Privacy Policy

Effective date: June 2026

HOLIDAY TOUR, operated by Holiday Tour Inc., is a B2C online travel and transportation booking platform at holidaykr.com where international visitors and domestic travelers can search, book, and pay for Korea tours, private transfers, shuttles, guided experiences, and tickets.

This Privacy Policy has been established pursuant to Article 30 of the Personal Information Protection Act and related notices to clearly inform data subjects (hereinafter, 'Users') about the collection, use, provision, destruction of personal information, and the rights of data subjects.

This Policy applies to general members and booking/payment users of holidaykr.com (B2C). Users of the B2B Partner Portal (partner.holidaykr.com) are subject to that portal's separate privacy policy.

  1. Article 1 (Purpose of Collection and Use of Personal Information, Items, and Retention Period)

    We lawfully collect and process personal information only to the minimum extent necessary to provide services and perform contracts.

    Member TypePurpose of Collection and UseRequired ItemsRetention and Use Period
    B2C General MemberMembership approval, identity verification, prevention of duplicate registrations, and notifications of important information such as booking completionName, email address, password, country code, mobile phone numberDestroyed immediately upon membership withdrawal (except where legal mandatory retention periods apply)
    Booking and Payment CustomerPayment authorization, guide assignment, issuance of flight/shuttle boarding passes, and processing of booking refundsPassport number, English name, flight number, encrypted credit card information (card number, expiration date), mobile messenger IDRetention of payment and withdrawal-of-offer records for 5 years pursuant to applicable laws (e-Commerce Act, etc.)
  2. Article 2 (Protection of Personal Information of Children Under 14)

    When accepting membership or bookings from children under the age of 14, we provide practical verification methods (mobile phone identity verification, credit card verification, etc.) to obtain and confirm explicit consent from the legal guardian.

    A legal guardian may at any time request access, correction, deletion, or suspension of processing of the child’s personal information, and we will take necessary measures without delay.

  3. Article 3 (Provision to Third Parties and Cross-Border Transfer of Personal Information)

    We do not provide personal information to third parties or disclose it externally beyond the scope of collection without the user's prior consent. However, for the actual fulfillment of reservations for global local rental cars, driver-guides, and resort and activity distributors in Gangwon-do and the outskirts of Seoul, we provide to third parties and conduct cross-border transfers as follows.

    Specifications of cross-border data transfer:

    Recipient of the data: Overseas local land operators and vehicle partners providing services as specified on the booking page

    Purpose of transfer: Allocation of dedicated local vehicles overseas, passenger verification for shuttles and chartered guides, and response to local emergencies

    Items transferred: English name, passport number, mobile messenger ID (WhatsApp/LINE/WeChat), flight number, date of use

    Method and timing of transfer: Real-time transmission over a secure network (SSL/TLS) upon completion of booking payment

    Retention and use period: Destroyed immediately after service use and settlement are completed; however, if retention is mandated under applicable local tax laws overseas, such laws will be observed

    Users have the right to refuse the above cross-border transfers; however, refusal may restrict reservations for overseas local products and registration/use of the platform.

  4. Article 4 (Procedures and Methods for Destruction of Personal Information)

    When personal information becomes unnecessary due to the expiration of the retention period, achievement of the processing purpose, etc., we destroy such personal information without delay (typically within 5 days).

    Information in electronic file form is deleted using technical methods that render records irrecoverable (e.g., low-level format), and personal information printed on paper is destroyed by shredding or incineration.

  5. Article 5 (Personal Information Protection Officer and Complaint Handling)

    To protect users' personal information rights and handle grievances and inquiries related to personal information smoothly, we designate the following Personal Information Protection Officer.

    Personal Information Protection Officer: CEO Park Un-yong

    Dedicated department for complaint handling: Platform Information Security Team

    Email and main phone: info@holidaykr.com | +82-32-657-8888

  6. Article 6 (Entrustment, Re-Entrustment, and Partner Controls)

    For booking fulfillment, the Company may entrust limited processing of personal information to payment processors, booking system providers, local land operators, driver-guides, vehicle companies, hotels, resorts, ticket suppliers, messaging providers, and customer-support vendors only within the scope necessary to provide the booked service.

    A partner or processor may not re-entrust passenger lists, passport details, contact information, location information, or booking data to a second- or third-tier subcontractor without the Company's prior written approval. The Company may require a written data processing agreement, security checklist, training evidence, deletion confirmation, and audit cooperation from processors and re-processors.

    If a processor or partner becomes aware of unauthorized access, loss, theft, disclosure, falsification, alteration, damage, or suspected leakage of personal information, it must notify the Company without delay and cooperate with investigation, user notice, regulatory reporting, remediation, and evidence preservation.

  7. Article 7 (Security Incident Notice and User Remedies)

    If the Company confirms or reasonably suspects unauthorized access, leakage, loss, theft, falsification, alteration, or damage involving personal information, the Company will take measures required by applicable law, including prompt notice to affected users and regulatory reporting where required.

    Incident notices may include the categories of affected information, timing and route of occurrence, measures taken by the Company, user protective steps, contact point for inquiries, and available remedies such as damage compensation claims or personal information dispute mediation where applicable.

    Operational details such as statutory thresholds, reporting forms, and authority submission procedures are maintained in the Company's internal incident-response manual and are subject to confirmation by legal/privacy counsel before external filing.

  8. Article 8 (Automated Recommendations and Data Subject Controls)

    The platform may display automated recommendations, personalized product rankings, recently viewed items, or AI-assisted suggestions based on language, currency, destination interest, booking history, viewed products, cookies, and similar service-use signals.

    Users may object to or disable non-essential personalized recommendations and marketing cookies through cookie settings, browser settings, account settings, or by contacting info@holidaykr.com. Where a fully automated decision materially affects a user's rights or obligations, the Company will provide an explanation, a way to request human review, or an alternative manual process as required by applicable law.

Holiday Korea

HOLIDAY TOUR

Holiday Tour Travel Concierge

AI 스마트 상담

안녕하세요! Holiday Tour 여행 콘시에르주입니다. 상품·예약·맞춤 여행, 무엇이든 편하게 물어보세요.