ポリシー本文へスキップ

ポリシーレビュー

Privacy Policy — Review Draft

下書き — クライアントによる確認が必要

このレビュー用コピーは、最終的に公開されるストアポリシーではありません。強調表示された項目には、クライアントまたは法務担当者の確認が必要です。

法務本文は現在、レビュー用に英語で提供されています。

About this draft

This English draft describes proposed privacy practices for the Korea eSIM storefront. It is not the final published privacy policy and does not replace the privacy policy currently configured in Shopify.

Review status

  • Legal, operational, and service-provider details remain subject to approval.
  • Customers should use only approved support routes when sharing order information.

Client review required: Identify the legal entity responsible for personal information.

Information we collect

Korea eSIM may collect information a customer provides when browsing, placing an order, requesting Red eSIM support, reserving Gold USIM airport pickup, or contacting support. Depending on the interaction, this may include name, contact information, order and payment status, selected product, device information, pickup location and date, optional arrival details, and support correspondence.

Payment card data may be handled by the selected payment provider rather than stored directly by Korea eSIM. Customers should not send passport numbers, payment card numbers, passwords, or other highly sensitive information through general support messages.

Client review required: Decide whether passport information is collected outside the airport counter.

Client review required: Decide whether passport information is retained outside the airport counter.

Client review required: Approve the secure passport-handling process.

How information is used

Information may be used to process orders, issue Red eSIM setup information, prepare Gold USIM pickup requests, communicate about fulfillment, provide support, prevent fraud, maintain the storefront, meet applicable obligations, and understand service performance.

Operational purposes

  • Confirm payment and order details.
  • Send Red eSIM QR or setup communications.
  • Prepare and support Gold USIM airport pickup.
  • Respond to cancellation, refund, compatibility, and activation inquiries.

Processors and service partners

Personal information may be handled by providers that support ecommerce, payments, customer communications, analytics, email delivery, technical operations, and airport pickup. Information should be limited to what each approved provider needs for its role.

Client review required: Approve the complete processor list.

Client review required: Approve the processor disclosure wording.

International transfers

Customers, storefront infrastructure, and service providers may be located in different countries. Cross-border handling should occur only under the transfer safeguards required for the approved operating model.

Client review required: Select the applicable international-transfer mechanism.

Client review required: Identify the countries affected by international transfers.

Client review required: Approve the customer-facing transfer disclosure.

Retention

Information should be retained only for approved operational, accounting, dispute, fraud-prevention, and legal purposes, then deleted or anonymized under the approved retention schedule.

Client review required: Set the retention period for order information.

Client review required: Set the retention period for support information.

Client review required: Set the retention period for pickup information.

Client review required: Set the retention period for analytics information.

Client review required: Set the retention period for passport-related information.

Privacy rights and choices

Depending on applicable law, a person may have rights to request access, correction, deletion, restriction, objection, or portability, and may be able to withdraw consent where processing relies on consent. Requests may require proportionate identity verification.

Client review required: Approve the deletion-request channel.

Client review required: Approve the deletion-request identity check.

Client review required: Approve the deletion-request response procedure.

Client review required: Identify lawful exceptions to deletion.

Client review required: Identify the jurisdiction governing privacy rights.

Client review required: Approve the privacy complaint route.

Client review required: Approve the regulator disclosure.

Security

Korea eSIM should use administrative, technical, and organizational safeguards appropriate to the approved processing activities. No online transmission or storage method can eliminate every risk, so sensitive information should not be sent through general support channels.

Changes to this policy

An approved policy may be updated when services, providers, legal requirements, or operational practices change. The published version should state its effective date and describe any notice required for material changes.

Contact

Privacy inquiries should be sent through the official privacy route published in the final policy. General order support should remain separate when the request involves privacy rights or sensitive information.

Client review required: Approve the official privacy email address.

Client review required: Approve the privacy mailing address.

Client review required: Assign the privacy escalation owner.

Review checklist

  • Confirm the responsible legal entity.
  • Approve whether and how passport information is collected, retained, and secured.
  • Confirm processors and international-transfer details.
  • Set retention periods for each information category.
  • Approve rights, deletion, complaint, and regulator procedures.
  • Confirm privacy contact details and ownership.