Privacy Policy

Notice of revision · published 25 September 2026

Notice of revision · published 23 September 2026

Effective date: 2026-09-25 (items marked like this take effect 2026-10-23)

Previous effective date: 2026-09-23

In providing the Dear Pantry service we process personal information lawfully and keep it secure, in accordance with the Personal Information Protection Act of the Republic of Korea and related legislation. Under Article 30 of that Act we establish and publish this Privacy Policy so that data subjects are informed of how their personal information is handled and so that related concerns can be resolved promptly.

■ Summary

■ Contents

  1. Purposes, items collected, retention and use periods
  2. Provision to third parties
  3. Entrustment of processing
  4. Transfer abroad
  5. Destruction of personal information
  6. Rights of data subjects and legal representatives, and how to exercise them
  7. Measures to secure personal information
  8. Automatic collection devices and how to refuse them
  9. Usage statistics: what we collect and how to object
  10. Privacy officer and requests for access
  11. Remedies for infringement of rights
  12. Changes to this policy

◼︎ Purposes, items collected, retention and use periods

The personal information we process, its purpose and its retention period are as follows.

AreaPurposeItems collectedRetention and use periodLegal basis
Member management
  • Identification and authentication
  • Maintaining membership
  • Preventing fraudulent sign-up and use
Required: device ID, nickname / Optional: email, password hash, date of birth, gender One year from withdrawal of membership Necessary for performance of the contract
Device authentication and security
  • Device authentication and session management
  • Tracking security events and detecting abnormal access
  • Incident response and operational stability
Required: FCM token, device model, OS name and version, app version name and code, locale, timezone, user agent, client IP, access token hash One year from withdrawal of membership Necessary for performance of the contract
Item management and reminders
  • Creating, editing, deleting and syncing managed items
  • Calculating replacement cycles and sending push reminders
  • Tag-based organisation and storing your memos
Required: item name, product URL, start date, replacement cycle, reminder lead time / Optional: tags, memo, image URL, product lifecycle information One year from withdrawal of membership Necessary for performance of the contract
Consent records
  • Managing consent to the terms of service, this policy, and marketing or push messages
  • Keeping a history of consent changes
Required: consent status and the time it changed One year from withdrawal of membership Legal obligation and legitimate interest
(Optional) Marketing
  • Promotional messages
  • Event announcements
  • Product and service recommendations
Required: marketing and push consent status, FCM token Until consent is withdrawn Consent of the data subject
Family pantry sharing
  • Creating groups, sending invitations and joining
  • Showing items a member chose to share, and sending the related reminders
  • Checking whether an invite link is still valid
Required: group name, invite code and its expiry, member IDs and the time they joined, the items a member chose to share. Items you did not share are not visible to other members. Until you leave or the group is dissolved, or one year from withdrawal of membership Necessary for performance of the contract
Affiliate shopping and settlement
  • Issuing affiliate links and measuring results by screen
  • Checking and reconciling settlement records
  • Preventing click fraud and abuse
Required: the screen the link was opened from (for example, “This week’s list” or a product page — a value that cannot identify you), the issued affiliate link. Order records supplied by the affiliate network in its settlement report (order identifier, product identifier and name, quantity, transaction amount, commission rate and amount, cancellation status). Order records are not linked to members, and we do not receive payment details such as payment method or delivery address. Until settlement and any dispute is resolved (or the period required by the Act on Consumer Protection in Electronic Commerce) Performance of the contract and legitimate interest
from 2026-10-23
Usage statistics
  • Understanding which features are used, to improve the service
  • Checking quality, such as whether reminders arrive and are opened
  • Producing statistics such as the number of active users
  • Activity records: an app session identifier (randomly generated; it changes when the app restarts or you sign out), the kind of action, the screen it came from, and the time received. They contain no member ID, device identifier, advertising identifier, item name, URL or memo.
  • Active-day records: the member ID and the date the service was used (not what was done).
  • Push delivery results: counts of sent, failed and revoked tokens per batch (aggregate figures).
Activity records: 180 days from collection / Active-day records: one year from withdrawal of membership / Push delivery results: kept as aggregate figures Legitimate interest in improving the service

