local/seoul

Privacy Policy

Effective 2026-09-16 · Previous version 2026-09-10

This document is interpreted on the basis of its English version. Translations are provided for reference only; if a translation is inconsistent with the English text, the English text prevails, except as otherwise provided in Section 14 of the Terms of Service.

Profile face photos and display consent

We collect profile face photos, the submission time and the related confirmations and consents to support trust, mutual recognition and meeting coordination. Confirming that a photo shows you is separate from consenting to its display.

Local photos may appear on public Local profiles only with separate, explicit public-display consent and applicable Local and photo approval. Public-display consent is optional; without it, the Local card is not shown publicly. The photo may still be shared within authorised matching and meeting coordination under the separate sharing consent.

Traveler photos are not displayed on public Local cards. They are available to the Traveler through their secure request link, authorised approved Locals in request-board and matching flows, and the operations team as needed for review and coordination. They are not used for public marketing under this consent.

Photo submission records the new confirmations and consents; we do not apply them retroactively or reuse identity-document copies as profile photos. You may submit a replacement photo; replacement photos are reviewed again. A Local may choose not to give public-display consent when replacing a photo. For removal, withdrawal or other privacy requests, use the contact and rights procedures in this Privacy Policy. Its existing retention provisions apply. Consent for meetup-proof publication is separate.

1. Scope and controller

This Privacy Policy explains how Kohwoon & Company Co., Ltd. ("we", "us") collects, uses, shares, and protects personal data when you use local/seoul at localseoul.com (the "Service"). We are the data controller (개인정보처리자) for this data.

We process personal data in accordance with the Personal Information Protection Act of Korea (PIPA), the Act on Promotion of Information and Communications Network Utilization and Information Protection, and, for Users located in the European Economic Area, the United Kingdom, or other jurisdictions with comparable laws, the rights described in Section 10.

Capitalised terms not defined here have the meaning given in the Terms of Service.

2. Personal data we collect

We collect only what the matching flow needs. Required items are marked with an asterisk on our forms; everything else is optional and you can leave it blank.

Travelers (when submitting a meetup request):

  • Required: name, email address, nationality, gender, arrival and departure dates, party size (1–4), preferred neighborhoods (or the Local you chose), interests, and your message to the Local.
  • Optional: a link to a public social-media profile, and a WhatsApp or phone number used only to coordinate the meetup after a match. Your email address, phone or messenger contact, and social-media link are never shown on the request board; they are provided only to the one Local you are matched with.
  • Your attestation that you are 19 or older, and your answer to each consent item on the form (collection and use, provision to verified Locals as described in Section 4, Terms and Safety Rules, service notices, and the optional marketing opt-in).

Locals (when applying, browsing the request board, and accepting meetups):

  • Required: real name (verification only, never shown), email address, mobile phone number (acceptance links, new-request notices and reminders are sent by SMS and email), the neighborhoods you are active in, English level, and at least one public SNS link (e.g. Instagram or LinkedIn) shown on your profile card so Travelers can see who you are.
  • Optional: nickname shown to Travelers, interests, availability, and a short self-introduction.
  • A copy of a government-issued ID that you have masked yourself (see Section 5), kept for at most 30 days.
  • Your attestation that you are 19 or older, and your answer to each consent item (collection and use, public profile including English level and SNS link, provision to matched Travelers, Terms and Safety Rules, ID masking confirmation, and the optional marketing opt-in).
  • The meeting time and public place you propose when choosing or accepting a request.
  • Board activity records: your login events and a log of which request cards you viewed and when, kept as an access record for the personal data shown on those cards.

Consent records (both): for every form submission we keep the items you agreed to or declined, the version of this policy shown to you, the date and time, your IP address, and your browser's user-agent string, as evidence that consent was given.

Chat (matched pairs only):

  • Messages you send in the one-to-one web chat with your matched counterpart, including text and emoji.
  • Image attachments (converted to a reduced size on our servers) and short video attachments of up to 15MB, together with sent times and related metadata, stored with the request record.

Support chat (any visitor, optional):

  • Messages you type into the support chat window on our public pages, any name or contact you choose to include, the time sent, your browser language and the page you were on. The chat is opened only when you click the chat button; just visiting sends nothing.
  • A visitor token kept in your browser storage and a first-party cookie (1 year) so a returning visitor can see their earlier conversation. It is not linked to a traveler or Local account.

