Privacy Policy
2026. 8. 10.
Privacy Policy
Effective Date: 2026.08.10
Company: Sellking (Maedowang Co., Ltd.)
Service: Momocall
Article 1. Purpose
Sellking (Maedowang Co., Ltd.; the “Company”) establishes and publishes this Privacy Policy (the “Policy”) to protect the information (“Personal Information”) of individuals (“Users” or “Individuals”) who use Momocall (the “Company Service”), a service provided by the Company; to comply with applicable laws and regulations, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, Etc. (the “Information and Communications Network Act”); and to promptly and effectively handle complaints relating to the protection of Users’ Personal Information. In addition to Momocall’s call and message data analysis features, this Policy covers Personal Information additionally processed for the operation of the reward point service, mobile phone identity verification, verification of the one-person-one-account principle, prevention of fraudulent use, withholding and submission of statements of payment in connection with prizes, and Keyword-Based Personalized Advertising Recommendations (optional).
Article 2. Personal Information Processed by Purpose and Retention and Use Period
The Personal Information processed by the Company, the purposes of processing, and the applicable retention and use periods are as follows.
Category | Personal Information Processed | Purpose of Processing | Retention and Use Period |
|---|---|---|---|
Membership Registration and Management (Required) | Email address (ID), login account identifier (such as a social account ID), name or nickname, password (hashed value), Service usage history (registration date, withdrawal date, and login records), smartphone device information (device model, OS version, app version, and device identifier), access IP address, access date and time, Service usage logs, failure and error logs, and history of improper use | Member identification and identity confirmation, account creation and management, prevention of fraudulent use and abnormal activities, management of Service usage history, delivery of notices, alerts, and important announcements, response to customer inquiries, and complaint handling | Until termination of the Service Agreement and membership withdrawal. However, where retention is required under applicable laws and regulations, the information shall be separately retained for the applicable statutory period (see the separate table below). |
Customer Inquiries and Complaint Handling (Required) | Email address, inquiry details, conversation records generated during the inquiry or consultation process (such as email and chat records), account information (ID and Service usage history), and contact information | Receipt and handling of Member inquiries, consultations, and complaints; response to Service failures and errors; handling and response in the event of disputes; and management of consultation history | Three years after completion of the inquiry or complaint handling, pursuant to the obligation to retain records of consumer complaints and dispute handling under the Act on the Consumer Protection in Electronic Commerce, Etc., after which the information shall be destroyed without delay. |
Marketing and Event Notifications (Optional) | Mobile phone number, email address or social account ID, app push token (token used to identify the device), Service usage records (such as general usage type and frequency), and event participation history | Provision of Service-related news, notices of feature or pricing plan changes, event and promotion notices, personalized notices, and marketing communications intended to expand Service use | Until withdrawal of optional consent or membership withdrawal. However, where retention is required under applicable laws and regulations, the information shall be retained for the applicable statutory period. |
Fee Settlement, Payment, and Refunds (Required) | Paid Service usage records, purchased product information, payment amount, payment date and time, payment approval and cancellation history, refund history, and marketplace payment identifiers (such as Google Play or Apple App Store payment IDs) | Billing and payment processing for paid Services (such as subscriptions and passes), refund and cancellation processing, settlement of overpayments and unpaid amounts, and response to payment-related complaints | Until termination of the Service Agreement and membership withdrawal |
Point Service Operation (Required) | Point accrual and use history, Reward Activity history (records of advertisement viewing and call event participation), statistics on call duration and number of calls (Note: original call contents and audio files are not included in this category), and Point Store product exchange history | Provision of reward point accrual and settlement services and Point Store product exchange services, and delivery of exchanged products (such as mobile gift certificates) | Until membership withdrawal or expiration of the Points. Information subject to a retention obligation under the Act on the Consumer Protection in Electronic Commerce, Etc. shall be separately retained for the applicable statutory period. |
Mobile Phone Identity Verification and Verification of Reward Recipients (Required at a time announced in advance by the Company) | Name, date of birth, gender, Korean or foreign national status, mobile phone number, Connecting Information (CI), Duplication Information (DI), and mobile carrier information | Mobile phone identity verification; verification of the one-person-one-account principle and prevention of duplicate account creation; prevention of fraudulent accrual and use of reward Points; identification of reward recipients; and delivery of exchanged products such as mobile gift certificates | Name, date of birth, gender, mobile phone number, CI, and DI shall be retained until membership withdrawal. After withdrawal, such information shall be separately retained for the period specified in the “Prevention of Fraudulent Use” category below. Korean or foreign national status and mobile carrier information shall be destroyed without delay after identity verification is completed. Information that must be separately retained under applicable laws and regulations shall be segregated and retained for the applicable statutory period. |
