Pglemaps
Travel Tools
  • Trip Budget
  • Survival Phrases
  • Packing Checklist
  • Emergency Contacts
  • Medical Facilities
  • Tax Refund
  • Running & Cycling
  • Currency Exchange
Coupons Guide Community
  • EN
  • Español
  • Русский
  • العربية
  • 한국어
  • 日本語
  • 简体
  • 繁體
Log in
  • My Page
  • Messages
  • Sign out
Travel Tools
Trip BudgetSurvival PhrasesPacking ChecklistEmergency ContactsMedical FacilitiesTax RefundRunning & CyclingCurrency Exchange
Coupons Guide Community
Legal

Privacy Policy

Effective: June 25, 2026

Contents

  • Pglemaps Privacy Policy [Translation of the Controlling Korean Original]
    • 1. Purposes of Processing Personal Information
    • 2. Categories of Personal Information Processed
      • A. Non-member use of the travel planner
      • B. Registration and login
      • C. Booking, payment, cancellation and refund
      • D. Inquiries, coupons, affiliates and events
      • E. Automatically generated or collected technical information
    • 3. Methods of Collection
    • 4. Retention and Use Period
    • 5. Third-Party Provision and Processing Entrustment
      • A. Third-party provision to perform a booking
      • B. Processing entrustment and external services
      • C. Payment-processor preparation status
    • 6. Overseas Transfers
    • 7. Cookies and Similar Technologies
    • 8. Behavioral Information and Personalized Advertising
    • 9. Generative AI Functions
    • 10. Destruction Procedures and Methods
    • 11. User Rights and How to Exercise Them
    • 12. Security Measures
    • 13. Personal Information of Children Under 14
    • 14. Automated Decision-Making
    • 15. Personal Information Protection Officers and Contact Details
    • 16. Changes to this Privacy Policy

Pglemaps Privacy Policy [Translation of the Controlling Korean Original]

Effective Date: 2026-07-29 Last Revised: 2026-07-29

This is a faithful English translation. If this translation differs in interpretation from the Korean original, the Korean-language version shall prevail.

Pglemap Co., Ltd. (service name: Pglemaps; the “Company” or “Pglemaps”) processes personal information only to the extent necessary for users to create travel itineraries, search for places, check and optimize routes, share travel baskets, use booking intermediation, make payments and receive refunds, view coupon and affiliate information, and operate member and advertiser accounts. In consideration of the Personal Information Protection Act and other applicable laws, and the Personal Information Protection Commission's guidance for preparing privacy policies, the Company publishes this Policy so users can readily understand what information is processed, for what purposes, and by what means.

The Korean version of this document is the controlling Pglemaps Privacy Policy. The privacy portion of the “Consent to the Terms of Service and Collection and Use of Personal Information” shown during registration summarizes the essential matters in this Policy that require consent. If the two documents differ, the scope of processing will not be interpreted expansively to the user's disadvantage. Processing that legally requires separate consent will be presented for consent again before the relevant function is provided.

This Policy applies to the Pglemaps website, mobile web, registration and login, bookings, payments and refunds, Customer Support, administrative functions, automated posting functions, coupon and affiliate pages, and advertiser-account functions. Once a user moves to the website or app of an external partner, map, search, AI or advertising provider, or social-login provider, personal information independently processed by that provider is governed by its privacy policy.

1. Purposes of Processing Personal Information

Pglemaps processes personal information for the following purposes:

