Privacy Policy
MUZLIVE Inc. (hereinafter referred to "Company") has complied and would comply with the personal information protection regulations under the related laws and regulations that information and communication service providers shall comply with including the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc., the Protection of Communication Secrets Act, and the Telecommunications Business Act and is making best efforts to protect the rights and interests of users by establishing the privacy policy.
In accordance with Article 30 of the Personal Information Protection Act, the Company establishes and discloses the privacy policy to protect the personal information of data subjects and to handle related grievances promptly and smoothly as follows. Unless otherwise separately described herein, it applies to all personal information files processed by the Company. However, if any separate privacy policy is enacted and implemented in other service platforms directly operated by the Company for processing of the Company's business affairs, it shall be followed and posted on the website operated by the applicable platform.
This Privacy Policy shall come into effect from October 4, 2024.
Article 1 (Purpose of Collection / Use of Personal Information)
The company collects the minimum necessary personal information required for membership registration, use of services and customer support, participation in events, and inquiries via fax or phone through its website (kitbetter.com) and mobile applications (KiTplayer, KiTpage). Such collection is conducted with prior notice and consent from users.
The Company processes personal information for the purposes described below. The personal data to be processed shall not be used for purposes other than those specified below. The Company will take necessary measures, such as obtaining separate consent in accordance with Article 18 of the Personal Information Protection Act.
- Website sign-up and management
- Personal information is processed for the purpose of confirming the intention to sign up as a website member (hereinafter referred to as "member"), identifying and verifying the identity according to the membership service, maintaining and managing membership, preventing illegal use of services, various public notifications and notices, and handling grievances.
- Providing goods or services
- Personal information is processed for the purpose of delivering goods, providing services, delivering content, and offering customized services.
- Use in marketing and advertising.
- Personal information is processed for the purpose of developing new services (products), providing customized services, event/advertising information, and participation opportunities, providing services according to demographic characteristics, posting advertisements, and so on.
- Service improvement, etc.
- Service usage records, IP addresses, cookies, connected device model names, OS information, etc., are automatically generated and collected for the purposes of preventing illegal service use, confirming usage history, accessing frequency and usage statistics, handling customer inquiries, and improving service.
- The company provides a social login feature through Google and Apple to simplify membership registration and service usage. The company collects the following personal information:
- Email address, name, profile picture, and any other relevant data provided through Google or Apple
- Purpose of Use: Membership registration and login via the social login feature, identity verification, and providing customized services.
- Retention Period: 3 months after membership withdrawal or as specified by relevant laws.
Article 2 (Processing and Retention Period of Personal Information)
The Company shall destroy the personal information of the data subject without delay when the purpose of collection/use of personal information, such as membership withdrawal, is achieved. However, provided that personal information of members shall be retained for each of the reasons and periods below, exceptionally:
- Internal policy of the Company
- Prevention of re-signup by bad users, prevention of illegal use, billing of charges to customers who failed to pay for the service, and response to other complaints.
- Retention period: 6 months after membership withdrawal (However, when payment is made in full in case of unpaid billing, and when the complaint is resolved in case of responding to complaints)
- Retained information: ID, name, e-mail, mobile phone number, encrypted identification information (CI), date of sign-up, and withdrawal
- Prevention of re-signup by bad users, prevention of illegal use, billing of charges to customers who failed to pay for the service, and response to other complaints.
- When the data subject directly requests preservation of personal information or when the Company obtains the consent of the data subject individually
- Retention period and information: Retained for the applicable period only for items/periods for which the data subject's request or consent was obtained
- When it is decided to preserve data without the user's consent, in accordance with applicable laws and regulations.
| Ground laws | Information to be preserved | Retention period |
|---|---|---|
| Act on Consumer Protection in Electronic Commerce, etc. | Records on contracts or withdrawal of subscription | 5 years |
| Act on Consumer Protection in Electronic Commerce, etc., Commercial Act, Framework Act on National Taxes, Income Tax Act, Corporate Tax Act, Value Added Tax Act | Records on payment and supply of goods, commercial books and business slips, and documentary evidence | 5 years |
| Act on Consumer Protection in Electronic Commerce, etc. | Records of consumer complaints or dispute resolution | 3 years |
| Protection of Communication Secrets Act | Records of on-site visits | 3 months |
- In accordance with the Personal Information Validity Period System, the Company informs members who have not used the service for at least 1 year at least 30 days prior to the expiration date. The Company separately stores personal information and destroys it without delay after 4 years.
