Privacy Policy
Effective date: July 27, 2026 Last updated: July 27, 2026
KOncierge Corp. (주식회사 콩시어지, "KOncierge", the "Company", "we", "us") respects your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, how we protect it, and the rights and choices you have.
This Policy applies to:
- the websites operated by the Company, including koncierge.kr (the "Website");
- the KOncierge Concierge Agent on the Website, LINE, and WhatsApp;
- the guide marketplace and KOncierge Travel products; and
- our community features, support channels, and related services (together, the "Services").
We are the data controller (개인정보처리자) for the processing described in this Policy, and we process personal data in accordance with the Personal Information Protection Act of Korea (PIPA) and other applicable laws. Where users in other jurisdictions have additional rights, Section 14 applies.
1. Overview at a Glance
| Question | Short answer | Details |
|---|---|---|
| What do we collect? | Account details, chat messages, booking and payment records, community posts, device and usage data | Section 2 |
| Why? | To run the concierge service, process bookings and payments, keep the platform safe, improve the Services, and (with consent) send marketing | Section 3 |
| Do we link channels? | Yes — web registration with a matching email/phone links your LINE/WhatsApp history to your account | Section 4 |
| Is chat processed by AI? | Yes — by third-party AI providers under contract, not used to train their models | Section 5 |
| Do we sell personal data? | No | Section 7 |
| Is data sent abroad? | Yes — to hosting, AI, email, analytics, and payment providers listed in Section 8 | Section 8 |
| How long do we keep data? | Until account closure, plus statutory periods (up to 5 years for commerce records) | Section 9 |
| Your rights? | Access, correction, deletion, suspension, consent withdrawal, complaint | Sections 12–14 |
This table is a summary only; the full sections below are definitive.
2. Personal Data We Collect
2.1 Data you provide directly
Account and profile data. When you register: name or display name, email address, phone number, password (stored only in salted, hashed form), language preference, country/region. Optional profile fields you choose to complete.
Messaging profile data. When you chat with us on LINE or WhatsApp: your platform user identifier, display name, and profile details the platform makes available to business accounts.
Chat content. Messages you exchange with the Concierge Agent — both AI chat and Human Sessions — including any details you volunteer (travel dates, destinations, companions, preferences, special requests). Please avoid sharing more personal detail than your request requires; in particular, do not send government ID numbers, full card numbers, or passwords in chat.
Booking data. Products viewed and booked, participant names and party size, tour dates and options, meeting details, special requests (which may include accessibility or dietary needs you choose to disclose), and communications about the Booking.
Payment and transaction data. Payment method type, masked card information, transaction amount and currency, approval and settlement records, refund records, Credit purchase and consumption history. Full card numbers are collected and processed by our payment providers (Toss Payments, PayPal) and never stored on our servers.
Community content. Reviews, board posts, comments, photos, and other content you submit to public areas, together with your display name.
Support and dispute records. Inquiries, complaints, refund requests, related correspondence, and identity-verification materials where verification is required.
Survey and event data. Responses to surveys and entries to promotions, where you choose to participate.
2.2 Data collected automatically
Device and log data. IP address, browser type and version, device and operating system information, access timestamps, pages and screens viewed, referring URLs, clicks and interactions, crash and error logs.
Approximate location. Inferred from IP address, used for language/currency defaults and fraud prevention. We do not collect precise GPS location.
Cookies and similar technologies. See Section 15.
2.3 Data from third parties
Messaging platforms. LINE and WhatsApp deliver to us the messages you send to our official accounts, along with the profile data described above.
Payment providers. Confirmation of payment outcomes, chargeback and dispute notices, and fraud signals.
Guides. Information a Guide records about a Booking's delivery (for example, completion confirmation or an incident report), where relevant to your Booking.
2.4 Sensitive data
We do not intentionally collect sensitive personal data (health, beliefs, biometrics, etc.). If you voluntarily include such details in chat or booking requests — for example, an accessibility or dietary requirement — we use them only to arrange the service you requested and share them only with the Guide or vendor who needs them for that purpose.
