Korea · PIPA
Privacy notice
for Korea.
Published under Article 30 of Korea’s Personal Information Protection Act. It applies to users resident in Korea and prevails over the general policy.
Effective · 2026. 08. 06.
1. About this notice
CommonSource (“the Company”) publishes this notice under Article 30 of the Personal Information Protection Act of the Republic of Korea (PIPA) so that data subjects can understand how their personal information is handled and raise concerns easily.
This notice applies to users resident in Korea and supplements the Company’s general privacy policy. Where the two differ, this notice prevails for Korean users.
2. Purposes of processing
- Support enquiries
- Reviewing enquiries, verifying identity, investigating facts, notifying outcomes and following up.
- Providing and maintaining the service
- Delivering app and website functionality, confirming purchases and subscriptions, diagnosing errors and responding to incidents.
- Security
- Preventing misuse, responding to security incidents and monitoring service stability.
- Improvement
- Improving features and quality using pseudonymized or anonymized usage statistics.
3. Categories of personal information processed
- When you contact us
- Required — email address and message. Optional — app name, device model, OS version, app version. Anything you choose to include in the message body is processed with it.
- Generated automatically
- App version, device type, OS version, crash and error reports, access logs and pseudonymized usage statistics.
- Payments
- The Company does not collect payment instrument details. Payments are handled by the Apple App Store and Google Play; card numbers are never transmitted to the Company.
- In-app content
- Core data such as scanned documents, photos, learning history and vehicle diagnostics is processed on your device and is not collected by the Company. It leaves the device only when you explicitly use an export or backup feature, and only to the destination you choose.
4. Retention periods
The Company retains personal information only for the period permitted by law or consented to by the data subject.
- Support and enquiry records
- Three years after the matter is closed. Deleted without delay on request unless a statutory retention duty applies.
- Crash and error reports
- Up to one year from collection, then deleted or converted into anonymous statistics.
- Pseudonymized and anonymous statistics
- May be retained for statistical purposes because individuals can no longer be identified.
- Statutory retention
- Under the Act on Consumer Protection in Electronic Commerce: records of contracts and withdrawal of subscription — 5 years; records of payment and supply of goods — 5 years; records of consumer complaints and dispute resolution — 3 years. Under the Protection of Communications Secrets Act: access logs — 3 months.
5. Provision to third parties
The Company processes personal information only within the purposes stated in Section 2, and provides it to third parties only where Articles 17 and 18 of PIPA permit — such as with the data subject’s consent or under a specific provision of law.
The Company never sells personal information and does not provide it to third parties for advertising purposes.
6. Entrustment of processing
The Company entrusts certain processing tasks as set out below. Each contract includes the safeguards required by Article 26 of PIPA.
- Apple Inc.
- App distribution, in-app purchase and subscription processing, app analytics.
- Google LLC
- App distribution, in-app purchase and subscription processing, app analytics.
- Vercel Inc.
- Hosting and traffic analytics for commonsourcelab.com.
- Generative-AI providers
- Processing of the content you submit, only in apps with an AI feature and only when you actively use it. The app gives notice before any transfer.
7. Overseas transfer
The distribution, hosting and analytics providers used by the Company operate servers outside Korea, so personal information may be transferred overseas. The following is disclosed under Article 28-8 of PIPA.
- Items transferred
- The enquiry data, automatically generated data and usage statistics described in Section 3.
- Country, timing and method
- The United States and other countries where each processor operates data centres. Transferred over the network at the time of use.
- Recipients
- Apple Inc., Google LLC, Vercel Inc., and the provider behind any AI feature you choose to use.
- Recipient purposes and retention
- App distribution, payment processing, hosting, analytics and AI feature delivery, for the periods set in each provider’s own privacy policy.
- How to object
- Write to contact@commonsourcelab.com to object to overseas transfer. Because distribution, payment and hosting are essential to the service, objecting may make the service unusable.
8. Rights of data subjects and legal representatives
You may at any time request access to, correction or deletion of, or suspension of processing of your personal information, and may withdraw consent. Where an automated decision is made, you may request an explanation of it or refuse to be subject to it.
Requests may be made in writing or by email to contact@commonsourcelab.com and will be acted on without delay. A legal representative or authorised agent may act on your behalf, in which case a power of attorney in the form prescribed by the Notification on Methods of Personal Information Processing (Form 11) must be submitted.
The Company verifies that a requester is the data subject or a legitimate representative and may ask for the minimum additional information needed to do so.
9. Destruction of personal information
When personal information becomes unnecessary — because the retention period has passed or the purpose has been achieved — the Company destroys it without delay.
Where information must be preserved under another statute despite the purpose having been achieved, it is moved to a separate database or storage location.
Electronic files are deleted by technical means that make recovery impossible; printed material is shredded or incinerated.
10. Security measures
- Administrative
- An internal management plan, a minimal number of staff handling personal information, and regular training.
- Technical
- Access-rights management for processing systems, access control systems, encryption in transit (HTTPS/TLS), and maintained security software.
- Physical
- Access control for systems where personal information is stored.
- By design
- Apps are designed to keep core data on the device so that collection is minimised at source.
11. Automatic collection devices
commonsourcelab.com does not use advertising cookies to identify visitors. Only the minimum information needed to measure site performance is processed, in aggregate form that does not identify individuals.
You can refuse cookies in your browser settings, although some functionality may become harder to use.
12. Children under 14
The Company does not offer services requiring consent to process the personal information of children under 14, and does not knowingly collect such information.
If the Company learns that information about a child under 14 has been collected without the consent of a legal representative, it destroys that information without delay.
13. Privacy officer and access requests
The Company has designated the following privacy officer to take overall responsibility for processing and to handle complaints and remedies.
- Chief Privacy Officer
- Position — Representative / Contact — contact@commonsourcelab.com
- Department receiving access requests
- CommonSource Support / contact@commonsourcelab.com
- Response time
- Requests for access, correction, deletion or suspension are handled within 10 days of receipt. Where this is not possible, the reason and expected date are notified.
14. Remedies for infringement
You may apply to the following bodies for dispute resolution or consultation. In addition, anyone whose rights or interests are harmed by a disposition or omission by the head of a public institution in respect of a request under Articles 35, 36 or 37 of PIPA may file an administrative appeal under the Administrative Appeals Act.
- Personal Information Dispute Mediation Committee
- +82-1833-6972 / www.kopico.go.kr
- Privacy Infringement Report Centre
- 118 (within Korea) / privacy.kisa.or.kr
- Supreme Prosecutors’ Office, Cyber Investigation Division
- 1301 (within Korea) / www.spo.go.kr
- National Police Agency, Cyber Bureau
- 182 (within Korea) / ecrm.police.go.kr
15. Changes to this notice
This notice applies from its effective date. Where content is added, removed or amended because of changes in law, policy or security technology, the change is announced on this website at least 7 days before it takes effect.
Changes that materially affect user rights are announced at least 30 days in advance.
This document reflects the disclosure items required by PIPA. Verify regularly that the SDKs, AI providers, analytics tools and retention periods actually in use match what is stated here, and have it reviewed by a qualified lawyer before it takes effect.