Privacy Policy
Article 1. Purpose
1.1. This Privacy Policy outlines how Lighters Company Co., Ltd (hereinafter the "Company") manages, protects, and uses personal information collected from members using the Kooky service (hereinafter the "Service").
1.2. The Company complies with applicable laws, including the Act on Promotion of Information and Communication Network Utilization and Information Protection.
1.3. This policy clearly states how personal information is used, processed, and protected.
1.4. This policy is always accessible on the Service interface.
Article 2. Items and Methods of Collecting Personal Information
2.1. Personal Information Collected
Users automatically consent to personal information collection upon registration. Optional information will be collected only if users voluntarily provide it.
Users automatically consent to personal information collection upon registration. Optional information will be collected only if users voluntarily provide it.
- Required Items: Email account, password (encrypted), email verification code (temporarily stored), mobile phone number and phone verification code (temporarily stored), date of birth, authentication status, profile name, service version, OS and OS version, device model name, terminal unique ID, language, Time Zone.
- Optional Items: Purchase history, country/region, gender, name, phone numbers in address book, profile picture (including metadata), status messages, purchased items/products, location data.
2.2. Methods of Collection
- (a) Membership registration, inquiries, event applications, and delivery requests.
- (b) Automatic collection during service usage (usage records, logs, IP addresses, payment records, and cookies).
2.3. Location Data
- Precise location data is accessed temporarily (not stored) when using the "Kooky Map" feature.
Article 3. Purpose of Collection and Use of Personal Information
The company uses collected personal information for:
3.1. Providing service and content delivery.
3.2. Member management:
- Prevention of unauthorized usage, confirming duplicate registrations, handling complaints, notifications, and dispute resolution.
- Mobile phone number: verifying that a person controls the number at sign-up, so that one number corresponds to one account. This is used to prevent duplicate accounts and the abuse of sign-up rewards, votes, and events. The number is not used to send marketing messages.
- No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. Message frequency: 1 msg per verification request. Msg & data rates may apply. Reply STOP to opt out or HELP for help.
- Date of birth: determining the member's age so that we can meet our obligations toward children, and applying any age-based restrictions required by law.
3.3. Marketing and analytics:
- New service development, customized service recommendations, statistical analysis, marketing information, and participation opportunities.
- This does not include mobile information or text messaging consent. Numbers collected for SMS verification and the consent given for it are used only for the verification purpose described in 3.2, and are excluded from every marketing, promotional, and third-party sharing category in this policy.
Article 4. Sharing and Provision of Collected Personal Information
4.1. The company uses members' personal information strictly within the scope stated in Article 3 and does not disclose it externally without prior consent, except in the following cases:
- (a) With users' explicit prior consent.
- (b) Upon lawful request by judicial or investigative authorities under applicable laws. In such cases, the company strictly follows legal procedures, providing only minimal required data.
4.2. Personal information may be shared with third parties only when members explicitly consent. In such cases, the information is held only for the duration consented to or as required by applicable law, after which it is destroyed immediately.
- Customer registration/management: Until membership termination.
- Consumer complaint/dispute records: 3 years. Payment/supply
- transaction records: 5 years.
- Advertisement records: 6 months.
- User access logs: 1 year.
Article 5. Consignment of Personal Information
5.1. Outsourced Data Handling
To improve service efficiency, the company entrusts personal information processing to specialized external companies. To ensure safe management, contracts strictly stipulate confidentiality obligations, prohibition of third-party use, and accident liability.
To improve service efficiency, the company entrusts personal information processing to specialized external companies. To ensure safe management, contracts strictly stipulate confidentiality obligations, prohibition of third-party use, and accident liability.
5.2. Entrusted Companies and Processing Details
- Amazon Web Services: Cloud server management (no direct access to personal data).
- Google Analytics: Usage analysis (no personally identifiable information collected).
- Twilio: Sending and checking the one-time code used to verify a mobile phone number at sign-up. Twilio is provided with the phone number being verified and a pseudonymised identifier of the requesting connection; it is not provided with your account, name, or email address.
- PostHog: Usage analysis, error tracking, and session replay of the purchase and payment flows. Session replay records on-screen activity such as clicks, scrolling, and page transitions. Text entered into input fields is masked and is not collected, and payment card details are entered inside the payment providers' own frames and are never captured. PostHog is provided with your account identifier and standard access data (IP address, device and browser information), but is not provided with your name or email address.
5.3. Delegation of Payment Processing
The company entrusts payment processing to external payment processors as follows and does not directly store or handle sensitive payment information (e.g., card numbers, CVV):
The company entrusts payment processing to external payment processors as follows and does not directly store or handle sensitive payment information (e.g., card numbers, CVV):
- Mobile Payments (App Store, Google Play Store): Only payment receipt IDs and purchase details provided by platforms are stored for delivering paid assets (Loovy). Sensitive payment information (e.g., credit card details) is processed in accordance with Apple's and Google's payment policies and is not collected or stored by the company.
