Privacy Policy
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes and does not use it for any purpose other than those stated below. If the purpose of processing changes, the Company will take the necessary measures, including obtaining separate consent where required under the Personal Information Protection Act.
1. Website Membership Registration and Management (clem.co.kr)
To verify membership registration, identify and authenticate members, maintain and manage membership, prevent unauthorized use, provide notices, and handle customer inquiries and complaints.
2. Provision of Goods and Services
To process orders, deliver products, provide services and content, verify identity, process payments, and send contracts or electronic documents.
3. Customer Support
To verify the identity of customers, respond to inquiries and complaints, conduct necessary investigations, and notify customers of the results.
4. Marketing and Promotional Information (Optional Consent)**
With the user's separate consent, to provide information on new products, services, events, and promotional offers.
Article 2 (Retention and Processing Period of Personal Information)
① The Company processes and retains personal information within the retention period prescribed by applicable laws or the period consented to by the data subject at the time of collection.
② The specific retention periods for personal information are as follows, in accordance with applicable laws, including the Act on Consumer Protection in Electronic Commerce, etc.
1. Website Membership Registration and Management: Until membership is terminated.
However, in the following cases, personal information will be retained until the relevant matter has been resolved.
– Where an investigation or inquiry related to a violation of applicable laws is in progress: Until the investigation or inquiry is completed.
2. Records relating to contracts or withdrawal of subscription: 5 years
(Act on Consumer Protection in Electronic Commerce, etc.)
3. Records relating to payment and the supply of goods or services: 5 years
(Act on Consumer Protection in Electronic Commerce, etc.)
4. Records relating to consumer complaints or dispute resolution: 3 years
(Act on Consumer Protection in Electronic Commerce, etc.)
5. Records relating to advertising and labeling: 6 months
(Act on Consumer Protection in Electronic Commerce, etc.)
6. Records relating to website visits (Login Records): 3 months
(Protection of Communications Secrets Act)
Article 3 (Categories of Personal Information Processed)
The Company processes the following categories of personal information.
1. Website Membership Registration and Management
Required Information: Name, Username (ID), Password, Mobile Phone Number, Email Address
2. Purchase and Delivery of Goods or Services
Required Information: Customer Name, Mobile Phone Number, Shipping Address, Payment Information (such as the card issuer and payment method verification information. Detailed payment information, including card numbers, is processed separately by the payment service provider.)
For international shipments (including Japan): The Company additionally collects the minimum information required for delivery, such as the recipient's name in English, country, and international phone number.
3. Customer Inquiries (Q&A Board)
Required Information: Name, Email Address or Contact Information, Inquiry Details
4. Information Automatically Collected During Service Use
IP Address, Cookies, Date and Time of Visit, Service Usage Records, and Records of Improper Service Use
Article 4 (Provision of Personal Information to Third Parties)
The Company processes personal information only within the scope specified in Article 1 (Purpose of Processing Personal Information) and provides personal information to third parties only with the data subject's consent or where permitted under Articles 17 and 18 of the Personal Information Protection Act, including where otherwise required by applicable law.
The outsourcing of personal information processing activities described in Article 5 (Outsourcing of Personal Information Processing) does not constitute the provision of personal information to a third party.
Article 5 (Outsourcing of Personal Information Processing)
① To facilitate the efficient processing of personal information, the Company entrusts certain personal information processing activities to the following service providers.
1. Service Provider: Cafe24 Corp.
Scope of Services: Operation of the online shopping mall (clem.co.kr) and server hosting services.
2. Service Provider: KG INICIS Co., Ltd.
Scope of Services: Provision of electronic payment services, including credit card payment processing.
3. Service Provider: Lotte Global Logistics (Lotte Courier)
Scope of Services: Domestic and international delivery of ordered products.
② When entering into outsourcing agreements, the Company specifies matters required under **Article 26 of the Personal Information Protection Act**, including the prohibition of processing personal information for purposes other than the entrusted services, technical and organizational security measures, restrictions on subcontracting, supervision of service providers, and liability for damages. The Company also supervises its service providers to ensure that personal information is processed securely.
③ If there are any changes to the outsourced services or service providers, the Company will promptly disclose such changes through this Privacy Policy.
Article 6 (Cross-Border Transfer of Personal Information)
The Company transfers personal information overseas only for orders requiring international delivery, such as shipments to Japan, for the purposes of customs clearance and local delivery.
1. Recipient
Overseas delivery partners of Lotte Global Logistics (Lotte Courier), including customs brokers and local courier service providers.
2. Categories of Personal Information Transferred
The minimum information required for customs clearance and delivery, including the recipient's name, shipping address, and international phone number.
3. Countries to Which Personal Information Is Transferred
The destination country selected by the customer at the time of placing the order (e.g., Japan).
4. Time and Method of Transfer
Personal information is electronically transferred through the logistics system of Lotte Global Logistics when an international shipping order is placed.
5. Retention and Use Period by the Recipient
Until customs clearance and delivery are completed, and thereafter for the period required by applicable laws or the recipient's data retention policy.
6. Right to Refuse the Transfer and Consequences
Data subjects may refuse the cross-border transfer of their personal information by choosing not to place an international shipping order. In such cases, international shipping services will not be available.
