지머니트랜스㈜(이하 “회사”)는 정보주체의 자유와 권리 보호를 위해 「개인정보 보호법」및 관계 법령이 정한 바를 준수하여, 적법하게 개인정보를 처리하고 안전하게 관리하고 있습니다. 이에 「개인정보 보호법」제30조에 따라 정보주체에게 개인정보 처리에 관한 절차 및 기준을 안내하고, 이와 관련한 고충을 신속하고 원활하게 처리할 수 있도록 하기 위하여 다음과 같이 개인정보 처리방침을 수립·공개합니다.
목차
제1조개인정보의 처리목적
“회사”는 개인정보를 다음 각 호의 목적을 위해 처리합니다. 처리한 개인정보는 다음의 목적 외의 용도로는 사용되지 않으며 이용 목적이 변경될 시에는 사전동의를 구할 예정입니다.
회원 가입, 회원제 서비스 제공에 따른 본인 식별 및 인증, 서비스 부정이용 방지, 각종 고지 및 통지, 고충처리의 목적으로 개인정보를 처리합니다.
국내 및 해외 송금 서비스, 카드 서비스, 오픈뱅킹 서비스 제공을 목적으로 개인정보를 처리합니다.
교통카드 충전, 국내 및 국외 휴대폰 충전, 공과금 납부 등과 같이 이용자의 생활편의 서비스 제공을 목적으로 개인정보를 처리합니다.
제2조처리하는 개인정보의 항목
“회사”는 다음과 같은 개인정보 법적 근거로 이용자의 개인정보를 수집 및 이용합니다.
① 이용자의 동의를 받지 않고 처리하는 개인정보 항목
“회사”는 다음의 개인정보 항목을 이용자의 동의 없이 처리하고 있습니다.
| 법적 근거 | 목적 | 처리하는 개인정보 |
|---|---|---|
| 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제2호 및 제6호 「전자금융거래법」 제21조(안전성 확보의무) 제1항 | 전자금융거래 내용 추적 및 검색, 보안정책 수립, 사고 방지 | 기기식별정보(UUID), 핸드폰 모델명, OS 구분(Android OS, iOS), OS버전, E-Mail, IP주소 |
| 「금융실명거래 및 비밀보장에 관한 법률」 제3조(금융실명거래) 제1항 | 금융거래 시 실명확인 | 이름, 고유식별정보(주민등록번호, 외국인등록번호, 여권번호), 신분증 사진(주민등록증, 외국인등록증, 여권) |
| 「외국환거래법」 제20조(보고·검사) 제4항 및 제5항 | 해외송금 현황보고(한국은행 ORIS) | 송금인 식별정보(주민등록번호/사업자등록번호/여권번호), 성명, 계좌정보, 송금일시, 송금금액(USD 환산액, 환율), 송금사유(경상거래/자본거래), 수취인 정보(이름, 국적, 수취방식, 수취번호), 중계기관 정보 |
② 이용자의 동의를 받아 처리하는 개인정보 항목
“회사”는 다음의 개인정보 항목을 이용자의 동의를 받아 처리하고 있습니다.
| 서비스 구분 | 처리 목적 | 처리 항목 | 법적 근거 |
|---|---|---|---|
| 회원가입 및 고객확인 | 서비스 가입 | 이름, 이메일(선택), 휴대폰번호, 추천인코드(선택) | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 |
| 휴대폰 본인 인증 | 이름, 생년월일, 성별, 휴대폰번호, 통신사, 연계정보(CI), 중복가입확인정보(DI) | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 | |
| 안면인식 기술을 활용한 비대면 실명확인 | 얼굴 원본정보, 얼굴 특징정보 | 「개인정보 보호법」 제23조(민감정보의 처리 제한) 제1항 제1호 「특정 금융거래정보의 보고 및 이용 등에 관한 법률」 제5조의2(금융회사 등의 고객 확인의무) | |
| 고객 확인 | ⊙주민등록증 정보 주민등록증 사진(앞면/뒷면), 이름, 주민등록번호, 생년월일, 성별, 신분증 발급일 ⊙외국인등록증 정보 외국인등록증 사진(앞면/뒷면), 이름, 외국인등록번호, 생년월일, 성별, 국적, 신분증 발급일, 비자 종류 ⊙여권 정보 여권 사진, 이름, 여권번호, 생년월일, 성별, 국적, 여권 발급일, 여권 만료일 ⊙고객 확인을 추가 정보 주소, 우편번호, 직업, 계좌 사용 목적, 자금원천, 회사명 | 「특정 금융거래정보의 보고 및 이용 등에 관한 법률」 제5조의2(금융회사 등의 고객 확인의무) | |
| 해외송금 서비스 | 해외송금 서비스 이용 | ⊙ 송금자 정보 이름, 생년월일, 휴대폰번호, 주소, 송금국가, 수취인과의 관계, 송금목적, 신분증 타입, 신분증번호, 국적, 직업, 자금원천, 수취은행명, 계좌번호, 신분증 발급일, 출생국가코드, 성별, 고객번호, Gcash Wallet Number, 신분증 만료일, 거주국가, 송금국가코드, 신분증 발급국가, 출생지역 ⊙ 수취인 정보 이름, 계좌번호, 휴대폰번호, 주소, MoMo Wallet Number, 국적, 수취은행코드, 수취은행명, UZ Card/HumoCard Number, Visa/Master Card Number, 지역코드, Bkash Number, 생년월일, 출생국가코드, AliPay Wallet Name, AliPay Wallet Number, 수취인과의 관계, 계좌 타입, Rocket Wallet Number, 송금국가, 수취국가코드, 계좌번호, 신분증 타입, 신분증 만료일, 성별, 신분증번호, IFSC Number, Nagad Wallet Number, WeChat Wallet Number, 수취은행명, 수취은행 지점코드 | 「개인정보 보호법」 제28조의8(개인정보의 국외 이전) 제1항 제1호 「특정 금융거래정보의 보고 및 이용 등에 관한 법률」 제5조의3(전신송금 시 정보제공) |