- Website Payments (Stripe, Tosspayments): Payments for Loovy, digital goods, tickets, merchandise, etc., are processed by Stripe and Tosspayments. PayPal payments made on the website are also processed through Tosspayments. The company stores only payment receipt IDs and purchase details. Sensitive payment information (credit card numbers, CVVs) is entered directly into the payment interfaces provided by these processors and is securely handled according to the policies of Stripe (https://stripe.com/privacy) and Tosspayments (https://pages.tosspayments.com/terms/homepage/privacy/policy/) and is not stored by the company.
5.4. Payment Protection and Liability
- The company is not liable for issues outside of its control (e.g., payment gateway downtime, delays, or failures).
- Users must report payment issues via hello@kooky.io. The company will respond within one business day (max 48 hours); requests received on weekends/holidays are processed on the next business day.
5.5. Overseas Transfer of Personal Information
In connection with the entrusted processing described above, the company transfers personal information to processors located outside the Republic of Korea as follows. Transfers are made over the network at the time the relevant data is generated during service use.
Payments processed by Tosspayments are handled within the Republic of Korea and do not involve an overseas transfer. Payments made through the App Store or Google Play Store are governed by Apple's and Google's own policies as described in 5.3.
In connection with the entrusted processing described above, the company transfers personal information to processors located outside the Republic of Korea as follows. Transfers are made over the network at the time the relevant data is generated during service use.
- Amazon Web Services, Inc. (United States) — Items transferred: service data stored on cloud servers. Purpose: operation and maintenance of cloud infrastructure, including backups and technical support. Primary storage region: Seoul, Republic of Korea. Retention: for the periods stated in Article 6. Contact: https://aws.amazon.com/privacy/
- PostHog Inc. (United States; 2261 Market Street #4008, San Francisco, CA 94114; privacy@posthog.com) — Items transferred: account identifier, access data (IP address, device and browser information), service usage records, and session replay of purchase and payment screens excluding the contents of input fields. Purpose: usage analysis, error tracking, and diagnosis of payment failures. Retention: until the end of the processing agreement or the expiry of the retention period configured in PostHog, whichever comes first.
- Stripe, Inc. (United States) — Items transferred: information required to process payments. Purpose: payment processing. Retention: as stated in Stripe's privacy policy (https://stripe.com/privacy).
- Twilio Inc. (United States; 101 Spear Street, San Francisco, CA 94105; privacy@twilio.com) — Items transferred: the mobile phone number being verified and a pseudonymised identifier of the requesting connection. Purpose: sending and checking the one-time verification code, and blocking abusive sending patterns. Retention: as stated in Twilio's privacy notice (https://www.twilio.com/en-us/legal/privacy). Your account, name, and email address are not transferred.
- Google LLC (United States) — Items transferred: access data and service usage records collected through Google Analytics. Purpose: usage analysis. Retention: as stated in Google's privacy policy (https://policies.google.com/privacy).
Payments processed by Tosspayments are handled within the Republic of Korea and do not involve an overseas transfer. Payments made through the App Store or Google Play Store are governed by Apple's and Google's own policies as described in 5.3.
5.6. Refusing an Overseas Transfer
The overseas transfers described in 5.5 are required to operate the Service, including cloud infrastructure and payment processing. If you refuse these transfers, the Service cannot be provided. You may exercise your refusal by withdrawing your membership through the service interface, or by requesting withdrawal through customer service at hello@kooky.io.
Separately from the above, you may block analytics cookies through your browser settings as described in 10.3 and 10.4.
The overseas transfers described in 5.5 are required to operate the Service, including cloud infrastructure and payment processing. If you refuse these transfers, the Service cannot be provided. You may exercise your refusal by withdrawing your membership through the service interface, or by requesting withdrawal through customer service at hello@kooky.io.
Separately from the above, you may block analytics cookies through your browser settings as described in 10.3 and 10.4.
Article 6. Retention and Use Period of Personal Information
6.1. Users must personally request account deletion through the service interface. Email-based requests without verification cannot be processed.
6.2. Upon account deletion, personal information is permanently deleted, except as specified below:
- Fraudulent activity records: stored for 1 year.
- Email addresses: stored for 1 year after deletion.
- Device IDs: encrypted, stored for 6 months (to prevent duplicate registrations).
- Mobile phone numbers: on deletion, the number itself is erased. What remains is a one-way cryptographic value derived from it, which is retained indefinitely. That value cannot be turned back into your number and cannot be used to contact you; it only lets us recognise that the number has already been used for an account. We keep it because sign-up rewards, votes, and events would otherwise be open to repeated deletion and re-registration from the same number. If you need a number released so that it can be registered again, contact us at hello@kooky.io.
6.3. Additional legally mandated retention periods:
- Contracts/payment records: 5 years.
- Consumer complaints/disputes: 3 years.
- Advertising records: 6 months.
- Transaction and financial records: 5 years.
- Service visit logs: 3 months.
6.4. Children:
- The company collects each member's date of birth at sign-up and therefore knows the member's age. This information is used to meet the company's obligations toward children and to apply age-based restrictions required by law.
