Privacy Policy

Effective date: July 27, 2026 Last updated: July 27, 2026

KOncierge Corp. (주식회사 콩시어지, "KOncierge", the "Company", "we", "us") respects your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, how we protect it, and the rights and choices you have.

This Policy applies to:

  • the websites operated by the Company, including koncierge.kr (the "Website");
  • the KOncierge Concierge Agent on the Website, LINE, and WhatsApp;
  • the guide marketplace and KOncierge Travel products; and
  • our community features, support channels, and related services (together, the "Services").

We are the data controller (개인정보처리자) for the processing described in this Policy, and we process personal data in accordance with the Personal Information Protection Act of Korea (PIPA) and other applicable laws. Where users in other jurisdictions have additional rights, Section 14 applies.

1. Overview at a Glance

QuestionShort answerDetails
What do we collect?Account details, chat messages, booking and payment records, community posts, device and usage dataSection 2
Why?To run the concierge service, process bookings and payments, keep the platform safe, improve the Services, and (with consent) send marketingSection 3
Do we link channels?Yes — web registration with a matching email/phone links your LINE/WhatsApp history to your accountSection 4
Is chat processed by AI?Yes — by third-party AI providers under contract, not used to train their modelsSection 5
Do we sell personal data?NoSection 7
Is data sent abroad?Yes — to hosting, AI, email, analytics, and payment providers listed in Section 8Section 8
How long do we keep data?Until account closure, plus statutory periods (up to 5 years for commerce records)Section 9
Your rights?Access, correction, deletion, suspension, consent withdrawal, complaintSections 12–14

This table is a summary only; the full sections below are definitive.

2. Personal Data We Collect

2.1 Data you provide directly

Account and profile data. When you register: name or display name, email address, phone number, password (stored only in salted, hashed form), language preference, country/region. Optional profile fields you choose to complete.

Messaging profile data. When you chat with us on LINE or WhatsApp: your platform user identifier, display name, and profile details the platform makes available to business accounts.

Chat content. Messages you exchange with the Concierge Agent — both AI chat and Human Sessions — including any details you volunteer (travel dates, destinations, companions, preferences, special requests). Please avoid sharing more personal detail than your request requires; in particular, do not send government ID numbers, full card numbers, or passwords in chat.

Booking data. Products viewed and booked, participant names and party size, tour dates and options, meeting details, special requests (which may include accessibility or dietary needs you choose to disclose), and communications about the Booking.

Payment and transaction data. Payment method type, masked card information, transaction amount and currency, approval and settlement records, refund records, Credit purchase and consumption history. Full card numbers are collected and processed by our payment providers (Toss Payments, PayPal) and never stored on our servers.

Community content. Reviews, board posts, comments, photos, and other content you submit to public areas, together with your display name.

Support and dispute records. Inquiries, complaints, refund requests, related correspondence, and identity-verification materials where verification is required.

Survey and event data. Responses to surveys and entries to promotions, where you choose to participate.

2.2 Data collected automatically

Device and log data. IP address, browser type and version, device and operating system information, access timestamps, pages and screens viewed, referring URLs, clicks and interactions, crash and error logs.

Approximate location. Inferred from IP address, used for language/currency defaults and fraud prevention. We do not collect precise GPS location.

Cookies and similar technologies. See Section 15.

2.3 Data from third parties

Messaging platforms. LINE and WhatsApp deliver to us the messages you send to our official accounts, along with the profile data described above.

Payment providers. Confirmation of payment outcomes, chargeback and dispute notices, and fraud signals.

Guides. Information a Guide records about a Booking's delivery (for example, completion confirmation or an incident report), where relevant to your Booking.

2.4 Sensitive data

We do not intentionally collect sensitive personal data (health, beliefs, biometrics, etc.). If you voluntarily include such details in chat or booking requests — for example, an accessibility or dietary requirement — we use them only to arrange the service you requested and share them only with the Guide or vendor who needs them for that purpose.