  • Travel planner: select countries and cities; search accommodations and restaurants; add places; display maps; check and optimize routes; create and restore travel baskets
  • AI travel summaries: use an external AI API, such as Gemini, to generate itinerary summaries and guidance based on the user's selected itinerary, places and travel route
  • Sharing: reload a travel basket and itinerary data through a sharing link created directly by the user
  • Member and advertiser accounts: registration, login, email verification, password reset, social-login connection, advertiser-account application and approval, and store management
  • Booking intermediation: select products and stores; submit, confirm, change or cancel a booking; provide advertisers with information necessary to perform a booking; send booking notices
  • Payment and refund processing: fix the payment amount and currency; confirm authorization results; process cancellation, partial cancellation and refund; prevent duplicate and fraudulent payments; reconcile transactions
  • Customer inquiries: review and answer inquiries and address disputes or failures involving no-shows, cancellations and refunds
  • Service stability and security: detect abnormal requests, enforce rate limits, manage sessions, analyze error logs and prevent abuse
  • Service improvement and statistics: analyze search quality, image loading, map and route functions, language-specific display and coupon-page performance
  • Advertising and affiliate performance: measure visits and conversions through Google Analytics/AdSense, Meta Pixel and affiliate links only on reviewed, signed-out public pages after the user accepts optional cookies; never on login, account, messaging, booking, payment or legal pages

2. Categories of Personal Information Processed

Pglemaps processes the minimum information necessary to provide the Service. Some information is entered or selected by users, while other information is automatically generated through use of the Service.

A. Non-member use of the travel planner

  • Required or automatically generated information: session_id cookie, access date and time, IP address or partial IP address, browser and device information, language setting, screen size, referral path and error information
  • Information selected or entered by the user: country, city, travel dates, accommodation/place/restaurant queries, selected accommodations and places, coordinates, addresses, travel routes, travel-basket contents and whether a sharing link was created
  • When requesting an AI summary: itinerary data, place names, address or coordinates, movement order, text entered by the user and the AI-generated summary
  • When using sharing: sharing identifier, itinerary data for sharing, departure and return dates, creation time and expiration time

B. Registration and login

  • Email registration: email address, password hash, nickname, given name, family name, preferred language, confirmation that the user is at least 14, services of interest and account type. Date of birth, gender and nationality are not required for ordinary registration and are processed only if the user later provides them as optional profile data
  • Advertiser-account application: company name, advertiser approval status, approval time, identifier of the approver, approval notes and other operationally necessary information
  • Email verification/password reset: hash of the verification or reset token, target email, issue time, expiration time, use time and issuing IP address
  • Login session: session-token hash, CSRF token, session creation/expiration/last-use times, login IP address and user agent
  • Social login: the provider currently implemented and selected by the user—Google, Facebook, LINE or Kakao—plus its unique identifier, supplied email, email-verification state, connection and last-use times and the minimum necessary profile response. Apple and Naver values exist in the provider-neutral database model but are not represented as currently implemented consumer-login processors

C. Booking, payment, cancellation and refund

  • Booking information: booking number, user's name, telephone number, email, nationality and communication language, Business and product, booking date and time, number of guests, selected options, requests, booking status and change history
  • Payment information: order number, payment or refund amount, sales and authorization currency (USD), internal calculation base amount (KRW), applied exchange-rate snapshot, payment-method type, PG transaction identifier, authorization number, status and processing time of authorization, failure, cancellation, partial cancellation and refund
  • Dispute information: reason for cancellation or no-show, objection, processing result, evidence and Customer Support consultation history
  • The Company does not directly store the full payment-card number, CVC or other raw card data. When actual payments are introduced, card information will be processed by a PG and payment-method provider that has completed contracting and review. The Company will process only information necessary for transaction management, such as the payment result and transaction identifier.

D. Inquiries, coupons, affiliates and events

  • Inquiry content, email address or other reply contact, and inquiry-handling history
  • Coupon or affiliate page visit and click information, click identifiers necessary to move to the affiliate, and browser and device information
  • If a separate event or promotion is offered, the items disclosed and consented to on the relevant screen

E. Automatically generated or collected technical information

  • Server access logs, requested URL, status code, request processing time and error message
  • Client error report: error message, error file and line, part of the URL path and query string, browser language, screen size, user agent and masked IP range
  • Security and rate-limit information: request counts by session or IP and rate-limit history

Pglemaps does not request resident registration numbers, passport numbers, full payment-card numbers, health information or other sensitive identifiers in the travel planner or booking requests. The server blocks booking requests that contain health, illness, allergy or medication information, resident registration numbers or passport numbers. Do not place sensitive information in other free-text inquiries or messages. If booking-request translation is selected, the original text and language may be sent to Google Gemini only after the separate on-screen disclosure and consent.

