Privacy Policy
Online mall operated by Yes 24 Corp. (hereinafter referred to as "YES24") considers private information of our users very important, and has the privacy policy as follows. Through the privacy policy, we inform you in what ways and for what purposes the personal information you provided is used as well as what measures are done to protect the personal information. This privacy policy may change depending on changes in the personal information protection laws or regulations, or changes in the company policy. Users should visit "YES24" frequently and check the privacy policy.
1. Purposes of Collection and Use of Personal Information
2. Agreement on Collection of Personal Information
3. Collected Personal Information Items and Collection Methods
4. Protection of Non-members' Personal Information
5. Use of Personal Information for Purposes Other Than Those Stated and Provision of Personal Information to Third Parties
6. Viewing and Revision of Personal Information and Withdrawal of Consent (Membership Withdrawal) to Collection of Personal Information
7. Periods of Retention and Use of Personal Information
8. Procedures and Methods of Personal Information Destruction
9. Use of Cookies
10. Technological/Managerial Measures for Personal Information Protection
11. Gathering Opinions and Handling Complaints
12. Personal Information Protection for Children
13. Chief Privacy Officer, etc.
14. Consignment of Personal Information Handling
15. Protection of Personal Location Information
16. Personal Information of Mobile Applications
17. Obligation of Notification
1. Purposes of Collection and Use of Personal Information
"Personal Information" is information on existent individuals that identifies the individuals using names and resident registration numbers included in the information and includes information that does not identify the individuals by itself but can be used to identify the individuals in combination with other information.
Collection of personal information is carried out to confirm users' intention to use "YES24" and provide the optimal services to the users. "YES24" is an Internet E-commerce company and collects personal information within a limited scope to provide E-commerce and various related services that fit users' characteristics and tastes and to solve problems that occur when using services of "YES24".
"YES24"'s purposes of collecting user information are as follows.
Category | Purpose of Use |
Member Management | Personal authentication and identification for use of membership services |
Preventing improper or unauthorized use of the services by delinquent members and preventing duplicate registrations | |
Confirming users' intent to register and limiting users' registration and frequency of registration | |
Confirming legal guardians' agreement when collecting personal information of children who are 13 years old or younger | |
Keeping records for customer counsel, complaint handling, and grievance mediation | |
Providing notifications | |
Fulfillment of agreement on service provision and settlement of payments | Providing transaction services for transactions among members |
Providing service contents, notifying prize winners, and shipping prizes | |
Providing financial services, including personal authentication for financial transactions | |
Item shipping, purchase and payment | |
Use in marketing and advertisement | Providing optimal services to users |
Developing and specializing new services and products | |
Providing services and posting advertisements based on demographic characteristics | |
Figuring out access frequency and analyzing service usage statistics | |
Delivering periodicals and providing information on new products or services | |
Designing web services and events tailored to customers' interests | |
Providing advertising information, such as sweepstakes and events, and operating a forum for members |
2. Agreement on Collection of Personal Information
"YES24" has a process in which you can agree or disagree to the 'terms and conditions of services' and 'privacy policy' during membership registration, and you cannot register as a member unless you agree to both of them.
3. Collected Personal Information Items and Collection Methods
(1) Personal Information Items Collected
First, "YES24" collects personal information as below for the purposes of order information inquiry, convenient customer counsel and provision of various services during membership registration or order placement by non-members.
① Members including children who are 13 years old or younger:
- Required information: Personal authentication information, personal authentication information of a legal guardian, name, ID, password, nickname, birth date, gender, address, home phone number, and email address
- Optional information: Mobile phone number, occupation, marital status, wedding anniversary, and whether you have children
② Corporate members:
- Required information: Business registration number, name of business, sector and type of business, name of CEO, ID, password, address of business, and phone number
- Optional information: Name, department, phone number, and email address of person in charge
③ Foreign members:
- Required information: Name, foreigner registration number, ID, password, nickname, gender, birth date, nationality, email address, address, and phone number
- Optional information: Mobile phone number, occupation, marital status, wedding anniversary, and whether you have children
④ Members residing overseas:
- Required information: Name, English name, ID, password, nickname, gender, birth date, nationality, address, email address, and phone number
- Optional information: Mobile phone number, occupation, marital status, wedding anniversary, and whether you have children
⑤ Non-member:
- Required information: Name, password, address, email address, and mobile phone number
- Optional information: Phone number
Second, information such as shown below may be generated and collected automatically in the process of using services and handling businesses.
