Skip to content

Privacy Policy

Last updated: 2026-08-27

1. Introduction

Tumakr ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our travel platform and services.

2. Information We Collect

Information you provide:

  • Account information: name, email address, phone number, and password.
  • Booking information: travel dates, tour preferences, number of travelers, gender, nationality, arrival/departure flight times, and special requests. We collect these to perform your tour booking contract (Personal Information Protection Act Art. 15(1)4 / GDPR Art. 6(1)(b)); no separate consent is required for this contract-necessary information.
  • Payment information: processed securely through PayPal. We do not store your full payment card details.
  • Communications: messages you send through our chat feature or customer support.

Information collected automatically:

  • Device information: browser type, operating system, and device identifiers.
  • Usage data: pages visited, features used, and interaction patterns.
  • Location data: general geographic location based on IP address.
  • Cookies and similar tracking technologies (see Section 6).

What we do not collect:

We do not collect resident registration numbers (주민등록번호), passport numbers, or sensitive information such as health data. Where a specific tour requires additional non-sensitive booking details (for example, arrival/departure flight times to arrange airport pickup), we collect only what is necessary to perform your tour booking contract, under Personal Information Protection Act Article 15(1)4 (GDPR Article 6(1)(b)). Custom form responses are encrypted at rest (see Section 7); see Section 5 for retention.

3. How We Use Your Information

  • To provide and manage your tour bookings and travel services.
  • To process payments and send booking confirmations.
  • To communicate with you about your bookings and inquiries.
  • To personalize your experience and provide AI-powered travel recommendations.
  • To improve and optimize our platform and services.
  • To send promotional communications (with your consent, which you can withdraw at any time).
  • To comply with legal obligations and protect our rights.

Before submitting a booking or payment, you are asked to separately confirm: (1) your agreement to our Terms of Service, and (2) your consent to this Privacy Policy's collection and use of your personal information. Consent to receive marketing communications is optional, presented separately, and is never required to complete a booking.

4. Sharing of Information

We may share your personal information with the following parties:

  • Tour operators and guides: to fulfill your bookings (e.g., names, tour dates, special requests).
  • Payment processors: PayPal, to process your payments securely.
  • Service providers: including Supabase (authentication), Google (maps and AI services), and AWS (file storage), who help us operate the platform.
  • Legal authorities: when required by law or to protect our legal rights.

We do not sell your personal information to third parties.

5. Data Retention

We retain personal information only as long as necessary for the purposes described in this Policy, and in line with the following schedule:

  • Personal information not converted to a paid transaction (e.g., a quote or booking inquiry that never results in payment): retained only to follow up on, and to handle re-inquiries about, that quote or booking inquiry, and deleted or anonymized within 6 months.
  • Visit and access logs: retained for 90 days.
  • Payment and contract records (confirmed bookings and completed payments): retained for 5 years, as required under Article 6 of Korea's Act on Consumer Protection in Electronic Commerce (전자상거래 등에서의 소비자보호에 관한 법률 제6조).
  • Dispute-related records (complaints, cancellations, refund disputes): retained for 3 years.
  • Account data on withdrawal: when you close your account we delete or anonymize your personal information within 30 days, except records we are legally required to retain (Personal Information Protection Act Article 21).

An automated process periodically deletes or anonymizes data once the applicable retention period expires. Where we are required to retain information longer for legal, tax, or compliance purposes, we do so only for that purpose.

6. Cookies and Tracking

We use cookies and similar technologies to:

  • Keep you signed in to your account.
  • Remember your preferences and settings.
  • Analyze how our platform is used to improve performance.
  • Provide personalized content and recommendations.

You can manage cookie preferences through your browser settings. Note that disabling cookies may affect the functionality of the Service.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information. Data is encrypted in transit (TLS) and custom payment/booking form responses are encrypted at rest before storage. Access to decrypted data is limited to authorized personnel who need it to fulfill your booking. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate data.
  • Deletion: request deletion of your personal data.
  • Suspension of processing: request that we suspend processing of your personal data (Personal Information Protection Act Article 37).
  • Portability: request your data in a portable format.
  • Opt-out: unsubscribe from marketing communications at any time.

To exercise these rights, please contact us at info@onedaykorea.com.

