SHAASHOP
About Terms of Service Payment Terms Privacy Policy Refund Policy

Privacy Policy

<Shaashop Co., Ltd.> (hereinafter the "Company") establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

The "Company" discloses this Privacy Policy through the initial screen of its website so that it may be viewed at any time. It may be amended in accordance with personal information-related statutes, guidelines, or public notices, or in accordance with the service policies of the "Company," and in the event of an amendment, the Company will give notice thereof through the notices section of the website (or through individual notice).

This Privacy Policy describes the Company's policies and procedures on the collection, use and disclosure of the customer's information when the customer uses the Service, and informs the customer of the customer's privacy rights and of how the law protects you.

The Company uses the customer's personal data to provide and improve the Service. By using the Service, the customer consents to the collection and use of information in accordance with this Privacy Policy.

Article 1 (Purpose of Processing Personal Information)

(1) The "Company" processes personal information for the following purposes, and does not use it for any purpose other than the following.

  1. Confirmation of the customer's intent to register
  2. Identification and authentication of the individual in connection with the provision of services to the customer
  3. Where contact with the customer is necessary within a reasonable scope, such as for the maintenance and management of membership status, updates, and push notifications
  4. Payment of amounts and purchase contracts in connection with the supply of goods or services
  5. Supply and delivery of goods or services, and the development, observance and performance of other contracts concluded
  6. Grievance handling, mediation services and customer support services for the resolution of customer inquiries, and monitoring of service use

(2) In the event that the scope of the information collected or the purpose or use thereof is changed, prior consent shall be obtained from the "Member."

Article 2 (Processing and Retention Period of Personal Information)

(1) The "Company" processes and retains personal information within the period for retaining and using personal information consented to when the personal information was collected from the data subject, or within the period for retaining and using personal information under the relevant statutes. The processing and retention period for each category of personal information is as follows.

  1. Registration for and management of membership of the "SHAASHOP" service: until withdrawal from the service

    [Upon Membership Registration]

    • Upon general email membership registration: date of birth, gender information, pen name, mobile phone number, password, service use records (date and time of visit, IP, records of improper use, etc.), device information (device type, OS version), email
    • Upon registration via SNS (KakaoTalk, Naver, Facebook, Google): login information identification value, SNS profile photo, pen name, mobile phone number, email, gender, service use records (date and time of visit, IP, records of improper use, etc.), device information (device type, OS version)
    • Upon registration via Apple: Apple ID, pen name, service use records (date and time of visit, IP, records of improper use, etc.), device information (device type, OS version)

    However, in cases falling under any of the following grounds, until the termination of the relevant ground:

    1. Where an investigation or inquiry, etc. is in progress due to a violation of the relevant statutes: until the completion of such investigation or inquiry
    2. Where a claim or debt relationship arising from the use of the website remains: until such claim or debt relationship is settled
  2. Provision of goods or services: until the completion of the supply of the goods/services and the completion of the payment and settlement of charges

    However, in cases falling under any of the following grounds, until the expiration of the relevant period:

    1. Records concerning transactions, such as labeling/advertising and the contents and performance of contracts, under the "Act on the Consumer Protection in Electronic Commerce, etc."
      • Records concerning labeling and advertising: 6 months
      • Records concerning contracts or withdrawal of subscription, payment of price, and the supply of goods, etc.: 5 years
      • Records concerning consumer complaints or dispute resolution: 3 years
    2. Retention of communication confirmation data pursuant to Article 41 of the "Protection of Communications Secrets Act"
      • Date and time of a subscriber's telecommunications, start and end times, the other party's subscriber number, frequency of use, and location tracking data of the transmitting base station: 1 year
      • Computer communications, internet log records, and access location tracking data: 1 year
    3. Retention of identity verification information pursuant to Article 29 of the Enforcement Decree of the "Act on Promotion of Information and Communications Network Utilization and Information Protection": 6 months after the posting of the information on the bulletin board has ended

Article 3 (Provision of Personal Information to Third Parties)

(1) The "Company" processes the personal information of data subjects only within the scope specified in Article 1 (Purpose of Processing Personal Information), and provides personal information to third parties only where the case falls under Article 17 or Article 18 of the Personal Information Protection Act, such as with the consent of the data subject or under special provisions of law.

