Legal operator information
- Legal name: Pglemap Co., Ltd.
- Representatives: Kim Jung-hyun and Ko Sang-gyun
- Business registration number: 360-05-03393
- Mail-order sales registration number: 2026-Gyeonggi Uiwang-0284
- Address: Unit 1101, Building 203, 21 Saerom-gil, Uiwang-si, Gyeonggi-do, Republic of Korea (Poil-dong, Indeogwon Central Prugio)
- Telephone: 010-2743-8473
- Email: pglemap@gmail.com
- Privacy officers: Kim Jung-hyun and Ko Sang-gyun
Pglemaps Privacy Policy [Translation of the Controlling Korean Original]
Document Version: v3.6 Effective Date: 2026-08-27 Last Revised: 2026-08-27
This is a faithful English translation. If this translation differs in interpretation from the Korean original, the Korean-language version shall prevail.
Pglemap Co., Ltd. (service name: Pglemaps; the “Company” or “Pglemaps”) processes personal information only to the extent necessary for users to create travel itineraries, search for places, check and optimize routes, share travel baskets, use booking intermediation, make payments and receive refunds, view coupon and affiliate information, and operate member and advertiser accounts. In consideration of the Personal Information Protection Act and other applicable laws, and the Personal Information Protection Commission's guidance for preparing privacy policies, the Company publishes this Policy so users can readily understand what information is processed, for what purposes, and by what means.
The Korean version of this document is the controlling Pglemaps Privacy Policy. The privacy portion of the “Consent to the Terms of Service and Collection and Use of Personal Information” shown during registration summarizes the essential matters in this Policy that require consent. If the two documents differ, the scope of processing will not be interpreted expansively to the user's disadvantage. Processing that legally requires separate consent will be presented for consent again before the relevant function is provided.
This Policy applies to the Pglemaps website, mobile web, registration and login, bookings, payments and refunds, Customer Support, administrative functions, automated posting functions, coupon and affiliate pages, and advertiser-account functions. Once a user moves to the website or app of an external partner, map, search, AI or advertising provider, or social-login provider, personal information independently processed by that provider is governed by its privacy policy.
1. Purposes of Processing Personal Information
Pglemaps processes personal information for the following purposes:
- Travel planner: select countries and cities; search accommodations and restaurants; add places; display maps; check and optimize routes; create and restore travel baskets
- AI travel summaries: use an external AI API, such as Gemini, to generate itinerary summaries and guidance based on the user's selected itinerary, places and travel route
- Sharing: reload a travel basket and itinerary data through a sharing link created directly by the user
- Member and advertiser accounts: registration, login, email verification, password reset, social-login connection, advertiser-account application and approval, and store management
- Country-specific booking and Booking Deposit payment rules: use the nationality selected directly by the user during social sign-up to apply booking and Booking Deposit payment eligibility and minimum-amount rules
- Booking intermediation: select products and stores; submit, confirm, change or cancel a booking; provide advertisers with information necessary to perform a booking; send booking notices
- Payment and refund processing: fix the payment amount and currency; confirm authorization results; process cancellation, partial cancellation and refund; prevent duplicate and fraudulent payments; reconcile transactions
- Customer inquiries: review and answer inquiries and address disputes or failures involving no-shows, cancellations and refunds
- Service stability and security: detect abnormal requests, enforce rate limits, manage sessions, analyze error logs and prevent abuse
- Service improvement and statistics: analyze search quality, image loading, map and route functions, language-specific display and coupon-page performance
- Public Service-use statistics: on non-sensitive public HTML, process limited cookieless signals—such as page path, browser/device, consent state and approximate country—through Google Analytics advanced Consent Mode. Before an optional choice, analytics and advertising storage are denied and no GA or advertising-identifier cookie is created
- Advertising and affiliate performance: only after the user allows optional cookies, measure visits and conversions through Google Tag Manager, Google AdSense, Meta Pixel and affiliate links on signed-out public pages
- Context protection: no third-party analytics or advertising tag runs on account, login/registration, message, booking, payment or legal pages, or when a URL query contains a token, identity information or free text.
