Privacy Policy
We corrected what differed from actual processing: removed a hosting provider no longer used from the processor list, designated the privacy officer, and restated cookies and technical safeguards as they are applied today. When a legal professional has reviewed this Policy, the outcome will be recorded in the revision history.
YouthOn (the “Company”) complies with the Personal Information Protection Act and other applicable laws and establishes and publishes this Privacy Policy to safely protect personal information of user organizations and their administrators. The Company collects and uses only the minimum personal information necessary to provide services such as software procurement, Google Workspace provisioning and operations, quotations, and payments.
1. Personal Information We Collect
The Company collects the following information during organization registration, login, quotation/payment, and inquiry processes.
| Category | Collected items | Collection point |
|---|---|---|
| Organization information | Organization name, organization type, organization domain, business registration number | Organization registration · quotation |
| Administrator information | Administrator name, email address, contact number | Organization registration · login |
| Verification documents | Business registration certificate, unique-number certificate, evidence of youth-organization eligibility | Organization verification application |
| License recipient | Name · email address · affiliation of the user receiving the license | License provisioning request |
| Transaction information | Purchase and quotation history, payment method type, payment approval/cancellation records, tax invoice information | Quotation · payment |
| Refund information | Bank name, account number and account holder for the refund | When a refund is paid to a bank account |
| Automatically generated | Service usage records, access logs, cookies, browser · device information, IP address | During service use |
For card payments, payment instrument information such as card number, expiration date, and password is collected and processed directly by the payment gateway (PG). The Company does not receive or store it. The Company stores only the minimum information needed to confirm transactions, such as payment method (card/bank transfer/deferred), authorization number, approved amount, and timestamp.
The Company does not collect information such as ideology or beliefs, labor-union membership, political opinions, health information, or information about sexual life — sensitive information is not collected. The Company also does not collect unique identification information such as resident registration numbers. A business registration number identifies a corporation or organization and is not treated as unique identification information.
2. Purposes of Collection and Use
- Organization verification · member management — verify organization eligibility (apply youth-organization pricing), identify administrators, prevent misuse
- Service provision — provision and apply software licenses, create and migrate accounts, issue quotations, provision and operate Google Workspace
- Payment · settlement — process purchase and renewal payments, issue tax invoices and transaction documents
- Notices · support — expiration and renewal guidance, service notices, inquiries and incident response
- Service improvement — improve functionality by analyzing usage statistics (processed after removing identifying information)
3. Retention and Use Period
The Company destroys personal information without delay once the collection/use purpose has been achieved. However, the following information is retained for the periods required by applicable law.
| Retained item | Retention period | Legal basis |
|---|---|---|
| Records concerning contracts or withdrawal | 5 years | Electronic Commerce Act |
| Records concerning payment and supply of goods/services | 5 years | Electronic Commerce Act |
| Records concerning consumer complaints or dispute resolution | 3 years | Electronic Commerce Act |
| Records concerning labeling and advertising | 6 months | Electronic Commerce Act |
| Transaction evidence such as tax invoices | 5 years | Framework Act on National Taxes · Value-Added Tax Act |
| Service access records | 3 months | Protection of Communications Secrets Act |
| Member (organization) information | Until membership withdrawal | Data-subject consent |
4. Provision of Personal Information to Third Parties
The Company does not use personal information beyond the purposes stated in this Policy or provide it to third parties, except in the following cases:
- The data subject has separately consented in advance
- License provisioning request to a software Vendor — due to the nature of procurement, the email address of the user receiving the license and the organization name are provided to the relevant Vendor. The provided items, purpose, and retention period are disclosed by product when the quotation is finalized. If the data subject does not consent, provisioning of that product may be restricted.
- Where specifically permitted by law or requested by an investigative authority in accordance with procedures and methods prescribed by law
5. Outsourcing of Personal Information Processing
The Company outsources personal information processing as follows to provide Services smoothly and specifies responsibilities for secure management, restrictions on sub-processing, damages, and related matters in outsourcing agreements.
| Processor | Outsourced work | Retention · use period |
|---|---|---|
| Cloudflare, Inc. (Cloud Infrastructure) | Site and API hosting with cookie-free traffic statistics (Cloudflare Web Analytics); storage and processing of applications, inquiries, quotations, orders and registration documents; generating AI assistant answers | Until termination of the agreement or the retention period in this Policy |
| Resend (Email delivery) | Sign-in links, verification results, order and payment emails, billing and expiration notices | Until termination of the outsourcing agreement |
Card payment is not offered yet, so no work is outsourced to a payment gateway. When card payment starts, the gateway will be added to this table before it is used. Changes to processors or outsourced work will be disclosed through this Policy.
6. Overseas Transfers of Personal Information
Many software products handled by the Company are supplied by overseas businesses. Personal information may be transferred overseas as follows for license provisioning.
| Recipient | Transferred items | Destination country · purpose | Retention period |
|---|---|---|---|
| Google LLC and other overseas software Vendors | User email address, name, organization name | United States and other Vendor locations · license provisioning and account creation | Until license use ends or according to Vendor policy |
| Cloudflare, Inc. Privacy contact | Email address, name, organization, phone, registration document file, inquiry/quotation/order/license assignment records, IP address | United States and other countries with Cloudflare data centers · service operations and storage · transmitted over the network when you submit data | The retention period in Section 3 or until termination of the agreement |
| Resend Privacy contact | Recipient email address; name, organization and order details included in the email | United States · sending notices · transmitted when an email is sent | Until termination of the outsourcing agreement |
Transfers to Cloudflare and Resend are necessary to operate the site and accounts, so if you refuse them you cannot use sign-up, sign-in, inquiries or quotations. You can refuse by contacting the privacy officer. For software Vendors, the recipient's legal name and contact information, destination country, transfer timing, and transfer method are specifically disclosed by product at the quotation stage when the purchased product is finalized. Data subjects may refuse overseas transfer. However, refusal may make it impossible to provision a license for the relevant product. In accordance with Article 28-8 of the Personal Information Protection Act, the Company ensures through contracts and other measures that recipients implement necessary protections for personal information.
