Privacy Policy
Last updated: July 30, 2026
1. Company Information
- Company name: EZBY Inc. (์ด์ง๋ฐ์ด(์ฃผ))
- CEO: Kang Jungin
- Address: 7F, 7012, 154 Haeundae Beach Road, Haeundae-gu, Busan, Korea
- Business Registration No: 522-88-01642
- Email: admin@ez2busan.com
2. Information We Collect
- Email address (for account identification and communication)
- Password (encrypted, never stored in plain text)
- Nickname (display name for your account)
- Location data (GPS, collected once per request and deleted after completion)
- Request details (service type, preferences, requirements you submit)
- Chat messages (conversations with our concierge team)
- Payment key (Toss Payments transaction identifier; we do not store card numbers)
- Push subscription (for browser notification delivery)
3. How We Use Your Information
- Account management: creating and maintaining your account
- Service fulfillment: processing your concierge requests (restaurant bookings, recommendations, translations, etc.)
- Payment processing: handling credit charges and refunds via Toss Payments
- Notifications: sending request status updates and service alerts
- Service improvement: analyzing aggregate request trends (popular service types, peak request times, Busan area coverage) to improve our concierge recommendations. No individual user profiling or automated decision-making is performed.
4. Information Retention
- Account data: deleted upon account deletion, except for records that must be retained by law (see below)
- Payment and contract records: retained for 5 years per the Act on Consumer Protection in Electronic Commerce
- Complaint and dispute records: retained for 3 years
- Legally required retention: data stored separately from active systems and deleted after the retention period expires
5. Data Processing & Third-Party Sharing
Data Processors (Service Providers)
We use the following service providers to operate our platform. They process your data on our behalf (as data processors) under appropriate agreements:
- Supabase Inc. (database hosting) โ Transfer country: United States. Purpose: user data storage and authentication. Data items: account info, request data, chat messages, payment records. Retention: as specified in Sections 2 and 4. Safeguards: encryption at rest, RLS, SOC 2 Type II compliance.
- Cloudflare Inc. (server hosting, CDN) โ Transfer country: global (data stored closest to user). Purpose: web application hosting and content delivery. Data items: IP address, request data (transient). Retention: server logs retained up to 30 days. Safeguards: TLS encryption, access controls.
- Toss Payments (payment processing) โ Transfer country: Korea. Purpose: payment authorization and refund processing. Data items: payment key, transaction amount. Retention: per Toss Payments terms. Safeguards: PCI DSS compliance.
Third-Party Sharing
We do not sell, rent, or trade your personal information to any third parties. Your data is only shared with the service providers listed above for the purpose of operating our platform.
6. Cookies & Auto-Collection
- Session cookies: used for authentication (Supabase Auth). Deleted when you close your browser.
- Service Worker cache: stores static assets for offline use. Does not contain personal data.
- Web Push subscription: stored if you opt in to push notifications. Can be disabled in your browser settings.
- We do not use third-party analytics cookies, advertising cookies, or tracking pixels.
Most browsers allow you to control cookies through their settings. You may lose some functionality (such as staying logged in) if you disable all cookies.
7. Data Deletion
- Electronic files: permanently deleted using methods that prevent recovery
- Legally retained data: stored separately from active systems and deleted after the statutory retention period expires
- Account deletion: all personal data except legally required records is deleted immediately
8. Your Rights
- Right to access: request a copy of your personal data
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure: request deletion of your data
- Right to restrict processing: limit how we use your data
- Right to withdraw consent: revoke previously given consent at any time
To exercise these rights, contact us at admin@ez2busan.com. We will respond within 10 days of receiving your request.
9. Privacy Officer
- Name: Kang Jungin
- Title: CEO, EZBY Inc.
- Email: admin@ez2busan.com
10. Location Information
- We collect your GPS location once per request to provide location-based services (nearby restaurants, hotels, hospitals in Busan).
- Location data is deleted immediately after your request is completed.
- We do not track your location in real time or in the background.
- Per the Act on the Protection and Use of Location Information, we do not collect location data from users under 14 years of age. Users under 14 cannot use location-based features and must manually enter their service area.
11. Security Measures
- Encryption: all personal data is encrypted at rest (Supabase) and in transit (SSL/TLS)
- Access control: Row-Level Security (RLS) ensures users can only access their own data
- Breach notification: in the event of a data breach, we will notify affected users and the Personal Information Protection Commission without delay, and in any case within 72 hours of becoming aware of the breach
- Regular review: our security practices are reviewed and updated regularly
For privacy inquiries: admin@ez2busan.com
This Privacy Policy may be updated from time to time. Changes will be posted on this page.