Pledge (BoA's KAVE) Privacy Policy
Pledge Co., Ltd. (the "Company") complies with the Personal Information Protection Act and related laws to protect members' freedoms and rights, and lawfully processes and safely manages personal information. In addition, pursuant to Article 30 of the Personal Information Protection Act, the Company has established this Privacy Policy (the "Privacy Policy") to inform members of the procedures and standards for processing and protecting personal information and to promptly and smoothly handle related complaints. The Company discloses this Privacy Policy on its website so that members can easily access it at any time.
The Company's Privacy Policy includes the following matters. If this Privacy Policy is amended due to changes in applicable laws or the Company's operating policy, the Company shall assign an effective date and promptly announce the amended content on its website.
[ Table of Contents ]
Purpose of collecting and using personal information, collected items, and retention period
Outsourcing of personal information processing
Provision of personal information to third parties
Overseas transfer of personal information
Procedures and methods for destroying personal information
Matters concerning installation, operation, and refusal of automatic personal information collection devices
Matters concerning processing personal information of children under 14 years of age
Rights and obligations of members and legal representatives regarding personal information and methods of exercising them
Matters concerning measures to ensure the safety of personal information
Department and contact information responsible for personal information protection for collecting member opinions and handling complaints
Remedies for infringement of members' rights and interests
Miscellaneous
Changes to the Privacy Policy
Purpose of Collecting and Using Personal Information, Collected Items, and Retention Period
The Company collects, uses, and retains members' personal information to the minimum extent necessary to provide the Service as follows.
- Collection and use of personal information for Service use
- Items processed without the data subject's consent
| Time of Collection | Purpose of Processing | Collected Items | Retention and Use Period | Legal Basis |
|---|---|---|---|---|
| Upon membership sign-up | Member identification and management, and fan verification | Name, date of birth, mobile phone number, email, NFC UID, membership number, Pledge Identifier, password | Until membership withdrawal or deletion of a long-term inactive account | Article 15(1)4 of the Personal Information Protection Act |
| During use | Management of PP activity logs and accumulation history | Cumulative number of logins, number of visit days in the current month, last visit date and time, consecutive visit days, stay time, feed/comment/like activity, content unlock/vote count, purchase count and amount, QR scan count/location/date, and all other activity history | Until membership withdrawal | |
| Community operation | Nickname, profile image, post and comment content | Until service termination or membership withdrawal | ||
| Upon payment | Product purchase and delivery | Recipient name, contact information, postal code, address, payment method information, payment date, payment amount, order number, payer contact information | 5 years | Article 6 of the Act on Consumer Protection in Electronic Commerce |
| Upon winning an event or prize | Processing taxes and public charges | Name, recipient contact information, delivery destination information (address), resident registration number | Destroyed without delay after achieving the purpose (tax reporting) | Article 15(1)2/Article 24-2 of the Personal Information Protection Act; Article 164 of the Income Tax Act |
| Automatic collection | Service use and prevention of unauthorized use | Access records, authentication records, payment records, records of improper use, device and access information (OS, device model, IP) | - Access records: 3 months - Unauthorized use records: 30 days from the date of action | Article 15(1)6 of the Personal Information Protection Act |
- Payment method information means information on payment methods such as credit card, PayPal, or bank transfer without a bankbook.
- Payments are processed through payment gateway companies, and the Company does not store card numbers, expiration dates, or CVCs.
- Delivery destination information (address) and resident registration numbers are collected only when required for prize delivery methods or for reporting and paying taxes and public charges related to prizes.
