Privacy Policy
EE-UT (이웃, the "Company") complies with the personal information protection provisions of applicable laws, including the Personal Information Protection Act, the Act on Consumer Protection in Electronic Commerce, and the Act on Promotion of Information and Communications Network Utilization and Information Protection, and establishes and discloses this Privacy Policy as follows in order to process users' personal information safely. When the Company revises this Privacy Policy, it announces the revision through website notices (or the first screen of this policy).
This Privacy Policy provides information related to the Company's processing of personal information, explains the rights held by customers and how those rights can be exercised, and provides the contact information of the privacy officer and the person in charge whom you can contact with any personal-information inquiries arising while using our services.
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the following purposes, and the personal information being processed is not used for any purpose other than the following. If the purpose of use changes, the Company will implement necessary measures, such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
- Membership registration and management: identifying members via email/Google accounts, identity verification, prevention of fraudulent use of the service, confirmation of intent to withdraw membership
- Provision of reservation/purchase services and voucher issuance: verifying the identity of the user (reserver), confirming reservation details, issuing and sending QR-code-based mobile vouchers, processing reservation changes and cancellations
- Provision of attraction/spot recommendation services: personalized spot recommendations (cafes, beauty shops, restaurants, etc.) based on the user's usage history and interests (* The user's current location information is not collected, and no location-based technology such as GPS is used)
- Payment processing and settlement: processing payments through the PG, handling payment approvals, cancellations, and refunds, managing transaction records
- Customer consultation and complaint/dispute handling: receiving and processing inquiries and complaints, notifying the results of processing
- Fulfillment of legal obligations: record retention under the E-Commerce Act and other applicable laws, dispute response, prevention of fraudulent transactions
Article 2 (Items of Personal Information Processed)
The Company collects only the items below for the provision of the service and does not collect any other information.
1. Items processed with the consent of the data subject
- Email sign-up: email address, password (stored encrypted) — collected at sign-up, with the data subject's consent (Article 15(1)1 of the Personal Information Protection Act)
- Google social login (linking): email address, profile information (name) — collected when linking a Google account, received from Google LLC based on the data subject's consent (Article 15(1)1 of the Personal Information Protection Act)
- Purchase and reservation/voucher issuance: user (reserver) name, mobile phone number — collected when applying for a reservation/purchase, for the conclusion and performance of a contract (Article 15(1)4 of the Personal Information Protection Act)
※ All services provided by the Company are non-physical products issued in the form of mobile vouchers, and no address information for delivery is collected.
2. Information the Company does not collect
- The Company does not collect users' current location information (GPS, etc.) when providing attraction/spot recommendation services. Spot recommendations are provided based on interests directly entered by the user, service usage history, and the like, and are not based on real-time location data.
- Card payment information such as credit card numbers, card expiry dates, and CVC is collected and processed directly by the payment gateway (PG), and is not stored on the Company's servers. The Company receives from the PG only payment-related transaction records, such as the payment date and time, transaction (approval) amount, payment method, and the PG-issued transaction number (approval number), for the purpose of confirming payment completion and managing transactions, and retains them for the periods prescribed by applicable laws. (See Article 4)
3. Information automatically generated and collected during service use
In the course of using the service, IP address, access logs, cookies, service usage records, and device information (OS, browser type, etc.) may be automatically generated and collected. (See Article 9)
Article 3 (Processing and Retention Period of Personal Information)
① The Company processes and retains personal information within the retention and use period prescribed by law or the retention and use period consented to by the data subject at the time of collection.
② The processing and retention periods for each type of personal information are as follows.
- Member information (email, password, Google profile information, etc.): until membership withdrawal (however, if an investigation or inquiry into a violation of applicable laws is in progress, until that procedure is concluded)
- Records on contracts or withdrawal of offers: 5 years (Article 6(1)3 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce)
- Records on payment and the supply of goods (payment date and time, transaction amount, etc.): 5 years (Article 6(1)3 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce)
- Records on consumer complaints or dispute handling: 3 years (Article 6(1)4 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce)
- Records on display and advertising: 6 months (Article 6(1)1 of the Enforcement Decree of the Act on Consumer Protection in Electronic Commerce)
- Login records (communication confirmation data): 3 months (Protection of Communications Secrets Act)
- Books and supporting documents on transactions such as tax invoices: 5 years (Framework Act on National Taxes)
③ The Company destroys the relevant personal information without delay when the above retention period elapses or the purpose of processing is achieved.
Article 4 (Procedure and Method of Destroying Personal Information)
① The Company destroys personal information without delay when it becomes unnecessary, such as upon the elapse of the retention period or the achievement of the purpose of processing.
② If personal information must continue to be preserved under other laws despite the elapse of the retention period consented to by the data subject or the achievement of the purpose of processing, the Company moves the personal information to a separate database (DB) or preserves it in a different storage location.
③ Destruction procedure: The Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of the Company's privacy officer.
④ Destruction method: Personal information recorded and stored in electronic file format is deleted using technical methods that make the records unrecoverable, and personal information recorded and stored in paper documents is destroyed by shredding or incineration.