/plan,/country,/dates,/stays,/basketand/summaryare GA-only and never load the general GTM/AdSense/Meta/affiliate-marketing set
2. Categories of Personal Information Processed
Pglemaps processes the minimum information necessary to provide the Service. Some information is entered or selected by users, while other information is automatically generated through use of the Service.
A. Non-member use of the travel planner
- Required or automatically generated information: session_id cookie, access date and time, IP address or partial IP address, browser and device information, language setting, screen size, referral path and error information
- Information selected or entered by the user: country, city, travel dates, accommodation/place/restaurant queries, selected accommodations and places, coordinates, addresses, travel routes, travel-basket contents and whether a sharing link was created
- When requesting an AI summary: itinerary data, place names, address or coordinates, movement order, text entered by the user and the AI-generated summary
- When using sharing: sharing identifier, itinerary data for sharing, departure and return dates, creation time and expiration time
B. Registration and login
- Email registration: email address, password hash, nickname, given name, family name, preferred language, confirmation that the user is at least 14, services of interest and account type. Date of birth, gender and nationality are not required for email registration and are processed only if the user later provides them as optional profile data. Existing users whose nationality remained blank before v3.6 are not retroactively required to provide it.
- Advertiser-account application: company name, advertiser approval status, approval time, identifier of the approver, approval notes and other operationally necessary information
- Email verification/password reset: hash of the verification or reset token, target email, issue time, expiration time, use time and issuing IP address
- Login session: session-token hash, CSRF token, session creation/expiration/last-use times, login IP address and user agent
- Social sign-up and login: the provider currently implemented and selected by the user—Google, Facebook, LINE or Kakao—plus its unique identifier, supplied email, email-verification state, connection and last-use times and the minimum necessary profile response. To complete social sign-up, the nationality selected directly by the user is required; declining to provide it prevents completion of social sign-up. Nationality is not required for email registration. Apple and Naver values exist in the provider-neutral database model but are not represented as currently implemented consumer-login processors
C. Booking, payment, cancellation and refund
- Booking information: booking number, user's name, telephone number, email, nationality and communication language, Business and product, booking date and time, number of guests, selected options, requests, booking status and change history
- Payment information: order number, payment or refund amount, sales and authorization currency (USD), internal calculation base amount (KRW), applied exchange-rate snapshot, payment-method type, PayVerse TID, authorization number, status and processing time of authorization, failure, cancellation, partial cancellation and refund
- Dispute information: reason for cancellation or no-show, objection, processing result, evidence and Customer Support consultation history
- Payment credentials, including the full payment-card number and CVC, are processed directly in the PayVerse-hosted payment window and are not directly stored by the Company. The Company processes the transaction result, TID, amount, currency and status needed to manage the transaction.
D. Inquiries, coupons, affiliates and events
- Inquiry content, email address or other reply contact, and inquiry-handling history
- Coupon or affiliate page visit and click information, click identifiers necessary to move to the affiliate, and browser and device information
- If a separate event or promotion is offered, the items disclosed and consented to on the relevant screen
E. Automatically generated or collected technical information
- Server access logs, requested URL, status code, request processing time and error message
- Client error report: error message, error file and line, part of the URL path and query string, browser language, screen size, user agent and masked IP range
- Security and rate-limit information: request counts by session or IP and rate-limit history
Pglemaps does not request resident registration numbers, passport numbers, full payment-card numbers, health information or other sensitive identifiers in the travel planner or booking requests. The server blocks booking requests that contain health, illness, allergy or medication information, resident registration numbers or passport numbers. Do not place sensitive information in other free-text inquiries or messages. If booking-request translation is selected, the original text and language may be sent to Google Gemini only after the separate on-screen disclosure and consent.
