Privacy Policy
1. What is a Privacy Policy?
STAYGE Labs, Inc. (‘the Company’) collects, uses, and provides the User’s personal information based on the User’s consent, and actively protects the User’s rights (to self-determination concerning their personal information).
The Company, as an information and communications service provider, is subject to and complies with the applicable laws, personal information protection provisions, and guidelines of the Republic of Korea.
The Privacy Policy refers to the guidelines with which the Company complies to protect the User’s invaluable personal information so that the User can use the services safely.
This Privacy Policy applies to services (“Services”) provided by the Company.
2. Collection of Personal Information
The Company collects personal information to the minimum extent necessary for service provision.
The Company collects minimum personal information necessary to provide the User with the Services when the User signs up or uses the Services on the website, applications, or programs as follows:
[Basic information collected]
- (Required) Email address, password, user name, community profile name, profile photo, Buyer information (name, mobile phone number, email), ticket reservation, cancellation, refund information, payment method information
- (Optional) Country, sex, device information, shipping information (Recipient name, shipping address, phone number)
For some Services, the Company may collect additional personal information, upon obtaining the User’s consent, to provide specialized services.
- Required information: information needed to perform essential functions of the Services
- Optional information: information collected additionally to provide more specialized services (No restrictions on the use of the Services even if the User opts out on optional information)
How personal information is collected:
The Company provides the User with prior notice of its collection of personal information. The Company collects personal information when:
- the User consents to the collection of personal information and enters their personal information as they sign up or use the Services;
- provided by affiliated services or organizations;
- obtained from a website, email, fax, phone, etc. in the process of customer service consultation; or
- the User participates in online or offline events.
The Company collects personal information as follows when the User uses the Services:
Information that may be automatically created and collected when the User uses the PC web, mobile web/app includes device information (OS, screen size, device ID, mobile phone type, model of the device), IP address (to confirm the User’s country of access), cookies, date and time of visit, records of fraudulent use, records of service use.
The Company may obtain personal information from third parties for affiliated or connected services.
3. Use of personal information
The Company uses personal information for the purposes of member administration, service provision, and improvement, new service development, etc. The Company collects the minimum personal information necessary to provide the User with Services as follows when the User signs up or uses the Services on the website, applications, or programs:
- Confirming member identity and consent to sign-up, confirming user identity/age, preventing fraudulent use or abuse;
- Developing new services, providing services, processing questions or complaints, announcing notices;
- In case of the use of paid services, transmitting content or shipping goods, settling payments, collecting a debt;
- Preventing and restricting behaviors that may obstruct the smooth operation of the Services (including but not limited to account theft and fraudulent use);
- Recommending customized content and using for marketing efforts based on demographics and user interests, preferences, and inclinations;
- Offering personalization services;
- Building statistics on the records of service use, access frequency, and service uses to create a service environment conducive to privacy protection and to improve services; and
- Deidentifying personal information and using the de-identified information for statistical analysis and scientific research
4. Provision and consignment
STAYGE Labs does NOT provide the User’s personal information to a third party unless consented to by the User or required by the laws.
The Company provides personal information to connect to the third party services as follows: The Company does NOT provide the User’s personal information to a third party without the User’s prior consent. However, the Company may request the User’s consent and provide personal information to a third party to the extent necessary for the User to use the services of the external affiliates.
[Personal information shared with the third party]
- Consignee: CJ ENM Inc.
- Purpose: Conducting surveys to improve Mnet Plus services and holding events; Securing an effective communication channel for confirming event applicants, providing and shipping rewards, and operating special pages within services, improve services
- Personal information shared: Information of survey recipient and event winners among ENM official community users (community profile name, email, country, gender, device information, delivery information (recipient name, shipping address, phone number))
- Retention and use periods: During the official community operation period
- Consignee: [List of Companies]
- Purpose: Handling of duties necessary for the performance of ticket purchase contracts, such as ticket reservation, cancellation, customer consultation, etc, and handling of duties for responding to persons subject to fraudulent reservation
- Personal information shared: Name, phone number, Buyer Information (Name, Mobile Number, Email), Ticket Reservation and cancellation Information
- Retention and use periods: Until the purpose of providing information is achieved
[The Company consigns the following task to a third party]
The Company consigns personal information to a third party to perform tasks needed to provide the Services. The Company manages and supervises the consignee to comply with the applicable laws.
