Privacy Policy
Inchanters Co., Ltd. Privacy Policy
Inchanters Co., Ltd. (hereinafter the "Company") regards the protection of users' personal information as a matter of the highest importance. The Company makes every effort to protect the personal information provided to it when users access its wired and wireless internet services, PC and mobile game services, and online and offline game services (hereinafter the "Services" — meaning all available Services provided by the Company, regardless of device type or distribution platform). The Company complies with the personal information protection provisions of applicable laws, including the Personal Information Protection Act and the Act on Promotion of Information and Communications Network Utilization and Information Protection of the Republic of Korea.
This Policy has been prepared to disclose all matters relating to the Company's handling of personal information in the operation of its Services, including the categories of personal information collected, methods of collection, sharing, retention, destruction, protection, and operation. This Policy may be amended due to changes in laws, regulations, or public notices, or in accordance with the Company's terms of service and internal policies. In the event of an amendment, the Company will notify users through its official community channels, in-game notices, the Steam Community Hub, and similar means.
Users may decline consent to any of the matters set out below concerning the collection, use, provision, or entrustment of personal information. Please note, however, that declining consent may restrict the use of all or part of the Services.
Article 1 (Categories of Personal Information Collected and Methods of Collection)
The Company collects personal information through the categories and methods set out below for purposes including the smooth operation of its games, customer support, and service quality improvement. The categories collected vary depending on the platform the user uses.
1. Users of PC Game Services (Steam and other PC distribution platforms)
● Categories of personal information collected and used
-
Common: Game version information; system information (operating system type and version, CPU / GPU / memory specifications, screen resolution, language and country settings); service usage information (play records, in-game progress data, access logs, access IP address)
-
For error diagnosis: Crash logs, game state information at the time of the error, system environment information
-
Upon platform integration: Steam unique identifier (SteamID), Steam public profile information (nickname, country information)
-
Upon customer inquiry: Email address, contents of the inquiry, and any information voluntarily provided by the user for the purpose of verifying the inquiry
● Regarding analytics tools
The Company does not use any separate user behavior analytics tools in connection with its PC Game Services. The Company does not collect users' nicknames, chat messages, free-form text input, addresses, passwords, or marketing profiling information.
● Regarding payment information
Payments for PC Game Services are processed independently by the distribution platform operator (such as Valve Corporation). The Company does not directly collect or store users' payment method information, including credit card numbers and account details. The Company receives only sales and refund statistics from the platform operator in a form that does not permit identification of individuals.
● Methods of collection
-
Automatic collection through the PC game client
-
Collection through the integration features of the distribution platform (such as Steam)
-
One-to-one customer inquiries via email, community hub, and similar channels
-
Separate consent procedures conducted for promotions and events
2. Users of Mobile Game Services
● Categories of personal information collected and used
-
Common: Game version information; device information (model name, OS information and version, language and country settings, advertising identifier); payment information (payment history, payment reference number); service usage information (usage records, access logs, IP address)
-
When using a Google account: Google ID, public profile (name, age, gender information), nickname
-
When participating in promotions and events (in such cases the Company notifies users of the fact and obtains their consent): Mobile phone number, address, email address, age verification and identity verification information
-
Personal information provided by Google: The Company uses Google Analytics and Google Ads solely in connection with its Mobile Game Services, and may collect and use personal information provided by Google.
● Methods of collection
-
Collection through mobile devices, one-to-one support inquiries, and other direct user input
-
Separate consent procedures conducted for promotions and events
-
Provision by Google Analytics and Google Ads
Article 2 (Purposes of Use of Personal Information)
The Company distinguishes between items requiring the consent of the data subject and items not requiring consent. The purposes of use for each category are as follows.
● Items requiring user consent
-
Mobile phone number, email address: Identity verification, customer support and provision of customer service, delivery of notices, provision of paid payment services
-
Device information: Push notifications regarding new services and events, identification and management of abusive users, service quality improvement and processing of statistical information
● Items not requiring user consent
-
Service usage information: Service quality improvement, performance of contractual obligations and dispute resolution, processing of statistical information
-
System information and crash logs: Analysis of error causes, bug fixes, game optimization and compatibility improvement
-
Payment information: Customer support services relating to payment for paid services
● Regarding platform account integration
Where a user accesses the Company's Services using an account provided by another company, such as Steam or a social login, the Company receives only the data necessary to identify the user and the personal information for which the user has given consent to that company, and processes such information solely within the scope of the consent given.
