Privacy Policy

Latel (hereinafter "Company") establishes and discloses this Privacy Policy in accordance with the Personal Information Protection Act and other applicable laws to protect users' personal information and handle related complaints promptly and smoothly.

Article 1 (Personal Information Collected)

The Company collects the following personal information by collection channel.

Information Provided by Kakao

Collection ChannelItemRequirementPurpose
Kakao LoginKakao Member Number (service-linking identifier)RequiredKakao account-based registration and login, and linking the service account
Web Kakao Login (Supabase Auth)Profile nickname and profile image URLRequired when web Kakao Login is usedCreating and identifying the web authentication account and processing Supabase Auth account metadata
Web Kakao Login (Supabase Auth)Kakao Account emailOptionalCreating and identifying the web authentication account and processing the Supabase Auth account email
Tonghari mobile Kakao LoginKakao Account Phone NumberRequiredMatching against the phone number in a pre-registered union member or property-owner roster or invitation to confirm registration eligibility, link accounts, prevent duplicate or incorrect registrations, and simplify data entry

Information Processed through Sign in with Apple

Collection ChannelItemRequirementPurpose
Sign in with AppleApple user identifierRequired when using Apple loginRegistration, login, and service-account linking
Sign in with AppleName and email address, including an Apple private relay addressProcessed at first login when Apple provides it and the user chooses to share itAccount creation, simplifying name entry, and account identification
Sign in with AppleID token and nonceRequired when using Apple loginLogin verification, registration/login, service-account linking, and session issuance
Sign in with AppleAuthorization code and encrypted refresh tokenWhen Apple provides a code and the code exchange succeedsRevoking Apple access when the app account is deleted

Information Entered or Confirmed on the Registration Form

RequirementItemsPurpose
Required when checking all unions' pre-registration rostersName, date of birth, and mobile phone numberMatching active unions' pre-registration rosters and invitations, identifying eligible unions, linking the account, immediately joining invited unions, and requesting approval from matched uninvited unions
RequiredName, date of birth, mobile phone number, selected union, address and type of owned property, and residential addressRegistration request, roster matching, confirmation of union member or property-owner eligibility, contact, and service provision
Conditionally RequiredBuilding and unit numbers, depending on the property typeIdentifying the owned property and matching it against the roster
OptionalResidential address detailsSupplementing the address for postal or in-person contact

Information Entered or Generated during Service Use

  • Posts, questions, answers, comments, report details, image/PDF attachments and metadata such as filename, size, and type, editing records, and aggregate view counts for each post
  • Customer-managed member or property-owner records, membership status, contact and address information, and ownership/property information
  • Push token, app version, platform, device/session identifier, accepted policy version and time, access time, User-Agent, and error and security logs
  • Join-request and all-union pre-registration roster-check privacy collection/use consent document version, server-recorded time, client-reported consent time, app platform/version, authentication-account type and identifier, and organization/join-request user identifiers
  • Push-delivery log data: user/organization identifiers, notification type, delivery status and target/success/failure counts, sanitized error code, and creation time. Only a non-identifying fixed title is stored; the message body is not stored
  • When advertising-inquiry or report/block alert email is used: inquiry title/message/reply contact, report type/target, related user/organization identifiers, and submission time

When Web Electronic-Meeting, Identity, or E-Signature Features Are Used

ConditionItemsPurpose
Only when the relevant web feature is usedName, phone number, and date of birth when passed to the authentication request; CI/DI; gender and domestic/foreign status when returned in the result; authentication/signature data; consent text; transaction identifiers (mTxId and txId); result code; authentication method/time; and IP address/User-Agent for meeting attendanceIdentity verification, electronic signature, meeting entry and attendance, duplicate-participation prevention, and voting/dispute evidence

These items concern conditional Tonghari web features. Gender is not requested or collected as a Kakao additional-consent item or on the Tonghari mobile union-registration form.

