스페이스케이랩(이하 "운영자")은 TripAgit(이하 "서비스") 이용자의 개인정보를 보호하기 위해 개인정보 보호법 등 관계 법령을 준수합니다. 본 방침은 서비스가 실제로 처리하는 개인정보와 외부 서비스 연동을 기준으로 작성됩니다.
| 항목 | 처리 시점 | 목적 |
|---|---|---|
| 이메일 주소, 계정 식별자 | Google 로그인 | 회원 식별, 로그인 및 계정 관리 |
| 여행 제목·날짜·메모·예산 | 여행 생성·편집 | 여행 일정 저장·표시 |
| 장소명·주소·좌표·시간·메모 | 일정 입력 | 일정 및 지도 기능 제공(장소 검색은 Google Places API 이용) |
| 지출 금액·통화·항목·메모·결제자·분담 | 지출 입력 | 여행 지출 관리 |
| 체크리스트 항목·담당자 | 체크리스트 입력 | 여행 준비 관리 |
| 바우처 제목·예약번호·날짜·링크·메모 | 바우처 입력 | 예약정보 관리 |
| 비상연락처 이름·전화번호·메모 | 비상연락처 입력 | 여행 중 비상연락 정보 관리 |
| 동행자 역할·초대 이메일 | 동행자 초대 | 동행자 관련 기능 제공 |
| 코멘트 작성자 이름·본문 | 코멘트 작성 | 공유 여행의 코멘트 기능 제공 |
| 피드백 본문·선택적 연락처·페이지 경로·언어·브라우저 정보·IP 해시 | 피드백 이용 또는 오류 발생 시 자동 전송 | 문의 대응, 오류·품질 개선, 스팸 방지 |
| 접속 IP·User-Agent | 서비스 접속 | 보안, 장애 대응, 호스팅 및 서비스 운영 |
서비스는 비밀번호를 별도로 저장하지 않고 Google OAuth 인증을 이용합니다. 오류 리포트는 이용자가 별도로 입력하지 않아도 서비스 오류 발생 시 자동으로 전송될 수 있으며, 이 경우 오류 메시지·발생 위치·페이지 경로만 전송되고 이용자가 입력한 내용(폼 값 등)은 전송하지 않습니다.
원칙적으로 회원의 개인정보는 회원 계정이 유지되는 동안 처리·보관합니다. 이용자가 여행이나 개별 항목을 삭제하면 서비스의 정상적인 삭제 절차에 따라 삭제합니다. 회원이 계정을 삭제하면 이용자가 소유한 여행 및 관련 하위 데이터는 삭제합니다.
다른 이용자의 여행에 작성한 코멘트는 대화의 맥락을 보존하기 위해 작성자 표시를 "삭제된 사용자" 등으로 변경하여 남길 수 있습니다.
장소 검색에 사용된 Google Places 데이터(이름·주소·좌표)는 Google 정책에 따라 30일 이상 경과 시 백그라운드에서 자동으로 최신화됩니다.
다만 관계 법령에 따라 일정 기간 보존해야 하는 정보가 있는 경우에는 해당 법령에서 정한 기간 동안 보관하며, 그 목적 범위에서만 이용합니다.
서비스에서는 이용자가 비상연락처의 이름·전화번호 또는 동행자의 이메일 주소 등 제3자의 개인정보를 직접 입력할 수 있습니다. 해당 정보를 입력·이용·공유하는 이용자는 관계 법령을 준수하고, 필요한 경우 제3자의 동의를 받는 등 적법한 조치를 취해야 합니다. 운영자는 제3자에게 별도로 동의를 요청하지 않습니다.
비상연락처는 원칙적으로 여행 소유자만 볼 수 있으며, 공유 설정에서 해당 정보의 공유를 선택한 경우에만 공유 링크를 통해 노출될 수 있습니다.
여행 일정은 여행 시기와 장소를 통해 개인의 이동계획이나 자택 부재 가능성을 드러낼 수 있으므로 접근 범위를 최소화합니다.
보유기간이 끝났거나 처리 목적이 달성된 개인정보는 지체 없이 파기합니다. 전자적 파일 형태의 정보는 복구·재생이 어렵도록 삭제하는 방법을 사용하며, 관계 법령에 따라 보존할 필요가 있는 정보는 별도로 분리하여 해당 목적에 한해 보관한 후 파기합니다.
| 권리 | 방법 |
|---|---|
| 열람·정정 | 서비스의 각 화면에서 직접 확인·수정하거나 문의처로 요청 |
| 삭제 | 대시보드 → 설정 → 계정 삭제 또는 개별 데이터 삭제 |
| 데이터 내보내기 | 대시보드 → 설정 → 데이터 내보내기 |
| 공유 중단·범위 축소 | 여행 상세 → 공유 링크 설정에서 범위 변경 또는 링크 재발급 |
법령상 제한되는 경우를 제외하고 정보주체의 권리 행사를 지체 없이 처리합니다. 대리인을 통해 권리를 행사하는 경우 정당한 대리권 확인을 요청할 수 있습니다.
