







MEETKAT (the "Service") complies with the Personal Information Protection Act and other applicable laws, and processes users' personal information as follows.
The Service provides a procedure for users to review the terms of use and the details of personal information collection and use, and to click the "Agree" button when signing up, making a guest reservation, or converting to a business account. Users are deemed to have consented to the collection and use of their personal information by clicking "Agree".
"Personal information" means information about a living individual that can identify that person, including information that can easily be combined with other information to do so. The Service collects and uses the following: 1. General members (at sign-up) - Mandatory: email, password, nickname - Optional: mobile phone number, profile image, introduction, date of birth, gender, country and preferred language, neighbourhood (activity area), preferred categories - Purpose: member identification and management, reservation services, notices, customer support * The mobile phone number is currently <b>stored without identity verification</b> and is not used for identity checks, notifications, or no-show history. Once business registration and SMS delivery are in place we will offer verification, and only verified numbers will be used for reservation notices and linking reservation history. You can delete it at any time before verification. - Retention: destroyed after the 30-day recovery grace period following withdrawal 2. Guest reservations (booking without signing up) - Mandatory: email or mobile phone number (to deliver the confirmation and management link) - Conditional: age (date of birth), gender, and neighbourhood, but only where the provider has required them as a condition of the reservation - Purpose: reservation confirmation and notices; the provider's decision on whether to accept the reservation - Retention: until 2 years after the reservation ends (Article 4) or the statutory retention period, whichever is longer 3. Business members (at business account conversion) - Mandatory: business name, contact number, business address and location - Optional: business registration number (verification), business introduction and images - Purpose: business listing, reservation management, subscription management * A business address is publicly listed business information, not an individual's location data. 4. Generated during service use - Reservation history, QR check-in (visit/no-show) records, MeetLogs, reviews and comments, chat messages, notification history, reports and blocks - Access IP address, access time, device and browser information (User-Agent), service usage records (collected automatically) - Purpose: preventing fraud and abuse, establishing the facts in reservation disputes, responding to security incidents, and diagnosing failures - The IP and device information captured when a reservation is created is retained as dispute evidence and is accessible only to administrators. - Text that users write and publish (business introductions, product and option information, MeetLog captions, review text) may be automatically translated and shown to users of other languages. How translation is processed is described in Article 6. 5. Information the Service does NOT collect - Payment information: the Service does not provide in-app payment and therefore does not collect card numbers or similar data. - Personal location data: the Service does not collect, use, or store your device location (GPS coordinates). "My neighbourhood" is an administrative district (dong/eup/myeon) that you select yourself by searching; the Service does not track your real-time location.
The Service uses cookies and browser storage to keep users signed in (authentication tokens), store language and display settings, and analyze usage statistics. Users may refuse or delete them in their browser settings (Chrome: Settings > Privacy and security > Cookies / Safari: Settings > Privacy). Refusing may limit some features such as staying signed in.
1) Personal information is destroyed without delay once the purpose of collection and use has been fulfilled. Upon membership withdrawal, it is destroyed after a 30-day recovery grace period. 2) To prevent re-registration abuse (such as laundering no-show history), contact details (email, phone number) are converted into irreversible one-way hashes and stored separately upon withdrawal. The original contact details cannot be recovered from these hashes, and they are not used for any purpose other than determining whether the same person is re-registering. 3) Personal information of members inactive for two (2) years or more is destroyed or stored separately after notice. Information about guests who booked without signing up is likewise destroyed 2 years after their last reservation ends. 4) The following records are retained as required by law: - Records on contracts or withdrawal of offers: 5 years (E-commerce Act) - Records on the resolution of consumer complaints or disputes: 3 years (E-commerce Act) - Log-in records: 3 months (Protection of Communication Secrets Act) 5) Destruction method: electronic files are deleted using technical methods that prevent recovery, and printed materials are shredded or incinerated.
