Privacy Policy

Effective Date: July 23, 2026 · Current Version

KRISTIN Company Co., Ltd. (the “Company,” “we,” or “us”) lawfully processes and securely manages personal information in accordance with the Personal Information Protection Act (“PIPA”) and other applicable laws and regulations to protect the freedoms and rights of data subjects. Pursuant to Article 30 of PIPA, we have established and published this Privacy Policy to explain the procedures and standards governing our processing and protection of personal information in connection with the “ShoeCatchservice operated by us (the “Service”) and to ensure that any related complaints are addressed promptly and efficiently. Unless otherwise expressly provided, references to laws or regulations in this Privacy Policy shall be construed as references to the laws of the Republic of Korea.

1. Purposes of Processing Personal Information

We process personal information for the purposes set forth below. We will not use the personal information we process for any purpose other than those set forth below. If any purpose of use changes, we will take the measures required under Article 18 of PIPA, including obtaining separate consent.

  • Membership Registration and Management: To confirm an individual’s intent to register as a Member; identify and authenticate Members in connection with membership-based services; maintain and manage membership status; prevent fraudulent or unauthorized use of the Service; provide notices and notifications; and address complaints.
  • Provision of Goods or Services: To provide the Service and content; respond to customer inquiries and complaints; and process payments and settle charges.
  • Service Improvement and Analysis: To analyze use of the Service and improve the Service.
  • Development of New Services: To develop new services separate from the existing Service.
  • Customer Inquiries and Complaints, Service Operations, and Notices: To receive and process customer inquiries; review and respond to complaints; provide information concerning use of the Service; deliver notices concerning service interruptions, maintenance, changes, and other matters; respond to disputes; and protect users.
  • Payment and Refund Processing: To process payments for Paid Services; verify payment details; settle charges; process withdrawals from or cancellations of purchases and refunds; prevent fraudulent payments; and respond to payment-related disputes.
  • Marketing: To provide information about events and send advertising or promotional information.

Without a Member’s express consent, we do not process Members personal information, including any personal information contained in input or generated output, for the purpose of training AI models.

2. Categories of Personal Information We Process

We collect and use personal information on the following legal bases.

Personal Information Processed Without Consent. We process the following categories of personal information without obtaining the data subject’s consent:

  • Membership Registration and Management
  • Legal Basis: Article 15(1)(4) of PIPA (entering into and performing a contract)
  • Categories Processed: Email address and password; for Members who register using a Google account, the email address associated with that Google account
  • Provision of Goods or Services
  • Legal Basis: Article 15(1)(4) of PIPA (entering into and performing a contract)
  • Categories Processed: Email address; Member identification information; Workspace and project information; Content entered, uploaded, generated, or stored by users and records relating to the processing of such Content; generation request history; Credit grant, usage, and deduction history; Subscription Plan and subscription information; and Service access-permission information
  • Service Improvement and Analysis
  • Legal Basis: Article 15(1)(4) of PIPA (entering into and performing a contract)
  • Categories Processed: Service usage records; IP address; cookies; device model; browser and operating-system information; generation request history; feature usage history; access logs; error and service-disruption records; and customer inquiries and feedback
  • Service Development
  • Legal Basis: Article 15(1)(4) of PIPA (entering into and performing a contract)
  • Categories Processed: Service usage records; IP address; cookies; device information; browser and operating-system information; generation request history; feature usage history; access logs; error and service-disruption records; and customer inquiries and feedback
  • Customer Inquiries and Complaints, Service Operations, and Notices
  • Legal Basis: Article 15(1)(4) of PIPA (entering into and performing a contract)
  • Categories Processed: Email address; details of inquiries; records of responses and handling; Service usage records; error and service-disruption records; and, optionally, mobile phone number
  • Payment and Refund Processing
  • Legal Basis: Article 15(1)(4) of PIPA (entering into and performing a contract)
  • Categories Processed: Email address; Member identification information; name of the product or service purchased; payment amount; payment date and time; payment status; payment method; order or transaction number; Subscription Plan and subscription information; and Credit grant, usage, deduction, and refund history
  • For card payments and card registration: Card issuer; partial card number; payment authorization number; and billing key or other payment-method identifier
  • For corporate card registration: Business registration number
  • For digital-wallet or other simplified payments: Payment service provider and payment authorization information
  • For payment cancellations and refunds: Cancellation or refund amount; cancellation or refund date and time; reason for the cancellation or refund; and cancellation or refund status

