운영 정책 · 운영 정책

private

Pledge (BoA's KAVE) Privacy Policy

Pledge Co., Ltd. (the "Company") complies with the Personal Information Protection Act and related laws to protect members' freedoms and rights, and lawfully processes and safely manages personal information. In addition, pursuant to Article 30 of the Personal Information Protection Act, the Company has established this Privacy Policy (the "Privacy Policy") to inform members of the procedures and standards for processing and protecting personal information and to promptly and smoothly handle related complaints. The Company discloses this Privacy Policy on its website so that members can easily access it at any time.

The Company's Privacy Policy includes the following matters. If this Privacy Policy is amended due to changes in applicable laws or the Company's operating policy, the Company shall assign an effective date and promptly announce the amended content on its website.

[ Table of Contents ]

  1. Purpose of collecting and using personal information, collected items, and retention period

  2. Outsourcing of personal information processing

  3. Provision of personal information to third parties

  4. Overseas transfer of personal information

  5. Procedures and methods for destroying personal information

  6. Matters concerning installation, operation, and refusal of automatic personal information collection devices

  7. Matters concerning processing personal information of children under 14 years of age

  8. Rights and obligations of members and legal representatives regarding personal information and methods of exercising them

  9. Matters concerning measures to ensure the safety of personal information

  10. Department and contact information responsible for personal information protection for collecting member opinions and handling complaints

  11. Remedies for infringement of members' rights and interests

  12. Miscellaneous

  13. Changes to the Privacy Policy

  14. Purpose of Collecting and Using Personal Information, Collected Items, and Retention Period

The Company collects, uses, and retains members' personal information to the minimum extent necessary to provide the Service as follows.

  1. Collection and use of personal information for Service use
  1. Items processed without the data subject's consent
Time of Collection Purpose of Processing Collected Items Retention and Use Period Legal Basis
Upon membership sign-up Member identification and management, and fan verification Name, date of birth, mobile phone number, email, NFC UID, membership number, Pledge Identifier, password Until membership withdrawal or deletion of a long-term inactive account Article 15(1)4 of the Personal Information Protection Act
During use Management of PP activity logs and accumulation history Cumulative number of logins, number of visit days in the current month, last visit date and time, consecutive visit days, stay time, feed/comment/like activity, content unlock/vote count, purchase count and amount, QR scan count/location/date, and all other activity history Until membership withdrawal
Community operation Nickname, profile image, post and comment content Until service termination or membership withdrawal
Upon payment Product purchase and delivery Recipient name, contact information, postal code, address, payment method information, payment date, payment amount, order number, payer contact information 5 years Article 6 of the Act on Consumer Protection in Electronic Commerce
Upon winning an event or prize Processing taxes and public charges Name, recipient contact information, delivery destination information (address), resident registration number Destroyed without delay after achieving the purpose (tax reporting) Article 15(1)2/Article 24-2 of the Personal Information Protection Act; Article 164 of the Income Tax Act
Automatic collection Service use and prevention of unauthorized use Access records, authentication records, payment records, records of improper use, device and access information (OS, device model, IP) - Access records: 3 months - Unauthorized use records: 30 days from the date of action Article 15(1)6 of the Personal Information Protection Act
  1. Items processed with the data subject's consent
Time of Collection Purpose of Processing Collected Items Retention and Use Period Legal Basis
Upon consent to receive marketing Receipt of marketing information (event and promotion notices, etc.) (Optional) Mobile phone number, email, device identifier (push token) Until withdrawal of consent or membership withdrawal Article 15(1)1 of the Personal Information Protection Act
Upon event application Event operation and prize delivery (Required) Name, mobile phone number, address 3 months after event end or completion of prize delivery
Upon sign-up for the official service Transfer and use of information collected during beta service for the official service (Required) Name, date of birth, mobile phone number, email, delivery information Until membership withdrawal
  1. If it is necessary to retain personal information under the period consented to by members or under applicable laws such as the Act on Consumer Protection in Electronic Commerce, the Company stores personal information for the period prescribed by applicable laws and destroys it after the retention period expires. In such cases, the Company uses the retained information only for the purpose of retention, and the retention periods are as follows.
Category Applicable Law Retention Period
National tax evidentiary materials Framework Act on National Taxes 10 years
Materials for reporting tax base and tax amount 5 years
Materials for reporting value-added tax base and tax amount Value-Added Tax Act 5 years
Records on electronic financial transactions Electronic Financial Transactions Act 5 years
Records on contracts or withdrawal of subscription Act on Consumer Protection in Electronic Commerce, Etc. 5 years
Records on payment and supply of goods, etc. 5 years
Records on consumer complaints or dispute handling 3 years
Records on display and advertisement 6 months
Website access (log) records Personal Information Protection Act 3 months
  1. To prevent recurrence of member misconduct (abuse) or abnormal use and to prevent confusion in the Service, the Company retains and uses personal information as follows only during the period of providing the Service to the member (use period) or the dispute handling period (retention period).
  1. Use period: From the date of Service sign-up until Service termination
  2. Retention period: Retained for 30 days from the date of termination of the service agreement or until completion of dispute/complaint handling, whichever is later
  1. During the process of using or processing the Service, information such as website and app access (log) records may be generated and collected to provide individual services.
  1. Outsourcing of Personal Information Processing

