Privacy Policy

MyTravel values and protects your personal information

MyTravel (hereinafter referred to as the "Service") protects the personal information of its users in accordance with the Personal Information Protection Act of Korea, the Act on Promotion of Information and Communications Network Utilization and Information Protection, the EU General Data Protection Regulation (GDPR), and other applicable laws and regulations. This Privacy Policy is established and disclosed to handle related grievances promptly and smoothly. This policy applies to all personal information collected through the use of the Service.

1. Personal Information We Collect

The Service collects the following personal information for membership registration, service provision, and customer inquiry handling.

Required Information

Collected ItemCollection PointPurpose
Email addressRegistrationAccount identification, login, notifications
Password (stored encrypted)RegistrationAccount authentication
Name (nickname)RegistrationDisplay within service, social features

Information Collected via Social Login

When using social login through Google, Apple, Kakao, or other providers, the following information is collected from the respective OAuth provider.

Unique identifiers (IDs) provided by OAuth providers are used solely for account linking and are not shared with third parties.

Optional Information (Collected with Feature Use)

The following items are collected only when the user explicitly grants permission and uses the corresponding feature.

Collected ItemCollection PointPurposeLegal Basis
Location Information (GPS coordinates) After user permission Location-based travel recommendations, nearby attractions search Act on the Protection and Use of Location Information
Push Notification Permission After user permission Trip invitations, AI generation completion, schedule notifications Act on Promotion of Information and Communications Network Utilization and Information Protection
Photo/Camera Access Permission After user permission Profile photo, travel photo uploads Personal Information Protection Act

Location Information Usage and Protection

Information Automatically Collected During Service Use

2. Purpose of Personal Information Use

The collected personal information is used for the following purposes.

3. Retention and Disposal of Personal Information

Retention Period

Users' personal information is promptly destroyed once the purpose of collection and use has been achieved. However, where retention is required by applicable laws and regulations, such information is stored separately in a dedicated database for the specified period.

Retained ItemRetention PeriodLegal Basis
Account information (email, name)Until account deletionService agreement / GDPR Art. 6(1)(b)
Travel plan dataUntil account deletionService agreement / GDPR Art. 6(1)(b)
Access logs3 monthsKorean Telecommunications Privacy Act / GDPR Art. 6(1)(f)
E-commerce transaction records5 yearsKorean Consumer Protection in E-Commerce Act / GDPR Art. 6(1)(c)
Audit logs30 daysService security and management / GDPR Art. 6(1)(f)

Disposal Methods

4. Disclosure to Third Parties

The Service does not, in principle, provide users' personal information to external parties. However, information may be shared in the following exceptional circumstances.

External Services Used for Service Operation

ServiceProviderPurposeData Collected
Google AnalyticsGoogle LLCUsage statistics analysisCookies, access logs, usage patterns (de-identified)
Google AdSenseGoogle LLCWeb ad placementCookies, ad interaction data
Google AdMobGoogle LLCMobile app ad placementAdvertising identifier (GAID/IDFA), ad interaction data
OpenAI APIOpenAI Inc.AI travel plan generationTravel destination, dates (not personally identifiable)
OpenWeatherMapOpenWeather Ltd.Weather informationLocation information (city name)
Google OAuthGoogle LLCSocial loginEmail, name, profile (with consent)
Kakao OAuthKakao Corp.Social loginEmail, nickname, profile (with consent)
RevenueCatRevenueCat Inc.Subscription payment managementSubscription status, payment events (payment information is processed directly by app stores)
Google Maps APIGoogle LLCPlace searchSearch queries, session tokens
LocationIQLocationIQ GmbHGeocoding (place name to coordinates)Place search queries (not personally identifiable)
Google Timezone APIGoogle LLCTime zone informationLocation coordinates (not personally identifiable)
SentryFunctional Software Inc.Error monitoringError data, user context (de-identified)
PaddlePaddle.com Market LtdWeb payment processing (Merchant of Record)Email, payment information, subscription status (card information is processed directly by Paddle)
MapboxMapbox Inc.Place search (primary)Search queries, session information (not personally identifiable)
Expo (Push Notifications)Expo Inc.Push notification deliveryExpo push token, device information
Affiliate partnersBooking.com, Klook, etc.Affiliate service referralsClick events, IP address, User Agent

5. Cookie Policy

The Service uses cookies to provide a better user experience. Cookies are small text files stored in the user's browser by the website, and are used for functions such as maintaining login status and remembering service settings.

Types of Cookies Used

This Service allows third-party advertisers, including Google, to use cookies to serve ads based on previous visits. For information about Google's use of advertising cookies, please refer to Google's Advertising and Content Network Privacy Policy.

Users can refuse cookie storage through browser settings; however, this may limit the use of certain services such as login. For Google advertising cookies, you can disable personalized ads on the Google Ad Settings page.

6. User Rights

Users (or their legal representatives) may exercise the following rights at any time.

Rights can be exercised through the profile settings within the Service or by contacting the Data Protection Officer via email. Requests will be processed and results communicated within 10 days (or within one month for GDPR requests, with possible extension). However, information required to be retained by applicable laws may be preserved for the designated period despite deletion requests.

7. Security Measures

The Service implements the following technical and administrative security measures to safely protect users' personal information.

8. Data Protection Officer

The following Data Protection Officer has been designated to handle inquiries, complaints, and remedies related to personal information protection.

If you need to report or consult regarding a personal information breach, you may contact the following organizations.

For EU residents, you have the right to lodge a complaint with your local Data Protection Authority (DPA) under GDPR Art. 77.

9. International Data Transfers

Users' personal information may be transferred internationally as follows for the operation of the Service.

RecipientLocationTransferred DataPurpose
OpenAIUnited StatesTravel dataAI itinerary generation
GoogleUnited StatesAd ID, usage patternsAd delivery, place search
RevenueCatUnited StatesSubscription informationPayment processing
SentryUnited StatesError dataError monitoring
PaddleUnited KingdomEmail, payment informationWeb payment processing (Merchant of Record)
LocationIQGermanyPlace search queriesGeocoding
MapboxUnited StatesSearch queries, session informationPlace search
ExpoUnited StatesPush token, device informationPush notification delivery

Each service provider maintains appropriate personal information protection measures. Transfers are conducted with user consent in accordance with applicable laws. For transfers from the EU/EEA, the Service relies on Standard Contractual Clauses (SCCs) or adequacy decisions as appropriate under GDPR Art. 46.

10. Data Breach Notification

In the event of a personal information breach, the following matters will be notified to users without delay.

Notifications will be made via email, in-app announcements, or other appropriate methods. Where required by GDPR, the relevant supervisory authority will be notified within 72 hours of becoming aware of the breach (GDPR Art. 33).

11. California Residents (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

To exercise these rights, use the in-app data export or account deletion features, or contact us at [email protected].

12. App Tracking Transparency (ATT)

On iOS devices, in accordance with Apple's App Tracking Transparency (ATT) policy, the Service separately requests tracking permission for personalized advertising. Users may decline this request, and declining will not limit the use of the Service. Tracking permission can be changed at any time in Device Settings > Privacy & Security > Tracking.

13. Changes to This Privacy Policy

This Privacy Policy may be amended in accordance with changes in applicable laws, service policies, or security technologies. Any changes will be announced through in-service notices or email at least 7 days before the effective date. For significant changes, advance notice of 30 days will be provided.

14. Effective Date