Withholding and Submission of Statements of Payment Relating to Prizes (Limited to winners of prizes for which the applicable obligation arises) | Name, resident registration number, Korean or foreign national status, prize payment details (prize name, value, and payment date), necessary expenses, other income amount, applicable tax rate, income tax, and local income tax | Delivery of prizes; withholding, reporting, and payment of taxes on other income; preparation and submission of statements of payment; and issuance of withholding tax receipts | Five years from the day following the statutory national tax filing deadline for the taxable period in which the relevant transaction occurred, after which the information shall be destroyed without delay |
Prevention of Fraudulent Use (Required) | Encrypted and hashed values of CI and DI; mobile phone number; date of birth; gender; device ID ( | Prevention of repeated receipt of rewards through re-registration after membership withdrawal; detection and blocking of multiple accounts operated using the same identity verification information or device information; detection and blocking of abnormal reward accrual or use; recovery of fraudulently accrued or used rewards; restriction of re-registration by fraudulent Users; and handling of objections | Encrypted and hashed values of CI and DI; mobile phone number; date of birth; gender; |
Keyword-Based Personalized Advertising Recommendations (Optional, Separate Consent) | Keywords extracted by the Company from call contents (processed in de-identified form and separated from Member identifiers), advertising identifiers (Android ADID and iOS IDFA), and consent and withdrawal records and timestamps | Extraction of advertising-matching keywords and provision of advertisements based on the Member’s separate consent | Destroyed immediately upon withdrawal of consent or membership withdrawal. Consent and withdrawal records shall be separately retained for three years from the termination of consent for dispute-response purposes. |
When a Member proceeds with mobile phone identity verification, the Company receives identity verification result information through an identity verification service linked by NHN KCP Corp.
When the Company provides a prize that gives rise to an obligation to withhold income tax or local income tax or to submit a statement of payment, the Company informs the winner of the purpose of processing, the Personal Information processed, and the retention period and directly collects the required information through a separate secure input method. Such information is processed separately from general membership information and mobile phone identity verification result information. The Company processes resident registration numbers only when necessary to fulfill the applicable obligation and does not collect them as required information for membership registration or ordinary reward accrual or exchange.
The 60-day and one-year retention periods following membership withdrawal are based on the Company’s fraudulent-use prevention policy. The Company retains the relevant information separately from general membership information, does not use it for any other purpose, and destroys it without delay upon expiration of the applicable retention period.
Personal Information being processed shall not be used for any purpose other than those stated above. If a purpose of use changes, the Company shall take necessary measures, such as obtaining separate consent pursuant to Article 18 of the Personal Information Protection Act.
The Company processes and retains Personal Information within the retention and use periods prescribed by applicable laws and regulations or consented to by the Data Subject at the time the Personal Information is collected.
Information Retained and Retention Periods Under Applicable Laws and Regulations
Applicable Law | Information Retained | Retention Period |
|---|---|---|
Act on the Consumer Protection in Electronic Commerce, Etc. | Records concerning contracts or withdrawal of offers | Five years |
Act on the Consumer Protection in Electronic Commerce, Etc. | Records concerning payment and supply of goods, etc. | Five years |
Act on the Consumer Protection in Electronic Commerce, Etc. | Records concerning consumer complaints or dispute handling | Three years |
Act on the Consumer Protection in Electronic Commerce, Etc. | Records concerning labeling and advertising | Six months |
Protection of Communications Secrets Act | Website log records | Three months |
Electronic Financial Transactions Act | Records concerning electronic financial transactions | Five years |
Act on the Protection and Use of Location Information | Records concerning Personal Location Information | Six months |
Framework Act on National Taxes | Books and supporting documents relating to withholding and submission of statements of payment in connection with prizes | Five years from the day following the statutory national tax filing deadline for the taxable period in which the relevant transaction occurred |
Article 3. Provision of Personal Information to Third Parties
The Company processes Data Subjects’ Personal Information only within the scope specified for the purposes of processing and provides Personal Information to third parties only where permitted under Articles 17 and 18 of the Personal Information Protection Act, such as where the Data Subject has given consent or where a special provision of law applies. Otherwise, the Company does not provide Data Subjects’ Personal Information to third parties.
Notice Regarding Keyword-Based Personalized Advertising Recommendations (Optional Feature): If a Member has given separate consent, the Company transfers de-identified keywords extracted from the Member’s call contents and advertising identifiers required for advertising matching (Android ADID and iOS IDFA) to advertising providers for the provision of advertisements. The Company does not provide advertising providers with the Member’s name, mobile phone number, email address, CI/DI, original call text, or call audio. Members may withdraw consent at any time through the app settings or customer center.
Where an obligation to submit information arises under applicable laws and regulations, the Company provides Personal Information to a third party as follows.