Photo & Gift Program (either party):

  • A photo taken together at the meetup, the date, and the meetup token or email you submit it with.
  • The mobile number or email address needed to deliver the Starbucks e-gift card.

Automatically collected (all visitors):

  • First-party cookies: ls_vid (anonymous visitor ID, 1 year) and ls_src (acquisition source, 90 days).
  • Event log: pages viewed, buttons clicked, form steps completed, timestamps, referrer, UTM parameters, browser and device type, approximate country derived from IP address, and a truncated IP address for rate-limiting and abuse prevention.

3. Why we use your data and legal basis

We use personal data for the following purposes:

  • Matching and coordinating meetups, including sending acceptance links, new-request notices and meetup reminders by SMS and email, and exchanging contact details after acceptance — performance of our agreement with you (Terms of Service).
  • Verifying the identity of Locals — our legitimate interest in and legal responsibility for community safety; your consent to the upload of the ID copy.
  • Running the Photo & Gift Program, including verifying photos and delivering Starbucks e-gift cards — performance of our agreement and compliance with tax and accounting law.
  • Responding to safety reports, preventing fraud and abuse, and enforcing our rules — legitimate interest and legal obligations.
  • Automatically screening chat messages and attachments for safety signals, notifying our team, and pausing a chat when needed — our legitimate interest in and legal responsibility for community safety (see Section 4).
  • Measuring how the Service is used, diagnosing problems, and improving the product — legitimate interest, using first-party analytics only.
  • Sending service messages (confirmations, acceptance notices, gift delivery). We do not send marketing email unless you opt in separately.
  • Complying with legal obligations, including record-keeping under Korean e-commerce and tax law.

Under PIPA, the collection described in Section 2 is necessary to provide the Service you requested; where we rely on consent (ID upload, photo publication), you may withdraw it at any time.

4. Who we share data with

We do not sell personal data and do not share it with advertisers or data brokers.

Provision to the other party of your meetup. Matching only works if each of you learns something about the other, so both forms ask for a separate consent to this provision. What is provided, and when:

  • To Locals, while your request is open: your request card — name, nationality, gender, travel dates, party size, neighborhoods, interests, message, and whether a profile link was provided (not the link itself) — is shown on the request board to identity-verified, approved Locals who log in. If you named a specific Local, the card is shown to that Local only; if they decline or do not respond, it is posted to the board only where you opted in. Your email address, phone or messenger contact, and social-media link are never shown on the board.
  • To the one Local you are matched with, only after the match: the Traveler's email address, the social-media link if given, and, if given, WhatsApp or phone number.
  • To the Traveler: the Local's public profile (nickname, neighborhoods, interests, introduction, English level, SNS link) from the moment the request is matched, and, after the match, the proposed times and public place and the Local's email address and mobile number so the two of you can coordinate directly.
  • Purpose: deciding whether to meet, and coordinating the meetup. Recipients may use the data for that purpose only and may not keep, share, or reuse it after the meetup is complete; both parties are bound by the Safety & Community Rules.
  • We keep a log of which Locals viewed which request cards, as an access record for the personal data shown. If a match is cancelled or released, the Local involved may not retain the card data, and the card reopens to other Locals on the same terms. If you refuse this provision we cannot match you.
  • Chat: messages and attachments sent in the matched pair's one-to-one web chat are shown to the other matched party only; they are not visible to any other User. Our staff may view chat content only when handling a report, resolving a dispute, or investigating suspected fraud or abuse.

With service providers acting on our instructions (processors), limited to what they need:

  • SMS delivery provider in Korea — Local's mobile number and the acceptance message.
  • Email delivery provider — email address and message content.
  • Cloud hosting located in the Republic of Korea — all data, encrypted at rest.
  • Mobile gift-voucher issuer — recipient's mobile number or email and the voucher amount.
  • Internal notification tooling (e.g., Slack) — request summaries for our operations team.
  • Support chat system (Kanal, operated by us on our own server in the Republic of Korea; the chat script is loaded from portal.k0.xyz) — chat messages, the visitor token and the page address, and a notice of each new conversation to our operations team.