2.5 Data about Guides

Guides (marketplace sellers) provide additional data during onboarding: license numbers and verification documents, business registration details, settlement bank account, and tax information. Processing of Guide data is described in the separate Guide agreement and guide privacy notice provided during the application process; this Policy governs where that notice is silent.

3. Purposes of Processing and Legal Bases

PurposeMain data usedLegal basis (PIPA Art. 15)
Account creation, authentication, and management; cross-channel linkingAccount data, messaging profile dataPerformance of contract
Operating the AI Concierge and Human SessionsChat content, account dataPerformance of contract
Processing Bookings; sharing necessary details with the Guide or vendor delivering your BookingBooking dataPerformance of contract
Payment processing, Credit ledger management, refunds, receiptsPayment and transaction dataPerformance of contract; legal obligation
Customer support, complaint handling, dispute resolutionSupport records, related account/booking dataPerformance of contract; legal obligation
Safety, security, fraud and abuse prevention, enforcement of our TermsDevice/log data, account and transaction dataLegitimate interests; legal obligation
Service analytics and improvement (aggregated wherever possible)Device/log data, usage dataLegitimate interests; consent (for analytics cookies)
Personalization of content and recommendations within the ServicesUsage data, booking historyLegitimate interests
Marketing communications (email, messaging)Contact details, preferencesConsent (opt-in; withdrawable at any time)
Advertising measurement and audiences (GA4, Meta Pixel)Cookie and event dataConsent (via cookie choices)
Compliance with law, tax, and lawful requests of authoritiesRecords required by lawLegal obligation

Where we rely on legitimate interests under PIPA Article 15(1)6, we do so only where the processing is clearly necessary for our justifiable interest and does not unreasonably infringe your rights, and you may object as described in Section 12.

4. Cross-Channel Account Linking

KOncierge operates across several channels: this website, and messaging apps including LINE and WhatsApp where you can chat with our AI concierge. If you have previously chatted with KOncierge on a messaging channel and you register a web account using an email address or phone number that matches the one we already have on file, we automatically link those records together. Linking means:

  • Your previous conversations on LINE or WhatsApp become visible in read-only form inside your web account's chat history.
  • Credits, bookings, and account standing associated with your messaging profile are recognized as yours on the web.
  • Messages you send through new channels remain separate threads — we do not merge ongoing conversations into a single unified thread.

This linking is a mandatory part of how the service functions; we cannot offer you the platform experience without it. You are informed of the linking at the time you register, which is the point at which the match — if any — is made.

If a link is made in error (for example, because a phone number was previously assigned to a different person), you may request an admin-side unlink at any time by contacting support. We will promptly separate the records once verified.

We do not create a linked record without a registration event on the web — passively chatting on LINE or WhatsApp without ever visiting the website does not trigger any linking.

5. AI Processing of Chat

5.1. Messages you send to the Concierge Agent are transmitted to third-party AI model providers, under data processing agreements, solely to generate responses and operate features of the Services. Our provider agreements prohibit use of your conversation content to train the providers' models.

5.2. Our human concierge staff may view conversations in order to take over a session, ensure quality, investigate abuse, and resolve complaints.

5.3. We may use conversation data internally, in de-identified or aggregated form, to evaluate and improve the Concierge Agent (for example, measuring answer quality). We do not publish identifiable conversation content.

5.4. AI outputs are generated automatically and may be inaccurate; decisions with legal or similarly significant effect on you are not made solely by automated means (see Section 17).

6. Marketing and Advertising

6.1. Direct marketing. With your opt-in consent, we send news, offers, and recommendations by email and/or your linked messaging channel. Every marketing message includes an unsubscribe mechanism, and you can withdraw consent at any time in account settings or via support. Withdrawing marketing consent does not affect transactional messages (booking confirmations, receipts, security notices).

6.2. Advertising measurement. With your consent to advertising cookies, we use Google Analytics 4 and the Meta Pixel to measure campaign performance and build audiences (for example, reaching people similar to our customers). These tools set identifiers described in Section 15. We do not share your chat content with advertising platforms.

