개인정보취급방침

Beauty Bash Seoul Privacy Policy

 

Effective 1 January 2026

Beauty Bash Seoul (the "Company") establishes and discloses the following privacy policy in order to protect users' personal information in accordance with applicable law, including the Personal Information Protection Act, and to handle complaints and issues relating to personal information promptly.

Article 1 (Purposes of Processing Personal Information)

The Company processes personal information for the following purposes. Where a purpose changes, the Company will take the necessary measures, such as obtaining separate consent, in accordance with applicable law.

  1. Sign-up and Member management: confirming the intention to join, identifying Members, maintaining and managing Member status, and giving notices.
  2. Provision of the Booking service: accepting, confirming, changing and cancelling Bookings, providing Partner Store information, sending Booking-related notifications (confirmation, upcoming visit reminders, changes, cancellations and refusals), and informing Members of details of provision to third parties.
  3. Customer support: responding to enquiries and consultations, and retaining records for complaint handling and dispute mediation.
  4. Sending marketing information: providing benefits and events, promotion and product news, and Korean beauty and travel information (only to Members who have consented to receive it).
  5. Service improvement and safety: managing usage records (such as completed visits and no-shows), preventing improper use, and analysing Service usage statistics.

Article 2 (Items of Personal Information Processed)

CategoryItemsPoint of collection

Sign-up (mandatory)

Email address, password

At sign-up

Marketing (optional)

Whether marketing consent is given

At sign-up, or when requesting a Booking

Sign-up (optional)

Passport name in English, date of birth and other information to be used for Bookings (where the Member optionally enters it in advance)

At sign-up

Booking (mandatory)

Passport name in English, nationality, gender, date of birth, email address (auto-filled from Member information), mobile phone number (text verification), messenger contact (type and ID, or messenger QR code image)

When requesting a Booking

Booking (optional)

Requests (entered by the Member)

When requesting a Booking

Booking registered by a Store on behalf of a Member

Booker's name or passport name in English, nationality, Service display language, contact details (at least one of mobile phone number and messenger contact), email address (if entered), Booking date and time

When a Partner Store registers a Booking on behalf of a Member

Booking Deposit (where applicable)

Whether the Booking Deposit has been paid, and the date and time payment was confirmed

When a Booking Deposit is paid for a Booking made through consultation

Customer enquiries

Information contained in the enquiry or consultation

When an enquiry is made

Automatically generated

Service display language, Booking number, Booking referral path, history of Bookings, visits, cancellations and no-shows, processing history, access logs (including IP address), cookies, device information

In the course of using the Service

  • Why passport name in English, nationality, gender and date of birth are collected as mandatory information for Bookings: Stores (including hospitals and clinics) use this information to verify the identity of visitors and to determine whether a treatment or service can be provided. Given the characteristics of overseas customers, passport-based identity information is the basic unit for customer handling.
  • A messenger QR code image may be registered by a Member instead of, or together with, an ID, and is used only for the purpose of the Store connecting to the Member's messenger channel in order to handle the visit.
  • A Booking registered by a Store on behalf of a Member is a case where a Partner Store registers a Booking it received by telephone, in person or otherwise in the Company's system. In such a case, the Company collects personal information from a source other than the data subject and informs the data subject of the source of collection and other matters in accordance with Article 10(5).
  • The Company does not collect information necessary for the performance of contracts, such as Bookings, as mandatory information at sign-up. Such information is collected at sign-up only where the Member optionally enters it in advance, and is otherwise collected at the point at which the need arises, such as when a Booking is made.

Article 3 (Processing and Retention Periods)

(1) The Company processes and retains personal information within the retention period prescribed by law or the period consented to at the time of collection.

(2) Retention periods by item are as follows.

ItemRetention period

Sign-up and Member management information

Until withdrawal from membership (destroyed immediately on withdrawal)

Booking and transaction records (contracts, withdrawal of subscription, Booking Deposit payments, etc.)

5 years (Act on Consumer Protection in Electronic Commerce, Etc.)

Messenger QR code images

Until withdrawal from membership or the end of the transaction or use relationship, then destroyed

Information on Bookings registered by a Store on behalf of a Member

1 year after completion of the visit, cancellation of the Booking or no-show handling. For transaction records subject to a statutory retention obligation, the period prescribed by that law

Records of consumer complaints and dispute handling

3 years (Act on Consumer Protection in Electronic Commerce, Etc.)