- IP address, cookie, date of visit, type of OS, type of browser, record of service usage, and record of improper usage
Third, when you use additional services or customized services or apply for events, we collect information such as shown below exclusively from users of the given services in so far as we obtain your consent for additional collection of personal information.
- Address for shipping items such as prizes, name of recipient, phone number, mobile phone number, email address, etc.
Fourth, when you use paid services, information such as shown below may be collected.
- In case of credit card payment: Name of credit card company, credit card number, etc.
- In case of mobile payment: Mobile phone number, telecommunications carrier, payment authorization number, email address, etc.
- In case of wire transfer: Name of bank, account number, etc.
- In case of using gift certificates: Certificate number
- In case of refund: Refund account information (name of bank, account number, and name of account holder)
Fifth, information that may infringe on users' basic human rights, such as ethnicity, race, ideology, belief, hometown, birth place, political stance, criminal record, health condition and sex life, is not collected unless agreed by users or specified by the law.
(2) Methods of Personal Information Collection
"YES24" collects personal information through its websites (member registration, order placement by non-member, and 1-on-1 customer counsel), phone calls, faxes, emails, user input during event participation, provision of information by partners and information collection tools.
4. Protection of Non-members' Personal Information
(1) In case of non-member orders, "YES24" only requests personal information that is required for shipping, payment, order detail inquiry, purchase confirmation and confirmation of legal names. In this case, the information is only used for the purposes related to payment and item shipping.
(2) Purposes of collection and use of non-members' personal information and items collected
① Name
② Smooth purchase/sales, confirmation of purchase intent, handling of complaints and conflicts, notification and provision of information, etc.: Phone number, mobile phone number, and email address
③ Provision of payment services, etc.: Bank account information and credit card information
④ Shipping products and prizes: Address, phone number, and email address
⑤ Prevention of improper service use, and storage of electronic financial transaction records: IP address and date of visit
(3) In case of using non-member services, every detail of "YES24"'s privacy policy applies except for the details of member services.
(4) "YES24" protects personal information of non-members as thoroughly as we do with the information of members.
5. Use of Personal Information for Purposes Other Than Those Stated and Provision of Personal Information to Third Parties
(1) "YES24" does not use the personal information of its users, other than the information disclosed through the Internet services screens, for purposes other than required to provide its Internet services, nor it provides personal information to third parties without its users' consent, except for the following cases.
① In the case that we obtained users prior consent
②In the cases specified by the relevant laws such as Act on Real Name Financial Transactions and Confidentiality, Act on the Use and Protection of Credit Information, Framework Act on Telecommunications, Telecommunications Business Act, Local Tax Act, Consumer Protection Act, Bank of Korea Act, Criminal Procedure Act, etc.
③ In the case that the information is required for payment settlement for services provided
④ In the case that the information is needed for statistics, academic research or market research and is provided in forms that do not identify the relevant individuals
(2) "YES24" may provide or share personal information with its partners to provide better services to its users. When providing or sharing personal information, we undergo the process of individually obtaining agreement from our users in advance by notifying the users who the partners are, what information is shared or provided, why such information must be provided or shared, how long such information is kept and how it is protected. In the case that users do not agree to the provision or sharing of personal information, we do not provide or share the information to or with partners. Also, users may withdraw the agreement at any times, even if they agree to provision of their personal information.
Category | Beneficiary of personal information | Purpose of personal information use | Personal information provided | Period of retention and use |
Book | Reseller | Shipping ordered products, providing customer counsel, and handling complaints | Name, address, and contact information | Until the purpose of personal information use is fulfilled (until the relevant period when the information must be retained based on the relevant laws and regulations or when prior consent is obtained) |
Gift, CD/LP, and DVD/Blu-ray | Reseller | |||
Second-hand store | Reseller | |||
Movie | Reseller | |||
Concerts and shows | Reseller |
(3) When using services of "YES24" without registering for the membership, payer information and recipient information that you provide are not used for purposes other than those related to payment and shipment of items.
