Privacy Policy
Locally (hereinafter "Locally") establishes and discloses the following Personal Information Processing Policy in order to protect the personal information of data subjects and to smoothly handle related grievances pursuant to Article 30 of the Personal Information Protection Act.
Article 1. (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than the following, and if the purpose of use changes, necessary measures such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act will be taken.
1. Homepage membership registration and management
Personal information is processed for the purposes of confirming membership registration intent, identifying and authenticating users in connection with providing membership services, maintaining and managing membership qualifications, confirming identity pursuant to the limited identity verification system, preventing improper use of services, confirming the consent of legal representatives for children under 14 years of age, issuing various notices and notifications, and handling grievances.
2. Provision of goods or services
Personal information is processed for the purposes of delivering goods, providing services, sending contracts and invoices, providing content, providing customized services, identity verification, age verification, fee payment and settlement, and debt collection.
3. Handling grievances
Personal information is processed for the purposes of verifying the identity of complainants, confirming the details of complaints, contacting and notifying for fact-finding, and notifying the results of processing.
Article 2. (Personal Information Processing and Retention Period)
① The Company processes and retains personal information within the personal information retention and use period stipulated by law or the personal information retention and use period agreed upon when collecting personal information from data subjects.
② The processing and retention period for each type of personal information is as follows.
1. Homepage membership registration and management: Until withdrawal from the business/organization homepage
However, in the following cases, until the reason ends:
1) If an investigation, inquiry, etc. due to violation of applicable laws is in progress, until the relevant investigation or inquiry is completed
2) If there are remaining debt or credit relationships from homepage use, until such relationships are settled
2. Provision of goods or services: Until goods/services are fully supplied and fees are paid and settled
However, in the following cases, until the relevant period ends:
1) Records related to transactions such as display/advertisement, contract details and fulfillment under the Act on Consumer Protection in Electronic Commerce:
- Records related to display/advertisement: 6 months
- Records related to contracts or withdrawal of subscriptions, payment of prices, supply of goods, etc.: 5 years
- Records related to consumer complaints or dispute resolution: 3 years
2) Communications confirmation data retention under Article 41 of the Protection of Communications Secrets Act:
- Subscriber telecommunications date/time, start/end time, counterpart subscriber number, usage frequency, originating base station location tracking data: 1 year
- Computer communications, internet log records, access location tracking data: 3 months
Article 3. (Provision of Personal Information to Third Parties)
① The Company processes personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only when the data subject consents or in cases corresponding to Article 17 of the Personal Information Protection Act, such as special provisions of the law.
② The Company provides personal information to third parties as follows:
- Recipients of personal information: Partners and institutions required for payment processing, reservation fulfillment, identity verification, and compliance with legal obligations
- Purpose of use by the recipient: Reservation confirmation, payment and settlement processing, identity verification, dispute response, and compliance with legal obligations
- Personal information items provided: Name, contact details, and information required to process reservations and payments
- Retention and use period of the recipient: For the period required by applicable law or contract
Article 4. (Entrustment of Personal Information Processing)
① The Company entrusts personal information processing as follows for smooth personal information operations.
- Trustee: Payment and escrow service providers
- Content of entrusted work: Payment approval, payment security, and settlement linkage
- Trustee: Cloud and service infrastructure operators
- Content of entrusted work: Service hosting, data storage, incident response, and log management
- Trustee: Messaging, email, and customer support partners
- Content of entrusted work: Intake of customer inquiries, response guidance, and delivery of notifications
- Trustee: Identity verification and authentication service providers
- Content of entrusted work: Identity verification, account protection, and fraud prevention
② When entering into entrustment contracts, the Company specifies matters related to liability such as prohibition of personal information processing for purposes other than the entrusted work, technical and administrative protective measures, restrictions on re-entrustment, supervision and management of trustees, and damages compensation in contracts and other documents pursuant to Article 25 of the Personal Information Protection Act, and supervises whether trustees process personal information safely.
③ If the actual content of entrusted work or the trustee changes, it will be disclosed through this Personal Information Processing Policy without delay.
Article 5. (Rights and Methods of Exercise for Users and Legal Representatives)
① Data subjects may exercise the following personal information protection-related rights against the Company at any time.
1. Request to view personal information
2. Request for correction in case of errors, etc.
3. Request for deletion
4. Request for suspension of processing
② The rights under paragraph ① may be exercised through written documents, telephone, email, fax, etc. to the Company, and the Company will take action without delay.
③ If a data subject requests correction or deletion of errors in personal information, the Company will not use or provide the relevant personal information until the correction or deletion is completed.
④ Rights under paragraph ① may be exercised through a legal representative of the data subject or a delegated agent. In this case, a power of attorney pursuant to Annex Form No. 11 of the Enforcement Rules of the Personal Information Protection Act must be submitted.
⑤ Data subjects must not infringe upon the personal information and privacy of themselves or others being processed by the Company in violation of the Personal Information Protection Act or other applicable laws.
Article 6. (Items of Personal Information Processed)
The Company processes the following personal information items.
1. Homepage membership registration and management
Required items: Email address or social login identifier, password (for email sign-up), name or nickname, and default language preference
Optional items: Profile photo, self-introduction, city of residence, and preference information
2. Provision of goods or services
Required items: Booker name, contact details, reservation and payment processing information, and settlement account information for hosts where applicable
Optional items: Special requests, travel preferences, and receipt issuance information
3. The following personal information items may be automatically generated and collected during internet service use.
IP address, cookies, MAC address, service use records, visit records, improper use records, etc.
