BYTREND โ Privacy Policy
Effective Date: May 12, 2026
Operator: BYTREND INC.
Service Domain: bytrend.co.kr
CEO: Park, Seongkoo
Address: #1108, 11th Floor, LG Yeouido Eclat, 780 Gukhoe-daero, Yeongdeungpo-gu, Seoul, Republic of Korea
Business Registration: 561-87-03731
E-Commerce Registration: 2026-Seoul-Yeongdeungpo-0441
Article 1 (Purpose and Consent)
BYTREND INC. ("BYTREND", "the Company", "we") operates the cyber mall and concierge platform at bytrend.co.kr (the "Service"). The Company values the personal information of its Users and complies with the Personal Information Protection Act, the Information and Communications Network Act, the Act on the Consumer Protection in Electronic Commerce, and other relevant laws of the Republic of Korea.
The Company establishes a procedure allowing Users to indicate consent to these Terms, the collection of personal information, and details of personal information use. Users shall be deemed to have agreed to the collection and use of their personal information by clicking the "Agree" button.
Article 2 (Personal Information Items Collected and Purpose of Use)
"Personal Information" means information about a living individual, including the individual's name, date of birth, contact information, or any other information that โ alone or in combination with other information โ identifies the individual.
The Company collects the following items for the following purposes:
A. General Membership Information
- Time of collection: At membership registration
- Mandatory items: ID, password, name, e-mail address, country of residence
- Optional items: Profile image, date of birth, telephone number, mailing address, preferred language, preferred messenger ID (LINE / WhatsApp)
- Purpose: Member identification, account management, customer consulting, delivery of operational notices
- Retention period: Immediately deleted upon withdrawal of membership, except for purchasing Members whose records are retained for 5 years under Article 4.1
B. Order and Booking Information (Members and Non-Members)
- Time of collection: At order or booking placement
- Mandatory items:
- Customer info: Name, address, telephone, e-mail
- Recipient info (where different): Name, address, telephone
- Payment approval information
- Optional items: Delivery message, gift message
- Purpose: Payment processing, goods delivery, service execution, customer support
- Retention period: 5 years (per Act on the Consumer Protection in Electronic Commerce)
C. VIP Operational Information (BYTREND-specific)
- Time of collection: After Pre-Inquiry confirmation, prior to Tailored Proposal issuance
- Mandatory items (where applicable to the booked service):
- Passport number, full legal name as on passport, nationality
- Flight number, arrival and departure dates and times, airline
- Hotel name, hotel check-in/check-out dates, room or reservation number
- Visa status (where relevant for itinerary planning)
- Names and ages of accompanying passengers (for vehicle and group tour bookings)
- Dietary restrictions, allergies, accessibility requirements (for gourmet and tour services)
- Messenger ID (LINE / WhatsApp) for operational coordination
- Purpose:
- Airport meet-and-greet and transfer coordination
- Vehicle dispatch routing and security planning
- Itinerary design integrated with hotel and flight schedules
- Restaurant booking with dietary accommodations
- Compliance with venue access requirements (e.g., palace tours, driving experience venue license verification)
- Retention period: Until 30 days after service completion, then destroyed, except where required for billing reconciliation, dispute resolution, or by law (in which case Article 4.1 retention applies)
D. Business Interpretation Engagement Information
- Time of collection: Upon Pre-Inquiry for interpretation services
- Mandatory items: Industry domain, terminology preference, engagement schedule, parties to be interpreted (names and titles where required for protocol)
- Purpose: Interpreter matching, terminology calibration, NDA preparation
- Retention period: Destroyed within 30 days of engagement completion, except where the User explicitly requests retention or where law requires longer retention
E. Cookies and Access Logs
- Items: IP address, browser information, access date and time, pages viewed, referring URL
- Purpose: Service quality improvement, statistical analysis, fraud prevention
- Retention period: Log-in records retained for 3 months (per Protection of Communications Secrets Act)
Article 3 (Cookies)
1) Purposes of Using Cookies
- Providing differentiated information based on individuals' interests and language preferences
- Analyzing access frequency and dwell time, identifying preferences for service improvement
- Tracing items of interest and purchase history for tailored concierge recommendations
2) Operation and Rejection of Cookies
Cookies are stored on the User's hard disk. Cookies identify the User's device but not the individual personally. Users may accept or reject all cookies, or be prompted before storage, by adjusting browser settings. Refusing cookies may impair some Service functions.
