This Privacy Policy (hereafter to be referred to as the "Policy") explains the way of treatment of the information which is provided or collected in the websites called TrollyGo(e-commerce platform of STX corporation) on which this Policy is posted. Through this Policy, the Company regards Personal Information of the users as important and inform them of the purpose and method of Company's using the Personal Information provided by the users and the measures taken by the Company for protection of those Personal Information.
1. Personal Information collected and used & Purpose of Collection and Use of Personal Information
The company collects and uses Personal Information as follows:
classification |
Personal Information collected/used |
Purpose of Collection/use |
All memebers (in common) |
ID, Password, Email, Name of the Person in Charge, Phone Number
Country, Company Name(in English), Name of Representative, Business registration number, Corporation Registration Number, D-U-N-S® Number, Company Registered Address(Business Address), Year of Establishment, Number of Employees, Annual Sales, Business Type, Business Items (Products), Company Website, Domestic Ultimate Estimate Revenue, Global Ultimate Estimate Revenue, Company Summary
Copy of Certificate of Business Registration, Copy of company Introduction
History of Chat Room(Transaction) |
- User registration and management
- User identification, delivery of notices, confirmation of user’s intentions
- Support service of system improvement
- Conclusion and execution of agreement, settlement of accounts |
Automatically collected information: service usage records, usage suspension records, usage termination records, IP address, connection logs and cookies |
- Prevention of illegal/unauthorized usage, services such as shopping cart and recently viewed products |
Company Name, ID, email, telephone number, Identity verification information(CI,DI) |
- Prevention of fraudulent transactions |
Vendor (Supplier) |
Beneficiary Name, Bank Name, Account
Number, Bank Code, Copy of Bank Statement
Product Information |
- Conclusion and execution of agreement, settlement of accounts |
2. Period of Possession and Use of Personal Information
- 2.1 The Company shall maintain and use the user’s Personal Information for the period which was notified by the Company and agreed by the customer. Personal Information of users of the company is destroyed after achieving purpose of collection and use, expiration of period for saving, or withdrawal of user’s consent.
- 2.2 The company possesses Personal Information of users for a certain period in accordance with applicable laws and regulations. According to relevant laws and regulations, the information that must be retained is as follows:
Laws and Regulation |
Personal Information retained |
Period of retention |
Act on the consumer protection in electronic commerce |
Records regarding execution of the agreement or withdrawal of subscriptions, |
5years |
Act on the consumer protection in electronic commerce |
Records regarding payments and provision of goods, etc. |
5years |
Act on the consumer protection in electronic commerce |
Records regarding consumer complaints or dispute resolution: |
3years |
Credit information use and protection act |
Records regarding of collection, processing and use of credit information |
3years |
Act on the consumer protection in electronic commerce |
Records regarding marks and advertisements |
6months |
Electronic financial transactions act |
Records regarding electronic financial transactions |
5years |
Protection of communications secrets act |
Records regarding website browsing history |
3months |
3. Use of the collected Personal Information and provision of such information to a Third party
- 3.1 The company shall use the Personal Information of users within the scope notified in the sign up form, service Terms and Conditions and “Purpose of Collection and Use of Personal Information” under the Policy and shall neither use the same in excess of such scope, nor provide it for other persons, companies or institutions. However, requests made with consent of the customer and requests made in accordance to procedures set by the law shall be excepted. In such case, Personal Information may be used and provided with due care.
- 3.2 Consent to transfer of Personal Information to a Third party
Recipient of Personal Information |
Purpose of using Personal Information by the recipient |
Personal Information provided |
Possession and usage period of Personal Information by the recipient |
financial institution designated by the users |
to provide guarantee (e.g. B2B e-commerce guarantee, performance bond, guarantee insurance) and to evaluate credit |
Company Name, ID, Corporation Registration Number, Name of Representative, Guaranteed Amount, Trade Performance, Transaction Amount, Date of Transaction |
until account withdrawal |
3.3 Consent to Provision of Personal Information to overseas
Personal Information transferred |
The country to which the Personal Information transferred |
Transfer date |
Transfer method |
Name of the person responsible for the management of information |
Purpose of using Personal Information |
Possession and usage period of Personal Information |
Company Name, Name of Representative, Name of the Person in Charge |
Refer to separately provided ‘Consent to provision of Personal Information to overseas’ |
Completion of payment |
Online |
Refer to separately provided ‘Consent to provision of Personal Information to overseas’ |
Refer to separately provided ‘Consent to provision of Personal Information to overseas’ |
3months after purchase confirmation |
3.4 In the event any transaction is realized through services provided by the company, the necessary information relating to the transaction and delivery shall be provided to the third parties related to the transaction.