Article 5 (Provision of Personal Information to Third Parties)
The Company, in principle, processes the data subject's personal information within the scope specified in Article 1 (Purposes of Processing), and provides personal information to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as with the data subject's consent or under special provisions of law.
Currently, the Company does not separately provide personal information to third parties in connection with payment processing; related tasks are handled through the outsourcing of personal information processing under Article 6.
Article 6 (Outsourcing of Personal Information Processing)
① For the smooth handling of personal information tasks, the Company outsources personal information processing as follows.
- Trustee: KG INICIS
Outsourced tasks: provision of electronic payment gateway services, payment approval, processing of payment cancellations and refunds
Personal information items entrusted
: user (reserver) name, mobile phone number, payment (transaction) amount, payment method, order number, and other information necessary for payment processing※ Actual payment information such as credit card numbers, card expiry dates, and CVC is collected and processed directly by KG INICIS,
and the Company does not store it. - Trustee: FlareLab (플레어랩)
Outsourced tasks: development, operation, and maintenance of the service (mobile web) system,
with access in that process to the database (DB) storing member information and reservation information
② When concluding an outsourcing contract, the Company specifies in the contract or other documents, in accordance with Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information for purposes other than performing the outsourced tasks, technical and managerial protective measures, restrictions on re-outsourcing, management and supervision of the trustee, and liability such as damages, and supervises whether the trustee processes personal information safely.
③ If the contents of the outsourced tasks or the trustee changes, the Company discloses this without delay through this Privacy Policy.
Article 7 (Overseas Collection and Transfer of Personal Information)
① The Company collects, transfers, stores, or processes users' personal information overseas as follows for the provision of the service.
- Google social login
- Recipient of the transfer: Google LLC
- Country of transfer: United States
- Timing and method of transfer: transmitted via information and communications networks at the time the user signs up or logs in with a Google account
- Personal information items transferred: email address, profile information (name), information necessary for login identification and authentication
- Purpose of transfer: Google-account-based sign-up and login, account linking and member identification
- Retention and use period: until membership withdrawal or until the Google account is unlinked. However, Google LLC's processing period follows that provider's policies.
② The Company complies with the Personal Information Protection Act and other applicable laws in connection with the overseas transfer of personal information,
and takes necessary protective measures so that personal information can be managed safely.
③ If matters related to overseas transfer change,
the Company will disclose them without delay through this Privacy Policy.
Article 8 (Measures to Ensure the Safety of Personal Information)
The Company takes the following measures to ensure the safety of personal information.
- Managerial measures: establishment and implementation of an internal management plan, minimization of and training for staff handling personal information
- Technical measures: management of access rights to personal information processing systems and the like, installation of access control systems, encryption of personal information such as passwords, prevention of hacking using antivirus software and the like, application of encrypted communication (SSL) when transmitting and receiving personal information
- Physical measures: access control to computer rooms, data storage rooms, and the like
Article 9 (Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
① The Company may use 'cookies', which store and periodically retrieve usage information, in order to provide users with personalized services.
② Purpose of using cookies: providing personalized services by analyzing users' access frequency and visit times, identifying users' tastes and areas of interest, and tracking participation in various events and number of visits
③ Users have the right to choose whether to allow the installation of cookies, and may allow all cookies, require confirmation each time a cookie is stored, or refuse the storage of all cookies by configuring options in their web browser. However, refusing the storage of cookies may cause difficulties in using some services.
Article 10 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)
① A data subject may exercise the following personal-information-protection rights against the Company at any time.
- Request for access to personal information
- Request for correction in case of errors or the like
- Request for deletion
- Request for suspension of processing
② The exercise of rights under Paragraph 1 may be made to the Company in writing, by email (support@ee-ut.com), or by other means, and the Company will take action without delay.
③ If a data subject requests the correction or deletion of errors or the like in personal information, the Company does not use or provide the relevant personal information until the correction or deletion is completed.
④ Rights may be exercised through an agent, such as the data subject's legal representative or a delegated person, in which case a power of attorney in the form of Attachment No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
Article 11 (Privacy Officer)
The Company designates a privacy officer as follows, who bears overall responsibility for personal information processing tasks and handles data subjects' complaints and damage relief related to personal information processing.
- Privacy officer: Jihyun Lee (CEO)
- Contact (email): support@ee-ut.com
Data subjects may direct all personal-information-protection-related inquiries, complaint handling, damage relief, and other matters arising from using the Company's services to the privacy officer. The Company will respond to and handle data subjects' inquiries without delay.
Article 12 (Remedies for Infringement of Data Subjects' Rights and Interests)
Data subjects may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and other bodies in order to obtain relief from personal information infringement. For other reports or consultations regarding personal information infringement, please contact the following organizations.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 without area code (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cyber Crime Investigation Unit: 1301 without area code (www.spo.go.kr)
- National Police Agency Cyber Investigation Bureau: 182 without area code (ecrm.cyber.go.kr)
Article 13 (Changes to This Privacy Policy)
This Privacy Policy applies from its effective date, and when there are additions, deletions, or corrections to its contents pursuant to laws or policies, the changes will be announced through the website from at least 7 days before they take effect.
Addendum
These Terms are announced on July 29, 2026 and take effect on July 29, 2026.
- Date of announcement: July 29, 2026
- Effective date: July 29, 2026
