Privacy PolicyDRAFT
Last updated — 2026-05-15 / Reflects PIPA revision effective 2026-09-11
This policy describes the scope and procedures by which ShowBravo collects, uses, retains, and deletes member personal data. It reflects the Personal Information Protection Act (PIPA) revision effective 2026-09-11.
Marketplace intermediary notice
ShowBravo is a marketplace intermediary platform operated by Inpica. The actual sellers of performance tickets are the venues and ticket distributors; Inpica acts as a marketplace intermediary and is not a party to the underlying transaction. ShowBravo facilitates payment processing, customer support, and refund procedures, but final responsibility for performance fulfillment, cancellation, or postponement rests with the seller.
1. Data collected
Required — email, display name. Optional — phone number (for booking alerts), profile photo. At payment — payment metadata only (amount, currency, authorization number). Raw card data (number, CVC, expiry) is transmitted directly to processors (Stripe / PayPal / Kakao Pay) and is not stored on ShowBravo servers. Location data is used only for a single lookup with explicit user permission and is never persisted.
2. Collection methods
Collected automatically during signup (email / OAuth), booking, and review writing. OAuth provider identifiers (Kakao, Google, Apple — profile_id, email, display_name) are processed under the same policy. We do not knowingly collect data from children under 14; if discovered, the data is deleted immediately.
3. Purpose of use
Booking processing, QR ticket issuance, payment receipt delivery, notification push (price drops, new shows, D-1 / D-7 reminders), fraud detection, and statistical analysis for service improvement. We do not use data for advertising or marketing without separate explicit consent.
4. Retention & deletion
Retained per the Korean E-Commerce Act — display / advertising records 6 months, contract / order-cancellation records 5 years, payment / fulfillment records 5 years, dispute records 3 years. On account deletion, identifying data is anonymized immediately and data without statutory retention obligation is deleted. Self-deletion is available at My → Delete account (/my/delete-account).
5. Third-party disclosure
Payment processing — Stripe Inc. (US), PayPal (US), Kakao Pay (KR). Email delivery — Resend Inc. (US). Error monitoring — Sentry (US). Marketing analytics — Google Analytics 4 (only with user opt-in consent). No other third-party disclosure occurs. Cross-border transfers are protected by Standard Contractual Clauses or equivalent safeguards.
6. Processor delegation
Database hosting — Supabase Inc. (server location: Seoul, Republic of Korea — ap-northeast-2). Web hosting — Vercel Inc. (Edge network). Delegated work is limited to operating this service, and the delegation contracts include explicit security and confidentiality obligations.
7. Member rights
Members may request access, correction, deletion, processing-suspension, and data-portability of their personal data. Direct edits at My → Account → Edit info, or send a request to dpo@inpica.com (processed within 30 days). Portability is provided via JSON export, downloadable from the same menu.
9. Security measures
TLS 1.3 in transit, AES-256 at rest, Supabase Row Level Security (RLS) for row-level access control, environment-isolated handling of sensitive tokens, and regular security audits / vulnerability checks. Passwords are stored only as bcrypt hashes — plaintext is never persisted anywhere.
10. PIPA 2026-09-11 revision compliance
Per the PIPA revision effective 2026-09-11, the following enhancements have been made — (1) right to opt out of automated decision-making (the recommendation algorithm can be disabled at My → Notification settings), (2) AI-processing disclosure (review sentiment analysis aggregates anonymously; per-individual identification is never surfaced), (3) annual impact-assessment summary published on the company blog, (4) data portability via JSON export.
11. Data Protection Officer
Name: Wontaek Seo / Title: Representative (DPO designation per the PIPA revision effective 2026-09-11) / Email: dpo@inpica.com / Phone: +82-70-4837-4077. Data-protection complaints can also be filed with the Korea Internet & Security Agency (KISA) Personal Data Infringement Center (118) or the Personal Data Dispute Mediation Committee (1833-6972).
12. EU residents (GDPR readiness)
For EU-resident data subjects, ShowBravo recognizes the rights granted under the General Data Protection Regulation (EU 2016/679) — (1) right of access (Art. 15), (2) right to rectification (Art. 16), (3) right to erasure / 'right to be forgotten' (Art. 17), (4) right to restriction of processing (Art. 18), (5) right to data portability (Art. 20, served via JSON export), (6) right to object (Art. 21), (7) right not to be subject to automated decision-making (Art. 22). EU data subjects may exercise these rights via the same channel (dpo@inpica.com), processed within one month. Cross-border transfers (US-based payment and email processors) are protected by Standard Contractual Clauses (SCC) or equivalent safeguards. An EU Representative will be designated at the point EU traffic becomes material in Phase 2.
13. California residents (CCPA threshold)
The California Consumer Privacy Act (CCPA / CPRA) applies to businesses that meet at least one of: (a) annual gross revenue over USD 25 million, (b) processing of personal information of 50,000+ California residents per year, or (c) deriving 50%+ of annual revenue from selling or sharing California residents' personal information. At Phase 1 launch, ShowBravo meets none of these thresholds and is therefore not formally subject to the CCPA. California residents may nevertheless exercise the rights described in §§(1)–(11) above, and once thresholds are reached we will publish a CCPA-specific notice covering the Right to Know / Delete / Opt-Out of Sale.