Name and date of birth are not requested from Kakao. A name shared by the user at the first Sign in with Apple may be shown on the registration form; otherwise, the user enters or confirms their name, date of birth, and addresses on that form. Gender is not requested or collected as a Kakao additional-consent item or on the Tonghari mobile union-registration form. A Kakao Account Phone Number is not used as legal identity verification or proof that the user currently possesses the number. The email and profile scopes conditionally requested by the web Kakao Login provider are separately disclosed in the table above; this mobile additional-consent application is limited to the Kakao Account Phone Number.

When automatic registration uses only a Kakao-provided phone number, it is matched against the pre-registration roster and invitation record to determine registration eligibility and account-linking availability, and is used only for the union that issued the valid invitation.

If the Kakao Account has no phone number, the Kakao API or server cannot provide it, or there is no invitation eligible for automatic registration, the user may, after giving separate required consent, enter a name, date of birth, and mobile phone number to check all active unions' pre-registration rosters. If all three match pre-registration records, invited unions are joined immediately and matched uninvited unions remain pending administrator approval. If no pre-registration record matches, the user continues with the property, address, and other information required for a general registration request.

Name, gender, birthday or birth year, address, CI, and shipping information are not requested as Kakao Login additional-consent items. Name, date of birth, and address needed in the general registration flow are entered directly on the Tonghari form.

Information Generated during Service Use: Device and session identifiers, platform, app version, push token, accepted policy version and time, access time, User-Agent, and error and security logs are processed. Mobile authentication events store a hash of the IP address; security and access logs held by hosting providers may contain the IP address.

Store Review Account: Only when the review feature is enabled, the submitted email and password are compared with reviewer credentials configured on the server. The reviewer email and password are not stored in a member profile in the separate database. Only the display name configured on the server is stored as a synthetic review member profile while the reviewer feature/account is operated. Device/session identifiers and login security records are handled like other mobile authentication records.

Article 2 (Purpose of Collection and Use)

  • Member Management: Confirmation of registration intention, Kakao- or Apple-based login, limited store-review login, and service-account linking
  • Registration Eligibility: Matching against pre-registered rosters or invitations, confirming union member or property-owner eligibility, and preventing duplicate or incorrect registrations
  • Service Provision: Union registration requests, contact and address management, notification and alert delivery, and complaint handling
  • Notification of major events such as union general meetings
  • Web Electronic Meetings and Authentication: Identity verification, electronic signatures, meeting entry/attendance, duplicate-participation prevention, and voting/dispute evidence
  • Customer consultation and complaint handling
  • Service Improvement: Service usage statistics, new service development

Article 3 (Retention and Use Period)

Retention and deletion depend on the category of information and the actual scope of account deletion. Selecting "Delete Account" in the app deletes the mobile login account, login sessions, account links, and push tokens associated with that app account, and initiates revocation or unlinking with Apple or Kakao.

Information CategoryRetention and Deletion Scope
Kakao-provided phone number stored locally with the login sessionStored in the app's secure storage while the login session is maintained and deleted on logout, session reset, or app-account deletion. A phone number submitted or confirmed in a join request is retained under the customer-organization join/roster scope below.
Mobile login account, provider identifier, sessions and links, push token, Apple display name and encrypted refresh tokenUntil app-account deletion or service-account unlinking. These records are deleted during account deletion; revocation at an external identity provider may be delayed by a provider outage or similar event.
Join requests, member or property-owner profiles, contact and address data, and property/ownership informationFor the period needed for customer-organization roster management, eligibility checks, the service contract, or applicable legal retention. App-account deletion does not automatically delete these records. A deletion request is handled after checking the customer organization's authority and legal retention grounds.
Posts, questions, answers, comments, and attachmentsUntil content deletion, completion of the customer organization's operational purpose, or contract termination. Limited retention after app account deletion may apply for shared records, disputes, or legal obligations.
Push-delivery logsRetained for 90 days after creation and then automatically deleted. If earlier deletion is requested before app-account deletion, the Company processes it after confirming authority and any legal-retention basis.
Advertising-inquiry and report/block operations email content and transmission logsRetained until the inquiry/report response or operations purpose is complete, or for the period required by applicable law, and then deleted. Mailbox content and transmission logs may be processed under the Company's Google Account settings and Google service policy.
Authentication, security, access, and consent recordsFor the period needed for security, misuse prevention, dispute handling, or applicable law. On app-account deletion, the mobile account ID link is removed. If a shared web authentication account remains, its auth user identifier may remain in the audit record. Join-request privacy-consent evidence is linked to the join-request user and organization and is deleted with either underlying record. The record is deleted when its purpose is complete.
Web KG Inicis authentication/e-signature transactions and meeting evidencePending transaction and callback tokens are periodically cleared after their five-minute TTL expires and removed immediately after the final result is retrieved. CI/DI hashes, authentication method/time, attendance records, and e-signature evidence generated after completion may be retained for the meeting/voting evidence purpose and the period required by applicable law or the customer-organization contract.