- Items processed with the data subject's consent
| Time of Collection | Purpose of Processing | Collected Items | Retention and Use Period | Legal Basis |
|---|---|---|---|---|
| Upon consent to receive marketing | Receipt of marketing information (event and promotion notices, etc.) | (Optional) Mobile phone number, email, device identifier (push token) | Until withdrawal of consent or membership withdrawal | Article 15(1)1 of the Personal Information Protection Act |
| Upon event application | Event operation and prize delivery | (Required) Name, mobile phone number, address | 3 months after event end or completion of prize delivery | |
| Upon sign-up for the official service | Transfer and use of information collected during beta service for the official service | (Required) Name, date of birth, mobile phone number, email, delivery information | Until membership withdrawal |
- If it is necessary to retain personal information under the period consented to by members or under applicable laws such as the Act on Consumer Protection in Electronic Commerce, the Company stores personal information for the period prescribed by applicable laws and destroys it after the retention period expires. In such cases, the Company uses the retained information only for the purpose of retention, and the retention periods are as follows.
| Category | Applicable Law | Retention Period |
|---|---|---|
| National tax evidentiary materials | Framework Act on National Taxes | 10 years |
| Materials for reporting tax base and tax amount | 5 years | |
| Materials for reporting value-added tax base and tax amount | Value-Added Tax Act | 5 years |
| Records on electronic financial transactions | Electronic Financial Transactions Act | 5 years |
| Records on contracts or withdrawal of subscription | Act on Consumer Protection in Electronic Commerce, Etc. | 5 years |
| Records on payment and supply of goods, etc. | 5 years | |
| Records on consumer complaints or dispute handling | 3 years | |
| Records on display and advertisement | 6 months | |
| Website access (log) records | Personal Information Protection Act | 3 months |
- To prevent recurrence of member misconduct (abuse) or abnormal use and to prevent confusion in the Service, the Company retains and uses personal information as follows only during the period of providing the Service to the member (use period) or the dispute handling period (retention period).
- Use period: From the date of Service sign-up until Service termination
- Retention period: Retained for 30 days from the date of termination of the service agreement or until completion of dispute/complaint handling, whichever is later
- During the process of using or processing the Service, information such as website and app access (log) records may be generated and collected to provide individual services.
- Outsourcing of Personal Information Processing
The Company outsources personal information processing tasks to provide and manage member convenience, including service use agreements, A/S provision, and related ancillary tasks. The Company manages processors by specifying, through personal information outsourcing agreements and similar documents, compliance with applicable laws and guidelines, information protection and confidentiality, prohibition of provision to third parties, responsibility in the event of accidents, and the obligation to return/destroy personal information immediately upon termination of the outsourcing period.
The Company requires companies entrusted with personal information processing (processors) to take all measures related to personal information protection. If a processor entrusted with a member's personal information causes damage to the member intentionally or negligently, the processor shall bear all responsibility therefor.
If the content of outsourced tasks or a processor changes, the Company will disclose the change without delay through this Privacy Policy.
| Processor | Purpose of Outsourced Task |
|---|---|
| KSNET Co., Ltd. | Payment agency service (PG company) |
| Korea PortOne Co., Ltd. | |
| PayPal | |
| Ddaengddaengddaeng Co., Ltd. | All domestic and overseas delivery and CS-related tasks |
| Amazon Web Services (AWS) | Infrastructure operation for Service provision and prevention of unauthorized Service use |
- Provision of Personal Information to Third Parties
The Company processes members' personal information only within the scope specified in the Terms of Service or this Privacy Policy and does not use personal information beyond the specified scope or provide it to third parties. However, exceptions apply in the following cases.
- Where separate consent has been obtained from the member
- Where special provisions exist in other laws
- Where it is clearly recognized as necessary for the urgent interests of the life, body, or property of the member or a third party
- Where necessary for public safety and security, such as public health
- Overseas Transfer of Personal Information
Because this Service is provided worldwide, including in the Republic of Korea, the Company may provide or outsource personal information overseas as follows for overseas members' sign-up, payment, and stable Service provision.
| Recipient | Country of Transfer | Transferred Items | Purpose of Transfer | Timing and Method of Transfer | Retention Period |
|---|---|---|---|---|---|
| PayPal | United States | Name, nationality, mobile phone number, email address, delivery address, card number | Overseas payment processing | Network transfer upon payment | In accordance with applicable laws |
| Amazon Web Services (AWS) | United States | Member information (name, mobile phone number, email address, date of birth), Service use records, access logs, order, payment, and delivery information (recipient name, delivery destination, phone number, email), posts/comments/content, point usage history | Infrastructure operation | Network transfer during Service use | Until membership withdrawal or termination of the outsourcing agreement |
Members may refuse overseas transfer of personal information. However, such transfer is essential for providing the Service. If a member refuses the transfer, use of the Service may be restricted. If a member does not want overseas transfer, the member may withdraw from membership or request suspension of personal information processing through the customer center.
