v2 · en
Maskit Inc. (the "Company") establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act ("PIPA") in order to protect the personal data of data subjects and to handle related grievances promptly. KSTAGE, operated by the Company, is an online ticketing service that sells tickets for performances held in Korea directly to overseas travellers (FIT) from Taiwan, Thailand, Japan and elsewhere; it is not a travel business selling bundled travel products.
In accordance with PIPA, the Company collects and uses personal data only to the minimum extent necessary to provide the Service.
| Legal basis | Activity | Purpose of collection and use | Items processed | Processing and retention period |
|---|---|---|---|---|
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Booking / Payment / Ticketing / Refund | Booking and ordering of performance tickets; payment and settlement; cancellation and refund processing; identity verification for ticket collection at the venue | Passport name in Roman letters, email address, booking details (performance title, seat grade, booking number, payment amount) | 5 years (Enforcement Decree of the E-Commerce Act, Art. 6(1)2 and 3) |
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Social login (LINE · Google) | Member identification, simple login, securing a means of contact for non-member bookings | LINE Login: LINE user identifier, email address (optional), profile name (optional), profile image (optional) Google Login: Google account email address, name, profile image |
Until the service link is terminated or membership is withdrawn |
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Email verification login | Member identification; identity verification by one-time passcode (OTP) | Email address | Until membership is withdrawn |
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Sending booking notifications | Sending notices essential to the transaction, such as booking confirmation, cancellation and ticketing | Email address, LINE user identifier, whether LINE notifications can be delivered (official account friend status) | Until membership is withdrawn or the service link is terminated |
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Display language and country-specific policy application | Providing screens and notices in the user's language, and applying consent and refund rules that differ by region of residence | Display language setting, region of use (derived from the selected language) | Until membership is withdrawn |
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Customer management and prevention of misuse | Managing consultation and handling history; protecting the Service from misuse such as repeated booking and cancellation | Email address, consultation and handling records, customer status markers recorded by operators (such as caution or transaction restriction) | 3 years (Enforcement Decree of the E-Commerce Act, Art. 6(1)4) |
| PIPA Article 15(1)2 (compliance with legal obligations) |
Retention of consent records | Keeping records to evidence the giving and withdrawal of consent, such as consent to provision to third parties | Type of consent, whether and when it was given or withdrawn, the version of the terms or policy applied, region of use, display language | Until membership is withdrawn (or, where a statutory retention period for the related transaction records remains, until the end of that period) |
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Customer support | Receipt and handling of enquiries, complaints and grievances relating to booking, ticketing and refunds | Email address, booking details (performance title, booking number), content of the enquiry | 3 years (Enforcement Decree of the E-Commerce Act, Art. 6(1)4) |
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Payment | Payment authorisation, cancellation and refund processing | Payment authorisation records (sensitive payment data such as card numbers are processed directly by the payment gateway and are not stored by the Company) | 5 years (Enforcement Decree of the E-Commerce Act, Art. 6(1)3) |
The Company does not currently send advertising information (such as performance recommendations or benefit notices) and does not collect or use personal data for that purpose. Messages sent by the Company are limited to information essential to the transaction, such as booking confirmations, cancellation notices and ticketing guidance.
Should the Company introduce the sending of advertising information in future (for example notices of new performances or benefits via LINE or email), it will obtain separate prior consent to receive such information in accordance with Article 50 of the Act on Promotion of Information and Communications Network Utilisation and Information Protection, and will allow users to opt out (withdraw consent) at any time. Until then, this clause does not apply.
| Basis of collection | Purpose of collection and use | Items of personal data | Processing and retention period |
|---|---|---|---|
| PIPA Article 15(1)4 (conclusion and performance of a contract) |
Provision and operation of the Service, prevention of unauthorised access, stable operation of systems, service improvement | Access logs, IP address, device and browser information (User-Agent), and cookies essential for maintaining the login session | 3 months (Protection of Communications Secrets Act, Art. 15-2(2)) |
Where the Company collects and uses personal data on the basis of consent, it clearly informs the data subject of the purpose of collection and use, the items collected, the retention and use period, the fact that the data subject has the right to refuse consent and any disadvantage resulting from such refusal, before obtaining consent. The same procedure applies where additional collection and use of personal data becomes necessary in connection with new business activities.
| Legal basis | Subject | Period |
|---|---|---|
| Enforcement Decree of the E-Commerce Act, Art. 6(1)2 | Records concerning contracts or withdrawal of subscription | 5 years |
| Enforcement Decree of the E-Commerce Act, Art. 6(1)3 | Records concerning payment and the supply of goods | 5 years |
| Enforcement Decree of the E-Commerce Act, Art. 6(1)4 | Records concerning consumer complaints or dispute handling | 3 years |
| Protection of Communications Secrets Act, Art. 15-2(2) | Communication confirmation data (access logs) | 3 months |
3. Separately from the statutory retention periods above, the Company's default policy is to retain the list of bookers provided to the venue for 6 months after the performance ends and then destroy it (see Article 5). This is a distinct retention period whose purpose and scope differ from the statutory retention period (5 years) for contract and payment records.
The Company restricts membership registration and use of the Service by children under 14 years of age and does not collect or process the personal data of children under 14.
| Recipient | Purpose of provision | Items provided | Retention and use period |
|---|---|---|---|
| The venue at which the performance is held (this differs by performance; the recipient is disclosed individually on the booking screen for the relevant performance and consent is obtained there) | Ticket issuance, verification of attendees at the venue, and contact regarding ticket issuance | Booker's name (passport name in Roman letters), email address, performance session, seat grade, number of tickets, booking number (voucher code) | Retained for 6 months after the performance ends, then destroyed |
The email address is provided only where contact concerning ticket issuance is necessary, such as a discrepancy at collection or a change of session, and the venue may not use it for marketing or any other purpose.
