Travel Pass

LEGAL

Privacy Policy

Effective dateAugust 13, 2026v1.0

Effective date: August 13, 2026

Personal information controller: Crosshub Co., Ltd.

Service: Travel Pass

Crosshub Co., Ltd. (the "Company") lawfully processes and securely manages personal information in compliance with the Personal Information Protection Act and other applicable laws to protect the freedom and rights of data subjects using Travel Pass.

Pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and publishes this Privacy Policy to explain its procedures and standards for personal information processing and to promptly handle enquiries and grievances concerning personal information.


Article 1 (Purposes of Processing Personal Information)

The Company processes only the minimum personal information necessary for the following purposes.

1. Account Registration and Member Management

  • Identify members and confirm intent to register
  • Create member accounts
  • Email verification and sign-in
  • Maintain and manage membership status
  • Prevent duplicate registration
  • Prevent unauthorized use
  • Process account withdrawal

2. Identity Verification and eKYC

  • Verify users' identities
  • Verify the authenticity and validity of identity documents, including passports and Korean residence cards
  • Verify identity for use of registered prepaid cards
  • Confirm that the identity-document holder and actual user are the same person
  • Face-match and liveness verification
  • Prevent duplicate, forged, stolen-identity, and other fraudulent authentication
  • Manage identity-verification results and authentication assurance levels

3. Prepaid-Card Services

  • Support prepaid-card application, collection, and registration
  • Activate cards
  • Provide card-status and balance enquiries
  • Support reporting of lost cards, suspension, reactivation, and replacement issuance
  • Provide card-use history
  • Provide card-related customer support

4. Top-up and Transaction Management

  • Top-ups using Korean and overseas credit and debit cards
  • Top-ups using virtual accounts and partner pay services
  • Confirm payment authorization and top-up results
  • Manage transaction history, including top-ups, payments, and cancellations
  • Confirm card balances
  • Support top-up cancellation and balance refunds
  • Verify erroneous and duplicate transactions
  • Prevent unusual transactions and unauthorized use

5. Customer Support and Dispute Handling

  • Handle user enquiries and complaints
  • Verify transaction facts
  • Respond to disputes relating to cards, top-ups, and payments
  • Respond to unauthorized use and financial incidents
  • Verify transactions with relevant institutions or partners

6. Service Stability and Security

  • Authenticate users and manage access
  • Identify service failures
  • Detect unusual access and unauthorized use
  • Investigate and respond to security incidents
  • Secure service and system stability

7. Linkage with Partner Services

  • Streamlined registration and sign-in for external services requested by users
  • Link accounts with Partner Services
  • Provide identity-verification results within the scope to which users consented

8. Marketing and Advertising

The Company processes personal information for the following purposes only when the user has separately given optional consent.

  • Notices of events and promotions
  • Notices of service benefits such as discounts and coupons
  • Notices of new services and features
  • Advertising and promotion relating to Travel Pass products and services
  • Notices of Partner Services and partner promotions
  • Other marketing and commercial information within the scope to which the user consented

Use of personal information for marketing purposes and receipt of commercial information are optional. Refusing or later withdrawing consent does not affect use of basic Travel Pass services.

Users may select whether to receive commercial information by each delivery method, including email and app push notifications.


Article 2 (Items of Personal Information Processed, Purpose, Legal Basis, and Retention Period)

1. Account Registration and Account Management

CategoryItems processedPurposeLegal basisRetention and use period
Standard account registrationName, date of birth, email address, password (stored using one-way hashing), internal service member identifierAccount registration, authentication, account management, and prevention of duplicate registration and unauthorized useEntering into and performing the service agreementUntil account withdrawal. If a statutory retention obligation applies, until the applicable period ends
Google streamlined registration/sign-inGoogle user identifier, email address, and nameStreamlined registration and sign-inEntering into and performing the service agreementUntil account withdrawal or unlinking of the relevant account
Apple streamlined registration/sign-inApple user identifier, email address, and name where provided by AppleStreamlined registration and sign-inEntering into and performing the service agreementUntil account withdrawal or unlinking of the relevant account

The Company generally does not persistently store Google or Apple access tokens and refresh tokens on its servers.


