Privacy Policy

Effective date: 2026-04-15

1. Personal Information Collected and How It Is Collected

The Company collects the following personal information to provide the Service.

(1) At sign-up: email address, password, nickname.

(2) When using Concierge: name, shipping address, contact information, payment information.

(3) Automatically collected: access IP, cookies, visit history, device information (OS, browser type).

Collection methods: in-Service entry forms, customer support interactions, automated collection tools.

2. Purposes of Collection and Use

(1) Member management: confirming sign-up intent, identity verification, maintaining membership, preventing fraudulent use.

(2) Service provision: content delivery, personalized recommendations, Concierge ordering / payment / shipping.

(3) Customer support: handling inquiries, delivering announcements.

(4) Service improvement: usage statistics analysis, development of new services.

3. Retention and Use Period

As a rule, the Company destroys personal information without delay once the purpose of its collection and use has been achieved. However, when retention is required by applicable law, the information is retained for the period specified below:

(1) Records of contracts or withdrawal of offers: 5 years (E-Commerce Act).

(2) Records of payment and the supply of goods: 5 years (E-Commerce Act).

(3) Records of consumer complaints or dispute resolution: 3 years (E-Commerce Act).

(4) Access logs: 3 months (Telecommunications Privacy Act).

4. Provision of Personal Information to Third Parties

As a rule, the Company does not provide User personal information to third parties. The following are exceptions:

(1) The User has consented in advance.

(2) Disclosure is required by law, or an investigative authority requests it through procedures and methods prescribed by law for investigative purposes.

5. Entrustment of Personal Information Processing

The Company entrusts personal information processing to the third parties listed below to facilitate smooth provision of the Service. The scope, retention period, and entrusted work for each are specified by separate contract.

(1) Cloud infrastructure — Amazon Web Services, Inc. / Cloudflare, Inc.: data storage, processing, and content delivery.

(2) Payment processing — Eximbay Co., Ltd. (주식회사 엑심베이): card authorization, settlement, refund, and dispute handling for cross-border purchases.

(3) Shipping — domestic and international couriers (selected per shipment): Concierge product delivery.

Entrustment contracts specify, in accordance with the Personal Information Protection Act, prohibition on using personal information for purposes other than the entrusted work, as well as technical and administrative safeguards. Personal information provided to the payment gateway for transaction processing is retained for the period required by the E-Commerce Act (5 years for records of payment and supply of goods).

6. Rights of Users and Legal Representatives

Users may at any time request to view, correct, delete, or suspend processing of their personal information, either via the Service’s settings menu or by contacting the Data Protection Officer below.

Personal information of children under the age of 14 is collected with the consent of a legal representative, who may request to view, correct, or delete the child’s personal information.

7. Destruction of Personal Information

When personal information is no longer necessary, for example because the retention period has elapsed or the purpose of processing has been achieved, it is destroyed without delay. Electronic files are deleted by methods that prevent recovery, and paper documents are shredded or incinerated.

8. Measures to Ensure Security

The Company takes the following measures to ensure the security of personal information:

(1) Administrative measures: establishment and operation of an internal management plan, regular staff training.

(2) Technical measures: access-rights management for personal-information systems, access-control systems, password encryption, installation of security software.

(3) Physical measures: access control for server rooms and document storage rooms.

9. Operation and Refusal of Cookies

The Company may use cookies to provide personalized services. Users may refuse cookie storage through browser settings, but doing so may restrict the use of certain services.

10. Data Protection Officer

Name: Ji-won Yoo (Representative of welkit).

Email: welkit.answer@gmail.com

Phone: +82 10-8335-7026

Users may direct any privacy-related inquiries, complaints, or requests for remedy arising out of their use of the Service to the contact above; the Company will respond and take action without delay.

11. Remedies for Infringement of Rights

If you need to report or consult on a personal-information infringement, you may contact the following Korean authorities:

· Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr).

· Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr).

· Supreme Prosecutors’ Office Cyber Investigation Division: 1301 (www.spo.go.kr).

· National Police Agency Cyber Bureau: 182 (ecrm.cyber.go.kr).

12. Changes to This Privacy Policy

This Policy takes effect on 2026-04-15. Any additions, deletions, or modifications due to changes in law, policy, or security technology will be posted within the Service at least 7 days before they take effect.