Privacy Policy

[코어16] (the "Company") complies with the Personal Information Protection Act and other applicable laws and regulations in order to protect the freedoms and rights of data subjects, and lawfully processes and securely manages personal information. Pursuant to Article 30 of the Personal Information Protection Act, the Company establishes and publishes this Privacy Policy to inform data subjects of the procedures and standards governing the processing and protection of personal information and to ensure that related grievances are handled promptly and effectively.

The Company collects and uses personal information only to the minimum extent necessary to provide the Service.

Effective date: Aug. 7, 2026


Table of Contents

  1. Purposes of Processing Personal Information
  2. Categories of Personal Information Processed
  3. Personal Information of Children Under 14
  4. Processing and Retention Period
  5. Destruction Procedures and Methods
  6. Provision of Personal Information to Third Parties
  7. Outsourcing of Personal Information Processing
  8. Cross-Border Transfers of Personal Information
  9. Security Measures
  10. Sensitive and Pseudonymized Information
  11. Cookies and Similar Technologies
  12. Behavioral Information
  13. Automated Decision-Making
  14. Rights and Obligations of Data Subjects and Legal Representatives
  15. Privacy Officer
  16. Remedies for Infringement of Rights
  17. Changes to This Privacy Policy

1. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. Personal information being processed will not be used for any purpose other than those stated below. If a purpose of use changes, the Company will take necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act.

  1. Membership registration and management: Confirming a user's intent to register; identifying and authenticating users in connection with membership services; maintaining and managing membership status; preventing unauthorized use of the Service; providing notices and notifications; and handling grievances
  2. Provision of the Service: Providing content and services such as supply-chain network lookup, disclosure-event exploration, visualization of relationships among stocks, and beneficiary-stock analysis; and saving personalized settings such as watchlists and filters
  3. Provision of paid services: Processing and settling payments, billing recurring payments, processing refunds and cancellations, and managing transaction history
  4. Service improvement and reliability: Analyzing usage records, measuring frequency of access, conducting security monitoring, and improving service quality
  5. Provision of promotional information: Providing consenting members with information about new features, investment-related content, events, benefits, and promotions

2. Categories of Personal Information Processed

The Company processes the following categories of personal information. The personal information processed is limited to the minimum extent necessary to provide the Service.

(1) Membership registration and management (entered directly by the user)

  • Required item: Email address
  • Optional items: None.

(2) Registration through social login (if applicable)

  • When using a social login service such as Google or Naver: Email address, profile name, and unique identifier provided by the applicable provider

(3) Use of paid services (if applicable)

  • Transaction identifier, payment approval and failure history, subscription status, card issuer and approval number for credit-card payments, and bank name and a portion of the account number for bank transfers
  • The Company does not store original payment-method information, such as card numbers; such information is processed by the payment service provider.

(4) Information automatically generated and collected while using the Service

  • IP address, cookies, service usage records, access logs, access date and time, browser and device information, lookup and search history, app and web push tokens, and device and browser information when push notifications are used

(5) Member settings (optional)

  • Whether the member has consented to receive promotional information (marketing_consent) and the date and time on which that consent was changed

3. Personal Information of Children Under 14

The Company does not provide the Service to children under 14 years of age and does not collect personal information from children under 14. If the Company becomes aware that it has collected personal information from a child under 14, it will take necessary measures, including destroying the information without delay.


4. Processing and Retention Period

The Company processes and retains personal information within the retention and use period prescribed by law or agreed to by the data subject. Personal information is destroyed without delay once the purpose of processing has been achieved.

CategoryRetention periodBasis
Member account and profile informationUntil withdrawal from membershipConsent to the collection and use of personal information
Use of email and push information to send promotional informationUntil withdrawal of consent or withdrawal from membershipConsent to receive promotional information
Status of consent to receive promotional information and date and time of changesUntil withdrawal from membershipVerification of member settings and consent or withdrawal history
Records concerning contracts or the exercise of statutory cancellation rights and similar matters5 yearsAct on the Consumer Protection in Electronic Commerce, Etc.
Records concerning payment and supply of goods or services5 yearsAct on the Consumer Protection in Electronic Commerce, Etc.
Records concerning consumer complaints or dispute resolution3 yearsAct on the Consumer Protection in Electronic Commerce, Etc.
Records concerning labeling and advertising6 monthsAct on the Consumer Protection in Electronic Commerce, Etc.
Communications confirmation data, including access logs3 monthsProtection of Communications Secrets Act

If an investigation or inquiry relating to a violation of applicable law is pending, the relevant information will be retained until the investigation or inquiry is concluded.