2. Identity Verification and eKYC

General eKYC Information

Items processedPurposeLegal basisRetention and use period
Name, date of birth, gender, nationality, document type, issuing country, expiration date, necessary information extracted from the MRZ, eKYC transaction identifier, authentication status, authentication assurance level, verification date and time, and validity periodIdentity verification, identity-document authenticity verification, use of registered cards, and prevention of duplicate and fraudulent authenticationProcessed to the extent necessary for service provision and performance of the service agreement; information requiring separate consent under applicable laws is processed based on that consentUntil the member relationship or the service relationship for a registered card requiring identity verification ends. If another retention basis applies, until the applicable period ends

The Company generally stores only the minimum information and verification results necessary to provide Travel Pass from information processed during eKYC.


3. Unique Identifying Information

The Company may process the following unique identifying information in eKYC and provision of services requiring identity verification.

  • Passport number
  • Alien registration number

Except where applicable laws separately require or permit processing, unique identifying information is processed after obtaining the consent required separately from consent for other personal information processing.

If storage of a passport number or alien registration number is actually required, the Company stores it in encrypted form in accordance with applicable laws.

The Company generally does not retain the full plain-text value of unique identifying information for an unnecessary extended period and destroys it without delay once the purpose, such as identity verification, has been achieved, or retains only minimum verification results necessary for the Service.

If processing a domestic residence-report number, the Company classifies it as important personal information and applies enhanced safeguards regardless of whether it is legally categorized as unique identifying information.


4. Passport OCR

The following personal information may be processed during passport OCR.

  • Original passport image
  • Name
  • Date of birth
  • Gender
  • Nationality
  • Passport number
  • Passport expiration date
  • Passport issuing country
  • MRZ information
  • Facial image in the passport
  • Document type
  • eKYC transaction identifier

The Company generally does not retain original passport images or facial images in passports for a long period in its own general service database.

An original passport may be processed temporarily during eKYC verification, and the Company retains only the minimum verification-result information necessary to provide the Service.


5. Electronic-Passport NFC Authentication

The following information may be processed during electronic-passport NFC authentication.

  • DG1: passport biographical and MRZ information
  • DG2: passport facial image
  • SOD and electronic-signature verification information
  • Electronic-passport authenticity-verification result
  • NFC authentication success or failure result

NFC processing may be performed through a specialized eKYC solution or SDK used by the Company.

The Company generally does not store original electronic-passport data or facial images in its own general service database and retains only minimum result information necessary to provide the Service, such as the electronic-passport verification result.


6. Facial Authentication and Liveness

The following information may be processed during electronic identity verification.

  • Facial image or video/consecutive frames captured by the user
  • Facial image included in a passport or identity document
  • Facial-feature information technically generated to authenticate or identify a specific individual
  • Face-match result
  • Liveness verification information
  • Face Match result
  • Final eKYC verification result

If facial-feature information technically generated to authenticate or identify a specific individual constitutes sensitive information under applicable laws, the Company obtains consent required separately from other personal information processing or processes it on another lawful basis recognized under applicable laws.

The Company generally does not retain the following information for a long period in its own general service database.

  • Original facial image
  • Facial video
  • Facial-feature values or embeddings

Where necessary, the Company may store the following minimum verification results.

  • Liveness success or failure
  • Face Match success or failure
  • Final eKYC verification result
  • Verification date and time
  • Authentication assurance level
  • Verification validity period

The Company generally does not store the original face-match score or liveness score unless it is essential to Service operations.


7. Identity Verification Using a Korean Residence Card or Similar Document

When using a Korean residence card or another identity document supported by the Company, the following information may be processed.

  • Name
  • Date of birth
  • Gender
  • Nationality
  • Alien registration number or domestic residence-report number
  • Sojourn status
  • Period of stay
  • Identification photograph
  • Date of issue
  • Identity-verification result

The Company generally does not retain original identity-document images for a long period in its own general service database and retains only the minimum verification results necessary to provide the Service.