3. Methods of Collection
Pglemaps collects or generates personal information through the following methods:
- Information directly entered or selected by a user on a screen
- Information automatically generated during use of the Service, including travel baskets, sharing links, registration, login, booking, payment, cancellation, refund, inquiries and coupon clicks
- Browser cookies, server logs, error reports and advertising or analytics scripts
- Information sent to Pglemaps by a social-login provider or external API provider based on the user's selection or execution of a function
- Information transmitted by PayVerse through its hosted payment window, payment-result return, server-to-server webhook or transaction-inquiry API
4. Retention and Use Period
Pglemaps destroys personal information without delay after the relevant purpose is achieved. Information may be retained to the necessary extent where required by law or needed for dispute response, abuse prevention or service recovery.
- Non-member session data: generally processed in the browser session and server memory; inactive server sessions are ordinarily cleared after 24 hours
- Travel sharing-link data (plan_shares): retained for 30 days from creation and then expires; expired data is cleared during lookup or creation of a new sharing link
- Final itinerary result file (JSON): may be stored to the extent necessary to complete or restore a travel basket, investigate a failure or answer an inquiry, and is destroyed when the purpose is achieved, upon a user's deletion request, or during a periodic internal review
- Member account information: retained until membership termination; information needed for a statutory retention duty, dispute handling or abuse prevention may be separately retained for the necessary period
- Records concerning a contract or withdrawal of an offer: five years under the Act on the Consumer Protection in Electronic Commerce
- Records concerning payment and supply of goods or services: five years under the Act on the Consumer Protection in Electronic Commerce
- Records concerning consumer complaints or dispute handling: three years under the Act on the Consumer Protection in Electronic Commerce
- Signup email OTP: ordinarily expires after 10 minutes. A separate email-verification link token ordinarily expires after 24 hours
- Password-reset token: ordinarily expires after 30 minutes
- Login session: an absolute lifetime of 12 hours and an idle timeout of 30 minutes. A user-selected remember-me token lasts no longer than 14 days
- Failed-login or security-restriction information: retained for the period necessary to prevent unauthorized login and respond to security incidents
- Client error and server operation logs: retained for the period necessary for failure response, security review and service-quality improvement, and then periodically deleted or de-identified
- Limited public-page analytics signals: before an optional choice, a non-sensitive public HTML page may send Google Analytics cookieless signals such as page path, browser/device, consent state and approximate country. Pglemaps excludes the URL query, fragment and free-text values from its configured page fields, and does not inject a third-party analytics tag when a request contains a token, identity or free-text query key
- Optional advertising/analytics cookies and affiliate-conversion information: created only after the user allows optional cookies; the choice cookie lasts no longer than 180 days. External provider retention follows the relevant contract and policy; Pglemaps does not invent a period that has not been confirmed by contract evidence
5. Third-Party Provision and Processing Entrustment
Pglemaps does not sell users' personal information. The Company provides the transaction counterparty—the relevant Business—with the minimum information necessary to perform a booking, and may entrust work necessary to operate the Service to external providers.