Information entered during the authentication process for a particular payment method is processed through Toss Payments Co., Ltd. or the applicable payment-method provider. We do not directly store complete card numbers, card verification codes (CVCs), or authentication information for digital-wallet or other simplified payments.

Personal Information Processed With Consent. We process the following categories of personal information with the data subject’s consent:

  • Marketing—Event Notices and Advertising or Promotional Information
  • Legal Basis: Article 15(1)(1) of PIPA (consent)
  • Categories Processed: Email address; name; company name; organizational affiliation; job function; mobile phone number; Service usage records; and event participation history

3. Personal Information of Children Under 14

We do not provide the Service to children under the age of fourteen (14) and do not collect or otherwise process personal information from children under the age of fourteen (14).

4. Processing and Retention of Personal Information

We process and retain personal information for the period prescribed by applicable laws and regulations, for the period necessary to enter into and perform a contract, or for the retention and use period to which the data subject consented at the time the personal information was collected.

As a general rule, we delete a Member’s personal information within thirty (30) days after termination of the Member’s membership. Notwithstanding the foregoing, we retain relevant personal information for the following periods, where applicable:

  • Ongoing investigations or inquiries: If an investigation or inquiry is underway in connection with a violation of applicable laws or regulations, until the investigation or inquiry is concluded.
  • Prevention of re-registration following a violation: If a person’s Service Agreement was terminated due to a violation of applicable laws, regulations, or the Terms of Use, for six (6) months following termination of the person’s membership, to prevent re-registration.
  • Outstanding claims or obligations: If any claim or obligation arising from the use of the Service remains outstanding, until the claim or obligation has been fully settled.
  • Records required under the Act on the Consumer Protection in Electronic Commerce, Etc. (the “E-Commerce Act”):
  • Records relating to contracts or cancellations of orders: Five (5) years (Article 6(1)(2) of the Enforcement Decree of the E-Commerce Act)
  • Records relating to payments and the supply of goods or services: Five (5) years (Article 6(1)(3) of the Enforcement Decree of the E-Commerce Act)
  • Records relating to consumer complaints or dispute resolution: Three (3) years (Article 6(1)(4) of the Enforcement Decree of the E-Commerce Act)
  • Records relating to labeling and advertising: Six (6) months (Article 6(1)(1) of the Enforcement Decree of the E-Commerce Act)
  • Communication confirmation data: Computer communications records, internet log records, and access-location tracking data will be retained for three (3) months pursuant to Article 15-2(2) of the Protection of Communications Secrets Act.
  • Generated output in a shared Workspace: Generated output created and stored by a data subject in a shared Workspace, including canvases and generated images, will be retained until the applicable Workspace is deleted to preserve continuity of work for other Workspace Participants. Information identifying the creator will be anonymized. However, generated output stored in a Workspace with no other Workspace Participants will be destroyed within thirty (30) days after termination of the Member’s membership.

5. Destruction of Personal Information

We promptly destroy personal information when it is no longer necessary, including when the applicable retention period expires or the purpose of processing has been fulfilled.

If we are required under other applicable laws or regulations to continue retaining personal information after the retention period agreed to by the data subject has expired or the purpose of processing has been fulfilled, we transfer the personal information to a separate database or store it in a separate location.

The procedures and methods for destroying personal information are as follows:

  • Destruction Procedure: We identify the personal information for which a ground for destruction has arisen and destroy it upon approval by our Chief Privacy Officer.
  • Destruction Methods: We permanently delete personal information recorded and stored in electronic files so that it cannot be recovered. Personal information recorded and stored in paper documents is destroyed by shredding or incineration.