8. Marketing and Advertising

The Company processes personal information within the scope of consent only when the user has separately given optional consent to use personal information for marketing purposes or to receive commercial information.

CategoryItems processedPurposeLegal basisRetention and use period
Marketing and advertisingName, email address, internal service member identifier, push token, language settingsNotices of events, promotions, discounts and coupons, new services and features, and advertising and benefits concerning Travel Pass and Partner ServicesOptional consent of the data subjectUntil withdrawal of consent to use personal information for marketing purposes or account withdrawal
Management of email commercial-information consentEmail address, consent status for email commercial information, date and time of consent, refusal, or withdrawalProviding commercial information by email and managing receipt consentOptional consent of the data subject and applicable lawsUntil withdrawal of receipt consent or account withdrawal. Consent, refusal, and withdrawal history is retained for the period necessary to confirm it under applicable laws
Management of app-push commercial-information consentPush token, app-related identifier, consent status for app-push commercial information, date and time of consent, refusal, or withdrawalProviding commercial information by app push and managing receipt consentOptional consent of the data subject and applicable lawsUntil withdrawal of receipt consent or account withdrawal. Consent, refusal, and withdrawal history is retained for the period necessary to confirm it under applicable laws

The Company does not use the following information for ordinary marketing or advertising purposes.

  • Passport number
  • Alien registration number
  • Domestic residence-report number
  • Original passport or identity-document image
  • Facial image or video
  • Biometric information such as facial-feature information
  • Original eKYC information
  • Full card number
  • CVC/CVV
  • Detailed merchant transaction history for card use

If the Company intends to offer personalized marketing using card-use history, location information, online behavioral information, or other personal information in the future, it separately reviews the lawful basis for the processing and carries out any additional notice and consent procedure required under applicable laws.

Details concerning use of personal information for marketing purposes and receipt of commercial information by email or app push are available in the Travel Pass Marketing and Commercial Information Consent Notice.


Article 3 (Processing of Card-Related Personal Information)

The Company may process the following information while a prepaid card is registered or managed in Travel Pass.

  • Card ID or card reference
  • Masked card number
  • Token provided by a card issuer or PG
  • Card issuer
  • Card status
  • Card issuance date
  • Card collection date
  • Card activation status
  • Lost-card or suspension status
  • Information relating to replacement issuance

The Company generally does not directly store the following information that is unnecessary for Service operations.

  • Full card number
  • CVC/CVV
  • Other original card-authentication information

Full card information and card-payment authentication information are generally processed by the relevant financial or payment business, such as a Partner Card Issuer or PG.


Article 4 (Information Processed During Top-ups and Transactions)

The Company may process the following information to process top-ups and related transactions.

  • Member ID
  • Wallet or internal service identifier
  • Order number
  • PG transaction number (Transaction ID/TID)
  • Merchant ID (MID)
  • Payment method
  • Card issuer
  • Masked card number or part of a card number
  • Transaction amount
  • Transaction currency
  • Approval number
  • Approval date and time
  • Transaction status
  • Result code and result message
  • Cancellation amount
  • Cancellation date and time
  • Refund amount
  • Original transaction identifier
  • Virtual account number
  • Virtual account bank
  • Deposit deadline
  • Deposit status
  • Deposit date and time
  • Depositor name, where provided by the PG

Full credit-card numbers and payment-authentication information such as CVC are processed through the payment systems of the PG or card issuer and are generally not directly collected or stored by the Company.


Article 5 (Processing of Card-Use History)

The Company may receive the following card-use information through service linkage with a Partner Card Issuer or relevant institution.

  • Card ID or card reference
  • Transaction ID
  • Payment date and time
  • Payment amount
  • Payment currency
  • Merchant name
  • Merchant number
  • Merchant category (MCC)
  • Approval number
  • Approval or cancellation status
  • Cancellation amount and date and time
  • Balance after transaction
  • Merchant country or region
  • Online or offline classification
  • ATM withdrawal history
  • Transit-card use history, where supported by the card product

The Company processes the information for the following purposes.

