Privacy Policy
Effective 1 August 2026 · permanent link to this version · past versions
This English text is provided for convenience. Where it differs from the Korean version, the Korean version prevails.
MOA Place (the “Company”) complies with the Personal Information Protection Act and related legislation, and publishes this policy to protect the personal data of data subjects and to handle related complaints promptly. It applies to the services provided at moa.place and its subdomains — Koroute, WellHour, the shared account and so on (the “Services”). Please read it alongside the Terms of Service and, for mobile device permissions, App Permissions.
1. Personal data processed, and how it is collected
Under Articles 15 and 22 of the Personal Information Protection Act, the Company obtains consent separately for required and optional items. Declining the required items may prevent registration; declining the optional items restricts neither registration nor use of the Services.
| Category | Items | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Registration — required | Email address, password (stored one-way hashed), given name, date of birth, nationality category (Korean / non-Korean) | Identifying and authenticating members, account management, confirming the member is 14 or over, preventing misuse | Art. 15(1)4 (performance of a contract); use of the date of birth for age confirmation, Art. 15(1)2 and Art. 22-2 | Until the account is closed (subject to the statutory periods in section 3) |
| Registration — optional | Family name, gender (female / male / other / undisclosed), contact number (mobile) | Displaying the name correctly, including family-name order by language convention; personalised service; account-related contact | Art. 15(1)1 (consent) | Until the account is closed or consent is withdrawn |
| Marketing — optional | Email address, contact number (if provided), consent status and the dates consent was given and withdrawn | Sending marketing and advertising information (to consenting members only) | Art. 15(1)1 (consent) and Art. 22 | Until consent is withdrawn or the account is closed |
| Use of the Services | Routes and places saved in Koroute; WellHour booking details (date and time, venue, item, requests); enquiry history | Providing and improving the Services, fulfilling bookings, handling enquiries | Art. 15(1)4 (performance of a contract) | Until the account is closed (subject to the statutory periods in section 3) |
| Collected automatically | IP address, browser and operating system, access time, service usage records, cookies (see section 10) | Security, prevention of misuse, retention of access records | Art. 15(1)4 and 15(1)6 (legitimate interests) | 1 year (access records); see section 3 |
Personal data is either entered by the data subject during registration, use of the Services and enquiries, or generated and collected automatically.
What we do not collect
The Company does not collect or store resident registration numbers or other unique identifiers. The contact number is optional, is used only for account-related contact, is not verified for ownership, and is not used as proof of identity. The Company collects no third-party advertising or tracking identifiers.
2. Purposes of processing
- Identifying and authenticating members, account management, prevention of misuse
- Confirming that the member is 14 or over
- Providing and improving the Services, including saving and recommending routes and wellness bookings
- Contacting and coordinating with partner businesses to fulfil bookings
- Member management, including announcements and handling enquiries and complaints
- Sending marketing and advertising information (to consenting members only; consent may be withdrawn at any time)
- Meeting legal obligations
3. Processing and retention periods
Personal data is destroyed without delay once its purpose is achieved (when the account is closed). Records of marketing consent and its withdrawal are kept until consent is withdrawn or the account is closed. The following are retained for the periods stated:
- Records of contracts and withdrawal of subscription: 5 years (Act on Consumer Protection in Electronic Commerce)
- Records of payment and supply of goods: 5 years (same Act)
- Records of consumer complaints and dispute resolution: 3 years (same Act)
- Access records: 1 year (Standards for Securing Personal Data Safety, Art. 8, which includes the 3-month minimum under the Protection of Communications Secrets Act)
Records of consent and its withdrawal are kept separately until the account is closed, so that the lawfulness of processing can be demonstrated.
4. Disclosure to third parties
The Company does not disclose personal data to third parties except with the data subject's consent or where the law provides a basis. For a WellHour booking, the minimum information needed to fulfil it (name, booking details, requests) is provided to the relevant partner business; the recipient and the items are shown on the booking screen.
5. Processors
The Company entrusts the following work to external processors. Contracts require compliance with data protection law, performance is supervised, and changes to processors or entrusted work are published in this policy.
| Processor | Entrusted work |
|---|---|
| Cloudflare, Inc. | Carrying service traffic, web application firewall and DDoS protection, domain name resolution |
| Amazon Web Services, Inc. (Asia Pacific, Seoul region) |
Sending verification, password-reset and security notification emails |
| TODO_HOSTING_PROVIDER | Server operation and data storage |
6. International transfers
The Company transfers personal data abroad as set out below, in order to protect the traffic reaching the service. The transfer is an entrustment necessary to perform the contract and improve service for the data subject under article 28-8(1)3 of the Personal Information Protection Act, and the particulars required by article 28-8(2) are published here.