Information subject to a statutory retention period is stored separately for that period and then deleted. A request can be submitted through the in-app account deletion feature or the Tonghari Account and Data Deletion guide.

Destruction Procedure and Method: Electronic files whose retention purpose has ended are deleted using a method designed to prevent recovery. Backup copies are overwritten according to the backup rotation schedule and access is restricted until then. Any paper records are shredded or incinerated.

Article 4 (Provision to Third Parties)

When a user submits a join request, administrators of the selected customer organization, or administrators of customer organizations whose rosters matched all three entries in the all-union pre-registration check, may view or export the user's name, date of birth, mobile phone number, address/property information, consent, and join status for review, contact, and roster management. The Company provides the service under the customer organization's instructions for this scope; the information is not disclosed for an independent third party's advertising or sales purpose.

In principle, the Company does not provide users' personal information to third parties. However, the following cases are exceptions:

  • When the user has given prior consent
  • When required by law or when requested by investigative agencies in accordance with procedures and methods prescribed by law for investigation purposes

Article 5 (Entrustment of Processing)

To provide the service, the Company entrusts processing to the following providers or connects to an external authentication or notification service chosen by the user.

TrusteeEntrusted Tasks
Supabase Pte. Ltd.Database, authentication, and file-storage operations
Vercel Inc.Web and mobile API hosting, deployment, and security logging
650 Industries, Inc. (Expo)Forwarding push tokens and notification content to APNs and FCM
Apple Inc.Sign in with Apple, account revocation, and iOS push notifications
Google LLCAndroid push notifications, app distribution, and advertising-inquiry or report/block operations email delivery through Gmail SMTP in the current operating configuration
Kakao Corp.Kakao Login, provision of consented account information, and Kakao/Daum postcode address search
AligoKakao AlimTalk delivery for customer organizations that use the feature
KG Inicis Co., Ltd.Identity verification, simple authentication, and e-signature when the relevant web electronic-meeting feature is used
Amazon Web Services, Inc. (AWS)Infrastructure for the Tonghari API server that relays KG Inicis and other external integrations

Article 6 (International Transfers)

Latel uses the following overseas service provider in connection with processing personal information.