6. Disclosure of Personal Information to Third Parties

We process personal information only within the scope specified in Section 1. We do not disclose personal information to third parties unless the data subject has separately consented to the disclosure or the disclosure is specifically permitted or required under applicable laws or regulations.

7. Criteria for Additional Use or Provision of Personal Information

Pursuant to Article 15(3) or Article 17(4) of PIPA, we may additionally use or provide personal information without the data subject’s consent after considering the matters prescribed in Article 14-2 of the Enforcement Decree of PIPA. We have considered the following factors:

  • The personal information to be additionally used or provided is used for the original purpose for which it was collected—namely, the provision and operation of the Service—and is reasonably related to that purpose.
  • In light of the circumstances surrounding the Service Agreement, the data subject can reasonably anticipate that personal information may be used or provided to provide and operate the Service.
  • The personal information is used or provided to deliver the Service at the data subject’s request and does not unfairly infringe upon the data subject’s interests.
  • We have implemented measures necessary to ensure the security of personal information and minimize its exposure, including encryption.

8. Entrustment of Personal Information Processing

  • Domestic Processing Arrangements. To facilitate the efficient handling of personal information, we entrust the following personal information processing activities within the Republic of Korea:

Service Provider (Processor)

Entrusted Processing Activities

Subprocessor Information

Toss Payments Co., Ltd.

Payment and refund processing

https://pages.tosspayments.com/terms/homepage/privacy/policy-entrustment

  • Cross-Border Entrustment: Details regarding our entrustment of personal information processing activities outside the Republic of Korea are set forth in Section 9.
  • Contractual Safeguards and Oversight: When entering into an entrustment agreement, we specify in the agreement or another written document, as required by Article 26 of the Personal Information Protection Act, matters concerning the prohibition on processing personal information for purposes other than performing the entrusted activities; technical and administrative safeguards; restrictions on further entrustment; management and oversight of the service provider; liability for damages; and other relevant obligations. We also supervise our service providers to ensure that they process personal information securely.
  • Subprocessors: Under Article 26(6) of the Personal Information Protection Act, a service provider must obtain our consent before further entrusting any personal information processing activities entrusted by us. We disclose the relevant subprocessors and the activities further entrusted to them through this Privacy Policy.
  • Changes to Entrustment Arrangements: If the scope of the entrusted activities or any service provider changes, we will disclose the change without delay through this Privacy Policy.

9. Cross-Border Transfer of Personal Information

General: We transfer personal information collected from data subjects in connection with the Service to recipients outside the Republic of Korea for outsourced processing and storage as described below. In accordance with Article 28-8(2) of the Personal Information Protection Act, we provide the following information regarding such cross-border transfers.

  • Legal Basis for Transfer: Article 26 (Entrustment of Personal Information Processing) and Article 28-8(1)(3) (Entrustment of Processing and Storage) of the Personal Information Protection Act
  • Timing and Method of Transfer: Personal information is transmitted electronically over an encrypted network at the time it is collected.

How to Refuse a Cross-Border Transfer and Consequences of Refusal: If you do not wish your personal information to be transferred outside the Republic of Korea, you may terminate your membership through Workspace > Account > Membership Withdrawal or submit a request to Customer Support at support@shoecatch.ai. However, if you refuse the cross-border transfer of your personal information, you will be unable to use the Service.

Recipient and Country of Transfer

Purpose of Transfer

Personal Information Transferred

Contact Information

Retention and Use Period

Subprocessor Information

Google LLC (Google Analytics) / United States

Analysis of user behavior and improvement of the Service

Date and time of visit, Service usage records, IP address, and cookies

googlekrsupport@google.com

Up to fourteen (14) months from the date of collection

https://cloud.google.com/terms/cloud-privacy-notice

Google LLC (Google Cloud Platform) / United States

Data storage, system operation, and provision of AI features

Account information, Service usage records, server logs, uploaded files, and generated outputs

googlekrsupport@google.com

Until the termination of the processing agreement or the fulfillment of the relevant processing purpose