Recipient | Purpose of Provision | Personal Information Provided | Recipient’s Retention and Use Period |
|---|---|---|---|
National Tax Service | Reporting of withholding on other income and submission of statements of payment | Name, resident registration number, Korean or foreign national status, number of payments, total amount paid, necessary expenses, other income amount, applicable tax rate, income tax, and local income tax | The period during which the National Tax Service retains and uses the information in accordance with applicable national tax laws and records-management standards |
The Company does not provide the National Tax Service with Personal Information of winners who are not subject to the applicable reporting obligation.
Article 4. Entrustment of Personal Information Processing
The Company entrusts the following Personal Information processing tasks to provide the Service and handle Personal Information-related operations effectively.
Entrusted Party | Entrusted Task | Retention and Use Period of Personal Information |
|---|---|---|
Mixpanel | Statistical analysis of acquisition media and logs collected upon app installation | Until termination of the entrustment agreement |
Google Cloud Platform | Data storage and Service operation | Until membership withdrawal or termination of the entrustment agreement |
NHN KCP Corp. | Linking and operation of the mobile phone identity verification service and provision of identity verification result information, including CI and DI | Until achievement of the purpose of identity verification or termination of the entrustment agreement. However, where retention is required under applicable laws and regulations, the information shall be retained for the applicable statutory period. |
Giftishow and Bizcon | Delivery of products exchanged in the Point Store, such as mobile gift certificates | Until termination of the entrustment agreement or, after completion of delivery, until expiration of the retention period prescribed by applicable laws and regulations |
When entering into an entrustment agreement, the Company specifies in documents such as contracts the prohibition of Personal Information processing for purposes other than the entrusted task, technical and administrative safeguards, restrictions on re-entrustment, management and supervision of the entrusted party, liability for damages, and other relevant matters pursuant to Article 26 of the Personal Information Protection Act. The Company also supervises whether the entrusted party processes Personal Information securely.
If the details of the entrusted tasks or entrusted parties change, the Company shall disclose the changes through this Policy without delay.
Article 4-2. Overseas Transfer of Personal Information
To provide the Service to Users, the Company entrusts Personal Information processing tasks to the following entrusted parties located outside Korea. Personal Information may be transferred overseas in this process.
Entrusted Party (Country) | Personal Information Transferred | Time and Method of Transfer | Purpose of Transfer | Retention and Use Period |
|---|---|---|---|---|
Mixpanel, Inc. (United States) | Event logs collected during use of the Service (such as button clicks and screen transitions), app installation and execution information and acquisition media information, device information (such as device identifier and OS/app version), IP address and access region information derived from the IP address (such as country and city), and, where optionally collected, account identification information such as email address | Transferred to Mixpanel’s servers over the internet when a User installs or runs the app or uses the Service | Analysis of Service usage behavior, generation of statistics, and improvement of Service quality and user experience | Until termination of the entrustment agreement or membership withdrawal. However, where retention is required under applicable laws and regulations, the information shall be retained for the applicable statutory period. |
Google Cloud Platform (United States and Asia regions) | Personal Information processed by the Company, including membership registration information, call and message data, AI processing results, and Point accrual and use records | Transferred to Google Cloud servers over the internet when a Member uses the Service through the app | Data storage and analysis and provision of Service operation infrastructure | Until membership withdrawal or termination of the entrustment agreement. However, where retention is required under applicable laws and regulations, the information shall be retained for the applicable statutory period. |
Article 5. Destruction of Personal Information
The Company destroys Personal Information without delay when it becomes unnecessary, such as upon expiration of the retention period or achievement of the purpose of processing.
If Personal Information must continue to be retained under another law despite expiration of the retention period consented to by the Data Subject or achievement of the purpose of processing, the Company moves the Personal Information to a separate database or stores it in a separate location.
The procedures and methods for destroying Personal Information are as follows.
Destruction Procedure: The Company selects Personal Information for which a reason for destruction has arisen and destroys it with the approval of the Company’s Chief Privacy Officer.
Destruction Method: Personal Information recorded and stored in electronic file format is destroyed in a manner that prevents restoration, and Personal Information recorded and stored in paper documents is shredded or incinerated.
Identifying information and device information separately retained for the purpose of preventing fraudulent use shall be destroyed immediately after the period specified in the “Prevention of Fraudulent Use” category in the Article 2 table has expired.
Article 6. Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them
Data Subjects may exercise rights against the Company at any time, including the right to request access to, correction or deletion of, or suspension of processing of their Personal Information. To access or modify Personal Information, a Data Subject may use “Change Personal Information,” “Edit Member Information,” or a similar feature. To terminate membership or withdraw consent, the Data Subject may use “Membership Withdrawal” and directly access, correct, or withdraw after completing the identity verification process.
The Company does not provide the Service to Users under the age of 14 and therefore does not process the Personal Information of Data Subjects under the age of 14.
Users may exercise their rights against the Company in writing, by email, by fax, or through other means pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company shall take action without delay.