5. Destruction Procedures and Methods

  1. When personal information is no longer necessary because its retention period has expired or the purpose of processing has been achieved, the Company destroys the personal information without delay.
  2. If personal information must continue to be retained under another law even after its retention period has expired or the purpose of processing has been achieved, the Company transfers the personal information to a separate database or stores it in a separate location.
  3. The destruction procedures and methods are as follows.
  • Destruction procedure: Personal information for which a ground for destruction has arisen is selected and destroyed with the approval of the Privacy Officer.
  • Destruction method: Information in electronic-file form is permanently deleted using technical means that prevent restoration of the records, and information recorded on paper is destroyed by shredding or incineration.

6. Provision of Personal Information to Third Parties

The Company processes a data subject's personal information only within the purposes set out in Section 1 and provides personal information to a third party only in circumstances permitted under Articles 17 and 18 of the Personal Information Protection Act, including where the data subject has consented or where specifically authorized by law.

The Company does not currently provide data subjects' personal information to third parties. If such provision becomes necessary, the Company will identify the recipient, purpose of provision, categories of information provided, and retention and use period and obtain prior consent.


7. Outsourcing of Personal Information Processing

  1. To facilitate the processing of personal information, the Company outsources personal-information processing as follows.
ProcessorPurposeProcessing activities
VercelHosting and infrastructure operationsServer operations, deployment, and data storage
SupabaseAuthentication and database operationsAccount identifiers, email addresses, settings, activity data, and similar information
TosspaymentsPayment service providerPayment and recurring-payment processing
ResendEmail deliveryDelivery of authentication, notification, and informational emails
Google AnalyticsVisitor statistics and service-usage analysisService-usage statistics and analysis
  1. When entering into an outsourcing agreement, the Company specifies in a written instrument, including the agreement, matters concerning the prohibition against processing personal information for purposes other than performing the outsourced work; technical and administrative safeguards; restrictions on sub-outsourcing; management and supervision of the processor; and liability for damages, in accordance with Article 26 of the Personal Information Protection Act. The Company also supervises whether the processor handles personal information securely.
  1. Any change to the outsourced activities or a processor will be disclosed through this Privacy Policy.

8. Cross-Border Transfers of Personal Information

To provide the Service and operate its infrastructure effectively, the Company stores and outsources the processing of personal information outside the Republic of Korea as follows.

Processor (country)Purpose of transferInformation transferredTiming and method of transferRetention and use period
Vercel (United States)Infrastructure operations and service deploymentServer access logs and similar informationTransmitted over the network when the Service is usedUntil withdrawal from membership or termination of the Service
Supabase (United States)Member authentication and database operationsAccount identifiers, email addresses, settings, and similar informationTransmitted upon membership registration and use of the ServiceUntil withdrawal from membership
Resend (United States)Provision of email-delivery servicesEmail address and recipient nameTransmitted when an email is sentDestroyed without delay after the purpose is achieved
Google (United States)Service statistics and analysis (Google Analytics)Service-usage records and device informationTransmitted through cookies when the Service is usedIn accordance with the Google Analytics policy

9. Security Measures

The Company takes the following measures to secure personal information.

  1. Administrative measures: Establishing and implementing an internal management plan and conducting regular employee training
  2. Technical measures: Managing access rights to personal-information processing systems; installing access-control systems; encrypting personal information; retaining and reviewing access logs; installing, operating, and updating security programs; inspecting and remediating vulnerabilities in personal-information processing systems; and encrypting data in transit using HTTPS and similar measures
  3. Physical measures: Controlling access to computer rooms, data-storage rooms, and similar facilities, if applicable

10. Sensitive and Pseudonymized Information

The Company does not process sensitive information concerning matters such as ideology or beliefs, health, or sex life, nor does it process unique identification information. The Company also does not currently process pseudonymized information.