3. Methods of Collection

Pglemaps collects or generates personal information through the following methods:

  • Information directly entered or selected by a user on a screen
  • Information automatically generated during use of the Service, including travel baskets, sharing links, registration, login, booking, payment, cancellation, refund, inquiries and coupon clicks
  • Browser cookies, server logs, error reports and advertising or analytics scripts
  • Information sent to Pglemaps by a social-login provider or external API provider based on the user's selection or execution of a function
  • After payments are introduced, information transmitted by a PG through its payment window, payment-result return, server-to-server webhook or transaction-inquiry API

4. Retention and Use Period

Pglemaps destroys personal information without delay after the relevant purpose is achieved. Information may be retained to the necessary extent where required by law or needed for dispute response, abuse prevention or service recovery.

  • Non-member session data: generally processed in the browser session and server memory; inactive server sessions are ordinarily cleared after 24 hours
  • Travel sharing-link data (plan_shares): retained for 30 days from creation and then expires; expired data is cleared during lookup or creation of a new sharing link
  • Final itinerary result file (JSON): may be stored to the extent necessary to complete or restore a travel basket, investigate a failure or answer an inquiry, and is destroyed when the purpose is achieved, upon a user's deletion request, or during a periodic internal review
  • Member account information: retained until membership termination; information needed for a statutory retention duty, dispute handling or abuse prevention may be separately retained for the necessary period
  • Records concerning a contract or withdrawal of an offer: five years under the Act on the Consumer Protection in Electronic Commerce
  • Records concerning payment and supply of goods or services: five years under the Act on the Consumer Protection in Electronic Commerce
  • Records concerning consumer complaints or dispute handling: three years under the Act on the Consumer Protection in Electronic Commerce
  • Signup email OTP: ordinarily expires after 10 minutes. A separate email-verification link token ordinarily expires after 24 hours
  • Password-reset token: ordinarily expires after 30 minutes
  • Login session: an absolute lifetime of 12 hours and an idle timeout of 30 minutes. A user-selected remember-me token lasts no longer than 14 days
  • Failed-login or security-restriction information: retained for the period necessary to prevent unauthorized login and respond to security incidents
  • Client error and server operation logs: retained for the period necessary for failure response, security review and service-quality improvement, and then periodically deleted or de-identified
  • Optional advertising/analytics cookies and affiliate-conversion information: created only after optional-cookie consent; the choice cookie lasts no longer than 180 days. External provider retention follows the relevant contract and policy; Pglemaps does not invent a period that has not been confirmed by contract evidence

5. Third-Party Provision and Processing Entrustment

Pglemaps does not sell users' personal information. The Company provides the transaction counterparty—the relevant Business—with the minimum information necessary to perform a booking, and may entrust work necessary to operate the Service to external providers.

A. Third-party provision to perform a booking

  • Recipient: the advertiser or participating Business booked by the user
  • Purpose: confirm the booking, coordinate the schedule, provide the service, and handle cancellation, no-show and customer inquiries
  • Information: name, telephone number, email, nationality and communication language, booked Business/product/date/time/guest count/options/requests, and booking status
  • Retention: until the purposes of performing the booking and handling disputes are achieved; the Business may retain it for a longer period where required by law applicable to that Business