7. Personal Information of Children Under 14
The Company does not directly collect personal information of children under 14 from the data subject. However, organizations using the Youth Organization Edition may request account provisioning for program participants (youth). In such cases, the following standards apply.
- Responsibility for obtaining consent to collect and use participant personal information rests with the relevant organization. For children under 14, the organization must obtain consent from a legal representative in advance.
- The Company processes only the minimum information required for account provisioning (name or identification ID, affiliated organization) and does not separately collect information beyond the roster submitted by the organization.
- When an account is no longer needed because a program has ended or for another reason, the Company deletes the account and related information without delay at the organization's request.
- Legal representatives may request access, correction, deletion, or suspension of processing of the child's personal information.
8. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
Data subjects may exercise the following rights regarding their personal information at any time:
- Request access to personal information
- Request correction of errors
- Request deletion
- Request suspension of processing
Rights may be exercised in writing or by email (privacy@youthon.kr), and the Company will act without delay. Requests may also be made through a legal representative or authorized agent. However, requests may be restricted where information must be retained by law or where the request may unjustly infringe another person's life, body, or property; in such cases, the Company will promptly notify the data subject of the reason. After logging in to My Page, users can directly view and delete organization/administrator information, issued quotation history, and organization verification status.
9. Destruction Procedures and Methods
- Destruction procedure — personal information whose processing purpose has been fulfilled or retention period has expired is destroyed through procedures established by internal policy and applicable law. Where retention is required by law, the information is moved to a separate database or stored in a different location.
- Destruction method — electronic files are permanently deleted in a manner that prevents recovery or restoration, and paper documents are shredded or incinerated.
10. Measures to Ensure Security of Personal Information
- Administrative measures — establish and implement internal management plans, minimize personnel handling personal information and provide regular training, manage access permissions
- Technical measures — TLS encryption on every connection, one-way hashing of passwords (PBKDF2-SHA-256), hashing of sign-in link and session values, separate-key encryption of provisioned account passwords (AES-256-GCM), two-factor authentication for the admin console, private storage for verification documents, and retention of access logs
- Physical measures — access control for data-storage systems and physical document-storage locations
11. Cookies and Other Automatic Collection Technologies
The Company uses cookies only to keep you signed in and to protect the sign-in process. Cookies are small pieces of information stored in the browser. Users can refuse or delete cookies through browser settings; if cookies are refused, functions that require sign-in cannot be used.
Visit statistics are collected without cookies (Cloudflare Web Analytics). Cart and quotation settings and the language choice are kept only in the browser's storage and are sent to the server when a quotation is issued.
The Company does not collect behavioral information for personalized advertising and does not use third-party tracking tools for advertising purposes.
12. Automated Decisions
The Company does not use personal information to make automated decisions that have legal effects or similarly significant effects on data subjects. If such decisions are introduced in the future, the Company will disclose in advance the criteria, procedures, and methods for refusing or requesting an explanation through this Policy.
13. Privacy Officer and Access Requests
The Company designates the following privacy officer to oversee personal information processing and handle complaints and remedies relating to personal information.
| Category | Details |
|---|---|
| Privacy officer | Name 조민우 · Title Representative · Email privacy@youthon.kr |
| Department receiving and processing personal-information access requests | YouthOn Operations Team · Email privacy@youthon.kr |
Data subjects may contact the privacy officer regarding any privacy-related inquiry, complaint, or request for remedy arising from use of the Services, and the Company will respond and act without delay.
14. Remedies for Rights Violations
Data subjects may request dispute resolution or counseling from the following organizations for remedies relating to personal-information infringement.
| Organization | Contact | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee | 1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center (KISA) | 118 without area code | privacy.kisa.or.kr |
| Supreme Prosecutors' Office Cyber Investigation Division | 1301 without area code | www.spo.go.kr |
| Korean National Police Agency Cyber Investigation Bureau | 182 without area code | ecrm.police.go.kr |
In addition, if rights or interests are infringed by an administrative disposition or omission of a personal-information controller, an administrative appeal may be filed under the Administrative Appeals Act.
15. Changes to This Privacy Policy
This Policy applies from its effective date. If additions, deletions, or amendments are made because of changes in law, policy, or security technology, notice will be provided at the top of this page and to registered administrator emails beginning 7 days before the effective date of the change ( 30 days before changes that materially affect data-subject rights). Previous versions will be retained and made available on request.
Revision history
- Version 1.1 (October 6, 2026) — Sales opened. Removed Amazon Web Services from the processor and overseas-transfer lists (hosting consolidated on Cloudflare), designated the privacy officer, added refund account information, and corrected cookies and technical measures to what is actually applied.
- Version 1.0 (August 22, 2026) — Draft before sales opened.
The structure and required items in this Policy were prepared based on the Personal Information Protection Commission's Guidelines for Drafting Privacy Policies and the statutory requirements of Article 30 of the Personal Information Protection Act.
Sentence structure and drafting style also reference open-source policy documents — Basecamp Policies (CC BY 4.0, “Adapted from the Basecamp open-source policies / CC BY 4.0”), GitHub Site Policy (CC0 1.0).
The licenses in the referenced source materials remain with their respective copyright holders, and this Policy has been modified and rewritten for YouthOn. It has not yet been reviewed by a legal professional; the outcome will be recorded in the revision history once it has.