| 카드 서비스 | GmoneyCard 발급 | 고유식별정보(주민등록번호, 외국인등록번호, 여권번호), 이름, 성별, 주소, 주소 이미지(선택), 휴대폰번호, 외국인구분, 이메일 | 「전자금융거래법 시행령」 제31조(민감정보 및 고유식별정보의 처리) 제3항 |
| 카드 보험 가입 | 고객번호, 가입 GmoneyCard 상품명, 카드등록일, 성별, 국적, 주소, 휴대폰번호, GmoneyCard 카드번호 | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 | |
| 오픈뱅킹 서비스 | 오픈뱅킹 서비스 이용 | 이름, 생년월일, 금융기관명, 계좌번호, 이메일, 연계정보(CI) | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 |
| 생활편의 서비스 | 교통카드 충전 서비스 이용 | 고객번호, 교통카드번호 | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 |
| 국내 휴대폰 충전 서비스 이용 | 이름, 국적, 휴대폰번호, 충전금액 | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 | |
| 해외 휴대폰 충전 서비스 이용 | 국가, 이름, 휴대폰번호, 통신사, 상품명, 충전금액 | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 | |
| 해외 공과금 납부 서비스 이용 | 공과금 계정번호, 수취인 휴대폰번호, 납부국가, 납부기관, 납무항목, 납부금액 | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 | |
| 게임 기프티콘 구매 서비스 이용 | 상품명, 휴대폰번호 | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 | |
| 세금 환급 신청서 작성 지원 서비스 이용 | 이름, 외국인등록번호, 귀속연도, 근무처명, 사업자등록번호, 해당 연도 총급여, 결정세액, 원천징수영수증 상의 결정세액, 신고기한 내 납부세액, 은행명, 계좌번호, 취업자 유형, 취업일, 생년월일, 감면기간, 세목, 귀속년월, 환급금액, 지급일, 지급은행, 환급 계좌번호 | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 「개인정보 보호법」 제24조(고유식별정보의 처리 제한) 제1항 제1호 | |
| 쇼핑몰 서비스 이용 | 고객번호, 이름, 주소, 주소 이미지(선택), 휴대폰번호, 생년월일, 국적 | 「개인정보 보호법」 제15조(개인정보의 수집·이용) 제1항 제1호 |
제3조개인정보의 처리 및 보유 기간
“회사”는 법령에 따른 개인정보 보유·이용기간 또는 이용자로부터 개인정보를 수집 시에 동의받은 개인정보 보유·이용기간 내에서 개인정보를 처리·보유합니다.
회원 탈퇴 시까지 보유합니다. 다만, 거래내역이 존재하거나 이용자 확인을 완료하였을 경우 탈퇴 후 5년간 보유합니다.
서비스 제공 완료시점부터 5년간 보유합니다.
서비스 제공 완료시점부터 5년간 보유합니다.
위 사항에도 불구하고 관련 법령에 따라 개인정보를 보존하여야 할 의무가 있을 경우 법령에 명시된 기간 동안 보유합니다.
| 구분 | 관련 법령 | 보유 기간 |
|---|---|---|
| 이용자 확인 기록 | 「특정 금융거래정보의 보고 및 이용 등에 관한 법률」 제5조의2(금융회사 등의 고객 확인의무) | 5년 |
| 전자금융거래에 관한 기록 | 「전자금융거래법」 제22조(전자금융거래기록의 생성·보존 및 파기) 「전자금융거래법 시행령」 제12조(전자금융거래기록의 보존기간·보존방법 및 파기 절차·방법 등) | 5년 |
| 계약 또는 청약철회에 관한 기록 | 「전자상거래 등에서의 소비자보호에 관한 법률」 제6조 | 5년 |
| 대금결제 및 재화 등의 공급에 관한 기록 | 「전자상거래 등에서의 소비자보호에 관한 법률 시행령」 제6조 | 5년 |
| 소비자의 불만 또는 분쟁처리에 관한 기록 | 「전자상거래 등에서의 소비자보호에 관한 법률 시행령」 제6조 | 3년 |
| 표시·광고에 관한 기록 | 「전자상거래 등에서의 소비자보호에 관한 법률 시행령」 제6조 | 6개월 |
제4조개인정보의 파기 절차 및 방법에 관한 사항
“회사”는 개인정보 보유기간의 경과, 처리목적 달성 등 개인정보가 불필요하게 되었을 때는 지체없이 해당 개인정보를 파기합니다.
이용자로부터 동의받은 개인정보 보유기간이 경과하거나 처리목적이 달성되었음에도 불구하고 다른 법령에 따라 개인정보를 계속 보존하여야 하는 경우에는 해당 개인정보를 별도의 데이터베이스(DB)로 옮기거나 보관장소를 달리하여 보존합니다.
개인정보 파기 절차 및 방법은 다음과 같습니다.
1. 파기 절차
- 회사”는 파기 사유가 발생한 개인정보를 선정하고, 개인정보 보호책임자의 승인을 받아 개인정보를 파기합니다.