  • Providing card-use history
  • Balance confirmation
  • Confirmation of payment and cancellation history
  • Customer enquiries and dispute handling
  • Verification of unusual transactions and unauthorized use

If the information constitutes personal credit information or similar information under applicable laws, the Company processes it in accordance with applicable laws and contracts, including the Credit Information Use and Protection Act.


Article 6 (Methods of Collecting Personal Information)

The Company may collect or receive personal information through the following methods.

  1. Direct input by users in the Travel Pass mobile application
  2. eKYC using identity documents such as passports and Korean residence cards
  3. Google and Apple streamlined registration and sign-in
  4. Top-up and payment processing through PGs
  5. Linkage of card status, balance, and transaction information through Partner Card Issuers
  6. Customer Support enquiries
  7. Information generated automatically during Service use
  8. Linkage with a Partner Service directly requested by the user

The Travel Pass official website currently does not provide account-registration or sign-in functionality.


Article 7 (Personal Information Collected from Sources Other Than the Data Subject)

The Company may receive personal information from a business or institution other than the data subject in the course of providing the Service.

Google

  • Google user identifier
  • Email
  • Name

Purpose of collection: Google streamlined registration and sign-in

Apple

  • Apple user identifier
  • Email
  • Name where provided by Apple

Purpose of collection: Apple streamlined registration and sign-in

Specialized eKYC Providers

  • OCR verification result
  • Identity-document authenticity-verification result
  • NFC verification result
  • Liveness result
  • Face Match result
  • eKYC verification status
  • Verification date and time
  • Minimum identity-verification result necessary, including the authentication assurance level

PGs

  • Payment, authorization, and cancellation results
  • PG transaction number
  • Payment method
  • Transaction amount and currency
  • Authorization information
  • Masked card information
  • Virtual-account-related information

Partner Card Issuers

  • Card status
  • Card and transaction identifiers
  • Balance
  • Authorization and cancellation history
  • Card-use history

If a data subject requests the source of collection or related information in accordance with applicable laws, the Company provides the necessary information to the extent prescribed by those laws.


Article 8 (Third-Party Provision of Personal Information)

The Company generally processes personal information within the scope of collection and processing purposes and does not provide it to a third party without the data subject's consent or another lawful basis recognized under applicable laws.

Third-party provision may be necessary to provide the following Travel Pass functions.

  • Application for and issuance of registered prepaid cards
  • Services linked with financial institutions
  • Streamlined registration and sign-in for Partner Services
  • Another Partner Service directly requested by the user

Where separate consent is required for third-party provision, the Company provides the following information and obtains the required consent before the actual provision.

  • Recipient of personal information
  • Purpose of use by the recipient
  • Items of personal information provided
  • Retention and use period
  • Right to refuse consent
  • Disadvantage of refusing consent

Unique identifying information such as passport numbers and alien registration numbers is not provided by default during ordinary streamlined registration or sign-in for Partner Services.

If a financial institution or card issuer necessarily requires unique identifying information under applicable laws or to provide the service, the Company reviews the necessity of provision and, where separate consent is required, obtains consent separately from consent to third-party provision of general personal information.

Detailed current information on third-party provision is managed so it can be reviewed in the Notice and Status of Third-Party Provision of Personal Information on the Travel Pass official website.

The Company does not provide personal information to a partner whose contract or service structure has not been finalized, and updates the relevant status before a new third-party provision begins.


Article 9 (Entrusted Processing of Personal Information)

Where necessary to provide the Service, the Company may entrust part of its personal information processing work to a specialized provider.

When entrusting processing, the Company includes matters such as the following in a contract or document and manages and supervises the entrusted processor in accordance with applicable laws.

  • Prohibition on processing personal information outside the purpose of the entrustment
  • Safeguards for personal information
  • Management and supervision relating to personal information protection
  • Matters concerning sub-processing
  • Destruction and return of personal information
  • Protection of data-subject rights

Partnership and entrusted-processing contracts relating to cards, PGs, eKYC, and similar services may be finalized according to the Service structure.

The Company will determine and disclose in this Privacy Policy the exact corporate name of the entrusted processor and the entrusted work before it begins entrusted processing of actual users' personal information.

