@ktown4u.com
② If a user requests correction of errors in their personal information, the Company will not use or provide such information until the correction is completed. If incorrect personal information has already been provided to a third party, the Company will promptly notify the third party of the correction to ensure that it is properly updated.
③ Personal information that has been terminated or deleted at the request of the user will be processed in accordance with “6. Retention and Use Period of Personal Information” and will not be accessed or used for any other purposes.
- Installation, Operation, and Refusal of Automatic Collection Devices
① Use of Cookies
- The Company’s website uses cookies for user authentication.
- Cookies are small data files sent by an HTTP server to the user’s browser, which help verify the user between the website and the user’s computer.
- The Company uses cookies to identify information related to user IDs in order to provide more relevant and useful services.
- Users may choose whether to allow the use of cookies. By adjusting browser settings, users may allow all cookies, confirm when cookies are stored, or refuse all cookies. However, if all cookies are refused, some services requiring login may not be available.
② How to Refuse Cookie Collection in Web Browsers
Edge: Menu > Settings > Cookies and site permissions > Manage and delete cookies and site data > Enable “Block third-party cookies”
Chrome: Menu > Settings > Privacy and security > Third-party cookies > Enable “Block third-party cookies”
Safari: Preferences > Enable “Prevent cross-site tracking” and “Block all cookies”
③ How to Enable/Disable Advertising Identifiers on Smartphones
Android: Settings > Security & Privacy > Privacy > More privacy settings > Ads > Reset advertising ID or Delete advertising ID
iPhone: Settings > Privacy & Security > Tracking > Disable “Allow Apps to Request to Track”
※ Menu names and steps may vary depending on the mobile OS version.
④ Push Notifications
- The Company sends benefits, event information, and product recommendations via push notifications to users who have consented to receive advertising information.
- Users may change their push notification preferences at any time in the app under [My Page > Notification Settings].
- For the purpose of providing smooth services, the Company collects and stores the user’s push notification consent status and device identification information (Device Token) on its servers.
⑤ How to Disable Push Notifications
Ktown4u App: Log in > My Page > Notification Settings > Turn OFF push notifications
- Measures to Ensure the Security of Personal Information
① Technical Safeguards
- The Company operates security systems related to servers and networks and conducts regular vulnerability inspections and improvements.
- The Company has implemented web firewall systems to ensure the protection of users’ personal information.
- Users’ personal information is stored and managed in encrypted form in accordance with applicable laws, and files and transmitted data are also encrypted.
- The Company controls access to personal information by granting, modifying, and revoking access rights to personal information processing systems.
- Access records to personal information processing systems are managed in accordance with applicable laws, and security measures are in place to prevent forgery, alteration, theft, or loss of such records.
- The Company installs security solutions such as antivirus software on employees’ PCs handling personal information and updates them in real time to protect against threats such as malware.
② Administrative Safeguards
- The Company operates its services under an information security management system certified by external professional organizations to ensure the safe protection of personal information.
- The Company limits the number of personnel who can handle users’ personal information to the minimum necessary.
- The Company has established and enforces internal policies to ensure that employees understand and comply with procedures related to access and management of personal information, and conducts regular training on personal information protection.
- The Company establishes and implements internal management plans to ensure the safe processing of personal information.
③ Physical Safeguards
- The Company protects key infrastructure by installing and operating security systems in areas with restricted and controlled access.
- The Company strictly controls the use of storage media containing personal information and restricts external transfer.
- The Company establishes and implements protective measures to prevent leakage or exposure of personal and sensitive information in the workplace, including office PCs, desks, and storage areas.
- Data Protection Officer and Contact Information
The Company has designated the following Data Protection Officer and personnel in charge, who will respond promptly and sincerely to inquiries regarding personal information.
① Data Protection Officer
Name: Baek Myung-seok
Department: System Development Division
Tel: +82-2-552-9855
Email: privacy@ktown4u.com
② Person in Charge of Personal Information Protection
Name: Kim Si-yeon
Department: Management Team
Tel: +82-2-552-9855
Email: privacy@ktown4u.com
If you require reporting or consultation regarding personal information infringement, please contact the following organizations:
① 개인정보 분쟁조정위원회 : 1833-6972 (www.kopico.go.kr)
② 개인정보 침해신고센터 : 118 (privacy.kisa.or.kr)
③ 대검찰청 사이버수사과 : 1301 (www.spo.go.kr)
④ 경찰청 사이버수사국 : 182 (ecrm.police.go.kr)
- Miscellaneous
In the event of additions, deletions, or modifications to this policy due to changes in laws or internal policies, such changes will be announced through the notice section on the homepage at least 7 days prior to the effective date.
However, in the case of significant changes affecting users’ rights or obligations, prior notice will be provided at least 30 days in advance.