Data categories, retention, processors, transfers

Privacy
Privacy Policy
Effective date: 2026-10-05
Accounts, service use, restrictions, liability, IP
Pricing, renewals, cancellation, refunds, overcharges
We only process the information needed to run owner accounts, guest check-in, and booking operations.
Guest reservation data is generally processed on the owner’s instructions, while we process security, billing, and legal-compliance data in our own capacity where needed.
The Business plan is billed at US$39 per month or US$420 per year (US$35 monthly equivalent, approximately 10% annual discount). All billing and settlement are processed in USD. Card and payment method details are handled directly in the Creem checkout flow. We do not store full card numbers.
Cloudflare, Creem, and Expo push may process limited data outside Korea, and the transfer basis and scope are disclosed in this policy.
Cloudflare is used for proxying, transport security, and traffic protection, including abnormal traffic filtering.
Ahn Jae Young · [email protected]
1. Purpose of processing personal information
We process personal information for owner accounts, property and room management, guest check-in on travelers’ personal phones using supported OTA booking evidence, check-in guidance and door code reveal, completion records, owner app alerts, support, billing, and service security.
Guest and traveler information uploaded by the owner is generally processed within the scope of the owner’s instructions. We do not use that data for our own marketing purposes except where independent processing is necessary for security, billing, legal compliance, or dispute response.
We use collected information only within those purposes. If the purpose changes, we provide any notice or consent required by applicable law.
2. Categories of information we collect and how we collect it
Information provided directly by the owner: email, password hash, name, property name, address, logo image, owner contact name, phone number, check-in and check-out time, room information, door codes, and guest guidance text.
Signup document acceptance and acknowledgement records: account identifier, versions of the Terms, Privacy Policy, and Billing & Subscription Policy, timestamp, and display language, used to establish the service agreement and applicable documents.
Booking information uploaded or entered by the owner: guest name, encrypted phone value and last four digits, encrypted passport number and hash, reservation number, room, check-in date, check-out date, notes, and upload review results.
Information entered or generated during personal-phone guest check-in: guest name, original reservation number from a supported OTA, an HttpOnly session cookie and server-side session, IP address, user agent, and completion timestamp.
We process a session identifier hash and expiry as part of check-in requests. Guest check-in does not require a registered device or device token.
Information generated through the owner mobile app: mobile access token, refresh token, push token, app version, device name, last seen time, and notification read history.
Billing and operational records: plan type, free trial start and end dates, account activation timestamp, billing status, reference details needed to process Creem orders or subscriptions, tax and receipt status, notification logs, and event or error logs.
Free-trial anti-abuse records: hashed identifiers derived from email, IP address, property name, customer page address, and owner phone number, plus related timestamps, used to limit repeat free-trial signup.
Security and delivery metadata: request metadata, timestamps, paths, browser and device information, and security detection logs generated through Cloudflare’s DNS, proxy, cache, and protection layer.
3. Legal basis for processing
We process information needed to register, authenticate, and operate the service because it is necessary to perform the service contract with the owner.
For guest booking and check-in data that the owner uploads or instructs us to process, we process that information to perform the service contract with the owner. The owner remains responsible for obtaining any lawful collection basis, notice, or consent required at the source.
We process billing, refunds, accounting, and dispute-response information where necessary to perform the contract or comply with legal obligations.
Owner app alerts and operational notifications are processed to provide the features selected by the owner and to operate the service reliably.
Security logs, anti-abuse records, and outage analysis data are processed to protect the service and comply with legal requirements.
4. Retention period
Owner account and property information is generally kept while the service agreement remains active and deleted without undue delay after account deletion or termination, unless retention is required for unresolved payments, disputes, or legal obligations.
Signup document acceptance and acknowledgement records are kept while the account exists and deleted with the account. Contract and transaction records that must separately be retained by law are subject to the applicable statutory retention requirements.
Booking, check-in, notification, and upload review records may be retained while needed for operational history and dispute response, and only as long as permitted or required after termination.
As a general rule, one year after checkout we anonymize or delete reservation-related personal data, including guest names, encrypted guest contact or identity fields, original OTA reservation numbers and search identifiers, source evidence, and normalized personal information in import rows. Related check-in sessions and electronic agreement evidence, including signature images and documents, hashes, IP addresses, and user agents, are also cleaned up after this retention period. Expired guest check-in sessions may be deleted after a 7-day cleanup grace period while valid signature and completion records remain linked.
Information about previously registered guest devices and their operational records may be processed as needed for the existing device feature; new personal-phone QR check-in does not require guest device registration. Expired or used device pairing tokens may be deleted through scheduled cleanup.
Hashed free-trial anti-abuse records may be retained without the original identifiers after account deletion to prevent repeated free-trial signup and support dispute response.
Under applicable consumer protection laws, records on contracts or withdrawals, payment and supply may be retained for 5 years, and complaint or dispute-handling records for 3 years.
Connection logs and similar telecom records may be retained for 3 months where required by law.
5. Third-party sharing
We do not share personal information with third parties as a rule.
Exceptions may apply where the user has consented, where law specifically requires disclosure, or where a lawful request is made by an investigative or regulatory authority.