Article 3 (Use of Collected Personal Information and Provision to Third Parties)
- The Company shall inform the data subject of personal information through the Terms of Use, the privacy policy, etc., and use it within the scope of obtaining consent, and does not use it or provide it to a third party beyond this scope. When providing personal information to a third party, the Company shall inform the data subject of the recipient, the items to be provided, the purpose of providing personal information, the period of retention and use in advance, and request consent/agreement. If the member disagrees, the Company shall not provide the personal information. However, if the data subject does not provide personal information to a third party when using the tie-up service, they shall be notified that there may be disadvantages, including the tie-up service not being available, and the benefits of using the tie-up service.
- However, when set forth in laws such as the Personal Information Protection Act, the personal information of the data subject may be used or provided to a third party without the consent of the member in the following cases:
- If necessary for the settlement of the price and charge according to the service
- When otherwise outlined in other laws, including the Protection of Communication Secrets Act, Framework Act on National Taxes, Act on Promotion of Information and Communications Network Utilization and Information Protection, etc., Telecommunications Business Act, Local Tax Act, Criminal Procedure Act, etc.
- However, the personal information of the member shall not be provided unconditionally, even if there is a special provision in the law and the administrative agency or investigative agency requires it for administrative or investigation purposes but may be provided only when it can be confirmed that it is the data required by law including a warrant or a document sealed by the head of the agency as prescribed.
- Provision to Third parties for Social Login Functionality.
- Recipients: Google, Apple
- Provided Items: Email address, name, profile image, etc.
- Purpose of Provision: To provide social login functionality, verify identity, and offer personalized services.
- Retention and Usage Period: From the point of using the social login function until membership withdrawal or as required by relevant laws.
Article 4 (Delegation of Personal Information Processing)
- The Company entrusts the processing of personal information to an external specialized service provider, which shall hold the personal information of the members to the extent required during the contract period in principle, but for the statutory period outlined in the related laws against such service providers, if any.
| Name of the service provider | Description | Period of service entrustment |
|---|---|---|
| CJ Korea Express | Delivery of goods | Until expiration or termination of the entrustment contract |
- Delegation for Provision of Social Login Functionality
| Name of Delegate | Details of Delegated Task | Delegation Period |
|---|---|---|
| Google, Apple | Processing of personal information for the provision of the social login function. | Until membership withdrawal or the termination of the delegation contract. |
Article 5 (Rights of Information Subjects and Legal Representatives and Method of Exercise)
- The data subject may exercise the right to inspection, correction, deletion, and processing suspension of personal information to the Company at any time. If a member intends to inspect and correct personal information on the website operated by the Company, it is possible to directly inspect or correct it by clicking 'Change Member Information'.
- The rights under Clause 1 may be exercised against the Company in writing, email, fax, etc., in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company shall take measures thereto without delay. In addition, only if it is difficult to directly correct or delete personal information (withdrawal of membership) due to unavoidable reasons, it is possible to request correction or deletion in writing, email, fax, etc., and the Company shall take measures accordingly without delay.
- The Company is taking protective measures to ensure children and their legal representatives are not disadvantaged due to personal information provided by children under 13 years old (hereinafter referred to as "children").
- The consent of the legal representative of the children is required when collecting personal information for children's service subscription, or when using or providing the personal information of children beyond the scope of the consent obtained during sign-up.
- The minimum necessary information such as the legal representative's name and contact information, may be requested to obtain the consent of the legal representative. In this case, the purpose of collection, use or provision of personal information and the effect that a consent of a legal representative is required shall be notified to the children in plain language to ensure the children may easily understand.
- The personal information on the legal representative collected to obtain the consent of the legal representative shall not be used or provided to a third party for any purpose other than to confirm the consent of the legal representative.
- The legal representative may withdraw consent to the collection, use or provision of personal information of children under 14 years old and may request to inspect the personal information or correct errors in the personal information provided by children under 13 years old.
