Rare-On

Privacy Policy

Policy version: 2026.09.07.1 / manual-20260913-privacy-en

Overview

rareon (the "Company") complies with the Personal Information Protection Act and other applicable laws and establishes and discloses this Privacy Policy to process users' personal information securely.

Article 1 (Personal Information Collected and Collection Methods)

① Registration and account management (required): name, email address, password, mobile phone number, and identity verification values (CI/DI, where necessary) — Purpose: member identification, identity verification, prevention of unauthorized use, and delivery of notices

② Registration of children under 14 (required): name and contact information of the legal representative — Purpose: verification of the legal representative's consent

③ Transactions and payments (required when a transaction occurs): settlement account number and account holder name, shipping address, recipient name, and contact information — Purpose: settlement of transaction proceeds, product delivery, and issuance of tax invoices and similar documents (payment card information is processed by the payment service provider, and the Company does not retain full card numbers in principle)

④ Inspection and product management: product photographs, serial numbers, and other product identification information (when registered by a seller)

⑤ Automatically collected information: IP address, cookies, access date and time, service usage records, and device identifiers — Purpose: prevention of unauthorized use, service improvement, and statistical analysis

The Company does not collect personal information beyond the purposes above without the data subject's consent and does not restrict service use because the user declines optional items, except for information required to perform a transaction.

Article 2 (Purposes of Processing Personal Information)

Account management; provision of goods and services, including brokerage, inspection, delivery, and settlement; marketing and advertising where separate consent is given; dispute resolution and complaint handling; and prevention of unauthorized use.

Article 3 (Provision of Personal Information to Third Parties)

As a rule, the Company does not provide a data subject's personal information to external parties. Where necessary to perform a transaction, the Company obtains consent and provides information as set out below in accordance with Article 17 of the Personal Information Protection Act. Separate consent is obtained for use beyond the stated purpose or for any other third-party provision.

RecipientPurpose of provisionInformation providedRetention and use period
Payment service provider (PG)Payment processing and management of settlement fundsPayment information, name, and contact informationRetention period required by applicable law
Courier and logistics service providersProduct deliveryName, contact information, and shipping addressDestroyed without delay after delivery, subject to retention where needed for disputes
Buyer and seller (for direct-shipping transactions)Performance of the transactionName, contact information, and shipping addressDestroyed without delay after completion of the transaction

Article 4 (Outsourcing of Personal Information Processing)

The Company may outsource part of its personal information processing to external providers for efficient service delivery and discloses the processors and outsourced functions in this Policy or through a separate notice, including inspection and logistics providers, customer-support operators, and cloud-hosting providers.

Article 5 (Retention and Use Period of Personal Information)

As a rule, the Company destroys personal information without delay once the purpose of collection and use has been achieved. The following information is retained separately where required by applicable law.

Records retainedRetention periodLegal basis
Records concerning contracts or withdrawal of offers5 yearsAct on Consumer Protection in Electronic Commerce, Etc.
Records concerning payment and supply of goods or services5 yearsAct on Consumer Protection in Electronic Commerce, Etc.
Records concerning consumer complaints or dispute resolution3 yearsAct on Consumer Protection in Electronic Commerce, Etc.
Records concerning labeling and advertising6 monthsAct on Consumer Protection in Electronic Commerce, Etc.
Transaction books and supporting documents5 yearsFramework Act on National Taxes
Records concerning the collection, processing, and use of credit information3 yearsCredit Information Use and Protection Act
Service access logsAt least 3 monthsProtection of Communications Secrets Act

Article 6 (Protection of Children's Personal Information)

The Company obtains consent from a legal representative to process the personal information of a child under 14. The legal representative may request access to, correction of, or deletion of the child's personal information pursuant to Article 22-2 of the Personal Information Protection Act.

Article 7 (Rights and Obligations of Data Subjects and How to Exercise Them)

A data subject may request access to, correction or deletion of, suspension of processing of, or withdrawal of consent to personal information at any time. The Company takes the necessary measures without delay in accordance with applicable law.

Article 8 (Procedures and Methods for Destroying Personal Information)

Personal information stored electronically is permanently deleted using a method that prevents recovery or restoration. Paper documents containing personal information are shredded or incinerated.

Article 9 (Measures to Secure Personal Information)

The Company implements administrative measures, including an internal management plan and access-right management; technical measures, including encryption, access-control systems, and security software; and physical measures, including access control for computer rooms and document-storage areas.

Article 10 (Chief Privacy Officer)

Chief Privacy Officer: Kim Jae-min (CLO) / Contact: 0507-1450-8930, kevin_clo@punkvism.io. Data subjects may contact the Chief Privacy Officer with inquiries, complaints, or requests for relief concerning personal information.

Article 11 (Remedies for Infringement of Rights)

A data subject may seek relief for a personal information infringement by filing a report or requesting advice from the Personal Information Dispute Mediation Committee, the Personal Information Infringement Report Center (dial 118), the Supreme Prosecutors' Office, or the National Police Agency.

Article 12 (Duty to Notify)

Any addition, deletion, or amendment to this Privacy Policy will be announced through a notice at least seven days before its effective date.

Effective date: 2026-09-07