SEOULEXPERIENCE PRIVACY POLICY & CROSS-BORDER DATA TRANSFER CONSENT
Version: 2026-08-03
Effective Date: August 3, 2026
Last Updated: August 3, 2026
Kori Between, Inc. ("Company", "we", "us", or "our") is committed to protecting your privacy and ensuring transparency in how your personal data is collected, processed, stored, and transferred. This Privacy Policy applies to all users ("Travelers"), experience hosts ("Localists"), and visitors accessing our platform at SeoulExperience.com and associated mobile applications (collectively, the "Platform").
1. Data Controller & Designated Representatives
(a) Global Data Controller:
Kori Between, Inc. (Delaware C-Corp)
131 Continental Dr, Suite 305, Newark, DE 19713, USA
Email: support@koribetween.com
(b) Korean Operating Entity and Domestic Contact:
Company’s affiliated Korean entity provides local operations, Customer support, Localist onboarding, payout support, and tax-withholding administration and serves as a domestic privacy contact where applicable:
Kori Between Inc. (Republic of Korea)
66 Chungmin-ro, T-9151B, Songpa-gu, Seoul, Republic of Korea
Business Tax ID: 415-81-60456 | Representative: Young Son Om
Contact: support@koribetween.com
2. Information We Collect
We collect personal data directly from you, automatically through your device usage, and from third-party services:
(a) Traveler Personal Data:
-
Account & Profile Data: Full name, email address, phone number, language preference, and profile details.
-
Booking & Transaction Data: Purchase history, Experience reservations, dates, special requests, and emergency contact details.
-
Financial & Payment Data: Payment method details (credit card tokens, billing address) processed securely via our payment gateway (Stripe).
-
Technical Data: IP address, browser type, device information, operating system, time zone, and interaction logs.
(b) Localist Partner Data:
-
Identity & Verification Data: Full legal name, photo identification, profile details, and business registration numbers.
-
Tax & Financial Data: Resident Registration Number (RRN) or local tax ID (for statutory tax withholding under Korean law), bank account details, and payout history.
3. Legal Bases & Purposes for Processing
We process personal data only for the purposes and on the legal bases available under applicable law:
| Processing Purpose | Categories of Data | Legal Basis |
|---|---|---|
| Facilitating Bookings & Experience Delivery | Name, contact info, booking details, emergency contact | Contractual Necessity: Required to fulfill our marketplace contract with you. |
| Payment Processing & Localist Payouts | Payment tokens, bank account details, transaction records | Contractual Necessity & Legal Obligation: Required for payment execution and statutory accounting. |
| Tax Withholding & Financial Reporting | Tax ID / RRN, payout records, tax invoices | Legal Obligation: Compliance with Korean Framework Act on National Taxes & Income Tax Act. |
| Platform Security & Fraud Prevention | IP address, device identifiers, login logs | Legitimate Interests: Protecting the Platform, users, and preventing payment fraud. |
| Customer Support & Dispute Mediation | Support communications, dispute evidence, chat logs | Legitimate Interests & Contractual Performance: Resolving inquiries and managing claims. |
| Optional Communications | Email address, push token, device/app identifier, notification preference | Consent or another basis available under applicable law; users may opt out of optional push or marketing messages. |
4. Cross-Border Data Transfer Consent
To operate the Platform, personal data may be transferred, remotely accessed, processed, or stored outside the country where it was collected. Account creation presents a separate, explicit cross-border-transfer consent. Agreeing to the Terms or merely browsing the Platform does not replace that consent.
| Recipient | Country / Region | Data and Purpose | Timing and Method | Retention |
|---|---|---|---|---|
| Kori Between, Inc. | United States | Account, booking, transaction, support, and Localist data for Platform operation, customer support, and payment orchestration. | Encrypted network transfer when an account, booking, payment, support, or Localist function is used. | Account lifetime plus the applicable statutory or dispute period. |
| Supabase, Inc. | United States / global infrastructure | Account, authentication, database, storage, booking, message, and audit data for backend hosting, security, and backup. | Encrypted network transfer and hosted storage when Platform backend functions are used. | Until account deletion, service-contract end, or the applicable statutory period. |
| Vercel Inc. | United States / global infrastructure | Web request, IP address, device, security, and limited application data for web hosting, delivery, and operational logs. | Encrypted network transfer when pages and server-rendered routes are accessed. | Provider log lifecycle or earlier deletion where configured. |
| Stripe, Inc. and affiliates | United States / global payment network | Payment token, billing and transaction data for Checkout, fraud prevention, refunds, disputes, and reconciliation. | Encrypted hosted Checkout and API transfer when payment or refund functions are used. | Stripe’s applicable financial-retention period and legal obligations. |
| Google LLC (Sign-In / Firebase Cloud Messaging) | United States / global infrastructure | Google account identifier, name, email, profile image; push token, device/app identifiers, preference, and notification payload for optional sign-in and push. | Encrypted OAuth/API transfer when the optional feature is selected. | Google account settings for Sign-In data; token deletion, invalidation, opt-out, or provider expiry for push data. |
| Resend, Inc. | United States / global email infrastructure | Email address, message content, delivery metadata, and provider message identifier for transactional email delivery and troubleshooting. | Encrypted API transfer when a transactional email is sent. | Provider delivery-log lifecycle or earlier deletion where configured. |
| Kori Between Inc. | Republic of Korea | Booking support, Localist onboarding, tax, payout, refund, and dispute data for local operations. | Encrypted authorized access when local support or settlement work is required. | Applicable booking, payment, tax, payout, and dispute periods. |
You may refuse or later withdraw cross-border-transfer consent. Refusal or withdrawal does not affect processing already lawfully completed, but we cannot create or continue an account or provide booking, payment, notification, or support functions that require the relevant transfer.
