1. Purposes of Processing
The Company processes only information necessary for these purposes. If a purpose changes, the Company obtains separate consent or updates this Policy as required by PIPA.
- Registration, login, account security, consent records, and abuse prevention
- Orders, payment, delivery, cancellation, exchange, returns, refunds, and transaction evidence
- Membership tiers, coupons, points, review rewards, child-birthday benefits, and referrals
- Product Q&A, customer support, disputes, complaints, and necessary notifications
- Service security, access records, incident response, and legal duties
- Email or SMS marketing and analytics only after separate consent
2. Categories of Personal Information
- The Company does not directly store card numbers, CVCs, easy-payment passwords, or Korean resident registration numbers.
- The Company does not collect a child’s name, birth year, full date of birth, or resident registration number.
- Phone identity verification is not currently implemented. Birthday and referral benefits operate without it using account-level safeguards. Data and recipient relationships will be disclosed before any future introduction.
Information processed by service
| Service | Required or actually processed | Optional or conditional |
|---|---|---|
| Email account | Email, password hash, registration and consent time and policy version, session and security records | Marketing consent |
| Social signup | Identifier and verified email from an enabled provider, provider/link history, required signup consent | Additional email verification when the provider supplies no email |
| Order and delivery | Buyer account, recipient name and phone, postal code and address, delivery instructions, items, amount, delivery, and claim records | Saved-address label |
| Payment and refund | Order number, payment method, payment provider transaction ID, approval/cancellation/refund amount and currency, time, status, and receipt link | None |
| Child-birthday benefit | Guardian declaration and consent record; month and day for one child | None |
| Reviews, Q&A, support | Author account, product/order link, rating, text, image, inquiry, answer, status, and support language | Content a user voluntarily enters in a public post |
| Member benefits | Tier, coupon and point ledger, referral relationship, birthday benefit, review award and dispatch record | Phone registered to the member account |
| Use and security | IP, access time, request ID, device/browser data, login failure, admin access, and consent-change records | Analytics and marketing cookies after separate consent |
3. Retention and Use Periods
The Company destroys information when its purpose is achieved or the account is closed. Records required by law are separated from active account data and retained only for their statutory purpose.
A lawful preservation order may delay destruction for its duration. Information is destroyed promptly when the reason ends.
Retention under law and operating policy
| Record | Period | Basis |
|---|---|---|
| Advertising and display records | 6 months | Korean E-Commerce Act |
| Contracts and withdrawal records | 5 years | Korean E-Commerce Act |
| Payment and supply records | 5 years | Korean E-Commerce Act |
| Consumer complaints and disputes | 3 years | Korean E-Commerce Act |
| Personal information system access logs | 1 year, or 2 years where the statutory condition applies | Korean security-measures standard |
| Profile, saved address, and child-birthday data | Until purpose completion or account closure | Service contract and consent |
| Minimum identifier for re-registration restriction | 6 months after closure | Contract and abuse prevention |
| CloudFront minimum-field raw logs | 90 days by default | Security and incident-response policy |
4. Provision to Third Parties
The Company uses personal information only within the disclosed purposes and provides it to a third party only with consent or another basis under Articles 17 and 18 of PIPA.
Where payment or delivery requires provision, the actual recipient, purpose, items, retention, and applicable consent are presented at checkout or in a separate notice.
The Company buys monthly best-review gifts itself and manually sends them to the phone registered to the winning account. It does not give the gift retailer customer information.
5. Processing Outsourcing and Overseas Transfers
The Company uses the following service providers only to the extent needed to provide the relevant feature and transfers only the minimum information required when a user uses that feature.
A feature involving overseas processing or transfer may be unavailable if the user does not use it or withdraws an applicable consent. The Company keeps recipient, country, data, purpose, and retention details aligned with its contracts and service settings.
Processors and external services
| Service provider | Processing task | Scope |
|---|---|---|
| Amazon Web Services | Database, object storage, content delivery, logging, email delivery, and support translation infrastructure | Only as needed to operate the service and handle requested support |
| PayPal (PayPal Pte. Ltd. and its affiliates, Singapore and United States) | USD payment, cancellation, refund, and receipts for the English store | Order number, amount, and the payment status data PayPal returns; the Company never receives card numbers. Involves transfer of order data outside the Republic of Korea when a user pays |
| Toss Payments Co., Ltd. | Card, Toss Pay, Kakao Pay, and Naver Pay payment, cancellation, refund, and receipts | Korean store only, when a user requests payment there |
| International and domestic carriers selected per order (including Hanjin and CJ Logistics) | Delivery, customs handling, and collection | Recipient name, phone, address, and parcel data sent only to the carrier selected for the order; international delivery transfers this data to the destination country |
| Google, Kakao, or NAVER | Selected social signup and login | Only the provider selected by the user |
| Cloudflare | Automated-request and abuse prevention | Only requests using the security verification feature |
| Google (YouTube) | Privacy-enhanced external video | Only when the user chooses to play external video |
6. Destruction Procedure and Method
- A daily job removes information whose purpose or retention period has ended and records success, failure, and lawful exceptions.