(4) When providing personal information to family sites such as fashion malls, we obtain agreement in advance on the beneficiary of personal information, purpose of collection and use of personal information, personal information provided and period of retention and use of personal information. Additionally, in case you want to withdraw the agreement on provision of personal information, you may do so for yourself by changing your personal information on the website. However, your use of services may be restricted when you withdraw your agreement.
① Beneficiary of personal information: iSTYLE 24
② Beneficiary's purposes of personal information use: Shipping ordered products, providing customer counsel, and handling complaints
③ Personal information provided: Name, address, and contact information
④ Period of retention and use of personal information: Until the purposes of personal information use are fulfilled
6. Viewing and Revision of Personal Information and Withdrawal of Consent (Membership Withdrawal) to Collection of Personal Information
(1) If a user views/changes his/her personal information at "My Page > Personal Information > Manage Account Information" after logging on to YES24 or contacts the chief privacy officer via letter, phone call or email regarding his/her personal information, we will take immediate measures. However, a user cannot change his/her user ID. Changing his/her name is possible after personal authentication only when he/she was rechristened.
(2) A user may withdraw his/her agreement on collection and use of the personal information at any times. A user can withdraw his/her agreement for himself or herself by logging on to the "YES24" website and navigating to "My Page > Personal Information > Withdraw Membership." Or a user may send a request to the chief privacy officer of "YES24" via email or letter and the chief privacy officer will take immediate actions according to the request and, for example, will destroy his/her personal information.
7. Periods of Retention and Use of Personal Information
In case that "YES24" collects and retains personal information of its users, the retention period starts when the user registers for the membership and ends when the membership terminates, including when the user requests for membership withdrawal or when "YES24" terminates the membership of the user. Also, in the event of membership withdrawal, "YES24" will destroy the collected personal information so that it cannot be viewed or used. If the personal information was provided to third parties, we will instruct the third parties to destroy the personal information. Additionally, we will destroy the personal information when the purposes of personal information collection or receipt are fulfilled.
(1) Payment information is retained until the payment is completed or until the extinctive prescription of the debt is completed.
(2) Shipping information is retained until the products or services are delivered or provided.
(3) However, based on the internal regulations of "YES24" and related laws such as Act on the Consumer Protection in Electronic Commerce, etc., Electronic Financial Transaction Act, Specialized Credit Finance Business Act, Framework Act on National Taxes, Corporate Tax Act and Value-Added Tax Act, personal information pertaining to the information that identifies the subjects of transactions such as names and addresses and the information required to confirm the relationship of rights and duties regarding transactions may be retained even when the agreement on service use is withdrawn. Accordingly, the following transaction records are retained.
① Records on display or advertisements
- Grounds for retention: Act on the Consumer Protection in Electronic Commerce, etc.
- Period of retention: 6 months
② Records on contracts or withdrawal of contracts
- Grounds for retention: Act on the Consumer Protection in Electronic Commerce, etc.
- Period of retention: 5 years
③ Records on payment or supply of goods
- Grounds for retention: Act on the Consumer Protection in Electronic Commerce, etc.
- Period of retention: 5 years
④ Records on consumer complaints or disputes
- Grounds for retention: Act on the Consumer Protection in Electronic Commerce, etc.
- Period of retention: 3 years
Users' personal information is transferred to a separate database after the membership is terminated or the purposes of information use are fulfilled. Then the personal information is retained for a certain period for the ground of information protection based on internal policies of "YES24" and related laws before the information is permanently deleted in a technically irreversible manner. Personal information that was transferred to a separate database is not used for purposes other than retention, unless specified otherwise by law.
8. Procedures and Methods of Personal Information Destruction
In principle, YES24 destroys personal information after the purposes of collection and use of the information are fulfilled, according to the periods of retention and use. Procedures, methods, and time of personal information destruction are as follows:
(1) Procedures of destruction
① The information that users provided for membership registration is transferred to a separate database (separate boxes for paper documents) after fulfillment of its purposes, and destroyed after a certain period of retention based on internal policies of "YES24" and related laws (refer to 7. Periods of Retention and Use of Personal Information).
② Personal information that was transferred to a separate database is not used for purposes other than retention, unless specified otherwise by law.
