Privacy Policy

2026. 8. 10.

Privacy Policy

  • Effective Date: 2026.08.10

  • Company: Sellking (Maedowang Co., Ltd.)

  • Service: Momocall

Article 1. Purpose

Sellking (Maedowang Co., Ltd.; the “Company”) establishes and publishes this Privacy Policy (the “Policy”) to protect the information (“Personal Information”) of individuals (“Users” or “Individuals”) who use Momocall (the “Company Service”), a service provided by the Company; to comply with applicable laws and regulations, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (the “Information and Communications Network Act”); and to promptly and effectively handle complaints relating to the protection of Users’ Personal Information. In addition to Momocall’s call and message data analysis features, this Policy covers Personal Information additionally processed for the operation of the reward point service, mobile phone identity verification, verification of the one-person-one-account principle, prevention of fraudulent use, withholding and submission of statements of payment in connection with prizes, and Keyword-Based Personalized Advertising Recommendations (optional).

Article 2. Personal Information Processed by Purpose and Retention and Use Period

The Personal Information processed by the Company, the purposes of processing, and the applicable retention and use periods are as follows.

Category

Personal Information Processed

Purpose of Processing

Retention and Use Period

Membership Registration and Management (Required)

Email address (ID), login account identifier (such as a social account ID), name or nickname, password (hashed value), Service usage history (registration date, withdrawal date, and login records), smartphone device information (device model, OS version, app version, and device identifier), access IP address, access date and time, Service usage logs, failure and error logs, and history of improper use

Member identification and identity confirmation, account creation and management, prevention of fraudulent use and abnormal activities, management of Service usage history, delivery of notices, alerts, and important announcements, response to customer inquiries, and complaint handling

Until termination of the Service Agreement and membership withdrawal. However, where retention is required under applicable laws and regulations, the information shall be separately retained for the applicable statutory period (see the separate table below).

Customer Inquiries and Complaint Handling (Required)

Email address, inquiry details, conversation records generated during the inquiry or consultation process (such as email and chat records), account information (ID and Service usage history), and contact information

Receipt and handling of Member inquiries, consultations, and complaints; response to Service failures and errors; handling and response in the event of disputes; and management of consultation history

Three years after completion of the inquiry or complaint handling, pursuant to the obligation to retain records of consumer complaints and dispute handling under the Act on the Consumer Protection in Electronic Commerce, Etc., after which the information shall be destroyed without delay.

Marketing and Event Notifications (Optional)

Mobile phone number, email address or social account ID, app push token (token used to identify the device), Service usage records (such as general usage type and frequency), and event participation history

Provision of Service-related news, notices of feature or pricing plan changes, event and promotion notices, personalized notices, and marketing communications intended to expand Service use

Until withdrawal of optional consent or membership withdrawal. However, where retention is required under applicable laws and regulations, the information shall be retained for the applicable statutory period.

Fee Settlement, Payment, and Refunds (Required)

Paid Service usage records, purchased product information, payment amount, payment date and time, payment approval and cancellation history, refund history, and marketplace payment identifiers (such as Google Play or Apple App Store payment IDs)

Billing and payment processing for paid Services (such as subscriptions and passes), refund and cancellation processing, settlement of overpayments and unpaid amounts, and response to payment-related complaints

Until termination of the Service Agreement and membership withdrawal

Point Service Operation (Required)

Point accrual and use history, Reward Activity history (records of advertisement viewing and call event participation), statistics on call duration and number of calls (Note: original call contents and audio files are not included in this category), and Point Store product exchange history

Provision of reward point accrual and settlement services and Point Store product exchange services, and delivery of exchanged products (such as mobile gift certificates)

Until membership withdrawal or expiration of the Points. Information subject to a retention obligation under the Act on the Consumer Protection in Electronic Commerce, Etc. shall be separately retained for the applicable statutory period.

