Privacy Policy

K2 Global Travel Personal Information Handling Policy

Privacy Policy

Published
September 21, 2026
Last updated
September 21, 2026

K2 Global Travel Co., Ltd. (hereinafter referred to as "the Company" or "K2 Global Travel") values the personal information and privacy of its customers.

This policy explains how the company collects, uses, saves, shares and protects personal information when providing private customized tours, accommodation arrangements, transportation, tour guides, itinerary planning and related customer services in South Korea.

By using our website, consulting services or providing personal information to our company, you indicate that you have read this policy. For matters that require separate consent according to law, the Company will separately explain and obtain your consent.

View catalog

1. Scope of application

This policy applies to personal information provided to the Company through the following methods:

  1. K2 Global Travel official website;
  2. email;
  3. WhatsApp, WeChat, LINE, KakaoTalk and other communication tools;
  4. Telephone or face-to-face consultation;
  5. Travel consultation form, registration form, itinerary confirmation documents and accommodation information;
  6. Payment, refund, complaint and after-sales service process;
  7. Information about fellow travellers provided by group representatives or contacts.

The processing of personal information by third-party websites, social media and communication platforms is still subject to their respective privacy policies.

2. Personal information that may be collected

Our company will collect all or part of the following information based on consultation or service needs.

1. Basic identity and contact information

  • Name;
  • nationality;
  • date of birth or age;
  • Gender (only if truly required for accommodation, ticketing or services);
  • phone number;
  • Email;
  • WhatsApp, WeChat, LINE, KakaoTalk and other communication accounts;
  • Country or region of residence.

2. Travel and accommodation information

  • Travel date and number of people traveling with you;
  • Flight, arrival and departure information;
  • Date of stay, room type and room allocation;
  • relationships among peer members;
  • Service needs for elders, children or members with reduced mobility;
  • Itinerary preferences, food preferences and budget;
  • Airport transfers, transportation, tour guides, restaurants, tickets and activity arrangements;
  • Luggage storage, check-in and check-out related information.

3. Passport and information required for booking

The Company will only collect passport or identification information necessary to complete a reservation if specifically requested by the hotel, flight, transportation, ticket, insurance or other supplier.

The company will not require customers to provide complete passport information for general itinerary consultation.

4. Special care and sensitive information

In order to ensure travel safety and provide appropriate services, the Company may need to know:

  • food allergies;
  • health status;
  • mobility;
  • medication or emergency care needs;
  • Religious or special dietary requirements;
  • Other circumstances that may affect travel arrangements.

The Company only collects such information when it is truly necessary, and will obtain additional explicit consent when required by law. Please do not provide medical records or other sensitive information unrelated to travel services.

5. Transaction and service records

  • Quotes, orders and contract information;
  • Payment, refund and cancellation records;
  • Information required for receipt or invoice;
  • Customer service, complaint and dispute handling records;
  • Records of emails and correspondence with the Company.

The company will not save complete credit card numbers, security codes or online banking passwords unless there is a genuine business and legal need.

6. Website usage information

Website hosting providers may automatically log:

  • IP address;
  • Browser and device type;
  • access time;
  • Pages viewed;
  • System logs and error data;
  • Cookies or similar technologies required for the website to function properly.

If the Company uses analytics, advertising or marketing tracking tools in the future, this policy will be updated accordingly and cookie choices will be provided where applicable.

3. How to collect personal information

The Company may collect information through the following methods:

  1. Customers take the initiative to fill in or submit inquiries;
  2. Customers contact the company through communication software, email or phone;
  3. Customer confirms quotation, itinerary, accommodation or other services;
  4. The group contact person submits information on behalf of fellow members;
  5. The customer requests the company to contact hotels, drivers, tour guides, restaurants or activity suppliers on their behalf;
  6. Customer processing of payments, refunds, complaints or emergencies;
  7. The website and hosting system automatically generate necessary access logs.

If you provide information on behalf of a peer member, please first confirm that you have obtained authorization from that member and ensure that the information provided is accurate.

4. Purpose of processing personal information

The company will use personal information within the following scope:

  1. Respond to travel and accommodation inquiries;
  2. Confirm customer needs, information about fellow travellers and budget;
  3. Design and modify private customized itineraries;
  4. Arrange accommodation, rooms, transportation, driver, tour guide, restaurants, tickets and activities;
  5. Handling airport transfers, luggage, check-in and check-out connections;
  6. Provide local support in Korea during the trip;
  7. Handle group member illness, lost items, itinerary changes or other emergencies;
  8. Produce quotes, orders, contracts, receipts and service records;
  9. Process payments, refunds, cancellations, complaints and disputes;
  10. Comply with applicable accounting, tax, consumer protection and personal information protection regulations in South Korea;
  11. Maintain the security of the website and information systems;
  12. protect against fraud, abuse or unauthorized access;
  13. To send travel information or marketing content with the customer's separate consent.