(2) Destruction procedure
① Personal information that is stored in an electronic format is deleted in a technically irreversible manner.
② Personal information that is printed on paper is destroyed by shredding or with fire.
(3) Destruction procedure for personal information of inactive accounts
① When users have not used the services for 1 year or longer after registration, "YES24" may terminate their memberships and destroy their personal information based on the Article 29. Destruction of Personal Information.
② The company must notify the users of inactive accounts of the following information no later than 30 days prior to the termination of their accounts. The details of notifications are as follows:
- The fact that their personal information will be destroyed or stored separately.
- Date of destruction
- Personal information items to be destroyed
③ The notifications can be done via email, phone or fax.
④ In the following cases, personal information may be retained even after the accounts have been inactive for 1 year or longer.
- When the user and telecommunications service provider agreed on the period of retention through a separate contract
9. Use of Cookies
"YES24" uses cookies that regularly search and store the user information. Cookies are small text strings that are transmitted by the website server to the browsers (Internet Explorer, Safari, Firefox, etc.) in users' computers. Cookies identify users' computers, but do not identify users individually.
(1) Operation of cookies
① Used to provide customized information based on individual's interests.
② Used to identify users' interests and preferences and perform targeted marketing by analyzing the frequency and time of member or non-member accesses.
③ Used to provide tailor-made services next time the user logs on by tracking the web-browsing history.
④ Used to analyze users' habits and utilize them to improve services.
(2) Options for cookies
Users may accept all cookies, turn on the notification function to be notified whenever cookies are installed, or reject all cookies by adjusting their web browsers. However, if they reject cookies, they may not be able to use some services that require logging on to "YES24".
Ways to opt in or out for cookie installation are as follows (for Internet Explorer):
① Select [Internet Options] in the [Tool] menu.
② Click the [Privacy] tab.
③ Select your option among "Accept All Cookies - Low - Medium - Medium High- High - Block All Cookies" in [Privacy Settings].
Cookies expire when you log out or exit the browser.
10. Technological/Managerial Measures for Personal Information Protection
(1) "YES24" provides the following technical measures in order to secure the safety by preventing personal information from being lost, stolen, leaked, modified or damaged while handling users' personal information.
① Users' personal information is protected through passwords and encryption. However, thorough protection of users' passwords and personal information is critical as they are very likely to be exposed to others in various ways, for example, when using the Internet in public spaces. Thus, users should not expose or provide personal information to others and should manage their own personal information responsibly. "YES24" does not take responsibilities for problems stemming from personal mistakes committed by users or fundamental dangers of the Internet.
② Users' personal information is protected by passwords and encryption by default, and important data are protected by additional measures such as encryption of files and transmitted data.
③ "YES24" has taken measures against computer viruses by using vaccine programs, and the vaccine programs are updated regularly. The up-to-date vaccine programs prevent a virus from infecting the system by providing the cure for the virus and preventing infringement of personal information.
④ "YES24" transmits personal information on a network using safe encryption algorithms.
⑤ To prevent personal information from being leaked or damaged by hacking or viruses, "YES24" monitors and manages the network 24/7 by adopting the systems that detect or block external infiltrations. The infiltration detection system and infiltration blocking system have redundant configurations to prepare for any emergencies.
(2) "YES24" is aware of the importance of protecting personal information, limits the number of employees who handle personal information to a minimum, and does its utmost to protect personal information by regularly holding training sessions for employees who handle personal information under the supervision of the chief privacy officer. In addition, we regularly inspect the employees' compliance with this policy, removing problems and taking necessary measures if any violations of the policy are observed.
11. Gathering Opinions and Handling Complaints
"YES24" operates a customer service center so that users can suggest opinions and file complaints regarding privacy protection.
In case that users need a consultation on infringement of personal information when any related disputes occur between them and "YES24", they may contact the Personal Information Infringement Report Center under Korea Internet & Security Agency or the Cyber Security Division under Korean National Police Agency.