A. Third-party provision to perform a booking
- Recipient: the advertiser or participating Business booked by the user
- Purpose: confirm the booking, coordinate the schedule, provide the service, and handle cancellation, no-show and customer inquiries
- Information: name, telephone number, email, nationality and communication language, booked Business/product/date/time/guest count/options/requests, and booking status
- Retention: until the purposes of performing the booking and handling disputes are achieved; the Business may retain it for a longer period where required by law applicable to that Business
B. Processing entrustment and external services
- Brevo (Sendinblue SAS): recipient email/name, subject, body and delivery identifier for signup OTP, password reset and transactional notices
- Google LLC: search terms, addresses, coordinates and route requests for Places/Maps/Routes; itinerary, place, language and free-text originals for Gemini. On non-sensitive public HTML, Google Analytics advanced Consent Mode processes limited cookieless analytics signals even before an optional choice, while analytics and advertising storage remain denied. Google Tag Manager/AdSense and advertising functions run only after optional cookies are allowed on signed-out public pages. No third-party analytics or advertising tag runs on login, registration, account, message, booking, payment or legal pages, or on requests with token, identity or free-text query keys. Country-selection, dates, stays, basket, summary and other planner steps use path-restricted GA without the general advertising container
- Mapbox, Inc. and the OpenStreetMap tile network: access information, viewport/tile, coordinate, geocoding and route requests for maps and fallback tiles
- DeepL SE: post text only when an authorized administrator runs post translation; ordinary visitor text is not automatically sent
- Meta Platforms, Inc.: identifier, email and minimum profile when the user selects Facebook Login. Meta Pixel runs only after optional-cookie consent on marketing-safe, signed-out public pages selected by the automatic context rules described above
- Sendon/Kakao AlimTalk: a merchant's configured contact and approved booking-notice variables when an operational notice is sent
- Kakao, NAVER/NAVER Cloud, LINE and Google/Meta OAuth: search/address/coordinate data or provider-returned identifier, email and minimum profile when the user directly selects the corresponding map, search, sharing or login feature
- Hot Pepper: search conditions and area when a Japanese restaurant search is run
- Google Fonts, jsDelivr, cdnjs, FlagCDN and Unsplash: a browser may send IP address, user agent, referrer and requested asset URL from pages containing those assets; an administrator's image-search term may be sent to Unsplash
- Klook, Agoda and Trip.com: click URL, affiliate identifier and browser information only after the user deliberately follows an outbound affiliate link. The audited path does not API-transfer a Pglemaps booking record to these partners
- Guide-application analytics: non-sensitive public guide pages use the same path-only Google Analytics Consent Mode described above. Vercel Analytics, guide-page AdSense, Meta Pixel and the general-purpose GTM advertising container do not run in that application
- Cloudflare, Inc. (Turnstile): processes IP address, user agent, referrer and page context, sitekey, action, verification token, and device- and network-based abuse signals through browser and server verification to prevent automated access, fraudulent registration, and account attacks on login and registration pages; it is not used for advertising or behavioral analytics
C. PayVerse payment processing
- Payments are processed through the PayVerse-hosted payment window.
- The Company does not directly store payment credentials and processes the transaction result, TID, amount, currency and status.
- PayVerse's exact contracting legal entity, legal role, processing country, overseas subprocessors and retention period have not been established by signed contract or DPA evidence and therefore are not presented as confirmed facts. They remain an overseas-transfer disclosure item that must be verified from contractual evidence and disclosed as required by law.
Examples of information that may be transmitted to an external API include search terms, place names, addresses, coordinates, itinerary text, travel routes, language settings, browser and device information, advertising and analytics events, and identifiers supplied by a social-login provider. Pglemaps seeks to limit transmitted information to what is necessary to perform the function.
If a recipient or processor is added or changed during operation of the Service, Pglemaps will update the relevant part of this Policy before actual processing begins and will obtain separate consent where required. A user may contact pglemap@gmail.com to ask which external function received that user's information.
6. Overseas Transfers
When the user runs one of the functions below, Pglemaps may transmit only the information needed by HTTPS API, browser asset request or OAuth redirect.