Article 7. (Destruction of Personal Information)
① The Company destroys the relevant personal information without delay when personal information becomes unnecessary, such as when the personal information retention period has elapsed or the processing purpose has been achieved.
② If personal information must continue to be retained pursuant to other laws despite the elapse of the personal information retention period consented to by the data subject or the achievement of the processing purpose, the relevant personal information will be moved to a separate database (DB) or stored in a different location.
③ The procedure and method for destroying personal information are as follows.
1. Destruction procedure
The Company selects the personal information for which a reason for destruction has arisen, and destroys the personal information with the approval of the Company's Personal Information Protection Officer.
2. Destruction method
For personal information recorded and stored in electronic file format, the Company uses methods such as Low Level Format to make it impossible to reproduce the records. For personal information recorded and stored in paper documents, the Company destroys them by shredding or incineration.
Article 8. (Measures to Ensure the Safety of Personal Information)
The Company takes the following measures to ensure the safety of personal information.
1. Administrative measures: Establishment and implementation of internal management plans, regular employee training, etc.
2. Technical measures: Management of access rights to personal information processing systems, installation of access control systems, encryption of unique identification information, installation of security programs
3. Physical measures: Access control to computer rooms, data storage rooms, etc.
Article 9. (Matters Concerning the Installation, Operation, and Refusal of Automatic Personal Information Collection Devices)
① The Company uses "cookies" that store and retrieve usage information from time to time in order to provide individually customized services to users.
② Cookies are small pieces of information sent by the server (http) used to operate the website to the user's computer browser and may also be stored on the user's computer hard disk.
a. Purpose of using cookies: Used to provide optimized information to users by identifying visit and usage patterns for each service and website visited by the user, popular search terms, whether secure connections are used, etc.
b. Installation, operation, and refusal of cookies: You can refuse to store cookies by selecting options in the menu Tools > Internet Options > Privacy in your web browser.
c. If you refuse to store cookies, you may have difficulty using customized services.
d. Third-party vendors, including Google, may use cookies to serve ads based on a user's prior visits to this website or other websites.
e. Google's use of advertising cookies enables Google and its partners to serve personalized ads based on users' visits to this website and/or other sites on the Internet.
f. Users may opt out of personalized advertising through Google Ads Settings (https://adssettings.google.com/). Where regional laws apply, users may also change their consent and advertising choices through the consent management message displayed on the site.
g. If consent is declined or personalized advertising is disabled, non-personalized ads may be shown or ad serving may be limited. More information about Google's privacy practices is available at https://policies.google.com/privacy.
h. The Company uses Google Analytics only when the user consents to analytics cookies, in order to measure page visits and the experience search and booking funnel in aggregate. Names, email addresses, phone numbers, and free-form search terms are not sent to Google Analytics. Users may change analytics consent through the consent management message on the site.
Article 10. (Personal Information Protection Officer)
① The Company designates a Personal Information Protection Officer as follows to take overall responsibility for personal information processing and to handle data subjects' complaints and damage relief related to personal information processing.
▶ Personal Information Protection Officer
Name: Nishimura Mayu
Position: Personal Information Protection Officer
Contact: locally.partners@gmail.com / Help Center 1:1 inquiry
※ You will be connected to the Personal Information Protection department.
▶ Personal Information Protection Department
Department name: Locally Operations
Person in charge: Customer Support Manager
Contact: locally.partners@gmail.com / Help Center 1:1 inquiry
② Data subjects may contact the Personal Information Protection Officer and the responsible department regarding all personal information protection-related inquiries, complaints processing, damage relief, etc. that arise while using the Company's services (or business). The Company will respond to and process data subjects' inquiries without delay.
Article 11. (Personal Information Access Requests)
Data subjects may request access to personal information pursuant to Article 35 of the Personal Information Protection Act to the following department. The Company will endeavor to process data subjects' personal information access requests promptly.
▶ Department for receiving and processing personal information access requests
Department name: Locally Operations
Person in charge: Customer Support Manager
Contact: locally.partners@gmail.com / Help Center 1:1 inquiry
Article 12. (Methods of Remedying Rights Infringements)
Data subjects may contact the following institutions regarding damage relief and consultation for personal information infringement.
▶ Personal Information Infringement Report Center (operated by Korea Internet & Security Agency)
- Jurisdiction: Reports and consultation applications for personal information infringement
- Website: privacy.kisa.or.kr
- Phone: (without area code) 118
- Address: 3F Personal Information Infringement Report Center, 9 Jinheung-gil, Naju-si, Jeollanam-do (58324)
▶ Personal Information Dispute Mediation Committee
- Jurisdiction: Applications for personal information dispute mediation, collective dispute mediation (civil resolution)
- Website: www.kopico.go.kr
- Phone: (without area code) 1833-6972
- Address: 4F, Government Seoul Building, 209 Sejong-daero, Jongno-gu, Seoul (03171)
▶ Supreme Prosecutors' Office Cyber Crime Investigation Division: 02-3480-3573 (www.spo.go.kr)
▶ National Police Agency Cyber Safety Division: 182 (http://cyberbureau.police.go.kr)
Article 13. (Effective Date and Amendments of Personal Information Processing Policy)
This Personal Information Processing Policy takes effect from February 15, 2025.