- Procedures and Methods for Destroying Personal Information
When personal information collected from members becomes unnecessary due to expiration of the retention period, achievement of the collection/use purpose, or similar reasons, the Company destroys members' personal information without delay. The targets, procedures, and methods are as follows.
- Target of destruction: Member personal information whose retention period and preservation period under applicable laws have expired
- Destruction procedure: Information provided by members for Service sign-up and similar purposes is moved to a separate database after the purpose is achieved, stored for a certain period according to internal policies and other applicable laws, and then destroyed by the methods specified below. Personal information moved to a separate database is not used for any purpose other than retention unless retained by law.
- Destruction methods
Personal information written or printed on paper: shredded or incinerated
Personal information stored as electronic files such as in a database: deleted by a technical method that prevents restoration of records
Matters Concerning Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
- The Company uses cookies that store and frequently retrieve usage information to provide smooth services, such as maintaining members' login sessions. The Company does not collect cookies for marketing purposes and uses only essential cookies necessary to maintain the Service on a limited basis.
- Cookies are small amounts of information sent by the server used to operate a website to the data subject's browser and stored on a computer or mobile device. Data subjects may refuse cookie storage through browser settings, but in such cases, there may be difficulties in using some services that require login.
- Members may configure settings such as cookie refusal through the following browser options.
- How to block cookies in a web browser
- Chrome: Select "⁝" at the upper right of the web browser → New incognito window (shortcut: Ctrl+Shift+N)
- Edge: Select "⋯" at the upper right of the web browser → New InPrivate window (shortcut: Ctrl+Shift+N)
- How to block cookies in a mobile browser
- Chrome: Select "⁝" at the upper right of the mobile browser → New incognito tab
- Safari: Mobile device settings → Apps → Safari → Advanced → Block All Cookies
- Samsung Internet: Select the "Tabs" icon at the bottom of the mobile browser → Turn on Secret mode → Start
- Matters Concerning Processing Personal Information of Children Under 14 Years of Age
- If consent is required for processing personal information of children under 14 years of age, the Company obtains consent from their legal representatives.
- When obtaining consent from a legal representative regarding the processing of personal information of a child under 14 years of age, the Company may request the minimum information necessary from the child, such as the legal representative's name and mobile phone number. The Company verifies such consent by having the legal representative indicate consent on an internet site where the consent details are posted and by notifying the legal representative via mobile phone text message that the consent indication has been confirmed.
- Rights and Obligations of Members and Legal Representatives Regarding Personal Information and Methods of Exercising Them
Members (including legal representatives in the case of children under 14 years of age) may at any time visit the Service to request access to, correction, deletion, and suspension of processing of their registered personal information (collectively, "access, etc."), or withdraw consent to the collection, use, outsourcing, or provision of personal information.
Methods for requesting access to, correction of, or withdrawal of consent for personal information are as follows.
- Access to, correction, deletion, and suspension of processing of personal information
- Members may request access, etc. to personal information through email, the customer center, or similar channels.
- When a member requests access, etc. to personal information, the Company verifies the member's identity by conducting an authentication procedure within the online service or by receiving a copy of an identification document such as a resident registration card, passport, or driver's license.
- When a member's agent requests access, etc. to the member's personal information, the Company verifies whether the person is an agent by requesting evidence such as a power of attorney showing the agency relationship, the named member's certificate of registered seal impression, and the agent's identification document.
- If a member requests correction of an error in personal information, the Company does not use or provide the relevant personal information until correction is completed. If incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction result without delay so that the correction is made.
- Withdrawal of consent to collection, use, outsourcing, or provision of personal information
- Members may request withdrawal of consent to personal information through email, the customer center, or similar channels.