- Consignee: Amazon Web Services, Inc.
- Purpose: System operation; AWS manages physical servers only, and does NOT have access to the User’s personal information.
5. Retention and disposal
The Company retains personal information until the purposes of the personal information use are fulfilled or the User deletes their account, with some exceptions applied.
The Company keeps the collected personal information until the purposes of the use of personal information are fulfilled or the User deletes their account. In case the Company terminates the Terms of Service with the User under the Terms of Use, however, the Company may keep the minimum personal information of the User for a certain period as required to prevent the User from signing up again during that period.
The Company destroys personal information without delay once the purposes of collection and use are fulfilled. The Company will employ the disposal methods and procedures as follows:The Company destroys personal information in the form of electronic files securely to make the data unrecoverable and unrevivable. For other forms of personal information such as records, printouts, written forms, etc., the Company disposes of them by shredding or burning.
To comply with the internal policy, however, the Company keeps some types of personal information for certain periods before destroying them.
[Records regarding contract or withdrawal of subscription or records regarding payment and supply of goods]
- Legal basis: Act on the Consumer Protection in Electronic Commerce
- Retention period: 5 years
[Records regarding consumer complaint or dispute handling]
- Legal basis: Act on the Consumer Protection in Electronic Commerce
- Retention period: 3 years
[Records regarding marks and advertisements]
- Legal basis: Act on the Consumer Protection in Electronic Commerce
- Retention period: 6 months
[Records regarding books and supporting documentation related to transactions as required by the tax laws]
- Legal basis: Framework Act on National Taxes and Corporate Tax Act
- Retention period: 5 years
[Records regarding electronic financial transactions]
- Legal basis: Electronic Financial Transactions Act
- Retention period: 5 years
[Records regarding website visits]
- Legal basis: Protection of Communications Secrets Act
- Retention period: 3 months
The Company stores separately or deletes personal information of a User who has not used the Services for 1 year or a period set by the User under the “Personal Information Expiration Date” scheme. Once personal information reaches its expiration date, the Company destroys the information immediately in an unrecoverable manner, even if the information is obligated to be retained by the laws.
6. Others
STAYGE Labs is committed to protecting the User’s rights.
The User can request to view, modify, delete, or suspend the processing of their personal information at any time.
More specifically, the User can adjust settings or delete the account in the Services. The User can also contact the Customer Center and submit a request in writing or via email. The Company will take immediate actions upon receiving such a request.
If the User requests to correct errors in personal information, the Company will not use or provide such personal information to third parties until the requested correction is made.
The User can exercise their rights through their legal representative or designated person by submitting a power of attorney to verify such representation or designation.
The Company may use cookies to provide web-based services.
Cookies are used to assist the User with faster and more convenient navigation of the website and offer customized services.
[What is a cookie?]
A cookie is a small piece of data (text file) that the server sends to the User’s browser to operate a website. A cookie is stored on the User’s personal computer.
[Purpose of cookies]
Cookies are used to provide personalized and customized services to the User by storing and recalling the User's information. When the User visits a website, the website server reads the cookies saved in the User’s device to maintain the User’s settings and provide customized services. Cookies help the User access the website conveniently by using existing settings. Cookies are also used to provide the User with customized information such as optimized advertisement based on the User’s website visit history and use patterns.
[Detailed cookie list]
- Detailed cookie list
- refreshToken
- Purpose: refreshToken stores refresh tokens to re-issue the User’s access tokens
- Type: HTTP cookie
- Placed by: Mnet Plus
- Lifespan: 30 days
- refreshToken
- Cookies used by a third party software (Google Analytics)
- _ga, _gat, gid
- Type: HTTP cookies
- Placed by: Google
- Purposes:
- The Company uses these cookies to improve the Services and deliver better user experiences.
