Skip to main content
FIRST RIDE, BIG SMILE ✦ A first balance bike for little riders

TinyRolly support

TinyRolly Privacy Policy

Effective date
September 7, 2026

1. Purposes of Processing

The Company processes only information necessary for these purposes. If a purpose changes, the Company obtains separate consent or updates this Policy as required by PIPA.

  • Registration, login, account security, consent records, and abuse prevention
  • Orders, payment, delivery, cancellation, exchange, returns, refunds, and transaction evidence
  • Membership tiers, coupons, points, review rewards, child-birthday benefits, and referrals
  • Product Q&A, customer support, disputes, complaints, and necessary notifications
  • Service security, access records, incident response, and legal duties
  • Email or SMS marketing and analytics only after separate consent

2. Categories of Personal Information

  • The Company does not directly store card numbers, CVCs, easy-payment passwords, or Korean resident registration numbers.
  • The Company does not collect a child’s name, birth year, full date of birth, or resident registration number.
  • Phone identity verification is not currently implemented. Birthday and referral benefits operate without it using account-level safeguards. Data and recipient relationships will be disclosed before any future introduction.

Information processed by service

Information processed by service
ServiceRequired or actually processedOptional or conditional
Email accountEmail, password hash, registration and consent time and policy version, session and security recordsMarketing consent
Social signupIdentifier and verified email from an enabled provider, provider/link history, required signup consentAdditional email verification when the provider supplies no email
Order and deliveryBuyer account, recipient name and phone, postal code and address, delivery instructions, items, amount, delivery, and claim recordsSaved-address label
Payment and refundOrder number, payment method, payment provider transaction ID, approval/cancellation/refund amount and currency, time, status, and receipt linkNone
Child-birthday benefitGuardian declaration and consent record; month and day for one childNone
Reviews, Q&A, supportAuthor account, product/order link, rating, text, image, inquiry, answer, status, and support languageContent a user voluntarily enters in a public post
Member benefitsTier, coupon and point ledger, referral relationship, birthday benefit, review award and dispatch recordPhone registered to the member account
Use and securityIP, access time, request ID, device/browser data, login failure, admin access, and consent-change recordsAnalytics and marketing cookies after separate consent

3. Retention and Use Periods

The Company destroys information when its purpose is achieved or the account is closed. Records required by law are separated from active account data and retained only for their statutory purpose.

A lawful preservation order may delay destruction for its duration. Information is destroyed promptly when the reason ends.

Retention under law and operating policy

Retention under law and operating policy
RecordPeriodBasis
Advertising and display records6 monthsKorean E-Commerce Act
Contracts and withdrawal records5 yearsKorean E-Commerce Act
Payment and supply records5 yearsKorean E-Commerce Act
Consumer complaints and disputes3 yearsKorean E-Commerce Act
Personal information system access logs1 year, or 2 years where the statutory condition appliesKorean security-measures standard
Profile, saved address, and child-birthday dataUntil purpose completion or account closureService contract and consent
Minimum identifier for re-registration restriction6 months after closureContract and abuse prevention
CloudFront minimum-field raw logs90 days by defaultSecurity and incident-response policy

4. Provision to Third Parties

The Company uses personal information only within the disclosed purposes and provides it to a third party only with consent or another basis under Articles 17 and 18 of PIPA.

Where payment or delivery requires provision, the actual recipient, purpose, items, retention, and applicable consent are presented at checkout or in a separate notice.

The Company buys monthly best-review gifts itself and manually sends them to the phone registered to the winning account. It does not give the gift retailer customer information.

5. Processing Outsourcing and Overseas Transfers

The Company uses the following service providers only to the extent needed to provide the relevant feature and transfers only the minimum information required when a user uses that feature.

A feature involving overseas processing or transfer may be unavailable if the user does not use it or withdraws an applicable consent. The Company keeps recipient, country, data, purpose, and retention details aligned with its contracts and service settings.

Processors and external services

Processors and external services
Service providerProcessing taskScope
Amazon Web ServicesDatabase, object storage, content delivery, logging, email delivery, and support translation infrastructureOnly as needed to operate the service and handle requested support
PayPal (PayPal Pte. Ltd. and its affiliates, Singapore and United States)USD payment, cancellation, refund, and receipts for the English storeOrder number, amount, and the payment status data PayPal returns; the Company never receives card numbers. Involves transfer of order data outside the Republic of Korea when a user pays
Toss Payments Co., Ltd.Card, Toss Pay, Kakao Pay, and Naver Pay payment, cancellation, refund, and receiptsKorean store only, when a user requests payment there
International and domestic carriers selected per order (including Hanjin and CJ Logistics)Delivery, customs handling, and collectionRecipient name, phone, address, and parcel data sent only to the carrier selected for the order; international delivery transfers this data to the destination country
Google, Kakao, or NAVERSelected social signup and loginOnly the provider selected by the user
CloudflareAutomated-request and abuse preventionOnly requests using the security verification feature
Google (YouTube)Privacy-enhanced external videoOnly when the user chooses to play external video

6. Destruction Procedure and Method

  • A daily job removes information whose purpose or retention period has ended and records success, failure, and lawful exceptions.
  • Statutory records are separated from active account data and access-restricted.
  • Electronic files are deleted so recovery is impracticable; paper is shredded or incinerated.
  • Backups expire under their lifecycle and deleted information is removed again if a backup is restored.

