Privacy Policy
Effective Date: June 27, 2025
Ublong Travel ("Company," "we," "us," or "our") is committed to protecting your personal information in accordance with the Personal Information Protection Act (PIPA), the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Act on the Consumer Protection in Electronic Commerce, and other applicable data protection laws of the Republic of Korea. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our travel services, website, and mobile applications (collectively, the "Services").
Table of Contents
- General Provisions
- Personal Information Collected
- Collection Methods
- Purposes of Processing
- Processing and Retention Periods
- Third-Party Provision
- Processing Entrustment
- International Transfers
- Destruction of Personal Information
- Data Subject Rights
- Cookies
- Security Measures
- Privacy Officer
- Remedies
- Marketing Consent and Withdrawal
- Policy Changes and Notification
- Effective Date
- GDPR Rights for EU Residents
- Frequently Asked Questions
1. General Provisions
This Privacy Policy applies to all personal information collected through the Services provided by Ublong Travel. We comply with the following Korean laws and regulations governing the protection of personal information:
- Personal Information Protection Act (PIPA): Governs the collection, use, provision, and protection of personal information.
- Act on Promotion of Information and Communications Network Utilization and Information Protection: Regulates the handling of personal information in information and communications networks.
- Act on the Consumer Protection in Electronic Commerce, etc.: Protects consumers in electronic commerce transactions, including payment and dispute resolution.
This Privacy Policy is publicly accessible via our website. Users may review the contents at any time and are encouraged to review this Policy periodically for updates.
2. Personal Information Collected
We collect the following categories of personal information. Information marked as mandatory is required to provide the Services; optional information is collected only if you choose to provide it.
2.1 Mandatory Information (Collected Upon Registration or Booking)
| Item | Description |
|---|---|
| Name (English) | Full name as it appears on travel documents |
| Name (Korean) | Full name in Korean (for domestic services) |
| Email Address | Used for account verification and service communication |
| Password | Encrypted for account security |
| Mobile Phone Number | Used for identity verification and booking confirmation |
| Date of Birth | Used for identity verification and age-related service eligibility |
2.2 Automatically Collected Information
| Item | Description |
|---|---|
| IP Address | Collected for security and service optimization |
| Cookies and Usage Data | Browser type, pages visited, time spent, click patterns |
| Device Information | Operating system, device model, screen resolution |
| Service Usage Records | Booking history, search queries, product reviews |
2.3 Optional Information (Provided at Your Discretion)
| Item | Purpose |
|---|---|
| Passport Information | Required for international travel bookings and visa processing |
| Dietary Preferences | Accommodation of dietary needs during tours and travel packages |
| Health Conditions | Ensuring safe participation in tour activities |
| Travel Preferences | Personalized recommendations and service improvement |
| Marketing Consent | Receipt of promotional materials, newsletters, and offers |
2.4 Sensitive Personal Information
We do not collect sensitive personal information such as political opinions, religious beliefs, race, ideology, or health records unless explicitly required for specific travel services (e.g., travel insurance) and only with your express written consent under PIPA Article 23.
3. Collection Methods
We collect personal information through the following methods:
| Method | Description |
|---|---|
| Direct Input | Registration forms, booking forms, customer service inquiries |
| Identity Verification | CI (Connecting Information) and DI (Duplication Information) verification through authorized authentication agencies |
| Payment Processing (PG) | Payment gateway companies for transaction processing and fraud prevention |
| Automated Collection | Cookies, server logs, and analytics tools during your use of the Services |
| Partner Services | Airline partners, accommodation providers, and tour operators for booking facilitation |
4. Purposes of Processing
We process your personal information for the following purposes. We will not use your personal information for purposes beyond those listed below without obtaining your prior consent.
4.1 Service Provision
- Processing travel bookings (flights, accommodations, tours, car rentals, insurance)
- Arranging travel packages and itineraries
- Facilitating payment processing and refunds
- Providing customer support and responding to inquiries
4.2 Member Management
- Creating and managing your member account
- Authenticating your identity and preventing fraud
- Communicating service updates, changes, and maintenance notices
- Managing your booking history and preferences
4.3 Marketing and Promotion (Opt-in Required)
- Sending newsletters, promotional offers, and personalized travel recommendations
- Conducting surveys and collecting feedback for service improvement
- Operating loyalty programs and special event notifications
You may withdraw your consent for marketing communications at any time as described in Section 15.
