jifei Privacy Policy
corebeau (Korean trade name: 코러보; registered English name: COREBEAU; the "Company") establishes and discloses this Privacy Policy as follows, in accordance with Article 30 of the Personal Information Protection Act (개인정보 보호법, the "PIPA"), in order to protect the personal data of data subjects and to handle related grievances promptly.
This document is not subject to consent; it is subject to disclosure (notice). The consent obtained at sign-up is "consent to the collection and use of personal data," and its content is set by Sections 1 and 2 below.
1. Personal Data the Company Processes
1.1 Items Collected and Purposes
| Item | When and how collected | Purpose of processing | Legal basis | Where it is kept |
|---|---|---|---|---|
| Email address | Social login (Google) | Account identification · prevention of duplicate sign-ups | Consent (PIPA Art. 15(1)1) | The integrated account system operated by the Company |
| Saved sizes | Registered by the Member on a product screen | Notification when conditions change | Consent · performance of the contract | Company database — (product style code, size) + the conditions set by the Member (method of receipt, price cap) |
| Alert records | When a saved condition is met and an alert is generated | Displaying the alert list · preventing duplicate sending | Performance of the contract | Company database — alert type, time generated, time read |
| Expressions of Interest in a buying agent | When the Member presses "I want this" | Gauging demand for a buying agent service | Consent | Company database — (product style code, size, target country) |
| Consent records | When the Member checks the consent items at sign-up | Keeping and proving the fact of consent · determining who must consent again when the terms are amended | Legitimate interests (PIPA Art. 15(1)6) — proving that consent was lawfully obtained | Company database — consent item, version of the document consented to, time of consent, language of the consent screen |
| Service access records | Generated automatically when the Service is used | Ensuring security · responding to outages · preventing fraudulent use · usage statistics | Legal obligation (PIPA Art. 29) · legitimate interests | Company server logs — IP address, date and time of access, request path, browser information |
| Seller page view records | Generated automatically when the Member opens a Seller's product page in the app | Verifying the accuracy of the product information displayed by the Service · preventing fraudulent use | Performance of the contract · legitimate interests (PIPA Art. 15(1)6) | Company database — the address of the product page the Member opened and the time it was opened, and the product information displayed on that page at that time. After 90 days, or upon closure of the jifei account, the link to the Member is severed — see the explanation below |
| Account closure records | When the Member closes their jifei account | Handling of re-registration · managing the destruction deadline for consent records | Legitimate interests (PIPA Art. 15(1)6) | Company database — time of closure, number of items destroyed, destruction deadline for consent records |
| Inquiry and complaint records | When a User sends an inquiry or complaint by email | Handling inquiries and complaints · responding to disputes | Legal obligation (Article 6 of the Act on the Consumer Protection in Electronic Commerce) · legitimate interests | Company email — the sender's email address, the content of the inquiry or complaint, and the result of handling it |
| Error diagnostic information | Generated automatically when an error occurs while the Service is in use | Diagnosing the cause of errors · preventing recurrence | Legitimate interests (PIPA Art. 15(1)6) | The overseas error-diagnostics processor — the address of the screen where the error occurred, the error message and its point of occurrence, browser and device type, time of occurrence. See also Sections 4 and 4.1 |
Information stored in cookies is set out separately in Section 7.
Note: In a Seller page view record, the only information about the Member is "who." Therefore, the Company severs this record's link to the Member instead of deleting the record — from that point on, the Company can no longer know whose record it was, and the information about the Member is thereby destroyed.
The link is severed at whichever of the following two comes first.
- When 90 days have passed from the date of Observation — the Company processes this automatically every day. The purpose for keeping this information linked to the Member requires it only for a much shorter period than that.
- When the Member closes their jifei account.
Note: No value identifying the User and no IP address is attached to error diagnostic information. The Company configures the error diagnostic tool so that it does not send User identification information along with it, and does not turn on the screen-recording feature (session replay). However, the address of the screen where an error occurred may contain search terms entered by the User.
