PRIVACY POLICY
Privacy Policy
The Operator publishes this policy under Article 30 of the Personal Information Protection Act of Korea to protect the personal information of guests and site visitors and to handle related concerns promptly.
Article 1 — Purposes of processing
- Receiving, confirming and settling accommodation reservations (this site's booking flow and booking channels such as Airbnb)
- Managing member accounts (when you create an account on this site)
- Communicating with guests (inquiries, messages, translation)
- Check-in and check-out confirmation, cleaning and facility operations
- Facility safety and prevention of fire and theft (video monitoring of common areas)
- Operational statistics (primarily de-identified aggregates)
Article 2 — Items collected and how
| Category | Items | How collected |
|---|---|---|
| Booking on this site | Stay dates, guests, payment amount, and the booker's name, email and mobile phone taken from the member account | Taken from the signed-in account on the booking screen (contact details are passed to Toss Payments to process the payment) |
| Member account (required) | Name, email, password, mobile phone number | Entered on the signup screen. The password is stored only in a non-reversible form and never kept in plain text. The phone number is collected so we can reach you and establish the facts if an incident or damage occurs during the stay |
| Member account (optional) | Nationality, gender, marketing consent | Entered on the signup screen only if you wish. Leaving them blank places no limit on signing up or booking |
| Email verification | Email address, verification code (stored only in a non-reversible form), attempt count | Confirms ownership of the email at signup — the code itself is never stored |
| Keeping you signed in | Session identifier (stored only in a non-reversible form), issue and last-used time | Created automatically at sign-in — held in the browser only as an HttpOnly cookie |
| Channel bookings | Name, phone number (when the channel provides it), country and language, check-in/check-out dates, guests, payment amount | Collected indirectly from booking platforms such as Airbnb through channel integration (Art. 20) |
| Guest conversations | Messages, reviews, email and Instagram inquiries | Booking platform message integration; inquiries sent by guests |
| Check-out confirmation | Device information of devices connected to the house WiFi (MAC address, device name, signal strength) | House router |
| Facility safety | CCTV footage of common areas such as house entrances | Fixed video equipment (see Article 9) |
※ We do not collect resident registration numbers. Payment card numbers are handled by the payment processor (Toss Payments) and are not collected or stored by the Operator. We do not collect passport numbers (removed from the collected items on 2 September 2026). This service is not directed at children under 14 and we do not knowingly collect children's personal information.
Article 3 — Retention and deletion
| Item | Retention | Basis |
|---|---|---|
| Reservation and payment records | 5 years after check-out, then de-identified (first letter of the name only) and phone numbers deleted | E-Commerce Act (contract and payment records, 5 years) |
| Guest conversations and inquiries | Deleted after 3 years | E-Commerce Act (consumer complaint and dispute records, 3 years) |
| Member account details | Deleted without delay upon account deletion request | Deleted when the purpose is fulfilled |
| Email verification codes | Unusable 10 minutes after they are issued; deleted by the daily automatic clean-up | Deleted when the purpose is fulfilled |
| Sign-in sessions | Unusable 90 days after the last sign-in and deleted by the daily automatic clean-up (all sessions are deleted immediately when the password changes) | Deleted when the purpose is fulfilled |
| Password reset links | Unusable 30 minutes after they are issued; deleted by the daily automatic clean-up | Deleted when the purpose is fulfilled |
| WiFi device information | Deleted within 90 days of last detection | Check-out confirmation purpose fulfilled |
| Check-out detection records | Deleted after 1 year | Operational confirmation purpose fulfilled |
| Service processing records | Deleted after 2 years | Personal information safety measure standards |
| CCTV footage | Automatically overwritten on rotating storage (typically within 30 days); segments kept separately only when needed for incident investigation | Video equipment operating policy |
Deletion runs automatically every day. Expired personal information is deleted irrecoverably or de-identified so it can only be used for statistics.
Article 4 — Provision to third parties
The Operator does not provide guest personal information to third parties. When synchronizing the reservation calendar with external booking channels, only reservation dates and status are shared — never names or contact details.
Article 5 — Outsourced processing and overseas transfer
Processing is entrusted to the companies below to run reservations and payments; some processing happens outside Korea (Art. 28-8). You may refuse the overseas transfer via the contact in Article 10, in which case services relying on the relevant function may be limited.
| Processor (country) | Items transferred | Purpose | When and how | Retention |
|---|---|---|---|---|
| Toss Payments Co., Ltd. (South Korea) | Payer name, email, mobile phone, payment details | Payment processing (domestic outsourcing) | When a payment is made | Period set by applicable law |
| Beds24 Ltd (United Kingdom) | Reservation details, guest names and contacts, messages | Unified booking channel management | Network transfer on booking and messaging | Duration of the outsourcing contract |
| Cloudflare, Inc. (USA and others) | Data stored in the site and reservation systems | Site and reservation system hosting | Continuously during service use | Duration of service use (Article 3 deletion rules apply) |
| Anthropic PBC (USA) | Reservation details and guest conversations referenced by AI features | Generating AI responses for operations (only when the Operator enables that engine) | Network transfer when AI features are used | Deleted without delay after the response is generated (not used for model training) |
| Google LLC (USA) | Past reservation notification emails (read-only) | Restoring past reservation data | When the feature is run | Access removed after the import completes |
| Slack Technologies (USA) | New reservation notifications (names masked; dates and house) | Real-time staff notifications | When a reservation occurs | Notification channel retention policy |
※ Conversations with the house concierge chatbot are used only to generate an immediate response on equipment owned by the Operator and are not stored. Default AI processing also runs on the Operator's own equipment.
Article 6 — Your rights and how to exercise them
Guests may request access, correction, deletion, or suspension of processing of their personal information at any time. Requests sent to the contact in Article 10 are handled without delay (within 10 days) and you will be informed of the result. Requests through a representative are accepted. Rights follow Articles 35–37 of the Act; records that the law requires us to keep may be exempt from deletion for that period.
Article 7 — Security measures
- HTTPS encryption on every connection
- Passwords stored only in a non-reversible form
- Payment card details never held by the Operator (handled by the payment processor)
- Guest data accessible only to authorized staff, with processing records kept
- Daily automatic deletion and de-identification of expired data
Article 8 — Automated decisions and AI features
AI features (guidance answers, response support) produce reference information that assists staff; they never make legally binding decisions about guests without human involvement.
Article 9 — Fixed video equipment (CCTV)
- Purpose: facility safety, fire and theft prevention, check-out confirmation
- Location and range: common areas such as house entrances (never inside rooms, bathrooms or other privacy-sensitive spaces)
- Retention: per the CCTV rule in Article 3; signs are posted in recorded areas
- Manager: same as the privacy officer in Article 10
Article 10 — Privacy officer
Privacy officer: Representative, Starry House
Contact: letohdoorman (골뱅이) gmail.com
Other privacy support in Korea: Personal Information Infringement Report Center (118 · privacy.kisa.or.kr), Personal Information Dispute Mediation Committee (1833-6972 · kopico.go.kr)
Article 11 — Changes to this policy
Changes are announced on this page at least 7 days before they take effect (30 days for material changes).
v1 · Effective 2026-08-10