- The cookies register a unique ID used to create statistical data on the visitor’s website usage patterns.
- The cookies are used by Google Analytics to adjust request speed.
- Notice of cookies, the scope of the notice, and third party cookies
This Notice of Cookie is valid only onhttps://mnetplus.world. However, the Company will NOT provide its collected cookies to third parties. The Company’s service provider (Google Analytics) may send cookies to the User in order to track the User’s browser on other websites and build the User’s web surfing profile.
[Rejection of cookies]
Cookies do not store identification information such as names and phone numbers. and the User reserves the right to choose to install cookies. The User can thus adjust web browser settings to accept all cookies, be asked about cookies every time they are saved or refuse all cookies. Provided that, if the User refuses the installation of cookies, the User may find it harder to navigate the web or use services that require login.
- How to adjust cookie preferences or reject them
- 1) Internet Explorer
- Select “Tools” menu at the top of the browser window > Select “Internet Options” > Select the “Privacy” tab > Set cookie options
- 2) Chrome
- Click “Settings” at the top right > Click “Security and Privacy” > Click “Cookies and other site data”
- 1) Internet Explorer
STAYGE Labs is making efforts as follows to safeguard the User’s personal information.
The Company regards the protection of the User’s personal information as the highest priority and is making efforts as follows when handling personal information:
- Encrypting the User’s personal information
- The Company transmits the User’s personal information through encrypted communication channels. The Company encrypts critical information such as passwords before storing it.
- Measures against hacking or computer viruses
- The Company has installed its systems where external access is restricted so as to prevent data leaks or damage due to hacking or computer viruses. The Company also installed a system that detects and blocks hacker intrusions 24/7 along with vaccine programs that prevent the latest malware or viruses. The Company consistently examines new hacking/security technologies and implements them for the Services.
- Minimizing the number of personnel with access to personal information
- The Company works to reduce the risk of personal information leaks by minimizing the number of staff handling personal information and restricting the use of external internet services on the staff’s work PCs. The Company also implemented a systematic set of standards for the creation and modification of passwords and access privileges for the database system (for storing personal information) and the system for processing personal information and consistently conducts inspections.
- Conducting regular trainings on personal information protection
- The Company holds regular training sessions and campaigns on personal information protection accountability and security for the staff in charge of handling personal information.
STAYGE Labs complies with the European Union’s General Data Protection Regulation (GDPR).
The Company complies with the GDPR and other data protection laws. The Company uses the User’s personal information for purposes as follows:
- Member sign-up and service provision: The Company may use the User’s personal information to sign an agreement with the User and perform the Company’s obligations under the terms and conditions of the agreement. The Company may use the User’s identity, contact, finance, transaction, marketing, and communication data while providing the Services when, for example, notifying the User of changes in the Services or fulfilling the User’s request.
- Security enhancement of the Services: The Company may use the User’s personal information to verify the User’s account, investigate suspicious activities, and apply the Terms of Service to the extent necessary for the Company to protect the rights of users and the Company regarding security enhancement and to perform the Company’s obligations under the applicable laws.
- Service improvement: The Company may analyze data such as records of use to improve Services and develop new businesses by leveraging more relevant content and user experiences.
- Promotion for the Services: The Company may use the User’s personal information to conduct marketing research and send promotional information to the User. The User can withdraw their consent to receiving marketing communication by clicking “unsubscribe” in the marketing message.
Under the GDPR and other relevant laws and regulations, the User can request to transfer their personal information to another controller or to suspend the processing of the personal information. The User also reserves the right to bring complaints to the information protection authorities. The User can make inquiries about data protection to the Customer Center. The Company processes such inquiries lawfully and quickly.
The Company’s Services are NOT intended for children. The Company collects personal information of children under the age of 16 who reside in the European Economic Area (EEA). In case the personal information of a child under the age of 16 living in the EEA is collected unintentionally in connection with the provision of the Services, the Company removes the information immediately. For inquiries about the personal information of children under the age of 16, please contact the Customer Center via phone or email.