If you are not satisfied with our response, you may seek remedy through the Personal Information Dispute Mediation Committee (개인정보분쟁조정위원회, kopico.go.kr) or report a privacy infringement to the KISA Privacy Infringement Report Center (개인정보침해 신고센터, dial 118).

9. International Data Transfers

Some of our service providers process personal data outside the Republic of Korea. These transfers are made under Article 28-8(1)3 of the Personal Information Protection Act — they are necessary to perform and manage your booking contract and are disclosed here — so separate consent is not required. In accordance with Article 28-8(2), we disclose the following for each overseas transfer.

Supabase Pte. Ltd.

  • Items transferred: account and authentication data, and the booking/quote form data described in Section 2 (name, email, phone number, travel details), stored in our managed database.
  • Country, timing & method: Singapore (AWS region ap-southeast-1). Transferred over an encrypted (TLS) connection when you create an account, submit a booking or quote, or use features that read or write this data.
  • Recipient & contact: Supabase Pte. Ltd. — privacy@supabase.io.
  • Purpose & retention: managed database and authentication; retained for the term of our service agreement and deleted within 30 days after the agreement ends, subject to the retention periods in Section 5.

PayPal Pte. Ltd.

  • Items transferred: payment and transaction-confirmation data needed to process your payment (we do not transfer full card numbers; PayPal collects payment credentials directly).
  • Country, timing & method: Singapore. Transferred over an encrypted connection at the time you make a payment.
  • Recipient & contact: PayPal Pte. Ltd. — see PayPal's privacy statement at paypal.com.
  • Purpose & retention: payment processing; retained for up to 10 years after the transaction to meet anti-money-laundering and financial record-keeping obligations.

Google Asia Pacific Pte. Ltd.

  • Items transferred: technical and usage data used by maps, analytics, tag management, and AI travel features (e.g., IP-derived location, device/usage signals, and content you submit to AI features).
  • Country, timing & method: Singapore (contracting entity; billed in Korea). Transferred over an encrypted connection when the relevant feature loads or is used.
  • Recipient & contact: Google Asia Pacific Pte. Ltd. — see policies.google.com.
  • Purpose & retention: maps, analytics, tag management, and AI recommendations; retained under Google's data processing terms.

Vercel Inc.

  • Items transferred: request and log data processed while serving the website (e.g., IP address and request metadata; personal data you submit passes through hosting infrastructure in transit).
  • Country, timing & method: United States (Delaware; serverless functions default to the US East region). Transferred over an encrypted connection each time you use the Service.
  • Recipient & contact: Vercel Inc. — privacy@vercel.com.
  • Purpose & retention: web hosting and application delivery; retained under Vercel's data processing terms.

Functional Software, Inc. (Sentry)

  • Items transferred: error and diagnostic context, which may include limited identifiers or request data present at the moment of an error.
  • Country, timing & method: United States / European Union. Transferred when an application error is reported.
  • Recipient & contact: Functional Software, Inc. (Sentry).
  • Purpose & retention: error monitoring and reliability; retained under Sentry's data processing terms.

Your right to refuse: Because these transfers rely on Article 28-8(1)3 (performance of your booking contract, disclosed in this Policy), they do not require separate consent, but you may still refuse them by contacting us at info@onedaykorea.com. These providers supply core functions — secure database storage, payment, hosting, and maps — so if you refuse the transfer we cannot create or maintain your account, process a payment, or complete your booking, and the affected features or booking may be unavailable. Refusing does not affect the lawfulness of any processing carried out before your request.

Domestic processing: Our primary compute and file storage run on Amazon Web Services in the Seoul region (ap-northeast-2, Republic of Korea). Because this data stays within Korea, it is handled as domestic outsourcing of processing under Article 26 of the Personal Information Protection Act rather than an overseas transfer. These operations are covered by K-ISMS certification.

We ensure appropriate safeguards for such transfers, including contractual data protection terms with our service providers (PayPal, Supabase, Google, Vercel, Sentry).

10. Children's Privacy

The Service is not intended for users under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the Service or by email. Your continued use of the Service after such changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at info@onedaykorea.com.

13. Chief Privacy Officer

Our Chief Privacy Officer (CPO, 개인정보 보호책임자, Personal Information Protection Act Article 31) is 원대희 (Won Dae Hee), Representative, reachable at info@onedaykorea.com for any questions regarding how we handle your personal information or to exercise your rights under this Policy.