2. 파기 방법
- 전자적 파일 형태로 기록·저장된 개인정보: 기록을 재생할 수 없도록 파기
- 종이 문서에 기록·저장된 개인정보: 분쇄기로 분쇄하거나 소각하여 파기
제5조개인정보의 제3자 제공에 관한 사항
“회사”는 원활한 서비스 제공을 위해 다음의 경우 「개인정보 보호법」 제17조 제1항 제1호에 따라 이용자의 동의를 얻어 필요 최소한의 범위로만 제공합니다.
| 제공받는 자 | 제공 목적 | 제공 항목 | 제공받는 자의 보유 및 이용기간 |
|---|---|---|---|
| 금융결제원 | 오픈뱅킹 서비스 이용 | 이름, 생년월일, 금융기관명, 계좌번호, 이메일, 연계정보(CI) | 거래일로부터 5년 |
| 비씨카드 | GmoneyCard 발급 및 배송 | 이름, 휴대폰번호, 주민등록번호, 여권번호, 외국인등록번호, 배송 주소지, 계좌번호, 카드 비밀번호, 이메일, 성별, 국적 | 거래일로부터 5년 |
| 메리츠화재 | 카드보험 가입 | 고객번호, 가입 GmoneyCard 상품명, 카드등록일, 성별, 국적, 주소, 휴대폰번호, GmoneyCard 카드번호 | 거래일로부터 5년 |
| 큐큐트레이드 | 국내 휴대폰 충전 | 휴대폰번호, 충전금액 | 거래일로부터 5년 |
| 주식회사 그라미스 | 쇼핑몰 이용 | 고객번호, 이름, 주소, 주소 이미지(선택), 휴대폰번호, 생년월일, 국적 | 회원 탈퇴시까지 |
| 한국철도공사 | 교통카드 충전 서비스 | 고객번호, 교통카드번호 | 거래일로부터 5년 |
“회사”는 원활한 서비스 제공을 위해 다음의 경우 「개인정보 보호법」 제17조 제1항 제1호에 따라 이용자의 동의를 얻어 필요 최소한의 범위로만 제공합니다.
| 관련 근거 | 제공받는 자 | 제공 목적 | 제공 항목 | 보유 및 이용기간 |
|---|---|---|---|---|
| 「외국환거래법」 제20조(보고·검사) 제4항 및 제5항 | 한국은행 | 해외송금 현황보고(한국은행 ORIS) | 송금인 식별정보(주민등록번호/사업자등록번호/여권번호), 성명, 계좌정보, 송금일시, 송금금액(USD 환산액, 환율), 송금사유(경상거래/자본거래), 수취인 정보(이름, 국적, 수취방식, 수취번호), 중계기관 정보 | 5년 |
개인정보를 국외의 제3자에게 제공하는 경우는 ‘제7조(개인정보의 국외이전에 관한 사항)’에서 안내하고 있습니다.
제6조개인정보 처리업무의 위탁에 관한 사항
“회사”는 원활한 개인정보 업무처리를 위하여 다음과 같이 개인정보 처리업무를 위탁하고 있습니다.
| 위탁받는 자(수탁자) | 위탁업무 |
|---|---|
| 쿠콘 | 신분증 진위확인 서비스 예금주 실명조회 서비스 가상계좌 중계 서비스 입금이체 서비스 COATM 서비스 ARS 인증 모바일증명서 조회 서비스 |
| 코리아크레딧뷰로 | 휴대폰 본인인증 서비스 |
| 비씨카드 | GmoneyCard 거래 승인, 취소 및 중계, 가맹점 대금 정산 |
| 엠에프컴퍼니 | 문자발송 서비스 |
| 엔아이티소프트 | 문자발송 서비스 |
| 갤럭시아머니트리 | 편의점 바코드 결제 서비스 편의점 바코드 입금 서비스 효성ATM 입금 서비스 |
| 더치트 | 부정거래자 조회 서비스 |
| 다우기술 | 메일 발송 서비스 |
| 금융결제원 | 신분증 진위확인 서비스 통합 일간 출금한도 조회 서비스 |
“회사”는 위탁계약 체결 시 「개인정보 보호법」 제26조에 따라 위탁업무 수행목적 외 개인정보 처리금지, 기술적・관리적 보호조치, 재위탁 제한, 수탁자에 대한 관리・감독, 손해배상 등 책임에 관한 사항을 계약서 등 문서에 명시하고, 수탁자가 개인정보를 안전하게 처리하는지를 감독하고 있습니다.
「개인정보 보호법」 제26조 제6항에 따라 수탁자가 당사의 개인정보 처리업무를 재위탁하는 경우 “회사”의 동의를 받고 있습니다.
위탁업무의 내용이나 수탁자가 변경될 경우에는 지체없이 본 개인정보 처리방침을 통하여 공개하도록 하겠습니다.
제7조개인정보의 국외이전에 관한 사항
“회사는 서비스 이용자로부터 수집한 개인정보를 아래와 같이 국외에 제공하고 있습니다. 해외송금 및 공공요금 납부, 바우처 구입을 위해 원칙으로 하고 있어 국외 이전을 거부하실 경우 서비스 이용이 불가능합니다. 국외 이전을 원치 않으실 경우 앱(메뉴-내 정보-회원탈퇴)에서 회원탈퇴를 진행하시거나 고객센터(1670-4565)를 통하여 회원탈퇴를 요청하실 수 있습니다.
개인정보 국외 제공 현황의 경우 아래 링크에서 확인하실 수 있습니다.
※ 개인정보 국외 제공 업체 목록(List of cross-border transfer personal information and company)
제8조개인정보의 안전성 확보조치에 관한 사항
“회사”는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
- 개인정보의 안전한 관리를 위해 내부관리계획을 수립하여 운영하고 있습니다.
- 개인정보를 처리하는 직원들을 대상으로 정기적인 교육을 수행하여 직원들의 개인정보보호에 대한 인식을 향상시키고 있습니다.
- 개인정보를 처리하는 시스템의 접근 권한을 최소한으로 부여하고 침입차단시스템을 이용하여 외부의 접근을 통제하고 있습니다.
