Privacy Policy

Version 1.0 · Effective 2026-06-02

1. Personal Information Collected

[Required at sign-up] Email, password (one-way hashed), nickname [Required when booking and paying] Name, date of birth, gender, nationality, mobile phone number (identity verification) — limited to what is needed for flight ticketing, local reservations, and age verification [Optional] Nationality (if you choose to enter it at sign-up), referral code, acquisition channel, marketing-receipt consent [When submitting medical receipts] Receipt images and transaction details shown on the receipt (treatment type, date) — for point calculation. The Company does not collect or store medical information such as allergies, medications, or treatment history. [Automatically collected] IP address, cookies, browser info, access timestamps, payment transaction IDs

2. Purposes of Processing

1. Member identification and authentication (signup, login, booking-confirmation gate) 2. 1:1 curator consultation and design of experience (including medical treatment) and travel itineraries 3. Payments and refunds, and point accrual upon receipt review 4. Calculation and disbursement of referral rewards 5. Customer support, incident handling, and complaints 6. Fraud detection and security (suspicious IP blocking, identity-theft prevention) 7. Statutory obligations of a foreign-patient attractor (reports to the Ministry of Health and Welfare, etc.) 8. With consent, marketing and event notifications

3. Retention and Use Period

In principle, all personal information is destroyed immediately upon withdrawal. The following statutory periods apply for separately stored data: - Electronic Commerce Act: contracts/cancellations — 5 years - Electronic Commerce Act: payments and product supply — 5 years - Electronic Commerce Act: consumer complaints/disputes — 3 years - Medical Service Act: medical records are kept by Partner Experience Providers; the Company does not store them. - Communications Privacy Protection Act: access logs — 3 months - Suspected fraudulent transactions: refusal/suspension/termination records — 1 year

4. Provision to Third Parties

In principle, personal information is not provided to third parties. With prior consent, the minimum necessary information is shared with: 1. Partner Experience Providers — for booking (name, date of birth, nationality, preferred language). Contact details (phone/email) are not shared, as the curator mediates communication. Treatment-safety medical information is provided by the Member directly or via the curator to the institution; the Company does not separately store it 2. Payment processors (Eximbay, etc.) — for payment/refund 3. Carrier authentication agencies — for mobile verification 4. Investigation/government agencies under statutory obligation Members may refuse consent, but doing so may restrict the relevant service.

5. Outsourcing of Processing

For service operation, the Company outsources to: - Supabase Inc. (HQ in USA / data stored in AWS Seoul region): database, authentication, real-time communication - Vercel Inc. (USA): web hosting, CDN (static assets, access logs; no member personal data stored) - Eximbay (Korea): global card / WeChat Pay / Alipay / PayPal - Twilio Inc. (USA): SMS authentication and notifications - Gabia (Korea): email infrastructure (SMTP) Outsourcing contracts specify data-protection obligations, processing limits, and safeguards.

6. International Transfers

Members' personal information is, in principle, stored and retained within Korea (AWS Seoul region). However, to provide certain services such as SMS verification and global payments, overseas processors may process only the minimum information necessary for those services. [Information processed overseas] The minimum necessary for the service (e.g., mobile number for verification, payment details for payment) [Overseas processors] Those located outside Korea among the processors listed in Article 5 [Method] Real-time transmission during service use, encrypted with TLS 1.2+ [Retention] Destroyed upon achievement of the processing purpose or upon Company request Members may refuse such overseas processing, but doing so may restrict certain services such as global payments and SMS authentication.

7. Member Rights

1. Access and correction (My Page) 2. Suspension of processing / deletion (My Page withdrawal or request to cs@usoultrip.com) 3. Withdrawal of consent (marketing receipt, etc.) 4. Direct inquiry to the Privacy Officer 5. Reports to Korean authorities: - Personal Information Dispute Mediation Committee: 1833-6972 / kopico.go.kr - Privacy Infringement Report Center: 118 / privacy.kisa.or.kr

8. Cookies and Similar Tools

[Essential] Login session, security tokens [Functional] Language preference, settings [Analytics] Anonymous statistics (sources, time on page) — not joined with member identity Declining cookies may limit auto-login or language persistence. Cookies can be blocked or deleted in browser settings.

9. Security Measures

1. TLS 1.2+ in transit 2. One-way hashed passwords (bcrypt) 3. Minimized number of staff handling personal data, with training 4. Supabase Row-Level Security — only owners can view/edit their data 5. Restricted access to message bodies (curator only for assigned threads; CS only metadata) 6. Audit logs (audit_logs) for all admin actions 7. Suspicious-IP blocking and abnormal-login alerts 8. Periodic security audits and patching

10. Privacy Officer

[Privacy Officer] Name: 현재환 (Hyun Jaehwan) — CEO Contact: cs@usoultrip.com / +82-51-628-3967 [Privacy Department] Customer Support Team cs@usoultrip.com / +82-51-628-3967 Members may report any privacy-related inquiry, complaint, or remediation request via the contact above.

11. Changes to this Policy

This Policy may be amended in line with changes to law, policy, or security technology. Amendments are announced 7 days in advance (30 days when unfavorable to Members). Members may refuse amendments and terminate processing by withdrawing membership. [Effective Date] June 2, 2026 (Version 1.0)

Company Information

Company: 유솔트립 주식회사 (uSoulTrip Co., Ltd.) Representative: 현재환 (Hyun Jaehwan) Business Reg. No.: 176-86-03967 Foreign-Patient Attractor Reg. No.: A-2026-02-01-067890 Headquarters: 부산광역시 부산진구 동천로 16, 2F 셀렉스페이스 213호(전포동, 유성넥스빌) Customer Support: cs@usoultrip.com / +82-51-628-3967

※ The Terms of Service (v1.4) are effective August 17, 2026; the Privacy Policy (v1.0) is effective June 2, 2026. Any changes will be announced at least 7 days in advance, and existing members will be asked to re-consent.