Privacy Policy

MyTravel values and protects your personal information

MyTravel (hereinafter referred to as the "Service") protects the personal information of its users in accordance with the Personal Information Protection Act of Korea, the Act on Promotion of Information and Communications Network Utilization and Information Protection, the EU General Data Protection Regulation (GDPR), and other applicable laws and regulations. This Privacy Policy is established and disclosed to handle related grievances promptly and smoothly. This policy applies to all personal information collected through the use of the Service.

1. Personal Information We Collect

The Service collects the following personal information for membership registration, service provision, and customer inquiry handling.

Required Information

Collected ItemCollection PointPurpose
Email addressRegistrationAccount identification, login, notifications
Password (stored encrypted)RegistrationAccount authentication
Name (nickname)RegistrationDisplay within service, social features

Information Collected via Social Login

When using social login through Google, Apple, Kakao, or other providers, the following information is collected from the respective OAuth provider.

Unique identifiers (IDs) provided by OAuth providers are used solely for account linking and are not shared with third parties.

Information Automatically Collected During Service Use

2. Purpose of Personal Information Use

The collected personal information is used for the following purposes.

3. Retention and Disposal of Personal Information

Retention Period

Users' personal information is promptly destroyed once the purpose of collection and use has been achieved. However, where retention is required by applicable laws and regulations, such information is stored separately in a dedicated database for the specified period.

Retained ItemRetention PeriodLegal Basis
Account information (email, name)Until account deletionService agreement / GDPR Art. 6(1)(b)
Travel plan dataUntil account deletionService agreement / GDPR Art. 6(1)(b)
Access logs3 monthsKorean Telecommunications Privacy Act / GDPR Art. 6(1)(f)
E-commerce transaction records5 yearsKorean Consumer Protection in E-Commerce Act / GDPR Art. 6(1)(c)
Audit logs30 daysService security and management / GDPR Art. 6(1)(f)

Disposal Methods

4. Disclosure to Third Parties

The Service does not, in principle, provide users' personal information to external parties. However, information may be shared in the following exceptional circumstances.

External Services Used for Service Operation

ServiceProviderPurposeData Collected
Google AnalyticsGoogle LLCUsage statistics analysisCookies, access logs, usage patterns (de-identified)
Google AdSenseGoogle LLCAd placementCookies, ad interaction data
OpenAI APIOpenAI Inc.AI travel plan generationTravel destination, dates (not personally identifiable)
OpenWeatherMapOpenWeather Ltd.Weather informationLocation information (city name)
Google OAuthGoogle LLCSocial loginEmail, name, profile (with consent)
Kakao OAuthKakao Corp.Social loginEmail, nickname, profile (with consent)
RevenueCatRevenueCat Inc.Subscription payment managementSubscription status, payment events (payment information is processed directly by app stores)
Google Maps APIGoogle LLCPlace searchSearch queries, session tokens
LocationIQLocationIQ GmbHGeocoding (place name to coordinates)Place search queries (not personally identifiable)
SentryFunctional Software Inc.Error monitoringError data, user context (de-identified)
StripeStripe Inc.Web payment processingEmail, payment information, subscription status (card information is processed directly by Stripe)
Affiliate partnersBooking.com, Klook, etc.Affiliate service referralsClick events, IP address, User Agent

5. Cookie Policy

The Service uses cookies to provide a better user experience. Cookies are small text files stored in the user's browser by the website, and are used for functions such as maintaining login status and remembering service settings.

Types of Cookies Used

This Service allows third-party advertisers, including Google, to use cookies to serve ads based on previous visits. For information about Google's use of advertising cookies, please refer to Google's Advertising and Content Network Privacy Policy.

Users can refuse cookie storage through browser settings; however, this may limit the use of certain services such as login. For Google advertising cookies, you can disable personalized ads on the Google Ad Settings page.

6. User Rights

Users (or their legal representatives) may exercise the following rights at any time.

Rights can be exercised through the profile settings within the Service or by contacting the Data Protection Officer via email. Requests will be processed and results communicated within 10 days (or within one month for GDPR requests, with possible extension). However, information required to be retained by applicable laws may be preserved for the designated period despite deletion requests.

7. Security Measures

The Service implements the following technical and administrative security measures to safely protect users' personal information.

8. Data Protection Officer

The following Data Protection Officer has been designated to handle inquiries, complaints, and remedies related to personal information protection.

If you need to report or consult regarding a personal information breach, you may contact the following organizations.

For EU residents, you have the right to lodge a complaint with your local Data Protection Authority (DPA) under GDPR Art. 77.

9. International Data Transfers

Users' personal information may be transferred internationally as follows for the operation of the Service.

RecipientLocationTransferred DataPurpose
OpenAIUnited StatesTravel dataAI itinerary generation
GoogleUnited StatesAd ID, usage patternsAd delivery, place search
RevenueCatUnited StatesSubscription informationPayment processing
SentryUnited StatesError dataError monitoring
StripeUnited StatesEmail, payment informationWeb payment processing
LocationIQGermanyPlace search queriesGeocoding

Each service provider maintains appropriate personal information protection measures. Transfers are conducted with user consent in accordance with applicable laws. For transfers from the EU/EEA, the Service relies on Standard Contractual Clauses (SCCs) or adequacy decisions as appropriate under GDPR Art. 46.

10. Data Breach Notification

In the event of a personal information breach, the following matters will be notified to users without delay.

Notifications will be made via email, in-app announcements, or other appropriate methods. Where required by GDPR, the relevant supervisory authority will be notified within 72 hours of becoming aware of the breach (GDPR Art. 33).

11. Changes to This Privacy Policy

This Privacy Policy may be amended in accordance with changes in applicable laws, service policies, or security technologies. Any changes will be announced through in-service notices or email at least 7 days before the effective date. For significant changes, advance notice of 30 days will be provided.

12. Effective Date