- Members may withdraw consent after completing the Company's identity verification procedure.
- The Company may exceptionally restrict access to and correction of personal information in the following cases.
Where there is a risk of significantly harming the life, body, property, rights, or interests of the member (data subject) or a third party
Where there is a risk of significantly hindering the business of the relevant service provider
Where it violates laws
Matters Concerning Measures to Ensure the Safety of Personal Information
The Company establishes the following technical, administrative, and physical protective measures to ensure safety so that members' personal information is not lost, stolen, leaked, altered, or damaged.
- Technical protective measures
- Personal information is protected by passwords, and important data is protected through separate security functions such as encrypting files and transmission data or using file lock functions.
- The Company takes measures to prevent damage from computer viruses by using antivirus programs. Antivirus programs are updated periodically, and if a virus suddenly appears, the Company introduces and applies the vaccine as soon as it becomes available to prevent infringement of personal information.
- The Company adopts security devices (SSL) to safely transmit personal information over networks.
- To prevent members' personal information from being leaked due to hacking or similar incidents, the Company installs systems in areas where external access is controlled and uses devices that block intrusions.
- Administrative protective measures
- The Company establishes procedures necessary for managing and accessing members' personal information, ensures that executives and employees understand and comply with them, and periodically checks compliance.
- The Company limits persons who can process members' personal information to the minimum necessary, manages access authority, and provides training to ensure compliance with laws and policies. Persons who process members' personal information are as follows.
- Persons who directly or indirectly interact with members to perform work
- Persons in charge of personal information management and protection, such as the Chief Privacy Officer and personal information protection staff
- Other persons whose access to personal information is unavoidable for business purposes
- When hiring new employees, the Company prevents leakage of information, including personal information, by requiring them to sign an information protection pledge, regularly reminds them of personal information protection obligations, and establishes and implements internal procedures for auditing compliance.
- Handover of duties by personal information processors is conducted thoroughly while maintaining security, and responsibility for personal information infringement incidents after joining or leaving the Company is clearly defined.
- Physical protective measures
The Company designates computer rooms, data storage rooms, and similar areas as special protection zones and implements access management procedures, including entry and access control for unauthorized persons.
Documents and auxiliary storage media are stored in secure locations with locking devices, and the Company establishes and implements an internal system to control bringing auxiliary storage media in and out.
Department and Contact Information Responsible for Personal Information Protection for Collecting Member Opinions and Handling Complaints
The Company designates the following Chief Privacy Officer to protect members' personal information and handle complaints and damage relief related to personal information processing.
- Chief Privacy Officer Name: Minjun Lee Affiliation: Pledge Co., Ltd. Contact: mj.lee@dayonedream.com
- Personal Information Protection Manager Name: Jinhyeong Noh Affiliation: Pledge Co., Ltd. Contact: jh.noh@dayonedream.com
Members may contact the Chief Privacy Officer and the department in charge of personal information protection for all personal information protection-related inquiries, complaint handling, damage relief, and similar matters arising from use of the Company's Service. The Company will provide prompt and accurate answers to members' inquiries.
- Remedies for Infringement of Members' Rights and Interests
Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, and similar organizations to obtain remedies for personal information infringement. For other reports or consultations concerning personal information infringement, please contact the following organizations.
- Personal Information Dispute Mediation Committee: 1833-6972 without area code (https://www.kopico.go.kr/)
- Personal Information Infringement Report Center: 118 without area code (https://privacy.kisa.or.kr/)
- Supreme Prosecutors' Office: 1301 without area code (https://www.spo.go.kr/)
- Korean National Police Agency: 182 without area code (https://ecrm.police.go.kr/)
- Miscellaneous
The Company may provide links to other sites or materials. Because the privacy policies of external sites are unrelated to the Company, please review the policies of those sites.
- Changes to the Privacy Policy
- If additions, deletions, or modifications are made to the current Privacy Policy due to changes in laws, policies, security technologies, or similar matters related to personal information protection, the Company will notify members through website announcements at least 7 days before the amended Privacy Policy takes effect.
- This Privacy Policy applies from June 22, 2026.