Mobile Phone Identity Verification and Verification of Reward Recipients (Required at a time announced in advance by the Company)

Name, date of birth, gender, Korean or foreign national status, mobile phone number, Connecting Information (CI), Duplication Information (DI), and mobile carrier information

Mobile phone identity verification; verification of the one-person-one-account principle and prevention of duplicate account creation; prevention of fraudulent accrual and use of reward Points; identification of reward recipients; and delivery of exchanged products such as mobile gift certificates

Name, date of birth, gender, mobile phone number, CI, and DI shall be retained until membership withdrawal. After withdrawal, such information shall be separately retained for the period specified in the “Prevention of Fraudulent Use” category below. Korean or foreign national status and mobile carrier information shall be destroyed without delay after identity verification is completed. Information that must be separately retained under applicable laws and regulations shall be segregated and retained for the applicable statutory period.

Withholding and Submission of Statements of Payment Relating to Prizes (Limited to winners of prizes for which the applicable obligation arises)

Name, resident registration number, Korean or foreign national status, prize payment details (prize name, value, and payment date), necessary expenses, other income amount, applicable tax rate, income tax, and local income tax

Delivery of prizes; withholding, reporting, and payment of taxes on other income; preparation and submission of statements of payment; and issuance of withholding tax receipts

Five years from the day following the statutory national tax filing deadline for the taxable period in which the relevant transaction occurred, after which the information shall be destroyed without delay

Prevention of Fraudulent Use (Required)

Encrypted and hashed values of CI and DI; mobile phone number; date of birth; gender; device ID (device_id); advertising identifiers (Android ADID and iOS IDFA); SSAID; device model; operating system and app versions; access IP address; Service access records; Point accrual and use records; and records of the detection of and measures taken against fraudulent use

Prevention of repeated receipt of rewards through re-registration after membership withdrawal; detection and blocking of multiple accounts operated using the same identity verification information or device information; detection and blocking of abnormal reward accrual or use; recovery of fraudulently accrued or used rewards; restriction of re-registration by fraudulent Users; and handling of objections

Encrypted and hashed values of CI and DI; mobile phone number; date of birth; gender; device_id; Android ADID; iOS IDFA; SSAID; device model; operating system and app versions; access IP address; Service access records; and Point accrual and use records shall be separately retained for 60 days from the date of membership withdrawal and then destroyed. However, the relevant information of a Member confirmed to have engaged in fraudulent use, together with records of the detection of and measures taken against the fraudulent use, shall be separately retained for one year from the date of membership withdrawal and then destroyed. Records that must be separately retained under applicable laws and regulations shall be segregated and retained for the applicable statutory period.

Keyword-Based Personalized Advertising Recommendations (Optional, Separate Consent)

Keywords extracted by the Company from call contents (processed in de-identified form and separated from Member identifiers), advertising identifiers (Android ADID and iOS IDFA), and consent and withdrawal records and timestamps

Extraction of advertising-matching keywords and provision of advertisements based on the Member’s separate consent

Destroyed immediately upon withdrawal of consent or membership withdrawal. Consent and withdrawal records shall be separately retained for three years from the termination of consent for dispute-response purposes.

When a Member proceeds with mobile phone identity verification, the Company receives identity verification result information through an identity verification service linked by NHN KCP Corp.

When the Company provides a prize that gives rise to an obligation to withhold income tax or local income tax or to submit a statement of payment, the Company informs the winner of the purpose of processing, the Personal Information processed, and the retention period and directly collects the required information through a separate secure input method. Such information is processed separately from general membership information and mobile phone identity verification result information. The Company processes resident registration numbers only when necessary to fulfill the applicable obligation and does not collect them as required information for membership registration or ordinary reward accrual or exchange.

The 60-day and one-year retention periods following membership withdrawal are based on the Company’s fraudulent-use prevention policy. The Company retains the relevant information separately from general membership information, does not use it for any other purpose, and destroys it without delay upon expiration of the applicable retention period.

Personal Information being processed shall not be used for any purpose other than those stated above. If a purpose of use changes, the Company shall take necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.

The Company processes and retains Personal Information within the retention and use periods prescribed by applicable laws and regulations or consented to by the Data Subject at the time the Personal Information is collected.

Information Retained and Retention Periods Under Applicable Laws and Regulations

Applicable Law

Information Retained

Retention Period

Act on the Consumer Protection in Electronic Commerce, Etc.

