Legal

Privacy Policy 개인정보 처리방침

Last Updated: February 4, 2026 | 최종 수정일: 2026년 2월 4일

1. Introduction and Scope / 서문 및 적용 범위

This Privacy Policy ("Policy") describes how ABITRA Inc. ("ABITRA," "we," "us," or "our"), a United States corporation, collects, uses, discloses, and protects your personal information when you use the OneJikgu (원직구) service, including the website located at onejikgu.abitra.co, the OneJikgu mobile application for Android and iOS, and all related services (collectively, the "Service").

OneJikgu is a cross-border shopping agent platform designed for South Korean consumers. We act as a purchase agent, shipping agent, and intermediary to facilitate cross-border shopping from international e-commerce retailers. Our Service includes real-time translation, customs duty and shipping cost calculation, payment processing, and logistics coordination.

By accessing or using the Service, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal information as described in this Policy. If you do not agree with this Policy, please do not use the Service.

This Policy applies to all users of the Service, regardless of location, and is designed to comply with applicable laws including but not limited to the Republic of Korea's Personal Information Protection Act (개인정보보호법, "PIPA") and applicable United States federal and state privacy laws.

Effective Date: February 4, 2026 | 시행일: 2026년 2월 4일

2. Data Controller / 개인정보 관리자

The data controller responsible for your personal information is:

ABITRA Inc.

Entity Type: United States Corporation

Service Name: OneJikgu (원직구)

Website: onejikgu.abitra.co

Email: support@abitra.co

Data Protection Inquiries: support@abitra.co

ABITRA Inc. is responsible for determining the purposes and means of processing your personal information in connection with the Service. For any inquiries or requests regarding your personal information, please contact us using the details above.

3. Personal Data We Collect / 수집하는 개인정보

3.1 Information You Provide Directly / 이용자가 직접 제공하는 정보

When you create an account, place an order, or otherwise interact with the Service, we may collect the following information:

  • Account Information: Name, email address, and account credentials (including authentication tokens from Google or Apple OAuth sign-in).
  • Contact Information: Phone number and communication preferences.
  • Shipping Address: Korean delivery address (including recipient name, address line 1, address line 2, city, province, postal code, and phone number) required for customs clearance and domestic delivery.
  • Payment Information: Payment method details necessary to process transactions. Payment card information is collected and processed directly by our payment processor, Stripe, Inc., and is not stored on our servers.
  • Personal Customs Code (개인통관고유부호): As required by Korean customs regulations for import clearance of international shipments.
  • Communication Records: Records of your communications with our customer support team, including inquiries regarding orders, returns, exchanges, and refunds.
  • User Preferences: Language preferences, notification settings, and saved shopping preferences.

3.2 Information Collected Automatically / 자동으로 수집되는 정보

When you use the Service, we automatically collect certain information, including:

  • Device Information: Device type, model, operating system and version, unique device identifiers, and mobile network information.
  • Log and Usage Data: IP address, browser type and version, access times, pages and screens viewed, and interactions with Service features.
  • Browsing Behavior within OneJikgu: Which international shopping sites you visit through the Service, products you view, items added to your cart, search queries within the in-app browser, and time spent on product pages.
  • Location Data: Approximate geographic location derived from your IP address. We do not collect precise GPS location data.
  • App Performance Data: Crash reports, performance diagnostics, and error logs to maintain and improve the Service.

3.3 Information from Third Parties / 제3자로부터 수집하는 정보

We may receive information about you from the following third-party sources:

  • Payment Processor (Stripe): Transaction status, payment confirmation, and limited payment method details necessary for order management and customer support.
  • Shipping and Logistics Providers: Shipment tracking information, delivery status updates, and customs clearance status.
  • Customs Authorities: Information related to the customs clearance process as required by applicable Korean and international trade regulations.
  • Authentication Providers (Google, Apple): Basic profile information (name, email address) when you sign in using third-party OAuth authentication.

4. How We Use Your Data / 개인정보의 이용 목적

We use the personal information we collect for the following purposes:

4.1 Service Provision and Order Fulfillment

  • Processing your purchase orders, including communicating with international retailers on your behalf as a purchase agent.
  • Coordinating international shipping and domestic delivery to your Korean shipping address.
  • Facilitating customs clearance procedures with Korean customs authorities.
  • Calculating customs duties, value-added tax (VAT), shipping costs, and total landed costs in Korean Won (KRW).
  • Providing real-time translation of international e-commerce content through our AI-powered translation service (Gemini 2.0 Flash).
  • Processing payments through our payment processor, Stripe.