| Recipient | Country/processing region | Information and purpose | Timing/method | Retention and refusal |
|---|---|---|---|---|
| Google LLC | United States and globally contracted regions | search, address, coordinate and route data; itinerary, place, translation original and language; OAuth identifier/email; cookieless page-path, browser/device, consent-state and approximate-country signals on non-sensitive public HTML; analytics cookies and advertising events after optional consent | HTTPS/API/OAuth when invoked; advanced Consent Mode script when public HTML loads; additional analytics and advertising tags after optional consent | contract/API settings and Google policy; before an optional choice, analytics/advertising storage and ad personalization are denied and no GA or advertising-identifier cookie is created. Users may avoid map/AI/login features or use browser tracking controls |
| Mapbox, Inc. | United States and global regions | IP/browser data, viewport, coordinates and route | HTTPS/API or browser request when using the map | contract/API policy; avoid the corresponding map function |
| Sendinblue SAS (Brevo) | France, EU and contracted regions | email, name, subject/body and transaction notice delivery | HTTPS API when an OTP, authentication or transaction email is sent | contractual delivery, security and legal period; refusing a required email limits email registration or that notice |
| Meta Platforms, Inc. | United States and global regions | Facebook OAuth identifier/email/minimum profile; advertising event after consent | OAuth or script after optional consent | Meta policy and account settings; do not use Facebook login or reject optional cookies |
| LINE affiliates | Japan and contracted regions | OAuth identifier, email and minimum profile | OAuth/API when LINE login is selected | LINE policy and account settings; do not use LINE login |
| DeepL SE | Germany/EU | post original selected for translation by an administrator | HTTPS API on the administrative translation action | contract/API policy; no transfer merely by visiting the Service |
| Cloudflare, Inc. (Turnstile) | United States and global processing regions | IP address, user agent, referrer/page context, sitekey, action, verification token, and device/network security signals; login and registration abuse prevention | browser and server HTTPS verification when a protected login or registration page is loaded or submitted | Cloudflare contractual and security policy periods; refusing this essential security processing prevents use of the protected login or registration function |
| OpenStreetMap tile network, jsDelivr, cdnjs, FlagCDN, Unsplash and Google Fonts | each provider's global CDN regions | IP, browser, referrer, asset/tile URL and administrator image-search term | browser/HTTPS request when the asset or search is used | each provider's cache/security policy; Pglemaps is moving toward self-hosting and will not add an unreviewed direct call |
Kakao and NAVER domestic processing is not listed as an overseas transfer. Klook, Agoda and Trip.com independently receive data after the user follows an external link; there is no current API that automatically gives them Pglemaps booking or identity data. PayVerse-hosted payment processing is active, but no confirmed legal entity, processing country, overseas subprocessor or retention period is added to the table because those details have not been established by signed contract or DPA evidence. They must be verified from contractual evidence and disclosed as required by law.
Actual processing countries, subprocessors and exact retention periods are continuously checked against signed DPAs and provider materials. Pglemaps does not state an unverified contract fact as certain and will not expand processing before the required evidence and notice are complete.
7. Cookies and Similar Technologies
Pglemaps uses essential technologies for Service operation, login security and language settings. On non-sensitive public HTML, limited cookieless Google Analytics signals may be sent through advanced Consent Mode before an optional choice, while analytics and advertising storage are denied and no GA or advertising-identifier cookie is created. Analytics cookies and advertising or affiliate technologies are used only after the user separately allows them.
- Essential cookies: session_id, pglemap_user_session, pglemap_user_csrf and post_admin_session, used to maintain a travel basket, log in, protect against CSRF and operate an administrator session
- Functional cookies or stored values: language selection, country/city selection, UI state, travel-basket restoration and similar convenience functions
- Limited analytics before an optional choice: on non-sensitive public HTML, Google Analytics may process cookieless page-path, browser/device, consent-state and approximate-country signals. Analytics and advertising storage remain denied and no GA or advertising-identifier cookie is created
- Optional analytics/advertising cookies: only after the user chooses “Allow optional cookies” does Pglemaps grant analytics storage and load Google Tag Manager, Google AdSense, Meta Pixel or affiliate-performance events on signed-out public pages. Country selection, dates, stays, basket, summary and other planner steps continue to use path-restricted Google Analytics without the general advertising container
- Exclusions: when an authentication cookie is present, the general-purpose GTM container and AdSense, Meta or affiliate-marketing tags do not load; direct GA remains on an otherwise eligible ordinary public page, applies the current consent state, and restricts URL information to the query-free path. No third-party analytics or advertising tag loads on login, registration, account, message, booking, payment or legal pages, or when the URL query contains a token, identity information or free text.