(2) The "Company" entrusts the following business operations in connection with the processing of personal information, and takes the measures necessary to ensure that personal information can be safely managed when concluding entrustment contracts in accordance with the relevant statutes. In addition, the information processed under entrustment is limited to the minimum information necessary to provide the "Service" smoothly.

  • Retention and use period of personal information: upon withdrawal of membership or upon termination of the entrustment contract
  • Entrusted companies
    Danal Co., Ltd., NICE Payments Co., Ltd.
  • Purpose of entrustment: processing related to payment/refund through account transfer, card payment, etc.

(3) In order to provide convenience in configuring the customer's usage environment, the "Company" sends notifications and news regarding various service use situations, events and benefits through means of contact such as the user's email address and telephone number (mobile phone number). Notifications relating to the use of essential services are not subject to optional consent, and with respect to event and advertising notifications, users who do not give such optional consent may choose not to use this Service.

(4) The "Company" uses "Firebase/Google Analytics," a mobile application analytics service provided by Google INC. ("Google"), in order to improve service quality.

For this purpose, users' usage behavior in the service application, log information, cookies and the like are transmitted to "Google's" servers. "Google's" policy on the collection and processing of personal information may be found at the following link. (http://www.google.com/policies/privacy/partners)

Based on the above information, "Google" comparatively analyzes information on usage behavior in the service application and provides it to the Company, and the Company uses such comparative analysis information solely for the purpose of improving service quality.

(5) The "Company" uses remarketing services to advertise to customers on third-party websites after the customer has used the Service. The Company and its third-party vendors use cookies to inform, optimize and serve advertisements based on the customer's past visits to the Service. For this purpose, the "Facebook" remarketing service is used. You may learn more about Facebook's interest-based advertising by visiting the following link. (https://www.facebook.com/help/164968693837950)

To opt out of Facebook's interest-based advertising, please follow the instructions at the following link provided by Facebook. (https://www.facebook.com/help/568137493302217)

For more information about Facebook's privacy practices, please refer to Facebook's Data Policy. (https://www.facebook.com/privacy/explanation)

(6) As a shopping mall for worldwide delivery, the "Company" shares certain portions of customers' personal information with the delivery service contractors that support the Company's core business functions (e.g., order fulfillment, package delivery, compliance with personal requests relating to the delivery of products for the Service, third-party intermediaries, and postal and email dispatch).

The privacy policy of the Company's delivery service provider may be found at the link below.

DHL: https://www.dhl.com/global-en/home/footer/global-privacy-notice.html

(7) If the "Company" is involved in a merger, acquisition or asset sale, the customer's personal data may be transferred. The Company will provide notice before your personal data is transferred and becomes subject to a different privacy policy.

Article 4 (Rights and Obligations of Data Subjects and the Method of Exercising Them)

(1) A data subject may exercise the following rights relating to the protection of personal information against the "Company" at any time.

  1. Request to access personal information
  2. Request for correction where there is an error, etc.
  3. Request for deletion
  4. Request for suspension of processing

(2) The exercise of the rights under paragraph (1) may be made against the "Company" in writing, by email, by facsimile transmission (FAX) or by similar means in accordance with Form No. 8 attached to the Enforcement Rules of the Personal Information Protection Act, and the "Company" shall take action thereon without delay.

(3) Where a data subject requests the correction or deletion of an error, etc. in personal information, the "Company" shall not use or provide the personal information concerned until the correction or deletion has been completed. The procedures and methods for the destruction of personal information are as follows.