For paid subscriptions, taxes, refunds, and chargebacks, Creem may act as Merchant of Record. In that case, owner identity and order or subscription status information may be exchanged or received within the scope necessary to complete the payment relationship.
We do not sell guest or owner personal information or disclose it for third-party advertising purposes.
If a specific third-party disclosure becomes necessary, we disclose the recipient, purpose, categories of data, and retention period as required by law.
6. Role allocation and processors
For reservation and traveler data entered by the owner, the owner is generally the party responsible for lawful collection and source notice, while we process the data to provide the hosted service.
We may independently determine certain processing for security, billing, logs, legal compliance, and dispute response where that is necessary to operate and defend the service.
We use service providers where necessary to operate the service.
Cloudflare: DNS, CDN, reverse proxy, SSL/TLS, cache, traffic acceleration, web security, and DDoS protection. In that process, connection metadata such as IP address, headers, path, query string, user agent, and response status may be processed.
Creem: paid checkout, subscriptions, tax handling, invoices and receipts, refunds, and chargebacks. This may involve owner email, name, reference details needed to process orders or subscriptions, billing status, and related billing details. Payment instrument details such as full card numbers are handled directly in the Creem payment flow and are not stored by us.
Expo, Inc.: owner app push notification delivery. Push tokens, notification titles and bodies, deep links, device information, and delivery results may be processed for that purpose.
We update the policy or service notice if processors materially change, and we require processors by contract to follow restrictions and safeguards required by applicable privacy law.
7. International processing and transfers
Because the service relies on global infrastructure, some data may be processed outside Korea. We disclose the transfer basis and scope in accordance with Korean privacy law.
Cloudflare, Inc. / Countries: the United States and Cloudflare global network regions / Timing and method: transferred over encrypted HTTPS when the service or API is used / Data categories: IP address, request headers, path, query string, user agent, response status, and security logs / Purpose: DNS, CDN, proxying, SSL/TLS, web security, and DDoS mitigation / Retention: until the security or delivery purpose is fulfilled or for the retention period applied under Cloudflare’s contract or policy.
Creem / Countries: the United States. Additional countries may be involved where card networks, payment rails, or tax processing require it, and material changes are disclosed in this policy or the checkout flow. / Timing and method: transferred over encrypted APIs or checkout integrations during payment, renewal, refund, or chargeback processing / Data categories: owner email, name, order and subscription reference data, billing status, billing details, tax and receipt status / Purpose: payments, subscriptions, tax handling, invoices, receipts, refunds, and chargebacks / Retention: while the payment relationship or legally required retention period remains in effect.
Expo, Inc. / Countries: the United States / Timing and method: transferred through encrypted APIs when owner app alerts are sent / Data categories: Expo push token, notification title, notification body, deep link, minimal device identifiers, and delivery result / Purpose: owner alert delivery / Retention: until the token expires or is invalidated by logout, app deletion, or service configuration changes.
If a data subject does not want the relevant cross-border transfer, they may contact us. However, restricting transfers required for Cloudflare, Creem, or Expo push delivery may prevent the service, billing flow, or notifications from working in whole or in part.
8. Deletion of personal information
When retention is no longer necessary or the purpose has been fulfilled, we delete personal information without undue delay.
Electronic files are deleted in a manner that makes restoration impracticable, and paper records, if any, are shredded or otherwise destroyed.
Where law requires continued retention, the information is separated and not used for any purpose other than the required retention.
9. Rights of data subjects
Users may request access, correction, deletion, restriction, or withdrawal of consent relating to their personal information. Owners can generally request this through service settings or by contacting the official support email.
Requests concerning guest booking information are generally handled with reference to the owner’s management authority and any legal retention requirements, and the owner is the primary contact for source data that the owner uploaded or instructed us to process.
We verify identity where appropriate and respond without undue delay unless a legal restriction applies.
Account deletion requests can be submitted through the account deletion page or the official support email.
10. Cookies and similar technologies
We may use cookies or similar technologies for login persistence, session security, and service state management.
Guest check-in sessions use Secure, HttpOnly cookies; the raw authentication token is not stored in browser scripts or localStorage. Guest check-in does not use registered-device tokens or heartbeats.
Because Cloudflare is used for performance and security, request metadata may also be processed through caching, proxying, and security rule enforcement.
Users can restrict cookies through browser settings, though doing so may affect login and parts of the service.
11. Security measures
We apply technical and organizational safeguards such as access control, password hashing, field encryption for selected data, logging, and internal operating procedures.
Sensitive operational fields such as guest phone data and room door codes are handled through encryption or restricted-display patterns where appropriate.
We also use Cloudflare-based transport and edge security measures to mitigate attacks, block abnormal traffic, and strengthen SSL/TLS protection.
12. Privacy contact and complaint channels
Privacy contact: Ahn Jae Young
Organization: 지이오게이트웨이 (GEO Gateway)
Email: [email protected]
If you need external assistance, you may contact the Korea Internet & Security Agency (KISA) privacy complaint center or other competent Korean authorities.
13. Changes to this policy
This policy may be updated when laws, services, processing categories, or security practices change.
If a material change affecting rights or processing methods occurs, we provide advance notice through StayPass Lite or a related service screen, and the effective date will be stated at the top of the policy.