B. Processing entrustment and external services

  • Brevo (Sendinblue SAS): recipient email/name, subject, body and delivery identifier for signup OTP, password reset and transactional notices
  • Google LLC: search terms, addresses, coordinates and route requests for Places/Maps/Routes; itinerary, place, language and free-text originals for Gemini. Analytics/Tag Manager/AdSense runs only on reviewed, signed-out public pages after optional-cookie consent
  • Mapbox, Inc. and the OpenStreetMap tile network: access information, viewport/tile, coordinate, geocoding and route requests for maps and fallback tiles
  • DeepL SE: post text only when an authorized administrator runs post translation; ordinary visitor text is not automatically sent
  • Meta Platforms, Inc.: identifier, email and minimum profile when the user selects Facebook Login. Meta Pixel runs only after optional-cookie consent on reviewed, signed-out public pages
  • Sendon/Kakao AlimTalk: a merchant's configured contact and approved booking-notice variables when an operational notice is sent
  • Kakao, NAVER/NAVER Cloud, LINE and Google/Meta OAuth: search/address/coordinate data or provider-returned identifier, email and minimum profile when the user directly selects the corresponding map, search, sharing or login feature
  • Hot Pepper: search conditions and area when a Japanese restaurant search is run
  • Google Fonts, jsDelivr, cdnjs, FlagCDN and Unsplash: a browser may send IP address, user agent, referrer and requested asset URL from pages containing those assets; an administrator's image-search term may be sent to Unsplash
  • Klook, Agoda and Trip.com: click URL, affiliate identifier and browser information only after the user deliberately follows an outbound affiliate link. The audited path does not API-transfer a Pglemaps booking record to these partners
  • Vercel Analytics and guide-page AdSense: disabled as of 2026-07-29 because the guide application has no consent-aware loader

C. Payment-processor preparation status

  • No payment gateway has completed contracting, merchant review and technical integration. Production booking submission and actual booking-deposit collection remain blocked.
  • The Company does not present any candidate as a current processor and sends no user's payment information to a candidate before the contracting party is confirmed.
  • Before accepting payment, the Company will disclose the processor's legal name, fields, countries, timing and method, retention, overseas subprocessors, refusal method, and authorized and settlement currencies in this Policy and on the payment screen, and will obtain any required consent.

Examples of information that may be transmitted to an external API include search terms, place names, addresses, coordinates, itinerary text, travel routes, language settings, browser and device information, advertising and analytics events, and identifiers supplied by a social-login provider. Pglemaps seeks to limit transmitted information to what is necessary to perform the function.

If a recipient or processor is added or changed during operation of the Service, Pglemaps will update the relevant part of this Policy before actual processing begins and will obtain separate consent where required. A user may contact pglemap@gmail.com to ask which external function received that user's information.

6. Overseas Transfers

When the user runs one of the functions below, Pglemaps may transmit only the information needed by HTTPS API, browser asset request or OAuth redirect.

Recipient Country/processing region Information and purpose Timing/method Retention and refusal
Google LLC United States and globally contracted regions search, address, coordinate and route data; itinerary, place, translation original and language; OAuth identifier/email; advertising and analytics events after consent HTTPS/API/OAuth when invoked; scripts only after optional consent contract/API settings and Google policy; avoid the map/AI/login feature or choose essential-only cookies
Mapbox, Inc. United States and global regions IP/browser data, viewport, coordinates and route HTTPS/API or browser request when using the map contract/API policy; avoid the corresponding map function
Sendinblue SAS (Brevo) France, EU and contracted regions email, name, subject/body and transaction notice delivery HTTPS API when an OTP, authentication or transaction email is sent contractual delivery, security and legal period; refusing a required email limits email registration or that notice
Meta Platforms, Inc. United States and global regions Facebook OAuth identifier/email/minimum profile; advertising event after consent OAuth or script after optional consent Meta policy and account settings; do not use Facebook login or reject optional cookies
LINE affiliates Japan and contracted regions OAuth identifier, email and minimum profile OAuth/API when LINE login is selected LINE policy and account settings; do not use LINE login
DeepL SE Germany/EU post original selected for translation by an administrator HTTPS API on the administrative translation action contract/API policy; no transfer merely by visiting the Service
OpenStreetMap tile network, jsDelivr, cdnjs, FlagCDN, Unsplash and Google Fonts each provider's global CDN regions IP, browser, referrer, asset/tile URL and administrator image-search term browser/HTTPS request when the asset or search is used each provider's cache/security policy; Pglemaps is moving toward self-hosting and will not add an unreviewed direct call

Kakao and NAVER domestic processing is not listed as an overseas transfer. Klook, Agoda and Trip.com independently receive data after the user follows an external link; there is no current API that automatically gives them Pglemaps booking or identity data. No PG transfer is listed because the processor has not been selected and payment remains blocked.