Note: The Company does not collect passwords. At present, sign-up is possible only through a Google account, and the Company keeps passwords neither in plain text nor as hashes. Even if sign-up with email and password is opened, authentication will be performed by the integrated account system operated by the Company, and that system likewise does not keep passwords in a form from which they can be recovered.
1.2 Information the Company Does Not Collect
Payment methods · card numbers · bank account information · shipping addresses · real names · dates of birth · phone numbers
Because the Company does not receive payment for goods and does not deliver goods, it does not need this information. The Company does not take contact details for an Expression of Interest in a buying agent either — because it is a measurement of demand, not the acceptance of an application.
Once the User presses "Go to seller" and moves to a Seller, that Seller's privacy policy applies, and the Company is not involved in the processing that takes place there.
1.3 Right to Refuse Consent and the Resulting Disadvantages
Users may refuse to consent to the collection and use of personal data. However, a User who does not consent cannot create an account and cannot use the Save, alert and Expression of Interest features. The feature for searching products and prices without signing up may be used regardless of whether the User consents.
2. Processing and Retention Periods for Personal Data
| Item | Retention period | Basis |
|---|---|---|
| Account information (email) | Until the Company's integrated account is deleted. Upon closure of the jifei account, separated from jifei usage records | Achievement of the purpose of processing — see the explanation below |
| Saved sizes · alert records · Expressions of Interest in a buying agent | Until the Member closes their jifei account. However, they may be destroyed once 1 year has passed from the date of last use | Achievement of the purpose of processing |
| Consent records | 3 years after the Member closes their jifei account | See the explanation below |
| Service access records | 1 year | Article 29 of the PIPA, Article 30 of the Enforcement Decree of the PIPA (개인정보 보호법 시행령), and Article 8 of the Standards for Measures to Ensure the Security of Personal Information (개인정보의 안전성 확보조치 기준) — see the explanation below |
| Seller page view records | 90 days from the date of Observation. If the Member closes their jifei account before then, upon closure | Achievement of the purpose of processing — the link to the Member is severed at whichever comes first (see Section 1) |
| Account closure records | The same period as consent records (3 years after closure) | This record holds the destruction deadline for consent records |
| Error diagnostic information | Up to 90 days from the date the error occurred | The processor's event retention policy — Section 4 |
| Records of consumer complaints or dispute resolution | 3 years | Article 6 of the Act on the Consumer Protection in Electronic Commerce (전자상거래법) and Article 6 of its Enforcement Decree — see the explanation below |
Note: "Closing the jifei account" and "deleting the account" are different. A Member's account resides in the integrated account system operated by the Company and may also be used for the Company's other services. When a Member closes their jifei account, the information kept by jifei (saved sizes, alert records, and Expressions of Interest in a buying agent) is destroyed without delay and Seller page view records are unlinked from the Member, but the account itself and the email address may remain so that the Company's other services can be used. A Member who wishes the account itself to be deleted may request it by the method in Section 6, and the Company will process the request; in that case, the Member will no longer be able to use any of the Company's services.
Note: Some records remain after the jifei account is closed, for the retention periods in the table above — consent records and account closure records (three years after closure), service access records (one year), error diagnostic information (up to 90 days), and records of consumer complaints or dispute handling (three years). Other information held by jifei is destroyed without delay, or its link to the Member is cut, as described immediately above. Why consent records are kept — the fact that consent was obtained and the version it covered are materials proving the lawfulness of the consent; if they were destroyed at the moment of closure, the Company could no longer prove the very fact that it lawfully obtained consent. These records contain only a value identifying the User and the consent item, version, time, and screen language, and do not include saved sizes or alert contents. The period was set at 3 years in consideration of the period during which the lawfulness of consent may be disputed, and it is the same length as the retention period that Article 6 of the Enforcement Decree of the Act on the Consumer Protection in Electronic Commerce sets for records of consumer complaints and dispute resolution.
Note: About "usage statistics." From the server records above, the Company aggregates how many people viewed which screens. What remains as the result of aggregation is numbers; the Company does not create lists or profiles of individual Users. This is not for advertising, is not provided to third parties, and no new items are collected for this purpose — the records already described above are used as they are. The Company does not install tools for tracking in Users' browsers or devices (Section 7).
