D'CENT App Privacy Policy — Version History
This page collects all historical versions and change notices for the D'CENT App Privacy Policy. For the current version in effect, please see the Privacy Policy page.
Previous Versions
Click each version below to expand its full text.
Version effective from December 11, 2023
IoTrust Co., Ltd. (hereinafter referred to as the "Company") complies with the personal data protection regulations and related laws applicable to information and communication service providers. The Company has established this privacy policy in accordance with the relevant laws to make every effort to protect the rights and interests of users (hereinafter referred to as "Users").
The Company complies with the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. when processing personal information.
Purpose and use of personal information
The company processes personal information for the following purposes. Personal information will not be used for other purposes, and if the purpose of use changes, separate consent will be obtained, or necessary actions will be taken.
Furthermore, the company does not collect personally identifiable information that can identify the user's identity directly. D'CENT does not store or have access to the user's personal confidential information, such as passwords, recovery words, private keys, PIN codes, and biometric data. Maintaining the confidentiality of this personal confidential information is solely the user's responsibility. Even if the following information is collected, it does not contain personally identifiable information, so the company cannot provide user identity information.
| Category | Purpose |
|---|---|
| The company processes the following information: device session identifiers, IP addresses, clicks, actions (e.g., application launch, transaction function use, page views), attributes (e.g., type, version, language, and region recorded on the operating system), timestamps, identifiers used by partners to distinguish users (if using the service), cryptocurrency account lists, wallet addresses, user settings information (language, currency, wallet mode). | This information is used for analysis to support bug fixes, product and service improvements, research into additional services and features that may be needed, processing support requests, addressing security issues and fraud prevention, exploring and preventing regulatory violations, optimizing marketing activities (e.g., information about the most frequently used features), and transmitting important information (e.g., security alerts). |
Methods of Personal Information collection
The personal information mentioned may be collected through the following methods:
| Category | Details |
|---|---|
| Online | Information is collected through the company's mobile app. |
| Collection through user consent provided to third parties. |
Providing personal information to third party
In principle, company shall process and manage collected personal information within the scope specified for the purpose of collection and use, and shall not process it beyond the scope of its original purpose or provide it to a third party without prior consent from owner of information except for below cases:
- • In cases where explicit consent is obtained from the data subject
- • When there are specific legal provisions in force
- • When it is deemed necessary for the urgent interests of the information subject or a third party's life, body, property.
Retention and usage period of personal information
The user's personal information is collected and used within the following usage period as a general rule.
| Category | Purpose | Usage Period |
|---|---|---|
| The company processes the following information: device session identifiers, IP addresses, clicks, actions (e.g., application launch, transaction function use, page views), attributes (e.g., type, version, language, and region recorded on the operating system), timestamps, identifiers used by partners to distinguish users (if using the service), cryptocurrency account lists, wallet addresses, user settings information (language, currency, wallet mode). | This information is used for analysis to support bug fixes, product and service improvements, research into additional services and features that may be needed, processing support requests, addressing security issues and fraud prevention, exploring and preventing regulatory violations, optimizing marketing activities (e.g., information about the most frequently used features), and transmitting important information (e.g., security alerts). | until the purpose of use is achieved |
However, when it is necessary to retain personal information for a certain period in accordance with the provisions of relevant laws such as the Commercial Act and the Act on Consumer Protection in Electronic Commerce, the company retains the personal information for the period prescribed by the relevant laws. In such cases, the company only uses the information for the purpose of retention. The retention periods are as follows, and if there are other laws that apply not included in the list below, they will be retained in accordance with those laws.
| Information to be kept about | Applied Law | Period |
|---|---|---|
| Records of Display/Advertising | Consumer Protection Act in Commercial Law and Electronic Commercial Law | 6 months |
| Records and supporting documents for all transactions as regulated by tax laws | National Tax Law, Corporate Tax Law | 5 years |
| Customer's complaint or settlement of disputes | Electronic Commerce Act | 3 years |
| Records related to electronic financial transactions | Electronic Financial Transaction Act | 5 years |
| Records related to app usage | Protection of Communications Secrets Act | 3 months |
| Records related to the collection, processing, and use of credit information | Use and Protection of Credit Information Act | 3 years |
Destruction of personal information
When personal information is no longer necessary (including the completion of personal information processing, termination of services, and business closure), it is securely disposed of according to the following:
The company identifies personal information for which the disposal reason has arisen and, with the approval of the Personal Information Protection Officer, disposes of the personal information.