We do not use personal information for purposes beyond those stated above. If a purpose changes we will take the necessary steps, including obtaining separate consent under Article 18 of the Personal Information Protection Act.
We retain and use personal information within the period required by law or consented to by the data subject. However, where any of the following applies, we retain it until that matter ends:
- Where an investigation is under way for a breach of law, until it concludes
- Where obligations remain outstanding from use of the service, until they are settled
- Where a statutory retention period applies, until it ends
 1. Protection of Communications Secrets Act: records of visits to the website (3 months)
 2. Act on Consumer Protection in Electronic Commerce: records of contracts and withdrawal of subscription (5 years)
 3. Act on Consumer Protection in Electronic Commerce: records of payment and supply of goods (5 years)
 4. Act on Consumer Protection in Electronic Commerce: records of consumer complaints or disputes (3 years)
 5. Act on Consumer Protection in Electronic Commerce: records of labelling and advertising (6 months)
 6. Network Act: records of identity verification (6 months)

◼︎ Provision to third parties

We process personal information only within the stated purposes and, as a rule, do not provide it to third parties without your consent.
We may provide it to the minimum extent necessary only where there is a legal basis, or where an exception permitted by the Personal Information Protection Act applies, such as protecting the life, body or property of a data subject.

◼︎ Entrustment of processing

We entrust the following processing in order to provide the service.

ProcessorEntrusted workItems processedRetention and use period
Google LLC (Firebase Cloud Messaging) Mobile push notification delivery FCM token, notification message (title and body), delivery result Until withdrawal of membership or of consent

Our contracts with processors reflect the requirements of the Personal Information Protection Act, including a ban on processing beyond the entrusted purpose, technical and administrative safeguards, restrictions on sub-contracting, and supervision.

◼︎ Transfer abroad

We use Firebase Cloud Messaging (processor: Google LLC) to deliver push notifications, and in doing so the FCM token and notification message may be transferred to servers outside Korea.
The country and storage location may vary with the processor's own infrastructure policy. We verify the safeguards required by law and supervise the processor under contract.
You may raise questions about the transfer, or withdraw consent, through our contact address. Withdrawing consent may limit your ability to receive push notifications.

◼︎ Destruction of personal information

When personal information becomes unnecessary — because the retention period has passed or the purpose has been achieved — we destroy it without delay.
Where other legislation requires us to keep it even after that point, we move it to a separate database or storage location.
Our procedure and method are as follows.
- Procedure: we select the information for which grounds for destruction have arisen and destroy it with the approval of our privacy officer.
- Method: electronic files are destroyed so that the records cannot be recovered; paper documents are shredded or incinerated.
However, where any of the following applies, we retain it until that matter ends:
 1. Where an investigation is under way for a breach of law, until it concludes
 2. Where obligations remain outstanding from use of the service, until they are settled
 3. Where a statutory retention period applies, until it ends
 4. Protection of Communications Secrets Act: records of visits to the website (3 months)
 5. Act on Consumer Protection in Electronic Commerce: records of contracts and withdrawal of subscription (5 years)
 6. Act on Consumer Protection in Electronic Commerce: records of payment and supply of goods (5 years)
 7. Act on Consumer Protection in Electronic Commerce: records of consumer complaints or disputes (3 years)
 8. Act on Consumer Protection in Electronic Commerce: records of labelling and advertising (6 months)
 9. Network Act: records of identity verification (6 months)

◼︎ Rights of data subjects and legal representatives

You may at any time ask us to give you access to your personal information, or to correct, delete or stop processing it.
Requests may be made in writing, by email or by fax under Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and we will act on them without delay.
You may also exercise these rights through a legal representative or an authorised agent. In that case a power of attorney in the form of Appendix 11 of the Public Notice on the Processing of Personal Information (No. 2020-7) must be submitted.
Requests for access and for suspension of processing may be restricted under Articles 35(4) and 37(2) of the Act.
Correction or deletion cannot be requested where other legislation expressly requires the information to be collected.
We verify that the person making a request is the data subject or a legitimate representative.

◼︎ Measures to secure personal information

We take the following measures.
- Administrative: an internal management plan, a dedicated team, and regular staff training
- Technical: access control for systems handling personal information, an access control system, encryption, and installation and updating of security software
- Physical: access control for server rooms and archives

◼︎ Automatic collection devices and how to refuse them

We do not store or operate cookies for sign-in or personalisation.
Temporary data may nonetheless be stored by your browser's own policy when you open our terms pages in a web browser; you can manage this in your device or browser settings.