6.3. Your choices. You can refuse or withdraw advertising/analytics cookies via the cookie banner, configure your browser to block cookies, and use platform-level tools (Google Ads Settings, Meta Ad Preferences) to limit ad personalization.

7. Sharing of Personal Data

We do not sell personal data. We share it only as follows:

7.1 With Guides and service vendors delivering your Booking

When you book a Marketplace Product, we provide the Guide the minimum information needed to deliver it: participant name(s), party size, contact channel, meeting details, language, and special requests you submitted. Guides are contractually bound to use this data only for the Booking and to delete it when no longer needed. The same applies to vendors involved in delivering a KOncierge Travel Product (for example, a transport provider).

7.2 With processors acting on our instructions (처리위탁)

ProcessorEntrusted taskLocation
Supabase, Inc.Database, authentication, and file storage hostingUnited States
Vercel, Inc.Website hosting and content deliveryUnited States
Railway Corp.Backend application hostingUnited States
Anthropic, PBCAI response generation for the Concierge AgentUnited States
Toss Payments Co., Ltd.Payment processing (cards, local methods)Republic of Korea
PayPal Pte. Ltd. and affiliatesPayment processing (PayPal, international)Singapore / United States
Resend (Plus Five Five, Inc.)Transactional email deliveryUnited States
Google LLCWeb analytics (Google Analytics 4)United States
Meta Platforms, Inc.Advertising measurement (Meta Pixel)United States
Functional Software, Inc. (Sentry)Error and performance monitoringUnited States

We supervise processors through contracts covering purpose limitation, security measures, sub-processing restrictions, and deletion, as required by PIPA Article 26.

7.3 Messaging platforms (independent controllers)

If you choose to contact us via LINE (LY Corporation, Japan) or WhatsApp (Meta Platforms, Inc./WhatsApp LLC), those platforms process your messages and metadata under their own privacy policies, independently of us. We receive the messages you send to our official accounts.

7.4 Legal and safety

We may disclose personal data where required by law, court order, or a competent authority's lawful demand; to exercise or defend legal claims; or where necessary to protect the life, safety, or property of any person, in accordance with applicable law.

7.5 Corporate transactions

If the Company undergoes a merger, acquisition, or transfer of business, personal data may be transferred to the successor. We will notify you in advance as required by PIPA, including your right to object or request deletion.

7.6 With your separate consent

Any sharing outside the cases above will occur only with your separate, specific consent, identifying the recipient, purpose, items, and retention period.

8. International Transfers

Because we serve travelers worldwide and use global infrastructure, personal data is transferred outside Korea to the providers marked in the table in Section 7.2. In accordance with PIPA's overseas-transfer provisions, we disclose:

  • Items transferred: the data categories in Section 2 relevant to each provider's task (for example, chat content to the AI provider; email address to the email provider; event and cookie data to analytics providers).
  • Countries: United States; Japan (LINE); Singapore (PayPal); other jurisdictions where our providers operate.
  • Timing and method: transferred continuously via encrypted network connections (TLS) as the Services operate.
  • Recipients and contact points: listed in Section 7.2; contact details are available in each provider's published privacy policy or from our Privacy Officer.
  • Purposes and retention: as stated in Sections 3 and 9; providers retain data only as needed for their entrusted task.

We require overseas recipients to protect data to the standards required by PIPA. You may contact the Privacy Officer (Section 13) to ask questions or object to a transfer; please note that transfers essential to operating the Services (hosting, payment processing, AI processing for the Concierge Agent) cannot be separated from service provision, so objecting to them means we cannot provide the Services.

9. Retention and Deletion

9.1 Principle

We keep personal data only as long as necessary for the purposes collected, then destroy it without undue delay: electronic files are deleted irreversibly, and any paper records are shredded or incinerated.