2.5 Data about Guides
Guides (marketplace sellers) provide additional data during onboarding: license numbers and verification documents, business registration details, settlement bank account, and tax information. Processing of Guide data is described in the separate Guide agreement and guide privacy notice provided during the application process; this Policy governs where that notice is silent.
3. Purposes of Processing and Legal Bases
| Purpose | Main data used | Legal basis (PIPA Art. 15) |
|---|---|---|
| Account creation, authentication, and management; cross-channel linking | Account data, messaging profile data | Performance of contract |
| Operating the AI Concierge and Human Sessions | Chat content, account data | Performance of contract |
| Processing Bookings; sharing necessary details with the Guide or vendor delivering your Booking | Booking data | Performance of contract |
| Payment processing, Credit ledger management, refunds, receipts | Payment and transaction data | Performance of contract; legal obligation |
| Customer support, complaint handling, dispute resolution | Support records, related account/booking data | Performance of contract; legal obligation |
| Safety, security, fraud and abuse prevention, enforcement of our Terms | Device/log data, account and transaction data | Legitimate interests; legal obligation |
| Service analytics and improvement (aggregated wherever possible) | Device/log data, usage data | Legitimate interests; consent (for analytics cookies) |
| Personalization of content and recommendations within the Services | Usage data, booking history | Legitimate interests |
| Marketing communications (email, messaging) | Contact details, preferences | Consent (opt-in; withdrawable at any time) |
| Advertising measurement and audiences (GA4, Meta Pixel) | Cookie and event data | Consent (via cookie choices) |
| Compliance with law, tax, and lawful requests of authorities | Records required by law | Legal obligation |
Where we rely on legitimate interests under PIPA Article 15(1)6, we do so only where the processing is clearly necessary for our justifiable interest and does not unreasonably infringe your rights, and you may object as described in Section 12.
4. Cross-Channel Account Linking
KOncierge operates across several channels: this website, and messaging apps including LINE and WhatsApp where you can chat with our AI concierge. If you have previously chatted with KOncierge on a messaging channel and you register a web account using an email address or phone number that matches the one we already have on file, we automatically link those records together. Linking means:
- Your previous conversations on LINE or WhatsApp become visible in read-only form inside your web account's chat history.
- Credits, bookings, and account standing associated with your messaging profile are recognized as yours on the web.
- Messages you send through new channels remain separate threads — we do not merge ongoing conversations into a single unified thread.
This linking is a mandatory part of how the service functions; we cannot offer you the platform experience without it. You are informed of the linking at the time you register, which is the point at which the match — if any — is made.
If a link is made in error (for example, because a phone number was previously assigned to a different person), you may request an admin-side unlink at any time by contacting support. We will promptly separate the records once verified.
We do not create a linked record without a registration event on the web — passively chatting on LINE or WhatsApp without ever visiting the website does not trigger any linking.
5. AI Processing of Chat
5.1. Messages you send to the Concierge Agent are transmitted to third-party AI model providers, under data processing agreements, solely to generate responses and operate features of the Services. Our provider agreements prohibit use of your conversation content to train the providers' models.
5.2. Our human concierge staff may view conversations in order to take over a session, ensure quality, investigate abuse, and resolve complaints.
5.3. We may use conversation data internally, in de-identified or aggregated form, to evaluate and improve the Concierge Agent (for example, measuring answer quality). We do not publish identifiable conversation content.
5.4. AI outputs are generated automatically and may be inaccurate; decisions with legal or similarly significant effect on you are not made solely by automated means (see Section 17).
6. Marketing and Advertising
6.1. Direct marketing. With your opt-in consent, we send news, offers, and recommendations by email and/or your linked messaging channel. Every marketing message includes an unsubscribe mechanism, and you can withdraw consent at any time in account settings or via support. Withdrawing marketing consent does not affect transactional messages (booking confirmations, receipts, security notices).
6.2. Advertising measurement. With your consent to advertising cookies, we use Google Analytics 4 and the Meta Pixel to measure campaign performance and build audiences (for example, reaching people similar to our customers). These tools set identifiers described in Section 15. We do not share your chat content with advertising platforms.