https://cloud.google.com/terms/cloud-privacy-notice

CORDNET OÜ (Featurebase) / Estonia

Management of customer inquiries, feedback, and user activity information

Name, email address, location information, date and time of access, date and time of last activity, number of web sessions, country, city, time zone, browser language, browser type and version, and operating system (OS)

support@featurebase.app

Until the termination of the processing agreement or the fulfillment of the relevant processing purpose

https://help.featurebase.app/en/articles/4744036-privacy-policy

Tally BV (Tally) / Belgium

Management of inquiry, application, and survey forms

Name, email address, company name, inquiry details, and date and time of submission

hello@tally.so

Until the termination of the processing agreement or the fulfillment of the relevant processing purpose

https://tally.so/help/privacy-policy

Amazon Web Services / United States

Data storage and operation and management of IT systems

Account information (email address), Service usage records, server logs (IP address and date and time of visit), and stored files and data

aws-korea-privacy@amazon.com

Until the termination of the processing agreement or the fulfillment of the relevant processing purpose

https://pages.tosspayments.com/terms/homepage/privacy/policy

Features & Labels Inc. (fal) / United States

AI image and video generation

User-entered text and images processed to provide AI generation features

support@fal.ai

Until the termination of the processing agreement or the fulfillment of the relevant processing purpose

https://fal.ai/privacy

OpenAI, LLC (OpenAI) / United States

Generation and summarization of text based on information provided

User-entered text and images processed to provide AI generation features

info@openai.com

Thirty (30) days from the date of collection

https://openai.com/policies/row-privacy-policy/

Stability AI Ltd. (Stability AI) / United States

Provision of AI generation features

User-entered text and images processed to provide AI generation features

privacy@stability.ai

One (1) year from the date of collection

https://stability.ai/privacypolicy

Anthropic, PBC (Claude) / United States

Image generation based on information provided

User-entered text and images and Service usage records

privacy@anthropic.com

Thirty (30) days from the date of collection

https://www.anthropic.com/legal/consumer-terms

Topaz Labs LLC (Topaz) / United States

Enhancement of image and video quality

Uploaded images and videos and generated outputs

privacy@topazlabs.com

Until the termination of the processing agreement with fal or the fulfillment of the relevant processing purpose

https://www.topazlabs.com/privacy-policy

QuiverAI (Quiver.ai) / Canada

Provision of AI generation features

User-entered text, uploaded images, and generated outputs

support@quiver.ai

Until the termination of the processing agreement or the fulfillment of the relevant processing purpose

https://withquiver.com/privacy-policy

ByteDance Pte. Ltd. (ByteDance) / Singapore

Provision of AI generation features

User-entered text, uploaded images, and generated outputs

privacy@byteplus.com

Until the termination of the processing agreement with fal or the fulfillment of the relevant processing purpose

https://seed.bytedance.com/en/privacy-policy

Kling AI Pte. Ltd. (Kling AI) / Singapore

AI image and video generation

User-entered text, uploaded images, and generated outputs

support@kling.ai

Until the termination of the processing agreement with fal or the fulfillment of the relevant processing purpose

https://kling.ai/document-api/guides/protocols/privacy-policy

Black Forest Labs Inc. (FLUX) / Germany

AI image generation

User-entered text, uploaded images, and generated outputs

support@blackforestlabs.ai

Until the termination of the processing agreement with fal or the fulfillment of the relevant processing purpose

https://bfl.ai/legal/privacy-policy

10. Security Measures for Personal Information

We implement the following measures to protect personal information and ensure its security:

  • Administrative Measures: Establishment and implementation of an internal management plan for personal information; regular employee training; and operation of a dedicated privacy organization.
  • Technical Measures: Management of access rights to personal information processing systems; installation of access-control systems and implementation of other related safeguards; measures to isolate systems from external internet networks; encryption of personal information; retention and review of access logs; installation, operation, and updating of security software; identification and remediation of vulnerabilities in personal information processing systems; separate storage of pseudonymized information and additional information; destruction of additional information when it is no longer necessary; and separation and control of access rights to pseudonymized information and additional information.
  • Physical Measures: Access controls for computer rooms, data storage rooms, and similar facilities; storage of documents and removable storage media in secure, locked locations; safeguards against disasters and emergencies; and controls over the movement of removable storage media into and out of controlled areas.
  • Safeguards for AI-Related Processing: When providing AI generation features, we manage input text, uploaded images, generated outputs, and related information to ensure that they are processed only within the scope necessary to provide the Service. Data transferred to AI model providers is processed in accordance with the applicable agreement or the relevant provider’s policies. We also take necessary measures to prevent user-entered data from being used unnecessarily for model training.

[View the Data Processing Policies of Third-Party AI Service Providers]

For additional information regarding our use of generative AI and the identification and labeling of AI-generated content, please refer to the Terms of Use.

11. Use of Cookies and How to Manage Cookie Settings

  • Use of Cookies: We use cookies to store and periodically retrieve usage information in order to provide data subjects with personalized services and convenient features.
  • What Cookies Are: Cookies are small amounts of information sent to a data subject’s browser by the web server used to operate a website. Cookies are stored on the data subject’s computer or mobile device and are automatically transmitted from the browser to the server when the data subject accesses the website.
  • How to Manage or Block Cookies: Data subjects may refuse or otherwise manage cookies by adjusting their browser settings as described below.

Desktop Web Browsers:

  • Chrome: Settings > Privacy and Security > Third-party cookies > Block third-party cookies
  • Microsoft Edge: Settings > Cookies and Site Permissions > Manage and Delete Cookies and Site Data
  • Safari: Settings > Privacy > Block Cookies

Mobile Browsers:

  • Chrome: Settings > Site Settings > Cookies
  • Safari: Device Settings > Apps > Safari > Advanced > Block All Cookies
  • Samsung Internet: Select the "Tab" icon at the bottom of the browser > Turn on Secret Mode > Start

12. Collection of Behavioral Information by Third Parties

Third-Party Collection Technologies. For statistical analysis and improvement of the Service, we permit the following third parties to collect behavioral information through automated collection technologies:

Collection Tool

Technology Used

Collecting Entity

Behavioral Information Collected

Purpose of Collection

Google Analytics

JavaScript tags and cookies

Google, Inc.

Website visit history and browser information

Statistical analysis

Featurebase

JavaScript SDK

Cordnet OÜ

Name, email address, location information, date and time of last activity, date and time of first access, number of web sessions, country, city, time zone, browser language, browser type and version, and operating system

Customer support, feedback management, and management of documentation relating to use of the Service

Tally

iframe and JavaScript embed

Tally B.V.

Name, email address, company name, inquiry details, and date and time of submission

Provision of inquiry and application forms

Managing the Collection of Behavioral Information: You may allow or block the collection of behavioral information by third parties by changing your browser’s cookie settings or using similar controls. For instructions on how to block cookies, please refer to “How to Manage or Block Cookies” in Section 11.

13. Processing of Pseudonymized Information

In accordance with Article 28-2 of the Personal Information Protection Act, we pseudonymize personal information we collect so that specific individuals cannot be identified and use such information for purposes including the compilation of statistics and scientific research, as described below:

Category

Purpose of Processing

Items Used

Retention and Use Period

Compilation of statistics and scientific research

Compilation and analysis of statistics regarding usage behavior to improve the Service