4.2 Account Management and Customer Support

  • Creating, maintaining, and securing your user account.
  • Verifying your identity and authenticating your access to the Service.
  • Responding to your inquiries, requests, and complaints.
  • Facilitating exchanges, returns, and refund requests with international retailers.
  • Sending transactional communications, including order confirmations, shipping notifications, and delivery updates.

4.3 Service Improvement and Analytics

  • Analyzing usage patterns to improve the Service's functionality, performance, and user experience.
  • Improving the accuracy and quality of our AI translation engine and price calculation algorithms.
  • Conducting internal research and development.
  • Monitoring and analyzing trends and user activity within the Service.

4.4 Legal Compliance and Security

  • Complying with applicable laws, regulations, and legal obligations, including Korean customs reporting requirements, tax obligations, and consumer protection laws.
  • Preventing, detecting, and investigating fraud, unauthorized transactions, and other illegal or harmful activities.
  • Enforcing our Terms of Service and other agreements.
  • Protecting the rights, property, and safety of ABITRA, our users, and the public.

4.5 Marketing Communications

  • With your prior consent, sending you promotional communications about new features, special offers, supported shopping sites, and other information that may be of interest to you.
  • You may opt out of marketing communications at any time by following the unsubscribe instructions in any marketing email or by contacting us at support@abitra.co.

6. Data Sharing and Disclosure / 개인정보의 공유 및 제공

We do not sell your personal information to third parties. We may share your personal information with the following categories of recipients only as necessary to provide the Service and as described in this Policy:

6.1 Third-Party Retailers

When you place an order through the Service, we share the minimum necessary information (such as product selections, quantities, and shipping details) with the relevant international retailers to fulfill your purchase. We do not share more information than is required to complete the transaction.

6.2 Payment Processor

We use Stripe, Inc. as our payment processor. When you make a payment, your payment information is transmitted directly to and processed by Stripe in accordance with Stripe's privacy policy and PCI DSS (Payment Card Industry Data Security Standard) requirements. We do not store your full payment card details on our servers.

6.3 Shipping and Logistics Providers

We share your shipping address, recipient name, phone number, and package information with international and domestic shipping carriers and logistics partners to facilitate the delivery of your orders and provide tracking information.

6.4 Customs Authorities

As required by Korean customs regulations and applicable international trade laws, we provide necessary information to customs authorities, including your Personal Customs Code (개인통관고유부호), product descriptions, declared values, and shipping details for import clearance.

6.5 AI Translation Service Provider

We use Google's Gemini AI service to provide real-time translation of e-commerce content within the Service. Only the browsing content (product descriptions, reviews, and interface text) is transmitted for translation purposes. Your personal information (name, email, address, payment details) is not shared with or transmitted to the AI translation service.

6.6 Cloud Infrastructure and Service Providers

We use Supabase (and its underlying cloud infrastructure) for database management, user authentication, and backend services. These service providers process data on our behalf under contractual obligations to protect the confidentiality and security of your personal information.

6.7 Law Enforcement and Legal Requirements

We may disclose your personal information to law enforcement agencies, government authorities, or other third parties when we are legally required to do so, when we believe in good faith that disclosure is necessary to protect our rights or the rights of others, to prevent harm or illegal activities, or in response to a valid legal process such as a subpoena, court order, or government request.

6.8 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or other business transfer involving ABITRA, your personal information may be transferred as part of the transaction. We will notify you of any such transfer and any choices you may have regarding your personal information.

7. International Data Transfers / 개인정보의 국외 이전

As a cross-border shopping service operated by a United States corporation serving South Korean consumers, your personal information is necessarily transferred between the United States and the Republic of Korea, as well as to other countries where our service providers operate.

In accordance with Article 28-8 of the Korean Personal Information Protection Act (PIPA), we inform you of the following regarding cross-border transfers of personal information:

Transferee: ABITRA Inc. (United States)

Country of Transfer: United States of America

Date and Method of Transfer: Encrypted transmission at the time of account creation, order placement, and Service use via secure network connections

Items of Personal Information Transferred: Account information, shipping address, order details, and usage data as described in Section 3 of this Policy

Purpose of Transfer: To provide the Service, process orders, and operate business operations as described in Section 4 of this Policy

Retention Period: As described in Section 8 of this Policy

We implement appropriate safeguards to protect your personal information during international transfers, including encryption of data in transit using TLS/SSL protocols, contractual data protection obligations with our service providers, and access controls to limit data access to authorized personnel only.