6.3. Your choices. You can refuse or withdraw advertising/analytics cookies via the cookie banner, configure your browser to block cookies, and use platform-level tools (Google Ads Settings, Meta Ad Preferences) to limit ad personalization.
7. Sharing of Personal Data
We do not sell personal data. We share it only as follows:
7.1 With Guides and service vendors delivering your Booking
When you book a Marketplace Product, we provide the Guide the minimum information needed to deliver it: participant name(s), party size, contact channel, meeting details, language, and special requests you submitted. Guides are contractually bound to use this data only for the Booking and to delete it when no longer needed. The same applies to vendors involved in delivering a KOncierge Travel Product (for example, a transport provider).
7.2 With processors acting on our instructions (처리위탁)
| Processor | Entrusted task | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, and file storage hosting | United States |
| Vercel, Inc. | Website hosting and content delivery | United States |
| Railway Corp. | Backend application hosting | United States |
| Anthropic, PBC | AI response generation for the Concierge Agent | United States |
| Toss Payments Co., Ltd. | Payment processing (cards, local methods) | Republic of Korea |
| PayPal Pte. Ltd. and affiliates | Payment processing (PayPal, international) | Singapore / United States |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | United States |
| Google LLC | Web analytics (Google Analytics 4) | United States |
| Meta Platforms, Inc. | Advertising measurement (Meta Pixel) | United States |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | United States |
We supervise processors through contracts covering purpose limitation, security measures, sub-processing restrictions, and deletion, as required by PIPA Article 26.
7.3 Messaging platforms (independent controllers)
If you choose to contact us via LINE (LY Corporation, Japan) or WhatsApp (Meta Platforms, Inc./WhatsApp LLC), those platforms process your messages and metadata under their own privacy policies, independently of us. We receive the messages you send to our official accounts.
7.4 Legal and safety
We may disclose personal data where required by law, court order, or a competent authority's lawful demand; to exercise or defend legal claims; or where necessary to protect the life, safety, or property of any person, in accordance with applicable law.
7.5 Corporate transactions
If the Company undergoes a merger, acquisition, or transfer of business, personal data may be transferred to the successor. We will notify you in advance as required by PIPA, including your right to object or request deletion.
7.6 With your separate consent
Any sharing outside the cases above will occur only with your separate, specific consent, identifying the recipient, purpose, items, and retention period.
8. International Transfers
Because we serve travelers worldwide and use global infrastructure, personal data is transferred outside Korea to the providers marked in the table in Section 7.2. In accordance with PIPA's overseas-transfer provisions, we disclose:
- Items transferred: the data categories in Section 2 relevant to each provider's task (for example, chat content to the AI provider; email address to the email provider; event and cookie data to analytics providers).
- Countries: United States; Japan (LINE); Singapore (PayPal); other jurisdictions where our providers operate.
- Timing and method: transferred continuously via encrypted network connections (TLS) as the Services operate.
- Recipients and contact points: listed in Section 7.2; contact details are available in each provider's published privacy policy or from our Privacy Officer.
- Purposes and retention: as stated in Sections 3 and 9; providers retain data only as needed for their entrusted task.
We require overseas recipients to protect data to the standards required by PIPA. You may contact the Privacy Officer (Section 13) to ask questions or object to a transfer; please note that transfers essential to operating the Services (hosting, payment processing, AI processing for the Concierge Agent) cannot be separated from service provision, so objecting to them means we cannot provide the Services.
9. Retention and Deletion
9.1 Principle
We keep personal data only as long as necessary for the purposes collected, then destroy it without undue delay: electronic files are deleted irreversibly, and any paper records are shredded or incinerated.