The company disposes of personal information in the following ways:
- • Personal information recorded or stored on paper: Shredding or incineration
- • Personal information stored in electronic file format: Permanently deleting it to make it irrecoverable.
User's rights and duties and how to exercise them
User has the right to receive sincere response from the company's customer support team when there is a question, and can ask to view, correct or withdraw the registered user's personal information and request the company to view, provide, correct or withdraw the personal information.
The user should input the personal information accurately and precisely to prevent potential accidents. User has full responsibility for accidents caused by entering incorrect information, and you may lose membership if you enter false information including unauthorized use of other person's information.
Users have the right to protect the personal information. But also has responsibility to protect registered personal information and not to infringe other's personal information. User has to be careful not to disclose the personal information, including passwords and should not to damage the privacy of others, including posts. If user fails to fulfill such responsibilities and damage other's information, user may be punished under the Information and Communications Network Act.
Remedies for infringement of rights
Remedies for Infringement of Rights Information subjects may inquire about damage relief and counseling for personal information infringement to the following organizations.
<The following organizations are separate organizations from the company, so if you are not satisfied with the company's own personal information complaint handling and damage relief results, or if you need more detailed help, please contact them.>
Personal Information Infringement Report Center (operated by Korea Internet & Security Agency)
- • Responsibilities: Report personal information infringement, apply for counseling
- • Website: privacy.kisa.or.kr
- • Telephone Number: 118
- • Address: 9, Jinheung-gil, Naju-si, Jeollanam-do (301-2 Bitgaram-dong) 3rd floor (58324)
Personal Information Dispute Mediation Committee
- • Responsibilities: Personal information dispute mediation application, collective dispute mediation (civil settlement)
- • Website: www.kopico.go.kr
- • Telephone Number: 1833-6972
- • Address: 12th floor, Seoul Government Complex, 209 Sejong-daero, Jongno-gu, Seoul (03171)
Supreme Prosecutor's Office Cyber Crime Investigation Team: 02-3480-3574 (www.spo.go.kr)
National Police Agency Cyber Security Bureau: 182 (http://cyberbureau.police.go.kr)
Personal information protection
To protect personal information of members and handle complaints and inquiries for personal information reading, the company operates related department and chief privacy officer as the following:
| Chief Privacy Officer | Minho Yoo Vice President |
| Telephone Number: +82-2-1833-4022 | |
| E-mail: contact@iotrust.kr | |
| Privacy Management team / Request Personal information reading team | D'CENT Customer Support Team |
| Telephone Number: +82-2-1833-4022 | |
| E-mail: contact@iotrust.kr |
Announcement date: December 4, 2023
Effective date: December 11, 2023
The End.
Version effective from January 12, 2022
All personal information handled by the company shall be collected, held and processed in accordance with the Personal Information Protection Act and related laws and regulations. And the company shall protect the collected personal information and user's rights based on the Personal Information Protection Act and following policy has been placed for handling of user's complaints.
In case of the company's online mall, App and applications that handle personal information, the company sets privacy policy manual and operates based on Article 30, Section 1 of Personal Information Protection Act and Article 31, Section 1 of its enforcement ordinance.
When company's privacy policy has been changed, company shall post in public about timing of enforcement and changed information that shall be recognized by users easily.
Purpose and use of personal information
Personal information means information about an individual who is alive and can be identified by the name, e-mail, contact information, etc. contained in the personal information.