3) Method for Changing Settings to Reject Cookies
- Chrome: Menu (upper right) > Settings > Privacy and security > Cookies and other site data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
- Firefox: Preferences > Privacy & Security > Cookies and Site Data
Article 4 (Retention and Destruction of Personal Information)
1) Retention Periods Required by Law
After the purpose of collection has been achieved, personal information is destroyed without delay. The following exceptions apply per relevant laws:
A. Act on the Consumer Protection in Electronic Commerce
- Records on contracts or withdrawal of offers: 5 years
- Records on payments and supply of goods/services: 5 years
- Records on resolution of customer complaints or disputes: 3 years
B. Protection of Communications Secrets Act
C. Tourism Promotion Act and related regulations
- Travel service operation records: As required by relevant subordinate regulations
D. Other related laws: As required.
2) Destruction Procedures and Methods
A. Procedure: Information collected is transferred to a separate database (paper records to a separate filing cabinet) upon achievement of the collection purpose, retained per internal guidelines and statutes, and then destroyed. Such information is not used for any other purpose.
B. Methods:
- Paper records: Shredded or incinerated
- Electronic files: Permanently deleted using technical means that prevent restoration or regeneration
3) Dormant Member Policy
Members who have not used the Service for 24 months โ
(extended from statutory 12-month default in consideration of VIP visit cycles, subject to CEO confirmation) shall receive a notice of intended dormant-account separation. Where such Members fail to respond, their personal information shall be stored separately from active Member data and shall be destroyed after the lapse of the relevant statutory retention period. Upon request, separated information is restored at the time of Service resumption.
Article 5 (Provision of Personal Information to Third Parties)
1) General Principle
The Company shall not use Users' personal information beyond the scope of Article 2, nor provide such information to other persons, companies, or institutions.
2) Exceptions
The Company may provide personal information to third parties in the following cases:
- A. With User consent: Where the User has provided separate explicit consent for the specific provision (e.g., providing flight details to the airport reception team, providing dietary requirements to a restaurant).
- B. Statutory obligation: Where required by relevant laws or by the order of competent authorities for investigative purposes.
- C. Statistical or research use: Where provided in a form that cannot identify specific individuals, for advertisers, suppliers, or research organizations.
In all such cases, the Company exercises best efforts to ensure that information is not provided indiscriminately against the original purpose of collection.
Article 6 (Outsourcing of Personal Information Processing)
The Company outsources personal information processing to the following entrustees for service execution and User convenience:
| Outsourced Work |
Entrustee |
Items Provided |
| Hosting and platform operation |
Imweb Co., Ltd. |
All Service data hosted on the platform |
| Delivery tracking |
Goodsflow Inc. |
Recipient name, address, telephone, order number |
| Self-authentication, i-PIN |
Dream Security Inc. |
Authentication-related identifiers |
| Payment and escrow (PG) |
NICEPAY |
Card information, payment approval data |
| International payment processing |
PayPal |
Card information, billing address, transaction data |
| Vehicle dispatch |
Contracted vehicle Partners (categorically described to maintain operational confidentiality) |
Recipient name, pickup/dropoff locations, schedule, accompanying party count |
| Yacht rental (yachting bookings) |
Contracted yacht rental Partners |
Reservation name, party size, schedule |
| Driving experience (driving bookings) |
Contracted driving experience Partners |
Reservation name, license verification, schedule |
| Aerial tour (aircraft rental / sky safari) |
SKYTOUR and contracted aerial tour Partners |
Reservation name, party size, flight schedule, identity verification data |
| Restaurant reservations |
CatchTable and individual restaurant Partners |
Reservation name, party size, dietary requirements |
| Messenger channel operations |
LINE / WhatsApp |
Communication content for service coordination |
Notes:
- Information shared with entrustees is limited to the minimum required for the outsourced purpose.
- Optional personal information is provided only at the User's request for specific services.
- The list of entrustees may change with service evolution. Material changes shall be announced via notice prior to taking effect.
- All entrustees are contractually bound to BYTREND's confidentiality and data protection standards, including NDAs where applicable.
Article 7 (International Transfer of Personal Information)
The Company's primary servers and data processing infrastructure are located in the Republic of Korea (via Imweb Co., Ltd. hosting).
Where international Users provide personal information from outside Korea, such information is transferred to and stored on Korean servers. This constitutes a cross-border data flow under the laws of certain jurisdictions.
Where the Service uses international payment processors (e.g., Stripe, PayPal), payment-related personal information may be transferred to and processed in those processors' jurisdictions in accordance with their own privacy policies.
By using the Service, international Users consent to the transfer of their personal information to the Republic of Korea and, where applicable, to the jurisdictions of international payment processors.
Users from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with cross-border transfer restrictions may exercise their data subject rights by contacting the Chief Privacy Officer (Article 13).
Article 8 (Sensitive Information for VIP Operations)
The Company collects certain information that may be classified as sensitive (e.g., dietary restrictions indicating health conditions, accessibility requirements, religious dietary preferences) only with explicit User consent and only to the extent necessary for service execution.
The Company does not collect resident registration numbers (Korean nationals' RRN) or equivalent foreign national identification numbers (e.g., U.S. Social Security Number, U.K. National Insurance Number, Japan My Number, etc.) except where required by law.