- 고유식별정보, 계좌번호 등 이용자의 개인정보를 안전한 암호화 알고리즘으로 암호화하여 저장 및 관리하고 있습니다.
- 백신 프로그램을 설치하여 바이러스에 의한 피해를 방지하고 있습니다.
- 이용자의 개인정보가 보관된 장소를 인가된 자만이 접근이 가능하도록 출입통제 시스템을 운영 하고 있습니다.
제9조개인정보 자동 수집 장치의 설치·운영 및 그 거부에 관한 사항
"회사"는 이용자에게 개별적인 서비스와 편의를 제공하기 위해 이용정보를 저장하고 수시로 불러오는 '쿠키(Cookie)'를 사용합니다. 쿠키는 웹사이트 운영에 이용되는 서버가 이용자의 브라우저에 보내는 소량의 정보로서 이용자의 컴퓨터 또는 모바일 기기에 저장되며, 웹사이트 접속 시 이용자의 브라우저에서 서버로 자동 전송됩니다. 이용자는 브라우저 옵션 설정을 통해 쿠키 거부 등의 설정을 할 수 있습니다.
1. 웹 브라우저에서 쿠키 차단 방법
- 크롬(Chrome) : 웹브라우저 오른쪽 상단 ‘⁝’ 표시 선택 > 새 시크릿 창 (단축키 : Ctrl+Shift+N)
- 엣지(Edge) : 웹 브라우저 오른쪽 상단 ‘‧‧‧’ 표시 선택 > 새 InPrivate 창 (단축키 : Ctrl+Shift+N)
2. 모바일 브라우저에서 쿠키 차단 방법
- 크롬(Chrome) : 모바일 브라우저 오른쪽 상단 ‘⁝’ 표시 선택 > 새 시크릿 탭
- 사파리(Safari) : 모바일 기기 설정 > 앱 > 사파리(Safari) > 고급 > 모든 쿠키 차단
- 삼성 인터넷 : 모바일 브라우저 아래쪽 ‘탭’ 아이콘 선택 > 비밀 모드 켜기 > 시작
"회사"는 이용자의 ADID/IDFA를 수집할 수 있습니다. ADID(Android OS)/IDFA(iOS)란 모바일 앱 이용자의 광고 식별 값으로서, 사용자의 맞춤 서비스 제공이나 더 나은 환경의 광고를 제공하기 위한 측정을 위해 수집될 수 있습니다. 이용자는 모바일 단말기의 설정 변경을 통해 ADID/IDFA 수집을 차단·허용할 수 있습니다.
1. Android OS
- 설정 > 보안 및 개인정보 보호 > 개인정보 보호 > 기타 개인정보 설정> 광고 > 광고ID 재설정 또는 광고ID 삭제
2. iOS
- 설정 > 개인정보 보호 및 보안 > 추적 > 앱 추적 허용 해제
제10조정보주체의 권리·의무 및 행사방법에 관한 사항
이용자는 “회사”에 대해 언제든지 개인정보 열람·정정·삭제·처리정지 및 철회 요구, 자동화된 결정에 대한 거부 또는 설명 요구 등의 권리를 행사할 수 있습니다.
권리 행사는 “회사”에 대해 「개인정보 보호법 시행령」 제41조 제1항에 따라 서면, 전자우편, 모사전송(FAX)를 통해 하실 수 있으며, “회사”는 이에 대해 지체없이 조치하겠습니다.
권리 행사는 이용자의 법정대리인이나 위임을 받은 자 등 대리인을 통하여 하실 수도 있습니다. 이 경우 「개인정보 처리 방법에 관한 고시」 별지 제11호 서식에 따른 위임장을 제출하셔야 합니다..
이용자가 개인정보 열람 및 처리 정지를 요구할 권리는 「개인정보 보호법」 제35조 4항 및 제37조 2항에 의하여 제한될 수 있습니다.
다른 법령에서 그 개인정보가 수집 대상으로 명시되어 있는 경우에는 해당 개인정보의 삭제를 요구할 수 없습니다.
“회사”는 권리 행사를 한 자가 본인이거나 정당한 대리인인지를 확인합니다.
제11조개인정보보호책임자 및 고충사항 처리 부서에 관한 사항
“회사”는 개인정보 처리에 관한 업무를 총괄해서 책임지고 개인정보 처리와 관련한 이용자의 불만처리 및 피해구제 등을 위하여 아래와 같이 개인정보 보호책임자를 지정하고 있습니다.
| 구분 | ||
|---|---|---|
| 담당자(부서) | 이효섭 | Infra & Security |
| 연락처 | 1670-4565(고객센터를 통해 개인정보 담당부서 연결 요청) | |
제12조정보주체의 권익침해에 대한 구제방법
이용자는 개인정보 침해로 인한 분쟁 해결, 상담 등 피해 구제를 받고자 하는 경우 아래의 기관에 신고·상담 등을 신청하실 수 있습니다.
- 연락처 : (국번없이) 1833-6972
- 홈페이지 : www.kopico.go.kr
- 연락처 : (국번없이) 118
- 홈페이지 : privacy.kisa.or.kr
- 연락처 : (국번없이) 182
- 홈페이지 : ecrm.police.go.kr
제13조만 14세 아동의 개인정보 처리 제한
"회사"는 법정대리인의 동의가 필요한 만 14세 미만 아동의 회원가입은 받고 있지 않습니다.
제14조개인정보처리방침의 변경에 관한 사항
본 개인정보처리방침은 2026.07.06부터 적용됩니다.
이전 개인정보처리방침은 웹 페이지 최상단에서 확인하실 수 있습니다.