Personal information received from a third party is retained until the user requests its deletion or withdraws from membership. IDs and email addresses are retained for one month following that date.
Article 3 (Transfer of Personal Information Overseas)
As the Company provides its PC Game Services through overseas distribution platforms such as Steam, users' personal information may be transferred overseas in the course of providing the Services.
- Recipient : Valve Corporation
- Country : United States
- Items transferred : Steam unique identifier, public profile information, purchase and refund records, game data stored in Steam Cloud
- Purpose of transfer : Game distribution, payment processing, cloud storage and other platform services
- Retention period : In accordance with Valve's privacy policy
For information regarding Valve Corporation's handling of personal information, please refer to the Steam Privacy Policy (https://store.steampowered.com/privacy_agreement/).
Users may refuse the overseas transfer of their personal information; however, doing so may restrict their use of the Services through the relevant platform.
Article 4 (Retention and Use Period of Personal Information)
The Company retains and uses users' personal information only for the period during which the user uses the Services. Where a user withdraws from the Services or withdraws consent to the collection and use of personal information, the Company destroys that personal information without delay.
However, in order to restore service usage records and protect victims in the event of damage to users caused by identity theft or similar misuse, the Company may temporarily retain such information for up to fourteen (14) days from the date of withdrawal or withdrawal of consent, after which it is permanently deleted by a method that renders it irrecoverable.
Notwithstanding the foregoing, where retention is required under applicable laws, the Company retains users' personal information for the period prescribed by such laws. In such cases, the retained personal information is used solely for the purpose of retention. The retention periods are as follows.
-
Personal information relating to use of the Services (service usage records, access logs, IP address information)
-
Legal basis: Protection of Communications Secrets Act / Retention period: 3 months
-
-
Records relating to labeling and advertising
-
Legal basis: Act on Consumer Protection in Electronic Commerce / Retention period: 6 months
-
-
Records relating to contracts and withdrawal
-
Legal basis: Act on Consumer Protection in Electronic Commerce / Retention period: 5 years
-
-
Records relating to payment and supply of goods
-
Legal basis: Act on Consumer Protection in Electronic Commerce / Retention period: 5 years
-
-
Records relating to consumer complaints or dispute resolution
-
Legal basis: Act on Consumer Protection in Electronic Commerce / Retention period: 3 years
-
-
Records relating to identity verification
-
Legal basis: Act on Promotion of Information and Communications Network Utilization and Information Protection / Retention period: 6 months
-
Article 5 (Sharing and Provision of Personal Information)
The Company uses users' personal information solely within the purposes disclosed at the time of collection and, as a general principle, does not disclose users' personal information externally without their prior consent. The following are exceptions.
-
Where the user has consented to such disclosure in advance
-
Where the user has violated the posted terms of service or other service terms or policies
-
Where there are sufficient grounds to determine that personal information must be disclosed in order to take legal action against a user who has caused mental or material harm to another person through use of the Services
-
Where the minimum necessary information is provided to a distribution platform operator for the purposes of game distribution and payment processing
-
Where disclosure is otherwise required by law in the Company's good-faith judgment
-
e.g. where the provision of data is compelled under applicable law, or where a lawful request is made by a court, investigative authority, or other administrative agency
-
Article 6 (Procedures and Methods for Destruction of Personal Information)
Users' personal information is destroyed without delay once the purposes of its collection and use have been achieved. The procedures and methods of destruction are governed by the following standards.
● Order of destruction
-
Information entered by a user for the purpose of using the Services is, after the purposes of collection and use have been achieved, stored for the retention period required by internal policy and other applicable laws relating to information protection, and is then destroyed.
● Methods of destruction
-
Personal information printed on paper is destroyed by shredding or incineration.
-
Personal information stored in electronic file form is deleted using technical methods that render the records irrecoverable.
Article 7 (Rights of Users and Legal Representatives, and How to Exercise Them)
Users and their legal representatives may at any time request access to, correction of, deletion of, or suspension of the processing of their personal information, and may withdraw their consent to its provision.
● For Mobile Game Services
Withdrawal is available by selecting "Withdraw Membership" within the Service and completing the identity verification process.