Detecting a copied product link
Only if you turn on “Detect copied product links” in the app settings, when you return to the app we check on your device whether the clipboard holds a shopping site product address, and ask whether you want to add it. This feature is off by default, the check happens only on your device, and the clipboard contents are sent to our server only if you choose to add the item. A marker that prevents us from asking twice about the same content is stored only on your device. You can turn the feature off at any time in the app settings.

◼︎ Usage statistics: what we collect and how to object from 2026-10-23

We collect usage statistics to see which features are actually used and whether reminders arrive, so that we can improve the service. Collection begins on 23 October 2026; nothing is collected before then.

What we collect
 - Activity records: what you did (for example adding an item, opening a reminder, tapping a shopping link), the screen it came from and the time. An identifier generated at random for each app session is stored with it; that identifier is created anew when the app restarts or you sign out.
 - Active-day records: your member ID and the date you used the service. They do not record what you did that day.
 - Push delivery results: counts per delivery batch.

What we do not collect
 - Activity records contain no member ID, device identifier or advertising identifier. They therefore cannot identify a particular user on their own.
 - They contain no content as such — no item names, memos, product addresses (URLs), invite codes or group names. The kind of action and the screen are recorded only as values from a list we define in advance.
 - We do not track your browsing outside the app, and we do not send this data to third-party advertising or analytics tools. Statistics are stored on servers we operate ourselves in Korea.

Storage and destruction
 - Activity records are deleted by a daily clean-up job 180 days after collection.
 - Active-day records are destroyed within one year of withdrawal of membership.

Objecting and exercising your rights
 - Active-day records are linked to your member ID, so you may request access, deletion or suspension of processing. Email biggatescorp@gmail.com and we will act without delay.
 - Activity records are not linked to an account, so it is not possible to find a particular user's records; they are deleted automatically after 180 days.
 - If you do not agree to statistics being collected, please tell us at biggatescorp@gmail.com and we will explain how collection can be stopped for you. Statistics are not a condition of using the service — every feature remains available whether or not you agree.

◼︎ Privacy officer and requests for access

We have designated the following privacy officer to take overall responsibility for the processing of personal information and to handle complaints and remedies.
You may make a request for access under Article 35 of the Personal Information Protection Act to the department below, and we will handle it promptly.
 - Privacy officer: Lee Tae-yeop (Co-CEO, biggatescorp@gmail.com)
 - Department for access requests: Information Security Team
 - Person in charge: Kwak Ha-min (Privacy Officer in charge, biggatescorp@gmail.com)
You may raise any question, complaint or request for remedy arising from your use of our service with the privacy officer or the department above, and we will respond without delay.

◼︎ Remedies for infringement of rights

We work to guarantee your right to control your own personal information and to provide advice and remedies where it has been infringed. Please contact the department above if you need to report a matter or seek advice.
You may also apply for dispute resolution or advice to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency Privacy Infringement Report Centre, or the bodies below.
 - Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
 - Privacy Infringement Report Centre: 118 (privacy.kisa.or.kr)
 - Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
 - National Police Agency: 182 (ecrm.cyber.go.kr)
A person whose rights or interests are infringed by a disposition or omission of the head of a public institution in response to a request under Articles 35, 36 or 37 of the Personal Information Protection Act may request an administrative appeal under the Administrative Appeals Act.
 - Central Administrative Appeals Commission: 110 (www.simpan.go.kr)

Changes to this policy

We may amend this policy to reflect changes in legislation or in the service, and we announce the reason and the effective date in advance.
For matters that materially affect your rights — such as a change of purpose, provision to third parties or transfer abroad — we give notice at least 30 days before the effective date and obtain separate consent where required.
This policy takes effect on 25 September 2026. The “Usage statistics” items take effect on 23 October 2026 after the advance notice period.

VersionPublishedEffectiveMain changes
v4 2026-09-25 2026-09-25 Removed member-identifying values from affiliate shopping links and stopped linking affiliate order records to members (less collection)
v3 2026-09-23 2026-09-23 / statistics items 2026-10-23 Described family pantry sharing and affiliate settlement (existing features), added collection of usage statistics, added the note on detecting copied product links, and updated the contact address
v2 2026-02-17 2026-02-17 Reorganised device authentication, item management and consent records; disclosed entrustment and transfer abroad

Email: biggatescorp@gmail.com

Ⓒ 2025. Dear Pantry. ALL RIGHTS RESERVED.