Note: "Service access records" contain two things together. One is the server log in which Users' requests are recorded; the other is the "access logs" (records of personal data handlers accessing the personal data processing system) that the PIPA and its subordinate statutes require to be kept for at least 1 year. Because the Company keeps both in the same store, it applies 1 year, the longer of the two.
Note: About records of consumer complaints and dispute resolution. The Company applies this period on the premise that it is regarded as an online marketplace intermediary (mail-order brokerage). When an inquiry or complaint is received, its content and the result of handling it are kept for 3 years; the channel for receipt is the email address in Section 6(3).
Because the Company is not involved in the sale, payment, or delivery of goods, it does not keep records on contracts or withdrawal of offers, payment, or the supply of goods.
3. Provision of Personal Data to Third Parties
The Company does not provide Users' personal data to third parties. This does not apply, however, where laws or regulations specifically provide otherwise or where an investigative agency requests it in accordance with the procedures and methods prescribed by laws or regulations.
Note: The links in the Service that take Users to Sellers are not a provision of personal data. The Company does not tell Sellers which User pressed a link.
Note: "Provision to third parties" and "entrustment of processing" are different. Processors that process data for the Company and on the Company's instructions (cloud and error diagnostics) are not a provision to third parties and are set out separately in Section 4.
4. Entrustment of Personal Data Processing
| Processor | Entrusted work | Retention and use period |
|---|---|---|
| Amazon Web Services Korea LLC (아마존웹서비시즈코리아 유한책임회사; Amazon Web Services) | Provision of cloud infrastructure (servers, databases, file storage · content delivery (CDN) · sending account-related email) for operating the Service | Until the entrustment contract ends |
| Functional Software, Inc. (Sentry) | Automatic collection and diagnosis of errors occurring in the Service | Up to 90 days from the date the error occurred |
When entering into an entrustment contract, the Company specifies in the contract, in accordance with Article 26 of the PIPA, matters concerning responsibility, such as restrictions on re-entrustment, security measures, management and supervision, and compensation for damages.
The Company operates the integrated account system itself. Account creation and authentication are processing within the Company, so they do not constitute entrustment and are not listed separately in this table (account-related email is sent using the sending function of the cloud processor above). A Member's account may also be used for other services operated by the Company, but this is use within the same personal data controller and not a provision to third parties.
4.1 Cross-Border Transfer
Users' account information and Service usage records are not transferred outside the Republic of Korea. The Company's servers and databases are operated in a region within the Republic of Korea (ap-northeast-2, Seoul), and the counterparty to the cloud contract is also a Korean entity (Amazon Web Services Korea LLC). However, when you connect from abroad, your requests pass through a delivery point outside Korea close to you (content delivery — Section 4); they are processed there only for as long as needed to deliver them and are not stored there — service access records are kept in the Korean region.
However, the "error diagnostic information" in Section 1 is transferred to the United States. Because this constitutes entrustment of processing necessary for the performance of a contract under Article 28-8(1)3 of the PIPA, the Company discloses the matters listed in the subparagraphs of paragraph (2) of that Article as set out below in lieu of consent, and does not obtain separate consent.
| Matter to be disclosed | Details |
|---|---|
| Items of personal data transferred | The address of the screen where the error occurred, the error message and its point of occurrence, browser and device type, time of occurrence. No User identification information or IP address is attached (Section 1) |
| Country to which data is transferred | United States of America — where error events are stored. However, the recipient's affiliates and sub-processors may also process this information in Canada · Austria · the Netherlands for the operation and support of the service. The recipient publishes the current list of sub-processors at sentry.io/legal/subprocessors/ |
| Time and method of transfer | From time to time, whenever an error occurs in the Service; transmitted over encrypted communication (HTTPS) |
| Recipient | Functional Software, Inc. (d/b/a Sentry) · 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA · compliance@sentry.io |
| Recipient's purpose of use | Collection and storage of Service errors, and support for their diagnosis. Not used for any other purpose |
| Recipient's retention and use period | Up to 90 days from the date the error occurred |
Note: About re-entrustment (sub-processing). The recipient entrusts part of the processing in turn to cloud infrastructure providers, affiliates, and others. The Company consented to that re-entrustment in advance through the recipient's data processing agreement (Article 26(6) of the PIPA), and is notified of changes to the list of sub-processors and may object to them. If sub-processors are added and the countries to which data is transferred change, the Company will update this Section.
