Privacy Policy

v1.1 | May 2026

Article 1. Purpose of Processing Personal Information

The Company operates the NADO platform (“Platform”). In accordance with Article 30 of the Personal Information Protection Act (“PIPA”) of the Republic of Korea, the Company establishes and discloses this Privacy Policy to protect the personal information of data subjects and promptly address related grievances.

PurposeDetailsLegal Basis
Registration and managementIdentity verification, membership maintenance, prevention of fraudulent useContract performance (PIPA Art. 15(1)(4))
Service provisionIntermediation between NADOs and Guests, reservation and payment processing, in-app messaging and translation, shared photo albumContract performance
Safety managementLocation-based safety monitoring during service use, emergency responseLegitimate interest (PIPA Art. 15(1)(6))
Service improvementUsage analysis, new feature development, quality improvementLegitimate interest
Grievance handlingComplaint processing, dispute resolution, review and report handlingLegal obligation (PIPA Art. 15(1)(2))
NADO settlement and taxActivity fee settlement, withholding tax (3.3%) filing with the National Tax Service, bank account managementLegal obligation (Income Tax Act)
Contract managementHost activity agreement execution via e-signature (Modusign etc.), signed document storageContract performance
Application processingHost application review, interview scheduling, onboardingConsent / Contract performance
Marketing (with consent)Event and discount notifications, personalized recommendationsConsent (PIPA Art. 15(1)(1))

Article 2. Personal Information Collected

2.1 Information Required for Contract Performance

CategoryItemsWhen
RegistrationName, email, profile photoAt registration
VerificationMobile phone number (verified via SMS one-time code)At identity verification
PaymentTransaction reference (PayPal order ID and capture ID). Card details and billing address are entered and held by PayPal; the Company does not collect or store them.At reservation payment
Service useReservation records, usage history, chat messagesDuring use
ReviewsRatings, written contentAfter completion
NADO registrationName, email, phone, profile photo, activity name, bioAt NADO registration
Host applicationName, phone, email, Instagram, residence, neighborhood, interests, availability, self-introduction, photosAt application
Host contract (settlement)Bank name, account holder, account number, date of birthAt contract signing
Guest registrationNationality, gender, languages, interests, travel dates, city, preferred languageAt registration
NADO profileAreas, interests, languages, age range, real name (encrypted)At NADO registration
Matching preferences (internal)Matching preference settings — used only for matching algorithm; never displayed to guestsAt NADO registration
Beta tester applicationName, email, country, travel dates, interests, Instagram, IP address, user agentAt beta application
Customer supportReport category and body submitted via in-app safety / help (including any user-supplied screenshots), associated user account, timestampWhen the user submits a report or support request
Marketing analyticsReferral source, UTM parameters (source, medium, campaign), referrer URLAutomatically during registration

2.2 Information Requiring Separate Consent

  • Government-issued ID (last digits masked) — NADO registration, separate consent
  • Resident registration number — required by Income Tax Act for withholding tax (3.3%) filing; collected at contract signing with separate consent
  • Health information (allergies, dietary restrictions) — at reservation, optional
  • Voice data — collected during AI translation feature use; deleted within 24 hours of processing. Third-party processors are contractually required to delete within the same period; separate consent
  • GPS location — during service use, separate consent
  • Marketing — at registration, optional

2.3 Automatically Collected Information

The Company automatically collects device information (model, OS version), push notification tokens (Apple Push Notification service / Firebase Cloud Messaging device identifiers, used to route in-app notifications), log data (IP address, access times), and usage data (feature interaction records).

2.4 Information Received from Third Parties

The payment processor (PayPal) provides transaction confirmation data (order ID, capture ID, status). When a NADO chooses to connect their Instagram account, the public handle entered by the NADO is stored for display. If social login providers are integrated in a future release, this section will be updated accordingly and updated consent will be sought from existing users.

Article 3. Retention and Use Period

DataRetention
Membership informationUntil account deletion (destroyed within 30 days)
Dormant account dataSeparated storage for up to 3 years after dormancy conversion; permanently deleted after 4 years of total inactivity (PIPA Art. 39-6)
Reservation and payment records5 years after transaction
Consumer complaint records3 years
Chat messages3 years after completion (aligned with civil statute of limitations), or until related dispute is resolved
Location data90 days after completion
Shared album photos6 months (or upon deletion request)
NADO identity documentsDuring activity; destroyed within 30 days of termination (except settlement/tax records: 3 years after activity ends per National Tax Service requirements)
Host contract and settlement data3 years after activity ends (Income Tax Act, National Tax Basic Act)
Host application data (text)If rejected: destroyed within 3 months of decision notification. If accepted: personal information (name, phone, email, etc.) is transferred to the host account and contract management system; the original application is destroyed within 30 days of transfer. If no decision: destroyed no later than 6 months after submission. Destroyed upon request via support@withnado.com.
Host application photosIf rejected: destroyed within 30 days of decision notification. If accepted: transferred to host profile; original destroyed within 30 days of transfer. If no decision: destroyed no later than 3 months after submission. Destroyed upon request via support@withnado.com.
Beta tester application data6 months after beta period ends; destroyed upon request
Signed contract PDFs3 years after activity ends
Log records3 months

Article 4. Destruction Procedures and Methods

The Company shall destroy personal information within 5 business days of the expiration of the applicable retention period or the achievement of the processing purpose.