GmoneyTrans Co., Ltd. (hereinafter the “Company”) complies with the Personal Information Protection Act and other relevant laws and regulations to protect the freedom and rights of data subjects, and lawfully processes and securely manages personal information. Accordingly, pursuant to Article 30 of the Personal Information Protection Act, the Company hereby establishes and discloses the following Privacy Policy to inform data subjects of the procedures and standards for processing personal information and to handle related grievances promptly and smoothly.
Table of Contents
Article 1Purpose of Processing Personal Information
The Company processes personal information for the purposes set out in each of the following items. The personal information processed shall not be used for any purpose other than the following, and should the purpose of use change, the Company will obtain prior consent.
The Company processes personal information for the purposes of identity verification and authentication in connection with membership registration and the provision of membership services, prevention of fraudulent use of services, various notices and notifications, and grievance handling.
The Company processes personal information for the purpose of providing domestic and overseas remittance services, card services, and open banking services.
The Company processes personal information for the purpose of providing daily-life convenience services such as transit card top-up, domestic and overseas mobile top-up, and utility bill payment.
Article 2Categories of Personal Information Processed
The Company collects and uses users’ personal information on the following legal grounds.
① Personal information processed without the user’s consent
The Company processes the following personal information items without the user’s consent.
| Legal Basis | Purpose | Personal Information Processed |
|---|---|---|
| Personal Information Protection Act, Article 15(1)2 and (1)6 (Collection and Use of Personal Information); Electronic Financial Transactions Act, Article 21(1) (Duty to Ensure Security) | Tracing and searching electronic financial transaction details, establishing security policies, and preventing incidents | Device identification information (UUID), mobile phone model, OS type (Android OS, iOS), OS version, e-mail, IP address |
| Act on Real Name Financial Transactions and Confidentiality, Article 3(1) (Real Name Financial Transactions) | Real-name verification for financial transactions | Name, unique identification information (resident registration number, alien registration number, passport number), identification document photo (resident registration card, alien registration card, passport) |
| Foreign Exchange Transactions Act, Article 20(4) and (5) (Reporting and Inspection) | Reporting of overseas remittance status (Bank of Korea ORIS) | Remitter identification information (resident registration number / business registration number / passport number), name, account information, remittance date and time, remittance amount (USD-equivalent amount, exchange rate), purpose of remittance (current transaction / capital transaction), beneficiary information (name, nationality, receipt method, receipt number), intermediary institution information |
② Personal information processed with the user’s consent
The Company processes the following personal information items with the user’s consent.
| Service Category | Purpose of Processing | Items Processed | Legal Basis |
|---|---|---|---|
| Membership Registration and Customer Verification | Service registration | Name, email (optional), mobile phone number, referral code (optional) | Personal Information Protection Act, Article 15(1)1 (Collection and Use of Personal Information) |
| Mobile phone identity verification | Name, date of birth, gender, mobile phone number, mobile carrier, Connecting Information (CI), Duplication Information (DI) | Personal Information Protection Act, Article 15(1)1 | |
| Non-face-to-face real-name verification using facial recognition technology | Original facial information, facial feature information | Personal Information Protection Act, Article 23(1)1 (Restriction on Processing Sensitive Information); Act on Reporting and Using Specified Financial Transaction Information, Article 5-2 (Customer Due Diligence Obligations of Financial Companies, etc.) | |
| Customer verification | ◉ Resident Registration Card Information Resident registration card photo (front/back), name, resident registration number, date of birth, gender, ID issuance date ◉ Alien Registration Card Information Alien registration card photo (front/back), name, alien registration number, date of birth, gender, nationality, ID issuance date, visa type ◉ Passport Information Passport photo, name, passport number, date of birth, gender, nationality, passport issuance date, passport expiry date ◉ Additional Customer Verification Information Address, postal code, occupation, purpose of account use, source of funds, company name | Act on Reporting and Using Specified Financial Transaction Information, Article 5-2 (Customer Due Diligence) | |
| Overseas Remittance Service | Use of overseas remittance service | ◉ Remitter Information Name, Date of Birth, Mobile Phone Number, Address, Remitting Country, Relationship with Beneficiary, Purpose of Remittance, ID Type, ID Number, Nationality, Occupation, Source of Funds, Beneficiary Bank Name, Account Number, Date of Issue, Country of Birth Code, Gender, Customer ID, GCash Wallet Number, Date of Expiry, Country of Residence, Remitting Country Code, Country of Issue, Place of Birth ◉ Beneficiary Information Name, Account Number, Mobile Phone Number, Address, MoMo Wallet Number, Nationality, Beneficiary Bank Code, Beneficiary Bank Name, UzCard / Humo Card Number, Visa / Master Card Number, Region Code, BKash Number, Date of Birth, Country of Birth Code, Alipay Wallet Name, Alipay Wallet Number, Relationship with Beneficiary, Account Type, Rocket Wallet Number, Remitting Country, Beneficiary Country Code, IBAN Number, ID Type, Date of Expiry, Gender, ID Number, IFSC Number, Nagad Wallet Number, WeChat Wallet Number, Beneficiary Bank, Beneficiary Bank Branch Code | Personal Information Protection Act, Article 28-8(1)1 (Cross-Border Transfer of Personal Information); Act on Reporting and Using Specified Financial Transaction Information, Article 5-3 (Provision of Information in Wire Transfers) |
| Card Service | GmoneyCard issuance | Unique identification information (resident registration number, alien registration number, passport number), name, gender, address, address image (optional), mobile phone number, foreigner classification, email | Enforcement Decree of the Electronic Financial Transactions Act, Article 31(3) (Processing of Sensitive Information and Unique Identification Information) |
| Card insurance enrollment | Customer number, enrolled GmoneyCard product name, card registration date, gender, nationality, address, mobile phone number, GmoneyCard card number | Personal Information Protection Act, Article 15(1)1 | |
| Open Banking Service | Use of open banking service | Name, date of birth, financial institution name, account number, email, Connecting Information (CI) | Personal Information Protection Act, Article 15(1)1 |
| Daily-Life Convenience Service | Use of transit card top-up service | Customer number, transit card number | Personal Information Protection Act, Article 15(1)1 |
| Use of domestic mobile top-up service | Name, nationality, mobile phone number, top-up amount | Personal Information Protection Act, Article 15(1)1 | |
| Use of overseas mobile top-up service | Country, name, mobile phone number, mobile carrier, product name, top-up amount | Personal Information Protection Act, Article 15(1)1 | |
| Use of overseas utility bill payment service | Utility account number, recipient mobile phone number, payment country, payment institution, payment item, payment amount | Personal Information Protection Act, Article 15(1)1 | |
| Use of game gift card (gifticon) purchase service | Product name, mobile phone number | Personal Information Protection Act, Article 15(1)1 | |
| Use of tax refund application form preparation support service | Name, alien registration number, attribution year, workplace name, business registration number, total salary for the relevant year, determined tax amount, determined tax amount on the withholding receipt, tax payable within the filing deadline, bank name, account number, employment type, employment date, date of birth, reduction/exemption period, tax item, attribution year/month, refund amount, payment date, paying bank, refund account number | Personal Information Protection Act, Article 15(1)1; Personal Information Protection Act, Article 24(1)1 (Restriction on Processing Unique Identification Information) | |
| Use of shopping mall service | Customer number, name, address, address image (optional), mobile phone number, date of birth, nationality | Personal Information Protection Act, Article 15(1)1 |
Article 3Period of Processing and Retention of Personal Information
The Company processes and retains personal information within the retention/use period prescribed by law or the retention/use period consented to by the user at the time of collection.