Organization | Website Address | Phone Number |
Personal Information Infringement Report Center | http://www.privacy.kisa.or.kr | 118 |
High-tech Crime Division, The Supreme Prosecutors' Office | http://www.spo.go.kr | 02-3480-2000 |
Cyber Security Division, National Police Agency | http://www.ctrc.go.kr | 182 |
12. Personal Information Protection for Children
(1) For children who are 13 years old or younger to register for "YES24", they must obtain their legal guardian's agreement.
Thus the registration for "YES24" membership is completed only after personal authentication of a legal guardian.
Personal information provided by the legal guardian is only used for confirming their agreement.
(2) "YES24" shall immediately take necessary measures if a legal guardian requests viewing, revision or deletion of the information collected from their children who are 13 years old or younger.
(3) If a legal guardian wants to view, revise or delete personal information of their children, they may contact the Personal Information Complaint Team. The necessary measures will be taken immediately after confirming your status as a legal guardian.
13. Chief Privacy Officer, etc.
(1) "YES24" does its utmost to protect valuable personal information of its users by designating a chief privacy officer and a department responsible for privacy protection.
Users may inquire or raise suggestions or complaints about personal information via the contact information or email address shown below. We will respond to your inquiry promptly and sincerely.
Chief Privacy Officer | |
Name | Gwang-il Han |
Department | IT Service Department |
Position | CTO |
Phone Number | 1544-3800 |
Email Address | privacy@yes24.com |
Personal Information Complaint Team | |
Department | Customer Service Center |
Phone Number | 1544-3800 |
Email Address | privacy@yes24.com |
14. Consignment of Personal Information Handling
"YES24" consigns personal information handling to external agencies to a minimum extent to provide stable and convenient services. The period of retention and use of personal information ends when the membership is withdrawn or the consignment contract is terminated. We have established the matters required to safely manage personal information in the event of the consignment.
▶ Consignees, purposes of consignment, and services that consignees provide
Consignees to which "YES24" consigned the personal information handling
Consignee | Purpose of consignment |
Woorienyu | Customer counsel |
K-Tec Manpower | |
Gargantuan | |
Will & Vision | |
Careerise | |
Telcoin | Sending SMS messages regarding Giftishow for event prizes |
CJ Logistics | General shipping |
GTX (PK2 Global) | Same-day shipping |
Post office | General shipping (for P.O. boxes) |
CVSnet Inc. | Convenience store shipping |
EMS (post office) | Overseas shipping |
DHL | |
Kookje Corp. | Ticket shipping |
Mobilians | Mobile T money and mobile payment |
Inicis | Credit card payment, bank transfer, and simple payment |
NHN KCP Corp. | Credit card payment (Lotte card) |
NICE Information Service | Personal authentication and I-Pin authentication |
Korea Mobile Certification | Personal authentication for service use |
LG U+ | Sending SMS messages |
15. Protection of Personal Location Information
(1) "YES24" may collect and use location information to provide location-based services.
(2) Collection, use, and provision of location-based information are not performed for purposes other than those listed in (1). Information that does not have the grounds for its retention is destroyed after the purposes of its use are fulfilled.
(3) "YES24"'s responsibilities and users' rights regarding the protection of location-based personal information conform to the ’Act on the Protection, Use, Etc. of Location Information' and related laws.
16. Personal Information of Mobile Applications
(1) "YES24" may generate, collect, use, and store the following information to provide the mobile application services.
(2) When users use the services through a mobile app for smartphones, etc., "YES24" shall obtain their agreement on the collection and use of their personal information and carry out such actions within the obtained agreement.
- Login data for the mobile device
- Location-based information
- Mobile device ID, model, OS, and type of browser
- Photos, media, files, etc.
- Other information of which "YES24" obtained users' agreement on collection.
Users may access and change their user settings at any time, and can delete their usage history in the Settings menu under Device Options. However, users' member accounts are not deleted even if they delete the app in their devices. So, if they don't want to use the services anymore, they should withdraw their membership in the "YES24" website.
17. Obligation of Notification
The current privacy policy was established on Nov. 29, 2002. When there are additions, deletions, or modifications to the policy due to changes in the policy of "YES24" or the government regulations, such changes shall be immediately notified on the "YES24" website. The policy shall become effective on the day of notification.
Privacy policy version: V 5.3
Notification of changes in privacy policy: Apr. 01, 2017
The privacy policy becomes effective on: Apr. 10, 2017