| Recipient | Cloudflare, Inc. (privacy contact: privacyquestions@cloudflare.com) |
|---|---|
| Data transferred | IP address, time of access, browser type (User-Agent), requested address, cookie values, and the email address and password contained in a sign-in request |
| Destination | The United States and the countries where Cloudflare operates points of presence. The point of presence is chosen automatically by the visitor's location and is not confined to Korea. |
| When and how | At the moment of access, in real time, over encrypted transport (HTTPS). |
| Purpose | Carrying traffic, blocking attacks at the web application firewall, DDoS protection, and identifying automated abusive requests |
| Retention | Held for the duration of the processing needed to carry the request; security logs are kept for up to 30 days under Cloudflare's policy and then deleted. |
| How to refuse | You may refuse the transfer by contacting the data protection officer. The transfer is inherent in reaching the service at all, so refusing means the service cannot be used. |
The Company has a data protection agreement with the recipient and applies the safeguards required by law, including ensuring that the data is carried only over encrypted transport.
7. Deletion
Personal data whose retention period has elapsed or whose purpose has been achieved is destroyed without delay. Electronic files are deleted irrecoverably and printed material is shredded or incinerated. Information that must be retained by law is stored separately in its own database.
8. Rights of data subjects and legal representatives
You may exercise the following rights at any time:
- Request access to, correction or deletion of, or suspension of processing of your personal data
- Withdraw consent for optional items and for marketing communications
- View the history of consents given and withdrawn
- See the devices currently signed in and sign any of them out individually
- Withdraw consent and close your account (available directly at id.moa.place/account)
Requests may be made at id.moa.place/account or by email to contact@moaplace.com. The Company acts within the period set by law and notifies the outcome. Where a representative acts on your behalf, a letter of authority may be required.
9. Children under 14
The Services are open only to those aged 14 and over. The Company confirms age from the date of birth entered at registration, refuses registration by anyone under 14, and obtains a required confirmation of being 14 or over during sign-up. The Company does not collect the personal data of children under 14 and destroys it without delay if it is found to have been collected.
10. Cookies and similar technologies
- Session cookie: an HttpOnly session cookie set by id.moa.place to keep you signed in.
- Sign-in flow cookie: a short-lived cookie identifying the browser that began a sign-in request; it expires when sign-in completes.
- moa_auth: a non-sensitive display cookie (value “1”) used only to show whether you are signed in; it is never used to decide authentication.
- Theme preference: your dark or light mode choice is stored in browser localStorage and is not sent to the server.
You can refuse cookies in your browser settings, though some features such as signing in will then not work. The Company uses no third-party advertising or tracking cookies.
11. Security measures
- One-way password hashing (argon2id) and encryption in transit (TLS)
- Least-privilege access and access control
- Retention and review of access records
- Support for two-factor authentication and passkeys (WebAuthn)
- Email notification to the member on security-relevant changes — password change, disabling two-factor authentication, registering a passkey and similar
- Temporary restriction after repeated failed sign-in attempts
12. Notice for users in the EEA and the United Kingdom
For users resident in the European Economic Area or the United Kingdom, personal data is processed on the following bases:
- Performance of a contract (Art. 6(1)(b)): providing the account (email address, password, given name, date of birth, nationality category), saving routes, processing bookings
- Compliance with a legal obligation (Art. 6(1)(c)): statutory record retention, age confirmation
- Legitimate interests (Art. 6(1)(f)): security of the Services and prevention of misuse
- Consent (Art. 6(1)(a)): optional items (family name, gender, contact number) and marketing communications. Consent may be withdrawn at any time.
In addition to the rights in section 8, such users have the right to data portability, the right to object to processing, and rights in relation to automated decisions including profiling, and may lodge a complaint with the supervisory authority in their country. Transfers to Korea or other third countries are made under appropriate safeguards pursuant to Article 46 GDPR, such as standard contractual clauses. The Company makes no decision producing legal effects based solely on automated processing.
13. Data protection officer and contact
- Name: MOA Place · Representative: TODO_BIZ_REPRESENTATIVE · Business registration no.: TODO_BIZ_REGISTRATION_NO · Mail-order sales registration no.: TODO_BIZ_MAILORDER_NO
- Address: TODO_BIZ_ADDRESS
- Data protection officer: TODO_DPO_NAME (TODO_DPO_TITLE)
- Email: contact@moaplace.com
You may use this address for any enquiry, complaint or request for redress relating to personal data, and the Company will respond without delay.
14. Complaints and redress
If you need to report or discuss an infringement of your personal data, you may contact:
- Personal Information Infringement Report Centre: 118 / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 / kopico.go.kr
- Supreme Prosecutors' Office, Cyber Investigation Division: 1301 / spo.go.kr
- National Police Agency, Cyber Bureau: 182 / ecrm.police.go.kr
15. Changes to this policy
Where this policy is added to, amended or has content removed, notice is given through announcements in the Services at least 7 days before the change takes effect (30 days for significant changes). Superseded versions remain readable at their dated permanent links. Where the Korean and English versions differ, the Korean version prevails.
This policy takes effect on 1 August 2026 and supersedes the policy effective from 25 July 2026.