Prompts and configuration values entered by you

Ten (10) years after pseudonymization

14. Rights and Obligations of Data Subjects and Legal Representatives and How to Exercise Them

  • Your Rights and How to Exercise Them: You may at any time request access to or transmission of your personal information, correction or deletion of your personal information, suspension of its processing, or withdrawal of your consent (collectively, a “Rights Request”). You may submit a Rights Request in writing, by telephone, email, through the Internet, or by other means in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act. We will take action on your request without delay. You may also exercise your rights through the following Service menus:
  • Through “Workspace > Settings > Account,” you may directly view, correct, or delete your personal information; request suspension of its processing; withdraw your consent; or submit a request for access.
  • Through “Workspace > Settings > Account,” you may object to an automated decision and request an explanation regarding that decision.
  • Exercise of Rights Through a Representative: You may exercise your rights through a representative, such as your legal representative or an authorized agent. In such cases, you must submit a power of attorney using Form No. 11 appended to the Notice on the Methods of Processing Personal Information.
  • Limitations on Rights Requests: The exercise of the rights described in this Section may be restricted in accordance with applicable laws and regulations. For example, the rights to request access to personal information and suspension of processing may be restricted under Article 35(4) and Article 37(2) of the Personal Information Protection Act. If another law or regulation expressly requires certain personal information to be collected, you may not request deletion of that personal information.
  • Identity Verification and Response Period: We verify whether the person submitting a Rights Request is the relevant data subject or a duly authorized representative. You may submit a Rights Request to the department identified below. We will respond within ten (10) days after receiving your request, or without delay in the case of a request for transmission.
  • Department Responsible for Receiving and Processing Rights Requests. You may submit a Rights Request to the following department:
  • Department Name: BizAX Team
  • Address: 1F, 415 Sasang-ro, Sasang-gu, Busan, Republic of Korea (Mora-dong)
  • Contact: support@shoecatch.ai, +82 70-4027-2132 (within Korea: 070-4027-2132)

15. Chief Privacy Officer

  • Designation of Chief Privacy Officer. We have designated the following Chief Privacy Officer to oversee and take responsibility for all matters relating to the processing of personal information, including handling complaints and providing remedies for damage arising from such processing:

Chief Privacy Officer (CPO)

  • Name: Lee, Min-young
  • Title: D/CEO
  • Contact: yeong@kristinkorea.com, +82 70-4027-2132 (within Korea: 070-4027-2132)

Department Responsible for Personal Information Protection

  • Department Name: BizAX Team
  • Contact: support@shoecatch.ai, +82 70-4027-2132 (within Korea: 070-4027-2132)
  • Privacy Inquiries and Complaints: You may contact our Chief Privacy Officer or the department responsible for personal information protection regarding any privacy-related inquiry, complaint, or request for remedies arising from your use of the Service or otherwise in connection with our business. We will respond to and process your inquiry without delay.

16. Remedies for Infringement of Rights

If you wish to seek remedies, including dispute resolution or consultation, in connection with an infringement of your personal information, you may file a report or request consultation with any of the following agencies:

  • Personal Information Dispute Mediation Committee: 1833-6972 (within Korea; no area code required)
  • Personal Information Infringement Reporting Center: 118 (within Korea; no area code required)
  • National Police Agency: 182 (within Korea; no area code required)

17. Additional Disclosures for Data Subjects in the EU/EEA

If you are located in the European Union (“EU”) or the European Economic Area (“EEA”), we process your personal information in accordance with the General Data Protection Regulation (“GDPR”), to the extent applicable.

  • Data Controller: The Company acts as the data controller with respect to the processing of your personal information for purposes of the GDPR.
  • Legal Bases for Processing. Depending on the specific context and purpose of processing, we process your personal information on one or more of the following legal bases:
  • your consent (e.g., for communications);
  • performance of a contract (e.g., account creation, payment processing);
  • compliance with a legal obligation (e.g., tax and accounting requirements); or
  • legitimate interests pursued by us or a third party (e.g., service improvement, fraud prevention), provided that your fundamental rights are not overridden.
  • International Data Transfers: Your personal information may be transferred to, stored in, or processed in countries outside the EU/EEA, including the Republic of Korea, the United States, and the other countries identified in Section 9. In such cases, we implement appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, to protect your information.

