Privacy Policy

Key Information on Personal Information Processing

  • Items of personal information collected: name, email address, mobile phone number, IP address, cookies, device information, service usage records(Behavioral information: page views/clicks/time spent/inflow path, etc.)
  • Purposes of collection and use of personal information: membership registration, use of services, performance of contracts regarding service provision and settlement of fees arising from service provision, member management, marketing and advertising, satisfaction surveys
  • Retention and use period of personal information: until membership withdrawal, or for the period required by applicable laws
  • Method of destruction of personal information: shredding for paper documents, deletion for electronic files

1. Purpose of Processing Personal Information

Lightweight Co., Ltd. (hereinafter referred to as the “Company” or “we”) processes personal information for the following purposes. The items of personal information to be processed, collection methods, and purposes of use are as follows.

Performance of contracts related to service provision and fee settlement

- Items collected: name, mobile phone number, email address

- Collection methods: written forms, phone calls, email, and collection through information generation tools

- Purposes of use: membership registration and management, service provision, sending invoices, fee payment, and debt collection

Customer service provision

- Items collected: name, mobile phone number, email address, service usage records

- Collection methods: written forms, phone calls, email, and collection through information generation tools

- Purposes of use: handling customer complaints, VOC (voice of customer) management, delivery of notices

Use for marketing and advertising

- Items collected: name, mobile phone number, email address, service usage records, access IP information

- Collection methods: written forms, phone calls, email, and collection through information generation tools

- Purposes of use: information on events and promotions, information on new products, provision of advertising information

Additional purposes

- Service use: use of services through membership registration, performance of contracts regarding service provision, and settlement of fees arising from service provision

- Member management: identity verification required for membership-based services, maintenance and management of membership status, handling complaints and dispute resolution related to service use

- Marketing and advertising: development and marketing of new services, provision of advertising information such as events, understanding access frequency or compiling statistics on members’ service use

2. Items of Personal Information Collected and Collection Methods

A. Items of personal information collected

The Company collects the following personal information:

  • At the time of membership registration: name, mobile phone number, email address, IP address, cookies, device information
  • During the process of service use: service usage records

B. Collection methods

The Company collects personal information in the following ways:

  • At the time of membership registration: directly entered online or offline
  • During the process of service use: information automatically generated in the course of service use
  • Event participation
  • Access logs
  • Server logs

C. Information on Installation, Operation, and Rejection of Automatic Collection Devices (Cookies, etc.)

The Company uses “cookies” and similar technologies (e.g., local storage) to store and retrieve usage information from time to time in order to provide individualized services and improve service safety and user experience.

1. Purpose of Cookie Use

• Essential (Service Provision/Security): Maintaining login status, security tokens, CSRF protection, session identification, cookie consent status storage (CMP), etc.

• Analytics and Statistics: Service improvement through page views, click/scroll events, dwell time, referral paths, and error/performance indicators

• Personalization (Function): Optimizing user experience through preference settings (e.g., dark mode, models/options), recently used features, etc.

2. Cookie Installation/Operation and Rejection

Data subjects can allow/block cookies and withdraw consent through browser options or the website's "Cookie Settings (Consent Management)" function.

D. Matters concerning the collection, use, and rejection of behavioral information (service usage records)

The company may collect and use the following behavioral information through automatic collection devices (cookies, etc.) during service use. Analysis and statistical/personalized cookies are, in principle, used only with the consent of the information subject.

Current Status of Behavioral Information Collection and Use

• Legal Basis: Article 15, Paragraph 1, Subparagraph 1 of the Personal Information Protection Act (Consent)
※ Essential cookies are used only to the extent necessary for service provision/security

• Collected Information: Website visit/usage history (page views, click/scroll events, dwell time, referral path), browser/device information, cookie/session identifiers, error/performance indicators

• Collection Method: When accessing and using the website Automatically collected via cookies/scripts, etc.

• Collection Purpose: Service usage statistical analysis, UX improvement (heat maps/session replays, etc.), error analysis, and service quality improvement

• Retention/Use Period (Operational Standard):
· GA4: 14 months of user-level data (cookie expiration up to 25 months)
· Microsoft Clarity: 13 months of user data, 30 days of session recording data
· Matomo (installed): Adjusted based on company settings (e.g., user data up to 3 years, aggregate reports retained for statistical purposes)
※ The retention period is kept to a minimum based on service operation policies/tool ​​settings.