The Company does not sell customer information to third parties.

6. Retention period of personal information

The Company will only retain personal information for the period necessary to achieve the purpose of collection or as required by applicable Korean law.

List of retention periods for personal information
Data typeshelf life
Untransacted consultation information1 year after last contact
Completed travel or accommodation service records3 years after end of service
Customer complaint or dispute handling records3 years after completion of processing
Advertising and publicity records6 months
Records of conclusion, cancellation or withdrawal of contracts5 years
Payment and service provision records5 years
Consumer complaints and dispute handling records3 years

1. General business retention period

  • Information from enquiries that do not result in a booking: 1 year after the last contact;
  • Completed travel or accommodation service records: 3 years after the end of service;
  • Customer complaint or dispute handling records: 3 years after completion of handling;
  • Health, allergy and special care information used during the trip: will be deleted as soon as possible after the service ends and the relevant risk management is completed;
  • Copy of passport or identity certificate: deleted as soon as possible after completing the relevant booking or verification purpose, unless required to continue to be kept according to law;
  • Marketing contact information: deleted when the customer withdraws consent or requests to stop receiving it.

2. Retention period required by law

When Korean e-commerce consumer protection regulations apply:

  • Advertising and publicity record: 6 months;
  • Records of contract conclusion, cancellation or withdrawal: 5 years;
  • Payment and service provision records: 5 years;
  • Consumer complaint and dispute handling records: 3 years.

If tax, accounting or other applicable laws require a longer retention period, the Company will retain it in accordance with the relevant laws and limit the use of the information to statutory purposes only.

The above-mentioned e-commerce record period comes from the relevant enforcement orders in South Korea.

Korean E-commerce Consumer Protection Act Enforcement Order

7. Providing personal information to third parties

In order to complete the services requested by customers, the company may provide information to the following reception units or service providers within the minimum necessary scope:

  • Hotel, B&B and accommodation operators;
  • Drivers, vehicle companies and airport pick-up and drop-off personnel;
  • The tour guide responsible for the relevant group;
  • restaurant;
  • Ticket, experience and event suppliers;
  • Insurance company or emergency support unit;
  • Payment, accounting or legal assistance in processing transactions;
  • Government agencies, law enforcement agencies or regulatory agencies.

The information that may be provided includes name, number of people traveling with you, contact information, travel dates, flight information, accommodation arrangements, room allocation, itinerary and special requirements needed to complete the service.

The company only provides the minimum information required by the other party to complete the relevant services and will not allow third parties to use the information for unrelated marketing.

When it is necessary to notify separately or obtain the customer's consent according to the law, the company will explain the recipient, data items, purpose of use and retention period before providing the data.

In an emergency, in order to protect the life, body or property safety of customers, the Company may provide necessary information to medical, police, fellow travellers, or emergency assistance personnel within the scope permitted by law.

8. Entrusted processing and external services

The Company may use the following types of external services to process or store necessary data:

  • Personal Google Drive: file storage and business collaboration;
  • Website hosting services: website operation, security and system logs;
  • Email Services: Customer Communications;
  • WhatsApp, WeChat, LINE and KakaoTalk: the instant messaging customers choose to use;
  • Payment or banking services: collection, payment and refund processing;
  • Accounting and Tax Services: Handle financial records in accordance with the law.

The company will restrict access based on service needs and available functions, but third-party service providers will also process relevant data in accordance with their own terms and privacy policies.

Before customers choose to contact the Company through a third-party communication platform, they may read the privacy policy of that platform.

9. Storage and access management of personal Google Drive

The Company currently uses the personal Google Drive service provided by Google to store and manage travel and accommodation business documents.

Data access methods are as follows:

  1. Karyl Ng and the staff responsible for order operations can only access the information necessary for their work;
  2. Guides do not gain access to the entire Google Drive;
  3. Each team will use separate or restricted work folders;
  4. The tour guide only obtains necessary itinerary, contact and service information during the period of performing the group's services;
  5. After a tour guide completes the service or no longer needs the information, the Company will remove their access rights;
  6. The company will not share customer information in a public way that "anyone with the link can view";
  7. When passport, health, allergy or other sensitive information is involved, it will only be open to those who really need to handle the relevant matters;
  8. The company will regularly check folder permissions and require accounts with access to customer information to enable two-step verification;
  9. Where permitted, the company will restrict the editor from continuing to share files or change permissions.

Google will handle data in Google accounts and Drive services in accordance with its privacy policy.

Google privacy policy

10. Overseas processing and transmission

Google Drive, email, website hosting and international communication platforms may use servers, affiliates or service providers located outside of South Korea.