  1. Destruction procedure
    1. Information entered by a "Member" for purposes such as membership registration is, after the purpose thereof has been achieved, transferred to a separate DB (in the case of paper, to a separate document file cabinet), stored for a certain period in accordance with internal policies and grounds for information protection under other relevant statutes (see the retention and use period), and then destroyed.
    2. Personal information transferred to a separate DB is not used for any other purpose except as provided by law.
  2. Destruction method
    1. Personal information printed on paper is destroyed by shredding with a shredder or by incineration.
    2. Personal information stored in the form of an electronic file is deleted using a technical method that renders the records irreproducible.

(4) The exercise of the rights under paragraph (1) may be made through an agent, such as the legal representative of the data subject or a person duly authorized by the data subject. In such case, a power of attorney in accordance with Form No. 11 attached to the Enforcement Rules of the Personal Information Protection Act must be submitted.

Article 5 (Items of Personal Information Processed)

(1) The "Company" processes the following items of personal information.

  1. Membership registration and management
    • Mandatory items: email (same as the login ID), mobile phone number, password, gender, date of birth, name
    • Optional items: position, department, company name, occupation, educational background, state-recognized identification card, business registration certificate, account information, photo information, secondary means of contact
    • For the purpose of personal identification, prevention of fraudulent use, and user management necessary for service operation upon membership registration
  2. Matters relating to the use of the service
    • Mandatory items: full name, login ID, password, mobile phone number, profile photo, areas of interest, past purchase history, service use records, access IP, payment records, recipient information
    • Optional items: mutual SNS information, location information, flight information concerning departure from and entry into the country, requested product information, purchase information, market name, settlement account information (mandatory entry in the case of a seller), information on products registered on the market, review information, personal customs clearance code
    • For the purpose of securing trust among "Members" and providing services smoothly
  3. Matters relating to the use of payment services
    • When using a credit card: card company name, card number, card expiration date, cardholder name, payment deadline, name of the product paid for, payment-related information, etc.
    • For the purpose of providing payment services smoothly when payment services are used (including cancellation)
  4. Automatically generated and other information
    • IP address, cookies, MAC address, device information, application version used, service use records, visit records, records of improper use, etc.

Article 6 (Measures to Ensure the Safety of Personal Information)

(1) The "Company" takes the following measures to ensure the safety of personal information.

  1. Countermeasures against hacking, etc.
    • The Company does its utmost to prevent the personal information of "Members" from being leaked or damaged by hacking, computer viruses or the like. In preparation for damage to personal information, the Company backs up data from time to time, and uses the latest anti-virus programs to prevent the personal information or data of "Users" from being leaked or damaged; it also ensures that personal information can be transmitted safely over networks through encrypted communications and the like. In addition, the Company controls unauthorized access from outside by using an intrusion prevention system, and endeavors to equip itself with all other technical devices possible for systemically securing safety.
  2. Minimization of and training for the personnel handling personal information
    • The Company limits the personnel handling personal information to those in charge, grants separate passwords for this purpose and renews them regularly, and constantly emphasizes compliance with the "Company's" Privacy Policy through occasional training for the personnel in charge.
  3. Operation of a dedicated organization for personal information protection
    • Through an in-house dedicated organization for personal information protection and the like, the Company verifies the implementation of the "Company's" Privacy Policy and compliance by the personnel in charge, and endeavors to correct and rectify any problem immediately upon discovery. However, the "Company" shall bear no liability whatsoever for any problem arising from the leakage of personal information due to the "User's" own negligence or to problems on the internet.

Article 7 (Operation and Refusal of Cookies)

(1) The purposes of using cookies are as follows.

  1. The "Company" uses "cookies," which store and retrieve information about "Users" from time to time, in order to provide personalized services. A cookie is a small amount of information that the "SHAASHOP" server transmits to the "User's" browser and that is stored on the hard disk of the "User's" computer.
  2. The "Company" is able to provide specific customized services that are possible only through the use of cookies.
  3. The "Company" may use cookies to identify Members and to maintain Members' logged-in status.

