Connecting Information (CI) Processing Policy
Article 1 (Purpose)
The Company establishes and publishes this Connecting Information (CI) Processing Policy in accordance with the Personal Information Protection Act and other applicable laws and regulations to ensure the lawful and secure processing of Connecting Information (CI) of data subjects.
This Policy sets forth matters concerning the legal basis for processing CI, the purposes of collection and use, retention and use periods, and provision of CI to third parties.
Article 2 (Purposes of Collection and Use of CI)
The Company collects and uses CI only for the following purposes:
- Membership registration and identity verification
- Customer due diligence and suspicious transaction reporting
- Open Banking withdrawals
- Domestic partner payment services
The Company does not use CI for purposes other than those specified above. If the purposes of use are changed, the Company will take all necessary measures and procedures in accordance with applicable laws and regulations.
Article 3 (Retention and Use Period of CI)
The Company retains and uses CI until the member withdraws from the service or the purpose of processing has been fulfilled.
However, where retention is required under applicable laws and regulations, the Company retains CI for the period prescribed by such laws and regulations.
Legal Basis | Retention Period |
Electronic Financial Transactions Act | 5 years |
Act on Reporting and Using Specified Financial Transaction Information | 5 years |
Personal Information Protection Act and other applicable laws and regulations | Destroyed upon membership withdrawal |
Upon expiration of the applicable retention period, the Company destroys CI without undue delay in accordance with the methods prescribed by applicable laws and regulations.
Article 4 (Provision of CI to Third Parties)
As a general rule, the Company does not provide CI to third parties without the consent of the data subject.
However, the Company may provide CI where permitted or required under applicable laws and regulations.
Recipient | Purpose of Provision | Information Provided | Retention and Use Period |
Shinhan Card | Provision of data for year-end tax settlement simplification services, issuance of supporting documents, and processing of income tax deductions | Name, date of birth, gender, mobile phone number, CI, monthly payment amount and number of transactions | 5 years from the date the data is provided to the National Tax Service or the supporting documents are issued |
National Tax Service | Provision of data for year-end tax settlement simplification services, issuance of supporting documents, and processing of income tax deductions | Name, date of birth, gender, mobile phone number, CI, monthly payment amount and number of transactions | 5 years from the date the data is provided to the National Tax Service or the supporting documents are issued |
CJ OliveNetworks | Provision of the CJ ONE barcode payment service | CI, unique member identifier, name, date of birth, gender, email address, mobile phone number, and mobile carrier | Until the user terminates or withdraws from the service, or until termination of the relevant partnership |
LOTTE Members Co., Ltd. | Provision of the L.POINT barcode payment service | CI, name, date of birth, gender, address, email address, mobile carrier, and mobile phone number | Until the user terminates or withdraws from the service, or until termination of the relevant partnership |
SCK COMPANY Co., Ltd. | Conversion of the user's existing points into Starbucks Stars | CI | Destroyed immediately after verification of Starbucks membership status |
※ The Company provides CI only where permitted under applicable laws and regulations or where separate consent has been obtained from the data subject.
Article 5 (Security Measures for CI)
The Company implements the following measures to securely protect CI:
- Establishment and implementation of an internal management plan
- Minimization of access privileges and implementation of access controls
- Creation and periodic review of access logs
- Encryption of CI at rest and in transit
- Access controls for personal information processing systems
- Training for personnel handling personal information
- Installation and operation of security software
Article 6 (Rights of Data Subjects)
Data subjects may request access to, correction or deletion of, or suspension of processing of their CI to the extent permitted under applicable laws and regulations.
① The Company has designated the following person responsible for overseeing the processing of CI and handling complaints, inquiries, and requests for remedies from data subjects in connection with the processing of CI.
Department Responsible for CI | CI Protection Officer | Position | Contact Information |
Security Team | Byunghee Lee | CISO/CPO | support@travel-wallet.com / 02-522-0400 |
② Data subjects may contact the person responsible for personal information protection or the relevant department regarding any inquiries, complaints, or requests for remedies concerning personal information protection arising from the use of the Company's services or business activities. The Company will respond to and handle such inquiries without undue delay.
However, the exercise of such rights may be restricted where the Company is required to retain the relevant information under other applicable laws and regulations.
Article 7 (Amendments)
The Company may amend this Policy in response to changes in applicable laws and regulations or its internal policies. Any amendments will be announced on the Company's website prior to their effective date.