- The rights under Clauses 1 and 2 may be exercised through an agent, such as a legal representative of the data subject or a person authorized to act on their behalf. In this case, a power of attorney in the form of Attachment No. 11 of the "Notice of Personal Information Processing Method (Personal Information Protection Commission's Notification No. 2020-7, enacted on August 11, 2020)".
- The right to request to inspect and suspend processing of personal information may be restricted in the following cases, and, in such cases, the reasons of the postponement or restriction/rejection of such a request are provided through email by the member or the customer support center.
- Where the inspection and processing are prohibited or restricted by the laws
- Where there is a risk of harming the life or body of another person, or unfairly damaging/infringing the property and other interests of another person
- Where it is technically significantly difficult to delete only the image information of a specific data subject
- On request of inspection, correction, deletion or processing suspension by the data subject, MUZLIVE Inc. may the request of inspection etc. of the data subject is the genuine intent or the person requested it is the duly authorized representative by conformation of the subject and receiving power of attorney proving the agency relationship, certificates of seal impression, copies of ID cards and other documents.
Article 6 (Obligations of Members)
- Members shall prevent unexpected accidents in advance by entering their personal information accurately and up to date, ensuring they can receive timely information on important matters, such as securing the right to self-determination over personal details and changes, as well as the suspension/termination of the Company's service. Members shall be responsible for the consequences resulting from the entry of incorrect information. If false information is entered due to the illegal use of information belonging to others, they may lose their membership and be subject to punishment in accordance with relevant laws and regulations.
- Members have the obligation to protect themselves and not infringe on the information of others, along with the right to receive protection for their personal information. Members shall carefully manage their personal information, including IDs and passwords, to ensure it is not leaked. They shall also pay attention to not damage the personal information and reputation of others, including through postings. If any member fails to fulfill these obligations and damages the information of others, such a member may be subject to punishment under relevant laws and regulations, such as the Act on Promotion of Information and Communications Network Utilization and Information Protection.
- Members are obligated to protect their personal information. The Company shall not be responsible for any matter caused due to leakage of personal details arisen from matters on the internet beyond control of the Company, even of the Company has exercised reasonable care, including hacking using a method or technology that cannot be blocked with the security measures under the related laws, or the negligence of the members not attributable to the Company.
- Members are required to participate in periodic security activities in accordance with the Company's privacy policy.
Article 7 (Public Notification or Notice Method of the Privacy Policy)
- The privacy policy may be updated in response to changes in relevant laws and guidelines, as well as internal operational policies. If there is any addition, deletion, or modification of the privacy policy, the reason for the change and its contents shall be notified through the 'Notices' on the website at least 7 days prior to the revision. However, if there is a significant change in the member's rights regarding the collection/use of personal information, it shall be notified at least 30 days in advance.
- In the event of transferring all or part of the business or transferring the rights and obligations due to a merger or inheritance, the members shall be individually notified in writing or by e-mail, etc., and such a fact shall be notified by posting on the initial screen of the website for identification for more than 30 days. However, a notice in writing/e-mail or other means may be made through posting on more than two central daily newspapers (the daily newspaper circulated in the region when most of customers live in a specific area) more than once when the contact information on the customers is not available without a mistake or there is otherwise any proper reason of not providing the notice including natural disaster.
Article 8 (Preparation of Personal Information Items to Be Processed)
Personal information collected from members and used in the course of sign-up and service use is as follows;
- Joining with the community
- Email account, password (encrypted and stored to ensure it cannot be decrypted), nickname,
- Automatically created information
- Purpose of collection and use: Service use and counseling, identification/prevention of illegal use, statistics, and analysis
- Collection and use items: Cookies, service use records (visit date, IP, bad use records, etc.), device information (unique device identification value and OS version), APP version, language, country or region of residence, and time zone
- Retention period: 3 months after withdrawal from service or the period according to related laws
- Purchase and delivery of goods
- Purpose of collection and use: Buyer confirmation, delivery of goods, and operations
- Collection / use items:
- (Buyer confirmation) Name, date of birth, and phone number
- (Supply and delivery of goods) Name, date of birth, phone number, and address
- (Operation) Name, date of birth, phone number and SNS account
- Retention period: 1 year after purchase
- Participating in events and winning prizes
- Purpose of collection / use: Confirmation of applicants in the events, provision and delivery of giveaway, and operations
- Collection / use items:
- (Confirmation of applicants) Name, date of birth, and phone number
- (Providing and delivering the giveaway) Name, date of birth, phone number, and address
- (Operation) Name, date of birth, phone number, and SNS account
- Retention period: 1 year after the event ends. However, information on non-winning participants shall be destroyed within 7 days after the winner is announced.