Records concerning contracts or withdrawal of offers

Five years

Act on the Consumer Protection in Electronic Commerce, Etc.

Records concerning payment and supply of goods, etc.

Five years

Act on the Consumer Protection in Electronic Commerce, Etc.

Records concerning consumer complaints or dispute handling

Three years

Act on the Consumer Protection in Electronic Commerce, Etc.

Records concerning labeling and advertising

Six months

Protection of Communications Secrets Act

Website log records

Three months

Electronic Financial Transactions Act

Records concerning electronic financial transactions

Five years

Act on the Protection and Use of Location Information

Records concerning Personal Location Information

Six months

Framework Act on National Taxes

Books and supporting documents relating to withholding and submission of statements of payment in connection with prizes

Five years from the day following the statutory national tax filing deadline for the taxable period in which the relevant transaction occurred

Article 3. Provision of Personal Information to Third Parties

  1. The Company processes Data Subjects’ Personal Information only within the scope specified for the purposes of processing and provides Personal Information to third parties only where permitted under Articles 17 and 18 of the Personal Information Protection Act, such as where the Data Subject has given consent or where a special provision of law applies. Otherwise, the Company does not provide Data Subjects’ Personal Information to third parties.

  2. Notice Regarding Keyword-Based Personalized Advertising Recommendations (Optional Feature): If a Member has given separate consent, the Company transfers de-identified keywords extracted from the Member’s call contents and advertising identifiers required for advertising matching (Android ADID and iOS IDFA) to advertising providers for the provision of advertisements. The Company does not provide advertising providers with the Member’s name, mobile phone number, email address, CI/DI, original call text, or call audio. Members may withdraw consent at any time through the app settings or customer center.

Where an obligation to submit information arises under applicable laws and regulations, the Company provides Personal Information to a third party as follows.

Recipient

Purpose of Provision

Personal Information Provided

Recipient’s Retention and Use Period

National Tax Service

Reporting of withholding on other income and submission of statements of payment

Name, resident registration number, Korean or foreign national status, number of payments, total amount paid, necessary expenses, other income amount, applicable tax rate, income tax, and local income tax

The period during which the National Tax Service retains and uses the information in accordance with applicable national tax laws and records-management standards

The Company does not provide the National Tax Service with Personal Information of winners who are not subject to the applicable reporting obligation.

Article 4. Entrustment of Personal Information Processing

The Company entrusts the following Personal Information processing tasks to provide the Service and handle Personal Information-related operations effectively.

Entrusted Party

Entrusted Task

Retention and Use Period of Personal Information

Mixpanel

Statistical analysis of acquisition media and logs collected upon app installation

Until termination of the entrustment agreement

Google Cloud Platform

Data storage and Service operation

Until membership withdrawal or termination of the entrustment agreement

NHN KCP Corp.

Linking and operation of the mobile phone identity verification service and provision of identity verification result information, including CI and DI

Until achievement of the purpose of identity verification or termination of the entrustment agreement. However, where retention is required under applicable laws and regulations, the information shall be retained for the applicable statutory period.

Giftishow and Bizcon

Delivery of products exchanged in the Point Store, such as mobile gift certificates

Until termination of the entrustment agreement or, after completion of delivery, until expiration of the retention period prescribed by applicable laws and regulations

When entering into an entrustment agreement, the Company specifies in documents such as contracts the prohibition of Personal Information processing for purposes other than the entrusted task, technical and administrative safeguards, restrictions on re-entrustment, management and supervision of the entrusted party, liability for damages, and other relevant matters pursuant to Article 26 of the Personal Information Protection Act. The Company also supervises whether the entrusted party processes Personal Information securely.

If the details of the entrusted tasks or entrusted parties change, the Company shall disclose the changes through this Policy without delay.

Article 4-2. Overseas Transfer of Personal Information

To provide the Service to Users, the Company entrusts Personal Information processing tasks to the following entrusted parties located outside Korea. Personal Information may be transferred overseas in this process.