9.2 Operational retention periods
| Data | Period |
|---|---|
| Account and profile data | Until account closure (then deleted, subject to 9.3) |
| Chat content (AI and Human Sessions) | While the account is active; deleted 90 days after account closure |
| Community content | Until you delete it or your account is closed; posts may remain in de-identified form where removal would break discussion threads, unless you request full deletion |
| Credit ledger and transaction records | Life of the account, then per 9.3 |
| Marketing consent and delivery records | Until consent is withdrawn, then as evidence of the consent history per law |
| Security and fraud investigation records | Up to 1 year after case closure |
9.3 Statutory retention (survives account closure)
| Record | Period | Law |
|---|---|---|
| Records on contracts and withdrawal of offers | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records on payment and supply of goods/services | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records on consumer complaints and dispute handling | 3 years | Act on Consumer Protection in Electronic Commerce |
| Records on display and advertising | 6 months | Act on Consumer Protection in Electronic Commerce |
| Electronic financial transaction records | 5 years | Electronic Financial Transactions Act (where applicable) |
| Website access/login logs | 3 months | Protection of Communications Secrets Act |
| Tax and accounting books and evidentiary documents | 5 years | Framework Act on National Taxes et al. |
Data retained under this Section is stored separately, used only for the statutory purpose, and destroyed at the end of the period.
9.4 Dormant accounts
If you do not use the Services for 1 year, we may separate your data from active systems or delete it, after notifying you at least 30 days in advance at your registered contact details.
10. Security
We implement administrative, technical, and physical safeguards appropriate to the risk, including:
- encryption of data in transit (TLS) and encryption of key data at rest;
- password storage using salted one-way hashes;
- role-based access controls, least-privilege access to production data, and access logging;
- network protections, vulnerability management, and monitoring/alerting (including third-party error monitoring);
- contractual security obligations for all processors;
- internal training and confidentiality obligations for staff who may access personal data; and
- physical security controls at hosting facilities operated by our infrastructure providers.
No method of transmission or storage is completely secure. If a breach occurs that affects your personal data, we will notify you and report to the competent authorities within the timelines required by PIPA.
11. Notification of Breach
In the event of loss, theft, or leakage of personal data, we will promptly notify affected users of: the items affected, when and how it occurred, what you can do to minimize harm, our response measures and remediation procedures, and a contact point for reports and consultation — and we will file the reports required by law with the Personal Information Protection Commission or KISA.
12. Your Rights
12.1 What you can request
At any time, you (or your legal representative) may request:
- Access to the personal data we hold about you and to records of how it has been used and shared;
- Correction of inaccurate or incomplete data;
- Deletion of data (subject to statutory retention duties in Section 9.3);
- Suspension of processing of your data;
- Withdrawal of consent for any processing based on consent (for example, marketing);
- A copy of data you provided, in a commonly used electronic format, where technically feasible.
12.2 How to exercise them
Use the tools in your account settings where available (profile edits, marketing preferences, cookie settings, account closure), or contact the Privacy Officer in Section 13 by email. We may ask you to verify your identity — or an agent's authority — before acting, using the minimum information necessary.
12.3 Our response
We respond without undue delay and within the periods prescribed by PIPA (in principle, within 10 days for access requests). If we refuse a request in whole or in part (for example, because deletion would breach a statutory retention duty), we will explain the reason and the way to appeal. Exercising your rights is free of charge, except where a fee is expressly permitted by law for repeated copies.
12.4 Complaints and remedies
If you believe your privacy rights have been infringed, you may contact:
- Personal Information Dispute Mediation Committee: 1833-6972, kopico.go.kr
- KISA Personal Information Infringement Report Center: 118, privacy.kisa.or.kr
- Supreme Prosecutors' Office Cybercrime: 1301, spo.go.kr
- National Police Agency Cyber Bureau: 182, ecrm.police.go.kr
13. Privacy Officer (개인정보 보호책임자)
We have designated a Privacy Officer responsible for personal data protection and for handling inquiries, requests, and complaints:
- Privacy Officer: 안윤성 (Yunseong Ahn), Representative Director
-
- Email: partnership@koncierge.co.kr
- Phone: +82 70-4768-5412
- Address: 서울특별시 중구 명동길 14, 6층 6035호 (04536), Republic of Korea
You may direct all privacy-related inquiries, requests under Section 12, and complaints to the Privacy Officer, and we will answer promptly and in good faith.