Automated safety screening of chat. To protect Users, chat messages and attachments may be checked automatically. This screening is separate from staff review, which remains limited to reports, disputes, and suspected fraud or abuse:

  • An automatic filter (keyword rules) runs on our own servers.
  • An external AI classification service, OpenAI, L.L.C. (United States), may classify message text and image attachments. Content is sent solely for that classification, is processed immediately, and is not used to train the provider's models (we use the provider's settings that exclude our data from training).
  • If a risk signal is detected, our operations team is notified and the chat may be paused immediately, pending review. A paused chat becomes read-only for both parties; you can still reach us by email.

Cross-border transfer of personal data (PIPA Article 28-8). The AI classification above transfers personal data outside Korea. This is an entrustment of processing necessary to provide the chat you use, disclosed here under Article 28-8(1)(iii); the details are:

  • Recipient: OpenAI, L.L.C., United States of America (privacy@openai.com).
  • Items transferred: the text of chat messages and image attachments sent in chat.
  • When and how: at the moment a message or image is sent, over an encrypted API connection.
  • Recipient's purpose of use: automated classification of the content for safety (for example solicitation, threats, sexual content, or harassment).
  • Recipient's retention period: processed immediately for classification; under the provider's API data policy, content may be retained for up to 30 days for abuse monitoring and is then deleted.
  • How to refuse, and the effect: do not use the chat — you can coordinate your meetup by the email address and phone number exchanged after a match. Chat cannot be used without this screening.

With authorities: where required by law, court order, or where we reasonably believe disclosure is necessary to prevent harm or investigate a safety report.

We will publish an updated list of processors on request.

5. Identity documents

To keep Travelers safe, every Local must verify their identity before appearing on the Service. You do this by uploading a copy of a government-issued ID (Korean resident registration card, driver's licence, passport, or alien registration card).

You must mask sensitive fields yourself before uploading — in particular the last seven digits of a resident registration number, the licence number, and the passport number. We only need to see your name, photo, and date of birth. You are responsible for any exposure caused by uploading an unmasked document; if we receive one, we will mask or delete it and ask you to resubmit.

ID copies are stored encrypted, accessible only to the two staff members responsible for verification, and are destroyed as soon as verification is complete and in any case within 30 days of upload. We keep only a record that verification was completed, the document type, and the date.

6. Photos and publication

Photos submitted to the Photo & Gift Program are used to verify that a meetup actually took place. They are reviewed by our staff and stored with the meetup record.

Submitting a photo includes consent, given on the submission page, to publication on localseoul.com and our social channels with first names only — this is a condition of the Gift Program, and the person submitting confirms the other person in the photo also agrees. You may withdraw consent at any time by emailing us, and we will remove the photo from channels we control within 10 business days. Copies already shared by third parties may be outside our control.

7. Cookies and analytics

We use only first-party cookies and our own event log. We do not use third-party advertising pixels, remarketing tags, or cross-site tracking.

  • ls_vid — a random identifier that lets us count unique visitors and connect the steps of a request. Expires after 1 year.
  • ls_src — remembers how you first found us (e.g., a UTM source or referrer) so we know which channels work. Expires after 90 days.
  • Session and security cookies — needed for form submission, admin login, and CSRF protection; deleted when you close the browser or shortly after.

You can delete or block cookies in your browser settings. The Service will still work, but we may not be able to connect a request to the pages you viewed before it.

8. Retention and deletion

We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it:

  • Meetup requests that are never accepted — deleted 90 days after the request date.
  • Accepted meetups and exchanged contact details — 1 year after the meetup date, to handle reports and disputes.
  • Chat messages and attachments — stored with the request record for 1 year after the meetup (or the end of the match), the same as meetup records; deleted immediately on your request.
  • Automated safety-screening results (flags) — kept with the chat record for the same period as the chat.
  • Local profiles — destroyed 12 months after your last activity on the Service, or immediately on your request.
  • ID copies — destroyed on verification and within 30 days at most (Section 5).
  • Meetup photos — 1 year after submission unless you have consented to publication, in which case until you withdraw consent.
  • Gift delivery records — 5 years, as required by Korean tax and e-commerce record-keeping law.
  • Board view and login logs (Locals) — 1 year from the date of the record, as an access record for personal data.
  • Event log and cookies — raw events 13 months; aggregated statistics indefinitely without personal identifiers.
  • Safety reports and ban records — retained for as long as necessary to enforce a ban and protect other Users.

Electronic files are deleted using methods that prevent recovery; paper records, if any, are shredded.