4.4 Service Improvement
- Analyzing usage patterns to enhance user experience
- Developing new services and features
- Conducting statistical analysis of anonymized data
- Improving website and application performance
4.5 Legal Obligations
- Complying with applicable laws, regulations, and legal processes
- Responding to lawful requests from government authorities
- Fulfilling tax reporting and accounting obligations
- Resolving disputes and enforcing our terms of service
5. Processing and Retention Periods
We process and retain your personal information only for the period necessary to fulfill the purposes outlined in this Policy, or as required by applicable law. The following table details our retention periods:
| Category | Retention Period | Legal Basis |
|---|---|---|
| Member Account Information | Until account deletion or 2 years after last login | PIPA Art. 21, User Agreement |
| Booking Records | 5 years after travel completion | Act on Consumer Protection in Electronic Commerce Art. 6 |
| Payment Transaction Records | 5 years after transaction date | Commercial Act Art. 33, Value-Added Tax Act |
| Customer Service Inquiries | 3 years after inquiry resolution | PIPA Art. 21, Statute of Limitations |
| Marketing Consent Records | Until consent withdrawal + 1 year | PIPA Art. 22 |
| Cookie and Usage Data | Up to 1 year from collection | Information and Communications Network Act |
| CI/DI Verification Data | Until account deletion | PIPA, Identity Verification Guidelines |
6. Third-Party Provision
We may share your personal information with the following third parties for the purposes of providing travel services. We obtain your consent before sharing your personal information with third parties, except where required by law.
| Recipient | Purpose of Provision | Items Provided |
|---|---|---|
| Airlines | Flight booking and reservation | Name, passport information, flight preferences |
| Accommodation Providers | Hotel and resort booking | Name, contact information, check-in/check-out dates |
| Tour Operators | Tour package arrangements and guides | Name, contact information, dietary/health information |
| Travel Insurance Companies | Insurance policy issuance | Name, date of birth, passport information, health information |
| Payment Gateway (PG) Companies | Payment processing and fraud prevention | Name, payment information, transaction details |
| Car Rental Companies | Vehicle reservation | Name, driver's license information, rental dates |
| Government Authorities | Visa issuance, immigration compliance | Passport information, travel itinerary |
We do not sell or lease your personal information to any third party for their independent marketing purposes.
7. Processing Entrustment
We entrust certain data processing activities to the following trusted service providers. We select entrusted processors based on their compliance with data protection standards and establish contractual agreements to ensure the secure handling of personal information.
| Entrusted Processor | Purpose | Items Provided | Retention and Usage Period |
|---|---|---|---|
| AWS (Amazon Web Services) | Cloud hosting and data storage | All collected personal information | Until service termination or processing agreement expiry |
| Hostinger | Web hosting services | Account data, server logs | Until service termination or processing agreement expiry |
| Naver Cloud | Cloud infrastructure, SMS and email delivery | Member information, contact details | Until service termination or processing agreement expiry |
| Kakao | SMS and notification delivery | Mobile phone number, message content | Until message delivery is confirmed |
| Google Analytics | Website usage analysis | Cookies, usage data, device information | Up to 26 months from collection |
| Meta Pixel | Marketing analysis and optimization | Cookies, usage data, conversion events | Up to 26 months from collection |
| PG Companies (NICE, Toss Payments) | Payment processing | Payment information, member name, transaction details | Until transaction completion + 5 years |
8. International Transfers
Your personal information may be transferred to and processed in countries outside of South Korea for the purposes described in this Policy. The following table details international transfers:
| Recipient | Country | Purpose of Transfer | Legal Safeguards |
|---|---|---|---|
| Google LLC | United States | Analytics, advertising, and cloud services | Standard Contractual Clauses (SCCs), Google Data Processing Agreement |
| Meta Platforms, Inc. | United States | Marketing analysis and retargeting | Standard Contractual Clauses (SCCs), Meta Data Processing Terms |
| Airline Global Distribution Systems (GDS) | Various Countries | Flight reservation and ticketing | Industry-standard data protection agreements |
| International Hotel Chains | Various Countries | Accommodation reservation | Data protection agreements, contractual clauses |
| AWS (Amazon Web Services) | United States / Singapore | Cloud hosting and data processing | Standard Contractual Clauses (SCCs), AWS Data Processing Addendum |
We take appropriate measures to ensure that your personal information receives an adequate level of protection in any country to which it is transferred, in compliance with PIPA Article 17 and applicable international data transfer regulations.
9. Destruction of Personal Information
We destroy your personal information without delay when the processing purpose has been achieved, the retention period has expired, or you have requested deletion. The procedures and methods for destruction are as follows:
9.1 Procedures
Personal information stored in electronic files is deleted using irreversible technical methods so that the information cannot be recovered or reproduced. Personal information stored on paper documents is destroyed by shredding or incineration.