The Company also updates this Privacy Policy before changed processing begins if an entrusted processor or entrusted work changes.


Article 10 (Cross-Border Transfers of Personal Information)

If personal information is provided, accessed, processed by an entrusted provider, or stored outside Korea, the Company secures a lawful basis for cross-border transfer recognized by the Personal Information Protection Act and applies safeguards required by applicable laws.

The Company separately reviews whether cross-border transfers occur when using social sign-in, push notifications, overseas cards, or overseas payment methods.

The Company does not arbitrarily transfer personal information to an overseas business whose contract or service structure has not been finalized.

Before an actual cross-border transfer begins, the Company discloses the following information as required by applicable laws or, where necessary, separately provides it to the user and obtains consent.

  • Items of personal information transferred
  • Destination country
  • Time and method of transfer
  • Name and contact information of the recipient
  • Purpose of use by the recipient
  • Retention and use period
  • Legal basis for cross-border transfer
  • Method and procedure for refusing the transfer
  • Effect of refusing the transfer

Detailed current information on cross-border transfers is managed so it can be reviewed in the Notice and Status of Cross-Border Transfer of Personal Information on the Travel Pass official website.

When introducing a new cloud service or a service offered by an overseas business, the Company reviews the actual storage location of personal information, the possibility of overseas access, sub-processing, and backup locations to determine whether a cross-border transfer occurs.


Article 11 (Retention and Use Periods for Personal Information)

The Company generally destroys personal information without delay once the processing purpose has been achieved or the information is no longer necessary.

However, it may retain information for a certain period to the extent necessary where there is a statutory retention obligation or a need to preserve it for a dispute or transaction processing.

Personal information categoryRetention and use period
Basic member informationUntil account withdrawal. If a statutory retention obligation applies, until the applicable period ends
Google/Apple linkage informationUntil account withdrawal or unlinking of the relevant social account
Original passport imageGenerally not retained long term in Crosshub's own general service database
Facial image or videoGenerally not retained long term in Crosshub's own general service database
Facial-feature values or embeddingsGenerally not stored in Crosshub's own general service database
Passport number or alien registration numberStored in encrypted form only when actual retention is necessary and destroyed without delay after the processing purpose, such as identity verification, is achieved. Where separate consent is obtained, the period disclosed in that consent applies
eKYC verification resultsUntil the member relationship or the service relationship for a registered card requiring identity verification ends. If a statutory retention obligation applies, until the applicable period ends
Card ID, masked number, and status informationUntil the Travel Pass service relationship for the relevant card ends
Top-up, payment, cancellation, and refund transaction informationRetained during the service and transaction relationship; where a statutory transaction-record retention obligation applies, until the applicable statutory period ends
Customer enquiry and dispute-handling recordsFor the period necessary to handle the enquiry or dispute; where a statutory retention obligation applies, until the applicable period ends
Terms-of-use and privacy-related consent historyDuring the period the relevant consent remains effective and the period necessary to verify consent under applicable laws
Personal information for marketing purposesUntil withdrawal of consent to use personal information for marketing purposes or account withdrawal
Commercial-information receipt-consent historyFor the period necessary to confirm consent, opt-out, or withdrawal for email, app push, and similar channels and to comply with applicable laws
Access records of personal information handlers to personal information processing systemsFor the period prescribed by applicable laws; for a system processing unique identifying information or sensitive information, at least two years

Whether a statutory obligation to retain particular transaction records applies directly to the Company is determined by the actual Service structure and legal status. If such an obligation is confirmed, the Company will state the specific retention period in this Policy.


Article 12 (Procedures and Methods for Destruction of Personal Information)

① The Company destroys personal information without delay when it is no longer necessary, for example because the retention period has expired or the processing purpose has been achieved.

② Personal information that must be retained for a period under applicable laws is managed separately from other personal information so that it is not used for another purpose.

③ Personal information in electronic files is deleted by a secure method that makes recovery or reproduction difficult.

④ Where personal information is recorded in paper documents, it is destroyed by shredding, incineration, or another method.

⑤ When the retention period for a category of personal information ends, the Company may apply a secure destruction process, such as automated deletion.