/plan,/country,/dates,/stays,/basketand/summaryremain GA-only
Users may reject or delete cookies through their browser settings. Blocking essential cookies may prevent login, travel-basket maintenance, sharing-link restoration, or parts of map and route functions from operating correctly.
8. Behavioral Information and Personalized Advertising
On non-sensitive public HTML, Pglemaps may process limited cookieless Service-use signals through Google Analytics advanced Consent Mode before an optional choice. If the user allows optional cookies, Pglemaps additionally processes analytics-cookie and advertising or affiliate-performance information on signed-out public pages.
- Information before an optional choice: a query-free page path, browser/device information, consent state and an approximate-country signal inferred by Google from the network request; no GA cookie or advertising identifier
- Information after consent: public-page visits, clicks, coupon or affiliate-link clicks, travel-basket creation or completion events, referral paths, browser/device information, and analytics cookies or advertising identifiers where applicable. Account pages and other excluded contexts do not create these external events
- Purposes: Service-use statistics, error improvement, advertising-performance measurement, affiliate-conversion measurement, prevention of duplicate exposure, and increased efficiency of interest-based advertising
- Tools: Google Analytics advanced Consent Mode for limited pre-choice signals; after the choice, Google Analytics, Google Tag Manager, Google AdSense, Meta Pixel and affiliate-link tracking tools
- Retention: Pglemaps internal logs are cleared after their operational purpose is achieved; behavioral information processed by Google, Meta, affiliates and other external providers is governed by their policies and the user's browser or device settings
- Controls: browser cookie blocking/deletion, device advertising-identifier restrictions, Google advertising settings, Meta advertising settings and browser tracking-prevention functions
9. Generative AI Functions
Travel-basket completion, detailed route summaries, automated posting, booking-request translation and content assistance may use Google Gemini; administrative post translation may use DeepL. An AI request may include itinerary data, place names, addresses or coordinates, movement order, and original user-entered text and language. A booking-request original is sent for translation only after the separate disclosure and consent.
Pglemaps does not use a user's itinerary or prompt to train Pglemaps' own AI model. Data processing by an external AI API provider is governed by that provider's API terms and privacy policy. Do not enter sensitive information such as a passport number, resident registration number, payment information, health information or another person's contact information in an AI-summary request.
A user who does not want to use an AI summary or translation may choose not to run the relevant function. Requests to delete an already-generated AI summary, final itinerary file or sharing-link data, or objections and reports concerning an inappropriate response, may be sent to pglemap@gmail.com.
10. Destruction Procedures and Methods
Pglemaps destroys personal information without delay when the retention period ends or the processing purpose is achieved.
- Electronic files: deleted or access rights removed so that recovery is difficult
- Database records: deleted, expired, de-identified, or separately isolated and later destroyed
- Logs and backups: where immediate operational deletion is difficult, access is restricted and deletion follows the backup-retention cycle or periodic-review process
11. User Rights and How to Exercise Them
A user may request access to, correction or deletion of, or suspension of processing of the user's personal information, may withdraw consent, and may terminate membership. After verifying that the requester is the data subject, Pglemaps processes the request within the period and by the method prescribed by law.
- Member information: request correction, deletion or withdrawal through account-management functions available after login or through a customer inquiry
- Sharing-link data: request deletion of a sharing link or deletion before expiration
- AI summary and final itinerary data: request deletion or correction of user-generated results, or submit an objection or report concerning an inappropriate response
- Cookie/advertising identifiers: restrict through browser settings, device advertising settings, or advertising settings provided by Google, Meta and other external providers
- Contact: telephone 010-2743-8473 or email pglemap@gmail.com
A request may be restricted in whole or in part where information must be retained by law or where granting it could infringe another user's rights. Pglemaps will explain the reason for any restriction.