- Where the law of the member's country requires the consent or authorisation of a parent or legal guardian for a child of that age to use the service, the company will not create or continue the account until that consent or authorisation has been obtained, and may suspend the account in the meantime.
- A parent or legal guardian may contact hello@kooky.io to ask about, or request the deletion of, the personal information of a child in their care.
Article 7. Procedures and Methods for Destroying Personal Information
7.1. Personal information is promptly destroyed once retention periods expire or the purpose is fulfilled.
7.2. Destruction procedure:
- Data used for registration is destroyed immediately after fulfilling the purpose.
7.3. Destruction methods:
- Printed data: shredded or incinerated.
- Electronic data: irrecoverably deleted.
Article 8. Members' Rights and Their Exercise
8.1. Right to Access, Modify, and Delete Personal Information
- Members (or their legal representatives) may request access, modification, or deletion of their personal information.
- Requests for deletion of personal information can be made directly via the "Profile/My Profile" menu within the Service.
- If a request is made via email, additional identity verification may be required.
8.2. Account Deletion and Restriction Measures
- The Company may restrict, suspend, or delete accounts that violate applicable laws or the Company's operational policies.
- Deleted accounts cannot be recovered, and the deleted information will not be used for other purposes.
8.3. Correction of Personal Information and Notification to Third Parties
- If a member requests a correction of their personal information, and if such information has been shared with third parties, the Company will notify those third parties and make corrections where applicable.
8.4. Exercising Rights Through an Authorized Representative
- If a member is unable to exercise their rights personally, they may authorize a legal representative or agent to act on their behalf.
- To process such requests, the Company requires official documentation, such as a power of attorney and identity verification documents.
Article 9. Technical and Managerial Measures for Personal Information Protection
9.1. Technical measures:
Data backups, antivirus software, encrypted communications, firewalls, intrusion prevention.
Data backups, antivirus software, encrypted communications, firewalls, intrusion prevention.
9.2. Managerial measures:
Limited staff access, regular privacy training, and a designated Personal Information Protection Officer (CEO).
Limited staff access, regular privacy training, and a designated Personal Information Protection Officer (CEO).
Article 10. Use of Cookies and User Options
10.1. The company uses cookies (small text files sent to and stored in user devices) to provide faster and more personalized services.
10.2. Purpose of cookies:
- Strictly Necessary Cookies: Essential for login and secure services. Blocking these may restrict service access.
- Functional Cookies: Store user preferences for personalized user experience.
- Analytics Cookies: Used via Google Analytics and PostHog to analyze service use and to diagnose errors in the purchase and payment flows. Google Analytics collects no personally identifiable information (PII). PostHog links analytics events and session replay data to your account identifier; the contents of input fields, your name, and your email address are not collected. You may block these analytics cookies through your browser settings as described in 10.3 and 10.4.
10.3. User rights concerning cookies:
- Users can refuse cookie storage through browser settings. Blocking necessary cookies may limit service functionality.
10.4. Cookie settings (by browser):
- Chrome: [Settings] → [Privacy and Security] → [Site Settings] → [Cookies and Site Data]
- Safari: [Preferences] → [Privacy]
- Microsoft Edge: [Settings] → [Site Permissions] → [Cookies and Site Data]
Article 11. Linked Websites
The company may provide links to external websites or content. Such sites are not governed by this Privacy Policy, and users should review privacy policies of those websites separately.
Article 12. Personal Information Protection Officer
The company appoints a Personal Information Protection Officer to handle inquiries and complaints about privacy matters.
- Officer: Hami Kim, CEO
- Email: hami@kooky.io
- Customer Service Team: hello@kooky.io
12.1. Working Hours
- Weekdays: 10:00 AM – 7:00 PM (Lunch: 12:30 PM – 1:30 PM)
- Closed: Weekends and public holidays
12.2. Other reporting agencies for privacy infringements:
- Personal Information Infringement Report Center (privacy.kisa.or.kr, Tel: 118)
- Cyber Investigation Division, Supreme Prosecutors' Office (www.spo.go.kr, Tel: +82-2-3480-2000)
- National Police Agency Cyber Safety Bureau (www.cyber.go.kr, Tel: 182)
Article 13. Amendments to Privacy Policy
13.1. When amending this policy, the company will announce the changes via service notices or app push notifications.
- Significant amendments affecting user rights: Notified at least 7 days in advance.
- Critical amendments: Notified at least 30 days in advance.
- Minor or new-user-only amendments: Effective immediately without prior notice.
13.2. Users not objecting by the effective date are deemed to consent.
13.3. Additional data collection or third-party sharing will require separate explicit consent.
13.4. Effective date and amendment history
- Effective date: October 20, 2020
- Amendments:
- May 20, 2023: Added Loovy and Stripe/Xendit payment details
- October 15, 2024: Added precise location feature
- March 14, 2025: Added email verification-related policies
- September 7, 2026: Added mobile phone verification (SMS) and date of birth policies
