Privacy policy
This is an English translation for convenience. The Korean version is the official text and prevails in case of any difference. Read the Korean version.
TierStay (the “Service”) has established this privacy policy, in accordance with the Personal Information Protection Act (PIPA) of Korea, to protect data subjects’ personal information and to handle related complaints smoothly. No personal information is collected for viewing the map, lists, promotions or tier guide without signing in.
1. Purposes of processing personal information
- Identifying members and keeping them signed in (Google account sign-in)
- Receiving error reports and improvement requests, and informing members in ‘My reports’ of the outcome of checks against official sources
- Preventing misuse, such as repeated submission of the same content or excessive submissions
- Sending advertising information such as the newsletter (only where separate optional consent has been given)
Personal information is not used beyond the purposes above. If a purpose changes, we will notify you in advance and obtain any required consent.
2. Personal information items processed
| Category | Items | How collected |
|---|---|---|
| Required Member | Google account identifier, email address, whether the email address is verified, name, profile picture URL | Received from Google when you sign in with Google (scopes: openid, email, profile) |
| Required Usage records | Date, time and content of consent; sign-in session (cookie); information on the browser that created the session (User-Agent); content of reports sent and the address of the screen they were sent from | Generated automatically while using the Service, or entered directly |
| Optional newsletter | Whether and when consent to receive was given; sending records | When optional consent is given |
We do not process unique identification information such as resident registration numbers, or sensitive information. The Service is not directed at children under 14 and does not knowingly collect their personal information. Usage statistics that cannot identify individuals are described in section 9.
3. Processing and retention periods
- Member information: until you leave. When you leave, it is destroyed without delay.
- Sign-in session: 30 days from issue, or until you sign out or leave.
- Consent to receive the newsletter: until withdrawn or until you leave. We will remind you of your consent every 2 years.
- Reports sent: after you leave, the link to your account is removed so that the sender cannot be identified, and the report is kept as a record of data checks.
- Where laws require retention, information is kept for the period so required.
4. Procedure and method of destruction
Personal information whose retention period has ended or whose processing purpose has been achieved is destroyed without delay. Electronic files are deleted by a method that makes recovery impossible, and when you leave, the email address, name, profile picture and Google account identifier values are deleted. No personal information is kept in paper documents.
5. Provision of personal information to third parties
The Service does not provide personal information to third parties, except where laws make special provision.
6. Outsourcing of processing and overseas transfer
To operate the Service, we outsource the processing of personal information to the companies below. Because their servers are located overseas, personal information is transferred abroad.
| Recipient (contact) | Outsourced task and purpose | Items transferred | Destination country | Retention and use period |
|---|---|---|---|---|
| Cloudflare, Inc. (dpo@cloudflare.com) | Operating the website and database (hosting), visit statistics | All member information, usage records and reports listed in section 2 | United States and other regions where Cloudflare operates | Until you leave or the outsourcing contract ends |
| Plus Five Five, Inc. (Resend) (support@resend.com) | Sending newsletter emails | Email address, name | United States (sending servers in Japan) | The provider’s record retention period after sending, or until the outsourcing contract ends |
Timing and method of transfer: transmitted over an encrypted network (HTTPS) when you use the Service or when the newsletter is sent.
How to refuse and the effect of refusal: if you do not want your information transferred abroad, you can choose not to join or to leave, and refuse to receive the newsletter. If you refuse, you cannot use features that require sign-in (error reports, My reports) or the newsletter, but you can still view the map, lists, promotions and tier guide.
Google sign-in: when you sign in, we receive the account information in section 2 above from Google LLC. We do not send personal information to Google or outsource processing to it. Google’s processing is governed by Google’s privacy policy.
If an outsourced task or recipient changes, we will notify you without delay through this privacy policy.
7. Rights and obligations of data subjects and how to exercise them
- You may at any time request access to, correction, deletion or suspension of processing of your personal information, and withdraw your consent.
- Directly from the account menu: view ‘My reports’, turn the newsletter on or off, and leave (deletion).
- For any other request, contact us at the address in section 11; we will act within 10 days and inform you of the result. You may also make a request through a legal representative or a person you have authorised; in that case, please also send material that confirms the authorisation.
- You can withdraw from the newsletter immediately, without signing in, using the unsubscribe link in the email.
- Requests may be restricted in cases prescribed by law, such as where other laws require retention or where there is a risk of infringing another person’s rights; we will tell you the reason.
8. Measures to ensure the security of personal information
- Encryption in transit (HTTPS); sign-in session values are stored only as hashes
- Origin checks on requests that change state (CSRF protection); restricted access tokens for administrative functions
- Two-factor authentication on administrative accounts; access rights limited to the operator
- Email addresses are not passed to the automated runner that processes reports
9. Installation, operation and refusal of automatic collection devices (cookies), and usage statistics
We use one essential cookie (ts_session, 30 days) to keep you signed in. We do not use advertising or analytics cookies. You can block cookies in your browser settings, but you will then be unable to sign in.
Visits are counted with Cloudflare Web Analytics, which does not use cookies. It collects the address of the page visited, the previous page (referrer), browser and device type, country and page load speed, and we view these only as visit counts; it does not distinguish or track visitors.
In addition, to improve the Service, we store usage statistics (menus, cities and hotels viewed; chains, tabs and external links clicked; search terms entered; previous site address; device type; country) only as daily totals. Individual visit records, IP addresses, cookies and account information are not stored with them, and the totals are deleted after 400 days. To count a visit only once per browser tab, we place a single marker in storage that is cleared when the tab is closed (sessionStorage). Please do not enter personal information in the search box.
We do not use this information for personalised advertising, and we do not make automated decisions that affect users.
10. Sending advertising information
The newsletter is sent only where optional consent has been given, is marked “(광고)” [“(Advertisement)”] in the subject line, and is not sent between 9 p.m. and 8 a.m. the next day. When we process consent to receive, refusal or withdrawal, we will inform you of the result.
11. Chief privacy officer
Position: TierStay operator · Contact: help@tierstay.com
Please send enquiries, complaints and requests for remedies relating to the processing of personal information to the contact above. We will respond and deal with them without delay.
12. Remedies for infringement of rights
- Personal Information Infringement Report Center (privacy.kisa.or.kr, 118 without area code)
- Personal Information Dispute Mediation Committee (www.kopico.go.kr, 1833-6972)
- Supreme Prosecutors’ Office (www.spo.go.kr, 1301), Korean National Police Agency (ecrm.police.go.kr, 182)
13. Changes to this privacy policy
If this policy changes, we will announce it on the site 7 days before the change takes effect (30 days before for changes that are significant to users’ rights).
- Effective 2026-09-27 (first version)