Entrusted Party (Country)

Personal Information Transferred

Time and Method of Transfer

Purpose of Transfer

Retention and Use Period

Mixpanel, Inc. (United States)

Event logs collected during use of the Service (such as button clicks and screen transitions), app installation and execution information and acquisition media information, device information (such as device identifier and OS/app version), IP address and access region information derived from the IP address (such as country and city), and, where optionally collected, account identification information such as email address

Transferred to Mixpanel’s servers over the internet when a User installs or runs the app or uses the Service

Analysis of Service usage behavior, generation of statistics, and improvement of Service quality and user experience

Until termination of the entrustment agreement or membership withdrawal. However, where retention is required under applicable laws and regulations, the information shall be retained for the applicable statutory period.

Google Cloud Platform (United States and Asia regions)

Personal Information processed by the Company, including membership registration information, call and message data, AI processing results, and Point accrual and use records

Transferred to Google Cloud servers over the internet when a Member uses the Service through the app

Data storage and analysis and provision of Service operation infrastructure

Until membership withdrawal or termination of the entrustment agreement. However, where retention is required under applicable laws and regulations, the information shall be retained for the applicable statutory period.

Article 5. Destruction of Personal Information

  1. The Company destroys Personal Information without delay when it becomes unnecessary, such as upon expiration of the retention period or achievement of the purpose of processing.

  2. If Personal Information must continue to be retained under another law despite expiration of the retention period consented to by the Data Subject or achievement of the purpose of processing, the Company moves the Personal Information to a separate database or stores it in a separate location.

  3. The procedures and methods for destroying Personal Information are as follows.

    • Destruction Procedure: The Company selects Personal Information for which a reason for destruction has arisen and destroys it with the approval of the Company’s Chief Privacy Officer.

    • Destruction Method: Personal Information recorded and stored in electronic file format is destroyed in a manner that prevents restoration, and Personal Information recorded and stored in paper documents is shredded or incinerated.

  4. Identifying information and device information separately retained for the purpose of preventing fraudulent use shall be destroyed immediately after the period specified in the “Prevention of Fraudulent Use” category in the Article 2 table has expired.

Article 6. Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them

  1. Data Subjects may exercise rights against the Company at any time, including the right to request access to, correction or deletion of, or suspension of processing of their Personal Information. To access or modify Personal Information, a Data Subject may use “Change Personal Information,” “Edit Member Information,” or a similar feature. To terminate membership or withdraw consent, the Data Subject may use “Membership Withdrawal” and directly access, correct, or withdraw after completing the identity verification process.

  2. The Company does not provide the Service to Users under the age of 14 and therefore does not process the Personal Information of Data Subjects under the age of 14.

  3. Users may exercise their rights against the Company in writing, by email, by fax, or through other means pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company shall take action without delay.

  4. Rights may also be exercised through a legal representative of the Data Subject or an authorized agent. In such cases, a power of attorney must be submitted using the form prescribed in the Public Notice on Methods of Processing Personal Information.

  5. Requests to access or suspend the processing of Personal Information may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.

  6. If another law expressly provides that certain Personal Information must be collected, the Data Subject may not request deletion of such Personal Information.

  7. When a request is made to access, correct, delete, or suspend the processing of Personal Information under a Data Subject’s rights, the Company must verify whether the requester is the Data Subject or a legitimate representative.

  8. Consent to Keyword-Based Personalized Advertising Recommendations (optional) may be withdrawn at any time through the app settings or customer center. Withdrawal shall not affect the Member’s use of the basic Service.

Article 7. Measures to Ensure the Security of Personal Information

The Company takes the following measures to ensure the security of Personal Information.

  1. Administrative Measures: Regular employee training, establishment and implementation of an internal management plan, minimization of personnel handling Personal Information, and management of access privileges

  2. Technical Measures: Encryption of resident registration numbers and minimization of access privileges; encryption of important Personal Information such as CI, DI, and passwords; management of access privileges to Personal Information processing systems; installation and operation of access-control systems; and retention of access records and prevention of forgery or alteration

  3. Physical Measures: Access control for systems storing Personal Information, including servers, and entry control

Article 8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices

  1. The Company uses cookies, which are automatic Personal Information collection devices that store and retrieve usage information from time to time, to provide individualized and personalized services to Users. Cookies are small amounts of information sent by the server (HTTP) used to operate a website to the User’s web browser, including PC and mobile browsers, and may be stored in the User’s storage space.