Recipient and CountryItems and PurposeTiming and MethodRetention
Supabase Pte. Ltd. (Singapore). Primary storage/processing region: AWS ap-northeast-2, Seoul, South Korea
Contact: privacy@supabase.io
Account, registration, content, and device information needed for Supabase contract administration, support, and service operations. Primary database, authentication, and file storage are in the Seoul region; Supabase or authorized subprocessors may process limited data at other facilities when necessary for requested support or servicesEncrypted network transfer during service useFor the duration of the agreement unless earlier deletion is requested through service functionality; deletion follows the DPA after the 30-day return period on agreement expiry
Vercel Inc. (United States and other jurisdictions where Vercel operates)
Contact: privacy@vercel.com
Information in web/mobile API requests, IP address, User-Agent, and request metadata for hosting, transmission, and security. The current Function execution region is Seoul, South Korea (icn1), while account administration, support, security, service operations, and backups may involve the United States or other jurisdictions where Vercel operatesEncrypted network transfer when the web or app API is usedFunction runtime logs for the current project are retained for one hour. Other information is retained under Vercel's Privacy Notice for the minimum period needed for legal and contractual obligations, dispute resolution, enforcement of rights, and legitimate business purposes; deleted or anonymized when there is no ongoing legitimate business need, or securely retained where immediate deletion is not possible, such as backups
650 Industries, Inc. (Expo, United States)
Contact: https://expo.dev/contact
Expo push token, device push token, and notification title, body, and deep-link data for delivery to Apple APNs and Google FCMEncrypted transfer to Expo Push Service on U.S. GCP when a notification is sent, followed by transfer to Apple and Google push services in the United StatesExpo stores tokens needed to provide push service, deletes notification payloads after handoff to APNs or FCM, and clears push receipts after 24 hours
Apple Inc. (United States) — Sign in with Apple
Contact: https://www.apple.com/legal/privacy/contact/
App/service identifier, nonce, authorization request, authorization code/token exchange, and revocation request for authentication and account-link management. Name, email, and ID token provided by Apple to the Company are not Company-to-Apple transfers in this rowEncrypted transfer during Apple login, token exchange, or revocationRetained by Apple as needed to provide Sign in with Apple and meet legal requirements
Apple Inc. (United States) — APNs
Contact: https://www.apple.com/legal/privacy/contact/
iOS push token and notification title, body, and deep-link data for push deliveryEncrypted transfer when an iOS notification is sentUndelivered APNs notifications use a default maximum of one month when no separate TTL is set
Google LLC (U.S. entity; Google global infrastructure) — FCM
Contact: https://support.google.com/policies/contact/general_privacy_form
Android push token, Firebase installation ID, and notification title, body, and deep-link data for FCM deliveryEncrypted transfer when an Android notification is sentUndelivered FCM messages remain for up to four weeks by default when no separate TTL is set. A Firebase installation ID is retained until the deletion API is called; after deletion, data tied to that installation ID is removed from live and backup systems within 180 days
Google LLC (U.S. entity; Google global infrastructure) — Gmail SMTP
Contact: https://support.google.com/policies/contact/general_privacy_form
Operations-email recipient address, subject, and body for advertising inquiries, report notices, and block noticesEncrypted transfer when an operations email is sentMay be retained until the operator of the current personal Gmail account deletes it. Deletion starts Google's safe-deletion process; limited retention may continue for security, fraud prevention, legal obligations, or backups

You may ask the privacy operations and grievance-handling department to suspend processing if you do not want the overseas transfer. If database, authentication, file-storage, social-login, push, or operations email processing is suspended, the related feature or use of the service may be limited.

Article 7 (User Rights and How to Exercise Them)

Users may exercise the following rights at any time:

  • Request to view personal information
  • Request to correct or delete personal information
  • Request to suspend processing of personal information
  • Withdraw consent

Rights can be exercised through the settings menu within the service or by requesting in writing or by email to the privacy operations and grievance-handling department.

Article 8 (Security Measures)

The Company takes the following measures to ensure the security of personal information:

  • Administrative Measures: Establishment and implementation of internal management plans, regular employee training
  • Technical Measures: Access authority management for personal information processing systems, installation of access control systems, encryption of unique identification information, installation of security programs
  • Physical Measures: Access control to computer rooms and data storage rooms

Article 9 (Right to Refuse Consent and Disadvantages)

Users have the right to refuse consent to the collection and use of personal information.

  • If you do not consent to the required information provided by Kakao, you cannot complete Kakao Login-based registration.
  • If no phone number is registered with the Kakao account, or if it is not provided because of a Kakao API or server issue, you must use the direct-entry path, provide a name, date of birth, and mobile phone number, and give required consent before checking pre-registration rosters or submitting a union registration request.
  • If you do not consent to the collection and use of required directly entered information, you cannot submit a union registration request.
  • Refusing optional items does not prevent Kakao Login-based registration or a union registration request.

Article 10 (Privacy Operations and Grievance Handling Department)

Privacy operations and grievance-handling department: Latel Privacy Team

Email: ceo@latel-co.com

Phone: 010-3504-8164

For inquiries, complaints, or damage relief regarding personal information processing, please contact the department above.

This Privacy Policy is effective from August 5, 2026.

Last updated: August 5, 2026