Actual processing countries, subprocessors and exact retention periods are continuously checked against signed DPAs and provider materials. Pglemaps does not state an unverified contract fact as certain and will not expand processing before the required evidence and notice are complete.

7. Cookies and Similar Technologies

Pglemaps uses essential technologies for Service operation, login security and language settings. Advertising and analytics are used only after a separate optional choice.

  • Essential cookies: session_id, pglemap_user_session, pglemap_user_csrf and post_admin_session, used to maintain a travel basket, log in, protect against CSRF and operate an administrator session
  • Functional cookies or stored values: language selection, country/city selection, UI state, travel-basket restoration and similar convenience functions
  • Optional analytics/advertising cookies: Google Analytics, Google Tag Manager, Google AdSense, Meta Pixel or affiliate performance events load only after the user chooses “Allow optional cookies.” They never load when authentication cookies are present or on login, registration, account, message, booking, payment or legal pages

Users may reject or delete cookies through their browser settings. Blocking essential cookies may prevent login, travel-basket maintenance, sharing-link restoration, or parts of map and route functions from operating correctly.

8. Behavioral Information and Personalized Advertising

Pglemaps processes behavioral information for Service improvement, advertising measurement and affiliate performance only on reviewed, signed-out public pages after optional-cookie consent.

  • Information: page visits, button clicks, coupon or affiliate-link clicks, travel-basket creation or completion events, registration-completion events, referral paths, browser and device information, and cookie or advertising identifiers
  • Purposes: Service-use statistics, error improvement, advertising-performance measurement, affiliate-conversion measurement, prevention of duplicate exposure, and increased efficiency of interest-based advertising
  • Tools: Google Analytics, Google Tag Manager, Google AdSense, Meta Pixel and affiliate-link tracking tools
  • Retention: Pglemaps internal logs are cleared after their operational purpose is achieved; behavioral information processed by Google, Meta, affiliates and other external providers is governed by their policies and the user's browser or device settings
  • Controls: browser cookie blocking/deletion, device advertising-identifier restrictions, Google advertising settings, Meta advertising settings and browser tracking-prevention functions

9. Generative AI Functions

Travel-basket completion, detailed route summaries, automated posting, booking-request translation and content assistance may use Google Gemini; administrative post translation may use DeepL. An AI request may include itinerary data, place names, addresses or coordinates, movement order, and original user-entered text and language. A booking-request original is sent for translation only after the separate disclosure and consent.

Pglemaps does not use a user's itinerary or prompt to train Pglemaps' own AI model. Data processing by an external AI API provider is governed by that provider's API terms and privacy policy. Do not enter sensitive information such as a passport number, resident registration number, payment information, health information or another person's contact information in an AI-summary request.

A user who does not want to use an AI summary or translation may choose not to run the relevant function. Requests to delete an already-generated AI summary, final itinerary file or sharing-link data, or objections and reports concerning an inappropriate response, may be sent to pglemap@gmail.com.

10. Destruction Procedures and Methods

Pglemaps destroys personal information without delay when the retention period ends or the processing purpose is achieved.

  • Electronic files: deleted or access rights removed so that recovery is difficult
  • Database records: deleted, expired, de-identified, or separately isolated and later destroyed
  • Logs and backups: where immediate operational deletion is difficult, access is restricted and deletion follows the backup-retention cycle or periodic-review process

11. User Rights and How to Exercise Them

A user may request access to, correction or deletion of, or suspension of processing of the user's personal information, may withdraw consent, and may terminate membership. After verifying that the requester is the data subject, Pglemaps processes the request within the period and by the method prescribed by law.

  • Member information: request correction, deletion or withdrawal through account-management functions available after login or through a customer inquiry
  • Sharing-link data: request deletion of a sharing link or deletion before expiration
  • AI summary and final itinerary data: request deletion or correction of user-generated results, or submit an objection or report concerning an inappropriate response
  • Cookie/advertising identifiers: restrict through browser settings, device advertising settings, or advertising settings provided by Google, Meta and other external providers
  • Contact: telephone 010-2743-8473 or email pglemap@gmail.com

A request may be restricted in whole or in part where information must be retained by law or where granting it could infringe another user's rights. Pglemaps will explain the reason for any restriction.