The company always confirms the intention of the user who wants to use the service from the company when company collects the personal information, and the company does not use the personal information for any purpose other than listed purposes. The company shall not provide collected information to third parties without user's consent and purpose of collecting personal information is as follows.
| Purpose | |
|---|---|
| Membership | User authenticating using membership service |
| Detect and prevent unauthorized use of service and fraudulent use | |
| Customer service, Handling customer's complaints, Preservation of records for settlement of dispute settlement | |
| Public notices (Notification of changes in company's online mall website, App, application or policy changes) | |
| Order · Payment · Delivery | Payment |
| Fulfilling of agreement for delivering service | |
| Payment settlement | |
| Delivery | |
| User authentication in financial transactions and services | |
| Product returns, Refund, and Exchange | |
| Marketing | Improvement of existing services and development of new services |
| Offering customized services | |
| Providing services based on statistics and statistical key information of using the service | |
| Delivering Publications and announcing new products or services | |
| Informing of marketing campaign, event and advertisements or managing membership lounge |
Collection of personal information and collected information
Company collects user's personal information through registration of company's App or application membership, opening user account, and its online mall. Collected information is:
- • Required information for membership registration: E-mail, Password, Nickname
- • Required information for online mall ordering process: E-mail, Name, Contact number, Address
- • Credit card payment: Card company name, Card number, Expiration Date
User has the right to refuse for collection of required information and/or optional information, but there may be a limit for company to offer the services if user rejects it.
Providing personal information to third party
In principle, company shall process and manage collected personal information within the scope specified for the purpose of collection and use, and shall not process it beyond the scope of its original purpose or provide it to a third party without prior consent from owner of information except for below cases:
- • If company receives separate consent from the information owner
- • If there are special regulations in the law and/or act
- • If the owner of information or his legal representative is unable to express his intention, or prior consent cannot be obtained due to an incorrect address, and it deems necessary to protect life, body or economic profits of the owner of information or a third party from impending danger
- • If it is impossible to perform duties provided in other laws unless personal information is used for purposes other than those originally intended or provided to a third party, provided that it has been decided through deliberation at a meeting
- • If it is necessary to conduct criminal investigation and to commence and maintain prosecution
- • If it is necessary for the court to perform tasks related to trials
- • If it is necessary to execute punishment, preventive custody, and protective disposition
Personal information processing consignment
The company consigns part of collected personal information to external parties for them to carry out some of necessary tasks to provide various services to users. And we are supervising entrusted companies not to violate the personal information protection laws and regulations. In addition, collected information is based on the time when the user confirmed, and we will notify user when the consignment company or consignment work is changed.
(Contracted Companies)
| Name | Tasks | Information | Use of personal information |
|---|---|---|---|
| KG Inicis | Card Payment, Mobile Payment | Name, Phone number, Address, Card company name, Card number, CVC Number, Expiration Date | Until membership withdrawal or end of consignment contract |
| EXIMBAY | Overseas Card Payment | Name, Phone number, Address, Card company name, Card number, CVC Number, Expiration Date | Until membership withdrawal or end of consignment contract |
| Kakao Pay | Payment | Name, Phone number, Address, Payment related information | Until membership withdrawal or end of consignment contract |
| Mailchimp | E-mail address | Name, E-mail address | Until membership withdrawal or end of consignment contract |
| WeKeep | Delivery | Name, Phone number, Address, Openmarket ID (option) | Until membership withdrawal or end of consignment contract |
| DHL | Delivery | Name, Phone number, Address, E-mail, Tax ID (selected countries) | Until membership withdrawal or end of consignment contract |
Retention and usage period of personal information
In principle, collected information of user will be destroyed without delay when company reaches objective for collecting and using of personal information. However, in accordance with relevant laws and regulations including Consumer Protection Act in Commercial law and Electronic Commercial law etc., the company shall preserve the collected information for a certain period of time when is necessary. In this case, the company shall use the information solely for the original purpose, and its retention period is:
| Information to be kept about | Applied Law | Period |
|---|---|---|
| Withdraw or termination of agreement | Consumer Protection Act in Commercial Law and Electronic Commercial Law | 5 years |
| Payment of goods delivery | Consumer Protection Act in Commercial Law and Electronic Commercial Law | 5 years |
| Customer's complaint or settlement of dispute | Consumer Protection Act in Commercial Law and Electronic Commercial Law | 3 years |
| Advertisement and its display | Consumer Protection Act in Commercial Law and Electronic Commercial Law | 6 months |
| All ledgers and evidential documents related to transactions in accordance with tax laws | National Tax Law, Corporate Tax Law | 5 years |
| Electronic financial transactions | Electronic Financial Transaction Law | 5 years |
| Website visits | Protection of Communications Secrets Act | 3 months |
| Collection, processing and use of credit information | Use and Protection of Credit Information Act | 3 years |
| Identity verification | Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. | 6 months |
Destruction of personal information
In principle, the company shall delete personal information without delay when purpose of processing personal information has been accomplished and users withdrawal membership. And personal information of users who have not connected to our service more than one year shall be stored and managed separately.
