Terms and Policies 한국어 · moa.place

Privacy Policy

Effective 1 August 2026 · permanent link to this version · past versions

This English text is provided for convenience. Where it differs from the Korean version, the Korean version prevails.

MOA Place (the “Company”) complies with the Personal Information Protection Act and related legislation, and publishes this policy to protect the personal data of data subjects and to handle related complaints promptly. It applies to the services provided at moa.place and its subdomains — Koroute, WellHour, the shared account and so on (the “Services”). Please read it alongside the Terms of Service and, for mobile device permissions, App Permissions.

1. Personal data processed, and how it is collected

Under Articles 15 and 22 of the Personal Information Protection Act, the Company obtains consent separately for required and optional items. Declining the required items may prevent registration; declining the optional items restricts neither registration nor use of the Services.

Personal data processed
Category Items Purpose Legal basis Retention
Registration — required Email address, password (stored one-way hashed), given name, date of birth, nationality category (Korean / non-Korean) Identifying and authenticating members, account management, confirming the member is 14 or over, preventing misuse Art. 15(1)4 (performance of a contract); use of the date of birth for age confirmation, Art. 15(1)2 and Art. 22-2 Until the account is closed (subject to the statutory periods in section 3)
Registration — optional Family name, gender (female / male / other / undisclosed), contact number (mobile) Displaying the name correctly, including family-name order by language convention; personalised service; account-related contact Art. 15(1)1 (consent) Until the account is closed or consent is withdrawn
Marketing — optional Email address, contact number (if provided), consent status and the dates consent was given and withdrawn Sending marketing and advertising information (to consenting members only) Art. 15(1)1 (consent) and Art. 22 Until consent is withdrawn or the account is closed
Use of the Services Routes and places saved in Koroute; WellHour booking details (date and time, venue, item, requests); enquiry history Providing and improving the Services, fulfilling bookings, handling enquiries Art. 15(1)4 (performance of a contract) Until the account is closed (subject to the statutory periods in section 3)
Collected automatically IP address, browser and operating system, access time, service usage records, cookies (see section 10) Security, prevention of misuse, retention of access records Art. 15(1)4 and 15(1)6 (legitimate interests) 1 year (access records); see section 3

Personal data is either entered by the data subject during registration, use of the Services and enquiries, or generated and collected automatically.

What we do not collect

The Company does not collect or store resident registration numbers or other unique identifiers. The contact number is optional, is used only for account-related contact, is not verified for ownership, and is not used as proof of identity. The Company collects no third-party advertising or tracking identifiers.

2. Purposes of processing

3. Processing and retention periods

Personal data is destroyed without delay once its purpose is achieved (when the account is closed). Records of marketing consent and its withdrawal are kept until consent is withdrawn or the account is closed. The following are retained for the periods stated:

Records of consent and its withdrawal are kept separately until the account is closed, so that the lawfulness of processing can be demonstrated.

4. Disclosure to third parties

The Company does not disclose personal data to third parties except with the data subject's consent or where the law provides a basis. For a WellHour booking, the minimum information needed to fulfil it (name, booking details, requests) is provided to the relevant partner business; the recipient and the items are shown on the booking screen.

5. Processors

The Company entrusts the following work to external processors. Contracts require compliance with data protection law, performance is supervised, and changes to processors or entrusted work are published in this policy.

Processors and entrusted work
Processor Entrusted work
Cloudflare, Inc. Carrying service traffic, web application firewall and DDoS protection, domain name resolution
Amazon Web Services, Inc.
(Asia Pacific, Seoul region)
Sending verification, password-reset and security notification emails
TODO_HOSTING_PROVIDER Server operation and data storage

6. International transfers

The Company transfers personal data abroad as set out below, in order to protect the traffic reaching the service. The transfer is an entrustment necessary to perform the contract and improve service for the data subject under article 28-8(1)3 of the Personal Information Protection Act, and the particulars required by article 28-8(2) are published here.

International transfer
Recipient Cloudflare, Inc. (privacy contact: privacyquestions@cloudflare.com)
Data transferred IP address, time of access, browser type (User-Agent), requested address, cookie values, and the email address and password contained in a sign-in request
Destination The United States and the countries where Cloudflare operates points of presence. The point of presence is chosen automatically by the visitor's location and is not confined to Korea.
When and how At the moment of access, in real time, over encrypted transport (HTTPS).
Purpose Carrying traffic, blocking attacks at the web application firewall, DDoS protection, and identifying automated abusive requests
Retention Held for the duration of the processing needed to carry the request; security logs are kept for up to 30 days under Cloudflare's policy and then deleted.
How to refuse You may refuse the transfer by contacting the data protection officer. The transfer is inherent in reaching the service at all, so refusing means the service cannot be used.

The Company has a data protection agreement with the recipient and applies the safeguards required by law, including ensuring that the data is carried only over encrypted transport.

7. Deletion

Personal data whose retention period has elapsed or whose purpose has been achieved is destroyed without delay. Electronic files are deleted irrecoverably and printed material is shredded or incinerated. Information that must be retained by law is stored separately in its own database.

8. Rights of data subjects and legal representatives

You may exercise the following rights at any time:

Requests may be made at id.moa.place/account or by email to contact@moaplace.com. The Company acts within the period set by law and notifies the outcome. Where a representative acts on your behalf, a letter of authority may be required.

9. Children under 14

The Services are open only to those aged 14 and over. The Company confirms age from the date of birth entered at registration, refuses registration by anyone under 14, and obtains a required confirmation of being 14 or over during sign-up. The Company does not collect the personal data of children under 14 and destroys it without delay if it is found to have been collected.

10. Cookies and similar technologies

You can refuse cookies in your browser settings, though some features such as signing in will then not work. The Company uses no third-party advertising or tracking cookies.

11. Security measures

12. Notice for users in the EEA and the United Kingdom

For users resident in the European Economic Area or the United Kingdom, personal data is processed on the following bases:

In addition to the rights in section 8, such users have the right to data portability, the right to object to processing, and rights in relation to automated decisions including profiling, and may lodge a complaint with the supervisory authority in their country. Transfers to Korea or other third countries are made under appropriate safeguards pursuant to Article 46 GDPR, such as standard contractual clauses. The Company makes no decision producing legal effects based solely on automated processing.

13. Data protection officer and contact

You may use this address for any enquiry, complaint or request for redress relating to personal data, and the Company will respond without delay.

14. Complaints and redress

If you need to report or discuss an infringement of your personal data, you may contact:

15. Changes to this policy

Where this policy is added to, amended or has content removed, notice is given through announcements in the Services at least 7 days before the change takes effect (30 days for significant changes). Superseded versions remain readable at their dated permanent links. Where the Korean and English versions differ, the Korean version prevails.

This policy takes effect on 1 August 2026 and supersedes the policy effective from 25 July 2026.