When customers proactively contact the Company through WhatsApp, WeChat, LINE, KakaoTalk or other international services, the relevant platforms may process communication content, account information and technical records in other countries or regions in accordance with their own privacy policies.

The company will only perform relevant processing when providing services requested by customers, performing contracts, obtaining necessary consents or other circumstances permitted by law, and will take reasonable measures to reduce the scope of transmitted data.

If Korean law requires additional notification or consent to specific overseas recipients, countries, transmission methods, data items and retention periods, our company will handle this separately before the relevant processing occurs.

If customers do not wish to provide information through a certain communication platform, they can contact the company via email, but some instant contact functions may be restricted as a result.

11. Information about children and minors

Family tours may involve children or minors.

In principle, the company collects necessary information from minors through parents, guardians or group representatives, and will not require children to submit information unrelated to travel on their own.

Parents or legal guardians may exercise rights on behalf of minors such as access, correction, deletion, restriction of processing or withdrawal of consent.

If it is discovered that minors' information has been collected without appropriate authorization, the company will verify the situation and take deletion or other necessary measures.

12. Customer's rights

Subject to applicable law, customers may request the following:

  1. Confirm whether the company holds their personal information;
  2. Check or obtain relevant information;
  3. Correct inaccurate or incomplete information;
  4. Delete data that is no longer needed or should no longer be stored;
  5. suspend or restrict processing;
  6. Withdraw previously given consent;
  7. Stop receiving marketing messages;
  8. To raise questions or complaints about the processing of personal information.

Customers may make requests through the email address listed in this policy.

To prevent information from being obtained by unauthorized persons, the Company may require applicants to verify their identity or authorization relationship.

If the data must be kept in accordance with the law, involves the rights of others, is dealing with a dispute, or the company is legally allowed to refuse or limit the request, the company will explain the reasons.

13. Cookies and website logs

This website may use cookies or similar technologies that are necessary to maintain the normal operation, security and basic functions of the website.

Customers can restrict or delete cookies through browser settings, but some website functions may not function properly.

If the company adds Google Analytics, Meta Pixel, ad remarketing or other unnecessary tracking technologies in the future, the company will update this policy and obtain customer consent when required by law.

14. Security Protection of Personal Information

The company will adopt security measures commensurate with its business scale and data risks, including:

  • Restrict Google Drive folder access permissions;
  • Share files using a designated account;
  • Create separate folders for different tour groups;
  • Enable two-step verification;
  • Avoid sharing customer information through public links;
  • Restrict access by staff role;
  • Cancel tour guide privileges that are no longer needed after the service is over;
  • Regularly check shared personnel and file permissions;
  • Minimize the collection and transmission of sensitive information;
  • Explain confidentiality and data use requirements to staff;
  • Change passwords and permissions promptly when something goes wrong with your device, account, or file.

Internet transmission and cloud storage cannot guarantee absolute security, but the Company will take reasonable measures to reduce the risk of unauthorized access, disclosure, loss, tampering or misuse.

15. Deletion of personal information

When the retention period expires, the purpose of processing is completed, or the customer requires deletion in accordance with the law, the company will delete or anonymize the relevant information within a reasonable period, except for information that is required to be retained by law.

Deletion methods include:

  • Delete electronic files from Google Drive, email or business systems;
  • Clear shared data no longer needed;
  • Remove the relevant personnel's access rights;
  • Secure deletion of irrecoverable electronic records;
  • Shred or otherwise irrecoverably destroy paper materials.

Data that are required to be retained according to law will be managed separately from daily business data and will only be used for legal purposes.

16. Data leakage and security incidents

In the event of personal information leakage, loss, unauthorized access or other security incidents that may affect the rights and interests of customers, the company will:

  1. Investigate the scope of the incident as quickly as possible;
  2. Stop or restrict unauthorized access;
  3. Change relevant accounts, passwords or sharing permissions;
  4. Maintain records required to handle incidents;
  5. Notify affected customers and relevant authorities when required by law;
  6. Take steps to prevent similar incidents from happening again.

17. Person in charge of personal information protection

Personal information protection manager

name
Karyl Ng(NG HUI CHE)
Position
Company Representative and Person in Charge of Personal Information Protection
company
K2 Global Travel Co., Ltd.
address
Room 1209, No. 156, Yanghwa-ro, Mapo-gu, Seoul, South Korea

If you have any questions about the collection, use, storage, sharing, deletion or security measures of personal information, you can contact us via the above email address.

18. Policy changes

The company may modify this policy due to changes in business content, service methods, platform usage or legal requirements.

Significant changes will be announced via the website with the date of the update. For matters that require new consent according to law, the Company will separately notify and obtain consent.

19. Effective date

Published
September 21, 2026
Effective date
September 21, 2026
last updated date
September 21, 2026
CONTACT K2

Chat with K2

Planning your Korea trip? Choose your preferred way to contact us.