Note: There is no on-screen switch to turn this off. This information is not sent at the User's request but is generated automatically when an error occurs, so there is no point at which it can be turned off or on for each User. Instead, the items sent have themselves been narrowed as described above. Users do have the right to demand that this processing be stopped (demand to suspend processing — Section 6(1)4), and such demands are received through the channel in Section 6(3). Effect of refusal (suspension of processing) — error diagnostic information carries no value that identifies the User, so the Company cannot single out and stop transmission for a particular User. To refuse, block the error-reporting address (sentry.io) with your browser's content-blocking feature; doing so does not affect your use of the Service — the Company simply cannot diagnose errors that occur in that browser.
5. Procedures and Methods for Destroying Personal Data
- When personal data becomes unnecessary because the retention period has expired or the purpose of processing has been achieved, the Company destroys that personal data without delay (within 5 days, unless there is a justifiable reason).
- Where personal data must be preserved under other laws or regulations, the Company preserves it by moving it to a separate database or by storing it in a different location.
- The methods of destruction are as follows.
- Electronic files — permanent deletion by a method that prevents recovery or restoration
- Paper documents — shredding or incineration
- Where only part of a record is personal data, the Company may destroy it by erasing that part so that the individual can no longer be identified. Seller page view records are such a case: once the link to the Member is severed, the individual can no longer be identified, and the record is not personal data (see Section 1).
6. Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them
- Users may exercise the following rights against the Company at any time.
- Demand for access to personal data (Article 35 of the PIPA)
- Demand for correction where there are errors or the like (Article 36)
- Demand for deletion (Article 36)
- Demand to suspend processing (Article 37)
- Withdrawal of consent and closure of the jifei account
- The following rights may be exercised directly on screens within the Service.
- Access — "Download my data" on the Manage account screen (JSON file)
- Deletion and suspension of processing — saved sizes one at a time on the Alerts screen; all of them through "Close your jifei account" on the Manage account screen
- Other demands (correction, deletion of the account itself, access to Service access records and to account information (email)) may be made by email to junsoo.ahn@corebeau.ai or in writing (the Company's address is displayed at the bottom of the Service screens), and the Company will take action and inform the User of the result within 10 days from the date it receives the demand.
- In accordance with Article 38(4) of the PIPA, the Company makes the methods and procedures for exercising rights no more difficult than the methods by which it collects personal data — because sign-up takes place on screen, closing the jifei account also takes place on screen. Note: However, two matters are handled only through the channel in paragraph (3). (i) Closing the jifei account is not deletion of the account itself (see Section 2). (ii) Service access records and account information (email) are not included in the download file — access records are kept in server logs and account information in the integrated account system, so they cannot be provided through that route.
- Rights may also be exercised through a legal representative or a person delegated by the User; in that case, a power of attorney must be submitted.
- Users must not infringe the personal data or privacy of others processed by the Company in violation of the PIPA or other relevant laws and regulations.
- Children under the age of 14 may not sign up as Members, and the Company does not collect personal data of children under the age of 14.
7. Devices That Automatically Collect Personal Data (Cookies)
The Company uses cookies to keep Users signed in, to complete the sign-up process, and to remember the display settings the User chose (language · delivery country · currency). The Company does not use tracking tools for advertising or for analyzing User behavior — it does not install tools that collect advertising identifiers or behavioral information, and it does not record Users' screens. The Company does use a tool for diagnosing errors in the Service, as described in Sections 1, 4, and 4.1. That tool does not use cookies.