9. Where data is stored and how it is protected

Personal data is stored on servers located in the Republic of Korea. SMS, email, gift-voucher, and AI safety-classification providers may process the minimum data needed for delivery or classification; where a provider is located outside Korea (see the cross-border transfer notice in Section 4), we rely on your consent at the time of collection, on disclosure in this policy, or on the provider's contractual safeguards.

We protect data with encryption in transit (TLS) and at rest, access controls limited to named staff, rate limiting, audit logs of administrative access, and regular review of stored files. Acceptance links and meetup tokens are single-purpose, time-limited, and unguessable.

No system is perfectly secure. If a breach affecting your data occurs, we will notify you and the relevant authority as required by law, without undue delay.

10. Your rights

Under PIPA you may at any time request access to your personal data, correction of inaccurate data, deletion, or suspension of processing, and you may withdraw consent. You may exercise these rights through a legal representative.

If you are located in the EEA, the UK, or another jurisdiction with comparable law, you additionally have the rights to restriction of processing, data portability (a copy of the data you provided in a machine-readable format), and objection to processing based on legitimate interest, and the right to lodge a complaint with your local supervisory authority.

To exercise any right, email kwad@kohwoonc.com from the address you used with the Service, or describe how we can verify your identity. We will respond within 10 business days. We do not charge a fee unless requests are manifestly unfounded or excessive.

Korean residents may also contact the Personal Information Protection Commission's Privacy Call Center (privacy.go.kr, 118) or the Korea Internet & Security Agency (KISA) if they believe their rights have been infringed.

11. Minors

The Service is for adults aged 19 and over. We do not knowingly collect personal data from anyone under 19. If you believe a minor has provided us with data, please contact us and we will delete it.

12. Safety & Community Rules

Our expectations for conduct before, during, and after a meetup, how to report a concern, and what we do about violations have moved to a dedicated document: Safety & Community Rules at /rules. Safety reports are handled at kwad@kohwoonc.com within 24 hours.

13. Changes to this policy

We may update this policy as the Service evolves. We will post the new version here with a new effective date and, for material changes affecting Users with an active request or profile, notify you by email at least 7 days in advance. This version (effective 2026-09-09) replaces the version dated 2026-09-08; the main changes are the request board (cards visible to verified Locals, contact details hidden until a match, view logs kept), the Local dashboard login, unified retention wording for Local profiles, the one-to-one web chat for matched pairs, and automated safety screening of chat that includes a cross-border transfer to an AI classification provider in the United States (Section 4).

14. Privacy officer and contact

Privacy Officer (개인정보 보호책임자): Junsung Koh, CEO, Kohwoon & Company Co., Ltd.

Email kwad@kohwoonc.com · Tel 070-4769-0213 · 7F, 110-1 Bucheon-ro, Wonmi-gu, Bucheon-si, Gyeonggi-do, Republic of Korea.

Please include "Privacy" in the subject line so we can route your request quickly.

Who can see your request?

Optional: identity-verified, approved locals across Seoul may see your request card (name, nationality, gender, travel dates, party size, neighborhoods, interests, message, approved face photo, preferred languages, and whether you provided a contact or profile link) to decide whether to meet you. Your chosen meeting neighborhoods stay the same. Your email, contact details and profile link are shared only with the one matched local. Locals may use the card only for arranging a meetup and must not retain it after the meetup. Without this consent, only locals in your chosen neighborhoods can browse your card. You can withdraw it on this page while your request is open. A request addressed to one specific local stays private until you separately allow it onto the board.

Friend proposal and safety records

Proposals, approval and ignore actions are recorded with the request. Block records hash the traveler/local email pair and, when available, the traveler account ID to apply protection across requests. Undelivered messages and attachments are visible only to the sender and authorized safety staff. Private ignore/block records are not disclosed to the counterpart. Existing message storage and access rules apply; this notice does not establish a new retention period.

Operator

고운앤컴퍼니(주) · Kohwoon & Company Co., Ltd.
CEO 고준성 (Junsung Koh) · Business registration no. 707-88-01791
경기도 부천시 원미구 부천로 110-1, 7층 (원미동, 한위빌딩)
7F, 110-1 Bucheon-ro, Wonmi-gu, Bucheon-si, Gyeonggi-do, Korea
Tel 070-4769-0213 · kwad@kohwoonc.com

local/seoul is a social matching platform, not a travel agency. It does not sell, arrange, or guide tours.