E. Information on behavioral information collected by third parties (third-party automatic collection devices)

The company may use third-party scripts/tags to analyze services and improve user experience. When the information subject visits or uses the website, these third parties may collect behavioral information through automatic collection devices.

Behavioral information collected by third parties

• Collection device name / type / collecting business / collected items / purpose

1. Google Analytics 4 Tag (JavaScript) / Google LLC
· Visit/usage history, referral path, browser/device information, events (pageviews/clicks, etc.)
· Service usage statistical analysis and service improvement

2. Microsoft Clarity Script (JavaScript) / Microsoft Corporation
· Visit/usage history, on-page interactions (scrolling/clicking/mouse movements, etc.), browser/device information
· UX improvements (heat maps/session replays) and service quality enhancements

3. Matomo (open-source web log analysis tool, installable) / Matomo.org

• Opt-out:
· You can opt-out of or withdraw consent for each category at any time in the "Cookie Settings" section of the website.
· You can block/delete cookies in your browser.

In order to provide users with personalized services, the Company uses “cookies” that store and retrieve usage information from time to time.
A cookie is a small piece of information that the server (HTTP) operating the website sends to the user’s computer browser, and it may be stored on the hard disk of users’ PCs.

A. Purpose of use of cookies:
Cookies are used to identify each service visited by the user and patterns of use (such as popular search terms) in order to provide more convenient services to users.

B. Installation, operation, and rejection of cookies:
Users can choose to allow or block cookies by setting options in their web browser.

  • Edge: Settings menu at the top right of the web browser > Cookies and site permissions > Manage and delete cookies and site data
  • Chrome: Settings menu at the top right of the web browser > Privacy and security > Cookies and other site data
  • Whale: Settings menu at the top right of the web browser > Privacy > Cookies and other site data

C. If you refuse to store cookies, you may experience difficulties in using customized services.

3. Period of Processing and Retention of Personal Information

The Company retains the collected personal information until membership withdrawal. In principle, the Company retains personal information until membership withdrawal and, after the purposes of use have been achieved, destroys it in a manner that cannot be restored. However, in the following cases, personal information may be retained for a certain period in accordance with the provisions of relevant laws and regulations. The Company, in principle, retains personal information until membership withdrawal. However, in the following cases, it may exceptionally retain personal information for a certain period:


  • When consent is refused or withdrawn
  • When membership withdrawal is requested
  • When the retention period has expired
  • When there is a legal basis for retention
  • Legal grounds and retention periods

General items >

Items Retained
Legal Basis for Retention
Retention Period
Records on contracts or subscription withdrawal
Act on the Consumer Protection in Electronic Commerce, etc.
5 years
Records on payment and supply of goods, etc.
Act on the Consumer Protection in Electronic Commerce, etc.
5 years
Records on consumer complaints or dispute resolution
Act on the Consumer Protection in Electronic Commerce, etc.
3 years
Records on display/advertising
Act on the Consumer Protection in Electronic Commerce, etc.
6 months
Service visit records (log records, IP, etc.)
Protection of Communications Secrets Act
3 months

Detailed items >

Detailed items
Processing status
Voluntary membership withdrawal
Forced membership withdrawal
Dormant account
Email address
Server processing
Data retained for 30 days
Data retained for 30 days
Access to data is suspended for 6 months; data is automatically deleted after 1 year
Device information
Server processing
Data retained for 30 days
Data retained for 30 days
Access to data is suspended for 6 months; data is automatically deleted after 1 year
User communication information
Server processing
Data retained for 30 days
Data retained for 30 days
Access to data is suspended for 6 months; data is automatically deleted after 1 year
Service usage information
Server processing
Data retained for 30 days
Data retained for 30 days
Access to data is suspended for 6 months; data is automatically deleted after 1 year

4. Outsourcing of Personal Information Processing

The Company outsources personal information processing as follows in order to provide its services.