4. Entrustment of Personal Information handling
The company entrusts an outside company with handling of Personal Information for better business performance and convenience as follows:
Trustee |
Duties and purpose of entrustment |
Period of possession and use |
Bandeuthan company |
system development and maintenance |
Until account Withdrawal and End of Consignment Contract |
Nice payments(PG) |
payment approval and acquisition |
Until account Withdrawal and End of Consignment Contract |
TripleA |
payment approval and acquisition |
Until account Withdrawal and End of Consignment Contract |
5. Withdrawal of consent to collection, use and provision of Personal Information
- 5.1 A user may, at any time, withdraw his/her consent to collection, use and provision of Personal Information, which he/she consented to. A user may immediately withdraw consent to collection, use and provision of Personal Information by clicking "Membership Withdrawal" under “My Account” on the first page of the Homepage. If user contacts the supervisor in charge of management of Personal Information in writing, by telephone or by e-mail, etc., the company shall immediately take necessary measures for the withdrawal without delay.
- 5.2 In the event that a user is not utilizing TrollyGo, accounts including Personal Information will not be automatically deleted, a separate withdrawal process is mandatory for the deletion.
6. Procedure and Method of Destruction of Personal Information
- 6.1 In principle, the Company destructs the information immediately after the purposes of its collection and use have been achieved without delay: Provided that, if any information is to be retained as required by relevant laws and regulations, the Company retain it for the period as required by those laws and regulations before destruction and, in such event, the Personal Information which is stored and managed separately will never be used for other purposes.
- 6.2 Personal Information printed on paper shall be destroyed by shredding, incineration. Personal Information stored in an electronic file form shall be deleted by technical method which makes it impossible to restore or reproduce.
7. Technical and Administrative Measure for Protection of Personal Information
In order to prevent the loss, theft, leakage, alteration or damage of Personal Information of the users, the Company takes technical, managerial and physical measures for securing safety as follows:
items |
examples |
technical measures |
-Management of authority to access to Personal Information processing system
-Utilize security servers for transmitting encryption of Personal Information
-Take measures of encryption for confidential information
-Install and operate access control devices and equipment |
managerial measures |
-Establish and execute internal management plan -Provide education and training for staffs treating Personal Information |
physical measures |
-Establish and operate the procedure for access control for the facilities for storing Personal Information |
8. Matter’s concerning installation, operation and refusal of automatic Personal Information collection device
- 8.1 The Company may collect impersonal information through 'cookies'.
- 8.2 Cookies are very small text files to be sent to the browser of the users by the server used for operation of the websites of the Company and will be stored in hard-disks of the users' computer.
- A. These functions are used for evaluating, improving services and setting-up users' experiences so that much improved services can be provided by the Company to the users
- B. A user has an option to decide whether to install cookie or not.
A user may choose to accept all cookies, see a notice when cookies are installed, or refuse all cookie under "Tools > Internet Options > Privacy > Advanced" at the top of the web browser.
- C. When the user refuses to install cookie, there may be some inconvenience in use of or difficulty in provision of services.
9. User’s right to access and option
The user may access, revise and delete his/her Personal Information. However, the company shall have right to not to delete the Personal Information in case required by relevant laws and regulations.
- A. By clicking “My Account” and access, revise and delete
- B. By contacting person in charge of management of Personal Information below
10. Collection of opinions and complaints handling
- 10.1 The company makes the best efforts to answer users’ questions regarding protection of Personal Information promptly and sincerely. In addition, when a user seeks to contact person in charge of management of Personal Information, he/she may contact any of the following persons using the contact information or email address below :
- Department : DX department
- Email : info@trollygo.com
- ② The user may contact the Personal Information Infringement Reporting Center under the Korea Internet Security Agency or the Cyber Terror Response Center under the National Police Agency.
- (1) Personal Information Infringement Reporting Center
Telephone number: (No area code) 118
URL: http://privacy.kisa.or.kr
- (2) Personal Information Dispute Mediation Committee
Telephone number: (No area code) 1833-6972
URL: http://kopico.go.kr
- (3) Supreme Prosecutors' Office, Cybercrime Investigation Division
Telephone number: (No area code) 1301 URL: http://spo.go.kr
- (4) Cyber Terror Response Center under the National Police Agency
Telephone number: (No area code) 182
URL: http://cyberbureau.police.go.kr
11. Supervisor for management of Personal Information
- 11.1 Department in charge of management of Personal Information
- Department : DX department
- Email : ask@ trollygo.com
- 11.2 Supervisor for management of Personal Information :
- Name : Mun Ki Tak
- Department : External Cooperation Office
- Email : stx@trollygo.com
12. Duty to notify
This Policy was established on July 30, 2024. In the event of addition, deletion or amendments to its contents according to the changes in government policies or security technologies, any general changes shall be publicly announced at least seven (7) days before the changes take effect, and any important changes shall be publicly announced at least thirty (30) days before the changes take effect, under the “Notices” section of the Homepage.