- Advertising information
- Purpose of collection/use: Confirmation of applicants in the events, provision and delivery of giveaways, and operations
- Collection/use items: email and App Push
- Retention period: 3 months after withdrawal from service or the period according to related laws
- The Company collects personal information of members as above. However, sensitive personal information (including race and ethnicity, ideology and creed, place of birth and domicile, political orientation, criminal record, health status, and sex life) and unique identification information that may infringe upon members' fundamental human rights are not collected.
- When using the service through the mobile application, access to terminal information shall be notified and approved. The right to access terminal details through the mobile application is required or selectively requested from the user whenever necessary, and the authority may be changed through "Set-up" in the terminal.
- The company collects and uses the following items to provide the functionality of social login;
- Items Collected: Email address, name, profile picture, etc.
- Purpose of Collection: To provide social login functionality, verify identity, and offer personalized services.
- Retention Period: 3 months after membership withdrawal or as required by relevant laws.
Article 9 (Destruction of Personal Information)
- MUZLIVE Inc. destroys personal information without delay when it becomes unnecessary, such as when the retention period has expired or the purpose of processing has been achieved.
- If it is necessary to continue to preserve the personal information in accordance with other laws even when the personal information retention period agreed by the data subject is over or the purpose of processing has been achieved, the personal information shall be transferred to a separate database (DB) or preserved at different storage.
- The procedure and method for destroying personal information are as follows.
- Destruction procedure
- The Company selects the personal information to be destroyed and destroys it after obtaining approval from the Company's privacy officer.
- Destruction method
- Information in the form of electronic files is destroyed using a technical method that prevents the reproduction of records. Personal information printed on paper is shredded with a shredder or destroyed through incineration.
- Destruction procedure
Article 10 (Measures to Ensure Safety of Personal Information)
The Company is taking the following measures to ensure the safety of personal information;
- Minimizing and training of the personnel handling personal information: The Company is implementing measures to manage personal information by designating and minimizing/limiting the staff handling personal information to the applicable staff.
- Technical measures against hacking: In order to prevent leakage and damage of personal information caused by hacking or computer viruses, the Company installs security programs, periodically updates and inspects them, installs the systems in areas where access is controlled from outside, and performs the technical / physical monitoring and blocking.
- Encryption of personal information: User's personal information is stored and managed with encrypted passwords, which allows only the user to know it, and important data is used after separate security functions such as encrypting files and transmitting data or using a file lock function.
Article 11 (Cookies and Similar Technologies)
The Company uses cookies, local storage, session storage, and other browser storage technologies (collectively, "Cookies etc.") to provide personalized services, improve our services, and measure advertising effectiveness. Cookies etc. are small pieces of data sent from the server operating the website to your browser and stored on your device. Regardless of the type of storage technology used, they are classified as follows based on their collection purpose.
1. Categories and Items Collected
① Essential
These are strictly necessary to provide the basic functions of the Service and are collected without your consent. Disabling them may prevent or limit your use of the Service.
