Privacy and data protection
Privacy notice draft
NON-OPERATIVE DRAFT — Korean legal review and approval of the operating entity, regulatory scope, and detailed procedures are required.
This review draft transparently identifies data categories the current product may process and safeguards that still require verification. It is not a finalized privacy notice.
Information that may be processed
Account and order features may process email, payout or destination details, asset, network, amount, timestamps, order status, IP address, and security logs. If identity verification is required, identity data and images should be processed only after a separate notice and consent flow is approved.
Purposes
Information should be used only as needed for quotes and orders, security, customer support, fraud prevention, and legal obligations. Final terms must distinguish each purpose, legal basis, and mandatory or optional field.
Current protection status
Application-level protections cover payout details and customer email. Identity-image storage must not be treated as production-ready until storage encryption, access auditing, retention, and deletion have been verified.
Cookies and analytics
Necessary cookies may support sign-in and request security, and a referral cookie may remember a partner source. Optional analytics, if configured, must run only on public informational pages and must not receive order or authentication tokens or URL query strings.
Processors and international transfers
External processors may be required for payments, notifications, security, or compliance. Their identity, processing location, transfer basis, and safeguards must be documented after contracts and legal review are complete.
Retention and rights
Retention periods, deletion methods, access, correction, erasure and restriction procedures, and the privacy contact must be finalized after the operating entity and legal bases are verified.