7. Rights of Data Subjects and Representatives

  • A data subject may request access, correction, deletion, suspension, withdrawal of consent, and account closure.
  • Requests may be submitted through available account controls, cscenter@maechorom.com, +82 70-7677-7997, or the postal address below.
  • The Company verifies identity only as necessary and handles properly authorized representative requests under Korean law.
  • A lawful restriction, extension, or refusal is explained together with an appeal route.
  • Where the statutory right to data portability applies, the Company follows the required process and period and will announce formats and history checks when the applicable scope and standards are confirmed.

8. Children and Child-Birthday Data

Registration includes confirmation that the user is at least 14. The Company does not register a child under 14 as an independent member.

A birthday benefit processes only the month and day of one child after an adult member declares legal guardianship and consents. It does not store the child’s name, birth year, or full date of birth. Deletion or withdrawal ends future benefits and triggers destruction.

9. Cookies and Refusal Controls

Essential cookies and browser storage support login, security, consent choices, and carts. Analytics and marketing cookies are not requested, stored, or run before the corresponding optional consent. Choices can be changed through Cookie settings in the footer.

The Company does not assume current use of mobile advertising identifiers (ADID/IDFA) or targeted-ad pixels. Before introduction, this Policy will state the collector, purpose, items, retention, and opt-out method.

Browser controls

  • Chrome: Settings → Privacy and security → Third-party cookies
  • Safari: Settings → Privacy → Manage Website Data or Block all cookies
  • Edge: Settings → Cookies and site permissions → Manage cookies and site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Blocking every cookie may prevent essential login and cart functions.

10. Security Measures

  • Administrative: internal management plans, minimum staffing, access review, and training
  • Technical: role-based least privilege, administrator MFA and reauthentication, encryption in transit and at rest, password hashing, access and audit logs, upload validation and malware scanning, backup and recovery, and vulnerability management
  • Physical: access control for facilities and media containing personal information
  • Log minimization: no card number, authentication token, password, or unnecessary raw phone/address data in application logs

11. Data Protection Officer and Grievance Contact

Business and privacy contact

Business and privacy contact
ItemDetails
ControllerMaechorom Co., Ltd.
Representative, final privacy-responsible person, and Data Protection OfficerJuhyun Seok
Business Registration No.495-81-02660
Mail-order Business Registration No.2023-Jeonnam Yeosu-0038
AddressSuite 920, Desian Flex Knowledge Industry Center, 424 Yangcheon-ro, Gangseo-gu, Seoul, Republic of Korea
Phone+82 70-7677-7997
Emailcscenter@maechorom.com
Support hoursWeekdays 10:00–17:00, lunch 12:30–13:30; closed weekends and public holidays

12. Privacy Request Department

The Data Protection Officer and customer-support contact receive and handle access and other privacy requests at cscenter@maechorom.com, +82 70-7677-7997, or Suite 920, 424 Yangcheon-ro, Gangseo-gu, Seoul, Republic of Korea.

13. External Remedies

These agencies are independent from Company support. A data subject may contact the Company first or separately seek consultation, reporting, or mediation.

  • Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
  • KISA Personal Information Infringement Report Center: 118, privacy.kisa.or.kr
  • Supreme Prosecutors’ Office: 1301, www.spo.go.kr
  • Korean National Police Agency: 182, ecrm.police.go.kr

14. Automated Decisions and Review

Duplicate or abusive referral, review, or birthday benefits may be assessed by predefined rules using account, transaction, and benefit ledgers. This is rules-based processing, not an AI training model.

A user whose benefit is held or rejected may request the reason, an explanation, or human review through support. The Company does not determine a legal or similarly significant effect solely by automated processing.

15. Representative Responsibility and Breach Response

The representative bears final responsibility for supporting privacy personnel, budget, and internal controls. If the Company becomes aware of loss, theft, leakage, forgery, alteration, damage, or a likely occurrence, it investigates and contains it without delay and gives notices and reports required by Korean law, including available remedies and dispute-mediation routes.

16. Changes to This Policy

  • Effective date: September 7, 2026
  • Revision history: first effective version on August 30, 2026
  • Revision history: customer service lunch hours corrected to 12:30–13:30 on September 7, 2026
  • General changes are announced 7 days in advance; materially unfavorable changes are announced 30 days in advance. Separate consent is obtained where required.
  • If the English and Korean versions differ in meaning, the Korean version controls.