| Item | Provider | Purpose | Retention |
|---|---|---|---|
refreshToken, user_id, user_type, accessToken |
Muzlive Inc. | Login session maintenance and user authentication | Until session ends ~ 15 days |
userInfo |
Muzlive Inc. | Storage of user role and access token | 1 day |
_q_state_gSDtTCjJ2BozXgw6 |
Shopify Inc. | Shopping session maintenance | 2 years |
__stripe_mid |
Stripe, Inc. | Payment fraud prevention and session management | 1 year |
ch-veil-id, x-veil-id, _dd_s_v2 |
Channel Corporation | Customer support session identification and support widget operation status & error monitoring | 1 year |
artist_id, kitalbum_localization, recentViews |
Muzlive Inc. | Remembering user preferences (artist selection, language, recently viewed items) | 7 days ~ 60 days |
kitbetter_r_a (localStorage) |
Muzlive Inc. | Storing and auto-filling login email when "Remember email" is selected | Until deselected or browser data is cleared |
kitbetter_cookie_consent |
Muzlive Inc. | Storing cookie consent status and sharing across same-domain services (prevents re-display of consent banner) | 1 year (re-consent required upon expiry or policy revision) |
② Optional — Analytics/Statistics (collected upon consent)
Used for analyzing service usage and improving the Service. You may still use the Service without consenting.
| Item | Provider | Purpose | Retention |
|---|---|---|---|
_ga, _ga_* |
Google LLC (Google Analytics 4) | User identification, visit statistics, session and event tracking | 2 years |
mp_* |
Mixpanel, Inc. | User behavior analysis and event tracking | 1 year |
_hjSession_*, _hjSessionUser_* |
Hotjar Ltd. | UX analysis and heatmap collection | Until session ends / 1 year |
optimizelyEndUserId, optimizelySession |
Optimizely, Inc. | A/B testing and experiment management | 6 months |
_dd_s |
Datadog, Inc. | Service stability monitoring and error tracking | Until session ends |
③ Optional — Marketing/Advertising (collected upon consent)
Used for delivering personalized advertisements and measuring advertising effectiveness. You may still use the Service without consenting.
| Item | Provider | Purpose | Retention |
|---|---|---|---|
_gcl_au |
Google LLC (Google Ads) | Ad click and conversion measurement | 90 days |
_fbp |
Meta Platforms, Inc. | Facebook/Instagram ad performance measurement and retargeting | 90 days |
_rdt_* |
Reddit, Inc. | Reddit ad conversion measurement and retargeting | 3 months |
※ Third-party domain cookies — When using third-party services such as Google social login, Google may set cookies (SID, HSID, NID, etc.) on its own domain (google.com). These are not cookies installed or controlled by us and cannot be managed through our cookie settings. They may be managed through Google's Privacy Policy and your browser settings.
2. Cookie Consent Management
The Company operates cookie consent as follows depending on your region of access.
You may change or withdraw your consent for optional cookies at any time via the "Cookie Settings" link in the footer of the Service. Withdrawing consent is ensured to be as easy as giving consent.
| Region | Consent Banner | Cookie Settings Access | Analytics Cookies |
|---|---|---|---|
| Republic of Korea | Not displayed | Available via "Cookie Settings" link in service footer | Collected without separate consent (opt-out available via Cookie Settings) |
| All other regions | Banner displayed upon first visit | Available at any time via "Cookie Settings" link in service footer | Collected only upon prior consent (opt-in) |
3. Consent Record Retention
The Company retains your cookie consent records as follows.
| Item | Details |
|---|---|
| Stored items | Consent date/time, selection per cookie category, policy version, consent identifier (UUID, pseudonymized), country of access, member identifier (if consented while logged in) |
| Expiry | Maximum 12 months (re-consent requested upon expiry) |
| Record retention period | 3 years from the date of last consent |
4. Cross-border Transfer of Personal Information
When you consent to analytics and/or marketing/advertising cookies, your personal information may be transferred abroad as described below. Transfers occur continuously via cookies/SDK through network transmission during your use of the Service.
| Recipient | Country | Items Transferred | Purpose | Retention |
|---|---|---|---|---|
| Google LLC | USA | Cookie/advertising identifiers, service usage records | Visit statistics (GA4), ad conversion measurement (Google Ads) | Up to 2 years |
| Mixpanel, Inc. | USA | Cookie identifier, member identifier (when logged in), service usage records | User behavior analysis | 1 year |
| Hotjar Ltd. | Malta | Cookie identifier, member identifier and language settings (when logged in), screen usage records | UX analysis and heatmaps | Up to 1 year |
| Optimizely, Inc. | USA | Cookie identifier, experiment participation records | A/B testing | 6 months |
| Datadog, Inc. | USA | Cookie identifier, email address and member identifier (when logged in), error/performance records | Service stability monitoring | Until session ends |
| Meta Platforms, Inc. | USA | Cookie/advertising identifiers, service usage records | Ad performance measurement and retargeting | 90 days |
| Reddit, Inc. | USA | Cookie/advertising identifiers, hashed email address (when logged in), service usage records | Ad conversion measurement and retargeting | 3 months |
You may refuse or withdraw cross-border transfers by declining or withdrawing consent for analytics or marketing/advertising cookies via "Cookie Settings" in the service footer. Doing so will not restrict your use of the Service.