The Company transfers personal information overseas only to the extent necessary for the purposes described above. If the recipient, transferred information, or destination country changes, the Company will promptly update this Privacy Policy.
Article 7 (Procedures and Methods for the Destruction of Personal Information)
① The Company destroys personal information without undue delay when the retention period has expired or when the purpose of processing has been fulfilled and the personal information is no longer required.
② If the retention period consented to by the data subject has expired or the purpose of processing has been fulfilled, but the Company is required to retain the personal information under applicable laws, such personal information will be stored separately in a different database (DB) or in a separate storage location.
③ The procedures and methods for the destruction of personal information are as follows.
1. Destruction Procedures
The Company identifies personal information subject to destruction when a valid reason for destruction arises and destroys such information upon approval by the Company's Chief Privacy Officer.
2. Methods of Destruction
Personal information stored in electronic files is permanently destroyed using methods that prevent the recovery or reproduction of the records, such as low-level formatting. Personal information recorded or stored in paper documents is destroyed by shredding or incineration.
Article 8 (Installation, Operation, and Opt-Out of Automatic Personal Information Collection Devices)
① The Company uses cookies to store and retrieve user information in order to provide optimized services.
Cookies are used only for purposes such as maintaining login sessions, providing shopping cart functionality, and analyzing service usage statistics. The Company does not use third-party personalized advertising services such as Google Analytics or Meta Pixel.
② Installation, Operation, and Opt-Out of Cookies
Users may refuse the storage of cookies by changing their browser settings (e.g., **Tools > Internet Options > Privacy**).
However, if cookies are disabled, some services that require login may not function properly.
Article 9 (Rights of Data Subjects and Their Legal Representatives, and How to Exercise Them)
① Data subjects may exercise their rights at any time, including the right to request access to, correction, deletion, or suspension of the processing of their personal information.
② Requests under Paragraph 1 may be submitted to the Company in writing, by email, fax, or other methods prescribed under Article 41(1) of the Enforcement Decree of the Personal Information Protection Act. The Company will respond without undue delay.
③ Such rights may also be exercised through a legal representative or an authorized agent. In such cases, a power of attorney must be submitted in accordance with Form No. 11 of the Notice on the Methods of Processing Personal Information (Notice No. 2020-7).
④ Requests for access to personal information or suspension of processing may be restricted in accordance with Article 35(4) and Article 37(2) of the Personal Information Protection Act.
⑤ Requests for the correction or deletion of personal information may be denied where the retention of such information is required by applicable laws.
⑥ When a request for access, correction, deletion, or suspension of processing is made, the Company will verify whether the requester is the data subject or a duly authorized representative.
⑦ The Company does not provide services intended for children under the age of 14 and, as a general rule, does not collect the personal information of children under the age of 14 during the membership registration process.
Article 10 (Measures to Ensure the Security of Personal Information
The Company implements appropriate administrative, technical, and physical safeguards to protect personal information from unauthorized access, disclosure, alteration, loss, or destruction.
1. Administrative Measures
Establishment and implementation of internal privacy management policies, limitation of personnel with access to personal information, and regular privacy and security training for employees.
2. Technical Measures
Management of access privileges to personal information processing systems, implementation of access control measures, encryption of sensitive personal information, and installation and regular updates of security software.
3. Physical Measures
Restricted access to facilities where personal information is stored or processed, including server rooms and document storage areas.
Article 11 (Information Protection Officer)
① The Company has designated a Chief Privacy Officer who is responsible for overseeing the handling of personal information and managing matters related to personal information processing, including handling inquiries, complaints, and remedies for damages related to the processing of personal information, as follows.
Name: Lee Hyung-joo
Position
CEO
Contact information
070-8833-7020
jason@crazyoutdoor.co.kr
② Data subjects may contact the Chief Privacy Officer or the relevant department regarding any inquiries, complaints, or requests for remedies related to the protection of personal information that may arise while using the Company's services.
The Company will respond to and handle inquiries from data subjects without undue delay.
Article 12 (Remedies for Infringement of Data Subject Rights)
Data subjects may apply for dispute resolution or consultation through organizations such as the Personal Information Dispute Mediation Committee or the Korea Internet & Security Agency (KISA) Personal Information Infringement Report Center in order to seek remedies for damages caused by personal information infringement.
For other reports or consultations regarding personal information infringement, please contact the following organizations.
1. Personal Information Dispute Mediation Committee
Phone: 1833-6972 (without area code)
Website: www.kopico.go.kr
Personal Information Infringement Report Center
Phone: 118 (without area code)
Website: privacy.go.kr
Supreme Prosecutors' Office
Phone: 1301 (without area code)
Website: www.spo.go.kr
Korean National Police Agency
Phone: 182 (without area code)
Website: ecrm.cyber.go.kr
Article 13 (Changes to the Privacy Policy)
① This Privacy Policy shall take effect from July 7, 2026.
② If any additions, deletions, or modifications are made due to changes in laws, policies, or security technologies, the Company will notify users of such changes through the website notice board at least 7 days before the effective date of the changes.
However, if the changes significantly affect the rights or obligations of data subjects, the Company will provide prior notice at least 30 days before the changes take effect.