Rights may also be exercised through a legal representative of the Data Subject or an authorized agent. In such cases, a power of attorney must be submitted using the form prescribed in the Public Notice on Methods of Processing Personal Information.
Requests to access or suspend the processing of Personal Information may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.
If another law expressly provides that certain Personal Information must be collected, the Data Subject may not request deletion of such Personal Information.
When a request is made to access, correct, delete, or suspend the processing of Personal Information under a Data Subject’s rights, the Company must verify whether the requester is the Data Subject or a legitimate representative.
Consent to Keyword-Based Personalized Advertising Recommendations (optional) may be withdrawn at any time through the app settings or customer center. Withdrawal shall not affect the Member’s use of the basic Service.
Article 7. Measures to Ensure the Security of Personal Information
The Company takes the following measures to ensure the security of Personal Information.
Administrative Measures: Regular employee training, establishment and implementation of an internal management plan, minimization of personnel handling Personal Information, and management of access privileges
Technical Measures: Encryption of resident registration numbers and minimization of access privileges; encryption of important Personal Information such as CI, DI, and passwords; management of access privileges to Personal Information processing systems; installation and operation of access-control systems; and retention of access records and prevention of forgery or alteration
Physical Measures: Access control for systems storing Personal Information, including servers, and entry control
Article 8. Installation, Operation, and Refusal of Automatic Personal Information Collection Devices
The Company uses cookies, which are automatic Personal Information collection devices that store and retrieve usage information from time to time, to provide individualized and personalized services to Users. Cookies are small amounts of information sent by the server (HTTP) used to operate a website to the User’s web browser, including PC and mobile browsers, and may be stored in the User’s storage space.
Users have the right to choose whether to allow the installation of cookies. Users may configure their web browser settings to allow all cookies, request confirmation each time a cookie is stored, or refuse the storage of all cookies.
If cookies are refused, use of certain Company Services that require login may be difficult.
In the mobile app, the Company collects advertising identifiers (Android ADID and iOS IDFA) to prevent fraudulent use. Members may reset advertising identifiers or select tracking restrictions in the mobile OS settings.
Article 9. How to Configure Cookie Permissions
Cookie permissions, cookie blocking, and other settings may be configured through web browser options.
Edge: Settings menu in the upper-right corner of the browser > Cookies and site permissions > Manage and delete cookies and site data
Chrome: Settings menu in the upper-right corner of the browser > Privacy and security > Cookies and other site data
Whale: Browser settings menu in the upper-right corner > Privacy > Cookies and other site data
Safari: Browser settings menu > Privacy > Manage website data > Select this website and click Remove
Mobile OS advertising identifier settings:
iOS: Settings > Privacy & Security > Apple Advertising / Tracking
Android: Settings > Google > Ads > Delete or reset advertising ID
Article 10. Designation of the Company’s Chief Privacy Officer
The Company designates the following responsible department and Chief Privacy Officer to protect Users’ Personal Information and handle complaints relating to Personal Information.
Chief Privacy Officer
Name: Jusung Lim
Position: CTO
Email: cs@sellking.kr
Article 11. Remedies for Infringement of Rights
Data Subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency’s Personal Information Infringement Report Center, or another relevant institution to seek remedies for Personal Information infringement. For other reports or consultations concerning Personal Information infringement, please contact the following institutions.
Personal Information Dispute Mediation Committee: 1833-6972 without area code (www.kopico.go.kr)
Personal Information Infringement Report Center: 118 without area code (privacy.kisa.or.kr)
Supreme Prosecutors’ Office: 1301 without area code (www.spo.go.kr)
Korean National Police Agency: 182 without area code (ecrm.cyber.go.kr)
The Company endeavors to guarantee Data Subjects’ right to self-determination regarding Personal Information and to provide consultation and remedies for damages caused by Personal Information infringement. If a report or consultation is required, please contact the responsible department specified in Article 10.
A person whose rights or interests have been infringed due to a disposition or omission by the head of a public institution in response to a request under Article 35 (Access to Personal Information), Article 36 (Correction or Deletion of Personal Information), or Article 37 (Suspension of Processing, Etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.
Central Administrative Appeals Commission: 110 without area code (www.simpan.go.kr)
Addendum
This Policy shall take effect on August 10, 2026.
The previous Privacy Policy dated May 19, 2026 shall cease to be effective upon the effective date of this Policy.
Personal Information newly collected or processing purposes newly added under this Policy shall apply when the relevant Personal Information is collected or processed on or after the effective date.
If the Company intends to use Personal Information collected before the effective date for a purpose different from the purpose originally disclosed, the Company shall take necessary measures, such as obtaining separate consent.
This amendment to the Policy alone shall not retroactively expand the purposes of processing or retention periods applicable to CI and DI collected before the effective date.