Note: However, the address and time of the Seller product pages a Member opens in the app, and the product information displayed on that page at that time, are recorded ("Seller page view records" in Section 1). This is not for advertising or profiling, and the link to the Member is severed after 90 days or upon closure of the jifei account.
| Cookie | Purpose | Retention period | Remarks |
|---|---|---|---|
jf_at | Keeping the User signed in (authentication token) | 1 hour | httpOnly — cannot be read by scripts |
jf_rt | Extending sign-in (refresh token) | 30 days | httpOnly |
jf_in | A value for indicating whether the User is signed in (not a token) | 30 days | Used only for on-screen display |
jf_cs | Temporary storage of the sign-up consent items, versions, time of consent, and screen language | 1 hour | httpOnly · see the explanation below |
jifei-lang | Remembers the display language the User chose | 1 year | Stored only when the User chooses |
jf_to · jf_to_src | Remembers the delivery country the User chose (or that was set from the browser's region) and where that value came from | 1 year | Contains only a country code and its source (automatic · chosen) |
jf_cur | Remembers the display currency the User chose | 1 year | Stored only when the User chooses |
jf_fresh | Marks a reload by a screen that failed to load the list, so that it does not receive the stored failure screen | 20 seconds | Find screen only |
jf_cs contains the items the User consented to at sign-up, the versions of those documents, the time of consent, and the language of the consent screen. Consent is obtained before the account is created, but recording it requires an account, so this value is kept temporarily in the browser only until the social login process is complete and the account is confirmed. It is deleted immediately once recording is complete and expires after 1 hour at the latest. It contains no information identifying the User, such as name or email.
The language, delivery country, currency and reload cookies contain no information that identifies the User and are used only to remember those choices for the next visit.
Users may refuse the storage of cookies in their web browser settings. However, a User who refuses authentication cookies cannot use the features that require sign-in (Save and alerts).
The screen brightness setting (light/dark) is kept in the browser's local storage, not in a cookie, and does not leave the User's device.
8. Measures to Ensure the Security of Personal Data
In accordance with Article 29 of the PIPA and Article 30 of the Enforcement Decree of the PIPA, the Company takes the following measures.
- Administrative measures
- Minimizing the number of personal data handlers, and granting differentiated access rights
- Internal management plan — The Company is a small business owner that processes personal data concerning fewer than 10,000 data subjects, and accordingly, under the proviso to Article 4(1) of the Standards for Personal Information Security Measures (개인정보의 안전성 확보조치 기준), it has not established an internal management plan. When the number of data subjects reaches 10,000, the Company will establish and implement one.
- Technical measures
- Management of access rights to the personal data processing system, and retention of access logs for at least 1 year
- Encryption in transit (HTTPS)
- Delivering authentication tokens only in httpOnly cookies that scripts cannot read, and using
SameSite=Laxso that authentication cookies are not attached to requests sent from other sites (except when the User follows a link to the Service) - An architecture that does not keep passwords in a recoverable form — authentication is performed by the integrated account system operated by the Company, and the jifei Service does not receive passwords
- Malware prevention — the personal data processing system is periodically replaced by rebuilding it from images that incorporate security updates, and on the work devices of personal data handlers, the malware-blocking features provided by the operating system are turned on and security updates are applied automatically
- Physical measures — provided through the cloud provider's data center access controls
9. Automated Decisions
The Company does not make automated decisions using personal data. The Company does not analyze Users' personal data to make decisions that have a legal effect or a comparably significant effect on Users, and the order of the products and prices displayed on screen is determined not by Users' personal data but by the observed prices and stock and the search conditions selected by the User. (Article 37-2 of the PIPA)
10. Chief Privacy Officer
Users may direct all inquiries, complaints, and requests for remedies relating to personal data protection to the contact below, and the Company will respond and handle them without delay.
- Chief Privacy Officer — Junsoo Ahn (안준수) / Representative
- Contact — junsoo.ahn@corebeau.ai
11. Remedies for Infringement of Rights and Interests
To obtain remedies for infringement of personal data, Users may apply to the organizations below for dispute resolution or counseling.
| Organization | Phone | Website |
|---|---|---|
| Personal Information Dispute Mediation Committee (개인정보분쟁조정위원회) | 1833-6972 | www.kopico.go.kr |
| Personal Information Infringement Report Center (개인정보침해신고센터), Korea Internet & Security Agency (KISA) | 118 (no area code) | privacy.kisa.or.kr |
| Cyber Investigation Division, Supreme Prosecutors' Office (대검찰청 사이버수사과) | 1301 (no area code) | www.spo.go.kr |
| Cyber Investigation Bureau, Korean National Police Agency (경찰청 사이버수사국) | 182 (no area code) | ecrm.police.go.kr |
In addition, a person whose rights or interests have been infringed by a disposition or omission of a public institution in response to a demand under Article 35, 36, or 37 of the PIPA may file an administrative appeal as prescribed by the Administrative Appeals Act (행정심판법).