⑥ If it is difficult to immediately delete individual personal information from backup data, the Company restricts access to that data and destroys it securely after the backup retention period ends.

⑦ If backup data is used to restore a system, the Company takes necessary measures, such as applying deletion history, to ensure that previously deleted personal information is not used again.

⑧ If original images such as passports, identity documents, or facial images are created in temporary files or caches during processing, the temporary information is also subject to destruction after the purpose is achieved.


Article 13 (Safeguards for Personal Information)

The Company applies technical, administrative, and physical safeguards required under applicable laws to prevent loss, theft, leakage, forgery, alteration, or damage of personal information.

Technical Measures

  • Protection of information in transit through secure communications such as HTTPS/TLS
  • One-way password hashing that cannot be decrypted
  • Encryption of important information required by law, including passport numbers and alien registration numbers
  • No storage of unnecessary full card numbers and CVCs
  • Access-control management for personal information processing systems
  • Creation and retention of access records for personal information processing systems
  • Prevention of passwords, authentication tokens, unique identifying information, and similar information appearing in logs
  • Masking of personal information in administrator interfaces where necessary
  • Technical safeguards for responding to security incidents and unusual access

Administrative Measures

  • Minimization of access privileges to personal information
  • Management of access privileges for personal information handlers and administrators
  • Inspection of personal information processing and access status
  • Control of downloads and exports of personal information
  • Management and supervision of entrusted processors of personal information
  • Operation of internal management plans and procedures relating to personal information protection
  • Protection training for personal information handlers

Physical and Access-Control Measures

  • Restrictions on access to servers and personal information processing systems
  • Use of controlled access methods such as VPNs where necessary
  • Minimization of personnel who can access personal information processing systems
  • Physical and logical access controls for servers and important systems

The Company continuously reviews and improves necessary safeguards in accordance with the actual status of personal information processing and system structure.


Article 14 (Information Automatically Generated During Service Use)

The following information may be automatically generated or processed during use of the Service.

Travel Pass Mobile Application

  • IP address
  • Access date and time
  • Sign-in records
  • Device identification information
  • OS type and version
  • App version
  • Push token
  • Language settings
  • Service-use history

Travel Pass Official Website

  • IP address
  • Access date and time
  • Browser information
  • User-Agent
  • Website access and use history

The Company does not currently use advertising identifiers (IDFA or GAID) for user tracking for advertising purposes.

GPS location information is not currently collected automatically during ordinary use of Travel Pass.

If the Company introduces an error-analysis tool, usage-behavior analysis, or another automatic collection tool in the future, it will review the actual information processed, purpose of processing, and whether cross-border transfer of personal information occurs, and reflect the necessary information in this Privacy Policy.


Article 15 (Cookies and Similar Technologies)

The Travel Pass official website does not currently use cookies or similar technologies for maintaining sign-in status, user analysis, customized advertising, or retargeting.

The official website does not currently use the following tools.

  • Google Analytics
  • Google Tag Manager
  • Google Ads Conversion Tracking
  • Meta Pixel
  • Other tracking tools for advertising or retargeting

IP addresses, access date and time, and general access logs generated in operating the web server are distinct from cookies and are processed in accordance with Article 14.

If the Company introduces cookies or similar technologies in the future, it will review the actual purpose of use, information processed, retention period, and method for users to refuse use, and amend this Privacy Policy and the Cookie and Similar Technologies Policy.


Article 16 (Additional Use and Provision of Personal Information)

The Company generally processes personal information within the scope of the purpose for which it was collected.

If the Company additionally uses or provides personal information without separate consent within a scope reasonably related to the original collection purpose, it comprehensively considers the following in accordance with applicable laws.

  • Whether it is related to the original collection purpose
  • Whether additional use or provision can be expected in light of the circumstances of collection or processing practices
  • Whether it unfairly infringes the data subject's interests
  • Whether necessary safeguards, such as pseudonymization and encryption, have been applied

The Company internally reviews the appropriateness of additional use or provision where it is necessary.