※ Separately from the table above, the transfer of monitoring data generated during the operation of the support widget (Channel Corporation) to overseas occurs as an essential part of providing the support service, regardless of the user's consent. For details, please refer to Channel Corporation's Privacy Policy.
Article 12 (Link Site)
- Links to other companies' websites or data/materials may be provided to members through the Company's website. In this case, the Company does not take responsibility for or guarantee the usefulness of services or data/materials provided from external sites.
- If the member clicks a link included in the website and moves to a page on another site, the Privacy Policy of the Company no longer applies to the use of those sites.
Article 13 (Privacy Officer)
- The Company has designated the privacy officer who is responsible for the overall handling of personal information for handling complaints and damage relief of the data subject related to the processing of personal information as follows:
- Privacy Officer
- Name: Park, Jong-sung
- Contact: +82-2-376-9775, js.park@muzlive.com
- Privacy Officer
※ The member will be connected to the department in charge of personal information protection.
- Department in charge of personal information protection
- Title: Personal Information Manager
- Person in charge: Park, Jong-sung
- Contact: +82-2-376-9775, js.park@muzlive.com
- Title: Personal Information Manager
- The data subject may inquire about all personal information protection-related inquiries, complaint handling, damage relief, etc., to the privacy officer and the department in charge. The Company will respond and handle the inquiries of the data subject without delay.
Article 14 (Request for Access to Personal Information)
The data subject may file a request for access to personal information iaw Article 35 of the Personal Information Protection Act to the following departments. The Company will make every effort to promptly process the personal information access request of the data subject.
- Personal information access request reception/processing department
- Title: Personal Information Manager
- Person in charge: Park Jong-sung
- Contact: +82-2-376-9775, js.park@muzlive.com
Article 15 (Remedies for Infringement on Rights)
The data subject may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee or the Personal Information Infringement Report Center of Korea Internet & Security Agency, etc. to receive relief from personal information infringement. Additionally, for reports of personal information infringement and counseling, please contact the following organizations.
- Personal Information Dispute Mediation Committee: (without area code) 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center of Korea Internet & Security Agency: (without area code) 118 (privacy.kisa.or.kr)
- Cyber Crime Investigation Department of Supreme Prosecutor's Office: (without area code) 1301 (www.spo.go.kr)
- Cyber Investigation Bureau of National Police Agency: (without area code) 182 (ecrm.cyber.go.kr)
A person who is infringed of the rights or benefits due to disposition or inaction of the head of a public institution against a request pursuant to Article 35 (Inspection on Personal Information), Article 36 (Correction/Deletion of Personal Information), and Article 37 (Suspension of Personal Information Processing, etc.) of the Personal Information Protection Act may file an administrative appeal in accordance with the Administrative Appeals Act.
※ Please refer to the website of the Central Administrative Appeals Commission (www.simpan.go.kr) for more information on administrative appeals.
Article 16 (Change in Privacy Policy)
- This Privacy Policy is effective as of July 30, 2026.
- Previous versions of the Privacy Policy are available in the Notice section.
- Key changes (effective July 30, 2026)
- Article 11: Detailed specification of items collected and purposes of cookies and similar automatic collection technologies
- Article 11: Added scope of browser storage technologies (local storage, etc.)
- Article 11: Explicit disclosure of third-party services (GA4, Mixpanel, Meta Pixel, etc.)
- Article 11: Introduction of cookie consent banner and cookie settings feature, with region-specific consent methods (Republic of Korea: analytics cookies collected by default with opt-out available; all other regions: opt-in required)
- Article 11: Added notice of cross-border transfer to third parties
- Article 11: Added standards for retention of consent records