Passport information is collected solely for venue access verification, airport reception protocol, and vehicle Partner dispatch records. Passport copies, where provided, are securely deleted within 30 days of service completion unless retention is required for dispute resolution or by law.
Vehicle in-cabin recordings (dashcam, security camera): Where vehicle Partners operate dashcams or in-cabin security cameras for safety and dispute prevention, footage is retained for a maximum of 30 days by the Partner under contractual confidentiality terms with BYTREND, then securely destroyed unless retained for an active investigation.
Article 9 (Access, Modification, and Withdrawal of Consent)
1) Access and Modification
Users may access or modify their personal information at any time:
- Through the "My Account" or "Change Member Information" menu on the Service.
- By sending an e-mail or written request to the Chief Privacy Officer (Article 13).
The Company shall act without delay. During the correction process, the Company shall not use the information until the correction is complete.
2) Withdrawal of Consent
Users may withdraw consent to the collection, use, and provision of personal information at any time:
- Through the "Withdrawal" menu in My Account.
- By contacting the Chief Privacy Officer in writing, by telephone, or by e-mail.
The Company shall immediately take necessary measures including deletion of personal information, and shall confirm such measures to the User. The withdrawal procedure is no more burdensome than the consent procedure.
3) Correction Notice to Third Parties
Where incorrect personal information has already been provided to a third party, the Company shall immediately notify the third party of the correction and ensure their records are updated.
Article 10 (Security Measures)
The Company implements technical, administrative, and physical measures required under Article 29 of the Personal Information Protection Act:
1. Encryption
Passwords and personal information are encrypted in storage and transmission. Important data is secured with separate features including file encryption and access locking.
2. Technical Measures Against Hacking
The Company installs, regularly updates, and audits security programs to protect against leakage and damage from hacking or computer viruses. Systems are placed in access-controlled areas and are technologically and physically inspected.
3. Administrative Measures
- Personal information handlers are limited to the minimum necessary.
- All personnel and Partners with access to personal information are bound by confidentiality agreements.
- Regular training on personal information protection is conducted for handlers.
4. Liability for Damage
The Company bears full responsibility for damages arising from loss, theft, leakage, unauthorized provision, or tampering of Users' personal information โ including credit card and bank account information โ caused by the Company's intent or negligence.
Article 11 (Children Under 14)
The Company does not allow children under 14 years of age to register as Members independently.
For VIP Family Tours that include minors, all booking and personal information is registered under the legal guardian's name. The legal guardian is responsible for the personal information of accompanying minors and consents on their behalf.
Where a child under 14 signs up or provides personal information due to identity theft or system abuse, the legal guardian may exercise all rights under this Policy, including access, correction, and deletion.
Article 12 (Confidentiality for Business Interpretation)
All terminology, working notes, transcripts, draft documents, and communications generated during a Business Interpretation engagement are deemed confidential and are processed under strict NDA terms with the assigned interpreter.
Engagement materials are securely destroyed within 30 days of engagement completion, unless:
- The User explicitly requests longer retention (e.g., for follow-up engagements within a defined period), or
- Retention is required by law or by an active legal proceeding.
Interpreters are not authorized to reproduce, store on personal devices, or share engagement materials beyond the scope of the engagement.
Where a User requests certified destruction confirmation, the Company shall issue a written destruction certificate.
Article 13 (Chief Privacy Officer)
The Company designates the following Chief Privacy Officer responsible for personal information processing and for handling User complaints and damage relief related to personal information:
โถ Chief Privacy Officer
- Name: Park, Seongkoo
- Title: Chief Executive Officer
- Telephone: 02-784-8485
- E-mail: ceo@bytrend.co.kr
- Address: #1108, 11th Floor, LG Yeouido Eclat, 780 Gukhoe-daero, Yeongdeungpo-gu, Seoul
Users may also contact the following authorities for personal information protection consultation, dispute mediation, or reporting:
- Korea Internet & Security Agency (KISA) Privacy Complaint Center: privacy.kisa.or.kr / 118 (no area code)
- Personal Information Dispute Mediation Committee: kopico.go.kr / 1833-6972
- Cyber Investigation Division, Supreme Prosecutors' Office: spo.go.kr / 1301
- Cyber Bureau, National Police Agency: ecrm.cyber.go.kr / 182
Article 14 (Amendments to This Privacy Policy)
This Privacy Policy takes effect on the Effective Date specified in the header. Any addition, deletion, or modification โ whether due to changes in law or in the Company's operations โ shall be announced via notice on the Service at least 7 days prior to the effective date of the amendment. Where amendments materially affect User rights, the announcement shall be made at least 30 days in advance.
Supplementary Provisions
This Privacy Policy shall take effect on the date specified in the header. Where amendments are made under Article 14, the amendment notice shall specify the new effective date.