9.2 Operational retention periods

DataPeriod
Account and profile dataUntil account closure (then deleted, subject to 9.3)
Chat content (AI and Human Sessions)While the account is active; deleted 90 days after account closure
Community contentUntil you delete it or your account is closed; posts may remain in de-identified form where removal would break discussion threads, unless you request full deletion
Credit ledger and transaction recordsLife of the account, then per 9.3
Marketing consent and delivery recordsUntil consent is withdrawn, then as evidence of the consent history per law
Security and fraud investigation recordsUp to 1 year after case closure

9.3 Statutory retention (survives account closure)

RecordPeriodLaw
Records on contracts and withdrawal of offers5 yearsAct on Consumer Protection in Electronic Commerce
Records on payment and supply of goods/services5 yearsAct on Consumer Protection in Electronic Commerce
Records on consumer complaints and dispute handling3 yearsAct on Consumer Protection in Electronic Commerce
Records on display and advertising6 monthsAct on Consumer Protection in Electronic Commerce
Electronic financial transaction records5 yearsElectronic Financial Transactions Act (where applicable)
Website access/login logs3 monthsProtection of Communications Secrets Act
Tax and accounting books and evidentiary documents5 yearsFramework Act on National Taxes et al.

Data retained under this Section is stored separately, used only for the statutory purpose, and destroyed at the end of the period.

9.4 Dormant accounts

If you do not use the Services for 1 year, we may separate your data from active systems or delete it, after notifying you at least 30 days in advance at your registered contact details.

10. Security

We implement administrative, technical, and physical safeguards appropriate to the risk, including:

  • encryption of data in transit (TLS) and encryption of key data at rest;
  • password storage using salted one-way hashes;
  • role-based access controls, least-privilege access to production data, and access logging;
  • network protections, vulnerability management, and monitoring/alerting (including third-party error monitoring);
  • contractual security obligations for all processors;
  • internal training and confidentiality obligations for staff who may access personal data; and
  • physical security controls at hosting facilities operated by our infrastructure providers.

No method of transmission or storage is completely secure. If a breach occurs that affects your personal data, we will notify you and report to the competent authorities within the timelines required by PIPA.

11. Notification of Breach

In the event of loss, theft, or leakage of personal data, we will promptly notify affected users of: the items affected, when and how it occurred, what you can do to minimize harm, our response measures and remediation procedures, and a contact point for reports and consultation — and we will file the reports required by law with the Personal Information Protection Commission or KISA.

12. Your Rights

12.1 What you can request

At any time, you (or your legal representative) may request:

  • Access to the personal data we hold about you and to records of how it has been used and shared;
  • Correction of inaccurate or incomplete data;
  • Deletion of data (subject to statutory retention duties in Section 9.3);
  • Suspension of processing of your data;
  • Withdrawal of consent for any processing based on consent (for example, marketing);
  • A copy of data you provided, in a commonly used electronic format, where technically feasible.

12.2 How to exercise them

Use the tools in your account settings where available (profile edits, marketing preferences, cookie settings, account closure), or contact the Privacy Officer in Section 13 by email. We may ask you to verify your identity — or an agent's authority — before acting, using the minimum information necessary.

12.3 Our response

We respond without undue delay and within the periods prescribed by PIPA (in principle, within 10 days for access requests). If we refuse a request in whole or in part (for example, because deletion would breach a statutory retention duty), we will explain the reason and the way to appeal. Exercising your rights is free of charge, except where a fee is expressly permitted by law for repeated copies.

12.4 Complaints and remedies

If you believe your privacy rights have been infringed, you may contact:

  • Personal Information Dispute Mediation Committee: 1833-6972, kopico.go.kr
  • KISA Personal Information Infringement Report Center: 118, privacy.kisa.or.kr
  • Supreme Prosecutors' Office Cybercrime: 1301, spo.go.kr
  • National Police Agency Cyber Bureau: 182, ecrm.police.go.kr

13. Privacy Officer (개인정보 보호책임자)

We have designated a Privacy Officer responsible for personal data protection and for handling inquiries, requests, and complaints:

  • Privacy Officer: 안윤성 (Yunseong Ahn), Representative Director
  • Phone: +82 70-4768-5412
  • Address: 서울특별시 중구 명동길 14, 6층 6035호 (04536), Republic of Korea

You may direct all privacy-related inquiries, requests under Section 12, and complaints to the Privacy Officer, and we will answer promptly and in good faith.