To provide Services to the User, the Company may transfer, retain, and process personal information outside the EEA including the Republic of Korea. The User’s personal information may also be saved within the EEA when the information is stored in the device that the User uses to access the Services. When the Company transfers the User’s personal information outside the EEA, the Company guarantees a similar level of data protection as within the EEA by ensuring to take any one of the following measures:
- The Company transfers personal information to countries that the European Committee (EC) considers providing an adequate level of protection for personal information protection; or
- In case the Company uses certain service providers, the Company may use an EC-approved agreement with the provider to make sure that the same protection can be applied to personal information as in Europe.
For further inquiries about the measures to be taken by the Company when transferring personal information outside the EEA, please contact the Company.
STAYGE Labs complies with the California Consumer Privacy Act (CCPA).
The following notice applies only to California residents. Under the CCPA, consumers who reside in California can request to view, delete, or suspend the sale of personal information collected by the Company and NOT to be discriminated against for exercising the aforementioned rights. If the User exercises the right to opt-out-of-sale, the Company will not sell the User’s personal information and the Company will not discriminate against the User for exercising their rights related to personal information.
- The User can request to view the personal information collected by the Company for the 12 months preceding the User’s request, including:
- The categories and specific content of the User’s personal information collected;
- The sources from which the Company collected personal information; and
- The business or commercial purposes for collecting or selling the personal information
- The User can request that the Company delete the collected personal information related to the User and the User’s device.
- The Company can use the User’s personal information only in compliance with this Privacy Policy. The Company does not believe that the Company’s use and provision of personal information constitute the sale of personal information under the CCPA. The Company has not sold the User’s personal information in the past 12 months or neither does it plan to sell personal information.
- The Company will NOT provide personal information to third parties for them to use for direct marketing activities.
- Under California laws, the Company is obligated to disclose how the Company responds to web browser’s Do Not Track (DNT) requests. With no commercial or legal standards currently available for honoring DNT requests, the Company does NOT respond to DNT requests.
- In case the User wishes to exercise their personal information rights under the California laws or has any questions on the Company’s personal information protection measures, please send email or contact the Customer Center. The Company will verify the User’s request and take reasonable measures to implement the request to the extent that the request does not violate the applicable laws. If the Company denies the User’s request, the Company will provide a reasonable reason for such denial.
Questions about personal information protection?
If you have any questions, complaints, suggestions, and other matters related to personal information protection while using the Services , please contact the Company’s Data Protection Offer (DPO) or Data Protection Department. STAYGE Labs is committed to listening and responding to our Users quickly and sincerely.
[Data Protection Officer & Data Protection Department]
- Data Protection Officer
- Name: Myunghyun Baeg
- Position: CEO
- Phone: +82-2-324-5761
- Email: info@stayge.io
- Data Protection Department
- Phone: +82-2-324-5761
- Email: info@stayge.io
If the User wishes to make a report or to consult about a potential infringement of personal information protection, please contact the following organizations:
[Personal Information Infringement Report Center]
- +82-118
- https://privacy.kisa.or.kr
[Supreme Prosecutor’s Office, Cybercrime Investigation Division]
- +82-1301
- cid@spo.go.kr
[National Police Agency, Cyber Terror Response Center]
- +82-182
- https://cyberbureau.police.go.kr
Changes to this Privacy Policy
The Company may amend the Privacy Policy to reflect changes in the applicable laws or Services. If the Privacy Policy is amended, STAYGE Labs will make a notice of the amendment and the amendment shall take effect in 7 days from the date of notification. Provided, however, if major changes in the User’s rights are to be made such as a change in personal information items collected or purpose of use, the Company will provide the User with a minimum 30-day prior notice.
- Date of notification: April, 06, 2022
- Date of enforcement: April, 06, 2022
Comments
1 comment
Vote bts
Please sign in to leave a comment.