Our third-party service providers (including Stripe, Supabase, and Google) may process your data in various jurisdictions. Each provider maintains their own data protection practices in compliance with applicable laws.

8. Data Retention / 개인정보의 보유 및 파기

We retain your personal information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by applicable law. The specific retention periods are as follows:

CategoryRetention PeriodBasis
Account InformationDuration of active account + 5 yearsContractual necessity; legal obligations
Transaction Records5 years from date of transactionTax and customs reporting obligations
Payment Records5 years from date of transactionFinancial recordkeeping requirements
Customer Support Records3 years from resolutionConsumer protection; dispute resolution
Browsing and Usage Data1 year from date of collectionService improvement; analytics
Marketing Consent RecordsDuration of consent + 3 yearsProof of consent under PIPA

Upon expiration of the applicable retention period, or upon your valid request for deletion (subject to legal retention requirements), we will securely destroy or anonymize your personal information in accordance with our data destruction procedures. Electronic data will be permanently deleted using technical methods that render the information unrecoverable. Physical records, if any, will be shredded or incinerated.

Where certain data must be retained to comply with legal obligations (such as tax records or customs documentation), we will isolate such data and restrict processing to the minimum necessary for compliance purposes only, even if you have requested account deletion.

9. Data Security / 개인정보의 안전성 확보 조치

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include, but are not limited to:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security) / SSL (Secure Sockets Layer) protocols.
  • Encryption at Rest: Personal information stored in our databases is encrypted at rest using industry-standard encryption algorithms.
  • Secure Payment Processing: Payment information is processed by Stripe, which is certified as a PCI DSS Level 1 service provider, the highest level of payment security certification.
  • Access Controls: Access to personal information is restricted to authorized personnel who require access for legitimate business purposes. We implement role-based access controls and multi-factor authentication for administrative access.
  • Authentication Security: User authentication is managed through Supabase with support for Google and Apple OAuth, reducing the risk associated with password management.
  • Regular Security Reviews: We conduct periodic security assessments and reviews of our systems, processes, and third-party service providers to identify and address potential vulnerabilities.
  • Incident Response: We maintain incident response procedures to promptly detect, respond to, and mitigate security incidents. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the relevant authorities in accordance with applicable law, including notification to the Korean Personal Information Protection Commission (PIPC) as required by PIPA.

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to maintaining commercially reasonable safeguards appropriate to the sensitivity of the information.

10. Cookies and Tracking Technologies / 쿠키 및 추적 기술

We use cookies and similar tracking technologies to operate and improve the Service. The types of cookies we use include:

10.1 Essential Cookies (필수 쿠키)

These cookies are strictly necessary for the operation of the Service. They enable core functionality such as user authentication, session management, security features, and language preferences. The Service cannot function properly without these cookies, and they cannot be disabled.

10.2 Analytics Cookies (분석 쿠키)

With your consent, we use analytics cookies to understand how users interact with the Service, which pages and features are most popular, and how users navigate through the application. This information helps us improve the Service's functionality and user experience. Analytics data is aggregated and does not identify individual users.

10.3 No Third-Party Advertising Cookies

We do not use third-party advertising cookies or tracking technologies. We do not serve targeted advertisements based on your browsing behavior, and we do not allow third-party advertising networks to place cookies or trackers through the Service.

10.4 Cookie Management

You can manage your cookie preferences through the cookie consent mechanism provided on our website. You may also configure your browser settings to refuse cookies or to alert you when cookies are being sent. Please note that disabling essential cookies may impair the functionality of the Service. For the mobile application, similar data collection preferences can be managed through your device settings.

11. Your Rights / 이용자의 권리

Under the Korean Personal Information Protection Act (PIPA) and applicable United States privacy laws, you have the following rights with respect to your personal information:

  • Right of Access (열람권): You have the right to request access to the personal information we hold about you, including the categories of information collected, the purposes of processing, and the third parties to whom your information has been disclosed.
  • Right to Correction (정정권): You have the right to request that we correct any inaccurate or incomplete personal information we hold about you. Upon receiving a valid correction request, we will take reasonable steps to verify and update the information.
  • Right to Deletion (삭제권): You have the right to request the deletion of your personal information, subject to exceptions for data that we are required or permitted to retain by applicable law (such as transaction records for tax and customs compliance).
  • Right to Suspend Processing (처리정지권): You have the right to request that we suspend the processing of your personal information. Upon receiving a valid request, we will cease processing except where retention or processing is required by law.
  • Right to Withdraw Consent (동의 철회권): Where processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Right to Data Portability (개인정보 이동권): You have the right to request a copy of your personal information in a structured, commonly used, and machine-readable format, and to transmit that information to another service provider where technically feasible.
  • Right to Object (이의제기권): You have the right to object to the processing of your personal information where we process it based on our legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
  • Right to Lodge a Complaint (민원 제기권): You have the right to lodge a complaint with the Korean Personal Information Protection Commission (개인정보보호위원회, PIPC) or other relevant supervisory authority if you believe that the processing of your personal information violates applicable law.

