Privacy Policy

Article 1 (Items and Purposes of Personal Information Processing)

The Company processes personal information for the following purposes. The personal information being processed is not used for purposes other than the following, and if the purpose of use changes, the Company will take necessary measures such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.

Time of CollectionItems CollectedPurpose of Collection
Upon membership registration[Required] Name, email address (including Google email), region, company name, passwordVerifying intent to register, service registration/change/cancellation, delivery of notices, operation of member participation spaces, member surveys, provision of personalized services, provision and guidance of promotional information and partner services, confirmation of product delivery address and contact information, sending member anniversary congratulatory messages, sending publications
Upon use of the site[Required] IP address, cookies, service usage records (visit date and time, records of improper use, etc.), device information (unique device identifier, OS version, etc.)Statistical analysis of service usage (identifying age, region, gender, usage history, and usage frequency), prevention of fraudulent use by improper members
Upon customer consultation[Required] Name, company name, email address, country, consultation details (additional personal information may be collected depending on the type and content of the inquiry.)Handling customer consultation/complaints and dispute mediation, operation of member participation spaces, member surveys
Upon use of the service[Required personal information collected] Service usage status (registration date, usage period, service items used)Provision of personalized services
Upon purchase-related consultation[Required personal information collected] Payment-related records (product, amount), credit card (card company name, card number, expiration date, CVC), delivery-related information (country, street address, city, region, postal code), virtual account (bank name, account holder name, account number), cash receiptPayment settlement
Upon refund-related consultation[Required personal information collected] Account information (bank name, account holder name, account number), the required information collected upon purchase-related consultation abovePayment settlement

Article 2 (Processing and Retention Period of Personal Information)

① The Company retains and uses a member's personal information from the date the member registers for the service until the member withdraws, and when a member withdraws from the Company's service, the Company destroys the member's personal information without delay or stores it separately in accordance with Article 39-6 of the Personal Information Protection Act. However, information retained in accordance with relevant statutes is an exception.

② The processing and retention period of each type of personal information is as follows.

  • Log records, IP addresses, etc. required for the provision of communication confirmation data: 3 months (Protection of Communications Secrets Act)
  • Records concerning labeling/advertising: 6 months (Act on the Consumer Protection in Electronic Commerce)
  • Records concerning consumer complaints and dispute handling: 3 years (Act on the Consumer Protection in Electronic Commerce)
  • Records concerning identity verification: 6 months (Act on Promotion of Information and Communications Network Utilization and Information Protection)
  • Books and supporting documents concerning transactions: 5 years (Framework Act on National Taxes, Corporate Tax Act, Value-Added Tax Act, etc.)
  • Records concerning contracts or withdrawal of subscription: 5 years (Act on the Consumer Protection in Electronic Commerce)
  • Records concerning payment settlement and the supply of goods, etc.: 5 years (Act on the Consumer Protection in Electronic Commerce)
  • Records concerning the collection/processing and use of credit information: 3 years (Credit Information Use and Protection Act)

③ In order to prevent acts of illegitimately or improperly obtaining economic benefits such as discount coupons and event benefits provided by this service by repeatedly re-registering and arbitrarily withdrawing after a member voluntarily withdraws, as well as acts such as identity theft occurring in this process, the Company retains the member's name, email address, and mobile phone number identification information for 1 month after the member's withdrawal.

④ Where it is necessary to retain information in preparation for litigation, disputes, or other necessary cases, or for customer response, the Company stores such information separately from other members' personal information during the relevant period in accordance with Article 39-6 of the Personal Information Protection Act.

⑤ The Company may continue to retain personal information in a form in which a specific individual cannot be identified, for purposes such as statistical compilation and academic research.

Article 3 (Provision of Personal Information to Third Parties)

The Company processes the personal information of data subjects only within the scope specified in Article 1 (Purposes of Personal Information Processing), and provides personal information to third parties only where it falls under Article 17 and Article 18 of the Personal Information Protection Act, such as with the consent of the data subject or under special provisions of law.

Article 4 (Entrustment of Personal Information Handling)

① The Company may entrust the processing of personal information to other companies, etc., in order to improve its services. When entrusting the processing of personal information, the Company manages and supervises the service provider so that members' personal information is processed safely, and restricts the service provider from processing members' personal information for other purposes.

② When entrusting the processing of personal information, the Company will notify members of that fact in advance.

③ When entrusting the processing of personal information, the Company clearly stipulates, through an entrustment contract, etc., the service provider's strict compliance with instructions regarding personal information protection, confidentiality concerning personal information, the prohibition of provision to third parties, and liability in the event of an incident, and retains the contents of such contract in writing or electronically.

④ Status of personal information processing entrustment

Service ProviderEntrusted Work
Zendesk inc.Introduction of customer consultation work using chat, phone, and email; handling of other inquiries and consultations
IamportProcessing of usage fee payments
NICE Payments Co., Ltd.Processing of usage fee payments
StripeProcessing of usage fee payments

Article 5 (Rights and Obligations of Data Subjects and Their Legal Representatives, and Methods of Exercise)

① Data subjects may exercise their rights against the Company at any time, such as requesting to view, correct, delete, or suspend the processing of their personal information.