Retained until membership withdrawal. However, where transaction records exist or customer verification has been completed, the information is retained for 5 years after withdrawal.
Retained for 5 years from the completion of service provision.
Retained for 5 years from the completion of service provision.
Notwithstanding the above, where there is an obligation to retain personal information under relevant laws, the information is retained for the period specified in such laws.
| Category | Relevant Law | Retention Period |
|---|---|---|
| Customer verification records | Act on Reporting and Using Specified Financial Transaction Information, Article 5-2 (Customer Due Diligence) | 5 years |
| Records on electronic financial transactions | Electronic Financial Transactions Act, Article 22 (Generation, Preservation and Destruction of Electronic Financial Transaction Records); Enforcement Decree of the Electronic Financial Transactions Act, Article 12 (Retention Period, Method of Preservation, and Procedures and Methods of Destruction of Electronic Financial Transaction Records) | 5 years |
| Records on contracts or withdrawal of subscription | Act on Consumer Protection in Electronic Commerce, Article 6 | 5 years |
| Records on payment and supply of goods, etc. | Enforcement Decree of the Act on Consumer Protection in Electronic Commerce, Article 6 | 5 years |
| Records on consumer complaints or dispute resolution | Enforcement Decree of the Act on Consumer Protection in Electronic Commerce, Article 6 | 3 years |
| Records on labeling and advertising | Enforcement Decree of the Act on Consumer Protection in Electronic Commerce, Article 6 | 6 months |
Article 4Procedures and Methods for Destruction of Personal Information
When personal information becomes unnecessary due to the expiration of the retention period, the achievement of the processing purpose, etc., the Company destroys the relevant personal information without delay.
Where personal information must continue to be preserved pursuant to other laws even though the consented retention period has elapsed or the processing purpose has been achieved, the Company transfers such personal information to a separate database (DB) or stores it in a different storage location.
The procedures and methods for destroying personal information are as follows.
1. Destruction procedure - The Company selects the personal information for which a cause for destruction has arisen and destroys it upon approval of the Privacy Officer.
2. Destruction method - Personal information recorded/stored in electronic file format: destroyed so that the records cannot be reproduced - Personal information recorded/stored on paper documents: destroyed by shredding or incineration
Article 5Provision of Personal Information to Third Parties
For the smooth provision of services, the Company provides personal information only to the minimum extent necessary, with the user’s consent, pursuant to Article 17(1)1 of the Personal Information Protection Act, in the following cases.
| Recipient | Purpose of Provision | Items Provided | Retention and Use Period by Recipient |
|---|---|---|---|
| Korea Financial Telecommunications & Clearings Institute (KFTC) | Use of open banking service | Name, date of birth, financial institution name, account number, email, Connecting Information (CI) | 5 years from the transaction date |
| BC Card | GmoneyCard issuance and delivery | Name, mobile phone number, resident registration number, passport number, alien registration number, delivery address, account number, card PIN, email, gender, nationality | 5 years from the transaction date |
| Meritz Fire & Marine Insurance | Card insurance enrollment | Customer number, enrolled GmoneyCard product name, card registration date, gender, nationality, address, mobile phone number, GmoneyCard card number | 5 years from the transaction date |
| QQ Trade | Domestic mobile top-up | Mobile phone number, top-up amount | 5 years from the transaction date |
| Gromise Co., Ltd. | Use of shopping mall | Customer number, name, address, address image (optional), mobile phone number, date of birth, nationality | Until membership withdrawal |
| Korea Railroad Corporation (KORAIL) | Transit card top-up service | Customer number, transit card number | 5 years from the transaction date |
For the smooth provision of services, the Company provides personal information only to the minimum extent necessary, with the user’s consent, pursuant to Article 17(1)1 of the Personal Information Protection Act, in the following cases.
| Relevant Basis | Recipient | Purpose of Provision | Items Provided | Retention and Use Period |
|---|---|---|---|---|
| Foreign Exchange Transactions Act, Article 20(4) and (5) (Reporting and Inspection) | Bank of Korea | Reporting of overseas remittance status (Bank of Korea ORIS) | Remitter identification information (resident registration number / business registration number / passport number), name, account information, remittance date and time, remittance amount (USD-equivalent amount, exchange rate), purpose of remittance (current transaction / capital transaction), beneficiary information (name, nationality, receipt method, receipt number), intermediary institution information | 5 years |
Cases in which personal information is provided to a third party overseas are described in “Article 7 (Cross-Border Transfer of Personal Information)”.