Access logs

3 months (Protection of Communications Secrets Act)

Records of marketing consent and sending

Until consent is withdrawn or the Member withdraws from membership

Article 4 (Personal Information of Children Under 14)

(1) The Company does not collect the personal information of children under 14 years of age.

(2) The Company does not operate a separate age verification procedure and treats users as having confirmed that they are 14 years of age or older.

(3) Where the Company becomes aware that the personal information of a child under 14 years of age has been collected, it destroys that information without delay.

Article 5 (Provision of Personal Information to Third Parties)

(1) The Company provides personal information to third parties only with the consent of the data subject or where there is a legal basis.

(2) In the Booking service, personal information is provided as follows, with the consent of the data subject obtained at the time of the Booking request.

RecipientItems providedPurpose of provisionRetention and use period

The Partner Store booked by the Member

Passport name in English, nationality, gender, date of birth, Service display language, messenger contact (ID or QR code image), mobile phone number, requests, Booking date and time, Booking number

Confirming and performing the Booking, handling the visit, and contact relating to Booking changes and cancellations

Until withdrawal from membership or the end of the transaction or use relationship (for information that must be retained under applicable law, the period prescribed by that law)

(3) A Partner Store that receives personal information may use it only within the scope of the purpose of provision. Use for any other purpose and re-provision to third parties are prohibited. The Company governs this through its partner agreements and ensures compliance.

(4) For the performance and management of Bookings, the Company may receive information about Bookings from Partner Stores, such as whether a visit took place and how the Booking was handled.

Article 6 (Criteria for Additional Use and Provision)

The Company may additionally use or provide personal information without the consent of the data subject, within a scope reasonably related to the purpose of collection, pursuant to Articles 15(3) and 17(4) of the Personal Information Protection Act. In such cases, the Company considers the relationship to the original purpose of collection, foreseeability in light of the circumstances of collection and processing practices, whether the interests of the data subject are infringed, and whether measures to ensure security have been taken.

Article 7 (Outsourcing of Personal Information Processing)

(1) The Company outsources the processing of personal information as follows for the smooth handling of its business. In its outsourcing agreements, the Company stipulates that personal information be managed securely in accordance with applicable law, and supervises compliance.

Service providerOutsourced work

NHN Cloud

Sending domestic and international text messages (SMS), sending KakaoTalk notification messages to Partner Stores, and sending Booking-related and marketing emails

Amazon Web Services, Inc.

Server operation, data storage and content delivery (Seoul Region, Republic of Korea)

Vercel Inc.

Web service hosting (global edge network)

Google LLC

Sending Booking-related and marketing emails (Google Workspace), and analysis of Service usage statistics (Google Analytics)

(2) Where the content of the outsourced work or the service provider changes, the Company will disclose the change through this policy without delay.

Article 8 (Cross-Border Transfer of Personal Information)

(1) Personal information collected by the Company is stored in a data centre located in the Republic of Korea (the Amazon Web Services Seoul Region) and managed within Korea. However, some information is processed outside Korea as follows.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

(2) Where a cross-border transfer is added, the Company will comply with applicable law, including by giving notice of and obtaining consent to the necessary matters such as the recipient, the items transferred, the destination country, and the purpose of use and retention period, pursuant to Article 28-8 of the Personal Information Protection Act.

Article 9 (Destruction of Personal Information)

(1) The Company destroys personal information without delay once it becomes unnecessary, for example because the retention period has expired or the purpose of processing has been achieved.

(2) Information that must be retained under applicable law is stored separately in a separate database or storage location.

(3) Method of destruction: electronic files (including image files such as messenger QR code images) are deleted by a method that makes recovery impossible, and printed materials are shredded or incinerated.

Article 10 (Rights and Obligations of Data Subjects and How to Exercise Them)

(1) A data subject may at any time request access to, correction of, deletion of, or suspension of the processing of their personal information, or withdraw consent.

(2) Rights may be exercised through functions within the Service (such as the Account Settings screen or the unsubscribe link at the bottom of emails), in writing, or by email. The Company will act within the period prescribed by applicable law.

(3) Rights may be exercised through a legal representative or an authorised agent, in which case a power of attorney or other document prescribed by applicable law must be submitted.

(4) The department and contact details for receiving and handling requests for access and similar requests are the same as those of the privacy officer in Article 15.

(5) Where the Company collects and processes personal information from a source other than the data subject (such as where a Partner Store registers a Booking on behalf of a Member), the Company will, upon the request of the data subject, immediately inform them of the source of collection, the purpose of processing, and the fact that they have the right to request suspension of processing or to withdraw consent.