The Company outsources personal information processing tasks to provide and manage member convenience, including service use agreements, A/S provision, and related ancillary tasks. The Company manages processors by specifying, through personal information outsourcing agreements and similar documents, compliance with applicable laws and guidelines, information protection and confidentiality, prohibition of provision to third parties, responsibility in the event of accidents, and the obligation to return/destroy personal information immediately upon termination of the outsourcing period.

The Company requires companies entrusted with personal information processing (processors) to take all measures related to personal information protection. If a processor entrusted with a member's personal information causes damage to the member intentionally or negligently, the processor shall bear all responsibility therefor.

If the content of outsourced tasks or a processor changes, the Company will disclose the change without delay through this Privacy Policy.

Processor Purpose of Outsourced Task
KSNET Co., Ltd. Payment agency service (PG company)
Korea PortOne Co., Ltd.
PayPal
Ddaengddaengddaeng Co., Ltd. All domestic and overseas delivery and CS-related tasks
Amazon Web Services (AWS) Infrastructure operation for Service provision and prevention of unauthorized Service use
  1. Provision of Personal Information to Third Parties

The Company processes members' personal information only within the scope specified in the Terms of Service or this Privacy Policy and does not use personal information beyond the specified scope or provide it to third parties. However, exceptions apply in the following cases.

  1. Where separate consent has been obtained from the member
  2. Where special provisions exist in other laws
  3. Where it is clearly recognized as necessary for the urgent interests of the life, body, or property of the member or a third party
  4. Where necessary for public safety and security, such as public health
  1. Overseas Transfer of Personal Information

Because this Service is provided worldwide, including in the Republic of Korea, the Company may provide or outsource personal information overseas as follows for overseas members' sign-up, payment, and stable Service provision.

Recipient Country of Transfer Transferred Items Purpose of Transfer Timing and Method of Transfer Retention Period
PayPal United States Name, nationality, mobile phone number, email address, delivery address, card number Overseas payment processing Network transfer upon payment In accordance with applicable laws
Amazon Web Services (AWS) United States Member information (name, mobile phone number, email address, date of birth), Service use records, access logs, order, payment, and delivery information (recipient name, delivery destination, phone number, email), posts/comments/content, point usage history Infrastructure operation Network transfer during Service use Until membership withdrawal or termination of the outsourcing agreement

Members may refuse overseas transfer of personal information. However, such transfer is essential for providing the Service. If a member refuses the transfer, use of the Service may be restricted. If a member does not want overseas transfer, the member may withdraw from membership or request suspension of personal information processing through the customer center.

  1. Procedures and Methods for Destroying Personal Information

When personal information collected from members becomes unnecessary due to expiration of the retention period, achievement of the collection/use purpose, or similar reasons, the Company destroys members' personal information without delay. The targets, procedures, and methods are as follows.

  1. Target of destruction: Member personal information whose retention period and preservation period under applicable laws have expired
  2. Destruction procedure: Information provided by members for Service sign-up and similar purposes is moved to a separate database after the purpose is achieved, stored for a certain period according to internal policies and other applicable laws, and then destroyed by the methods specified below. Personal information moved to a separate database is not used for any purpose other than retention unless retained by law.
  3. Destruction methods
  1. Personal information written or printed on paper: shredded or incinerated

  2. Personal information stored as electronic files such as in a database: deleted by a technical method that prevents restoration of records

  3. Matters Concerning Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

  1. The Company uses cookies that store and frequently retrieve usage information to provide smooth services, such as maintaining members' login sessions. The Company does not collect cookies for marketing purposes and uses only essential cookies necessary to maintain the Service on a limited basis.
  2. Cookies are small amounts of information sent by the server used to operate a website to the data subject's browser and stored on a computer or mobile device. Data subjects may refuse cookie storage through browser settings, but in such cases, there may be difficulties in using some services that require login.
  3. Members may configure settings such as cookie refusal through the following browser options.
  1. How to block cookies in a web browser
  1. How to block cookies in a mobile browser
  1. Matters Concerning Processing Personal Information of Children Under 14 Years of Age
  1. If consent is required for processing personal information of children under 14 years of age, the Company obtains consent from their legal representatives.
  2. When obtaining consent from a legal representative regarding the processing of personal information of a child under 14 years of age, the Company may request the minimum information necessary from the child, such as the legal representative's name and mobile phone number. The Company verifies such consent by having the legal representative indicate consent on an internet site where the consent details are posted and by notifying the legal representative via mobile phone text message that the consent indication has been confirmed.
  1. Rights and Obligations of Members and Legal Representatives Regarding Personal Information and Methods of Exercising Them

Members (including legal representatives in the case of children under 14 years of age) may at any time visit the Service to request access to, correction, deletion, and suspension of processing of their registered personal information (collectively, "access, etc."), or withdraw consent to the collection, use, outsourcing, or provision of personal information.