When personal information of EEA residents is transferred to a third country outside the EU/EEA, the Company transfers personal information based on one of the following lawful bases in accordance with GDPR Chapter V:

  • An adequacy decision adopted by the European Commission, including the adequacy decision covering the Republic of Korea;
  • For transfers to a U.S. organization that participates in the EU-U.S. Data Privacy Framework, the applicable adequacy decision concerning that framework;
  • Execution of Standard Contractual Clauses (SCCs) approved by the European Commission (applying additional technical and administrative safeguards such as encryption, access control, and internal management procedures if necessary); or
  • Where the user's explicit consent has been obtained, or where the transfer is necessary for the performance of a contract with the user (e.g., provision of online services, account management, customer support, or payment processing).
  • Retention Period: We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including the periods described in Section 4, unless a longer period is required or permitted by applicable law.
  • Your Rights Under the GDPR: Subject to applicable law, you have the right to access; rectify; erase your personal information; restrict or object to its processing; and request data portability. You may also withdraw your consent at any time when processing is based on consent, without affecting prior lawful processing, and you have the right to lodge a complaint with your local data protection authority. In particular, you may lodge a complaint with the supervisory authority in the Member State of your habitual residence, place of work, or place of the alleged infringement.

If, notwithstanding Section 2, we process special category data, we will do so only where both a lawful basis under Article 6 and a condition under Article 9 of the GDPR apply (for example, your explicit consent). You may object at any time to our use of your data for direct marketing, and in other cases where processing is based on legitimate interests, unless we demonstrate overriding grounds. You also have the right not to be subject to automated decision-making, including profiling, that produces legal or similarly significant effects.

  • Cookies and Similar Technologies: For users located in the EU/EEA, except for cookies and similar technologies that are strictly necessary to provide the Service, we use analytics, advertising, or marketing cookies and similar technologies only with your prior consent, where required by applicable law. You may manage or withdraw your consent at any time through the cookie settings provided on our website. Withdrawal of consent does not affect the lawfulness of processing conducted before withdrawal.
  • EU Representative. Where required under Article 27 of the GDPR, we have appointed the following representative in the EU:
  • Name: Lee, Min-young
  • Email: yeong@kristinkorea.com
  • Address: 1F, 415 Sasang-ro, Sasang-gu, Busan, Republic of Korea (Mora-dong)
  • You may contact our EU representative regarding matters relating to the processing of your personal information under the GDPR.

18. Additional Disclosures for California Residents

If you are a resident of the State of California, you have additional rights under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (“CPRA, collectively the CCPA), to the extent the CCPA applies to our processing of your personal information.

  • Notice of Collection: During the preceding twelve (12) months, we have collected the following categories of personal information, as defined under the CCPA: identifiers (such as email address, mobile phone number, online identifiers, user ID, and IP address); commercial information (such as the name of the product or service purchased, Subscription Plan and subscription information, payment amount, payment date and time, payment status, payment method, order or transaction number, Credit grant, usage, deduction and refund history, cancellation or refund records, and customer inquiries and complaints); internet or other electronic network activity information (such as Service usage records, cookies, device information, browser and operating system information, access logs, generation request history, feature usage history, error and service disruption records, and Service access-permission information); professional or employment-related information (such as company name, organizational affiliation, and job function, where voluntarily provided); and user-generated content (such as Content input, uploaded, generated, or stored by users and records relating to the processing of such Content).
  • We collect personal information directly from you, automatically through your interactions with the Service, through account authentication and payment service providers; and from third-party integrations and service providers supporting authentication, payments, analytics, customer support, feedback management, forms, cloud infrastructure, and AI functionality.
  • Purposes for Collection and Use: We collect and use these categories of personal information for the business and commercial purposes described in California Civil Code § 1798.140(e), including providing, operating, and maintaining the Services; processing transactions and payments; verifying identity and preventing fraud; providing customer support and responding to inquiries; personalizing user experiences and delivering tailored content; conducting analytics and improving service performance; administering promotions, events, and marketing communications; improving services; and complying with applicable legal obligations and regulatory requirements.
  • Disclosure of Personal Information. During the preceding twelve (12) months, we may have disclosed personal information for business purposes to the following categories of service providers, contractors, and other recipients:
  • Payment processors and financial institutions;
  • Customer support and call center service providers;
  • Cloud service or data storage providers and IT infrastructure vendors;
  • AI model and content-processing service providers;
  • Data analytics providers;
  • Advertising and marketing partners;
  • Fraud prevention, security, and risk management vendors; and
  • Professional advisors and regulators, where required by law.
  • Additional information concerning individual service providers and overseas recipients is provided in Sections 8 and 9.
  • Sensitive Personal Information: We collect certain categories of sensitive personal information, such as account log-in information in combination with passwords or other credentials that permit access to an account.