3. Users may refuse consent to the provision to third parties above; however, where consent to provision of the list, which is essential for ticket issuance, is refused, booking that performance and collecting the ticket at the venue may not be possible.
4. Where there is a lawful request from an investigative authority under Article 18(2)2 of PIPA (special provisions of law) and Article 215 of the Criminal Procedure Act (seizure, search and verification), the Company may provide the minimum necessary personal data without the consent of the data subject.
In order to provide the Service smoothly, the Company outsources the processing of personal data as follows and stipulates the safe management of personal data in its outsourcing contracts.
| Processor | Outsourced work |
|---|---|
| Supabase Inc. | Database operation and authentication (Auth) processing |
| Google LLC | Service hosting (Google Cloud Platform); AI translation processing (Gemini / Vertex AI); Google social login integration |
| Resend, Inc. | Sending booking confirmation and notification emails |
| LY Corporation (LINE) | LINE Login integration; sending booking and performance notifications |
Payment gateway services are not currently outsourced, as no merchant agreement has yet been concluded. Once such an agreement is concluded, the Company will disclose the processor's name and the outsourced work in this Policy in advance.
The Company specifies in contracts and other documents matters such as the prohibition of processing personal data beyond the purpose of the outsourced work, technical and administrative protective measures, restrictions on sub-processing, supervision of the processor, and liability including compensation for damage, and supervises whether the processor handles personal data safely. Where the content of the outsourced work or the processor changes, the Company will disclose this through this Policy without delay.
The Company uses Google Cloud Platform (operated by Google LLC) for service hosting and AI-based multilingual translation processing, and Supabase Inc. for database operation. The database storing booking information and the service servers are located in the Republic of Korea (Seoul region); however, the providers listed below are companies headquartered outside Korea, and personal data may be transferred overseas in the course of system operation, technical support and certain processing functions.
| Recipient | Country of transfer | Items transferred | Purpose of transfer | Retention and use period |
|---|---|---|---|---|
| Google LLC (Google Cloud Platform / Google AI / Google Login) | Republic of Korea (service hosting — Seoul region) · United States and others (AI translation processing; Google social login authentication) | Personal data collected in the course of using the Service generally, access logs, performance information or notification text entered for translation processing, and the Google account email address, name and profile image where Google Login is used | Service hosting; AI translation (Gemini / Vertex AI) processing; Google social login authentication | For the duration of provision of the Service (destroyed without delay upon termination of the outsourcing contract or achievement of the purpose of processing) |
| Supabase Inc. | Republic of Korea (stored in the AWS Seoul region ap-northeast-2) · United States (access for operation and technical support) | All items stored in the database, including booking information (passport name in Roman letters and email address) | Database operation and authentication processing | For the duration of provision of the Service (destroyed without delay upon termination of the outsourcing contract or achievement of the purpose of processing) |
| Resend, Inc. | United States | Email address, and booking information contained in the body of booking confirmation and notification emails | Sending booking confirmation and notification emails | Until the purpose of sending is achieved |
| LY Corporation (LINE) | Japan | LINE user identifier, email address (optional), profile name (optional), profile image (optional), and information on notification recipients | LINE Login integration; sending booking and performance notifications | Until the service link is terminated or membership is withdrawn |
Users may refuse consent to the overseas transfer. However, hosting and the database are an essential basis for providing the Service, so booking services may be unavailable if consent is refused; LINE and Google social login may be replaced by email verification login. A refusal may be communicated to customer support at kstage@maskit.co.kr.
| Right | Method | Processing period |
|---|---|---|
| Access / correction | My Page within the Service, or customer support (email) | Immediately to within 10 days |
| Deletion / suspension of processing | Request to customer support (email) | Within 10 days |
| Withdrawal of consent | Consent management within the Service, or customer support (email) | Immediately |
The Company designates a Chief Privacy Officer as set out below to take overall charge of work relating to the processing of personal data and to handle data subjects' complaints and provide remedies for damage.
| Item | Details |
|---|---|
| Chief Privacy Officer | Bae Hoyeon (concurrently serving as Representative Director) |
| Contact | info@maskit.co.kr · +82-2-6349-0155 |
| General enquiries (customer support) | kstage@maskit.co.kr |
Data subjects may also consult or report personal data infringements to the following bodies.
The Company implements the following administrative, technical and physical measures for the safe processing of personal data.
The Company uses only those cookies that are essential to providing the Service, such as maintaining the login session and storing the display language setting. A cookie is a small amount of information sent to a user's browser by the server used to operate a website. Users may refuse the storage of cookies through their browser settings, in which case there may be difficulty in using parts of the Service such as logging in.
The Company does not collect behavioural information for advertising purposes and does not use third-party advertising or tracking tools (tracking SDKs). Nor does it collect sensitive behavioural information that risks infringing individual rights, interests or privacy, such as information on ideology, beliefs or medical history. Should the Company introduce an analytics tool for service improvement in future, it will disclose the items collected, the purpose and the means of refusal through this Policy before doing so.
In order to obtain a remedy for infringement of personal data, a data subject may apply for dispute resolution or consultation to the following bodies.
This Policy applies from 2 August 2026. Where it is amended in line with changes in law or in the content of the Service, the Company will announce the changes through the initial screen of the Service or a notice at least 7 days before they take effect (30 days before, where the change is unfavourable to data subjects).