9.2 Methods
| Format | Destruction Method |
|---|---|
| Electronic Files | Secure deletion using certified data destruction software, ensuring data is unrecoverable |
| Paper Documents | Cross-cut shredding or incineration by authorized destruction service providers |
| Backup Media | Destruction of backup tapes, hard drives, and removable media by certified e-waste recyclers |
9.3 Exceptions
Where required by applicable law, we may retain certain personal information for the mandatory period specified by law, even after the expiration of the general retention period:
- Records related to consumer complaints or disputes: retained for 3 years under the Act on Consumer Protection in Electronic Commerce
- Tax-related records: retained for 5 years under the Value-Added Tax Act
- Records of transactions and payment processing: retained for 5 years under the Commercial Act
10. Data Subject Rights
Under PIPA, you have the following rights regarding your personal information. You may exercise these rights at any time by contacting our Privacy Officer.
10.1 Rights Under PIPA
| Right | Description |
|---|---|
| Right of Access | Request to view the personal information we hold about you |
| Right to Rectification | Request correction of inaccurate or incomplete personal information |
| Right to Erasure | Request deletion of your personal information, subject to legal retention requirements |
| Right to Restriction of Processing | Request that we limit the processing of your personal information |
| Right to Withdraw Consent | Withdraw your consent for data processing at any time |
| Right to Data Portability | Request to receive your personal information in a structured, commonly used format |
| Right to Compensation | Claim compensation for damages arising from our mishandling of your personal information |
10.2 Children Under 14
We do not knowingly collect personal information from children under the age of 14 without verified consent from a parent or legal guardian. If we become aware that we have collected personal information from a child under 14 without proper consent, we will delete such information promptly.
Parents or legal guardians may request to view, correct, or delete the personal information of children under 14 by contacting our Privacy Officer.
10.3 How to Exercise Your Rights
You may exercise your rights through the following methods:
- Online: Log in to your account and access the "Privacy Settings" section
- Email: Send a written request to angela@ublong.kr
- Mail: Send a written request to the address listed in Section 13
- Phone: Contact our Privacy Officer at +82-033-1234-5678
We may require identity verification before processing your request to prevent unauthorized access to personal information.
11. Cookies
We use cookies and similar tracking technologies to enhance your experience and provide personalized services.
11.1 Purpose of Cookies
Cookies are small text files placed on your device to remember your preferences, analyze usage patterns, and deliver relevant content.
11.2 Types of Cookies
| Type | Purpose | Required Consent |
|---|---|---|
| Essential Cookies | Required for core website functionality (login, shopping cart, security) | Cannot be disabled |
| Functional Cookies | Remember your preferences (language, region, display settings) | Opt-in recommended |
| Analytics Cookies | Analyze website traffic and usage patterns to improve services | Opt-in required |
| Advertising Cookies | Deliver personalized advertisements and measure campaign effectiveness | Opt-in required |
11.3 Managing Cookies
You may manage or disable cookies at any time through the following methods:
- Browser Settings: Most web browsers allow you to control cookies through their settings menu
- Cookie Consent Banner: Accept or reject non-essential cookies through our consent management tool
- Opt-Out Links:
- Google Analytics Opt-Out: https://tools.google.com/dlpage/gaoptout
- Meta Opt-Out: https://www.facebook.com/settings?tab=ads
Please note that disabling essential cookies may affect the functionality of the Services.
12. Security Measures
We implement the following technical, administrative, and physical measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction.
12.1 Technical Measures
- Encryption of personal information during transmission using SSL/TLS protocols
- Secure storage of sensitive data with AES-256 encryption
- Regular security audits and vulnerability assessments
- Implementation of intrusion detection and prevention systems
- Multi-factor authentication for administrative access
12.2 Administrative Measures
- Strict access control policies limiting employee access to personal information on a need-to-know basis
- Regular training on data protection and privacy compliance for all employees
- Confidentiality agreements with employees and contractors
- Incident response procedures for data breaches
- Regular review and updating of security policies
12.3 Physical Measures
- Restricted access to data processing facilities with key card and biometric authentication
- Secure storage of paper documents in locked facilities
- Surveillance systems in data processing areas
- Proper disposal of physical media containing personal information
13. Privacy Officer
We have designated the following Privacy Officer to handle all matters related to the protection of your personal information. You may contact the Privacy Officer for inquiries, complaints, or to exercise your rights.
| Item | Details |
|---|---|
| Company Name | Ublong Travel |
| Privacy Officer | Jaewon Kim, Chief Privacy Officer |
| angela@ublong.kr | |
| Phone | +82-033-1234-5678 |
| Address | 2nd Floor, 2023 Gyeonggang-ro, Gangneung-si, Gangwon-do, South Korea |
14. Remedies
If you believe that your personal information rights have been violated, you may seek remedies through the following channels. We are committed to promptly addressing your complaints.
| Organization | Contact | Description |
|---|---|---|
| Korea Internet & Security Agency (KISA) Personal Information Complaint Center | 118 (no area code needed), https://privacy.kisa.or.kr | Reporting violations of personal information protection, filing complaints |
| Personal Information Dispute Mediation Committee | 1833-6972, https://www.kopico.or.kr | Mediation of disputes between data subjects and data controllers |
| Supreme Prosecutors' Office Cyber Crime Investigation Unit | 1301 | Reporting cyber crimes including unauthorized access and data breaches |
| National Police Agency Cyber Bureau | 182 | Reporting online crimes and data breaches |
We will make every effort to resolve your complaints promptly and fairly.