Article 6Outsourcing of Personal Information Processing
For the smooth processing of personal information, the Company outsources personal information processing tasks as follows.
| Outsourcee (Trustee) | Outsourced Task |
|---|---|
| COOCON | ID authenticity verification service Account holder real-name verification service Virtual account intermediary service Deposit transfer service CO-ATM service ARS authentication Mobile certificate inquiry service |
| Korea Credit Bureau (KCB) | Mobile phone identity verification service |
| BC Card | GmoneyCard transaction approval, cancellation and intermediation, and merchant settlement |
| MF Company | SMS dispatch service |
| NIT Soft | SMS dispatch service |
| Galaxia Money Tree | Convenience store barcode payment service Convenience store barcode deposit service Hyosung ATM deposit service |
| TheCheat | Fraudulent-transaction inquiry service |
| Daou Technology | Email dispatch service |
| Korea Financial Telecommunications & Clearings Institute (KFTC) | ID authenticity verification service Integrated daily withdrawal limit inquiry service |
When concluding an outsourcing agreement, pursuant to Article 26 of the Personal Information Protection Act, the Company specifies in documents such as the agreement the matters concerning the prohibition of processing personal information for purposes other than performing the outsourced task, technical and administrative protective measures, restrictions on re-outsourcing, management and supervision of the trustee, and liability such as damages, and supervises whether the trustee processes personal information securely.
Pursuant to Article 26(6) of the Personal Information Protection Act, where a trustee re-outsources the Company’s personal information processing tasks, the Company’s consent is obtained.
Should the content of the outsourced task or the trustee change, the Company will disclose this through this Privacy Policy without delay.
Article 7Cross-Border Transfer of Personal Information
The Company provides personal information collected from service users overseas as set out below. Because cross-border transfer is, in principle, required for overseas remittance, utility bill payment, and voucher purchase, you will not be able to use the services if you refuse the cross-border transfer. If you do not wish to have your personal information transferred overseas, you may withdraw your membership through the app (Menu - My Information - Membership Withdrawal) or request withdrawal through the Customer Center (1670-4565).
The status of cross-border transfer of personal information can be found at the link below.
※ List of cross-border transfer personal information and company
Article 8Measures to Ensure the Security of Personal Information
The Company takes the following measures to ensure the security of personal information.
- The Company establishes and operates an internal management plan for the safe management of personal information.
- The Company conducts regular training for employees who process personal information to enhance their awareness of personal information protection.
- The Company grants minimum access rights to systems that process personal information and controls external access using an intrusion prevention system.
- The Company encrypts and stores/manages users’ personal information, such as unique identification information and account numbers, using a secure encryption algorithm.
- The Company installs antivirus software to prevent damage caused by viruses.
- The Company operates an access control system so that only authorized persons may access the locations where users’ personal information is stored.
Article 9Installation and Operation of Automatic Personal Information Collection Devices and Refusal Thereof
The Company uses “cookies” that store and frequently retrieve usage information in order to provide individualized services and convenience to users. A cookie is a small piece of information that the server operating the website sends to the user’s browser; it is stored on the user’s computer or mobile device and is automatically transmitted from the user’s browser to the server upon accessing the website. Users may refuse cookies through their browser option settings.
1. How to block cookies in a web browser - Chrome: Select the “⁝” icon at the top right of the browser > New Incognito Window (Shortcut: Ctrl+Shift+N) - Edge: Select the “⋯” icon at the top right of the browser > New InPrivate Window (Shortcut: Ctrl+Shift+N)
2. How to block cookies in a mobile browser - Chrome: Select the “⁝” icon at the top right of the mobile browser > New Incognito Tab - Safari: Mobile device Settings > Apps > Safari > Advanced > Block All Cookies - Samsung Internet: Select the “Tabs” icon at the bottom of the mobile browser > Turn on Secret Mode > Start
The Company may collect users’ ADID/IDFA. ADID (Android OS)/IDFA (iOS) is an advertising identifier for mobile app users that may be collected for measurement purposes in order to provide customized services or a better advertising environment. Users may block or allow the collection of ADID/IDFA by changing their mobile device settings.
1. Android OS - Settings > Security and Privacy > Privacy > Other Privacy Settings > Ads > Reset Advertising ID or Delete Advertising ID
2. iOS - Settings > Privacy & Security > Tracking > Turn off Allow Apps to Request to Track
Article 10Rights and Obligations of Data Subjects and Methods of Exercise
Users may exercise their rights against the Company at any time, including the right to request access to, correction, deletion, and suspension of processing of personal information, withdrawal of consent, and refusal of or an explanation regarding automated decisions.
Rights may be exercised against the Company in writing, by email, or by facsimile (FAX) pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.
Rights may also be exercised through an agent, such as the user’s legal representative or a duly authorized person. In this case, you must submit a power of attorney in the form of Annex No. 11 of the Notification on Methods of Processing Personal Information.
The user’s right to request access to and suspension of processing of personal information may be restricted pursuant to Articles 35(4) and 37(2) of the Personal Information Protection Act.
Where the collection of personal information is specified as mandatory under other laws, you may not request the deletion of such personal information.
The Company verifies whether the person exercising the rights is the data subject in person or a legitimate agent.