  2. Users have the right to choose whether to allow the installation of cookies. Users may configure their web browser settings to allow all cookies, request confirmation each time a cookie is stored, or refuse the storage of all cookies.

  3. If cookies are refused, use of certain Company Services that require login may be difficult.

  4. In the mobile app, the Company collects advertising identifiers (Android ADID and iOS IDFA) to prevent fraudulent use. Members may reset advertising identifiers or select tracking restrictions in the mobile OS settings.

Article 9. How to Configure Cookie Permissions

Cookie permissions, cookie blocking, and other settings may be configured through web browser options.

  • Edge: Settings menu in the upper-right corner of the browser > Cookies and site permissions > Manage and delete cookies and site data

  • Chrome: Settings menu in the upper-right corner of the browser > Privacy and security > Cookies and other site data

  • Whale: Browser settings menu in the upper-right corner > Privacy > Cookies and other site data

  • Safari: Browser settings menu > Privacy > Manage website data > Select this website and click Remove

Mobile OS advertising identifier settings:

  • iOS: Settings > Privacy & Security > Apple Advertising / Tracking

  • Android: Settings > Google > Ads > Delete or reset advertising ID

Article 10. Designation of the Company’s Chief Privacy Officer

The Company designates the following responsible department and Chief Privacy Officer to protect Users’ Personal Information and handle complaints relating to Personal Information.

Chief Privacy Officer

Article 11. Remedies for Infringement of Rights

  1. Data Subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency’s Personal Information Infringement Report Center, or another relevant institution to seek remedies for Personal Information infringement. For other reports or consultations concerning Personal Information infringement, please contact the following institutions.

    • Personal Information Dispute Mediation Committee: 1833-6972 without area code (www.kopico.go.kr)

    • Personal Information Infringement Report Center: 118 without area code (privacy.kisa.or.kr)

    • Supreme Prosecutors’ Office: 1301 without area code (www.spo.go.kr)

    • Korean National Police Agency: 182 without area code (ecrm.cyber.go.kr)

  2. The Company endeavors to guarantee Data Subjects’ right to self-determination regarding Personal Information and to provide consultation and remedies for damages caused by Personal Information infringement. If a report or consultation is required, please contact the responsible department specified in Article 10.

  3. A person whose rights or interests have been infringed due to a disposition or omission by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), or Article 37 (Suspension of Processing, Etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.

    • Central Administrative Appeals Commission: 110 without area code (www.simpan.go.kr)

Addendum

  1. This Policy shall take effect on August 10, 2026.

  2. The previous Privacy Policy dated May 19, 2026 shall cease to be effective upon the effective date of this Policy.

  3. Personal Information newly collected or processing purposes newly added under this Policy shall apply when the relevant Personal Information is collected or processed on or after the effective date.

  4. If the Company intends to use Personal Information collected before the effective date for a purpose different from the purpose originally disclosed, the Company shall take necessary measures, such as obtaining separate consent.

  5. This amendment to the Policy alone shall not retroactively expand the purposes of processing or retention periods applicable to CI and DI collected before the effective date.

모모콜 AI 시작하기

설치 즉시 모모콜의 통화요약이 시작됩니다.
통화는 그대로, 정리는 모모콜이.
3초 만에 통화 부담이 사라지는 경험을 해보세요.

Chash Call CTA Mockup

모모콜 AI 시작하기

설치 즉시 모모콜의 통화요약이 시작됩니다.
통화는 그대로, 정리는 모모콜이.
3초 만에 통화 부담이 사라지는 경험을 해보세요.

Chash Call CTA Mockup

모모콜 AI 시작하기

설치 즉시 모모콜의 통화요약이 시작됩니다.
통화는 그대로, 정리는 모모콜이.
3초 만에 통화 부담이 사라지는 경험을 해보세요.

Chash Call CTA Mockup