Consignee
Details of entrusted work
AWS(Amazon Web Service)
operation of cloud servers and storage of data for service provision
Toss Payments
user information for providing payment services
Stripe
user information for providing overseas payment services

5. Provision of Personal Information to Third Parties

The Company provides personal information to third parties only in cases corresponding to Articles 17 and 18 of the Personal Information Protection Act, such as with the consent of the data subject or where there are special provisions in law.

Currently, the Company does not provide users’ personal information to third parties without the user’s prior consent. (For payment services, the personal information generated in the course of domestic payments through Toss Payments and overseas payments through Stripe is handled in accordance with the privacy policies of those respective companies.)

However, if a user consents to optional cookies, such as analytics and statistics, in "Cookie Settings," behavioral information may be transmitted to and collected by third parties via scripts/tags provided by third parties, such as GA4/Clarity. Users can opt out or block this information at any time through "Cookie Settings" or browser settings.

6. Procedures and Methods for Destruction of Personal Information

The Company promptly destroys personal information when the retention period has expired, the purpose of processing personal information has been achieved, or when retention and use are no longer necessary. The Company leaves records of personal information subject to destruction and destroys it safely by methods such as shredding, crushing, or incineration. In principle, the Company retains personal information until membership withdrawal. Upon membership withdrawal, the user’s personal information is destroyed without delay. The methods of destruction are as follows:

  • For paper documents: shredding with a shredder or incineration
  • For electronic files: deletion in a way that makes recovery or reuse impossible

Personal information for which the retention period has expired will be destroyed in a manner that makes reproduction impossible.

7. Rights of Users and Legal Representatives and How to Exercise Them

Users and their legal representatives may request access to, correction of, deletion of, or suspension of processing of personal information. To do so, they may fill out an application form in accordance with the [Withdrawal of Consent to Collection and Use of Personal Information] form under this Privacy Policy and submit it by mail, email, fax, etc.

Members may request access, correction, deletion, or suspension of processing of their personal information by contacting the Company by phone, email, fax, etc.

The Company will promptly take necessary measures in response to requests from users and legal representatives.

Users may exercise the following rights:

  • Request for access to personal information
  • Request for correction of errors, etc.
  • Request for deletion
  • Request for suspension of processing
  • Withdrawal of consent to changes to this Privacy Policy

8. Measures to Ensure the Security of Personal Information

The Company takes the following measures to ensure the security of personal information:

  • Minimization of employees handling personal information and training
  • Restriction of access to personal information
  • Regular checks and inspections of personal information
  • Encryption of personal information
  • Installation and operation of security programs
  • Storage and management of personal information

Administrative measures: Establishment and implementation of internal management plans, regular employee training, etc.

Technical measures: Management of access rights to personal information processing systems, installation of access control systems, installation of intrusion prevention systems, etc.

Physical measures: Safe management of computer rooms and data storage rooms

9. Protection of Children’s Personal Information

The Company does not allow children under the age of 13 to register as members because they do not meet the eligibility requirements under the Terms of Use; therefore, the Company does not retain personal information of such children. However, if we become aware for any reason that personal information of a child under that age has been collected, we will promptly delete such information.

10. When You Are Outside the Republic of Korea

Additional measures will be taken so that the supplemental terms of use and privacy policies applicable to the relevant region (country) are complied with.

11. Personal Information Protection Officer

The Company designates the following person as the Personal Information Protection Officer to protect personal information:

  • Name: Jae Yong Shin
  • Position: CTO
  • Contact: contact@lightweight.kr

Users may contact the Personal Information Protection Officer for inquiries or complaints related to personal information protection.

12. Reporting Personal Information Infringement

Complaints and reports regarding personal information infringement may be filed with the civil service office on the first floor of the Government Complex or with the following organizations:

  • Personal Information Dispute Mediation Committee: (without area code) 1833-6972 (www.kopico.go.kr)
  • Personal Information Infringement Report Center: (without area code) 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors’ Office: (without area code) 1301 (www.spo.go.kr)
  • Cyber Investigation Bureau of the National Police Agency: (without area code) 182 (ecrm.police.go.kr)

13. Duty of Notice

If the Company amends this Privacy Policy, it will notify users of the changes on its website at least 7 days prior to the effective date of the changes.