We use or disclose this sensitive personal information only for purposes permitted under Cal. Code Regs. tit. 11, § 7027(m), including providing the services you request, ensuring security and integrity, processing payments, preventing fraud, and performing services on our behalf. We do not use or disclose sensitive personal information for any purposes other than those permitted under applicable law. Accordingly, the right to limit the use and disclosure of sensitive personal information does not currently apply to our practices.

  • Storage and Location of Personal Information: Your personal information may be stored or processed in the Republic of Korea, the United States, and the other countries identified in Section 9. We retain each category of personal information only for as long as reasonably necessary for the purposes for which it was collected or as required or permitted by law. The applicable periods and criteria used to determine those periods are described in Section 4.
  • Minors Under 16: We do not have actual knowledge that we sell or share the personal information of consumers under the age of sixteen (16). If this changes, we will update this Privacy Policy and provide the opt-in and parental consent rights required under applicable law. As described in Section 3, we do not provide the Service to children under fourteen (14) years of age and do not knowingly collect or process their personal information.
  • Your Rights under the CCPA: California residents have the right to (a) know and access the categories and specific pieces of personal information we collect, use, and disclose; (b) request access to or deletion of personal information, subject to statutory exceptions; (c) request correction of inaccurate personal information or obtain a copy of their personal information in a portable and, to the extent technically feasible, readily usable format; (d) opt out of the sale or sharing of personal information; (e) limit the use and disclosure of sensitive personal information; and (f) not be discriminated against for exercising these rights.
  • Sale or Sharing of Personal Information; We do not sell personal information for monetary or other valuable consideration, and we do not share personal information for cross-context behavioral advertising, as “sell” and “share” are defined under the CCPA.
  • Limitation of Use of Sensitive Personal Information: We do not use or disclose sensitive personal information for purposes other than those permitted under Cal. Code Regs. tit. 11, § 7027(m). Accordingly, the right to limit the use and disclosure of sensitive personal information does not apply.
  • Exercising Your California Rights: You may exercise your California rights through the account settings described in Section 14 or by contacting us at support@shoecatch.ai. We may request information reasonably necessary to verify your identity and authority to make the request. We will respond within forty-five (45) days after receiving a verifiable request. Where reasonably necessary, we may extend this period by an additional forty-five (45) days after notifying you of the extension and the reason for it.
  • Authorized Agent: You may designate an authorized agent to submit requests on your behalf. We may require proof of authorization and verification of your identity before processing such requests.

19. Additional Disclosures for Nevada Residents

Under Nevada law (NRS 603A.340), if you are a Nevada resident, you may submit a request directing us not to sell certain kinds of personal information that we have collected or will collect about you. For purposes of this section, a “sale” under Nevada law means the exchange of personal information for monetary consideration by a business to a third party, for the third party to license or sell the personal information to additional third parties.

We do not currently sell personal information as defined under Nevada law; however, you may exercise your rights by contacting us at support@shoecatch.ai.

We will respond to a verified request within sixty (60) days after receiving it. We may extend the response period by up to thirty (30) additional days where reasonably necessary, after notifying you of the extension.

20. Changes to the Privacy Policy

  • Notice of Changes: We may update or amend this Privacy Policy, including to reflect changes in applicable laws or the Service. If we make any changes to this Privacy Policy, we will post notice of those changes at least seven (7) days before they take effect.
  • Effective Date and Previous Versions: This Privacy Policy is effective as of July 23, 2026.
  • Previous versions of this Privacy Policy are available below:
  • Effective from May 31, 2026 through July 22, 2026 ([View])