Destruction procedure
Personal information shall be deleted immediately or moved and stored in separate location for certain period based on internal policies and/or other related laws and regulations when purpose of processing personal information has been accomplished. Personal information that has been moved into separate location shall not be used for any other purpose unless related law and/or regulation order.
Destruction period and process
When the retention period has expired or personal information becomes unnecessary, printed personal information on paper is shredded or incinerate, and personal information stored in the form of an electronic file shall be deleted through technical methods that can not reproduce the original data.
User's rights and duties and how to exercise them
User has the right to receive sincere response from the company's customer support team when there is a question, and can ask to view, correct or withdraw the registered user's personal information and request the company to view, provide, correct or withdraw the personal information.
The user should input the personal information accurately and precisely to prevent potential accidents. User has full responsibility for accidents caused by entering incorrect information, and you may lose membership if you enter false information including unauthorized use of other person's information.
Users have the right to protect the personal information. But also has responsibility to protect registered personal information and not to infringe other's personal information. User has to be careful not to disclose the personal information, including passwords and should not to damage the privacy of others, including posts. If user fails to fulfill such responsibilities and damage other's information, user may be punished under the Information and Communications Network Act.
Denying installation and operation of automatic collecting device of personal information
The company uses 'cookie' to store information about users and to find them from time to time. 'Cookie' is a small amount of data from the HTTP server to a user's computer browser (i.e. Internet Explorer, Safari, Firefox, Chrome etc.). 'Cookie' identifies user's computer, but not you as an individual.
Purpose of 'cookie':
- • Provide customized information according to individual interests
- • Analyzes the frequency and duration of visits of members' and non-members' to identify user's interests and areas of interest for targeted marketing
- • Keep track of what users are looking for personalized service at their next visit
- • Analyze users' habits and use them as indications of service re-organization
Options for 'cookie':
- • By adjusting users' web browser, users can accept all cookies, send a notification when a cookie is installed, or reject all cookies. However, if users refuse storage of cookies, users may not be able to access certain services that require log-in
How to set-up different levels of cookies in Internet Explorer is as follows:
- • Select "Internet Option" in "Tool" menu
- • Select "Privacy"
- • Under "Setting" menu, users can choose "Accept" / "Block" / "Prompt"
- • 'Cookie' will be expire when internet browser is closed or log-out
Personal information protection measures
The company is taking the following measures to ensure the protection of personal information.
- 1. Administrative measures: Establish an internal management plan. Implementation, regular staff training, etc.
- 2. Technical measures: Management of access rights of personal information processing system, etc., installation of an access control system, encryption of unique identification information, etc., installation of security programs
- 3. Physical measures: Control access to computer rooms, data storage rooms, etc.
Remedies for infringement of rights
Remedies for Infringement of Rights Information subjects may inquire about damage relief and counseling for personal information infringement to the following organizations.
<The following organizations are separate organizations from the company, so if you are not satisfied with the company's own personal information complaint handling and damage relief results, or if you need more detailed help, please contact them.>
Personal Information Infringement Report Center (operated by Korea Internet & Security Agency)
- • Responsibilities: Report personal information infringement, apply for counseling
- • Website: privacy.kisa.or.kr
- • Telephone Number: 118
- • Address: 9, Jinheung-gil, Naju-si, Jeollanam-do (301-2 Bitgaram-dong) 3rd floor (58324)
Personal Information Dispute Mediation Committee
- • Responsibilities: Personal information dispute mediation application, collective dispute mediation (civil settlement)
- • Website: www.kopico.go.kr
- • Telephone Number: 1833-6972
- • Address: 12th floor, Seoul Government Complex, 209 Sejong-daero, Jongno-gu, Seoul (03171)
Supreme Prosecutor's Office Cyber Crime Investigation Team: 02-3480-3574 (www.spo.go.kr)
National Police Agency Cyber Security Bureau: 182 (http://cyberbureau.police.go.kr)
Personal information protection
To protect personal information of members and handle complaints and inquiries for personal information reading, the company operates related department and chief privacy officer as the following:
| Chief Privacy Officer | Minho Yoo Vice President |
| Telephone Number: +82-2-1833-4022 | |
| E-mail: contact@iotrust.kr | |
| Privacy Management team / Request Personal information reading team | D'CENT Customer Support Team |
| Telephone Number: +82-2-1833-4022 | |
| E-mail: contact@iotrust.kr |
Announcement date: January 12, 2022
Effective date: January 19, 2022
Change Notices
Click each notice below to view the reasons for change and Before/After comparisons.