● For PC Game Services (Steam and similar platforms)
The Company does not operate a separate membership registration process for its PC Game Services. Users who wish to have their collected information deleted may submit a request by email to the Personal Information Protection Officer listed in Article 11 below, and the Company will take action without delay following identity verification. Please note that deletion of the Steam account itself and of information held by Valve Corporation must be requested directly from Valve Corporation.
Where a user has requested the correction or deletion of personal information, the Company does not use or provide that personal information until the request has been completed. Where personal information predating the requested change has already been provided to a third party, the Company notifies that third party without delay so that the request is reflected.
The Company processes personal information deleted at the request of a user or their legal representative in accordance with Article 4 (Retention and Use Period of Personal Information), and ensures that it cannot be accessed or used for any other purpose.
Article 8 (Protection of Children's Personal Information)
Where the Company collects the personal information of a child under the age of fourteen (14), it obtains the consent of the child's legal representative. Where the Company becomes aware that a user is a child under the age of fourteen (14), it destroys the relevant information without delay. Legal representatives may request access to, correction of, deletion of, and suspension of the processing of a child's personal information.
Article 9 (Installation and Operation of Automatic Personal Information Collection Devices, and Refusal Thereof)
In order to provide users with a personalized service, the Company uses functions that create and store local data recording and retrieving user information. Such local data consists of very small text files stored on the user's device. When the Service is used, the contents of the stored local data are read in order to verify user information and provide a personalized service.
For PC Game Services, game settings and progress data are stored on the user's PC and are also stored on servers operated by Valve Corporation through the Steam Cloud feature. Steam Cloud synchronization may be disabled by the user directly in the Steam client settings; disabling it may restrict the synchronization of progress across devices.
Users have the right to choose whether local data is installed and used. Users may configure whether local data is permitted within the Services provided, and may also delete it. Please note that deleting or arbitrarily altering stored local data may restrict the user's use of the Services.
Article 10 (Technical and Administrative Measures for the Protection of Personal Information)
In processing users' personal information, the Company implements the following technical and administrative measures to prevent the loss, theft, leakage, alteration, or damage of personal information.
The Company makes every effort to prevent users' personal information from being leaked or damaged by hacking, computer viruses, and similar threats. The Company regularly backs up data in preparation for damage to personal information, uses up-to-date antivirus software to prevent the leakage or corruption of users' personal information and data, and employs cryptographic algorithms to enable the secure transmission of personal information over networks. The Company also controls unauthorized external access using intrusion prevention systems, and endeavors to keep all other technical safeguards for ensuring systemic stability continuously up to date.
The Company limits the handling of users' personal information to designated personnel, assigns separate passwords for this purpose that are updated periodically, and continually emphasizes compliance with this Privacy Policy through regular staff training. The Company also maintains a dedicated internal unit to verify the implementation of this Privacy Policy and personnel compliance, and to ensure that any identified issues are corrected and applied immediately.
Please note, however, that personal information may be leaked if a device used to access the Services is lost or if account credentials are compromised. Users are advised to take care and to make use of security features such as screen locks and two-factor authentication. The Company accepts no liability whatsoever for the leakage of important personal information resulting from a user's own negligence, including the loss of a device.
Article 11 (Handling of Inquiries Regarding Personal Information)
In order to protect users' personal information and to address grievances relating to personal information, the Company has designated a Personal Information Protection Officer as set out below. Users may direct any inquiry relating to the protection of personal information arising from their use of the Company's Services to the Personal Information Protection Officer or the responsible department. The Company will respond promptly and fully to user inquiries.
Personal Information Protection Officer
-
Name: Heeyong Choi
-
Title: Chief Executive Officer
-
Email: admin@inchanters.com
If you require consultation regarding an infringement of personal information beyond the above, please contact the following organizations.
-
Korea Internet & Security Agency (KISA) Privacy Infringement Report Center: 118 (no area code required) (https://privacy.kisa.or.kr)
-
Personal Information Dispute Mediation Committee: +82-1833-6972 (https://www.kopico.go.kr)
-
Supreme Prosecutors' Office Cyber Investigation Division: 1301 (no area code required) (https://www.spo.go.kr)
-
National Police Agency Cyber Investigation Bureau: 182 (no area code required) (https://ecrm.police.go.kr)
This Policy is effective as of July 31, 2023.
