Privacy
Privacy Policy
LASTMILE Co., Ltd. (the “Company”) complies with the Personal Information Protection Act and related laws to lawfully process and securely manage personal information and protect data subjects' rights and freedoms. Pursuant to Article 30 of the Personal Information Protection Act, we establish and disclose this Privacy Policy to explain procedures and standards for processing and protection and to handle related complaints promptly.
Table of contents
- Purpose, items, retention, and use period of personal information
- Processing and retention of personal location information
- Procedures and methods for destruction of personal information
- Provision of personal information to third parties
- Outsourcing of personal information processing
- Overseas collection and transfer of personal information
- Safeguards for personal information security
- Installation, operation, and refusal of automatic data collection devices
- Rights and obligations of data subjects and legal representatives
- Automated decision-making and pseudonymized information
- Privacy officer and location information manager
- Remedies for infringement of data subject rights
- Changes to this Privacy Policy
Article 1 (Purpose, items, retention, and use period of personal information)
① The Company processes personal information to the minimum extent necessary to provide services. Information is not used beyond stated purposes; if purposes change, we will obtain separate consent or take required measures.
② Personal information is processed and retained within periods required by law or contract.
1. Items processed without consent (contract performance and legal compliance)
| Category | Purpose of processing | Items processed | Legal basis | Retention and use period |
|---|---|---|---|---|
| Corporate customer employee accounts | Account provisioning, password reset, identification, fraud prevention | Name, ID, password, company, department, mobile phone, email | Personal Information Protection Act Art. 15(1)(4) (contract performance) | Until membership withdrawal or account deletion |
| Service provision and customer support | Monitoring/location services, contract performance, inquiries | Company name, user ID, service usage records | Personal Information Protection Act Art. 15(1)(4) (contract performance) | Until service delivery is complete |
| Automatically generated usage data | Service quality, fraud prevention, access log analysis | IP address, cookies, usage records, visit time, device identifiers (OS version, etc.) | Personal Information Protection Act Art. 15(1)(4) (contract performance) | 3 months (Communications Secrets Protection Act) |
2. Personal information retained under applicable laws
Where required by law, the Company retains personal information for statutory periods.
- Records on contracts or withdrawal of offers: 5 years (E-Commerce Act)
- Records on payment and supply of goods: 5 years (E-Commerce Act)
- Records on consumer complaints or disputes: 3 years (E-Commerce Act)
- Location information collection/use/provision logs: 6 months (Location Information Act Art. 16(2))
Article 2 (Processing and retention of personal location information)
① Under the Act on the Protection and Use of Location Information (“Location Information Act”), the Company collects and uses personal location information to provide location-based services.
- Purpose: monitoring and tracking, location-based workflows and notifications
- Collection methods: smartphone GPS, cell tower (Cell ID), Wi-Fi modules
- Retention and destruction: destroyed without delay when purposes are achieved
- Logs of collection/use/provision: recorded automatically per Article 16(2) of the Location Information Act and retained for six months
Article 3 (Procedures and methods for destruction of personal information)
① When retention periods expire or purposes are achieved, the Company destroys personal information without delay.
② Destruction procedures and methods are as follows.
- Procedure: select information subject to destruction, obtain approval from the privacy officer, then destroy.
- Method: delete electronic files irreversibly; shred or incinerate paper records.
Article 4 (Provision of personal information to third parties)
① The Company provides personal information to third parties only with consent or where permitted under Articles 17 and 18 of the Personal Information Protection Act.
② The Company does not currently provide users' personal information or personal location information to third parties. (If needed in the future, we will notify in advance and obtain separate consent.)
Article 5 (Outsourcing of personal information processing)
① To facilitate personal information processing, the Company outsources the following tasks.
| Processor (delegate) | Delegated tasks |
|---|---|
| Amazon Web Services | Cloud server (EC2, RDS, S3, Redis, etc.) operation and data storage/management |
| Naver Cloud | Push/SMS notification delivery |
| Google LLC | Push notification delivery |
② When entering outsourcing agreements, the Company specifies restrictions, safeguards, subcontracting limits, supervision, and liability under Article 26 of the Personal Information Protection Act and supervises processors.
Article 6 (Overseas collection and transfer of personal information)
① All personal information and personal location information are processed and stored on Amazon Web Services (AWS) in the Korea (Seoul) Region; we do not transfer personal information overseas (third-party provision, outsourcing, storage, etc.) in principle.
② If overseas transfer becomes necessary (e.g., foreign cloud regions or overseas SaaS), we will notify recipients, countries, items, and retention periods in advance under Article 28-8 of the Personal Information Protection Act and revise this Policy.
Article 7 (Safeguards for personal information security)
The Company takes the following measures to secure personal information.
- Administrative: internal management plans, regular employee training, dedicated teams
- Technical: access control, encryption of passwords and location data, security software updates
- Physical: access control to server and records rooms, locking devices
Article 8 (Installation, operation, and refusal of automatic data collection devices)
① The Company uses cookies to store and retrieve usage information for personalized services.
② You may block cookies in your browser settings.
- Chrome: ⋮ > Settings > Privacy and security > Block cookies and other site data
- Edge: … > Settings > Privacy, search, and services > Tracking prevention and cookie blocking
Article 9 (Rights and obligations of data subjects and legal representatives)
① Data subjects may request access, correction, deletion, suspension of processing, or withdrawal of consent at any time.
② Requests may be made in writing, by email, or via in-app “Contact us”; the Company will respond without undue delay.
③ Under the Location Information Act, users may withdraw all or part of consent to collection of personal location information and location-based services.
Article 10 (Automated decisions, pseudonymized and sensitive information)
① Automated decisions: The Company does not operate fully automated systems that make significant decisions (e.g., AI hiring, automatic recovery) using personal information.
② Pseudonymized information: The Company does not process pseudonymized information.
③ Sensitive information: The Company does not provide structures that could disclose sensitive information externally in the course of providing services.
Article 11 (Privacy officer and location information manager)
The Company designates the following officers to oversee personal information and location information protection and handle complaints and remedies.
- Privacy officer and location information manager
- Name: Hyeongmo Park
- Title: Vice President
- Department: Management Team
- Phone: 032-835-8098
- Email: momo@lastmile.co.kr
Article 12 (Remedies for infringement of data subject rights)
Data subjects may apply to the following organizations for dispute resolution or consultation regarding personal information infringement.
- Personal Information Dispute Mediation Committee: 1833-6972 (no area code) (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (no area code) (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (no area code) (www.spo.go.kr)
- National Police Agency: 182 (no area code) (ecrm.police.go.kr)
Article 13 (Changes to this Privacy Policy)
This Privacy Policy takes effect on August 2, 2026.