- Statutory records are separated from active account data and access-restricted.
- Electronic files are deleted so recovery is impracticable; paper is shredded or incinerated.
- Backups expire under their lifecycle and deleted information is removed again if a backup is restored.
7. Rights of Data Subjects and Representatives
- A data subject may request access, correction, deletion, suspension, withdrawal of consent, and account closure.
- Requests may be submitted through available account controls, cscenter@maechorom.com, +82 70-7677-7997, or the postal address below.
- The Company verifies identity only as necessary and handles properly authorized representative requests under Korean law.
- A lawful restriction, extension, or refusal is explained together with an appeal route.
- Where the statutory right to data portability applies, the Company follows the required process and period and will announce formats and history checks when the applicable scope and standards are confirmed.
8. Children and Child-Birthday Data
Registration includes confirmation that the user is at least 14. The Company does not register a child under 14 as an independent member.
A birthday benefit processes only the month and day of one child after an adult member declares legal guardianship and consents. It does not store the child’s name, birth year, or full date of birth. Deletion or withdrawal ends future benefits and triggers destruction.
9. Cookies and Refusal Controls
Essential cookies and browser storage support login, security, consent choices, and carts. Analytics and marketing cookies are not requested, stored, or run before the corresponding optional consent. Choices can be changed through Cookie settings in the footer.
The Company does not assume current use of mobile advertising identifiers (ADID/IDFA) or targeted-ad pixels. Before introduction, this Policy will state the collector, purpose, items, retention, and opt-out method.
Browser controls
- Chrome: Settings → Privacy and security → Third-party cookies
- Safari: Settings → Privacy → Manage Website Data or Block all cookies
- Edge: Settings → Cookies and site permissions → Manage cookies and site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Blocking every cookie may prevent essential login and cart functions.
10. Security Measures
- Administrative: internal management plans, minimum staffing, access review, and training
- Technical: role-based least privilege, administrator MFA and reauthentication, encryption in transit and at rest, password hashing, access and audit logs, upload validation and malware scanning, backup and recovery, and vulnerability management
- Physical: access control for facilities and media containing personal information
- Log minimization: no card number, authentication token, password, or unnecessary raw phone/address data in application logs
11. Data Protection Officer and Grievance Contact
Business and privacy contact
| Item | Details |
|---|---|
| Controller | Maechorom Co., Ltd. |
| Representative, final privacy-responsible person, and Data Protection Officer | Juhyun Seok |
| Business Registration No. | 495-81-02660 |
| Mail-order Business Registration No. | 2023-Jeonnam Yeosu-0038 |
| Address | Suite 920, Desian Flex Knowledge Industry Center, 424 Yangcheon-ro, Gangseo-gu, Seoul, Republic of Korea |
| Phone | +82 70-7677-7997 |
| cscenter@maechorom.com | |
| Support hours | Weekdays 10:00–17:00, lunch 12:30–13:30; closed weekends and public holidays |
12. Privacy Request Department
The Data Protection Officer and customer-support contact receive and handle access and other privacy requests at cscenter@maechorom.com, +82 70-7677-7997, or Suite 920, 424 Yangcheon-ro, Gangseo-gu, Seoul, Republic of Korea.
13. External Remedies
These agencies are independent from Company support. A data subject may contact the Company first or separately seek consultation, reporting, or mediation.
- Personal Information Dispute Mediation Committee: 1833-6972, www.kopico.go.kr
- KISA Personal Information Infringement Report Center: 118, privacy.kisa.or.kr
- Supreme Prosecutors’ Office: 1301, www.spo.go.kr
- Korean National Police Agency: 182, ecrm.police.go.kr
14. Automated Decisions and Review
Duplicate or abusive referral, review, or birthday benefits may be assessed by predefined rules using account, transaction, and benefit ledgers. This is rules-based processing, not an AI training model.
A user whose benefit is held or rejected may request the reason, an explanation, or human review through support. The Company does not determine a legal or similarly significant effect solely by automated processing.
15. Representative Responsibility and Breach Response
The representative bears final responsibility for supporting privacy personnel, budget, and internal controls. If the Company becomes aware of loss, theft, leakage, forgery, alteration, damage, or a likely occurrence, it investigates and contains it without delay and gives notices and reports required by Korean law, including available remedies and dispute-mediation routes.
16. Changes to This Policy
- Effective date: September 7, 2026
- Revision history: first effective version on August 30, 2026
- Revision history: customer service lunch hours corrected to 12:30–13:30 on September 7, 2026
- General changes are announced 7 days in advance; materially unfavorable changes are announced 30 days in advance. Separate consent is obtained where required.
- If the English and Korean versions differ in meaning, the Korean version controls.