  • Electronic files: Permanently deleted using irrecoverable methods
  • Paper documents: Shredded or incinerated
  • NADO identity documents: Deleted within 30 days of termination
  • Dormant accounts: Personal information is separated and stored securely upon dormancy conversion, and permanently destroyed after 4 years of total inactivity

Article 5. Provision to Third Parties

5.1 During Service Use

  • NADO public profile includes: nickname/activity name, photos, bio, areas, interests, languages, age range, gender, rating, review count, and response time. This information is visible to all Platform users.
  • Upon reservation, the following Guest information is shared with the NADO: name, photo, nationality, gender, languages, and interests.
  • NADOs may choose whether to display their real name or activity name to Guests. This preference can be changed at any time in profile settings. Regardless of the display setting, in cases of legal disputes or requests from investigative authorities pursuant to applicable law, NADO identity information may be provided through proper legal procedures.
  • Shared album photos are accessible only to the NADO and Guest involved in the relevant service.

5.2 Tax Reporting

NADO settlement information (name, resident registration number, bank account, payment amounts) is provided to the National Tax Service for withholding tax (3.3%) filing as required by the Income Tax Act.

5.3 Disclosure Required by Law

The Company may disclose personal information when required to do so by applicable law or in response to lawful requests from competent investigative or regulatory authorities.

Article 6. Entrustment of Processing

The Company entrusts personal information processing to the following categories of processors. Entrustment contracts include provisions for safeguards and compliance monitoring.

  • Payment processing: PayPal (Europe) S.à r.l. et Cie, S.C.A. — guest payment for host time; card details are entered and held by PayPal
  • Cloud infrastructure: Vercel Inc. (hosting, edge), Neon Inc. (database), Vercel Blob (file storage)
  • E-signature: Modusign etc. (contract execution — host name, email, bank account, signature)
  • Translation: Google Cloud (Gemini) — chat message text and short voice clips for real-time translation; processed and deleted within 24 hours
  • Real-time voice relay: LiveKit, Inc. — in-call audio streaming for the voice-translation feature; not recorded server-side
  • SMS verification: Solapi Co., Ltd. — sends one-time verification codes; receives recipient phone number
  • Transactional email: Google LLC (Gmail SMTP) — sends booking, match, password reset and other transactional emails
  • Push notification delivery: Expo (Expo, Inc.), forwarding to Apple Push Notification service (Apple Inc.) / Firebase Cloud Messaging (Google LLC) — receives device push tokens and notification payloads
  • Bot & abuse protection: Google reCAPTCHA Enterprise — receives IP address and browser/device signals on auth-sensitive endpoints
  • Maps: Apple Maps (Apple Inc.) on iOS / Google Maps Platform (Google LLC) for places search and directions — receives query strings and approximate coordinates
  • Analytics: Vercel Analytics, PostHog, Inc. (web product analytics, pseudonymised by user identifier)

Article 7. International Transfer

Personal information may be transferred internationally for translation (chat messages), cloud storage, and payment processing. The Company ensures appropriate safeguards. For EEA/UK users, Standard Contractual Clauses (SCCs) are applied.

RecipientCountryData TransferredPurposeRetention
Vercel Inc.United StatesApplication data, user contentCloud hosting, edge computingDuration of service
Neon Inc.United StatesDatabase records (encrypted)Database hostingDuration of service
Google Cloud (Gemini)United StatesChat messages, voice dataTranslation, speech-to-textDeleted within 24 hours
LiveKit, Inc.United StatesIn-call audio stream, room IDReal-time voice relay for translationNot recorded; ephemeral during call
PayPal (Europe)Luxembourg / United StatesPayer email, transaction amount and identifiersPayment processingPer PayPal retention policy
Expo, Inc.United StatesDevice push tokens, notification payloadsPush notification deliveryUntil token invalidation
Apple Inc. (APNs) / Google LLC (FCM)United StatesNotification payloadsOS-level push deliveryTransient delivery only
Google LLC (Gmail SMTP)United StatesRecipient email, message bodyTransactional email deliveryTransient delivery
Google LLC (reCAPTCHA Enterprise)United StatesIP address, browser/device signalsBot & abuse prevention on auth endpointsPer Google retention policy
Google LLC (Maps Platform)United StatesQuery strings, approximate coordinatesPlaces search and directionsPer Google retention policy
PostHog, Inc.United StatesPseudonymised product interaction eventsProduct analyticsUp to 7 years (PostHog default) unless deleted earlier on request
Solapi Co., Ltd.South KoreaRecipient phone number, one-time codeSMS verificationTransient delivery
ModusignSouth KoreaHost contract dataE-signature processingDuration of contract

Users have the right to refuse international transfer of their personal information. However, refusal may limit the availability of certain Platform features that require international processing. To exercise this right, contact support@withnado.com.