11. Cookies and Similar Technologies

  1. The Company uses cookies, which store and periodically retrieve usage information, in order to provide data subjects with individualized services and convenience.
  2. A cookie is a small amount of information sent to a data subject's browser by the server (HTTP) used to operate a website. It is stored on the data subject's device and automatically transmitted to the server when the website is accessed.
  3. Purposes of using cookies: Maintaining login sessions, providing security, saving user settings, and providing an optimized service by analyzing patterns of service use
  4. How to reject cookies: A data subject may reject the storage of cookies through the browser's option settings.
  • Chrome: Settings > Privacy and security > Cookies and other site data
  • Edge: Settings > Cookies and site permissions
  • Safari: Preferences > Privacy
  1. Rejecting the storage of cookies may make it difficult to use certain personalized services, including maintaining a logged-in session.

12. Behavioral Information

If the Company collects behavioral information, such as a data subject's patterns of service use, through a statistical-analysis tool such as Google Analytics, the following applies to the collection, use, and rejection of such information.

  • Behavioral information collected: Service-usage records, including pages visited, time spent using the Service, and click events
  • Method of collection: Collected automatically when a user visits and uses the Service
  • How to opt out: A user may reject the collection of behavioral information by using the blocking method described by the applicable analytics-tool provider, such as installing the Google Analytics Opt-out Browser Add-on, or by blocking cookies in the browser settings.

13. Automated Decision-Making

The Company does not make automated decisions under Article 37-2 of the Personal Information Protection Act, meaning decisions made entirely by an automated system that have legal or similarly significant effects on a data subject.


14. Rights and Obligations of Data Subjects and Legal Representatives

  1. A data subject may exercise any of the following rights against the Company at any time.
  • Request access to personal information
  • Request correction of errors or other inaccuracies
  • Request deletion
  • Request suspension of processing
  1. These rights may be exercised through the settings screen within the Service, in writing, or by email, and the Company will take action without delay.
  2. If a data subject requests correction or deletion of personal information due to an error or other reason, the Company will not use or provide the personal information until the correction or deletion is completed.
  3. Rights may be exercised through a representative, such as the data subject's legal representative or a person authorized by the data subject. In that case, a power of attorney in the form prescribed in Appendix Form No. 11 to the Enforcement Rule of the Personal Information Protection Act must be submitted.
  4. A data subject must not infringe upon their own or another person's personal information or privacy processed by the Company in violation of applicable laws and regulations.
  5. Consent to receive promotional information may be granted or withdrawn at any time in the My Page settings.

15. Privacy Officer

The Company has designated the following Privacy Officer to oversee and take responsibility for personal-information processing and to handle complaints and provide remedies for data subjects in connection with personal-information processing.

  • Privacy Officer
  • Name: 양해정
  • Title: CIO
  • Contact: 070-4225-0201 / hjyang@coresixteen.com

A data subject may contact the Privacy Officer regarding any privacy-related inquiry, complaint, or request for a remedy arising from use of the Service. The Company will respond and take action without delay.


16. Remedies for Infringement of Rights

A data subject may contact the following institutions to seek remedies or counseling regarding an infringement of personal information. These institutions are independent of the Company and may be contacted if the data subject is dissatisfied with the outcome of the Company's own handling of the matter or requires further assistance.

  • Personal Information Infringement Report Center (operated by the Korea Internet & Security Agency): 118 without an area code / privacy.kisa.or.kr
  • Personal Information Dispute Mediation Committee: 1833-6972 without an area code / www.kopico.go.kr
  • Cyber Investigation Division, Supreme Prosecutors' Office: 1301 without an area code / www.spo.go.kr
  • Cyber Investigation Bureau, National Office of Investigation, Korean National Police Agency: 182 without an area code / ecrm.police.go.kr

17. Changes to This Privacy Policy

  1. This Privacy Policy applies from its effective date, Aug. 7, 2026.
  2. If this Privacy Policy is amended, the timing of the amendment and its effective date and the amended provisions will remain publicly available, and the prior versions of the Privacy Policy and the period during which each version applied will be made available together.
  3. If an amendment materially affects the rights of data subjects, including a change to the categories of personal information processed or the purposes of processing, the Company will separately notify data subjects in a manner that permits comparison of the provisions before and after the amendment, either before the amendment or immediately after it is made.

[Privacy Policy Version History]

  • Effective date of current version: Aug. 7, 2026
  • Effective date of previous version: June 12, 2026
ChainScope Privacy Policy