15. Marketing Consent and Withdrawal
We obtain your explicit consent before sending marketing communications. You may withdraw your consent at any time.
15.1 Marketing Communications
- Newsletters and promotional emails
- Personalized travel offers and recommendations
- Event and loyalty program notifications
- SMS and push notification campaigns
15.2 How to Withdraw Consent
- Online: Log in to your account and navigate to "Marketing Preferences" or "Consent Management"
- Email: Send a withdrawal request to angela@ublong.kr
- Unsubscribe Links: Click the "Unsubscribe" link at the bottom of any marketing email
- Phone: Contact our Privacy Officer at +82-033-1234-5678
Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
16. Policy Changes and Notification
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
When material changes are made to this Privacy Policy, we will notify you through one or more of the following methods:
- Prominent notice on our website (at least 7 days before the changes take effect)
- Email notification to your registered email address
- In-app notification
- SMS notification for significant changes
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal information.
17. Effective Date
This Privacy Policy is effective as of June 27, 2025.
| Item | Details |
|---|---|
| Policy Effective Date | June 27, 2025 |
| Last Revised | June 27, 2025 |
| Version | 1.0 |
18. GDPR Rights for EU Residents
If you are a resident of the European Economic Area (EEA), the United Kingdom (UK), or any other jurisdiction subject to the General Data Protection Regulation (GDPR), you may have additional rights under GDPR. In such cases, we act as the data controller for your personal information.
18.1 Legal Basis for Processing
We process your personal information under the following legal bases:
| Legal Basis | Applicable Processing Activities |
|---|---|
| Consent (Art. 6(1)(a)) | Marketing communications, analytics cookies, personalized offers |
| Performance of Contract (Art. 6(1)(b)) | Processing travel bookings, account management, customer support |
| Legal Obligation (Art. 6(1)(c)) | Tax reporting, compliance with government requests |
| Legitimate Interests (Art. 6(1)(f)) | Fraud prevention, service improvement, security |
18.2 Additional GDPR Rights
| Right | Description |
|---|---|
| Right to Object | Object to processing based on legitimate interests or direct marketing |
| Right to Lodge a Complaint | Lodge a complaint with your local data protection supervisory authority |
| Right Not to Be Subject to Automated Decision-Making | Not be subject to decisions based solely on automated processing, including profiling |
| Right to Withdraw Consent | Withdraw consent at any time where processing is based on consent |
18.3 International Data Transfers
We ensure that transfers of personal information outside the EEA or UK are protected by appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent mechanisms.
18.4 Contact
For GDPR-related inquiries, please contact our Privacy Officer at angela@ublong.kr.
19. Frequently Asked Questions
Q1: What personal information does Ublong Travel collect? We collect personal information necessary to provide travel services, including your name, email address, phone number, date of birth, passport information (for international travel), payment details, and browsing activity. Optional information such as dietary preferences and health conditions is collected only when you provide it.
Q2: How does Ublong Travel use my personal information? We use your personal information to process travel bookings, manage your member account, provide customer support, send marketing communications (with your consent), improve our services, and comply with legal obligations.
Q3: Does Ublong Travel sell my personal information? No. We do not sell, lease, or rent your personal information to any third party for their independent marketing or commercial purposes. We share personal information only with service providers necessary to fulfill your travel bookings or as required by law.
Q4: How long does Ublong Travel retain my personal information? We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. Retention periods vary by category, ranging from 2 years for member account information to 5 years for booking and payment records.
Q5: How can I access or delete my personal information? You may access, correct, or request deletion of your personal information by logging into your account and using the "Privacy Settings" section, or by contacting our Privacy Officer at angela@ublong.kr or +82-033-1234-5678. We will respond to your request within 30 days.
Q6: How does Ublong Travel protect my payment information? Payment information is processed through certified payment gateway providers and is not stored on our servers. Transactions are encrypted using SSL/TLS protocols, and payment processors comply with PCI DSS (Payment Card Industry Data Security Standard) requirements.
Q7: What happens if I do not provide mandatory personal information? If you do not provide the mandatory personal information required for registration or booking, we will be unable to create your account or process your travel reservation. Optional information is not required, and declining to provide it will not affect your access to core services.
Q8: Does Ublong Travel transfer my personal information outside of South Korea? Yes. Some of our service providers are located outside of South Korea (e.g., Google, Meta, cloud hosting providers, airline reservation systems). When transferring personal information internationally, we implement appropriate safeguards such as Standard Contractual Clauses to ensure your data is protected in compliance with applicable data protection laws.