5. Data Retention & Destruction Schedule
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with statutory legal requirements:
(a) Standard Account Data: Retained for the duration of your active account subscription. Upon account deletion requests, personal data is permanently destroyed or anonymized within thirty (30) days, except where statutory retention applies.
(b) Statutory Retention Periods (South Korean Law):
-
Records on Contracts and Cancellation of Subscriptions: Retained for 5 years (Act on Consumer Protection in Electronic Commerce).
-
Records on Payment Settlement and Supply of Goods/Services: Retained for 5 years (Act on Consumer Protection in Electronic Commerce).
-
Tax Invoices, Payouts, and Statutory Tax Withholding Records: Retained for 5 years (Framework Act on National Taxes & Corporate Tax Act).
-
Consumer Complaints or Dispute Handling Records: Retained for 3 years (Act on Consumer Protection in Electronic Commerce).
-
Website Login and Access Records: Retained for 3 months where that statutory period applies, or for the shorter operational security-log lifecycle otherwise.
(c) Destruction Procedure: Electronic files are securely and permanently deleted using technical destruction methods that prevent recovery. Physical paper records are shredded or incinerated.
6. Disclosures to Third Parties & Subprocessors
We do not sell personal data. We disclose personal data only as needed to operate the Platform, complete a transaction, deliver an Experience, protect the service, resolve a dispute, or comply with law:
-
Backend Infrastructure: Supabase, Inc. (authentication, database, storage, backend functions, backup, and security operations).
-
Web Hosting: Vercel Inc. (web application hosting, content delivery, request processing, and operational logs).
-
Payment Processing: Stripe, Inc. and its affiliates (hosted Checkout, fraud prevention, refunds, disputes, and financial reconciliation). Company does not receive or store a full card number from Stripe.
-
Identity and Customer Communication: Google LLC for optional Google Sign-In and Firebase Cloud Messaging; Resend, Inc. for transactional email.
-
Localists: Traveler name, contact and participation information, booking time, requests, and other information reasonably required to deliver a booked Experience.
-
Legal Compliance: Public authorities or law enforcement agencies when required by mandatory legal order, court summons, or applicable law.
7. Cookies and Tracking Technologies
(a) What Are Cookies: Cookies are small text files placed on your device to collect standard internet log information and visitor behavior patterns.
(b) Categories of Cookies We Use:
-
Essential Cookies: Necessary for the technical operation of the Platform, secure authentication, and shopping cart functions.
-
Functional Cookies: Remember your preferences (such as selected currency or language).
(c) Managing Cookies: You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. Note that if you disable or refuse essential cookies, some parts of the Platform may become inaccessible or fail to function properly.
(d) Do Not Track and Cross-Site Collection: The Platform does not currently deploy third-party advertising or analytics technology intended to track a user’s activity over time across unrelated websites. Because there is no uniform browser Do Not Track standard, the Platform does not currently alter essential service behavior in response to a Do Not Track signal. Infrastructure, payment, email, and push providers may process request or device metadata only to deliver, secure, or troubleshoot their contracted service as described above. If this practice materially changes, this Policy will be updated and any required choice will be provided.
8. Technical & Organizational Data Security Measures
We use administrative, technical, and organizational safeguards appropriate to the data and risk, including:
-
Transport and Storage Protection: Encrypted network transport and provider-managed encryption at rest where available.
-
Access Controls: Role-based application and service boundaries restrict operational access to authorized personnel with a need to know.
-
Operational Protection: Audit logging, security review, secrets management, and provider security controls are used to detect and reduce unauthorized access.
-
No storage or transmission method can guarantee absolute security.
9. Your Privacy Rights & How to Exercise Them
Subject to applicable law, you may exercise the following rights:
-
Right to Access & Inspection: Request a copy of the personal data we hold about you.
-
Right to Rectification: Request correction of inaccurate or incomplete data.
-
Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data, subject to statutory retention obligations.
-
Right to Restrict or Object to Processing: Object to or request limitations on processing based on legitimate interests or direct marketing.
-
Right to Data Portability: Request transfer of your data to another controller in a structured format.
To exercise a right, review or correct account information, withdraw consent, or raise a privacy complaint, contact support@koribetween.com. We may verify identity before acting and will respond within the period required by applicable law. Material changes to this Policy will be identified by a new version and effective date and, where renewed consent is required, presented before the affected account or booking function continues. Prior versions are retained for audit and reference.