BITCOIN CENTER SEOUL / LEGAL
Privacy policy
How Bitcoin Center Seoul processes information for orders, events, and inquiries.
Nonce Lab Inc. processes information to confirm Bitcoin Center Seoul orders and payments, fulfill purchases, confirm event attendance, send related notices, and respond to inquiries. Purchases currently use guest checkout. We process information needed for a contract and information requiring separate consent on the applicable legal basis.
1. Information and purposes
Orders require a name and email address. Shipping orders also require a telephone number, country, city, and street address. Postal codes are required for domestic shipping and destinations that require them. Region and address details are optional. Pickup does not require a shipping address; a telephone number and order notes are optional.
We use items, quantities, amounts, order and payment references and status, fulfillment records, and event ticket verification and check-in records to fulfill orders, confirm payments, support customers, and handle disputes. Keep order links and confirmation codes private.
Collaboration proposals require a name, email, proposal type, and message; an organization is optional. We use these details to review and respond. Email inquiries contain the sender's address and any name, contact details, and message they provide. Do not send resident registration numbers, wallet recovery phrases, or private keys.
1-1. Collection methods and service protection
We collect information you enter in checkout or collaboration forms or provide through email and inquiries. Payment status comes from payment-service responses and verification. Fulfillment and check-in records arise when those tasks are performed.
To prevent excessive requests and misuse, we process connection identifiers such as the request's IP address. The request-limiting store holds a hashed identifier, request count, and expiry time. Expired entries are deleted during cleanup. Hashing does not remove all privacy obligations; our general retention and deletion principles apply.
1-2. Legal bases for processing
Names, email addresses, required telephone and shipping details, and order, payment, and fulfillment records needed for purchases, delivery, pickup, events, and related inquiries are processed to perform a contract or take steps requested before a contract under Article 15(1)(4) of Korea's Personal Information Protection Act. We cannot fulfill an order without its required information. Optional details such as order notes are not required to use the basic service.
We use a collaboration proposal's name, email, type, message, and any supplied organization to review and respond based on the proposer's separate consent under Article 15(1)(1). Without consent, the online proposal form cannot be used. You can request withdrawal of consent through the privacy contact channel.
Statutory transaction-record retention is based on Article 15(1)(2), Article 6 of Korea's Act on the Consumer Protection in Electronic Commerce, Etc., and Article 6 of its Enforcement Decree. Processing needed for contracts or statutory retention is not bundled with marketing consent.
2. Payments, delivery, and external services
For Zaprite payments, we transmit your name, email address, amount, currency, and order and payment references to request and verify payment and send a receipt. Lightning-address payments involve amounts, invoices, and technical information needed to verify payment.
For shipping orders, we send the recipient’s name, telephone number, address, and necessary order and item details to CJ Logistics (CJ대한통운) for delivery, return collection, and delivery support. The domestic shipping address form loads the Kakao address-search script to prepare the optional lookup; this can share connection information with the provider. When you run a search, the external address service may process your search terms and connection information. The address you select is used to complete your order.
We send and receive order and event notices and inquiry responses through Gmail through an organizational Google Workspace account. This involves email addresses, names, and the order or inquiry content needed for the task. Operational alerts using webhooks are planned after a receiving service is selected. Before transmitting personal information externally, we will disclose the recipient, processing tasks and information, and any applicable overseas transfers, and complete required legal procedures. Displaying the location map connects to Google Maps and may transmit connection information, including your IP address, to its provider. Playing an external video connects to YouTube, whose provider may process connection and device information.
2-1. Hosting, storage, and service providers
The website server, database, and backups use Amazon Web Services (AWS) in the Seoul Region (ap-northeast-2), Republic of Korea. Information needed to operate the website and store and recover order and inquiry data is processed there.
We use Gmail through an organizational Google Workspace account for email and CJ Logistics for product delivery and return collection. We process only the information needed for each task and distinguish our general retention and deletion rules from statutory retention duties.
Google Workspace’s published data processing terms permit processing in countries where Google or its subprocessors have facilities, subject to applicable data-location commitments. Email information may be processed outside the Republic of Korea depending on where Google and its subprocessors operate; our AWS Seoul Region setting does not guarantee that Google Workspace email stays in Korea. The retention and deletion rules below also apply to email content and mailboxes. After deletion makes data unrecoverable by the Company, copies in Google’s systems may require further deletion time. Google’s published data processing terms allow up to 180 days to comply with a deletion instruction, subject to statutory storage exceptions. This does not permit the Company to keep using information due for deletion or extend its ordinary retention period.
3. Retention
General personal information is retained for up to one year from collection. Inquiries, collaboration proposals, contact details for unpaid orders, and operational email content are kept only while needed for their purpose. We erase them without delay when that purpose is fulfilled or a lawful erasure or consent-withdrawal request applies, even before one year has passed. For an ongoing contract, refund, or dispute, we retain only information necessary under a valid legal basis.
Statutory records are retained separately: five years for contracts and withdrawals and for payment and supply, three years for consumer complaints and disputes, and six months for advertisements. We retain only the minimum information needed for those records, do not use it for general operations or promotion, and erase it without delay when the legal period ends. Expiry of an order link does not erase transaction records.
Minimum transaction information constituting tax books or supporting records is retained separately under Article 85-3 of Korea's Framework Act on National Taxes and other applicable rules. The usual period is five years after the statutory filing deadline for the relevant tax period; separate periods may apply, such as seven years for statutory offshore transactions. These periods and starting dates differ from electronic-commerce retention and do not apply indiscriminately to all customer contact or delivery information. Statutory records are separated from general operational information and deleted when their retention period ends.
We review retained information and deletion compliance every year. This review does not delay deletion until the annual review date. Information whose purpose or retention period has ended is deleted so it cannot be recovered or reproduced, or paper records are shredded. Copies in mailboxes, external providers, and backups are also subject to this policy's deletion requirements. Restoring a backup does not permit information due for deletion to be used again for general operations.
4. Browser storage
Local storage holds cart item references and quantities. A theme cookie lasts one year, and local storage also remembers the theme.
Access-token cookies verify permission to view guest quotes and orders. Quote cookies expire after one hour and order cookies after 30 days. Cookie expiry differs from server-side transaction-record retention. You can delete or block cookies and site data in your browser settings, which may affect saved preferences or access to quotes and orders.
5. Protection and your rights
We encrypt key stored order contact and address information and email content, and restrict access through order credentials and administrator authentication. You or an authorized representative may request access, correction, erasure, restriction of processing, and withdrawal of consent. We check only the information needed to establish your identity and handle the request under applicable law, explaining the outcome or any limitation. Legally required records may not be erased immediately.
5-1. Children and legal representatives
Where processing a child under 14's information requires consent, the child's legal representative must give consent and that consent must be verified. A legal representative should contact the Center before ordering or registering for an event for a child. Where possible, use the representative's contact details and do not provide extra information, such as the child's birth date or school, that the order does not need.
A child's legal representative may request access, correction, erasure, or suspension of processing of the child's information. If we identify child information collected without required representative consent, we check the legal basis and take necessary measures, including stopping processing and erasing without delay where there is no lawful basis.
6. Privacy officer and contact
Our privacy officer is Deokyoon Ko (고덕윤), Chief Executive Officer. Send privacy requests or concerns to hello@noncelab.com or +82 2-702-1718. Korea's privacy infringement hotline is 118; the Personal Information Dispute Mediation Committee can be reached at 1833-6972.
7. Changes
If our purposes, information collected, or services change, we will update this policy and follow any notification or consent procedure required by law.

