Privacy Policy

Effective: July 13, 2026 · Last updated: July 13, 2026

TRI-STAR TECH ("the Company") establishes and discloses this Privacy Policy pursuant to Article 30 of the Personal Information Protection Act (PIPA) to protect the personal information of data subjects and to handle related grievances promptly and smoothly.

Article 1 (Purposes of Processing)

The Company processes personal information for the following purposes and does not use it beyond them. If purposes change, we take necessary measures such as obtaining separate consent.

  • Membership & management: verifying sign-up intent, identification/authentication, maintaining membership, preventing misuse, notices, grievance handling
  • Service provision: AI-based buyer discovery, real-time translation chat, email campaigns, product catalog, campaign analytics and personalized features
  • Payment & settlement: charging/settling paid services, subscription management, refunds
  • Marketing & advertising: new service announcements, events and promotional information (with consent)
  • AI-based buyer research: collecting/analyzing prospective buyer company data from public web, extracting company website info, lead scoring and discovering publicly listed business contacts

Article 2 (Personal Information Collected)

CategoryItemsMethod
RequiredEmail, name, company name, password (for direct sign-up), onboarding survey (industry, target market, target export countries, export experience, etc.)Sign-up, social login
Social login (additional)Profile image URL, social account identifierAuto-collected on Google OAuth
PaymentPayment method info (card issuer, partial card number), amount, timestampCollected at payment
Auto-collectedIP address, browser info, access logs, cookies, service usage recordsAuto-collected during use
AI buyer researchCompany name, industry, country, website and publicly listed business contact (email)Crawling of public web / business directories (public sources, not the data subject)
Payment security: The Company does not directly store sensitive payment data such as full card numbers or CVC. Payments are handled via our payment provider (PG) PortOne — domestic cards through Toss Payments and international cards through Payletter — where card data is processed by providers compliant with payment security standards (PCI-DSS).

Article 3 (Processing & Retention Period)

The Company processes and retains personal information within the period required by law or consented to by the data subject.

ItemRetentionBasis
Member infoUntil account withdrawalConsent of data subject
Contract / subscription records5 yearsE-Commerce Act Art. 6
Payment / settlement records5 yearsE-Commerce Act Art. 6
Consumer complaint / dispute records3 yearsE-Commerce Act Art. 6
Access logs1 yearProtection of Communications Secrets Act Art. 15-2
Collected buyer contact details2 years from last verification/use (auto-purged if unused)PIPA Art. 21 (storage limitation / destruction)

Article 4 (Provision to Third Parties)

The Company processes personal information only within the stated purposes and, except in the following cases, does not process beyond the original purpose or provide to third parties without the data subject's prior consent.

  • Where separate consent has been obtained from the data subject
  • Where specifically provided for by law
  • Where deemed necessary for the urgent life, body or property interests of the data subject or a third party

Article 5 (Consignment & Cross-Border Transfer)

For smooth service provision, the Company consigns personal information processing as below. Some processors are located overseas, so personal information may be transferred abroad.

ProcessorTaskCountryRetention
Toss PaymentsDomestic payment processingRepublic of KoreaUntil end of contract
PayletterInternational payment processingRepublic of KoreaUntil end of contract
PortOnePayment integration / routingRepublic of KoreaUntil end of contract
OpenAIAI translation / analysis / chatbotUnited StatesUntil end of contract
DeepLTranslation processingGermany (EU)Until end of contract
Twilio SendGridEmail delivery, unsubscribe / bounce handlingUnited StatesUntil end of contract
Amazon Web Services (SES)Email delivery (fallback)United StatesUntil end of contract
GoogleSocial login (OAuth) authenticationUnited StatesUntil end of contract
SerpAPIBuyer search query processingUnited StatesUntil end of contract
VultrCloud server operation / hostingUnited States, etc.Until end of contract
Cross-border transfer: Personal information may be transferred to processors located in the US or EU. Only the minimum information necessary for each task is transferred, via encrypted channels (TLS) at the time of processing, and destroyed without delay once the purpose is achieved. For recipient contact details, please write to cs@tri-startek.com.

Article 6 (AI Buyer Research Processing)

To provide our overseas buyer (prospective partner) discovery service, the Company collects, compiles and analyzes companies' names, industries, countries, websites and publicly listed business contacts from public web sources (company websites, public business directories). This data is obtained from public sources, not from the data subject directly.

  • Legal basis: legitimate interest in identifying international trade counterparts (GDPR Art. 6(1)(f)), balanced against the data subject's rights and interests.
  • Data minimization: departmental/role-based business contacts are preferred over individuals' personal emails.
  • Cross-border transfer: during AI analysis, relevant data may be transferred to US-based processors (e.g., OpenAI).
  • Retention: personal contacts are kept only as long as necessary and are periodically purged if unused/unresponsive for an extended period.
  • Opt-out: marketing emails include an unsubscribe mechanism; unsubscribed or bounced addresses are not contacted again.

Want to remove your personal or company information?

You can request removal or opt-out of your data directly — without any account — on the page below.

Request data removal / opt-out →

Article 7 (Rights of Data Subjects)

Data subjects may exercise the following rights at any time.

  • Right to access
  • Right to rectification
  • Right to erasure
  • Right to restrict / object to processing (opt-out)

Rights may be exercised in writing, by email or via customer support (cs@tri-startek.com), and the Company will act without delay. Rights may also be exercised through a legal representative or authorized agent.

Article 8 (Destruction of Personal Information)

When personal information becomes unnecessary due to expiry of the retention period or achievement of purpose, the Company destroys it without delay. Electronic files are permanently deleted so they cannot be recovered, and printed documents are shredded or incinerated.

Article 9 (Security Measures)

  • Administrative: internal management plan, minimizing and training staff who handle personal data
  • Technical: access-control for processing systems, one-way hashing of passwords, TLS encryption in transit, access control and security software
  • Physical: physical security controls of the cloud infrastructure provider (data-center access control, etc.)

Article 10 (Cookies)

The Company uses cookies to provide personalized services. Cookies are small pieces of data sent by the server to the user's browser; users may allow, be prompted for, or refuse cookies via browser settings. Refusing cookies may limit some services.

Article 11 (Data Protection Officer)

The Company designates the following Data Protection Officer to oversee personal information processing and to handle complaints and remedies of data subjects.

Data Protection Officer

Company: TRI-STAR TECH · Business Reg. No.: 604-05-19062

Title: CEO

Address: #813, A-dong, 135 Gasan digital 2-ro, Geumcheon-gu, Seoul 08504, Republic of Korea

Email: cs@tri-startek.com · Tel: +82-70-4243-3838

Addendum

This Privacy Policy takes effect on July 13, 2026. It may be revised in line with changes to applicable laws or our services; changes will be announced on this page.