(2) Matters concerning the installation/operation and refusal of cookies are as follows.

  1. "Users" have the right to choose whether to allow the installation of cookies. Accordingly, "Users" may, by adjusting the options in their web browser, allow or refuse all cookies, or require confirmation each time a cookie is stored.
  2. If the storage of cookies is refused, it may be difficult to use some of the services provided by the "Company," such as personalized services.

Article 8 (Responsibility for Linked Sites)

(1) The "Company" may provide "Users" with links to other websites. In such case, since the "Company" has no control whatsoever over external sites and materials, the truthfulness, usefulness and the like of the services or materials provided therefrom are matters attributable to the parties concerned, and the "Company" bears no liability whatsoever and makes no warranty whatsoever in respect thereof. We recommend that you review the privacy policy of every site you visit.

(2) Since this "Privacy Policy" does not apply to the collection of personal information by linked websites, please be sure to review the policy of any newly visited site.

Article 9 (Chief Privacy Officer)

(1) The "Company" designates a Chief Privacy Officer as set out below, who takes overall responsibility for the work relating to the processing of personal information and who handles complaints from data subjects and provides relief for damage in relation to the processing of personal information.

- Department and person responsible for the management of personal information

  • Affiliation: SHAASHOP
  • Position: Team Leader
  • Name: Kim Tae-min
  • Contact: 070-4900-6420
  • Email: shaashop.taem@gmail.com

* You will be connected to the department in charge of personal information protection.

(2) Data subjects may direct to the Chief Privacy Officer and the department in charge any inquiries, complaint handling, relief for damage and other matters relating to the protection of personal information arising while using the SHAASHOP service. The "Company" will answer and handle data subjects' inquiries without delay.

Article 10 (Reporting of and Consultation on Other Personal Information Infringements)

(1) Users may make inquiries to the following organizations regarding relief for damage from, and consultation on, personal information infringements. The following organizations belong to government agencies; please contact them if you are not satisfied with the Company's own handling of personal information complaints or with the results of relief for personal information damage, or if you need more detailed assistance.

  • Personal Information Infringement Report Center
    Website: https://www.i-privacy.kr/, http://privacy.kisa.or.kr/
    Telephone: 118 (no area code required)
  • Personal Information Dispute Mediation Committee
    Website: http://kopico.or.kr/
    Telephone: 118 (no area code required)
  • Supreme Prosecutors' Office Cyber Crime Investigation Division
    Website: http://www.spo.go.kr
    Telephone: 02-3480-2000
  • Korean National Police Agency Cyber Bureau
    Website: http://www.netan.go.kr
    Telephone: 1566-0112

Article 11 (Duty of Notification)

(1) This Privacy Policy may be changed in accordance with government policy or the needs of the Company, and in the event of any addition, deletion or modification of its contents, prior notice will be given 7 days before the effective date through the notices section of the internet website and the mobile web.

(2) Where prior notice is difficult, notice will be given without delay, and this policy shall take effect from the date on which it is announced.

(3) Matters concerning the Privacy Policy are effective as of the time they are posted on this page.

1st announcement date: July 6, 2020
1st effective date: May 6, 2018

2nd announcement date: August 25, 2021
2nd effective date: August 25, 2021

Shazoom, LLC

2810 North Church Street, STE 89029

Wilmington, DE 19802, United States

Shaashop Co., Ltd.

5F O2 Tower, 83 Uisadang-daero, Yeongdeungpo-gu, Seoul, Republic of Korea

Business registration no. 179-88-01074

Customer support

Email: ewshin.korea@gmail.com

Phone: +82 10-6577-0505

Partnerships: shaashop.info@gmail.com

About SHAASHOP Terms of Service Electronic Payment Service Terms Privacy Policy Cancellation & Refund Policy

© 2026 SHAASHOP. All rights reserved.