Article 11Privacy Officer and Department in Charge of Grievance Handling
The Company designates a Privacy Officer as set out below to take overall responsibility for personal information processing and to handle users’ complaints and provide remedies for damage related to personal information processing.
| Category | ||
|---|---|---|
| Officer (Department) | Lee Hyoseop | Infra & Security |
| Contact | 1670-4565 (request connection to the privacy department through the customer center) | |
Article 12Remedies for Infringement of Data Subjects’ Rights
If users wish to obtain relief for damage—such as dispute resolution or counseling—arising from infringement of personal information, they may file a report or seek counseling with the following organizations.
- Contact: 1833-6972 (no area code)
- Website: www.kopico.go.kr
- Contact: 118 (no area code)
- Website: privacy.kisa.or.kr
- Contact: 182 (no area code)
- Website: ecrm.police.go.kr
Article 13Restriction on Processing Personal Information of Children Under the Age of 14
The Company does not accept membership registration of children under the age of 14 who require the consent of a legal representative.
Article 14Changes to the Privacy Policy
This Privacy Policy applies from July 6, 2026.
The previous Privacy Policy can be found at the top of this web page.
지머니트랜스㈜(이하 “회사”)는 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 등 관계 법령에 따라 정보주체의 연계정보(CI)를 안전하게 처리하기 위하여 다음과 같이 연계정보 처리에 관한 사항을 수립·공개합니다.
제1조연계정보의 처리 목적
지머니트랜스㈜(이하 “회사”)는 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 제23조의5 제1항에 따라 다음의 목적으로 본인확인기관으로부터 연계정보를 제공받아 수집·이용하고 있습니다.
- 전자금융거래 또는 연계된 서비스 이용에 따른 본인확인
제2조연계정보의 처리 및 보유 기간
회사는 제1조의 목적에 부합하는 계약의 체결 및 이행을 위하여 연계정보를 수집·이용하며, 동의받은 보유·이용기간 동안 연계정보를 보유하고 이용합니다.
제3조연계정보의 제3자 제공 및 위탁
회사는 「정보통신망 이용촉진 및 정보보호 등에 관한 법률」 제23조의5 제4항에 따라 정보주체에게 별도로 동의를 받아 연계정보를 제3자 제공하고 있습니다.
상세한 위탁 및 제공 현황은 회사의 개인정보처리방침에서 확인할 수 있습니다.
제4조연계정보의 안전조치
회사는 「정보통신망법」 제23조의6 제2항 및 「개인정보 보호법」 제29조에 따라 정보주체의 연계정보를 안전하게 처리하기 위하여 기술적·관리적 안전조치를 수행하고 있습니다.
연계정보의 안전한 처리를 위한 내부관리계획 수립
연계정보를 인터넷망 구간으로 송·수신하는 경우 안전한 암호화 알고리즘으로 암호화
연계정보 취급인원 최소화 및 연계정보 취급인원에 대한 정기적인 교육 수행
연계정보 분실·도난 등의 침해사고 발생 시 대응 계획 수립 및 시행
제5조정보주체의 권리행사 방법 및 절차
정보주체는 연계정보 처리에 관한 사항의 열람, 정정, 삭제, 처리정지 등을 회사의 개인정보처리방침에 따라 요청할 수 있습니다.
제6조침해사고 발생 시 접수 절차
정보주체는 자신의 권리가 침해당했거나 연계정보의 침해사고가 발생하는 경우 회사의 개인정보처리방침에 따라 문의 또는 요청할 수 있습니다.
GmoneyTrans Co., Ltd. (hereinafter the “Company”) establishes and discloses the following matters concerning the processing of Connecting Information (CI) in order to process data subjects’ Connecting Information safely in accordance with the Act on Promotion of Information and Communications Network Utilization and Information Protection and other relevant laws.
Table of Contents
Article 1Purpose of Processing Connecting Information
GmoneyTrans Co., Ltd. (hereinafter referred to as the “Company”) collects and uses Connecting Information (CI) received from identity verification agencies for the following purposes, pursuant to Article 23-5(1) of the Act on Promotion of Information and Communications Network Utilization and Information Protection.
- Identity verification in connection with electronic financial transactions or the use of linked services
Article 2Processing and Retention Period of Connecting Information
The Company collects and uses Connecting Information for the purpose of entering into and performing contracts in accordance with the purposes set forth in Article 1, and retains and uses such Connecting Information for the duration of the retention and utilization period for which consent has been obtained.
Article 3Third-Party Provision and Entrustment of Connecting Information
The Company provides Connecting Information to third parties upon obtaining separate consent from data subjects, pursuant to Article 23-5(4) of the Act on Promotion of Information and Communications Network Utilization and Information Protection.
Detailed information regarding the current status of entrustment and third-party provision may be found in the Company’s Privacy Policy.
Article 4Security Measures for Connecting Information
The Company implements technical and administrative security measures to ensure the safe processing of data subjects’ Connecting Information, pursuant to Article 23-6(2) of the Act on Promotion of Information and Communications Network Utilization and Information Protection and Article 29 of the Personal Information Protection Act.
Establishment of an internal management plan for the secure processing of Connecting Information
Encryption of Connecting Information using a secure encryption algorithm when transmitting or receiving such information over internet network segments
Minimization of personnel handling Connecting Information and conduct of regular training for such personnel
Establishment and implementation of a response plan in the event of a security incident involving the loss, theft, or other compromise of Connecting Information
Article 5Methods and Procedures for Exercise of Data Subjects’ Rights
Data subjects may request access to, rectification of, erasure of, or restriction of processing of matters relating to the processing of Connecting Information, in accordance with the Company’s Privacy Policy.
Article 6Procedures for Reporting Security Incidents
In the event that a data subject’s rights are infringed or a security incident involving Connecting Information occurs, the data subject may submit inquiries or requests in accordance with the Company’s Privacy Policy.