Article 8. Security Measures

  • Administrative: Internal management plans, regular training, Chief Privacy Officer
  • Technical: Access control, encryption in transit (TLS/SSL) and at rest for all personal data including names, contact details, dates of birth, and financial information, security software
  • Physical: Physical security through cloud service provider security certifications

Article 9. Cookies

The Platform uses essential cookies (session, security), analytics cookies (with consent), and marketing cookies (with opt-in consent). Users may manage settings through their browser.

Article 10. Special Provisions for NADO Services

  • Photos: NADOs may photograph Guests upon request. Following upload to the shared album, NADOs are required to delete such photos from their personal devices. Shared album photos are automatically deleted after 6 months.
  • Chat records: Chat records are accessible only to the NADO and Guest involved in the relevant service. The Company may access chat records in connection with safety incidents, user reports, or lawful legal requests.
  • Reviews: Reviews must not include personal information such as real names or phone numbers. The Company reserves the right to edit or delete reviews that violate this requirement.
  • Use of information obtained during service: NADOs and Guests shall not use personal information obtained about the other party in connection with the service for any purpose other than the service itself.

Article 11. Location Data

  • GPS location data is collected during active service use following check-in, or when a user voluntarily shares their location via in-app chat.
  • Automatically collected GPS data is shared exclusively with Platform support. Location data voluntarily shared through chat is visible to the other party in that conversation.
  • Collection of location data requires separate consent from the User.
  • Users may disable location data collection at any time; however, certain safety features may be limited as a result.
  • Location data is deleted within 90 days of service completion.

Article 12. Rights of Data Subjects

Users may request: access to, correction of, deletion of, suspension of processing of, and portability of their personal information. Such rights may be exercised via email (support@withnado.com), in-app settings, or written request addressed to the Company. The Company shall respond within 10 calendar days of receipt of the request (one month for EEA/UK users under GDPR).

If the Company is unable to respond within the prescribed period due to justifiable reasons, it shall notify the User of the reason for the delay and the expected processing date.

Article 13. Automated Decision-Making

The Company employs automated systems for the following purposes:

(1) Experience recommendations based on a user’s interests, location, and language preferences

(2) Host-guest matching based on host preference settings configured at registration

(3) Detection of anomalous behavior for fraud prevention and safety purposes

With respect to matching, hosts may configure preferences that determine which guests are shown their profile. Accordingly, certain hosts may not appear in the profiles shown to a particular guest based on the host’s stated preferences.

Users have the right to: (a) request an explanation of any automated decision that affects them; (b) request human review of such a decision; and (c) contest the outcome of such a decision. Such requests shall be submitted to support@withnado.com and will receive a response within 10 business days.

Article 14. Children’s Personal Information

The Platform is intended solely for users aged 19 and older. The Company does not knowingly collect personal information from children under the age of 14. In the event that such information is inadvertently collected, the Company shall destroy it without delay upon discovery.

Article 15. Chief Privacy Officer

The Company has designated a Chief Privacy Officer responsible for overseeing the processing of personal information and handling related grievances.

Chief Privacy Officer: Jihwan Kim
Title: CEO
Email: support@withnado.com

Article 16. Remedies

The following authorities are available for dispute resolution and relief in connection with personal information:

  • Personal Information Dispute Mediation Committee: 1833-6972
  • Personal Information Infringement Report Center (KISA): 118
  • Supreme Prosecutors’ Office: 1301
  • National Police Agency: 182

Article 17. Additional Rights for EEA/UK Users (GDPR)

Users located in the EEA or the United Kingdom hold additional rights under the GDPR, including: the right to obtain information regarding the legal basis for processing; the right to restrict processing; the right to data portability; the right not to be subject to solely automated decision-making that produces legal or similarly significant effects; and the right to lodge a complaint with their competent national data protection supervisory authority.

As the Company is not established in the EEA, it will designate a representative within the EEA in accordance with Article 27 of the GDPR prior to commencing the processing of EEA residents’ personal data. Contact details of the designated representative will be published on this page once appointed.

Article 18. Data Breach Notification

In the event of a personal data breach likely to result in high risk to the rights and freedoms of data subjects, the Company will notify affected users within 72 hours of becoming aware of the breach via email or in-app notification. The notification will include the nature of the breach, likely consequences, and measures taken. The Company will also notify the Personal Information Protection Commission (PIPC) and relevant supervisory authorities as required by law.

Under PIPA, the Company shall also notify affected users and the Personal Information Protection Commission (PIPC) when the breach involves 1,000 or more data subjects, sensitive information, or unique identifiers (such as resident registration numbers), regardless of the assessed risk level.

Article 19. Changes to This Policy

Material changes to this Privacy Policy shall be announced at least 30 days prior to the effective date via the Platform or by email notification to registered Users.

Effective May 2026.