Change notice — May 13, 2026
Hello, this is IoTrust D'CENT Support Team. We would like to inform you of some changes to our privacy policy, effective as of May 13, 2026. Please check the new contents in the privacy policy as your reference when using our services.
Reasons for changes
The revised personal information processing policy was revised due to the following reasons:
- • Addition of collected personal information items subject to outsourced processing and the purposes of their use
- • Addition of provisions regarding the outsourcing of personal information processing
- • Change of the person in charge of personal information protection
Changes Made
Purpose and use of personal information
Before
[Category]
The company processes the following information: device session identifiers, IP addresses, clicks, actions (e.g., application launch, transaction function use, page views), attributes (e.g., type, version, language, and region recorded on the operating system), timestamps, identifiers used by partners to distinguish users (if using the service), cryptocurrency account lists, wallet addresses, user settings information (language, currency, wallet mode).
[Purpose]
This information is used for analysis to support bug fixes, product and service improvements, research into additional services and features that may be needed, processing support requests, addressing security issues and fraud prevention, exploring and preventing regulatory violations, optimizing marketing activities (e.g., information about the most frequently used features), and transmitting important information (e.g., security alerts).
After
[Category]
The Company processes the following information: device session identifiers, instance IDs, IP addresses, clicks, actions (e.g., application launches, use of transaction functions, page views), attributes (e.g., hardware device ID, device type, operating system type, version, language, and region), timestamps, identifiers used by partners to distinguish users (e.g., anonymous UUIDs and FCM device registration tokens), cryptocurrency account lists, wallet addresses, user settings information (language, currency, wallet mode), and application error reports.
[Purpose]
This information is used for bug fixes, analysis for product and service improvements, processing support requests, detecting and preventing security issues, fraud, and regulatory violations, optimizing marketing activities, and transmitting important information (such as security alerts).
Outsourcing of Personal Information Processing
The Company transfers personal information collected from service users to overseas entities as described below. If a user does not consent to or wishes to withdraw consent to such overseas transfer, the user may discontinue use of the Services by refraining from using the Services or deleting the application.
| Recipient (Processor) | Transfer Country | Transfer Timing | Transferred Personal Information | Purpose of Use | Retention Period |
|---|---|---|---|---|---|
| Google Analytics | USA | Upon Service Use, Transfer via Network | Anonymous UUID, Instance ID, Device Type, Extension Version/Mode | Data Analytics | 14 months |
| Amplitude | USA | Upon Service Use, Transfer via Network | Instance ID, Hardware Device ID, Extension Version/Mode, Currency Settings, Testnet Status | Data Analytics | 1 year |
| Pushwoosh | USA | Upon Service Use, Transfer via Network | FCM Device Registration Token | Push Notification | 2 years |
Personal information protection
Before
| Chief Privacy Officer | Minho Yoo Vice President |
| Telephone Number: +82-2-1833-4022 | |
| E-mail: contact@iotrust.kr | |
| Privacy Management team / Request Personal information reading team | D'CENT Customer Support Team |
| Telephone Number: +82-2-1833-4022 | |
| E-mail: contact@iotrust.kr |
After
| CPO | KyungEun Kim Vice President |
| Telephone Number: +82-2-1833-4022 | |
| E-mail: contact@iotrust.kr | |
| Privacy Management team / Request Personal information reading team | D'CENT Customer Support Team |
| Telephone Number: +82-2-1833-4022 | |
| E-mail: contact@iotrust.kr |
Added
Added Outsourced Companies, Outsourced Content, and Personal Information Collection: Shopify, SaBangNet, Fasto, PayPal, CGETC, ySell, Yunige
The End.