The Service does not provide personal information to third parties beyond the scope of Article 2, except in the following cases: 1) Provision to the provider in order to fulfil a reservation (a core function of the Service) When you make a reservation, the following is provided to that provider so they can decide whether to accept it and can carry it out. This is essential to the reservation service itself. - Nickname and profile image - Reservation date and time, product, and requests - A means of contact (email or phone number). Depending on the provider's settings this may be shown partially masked. - Your record of keeping appointments (no-show and visit counts). This is reference information about reservation reliability; its nature and the objection procedure are governed by Article 7 of the Terms of Service. - Age, gender, and neighbourhood, but only where the provider required them as a condition of the reservation and you consented * You can adjust what is disclosed in Settings, and once the viewing period ends the provider can no longer see this information. 2) When requested by investigative agencies through lawful procedures in accordance with applicable laws 3) When provided in a form that cannot identify individuals, for statistics or research
The Service outsources personal information processing as follows: - Server and database operation: Amazon Web Services (Republic of Korea region) - File storage (images and similar): Cloudflare - Email delivery: Amazon Web Services - Automatic content translation: Google LLC (Google Cloud Translation) * Shared information is limited to the minimum required, and any change of contractors will be announced in advance through this policy. * The Service's servers are located in the Republic of Korea. File storage may be located outside Korea; in that case the only items stored there are image files uploaded by users. * For automatic translation, the only things sent to Google are the text to be translated (business introductions, product and option information, MeetLog captions, review text) and the target language. Information that identifies the author or the viewer, such as account details, contact information or access records, is not sent with it. However, if the author wrote personal information inside the text, that content is sent as part of the text. * The text is sent over an encrypted connection when a user of another language views it, and may be processed outside Korea (in countries where Google operates servers). Under Google's Cloud Translation data usage policy, the text is handled only temporarily while the translation is performed and is not used to train translation models or provided to third parties. Translation results are stored in the Service's database (Republic of Korea).
1) Users may view or modify their personal information at any time in the Settings screen, or request access or correction from the chief privacy officer in writing or by email. 2) When correction of an error is requested, the information is neither used nor provided until the correction is completed. 3) If incorrect information has already been provided to a third party, the result of the correction is notified without delay so it can be corrected.
Users may withdraw consent to collection and use at any time through the membership withdrawal function in Settings or by contacting the chief privacy officer. Accounts can be recovered by signing in again within 30 days of withdrawal; after the grace period, the information is destroyed in accordance with Article 4.
In accordance with Article 29 of the Personal Information Protection Act, the Service: 1) stores passwords with irreversible one-way encryption and never keeps them in plain text; 2) applies transport encryption (HTTPS) and token-based access control; 3) keeps access logs protected against forgery and alteration, and minimizes access privileges to personal information.
The Service does not allow children under fourteen (14) years of age to sign up. If such a child is found to have signed up through identity theft or misuse, their legal representative may exercise all rights over the child's personal information.
The mobile app requests device permissions for the features below. All permissions are <b>optional</b>: if you decline, you can still use the Service in full except for the specific feature concerned. 1) Camera (optional) - Purpose: scanning QR codes to confirm your visit at a venue; taking photos for meet logs and profile images - If declined: you can use photos already in your library, and confirm your visit with the reservation code instead of a QR scan. 2) Photos (optional) - Purpose: selecting images to attach to meet logs and profile pictures - If declined: only image attachment is unavailable. 3) Calendar (optional) - Purpose: automatically adding, updating, and removing your reservations in the device calendar - If declined: reservations remain viewable in the app; only automatic calendar sync stops working. Note: updating or deleting an event we previously created requires read access, so read and write permissions are requested together. We do not read or use any events other than those created by the Service. 4) Notifications (optional) - Purpose: alerts for reservation confirmations and changes, upcoming visits, and incoming messages - If declined: the same information is available in the in-app notification inbox and by email. Permissions are requested when you first use each feature, never all at once on launch. You may withdraw any granted permission at any time in your device settings. - Android: Settings > Apps > MEETKAT > Permissions - iOS: Settings > MEETKAT
The Service appoints a chief privacy officer responsible for overseeing personal information processing and handling related complaints and remedies. - Name: hani son - Title: Representative - Contact: privacy@meetkat.app
This policy takes effect on its effective date. Any addition, deletion, or modification under laws or service policies will be announced through notices at least seven (7) days before taking effect.
This policy takes effect on 2026-10-06. (Previous version: 2026-08-03)