② The exercise of rights under paragraph 1 may be made to the Company in writing, by email, or by facsimile (FAX), etc., in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action thereon without delay.

③ The exercise of rights under paragraph 1 may be made through a representative, such as the data subject's legal representative or a duly authorized agent. In this case, you must submit a power of attorney in the form of Appendix No. 11 of the "Notification on the Method of Personal Information Processing (No. 2020-7)."

④ Requests to view personal information and to suspend its processing may be restricted with respect to the rights of the data subject pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.

⑤ Requests to correct or delete personal information cannot demand its deletion where the collection of such personal information is specified as mandatory in other statutes.

⑥ When there is a request to view, a request to correct or delete, or a request to suspend processing pursuant to the rights of the data subject, the Company verifies whether the person making the request, etc., is the data subject in person or a legitimate representative.

Article 6 (Destruction of Personal Information)

① When personal information becomes unnecessary, such as upon the expiration of the retention period or the achievement of the processing purpose, the Company destroys the relevant personal information without delay.

② The procedure and method for destroying personal information are as follows.

Reason for DestructionDestruction ProcedureDestruction Method
Users may apply for the destruction of their personal information whenever they wish. To exercise your rights, please contact the following email. support@stclab.comThe Company selects the personal information for which a reason for destruction has arisen and destroys the personal information with the approval of the Company's Chief Privacy Officer.The Company destroys personal information recorded and stored in the form of electronic files so that the records cannot be reproduced, and destroys personal information recorded and stored in paper documents by shredding it with a shredder or incinerating it.

Even without a member's withdrawal request, in accordance with Article 39-5 of the Personal Information Protection Act, in the case of a user who has not used the Company's information and communications services such as its website or app for 1 year from the date of last use, the Company must notify the user of the fact of destruction of personal information, the expiration date of the period, and the items of information to be destroyed, by email or SNS, etc., 30 days before the 1-year mark, and then destroy the personal information of the inactive user once 1 year has passed from the date of last use of the service. However, among the information to be destroyed, information corresponding to each statutory retention period specified in Article 2(2) of this policy shall be stored and managed separately from the personal information of active users during the relevant statutory period.

Article 7 (Securing the Safety of Personal Information)

The Company takes the following measures to secure the safety of personal information.

  • Technical measures: management of access rights to the personal information processing system, etc., installation of an access control system, encryption of unique identifying information, etc., and installation of security programs

Article 8 (Matters Concerning the Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)

① The Company uses 'cookies' that store usage information and retrieve it from time to time in order to provide individually customized services to users.

② A cookie is a small piece of information that the server (http) used to operate the website sends to the user's computer browser, and it may also be stored on the hard disk within users' PCs.

  • Installation, operation, and refusal of cookies: You can refuse to store cookies through the option settings in the Tools > Internet Options > Privacy menu at the top of your web browser.

Article 9 (Chief Privacy Officer)

① The Company takes overall responsibility for tasks concerning the processing of personal information, and designates a Chief Privacy Officer as below in order to handle complaints from data subjects and provide relief for damages in relation to personal information processing.

Chief Privacy OfficerPersonal Information Protection Department
  • Name: Kim Ha-dong
  • Position: Chief Privacy Officer
  • Contact: Tel) 010-7277-6765, Email) henry@stclab.com
  • Department: Management Support Team
  • Person in charge: Jung Ki-taek
  • Contact: Tel) 010-3215-0896, Email) ktjung@stclab.com

② Data subjects may direct all inquiries, complaint handling, damage relief, and other matters concerning personal information protection that arise while using the Company's service (or business) to the Chief Privacy Officer and the department in charge. The Company will respond to and handle data subjects' inquiries without delay.

Article 10 (Request to View Personal Information)

Data subjects may file a request to view their personal information pursuant to Article 35 of the Personal Information Protection Act with the department below.

Department Receiving and Handling Requests to View Personal Information
  • Department: Marketing Team
  • Person in charge: Won Jae-in
  • Contact: Tel) 010-3262-5499, Email) to_jaein@stclab.com

Article 11 (Remedies for Infringement of Rights)

Data subjects may inquire with the following organizations regarding damage relief, consultation, etc., for personal information infringement.

<The organizations below are separate from the Company. If you are not satisfied with the Company's own handling of personal information complaints and damage relief, or if you need more detailed assistance, please contact them.>

  • Personal Information Infringement Report Center (operated by the Korea Internet & Security Agency): Responsibilities — reporting personal information infringement, consultation requests / Website: privacy.kisa.or.kr
  • Personal Information Dispute Mediation Committee: Responsibilities — application for personal information dispute mediation, collective dispute mediation (civil resolution) / Website: www.kopico.go.kr
  • Supreme Prosecutors' Office Cyber Crime Investigation Division: 02-3480-3573 (www.spo.go.kr)
  • National Police Agency Cyber Safety Bureau: 182 (https://cyberbureau.police.go.kr)

Article 12 (Changes to the Privacy Policy)

This Privacy Policy applies from September 1, 2022.

Effective date: December 16, 2022