14. Additional Disclosures for Users Outside Korea
14.1 Users in the EEA, United Kingdom, and Switzerland
If the GDPR or UK GDPR applies to our processing of your data, the following supplements this Policy:
- Legal bases. We process your data on the bases of: performance of a contract (operating your account, concierge service, bookings, payments); compliance with legal obligations; legitimate interests (security, fraud prevention, service analytics and improvement — balanced against your rights); and consent (marketing, non-essential cookies).
- Your additional rights include the right to object to processing based on legitimate interests, the right to data portability, and the right not to be subject to solely automated decisions with legal or similarly significant effects (see Section 17). You also have the right to lodge a complaint with your local supervisory authority.
- International transfers. Data is processed in Korea — which has been recognized by the European Commission as providing adequate protection — and by the providers listed in Section 7.2 in the countries stated there. Where a transfer requires safeguards, we rely on the recipient's compliance framework or standard contractual clauses.
- Controller and contact. KOncierge Corp. is the controller; contact details are in Section 13. We have not appointed an EU/UK representative to be designated if required by Article 27 thresholds.
14.2 Users in other jurisdictions
Where the law of your jurisdiction grants privacy rights beyond those in this Policy (for example, certain access or deletion rights under other national or state laws), we honor requests to the extent required by that law. Contact the Privacy Officer to make a request, stating your jurisdiction.
15. Cookies and Similar Technologies
15.1 What we use and why
| Category | Examples | Purpose | Duration |
|---|---|---|---|
| Strictly necessary | Session/auth cookies, CSRF tokens, cookie-choice storage | Login, security, checkout, remembering your cookie choices | Session to 12 months |
| Functional | Language and locale preference | Remembering your settings | Up to 12 months |
| Analytics | Google Analytics 4 (_ga, _ga_*) | Understanding usage to improve the Services | Up to 14 months |
| Advertising | Meta Pixel (_fbp) | Measuring ad performance; audience building | Up to 3 months |
| Diagnostics | Sentry session identifiers | Error and crash diagnosis | Session |
15.2 Your choices
Strictly necessary cookies cannot be switched off without breaking core functions like login and checkout. For all other categories you can: use the cookie settings cookie banner to give or withdraw consent; configure your browser to block or delete cookies; and use provider tools (Google Analytics opt-out browser add-on; Meta ad preferences). If you disable analytics/advertising cookies, the Services remain fully usable.
15.3 Do Not Track
There is no common industry standard for browser "Do Not Track" signals, and the Services do not currently respond to them. We honor the cookie choices you make in our settings, and Global Privacy Control signals where required by the law applicable to you.
16. Children
The Services are not directed to children under 14, and we do not knowingly collect personal data from children under 14 without the consent of a legal representative. If you believe a child under 14 has provided us personal data, contact the Privacy Officer and we will delete it promptly. Product pages may set higher minimum ages for participation in specific tours.
17. Automated Decision-Making
The AI Concierge automatically generates conversational responses and recommendations, and our systems apply automated rules for fraud and abuse detection (for example, flagging suspicious payment patterns for human review). We do not make decisions producing legal or similarly significant effects on you by solely automated means: account suspensions, refund denials, and fraud determinations are reviewed by our staff, and you may contest any such decision and request human re-review via support or the Privacy Officer.
18. Third-Party Sites and Services
The Services contain links to third-party websites and interoperate with third-party platforms (LINE, WhatsApp, payment providers, map services). This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their privacy policies.
19. Changes to This Policy
We may update this Policy to reflect changes in the Services, our providers, or applicable law. We will announce updates through the Services at least 7 days before they take effect — or at least 30 days for material changes to your rights or to the categories of data we share — and, for significant changes, we may additionally notify you by email or your linked messaging channel. The effective date at the top shows the current version; previous versions are available from the Privacy Officer on request.
20. Language
This Policy may be published in multiple languages for convenience. In case of inconsistency, the Korean version prevails.