12. Security Measures

Pglemaps applies the following measures to protect personal information:

  • Does not store plaintext passwords and stores scrypt-based password hashes
  • Stores hashes of email-verification tokens, password-reset tokens and login-session tokens
  • Uses secure cookies in HTTPS environments, HttpOnly, SameSite and CSRF tokens
  • Separates administrator sessions and verifies CSRF for administrative functions
  • Applies request rate limits, detects abuse and reviews error logs
  • Minimizes personal-information access privileges and manages production secrets
  • Controls database and server access
  • Manages external API keys and secrets through environment variables or server configuration

13. Personal Information of Children Under 14

Pglemaps does not intend to permit registration or submission of personal information by children under 14. If it confirms that personal information of a child under 14 was processed without the consent of a legal representative, Pglemaps will complete the necessary verification and delete or restrict use of the information.

14. Automated Decision-Making

Pglemaps may use automated processing to sort search results, make recommendations, optimize routes, and process advertising or analytics events. It does not, however, make a decision that produces a legal effect or has a material impact on a user solely through automated processing. Requests for an explanation or action concerning automated processing may be sent to pglemap@gmail.com.

15. Personal Information Protection Officers and Contact Details

  • Business name: Pglemap Co., Ltd. (service name: Pglemaps)
  • Representatives: Kim Jung-hyun and Ko Sang-gyun (Co-CEOs)
  • Business registration number: 360-05-03393
  • Mail-order sales registration number: 2026-Gyeonggi Uiwang-0284
  • Address: Unit 1101, Building 203, 21 Saerom-gil, Uiwang-si, Gyeonggi-do, Republic of Korea (Indeogwon Central Prugio, Poil-dong)
  • Customer Support telephone: 010-2743-8473
  • Personal Information Protection Officers: Kim Jung-hyun and Ko Sang-gyun
  • Contact email: pglemap@gmail.com

Department receiving and processing requests to access personal information: Pglemaps Operations Team

Submission method: telephone 010-2743-8473 or email pglemap@gmail.com

Assistance with personal-information infringement reports, dispute mediation and remedies is also available through the Personal Information Protection Commission's privacy portal, the Personal Information Infringement Report Center, the Personal Information Dispute Mediation Committee and other relevant authorities.

16. Changes to this Privacy Policy

Pglemaps may amend this Policy when Service functions, external APIs, laws or security policies change. For a material change, the effective date, details and reason will be announced through an in-Service notice or the Privacy Policy screen.

Principal changes from the previous Policy:

  • Reflected Pglemaps' actual functions, including the travel planner, sharing links, AI summaries, member and advertiser accounts, coupons and affiliates, and advertising and analytics
  • Changed sharing-link retention to 30 days to match the current code policy
  • Organized external APIs and possible overseas transfers by maps, place search, AI, translation, advertising, social login and affiliate functions
  • Added user booking, payment, cancellation and refund information and statutory retention periods
  • Distinguished the actual code paths for Brevo, Sendon/Kakao AlimTalk, Gemini booking originals, implemented OAuth providers, browser-direct assets and affiliate clicks
  • Reflected the pre-consent analytics/advertising block, sensitive-page exclusion and suspension of Vercel Analytics/AdSense in the guide application
  • Reflected one neutral payment status: no candidate is presented as current and payment remains blocked until contracting, review and notice are complete

sha256-519c1661c78fac8c00622e205684282a16a5ccca

Pglemaps

(주)피글맵 · Representatives 김정현, 고상균

Business Reg. No. 360-05-03393

Mail-Order Sales Reg. No. 제2026-경기의왕-0284호

경기도 의왕시 새롬길 21, 203동 1101호 (포일동, 인덕원센트럴푸르지오)

Phone 010-2743-8473

Email pglemap@gmail.com

Services

  • Travel Guides
  • Instagram
  • Threads
  • Channel Chat

About

  • About Us
  • Contact Us

Help

  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Refund Policy
  • Reviews & Ranking
© 2026 (주)피글맵. All rights reserved.