Article 17 (Rights of Data Subjects and Legal Representatives and How to Exercise Them)

Data subjects may exercise the following rights against the Company as prescribed by applicable laws.

  1. Request access to personal information
  2. Request correction of personal information
  3. Request deletion of personal information
  4. Request suspension of personal information processing
  5. Withdraw consent to personal information processing
  6. Withdraw from membership
  7. Other rights relating to personal information recognized under applicable laws

Members may directly review or correct certain personal information, or apply for account withdrawal, through functions provided in the Travel Pass app.

For matters difficult to handle directly in the app, a request may be made through the personal information enquiry channel in Article 19.

After verifying the data subject's identity, the Company processes the request in accordance with the procedures and time periods prescribed by applicable laws.

If the Company provides the Service to a user whose age requires consent from a legal representative, that legal representative may exercise necessary rights, such as access, correction, deletion, and suspension of processing, in accordance with applicable laws.


Article 18 (Use of Automated Technology and Automated Decisions)

The following automated technologies may be used during Travel Pass eKYC.

  • Identity-document OCR
  • Electronic-passport authenticity verification
  • Face matching
  • Liveness verification

The verification results of these automated technologies may be used to determine the user's identity-verification status and availability of the Service.

Final eligibility for issuance of a registered card or use of a financial service may be determined separately in accordance with applicable laws, card-product conditions, and standards of Partner Card Issuers or financial institutions.

If the Company later makes an automated decision under the Personal Information Protection Act using a fully automated system that materially affects a data subject's rights or obligations, it will separately disclose through the official website or another channel the fact of the decision, key standards and procedure, personal information processed, and methods to request refusal, explanation, or review, in accordance with applicable laws.


Article 19 (Chief Privacy Officer and Privacy Enquiries)

To oversee personal information processing and protection and to handle data subjects' enquiries, complaints, and remedies relating to personal information, the Company operates the following Chief Privacy Officer and enquiry channels.

Chief Privacy Officer

  • Name: Jaeseol Kim
  • Title: Representative Director
  • Telephone: +82-2-780-9930
  • Email: contact@travelpass.cards

Privacy Enquiries and Customer Support

  • Contact: Travel Pass Customer Support
  • Telephone: +82-2-780-9930
  • Email: contact@travelpass.cards

Data subjects may use the contact information above for personal information protection enquiries, complaint handling, remedies, and exercise of rights relating to use of Travel Pass.


Article 20 (Remedies for Personal Information Infringement)

For consultation, reporting, or dispute mediation concerning personal information infringement, data subjects may contact the following institutions.

  • Personal Information Infringement Report Center: 118 (without area code)
  • Personal Information Dispute Mediation Committee: 1833-6972

These institutions are separate from the Company. For the Company's own personal information enquiries or exercise of rights, users may use the privacy enquiry channel in Article 19.


Article 21 (Publication and Amendment of This Privacy Policy)

① The Company publishes this Privacy Policy on the Travel Pass official website so that anyone can easily review it regardless of whether they have registered for membership.

② If this Privacy Policy is amended, the Company provides information on the effective date and principal changes through the official website, Travel Pass app, or another channel.

③ If a change materially affects data subjects' rights or personal information processing, the Company carries out any additional notice or consent procedure required under applicable laws.

④ The Company manages prior versions of this Privacy Policy and change history so that users can review them.

⑤ If the status of third-party provision, entrusted processing, or cross-border transfer of personal information changes, the Company reflects the relevant information before the changed processing begins.


Addendum

This Privacy Policy takes effect on August 13, 2026.

Personal information controller: Crosshub Co., Ltd.

Representative: Jaeseol Kim

Address: Startup Building 301-17, 67 Yusang-ro, Deokjin-gu, Jeonju-si, Jeonbuk State, Republic of Korea (Palfbok-dong 2-ga, Jeonju Advanced Venture Complex)

Customer Support: +82-2-780-9930

Email: contact@travelpass.cards

Service: Travel Pass

Privacy Policy Change History

VersionEffective dateMain changes
v1.0August 13, 2026Initial establishment of the Travel Pass Privacy Policy

Privacy Policy version: v1.0