14. Additional Disclosures for Users Outside Korea

14.1 Users in the EEA, United Kingdom, and Switzerland

If the GDPR or UK GDPR applies to our processing of your data, the following supplements this Policy:

  • Legal bases. We process your data on the bases of: performance of a contract (operating your account, concierge service, bookings, payments); compliance with legal obligations; legitimate interests (security, fraud prevention, service analytics and improvement — balanced against your rights); and consent (marketing, non-essential cookies).
  • Your additional rights include the right to object to processing based on legitimate interests, the right to data portability, and the right not to be subject to solely automated decisions with legal or similarly significant effects (see Section 17). You also have the right to lodge a complaint with your local supervisory authority.
  • International transfers. Data is processed in Korea — which has been recognized by the European Commission as providing adequate protection — and by the providers listed in Section 7.2 in the countries stated there. Where a transfer requires safeguards, we rely on the recipient's compliance framework or standard contractual clauses.
  • Controller and contact. KOncierge Corp. is the controller; contact details are in Section 13. We have not appointed an EU/UK representative to be designated if required by Article 27 thresholds.

14.2 Users in other jurisdictions

Where the law of your jurisdiction grants privacy rights beyond those in this Policy (for example, certain access or deletion rights under other national or state laws), we honor requests to the extent required by that law. Contact the Privacy Officer to make a request, stating your jurisdiction.

15. Cookies and Similar Technologies

15.1 What we use and why

CategoryExamplesPurposeDuration
Strictly necessarySession/auth cookies, CSRF tokens, cookie-choice storageLogin, security, checkout, remembering your cookie choicesSession to 12 months
FunctionalLanguage and locale preferenceRemembering your settingsUp to 12 months
AnalyticsGoogle Analytics 4 (_ga, _ga_*)Understanding usage to improve the ServicesUp to 14 months
AdvertisingMeta Pixel (_fbp)Measuring ad performance; audience buildingUp to 3 months
DiagnosticsSentry session identifiersError and crash diagnosisSession

15.2 Your choices

Strictly necessary cookies cannot be switched off without breaking core functions like login and checkout. For all other categories you can: use the cookie settings cookie banner to give or withdraw consent; configure your browser to block or delete cookies; and use provider tools (Google Analytics opt-out browser add-on; Meta ad preferences). If you disable analytics/advertising cookies, the Services remain fully usable.

15.3 Do Not Track

There is no common industry standard for browser "Do Not Track" signals, and the Services do not currently respond to them. We honor the cookie choices you make in our settings, and Global Privacy Control signals where required by the law applicable to you.

16. Children

The Services are not directed to children under 14, and we do not knowingly collect personal data from children under 14 without the consent of a legal representative. If you believe a child under 14 has provided us personal data, contact the Privacy Officer and we will delete it promptly. Product pages may set higher minimum ages for participation in specific tours.

17. Automated Decision-Making

The AI Concierge automatically generates conversational responses and recommendations, and our systems apply automated rules for fraud and abuse detection (for example, flagging suspicious payment patterns for human review). We do not make decisions producing legal or similarly significant effects on you by solely automated means: account suspensions, refund denials, and fraud determinations are reviewed by our staff, and you may contest any such decision and request human re-review via support or the Privacy Officer.

18. Third-Party Sites and Services

The Services contain links to third-party websites and interoperate with third-party platforms (LINE, WhatsApp, payment providers, map services). This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their privacy policies.

19. Changes to This Policy

We may update this Policy to reflect changes in the Services, our providers, or applicable law. We will announce updates through the Services at least 7 days before they take effect — or at least 30 days for material changes to your rights or to the categories of data we share — and, for significant changes, we may additionally notify you by email or your linked messaging channel. The effective date at the top shows the current version; previous versions are available from the Privacy Officer on request.

20. Language

This Policy may be published in multiple languages for convenience. In case of inconsistency, the Korean version prevails.