12. Changes to the Privacy Policy
- This Privacy Policy applies from October 15, 2026 (first in force September 8, 2026).
- When the Company changes this Privacy Policy, it announces the reasons for and content of the changes through a notice within the Service starting 7 days before the changes take effect. However, where there is a material change to Users' rights, the Company announces it starting 30 days before.
- The Company also posts earlier versions within the Service so that Users can directly compare and confirm the content before and after a change.
13. For Users Residing in Japan
Because the Company also provides the Service to Users residing in Japan, it announces below the matters that the Act on the Protection of Personal Information of Japan (the "APPI") requires to be made public. Matters not set out in this Section follow the other Sections of this Privacy Policy.
| Matter | Content |
|---|---|
| Business operator handling personal information | corebeau (Korean trade name: 코러보) · Representative: Junsoo Ahn · the address and contact details are displayed at the bottom of the Service screens |
| Purposes of use | Limited to the purposes set out in the table in Section 1 |
| Country in which personal data is handled | The Republic of Korea — the Company takes the security measures in Section 8 with an understanding of the Republic of Korea's personal information protection system (the Personal Information Protection Act) |
| Requests for notification of purposes of use, disclosure, correction, suspension of use, or suspension of provision to third parties of retained personal data | May be made by the methods in Section 6. Requests are accepted in Korean, English, or Japanese |
| Security control measures | Section 8 |
| Provision to third parties in foreign countries | The Company does not provide Users' personal data to third parties in foreign countries. The error diagnostic information in Section 4.1 is designed not to carry any value that identifies the User or the IP address, and is therefore not provided to the processor in the United States as personal data |
| External transmission of user information | The only information sent from the User's browser outside the Company is error diagnostic information — recipient: Functional Software, Inc. (Sentry) · information sent and purpose: Section 4.1 · how to stop it: "Effect of refusal (suspension of processing)" in Section 4.1. There is no external transmission for advertising or analytics (Section 7) |
| Contact point for inquiries and complaints | The Chief Privacy Officer in Section 10 |
14. Language of This Privacy Policy
- This Privacy Policy is made in Korean and English, and the two versions have equal force.
- Where the two versions differ in interpretation, the interpretation more favorable to the User prevails.
- Any version the Company provides in another language is a reference translation for convenience only and has no legal effect.
Revision History
| Version | Effective date | Changes |
|---|---|---|
| 1.0 | 2026-09-08 | Initial adoption |
| 1.1 | 2026-10-15 | Corrected "Only consent records remain after the jifei account is closed" in Section 2 to follow the table · added inquiry and complaint records to the table in Section 1 and corrected the legal basis for consent records · added Expression of Interest to Section 1.3 (consequences of refusing consent) · stated in Sections 4 and 4.1 content delivery (CDN) and account email sending, delivery points outside Korea, how consent to re-entrustment is given, and how to refuse the cross-border transfer (suspension of processing) and its effect · stated in Section 6 how to access account information (email) and the address for written demands · stated in Section 7 the display-setting cookies (language, delivery country, currency, reload) and the scope of page view records · corrected the SameSite explanation in Section 8 · added the Security Measures Standards to the basis for access records in Section 2 · added Section 13 (For Users Residing in Japan) · added Section 14 (Language of This Privacy Policy) — the Korean and English versions (in force together from this amendment) have equal force · because the two versions share a version number, added the language of the consent screen to consent records in the table in Section 1 and to jf_cs in Section 7, so that it is recorded which version the User consented to — apart from this item, the items collected and the retention periods do not change, and the rest describes processing already carried out more accurately |