Korean Personal Information Protection Commission (PIPC)

개인정보보호위원회

Website: www.pipc.go.kr

Phone: (without country code) 1833-6972

To exercise any of these rights, please contact us at support@abitra.co. We will respond to your request within the timeframe prescribed by applicable law (generally within ten (10) days for PIPA-related requests). We may request additional information to verify your identity before processing your request.

You may also exercise your rights through a legally authorized representative. In such cases, we may require a valid power of attorney or other appropriate documentation.

12. Children's Privacy / 아동의 개인정보 보호

The Service is not directed at, and is not intended for use by, individuals under the age of eighteen (18). We do not knowingly collect personal information from children under 18 years of age. Cross-border shopping through our Service requires the legal capacity to enter into contractual agreements, including purchase agreements and payment transactions.

If we become aware that we have inadvertently collected personal information from a child under 18, we will take immediate steps to delete such information from our records. If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at support@abitra.co so that we can take appropriate action.

13. AI and Automated Processing / AI 및 자동화된 처리

Our Service utilizes artificial intelligence and automated processing in the following ways:

13.1 AI-Powered Translation

We use Google's Gemini 2.0 Flash AI model to provide real-time translation of international e-commerce content (product names, descriptions, reviews, size guides, and interface elements) from their original language into Korean. The translation service processes only the publicly available content of the e-commerce pages you visit through the Service. Your personal information is not transmitted to or processed by the AI translation service. Translated content is cached locally on your device and on our servers (up to 10,000 items) to improve performance and reduce latency.

13.2 Automated Price Calculations

The Service uses automated algorithms to calculate the total estimated cost of your purchases in Korean Won. These calculations include real-time currency conversion, customs duty estimation (6.5-13% depending on product category), value-added tax (10%), international and domestic shipping costs, and service fees. These calculations are provided as estimates and the final amounts may vary based on actual customs assessment and exchange rate fluctuations at the time of processing.

13.3 Automated Product Recognition

The Service uses automated scripts to extract product information (name, price, images, available options) from the e-commerce pages you browse. This processing occurs locally within the in-app browser and is used solely to display accurate product information and calculate costs within the Service.

13.4 No Significant Automated Decision-Making

We do not use automated processing, including profiling, to make decisions that produce legal effects concerning you or that similarly significantly affect you without human review. All material decisions regarding your account, orders, and transactions are subject to human oversight. If you have concerns about any automated processing, you may contact us to request human review.

14. Changes to This Policy / 본 방침의 변경

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational reasons. When we make changes to this Policy:

  • The updated Policy will be posted on our website at onejikgu.abitra.co/privacy with the revised "Last Updated" date.
  • For material changes that significantly affect your rights or how we process your personal information, we will provide at least thirty (30) days' advance notice before the changes take effect.
  • Notice of material changes will be provided via email to the address associated with your account and/or through a prominent notice within the Service (such as an in-app notification).
  • Where required by applicable law (including PIPA), we will obtain your renewed consent for any material changes to the processing of your personal information.

We encourage you to review this Policy periodically to stay informed about how we protect your personal information. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Policy, to the extent permitted by applicable law.

15. Contact Us / 문의처

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:

ABITRA Inc.

Service: OneJikgu (원직구)

Email: support@abitra.co

Website: onejikgu.abitra.co

For data protection inquiries specifically, including requests to exercise your rights under Section 11 of this Policy, please direct your correspondence to support@abitra.co with the subject line "Data Protection Inquiry" or "개인정보 보호 문의."

We will make every effort to respond to your inquiries within the timeframes prescribed by applicable law. For requests under the Korean Personal Information Protection Act (PIPA), we will respond within ten (10) days of receiving your request.

This Privacy Policy is effective as of February 4, 2026.

본 개인정보 처리방침은 2026년 2월 4일부터 시행됩니다.

© 2026 ABITRA Inc. All rights reserved.