Article 11 (Measures to Ensure the Security of Personal Information)

The Company takes the following measures to ensure the security of personal information.

  1. Administrative measures: establishing and implementing an internal management plan, and minimising and training personnel who handle personal information.
  2. Technical measures: managing access rights, encrypting personal information in storage and transmission, retaining access logs, and operating security programs.
  3. Physical measures: controlling access to facilities and materials in which personal information is stored.

Article 12 (Cookies and Other Automatic Collection Devices)

(1) The Company uses cookies to maintain the logged-in state, save user settings, and analyse use of the Service.

(2) Users may refuse the storage of cookies or delete stored cookies in the settings of the web browser they use. The settings path differs by browser and can generally be changed through the privacy or security section of the browser's settings screen.

(3) Where the storage of cookies is refused, use of some parts of the Service, such as functions that require login, may be restricted.

Article 13 (Behavioural Information and Third-Party Tools)

(1) The Company uses web analytics tools such as Google Analytics to analyse Service usage statistics and improve the Service, and records of visits to and use of the Service may be collected in that process. The cross-border transfer arising from this is set out in Article 8.

(2) The Company displays a Google review widget provided by a third party on Store detail screens. In the course of displaying the widget, the widget provider and Google may collect access information through cookies and similar technologies. Such processing is governed by the privacy policy of the provider concerned.

(3) Users may refuse such collection through the cookie-blocking settings of their browser or through opt-out mechanisms provided by the relevant tool (such as the Google Analytics opt-out browser add-on).

(4) The Company does not provide behavioural information to third parties for online tailored advertising. If tailored advertising is introduced, the Company will reflect it in this policy and give notice.

Article 14 (Automated Processing)

(1) The Company processes the following matters by automated means for the operation of the Booking service. Other determinations (such as confirming improper use and refusing to accept a Booking) are handled by a member of staff.

ProcessingCriteriaEffect on the data subject

Automatic confirmation of a no-show

Where the Partner Store takes no action by the time notified within the Service after the Booking time has passed

The Booking is recorded as a no-show. For Bookings for which a Booking Deposit has been paid, the refund amount may vary in accordance with the standards notified

(2) The Company informs the data subject of the outcome of processing under paragraph (1). A data subject may request an explanation of, or object to, that outcome through the customer support channel. Where verification shows that the processing was incorrect, the Company will correct it and take any necessary measures, including a refund.

(3) The Company does not make final determinations that materially affect the rights or obligations of a data subject without human involvement. Where an objection is received, it is verified and handled by a member of staff. Objections may be submitted through the contact details in Article 15 or the customer support channel within the Service.

Article 15 (Privacy Officer)

CategoryDetails

Privacy officer

KIM Young Soo

Department

Platform Business Division

Contact

unicornluv@naver.com

Data subjects may direct all enquiries, complaints and requests for remedy relating to the protection of personal information arising during use of the Service to the privacy officer, and the Company will respond and act without delay.

Article 16 (Remedies for Infringement of Rights)

Data subjects who need to report or seek advice regarding an infringement of personal information may contact the following bodies.

  1. Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
  2. Privacy Infringement Report Center: 118 (privacy.kisa.or.kr)
  3. Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
  4. National Police Agency: 182 (ecrm.police.go.kr)

Article 17 (Exercise of Rights by Users Outside Korea)

This policy has been prepared in accordance with the Personal Information Protection Act of the Republic of Korea. A data subject residing outside the Republic of Korea who wishes to exercise rights under the laws of their jurisdiction may make a request to the contact details in Article 15. The Company will handle the request to the extent permitted by applicable law and inform the data subject of the outcome.

Article 18 (Changes to This Policy)

Where the content of this policy is added to, deleted or amended, the Company will give notice through a notice within the Service (such as an on-screen notice or a push notification) from at least 7 days before the change takes effect (30 days before, for changes that are unfavourable to users or otherwise material).

Article 19 (Language of This Policy)

This policy is provided in English only. English is the sole language in which the Company provides this policy, and users review this policy in English regardless of the display language they select for the Service.

Addendum

(1) This policy takes effect on 1 January 2026.

(2) Upon this policy taking effect, the previous policy (effective 2 April 2025) is superseded.

  • View previous Privacy Policy (Apr 2, 2025 ~ Aug 5, 2026)

   ?