Methods for requesting access to, correction of, or withdrawal of consent for personal information are as follows.

  1. Access to, correction, deletion, and suspension of processing of personal information
  1. Members may request access, etc. to personal information through email, the customer center, or similar channels.
  2. When a member requests access, etc. to personal information, the Company verifies the member's identity by conducting an authentication procedure within the online service or by receiving a copy of an identification document such as a resident registration card, passport, or driver's license.
  3. When a member's agent requests access, etc. to the member's personal information, the Company verifies whether the person is an agent by requesting evidence such as a power of attorney showing the agency relationship, the named member's certificate of registered seal impression, and the agent's identification document.
  4. If a member requests correction of an error in personal information, the Company does not use or provide the relevant personal information until correction is completed. If incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction result without delay so that the correction is made.
  1. Withdrawal of consent to collection, use, outsourcing, or provision of personal information
  1. Members may request withdrawal of consent to personal information through email, the customer center, or similar channels.
  2. Members may withdraw consent after completing the Company's identity verification procedure.
  1. The Company may exceptionally restrict access to and correction of personal information in the following cases.
  1. Where there is a risk of significantly harming the life, body, property, rights, or interests of the member (data subject) or a third party

  2. Where there is a risk of significantly hindering the business of the relevant service provider

  3. Where it violates laws

  4. Matters Concerning Measures to Ensure the Safety of Personal Information

The Company establishes the following technical, administrative, and physical protective measures to ensure safety so that members' personal information is not lost, stolen, leaked, altered, or damaged.

  1. Technical protective measures
  1. Personal information is protected by passwords, and important data is protected through separate security functions such as encrypting files and transmission data or using file lock functions.
  2. The Company takes measures to prevent damage from computer viruses by using antivirus programs. Antivirus programs are updated periodically, and if a virus suddenly appears, the Company introduces and applies the vaccine as soon as it becomes available to prevent infringement of personal information.
  3. The Company adopts security devices (SSL) to safely transmit personal information over networks.
  4. To prevent members' personal information from being leaked due to hacking or similar incidents, the Company installs systems in areas where external access is controlled and uses devices that block intrusions.
  1. Administrative protective measures
  1. The Company establishes procedures necessary for managing and accessing members' personal information, ensures that executives and employees understand and comply with them, and periodically checks compliance.
  2. The Company limits persons who can process members' personal information to the minimum necessary, manages access authority, and provides training to ensure compliance with laws and policies. Persons who process members' personal information are as follows.
  1. When hiring new employees, the Company prevents leakage of information, including personal information, by requiring them to sign an information protection pledge, regularly reminds them of personal information protection obligations, and establishes and implements internal procedures for auditing compliance.
  2. Handover of duties by personal information processors is conducted thoroughly while maintaining security, and responsibility for personal information infringement incidents after joining or leaving the Company is clearly defined.
  1. Physical protective measures
  1. The Company designates computer rooms, data storage rooms, and similar areas as special protection zones and implements access management procedures, including entry and access control for unauthorized persons.

  2. Documents and auxiliary storage media are stored in secure locations with locking devices, and the Company establishes and implements an internal system to control bringing auxiliary storage media in and out.

  3. Department and Contact Information Responsible for Personal Information Protection for Collecting Member Opinions and Handling Complaints

The Company designates the following Chief Privacy Officer to protect members' personal information and handle complaints and damage relief related to personal information processing.

  1. Chief Privacy Officer Name: Minjun Lee Affiliation: Pledge Co., Ltd. Contact: mj.lee@dayonedream.com
  2. Personal Information Protection Manager Name: Jinhyeong Noh Affiliation: Pledge Co., Ltd. Contact: jh.noh@dayonedream.com

Members may contact the Chief Privacy Officer and the department in charge of personal information protection for all personal information protection-related inquiries, complaint handling, damage relief, and similar matters arising from use of the Company's Service. The Company will provide prompt and accurate answers to members' inquiries.

  1. Remedies for Infringement of Members' Rights and Interests

Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Personal Information Infringement Report Center, and similar organizations to obtain remedies for personal information infringement. For other reports or consultations concerning personal information infringement, please contact the following organizations.

  1. Miscellaneous

The Company may provide links to other sites or materials. Because the privacy policies of external sites are unrelated to the Company, please review the policies of those sites.

  1. Changes to the Privacy Policy
  1. If additions, deletions, or modifications are made to the current Privacy Policy due to changes in laws, policies, security technologies, or similar matters related to personal information protection, the Company will notify members through website announcements at least 7 days before the amended Privacy Policy takes effect.
  2. This Privacy Policy applies from June 22, 2026.