12. Security Measures
Pglemaps applies the following measures to protect personal information:
- Does not store plaintext passwords and stores scrypt-based password hashes
- Stores hashes of email-verification tokens, password-reset tokens and login-session tokens
- Uses secure cookies in HTTPS environments, HttpOnly, SameSite and CSRF tokens
- Separates administrator sessions and verifies CSRF for administrative functions
- Applies request rate limits, detects abuse and reviews error logs
- Minimizes personal-information access privileges and manages production secrets
- Controls database and server access
- Manages external API keys and secrets through environment variables or server configuration
13. Personal Information of Children Under 14
Pglemaps does not intend to permit registration or submission of personal information by children under 14. If it confirms that personal information of a child under 14 was processed without the consent of a legal representative, Pglemaps will complete the necessary verification and delete or restrict use of the information.
14. Automated Decision-Making
Pglemaps may use automated processing to sort search results, make recommendations, optimize routes, and process advertising or analytics events. It does not, however, make a decision that produces a legal effect or has a material impact on a user solely through automated processing. Requests for an explanation or action concerning automated processing may be sent to pglemap@gmail.com.
15. Personal Information Protection Officers and Contact Details
- Business name: Pglemap Co., Ltd. (service name: Pglemaps)
- Representatives: Kim Jung-hyun and Ko Sang-gyun (Co-CEOs)
- Business registration number: 360-05-03393
- Mail-order sales registration number: 2026-Gyeonggi Uiwang-0284
- Address: Unit 1101, Building 203, 21 Saerom-gil, Uiwang-si, Gyeonggi-do, Republic of Korea (Poil-dong, Indeogwon Central Prugio)
- Customer Support telephone: 010-2743-8473
- Personal Information Protection Officers: Kim Jung-hyun and Ko Sang-gyun
- Contact email: pglemap@gmail.com
Department receiving and processing requests to access personal information: Pglemaps Operations Team
Submission method: telephone 010-2743-8473 or email pglemap@gmail.com
Assistance with personal-information infringement reports, dispute mediation and remedies is also available through the Personal Information Protection Commission's privacy portal, the Personal Information Infringement Report Center, the Personal Information Dispute Mediation Committee and other relevant authorities.
16. Changes to this Privacy Policy
Pglemaps may amend this Policy when Service functions, external APIs, laws or security policies change. For a material change, the effective date, details and reason will be announced through an in-Service notice or the Privacy Policy screen.
Principal changes from the previous Policy:
- Required the nationality selected directly by the user during social sign-up, disclosed its use for country-specific booking and Booking Deposit payment eligibility and minimum-amount rules, and stated the consequence of refusal. This requirement does not apply retroactively to email registration or existing users whose nationality is blank.
- Reflected Pglemaps' actual functions, including the travel planner, sharing links, AI summaries, member and advertiser accounts, coupons and affiliates, and advertising and analytics
- Changed sharing-link retention to 30 days to match the current code policy
- Organized external APIs and possible overseas transfers by maps, place search, AI, translation, advertising, social login and affiliate functions
- Added user booking, payment, cancellation and refund information and statutory retention periods
- Distinguished the actual code paths for Brevo, Sendon/Kakao AlimTalk, Gemini booking originals, implemented OAuth providers, browser-direct assets and affiliate clicks
- Separated public analytics from optional advertising: aligned the Policy with limited Google Analytics advanced Consent Mode signals on non-sensitive public HTML, denied analytics/advertising storage and cookieless operation before a choice, analytics cookies and advertising tags after consent, sensitive-page and sensitive-query exclusions, and the GA-only planner boundary
- Reflected PayVerse-hosted payment processing, non-storage of payment credentials, and processing of transaction result, TID, amount, currency and status, without presenting unverified overseas-transfer contract or DPA details as facts
- Added Cloudflare Turnstile's browser-direct fields, overseas processing, and the consequence of refusal for login and registration security
v3.6