운영자는 이용자의 개인정보를 판매하거나 광고 목적으로 제3자에게 제공하지 않습니다. 다만 이용자가 외부 사업자와 직접 거래하거나 공유 기능을 이용하는 경우에는 이용자의 선택에 따라 필요한 정보가 해당 제3자에게 제공될 수 있습니다.
| 제공받는 자 | 제공되는 정보 | 목적 |
|---|---|---|
| 공유 링크를 통해 접근한 사람 | 이용자가 공유하도록 설정한 여행 정보 | 여행 공유 |
| 이용자가 선택한 외부 예약·제휴 사업자 | 외부 서비스 이용 과정에서 이용자가 직접 입력하거나 전달을 선택한 정보 | 예약·구매 등 외부 거래 |
서비스 운영을 위해 개인정보 처리를 외부 서비스 제공자에게 위탁하거나 외부 API를 통해 개인정보 또는 서비스 이용 관련 정보가 전송될 수 있습니다. 실제 처리 범위는 기능별로 필요한 최소한의 범위로 제한합니다.
| 수탁자·외부 서비스 | 처리 정보 | 목적 |
|---|---|---|
| Supabase | 회원 계정 정보 및 서비스 저장 데이터 | 데이터베이스·인증·서비스 운영 |
| Cloudflare | 접속 IP, User-Agent, 페이지 조회 관련 정보 | 호스팅·CDN·서비스 운영 및 분석 |
| Google Maps Platform | 장소 검색어, 좌표 등 API 요청 정보 | 지도·장소 검색 |
| Google Sign-In | 이메일 주소, 계정 식별자 | Google OAuth 로그인 |
| Mapbox | 좌표 등 필요한 API 요청 정보 | 이동시간 계산 및 지도 대체 기능 |
| OpenStreetMap Nominatim | 검색어, 좌표 등 필요한 API 요청 정보 | 장소 검색 대체 기능 |
| Open-Meteo | 좌표, 날짜 등 필요한 API 요청 정보 | 날씨 정보 |
| open.er-api.com | 통화 코드 등 필요한 요청 정보 | 환율 정보 |
| Wikidata / Wikimedia Commons | 도시명 등 | 여행지 이미지·정보 제공 |
| Wikipedia | 도시명, 좌표 등 | 여행지 정보 제공 |
| Google Fonts / jsDelivr | 파일 요청에 따른 접속 정보 | 글꼴·라이브러리 제공 |
Supabase 데이터베이스의 프로젝트 리전은 ap-northeast-2입니다. 다만 외부 서비스는 제공자의 글로벌 네트워크·서버를 통해 요청을 처리할 수 있으므로 국외에서 정보가 처리되거나 이전될 수 있습니다.
서비스는 글로벌 외부 서비스와의 연동 과정에서 개인정보 또는 개인정보와 결합될 수 있는 정보가 국외로 이전될 수 있습니다. 국외 이전이 발생하는 경우 개인정보 보호법에서 정한 적법한 이전 요건을 적용하고, 이 방침을 통해 이전 관련 사항을 공개합니다.
| 이전 대상 | 이전 국가 | 이전 항목 | 목적 | 이전 시점·방법 |
|---|---|---|---|---|
| 미국 등 Google의 글로벌 처리 인프라 소재국 | Google 로그인 및 지도·장소 검색에 필요한 정보 | 로그인·지도·장소 검색 | 해당 기능 이용 시 네트워크를 통해 전송 | |
| Cloudflare | 미국 등 Cloudflare의 글로벌 네트워크 처리 지역 | 접속 IP, User-Agent 등 | 호스팅·CDN·서비스 운영 | 서비스 접속 시 자동 전송 |
| Mapbox | 미국 등 Mapbox가 제공하는 글로벌 처리 지역 | 좌표 등 API 요청 정보 | 지도·이동시간 기능 | 해당 기능 이용 시 전송 |
| 기타 외부 API 제공자 | 각 제공자의 서버 소재 국가 | 각 API 기능에 필요한 최소 정보 | 날씨·환율·여행정보 등 | 해당 기능 이용 시 전송 |
위 표의 국가 정보는 각 제공자의 인프라 변경에 따라 달라질 수 있습니다. 정확한 국가, 법적 이전 근거 및 제공자의 최신 개인정보 처리 조건은 실제 연동 계약과 각 제공자의 최신 정책을 기준으로 정기적으로 확인하여 갱신합니다.
서비스는 Google Maps Platform을 이용합니다. Google 지도 관련 서비스에는 Google의 관련 약관 및 개인정보처리방침이 함께 적용될 수 있습니다.
서비스는 광고 목적의 쿠키를 사용하지 않습니다. 서비스 제공 및 이용자 환경 설정을 위해 브라우저 저장소를 사용할 수 있습니다.
| 저장소 | 내용 및 목적 |
|---|---|
| localStorage | 테마·언어 선택, 마지막으로 본 여행의 오프라인 스냅샷 등 |
| sessionStorage | 로그인 없이 이용하는 게스트 모드의 임시 데이터 |
| Supabase 인증 토큰 | 로그인 상태 유지 |
| Service Worker 캐시 | 오프라인 이용을 위한 정적 파일 캐시 |
Cloudflare Web Analytics 등 외부 분석 기능을 사용할 수 있으며, 해당 기능의 쿠키 사용 여부와 처리 방식은 제공자의 최신 정책에 따릅니다.
서비스는 만 14세 미만 아동을 주된 대상으로 하지 않으며, 해당 연령대의 개인정보를 고의로 수집하지 않습니다. 만 14세 미만 아동의 개인정보가 법적 근거 없이 제공된 사실을 알게 된 경우 문의처로 알려주시기 바랍니다.
| 구분 | 내용 |
|---|---|
| 개인정보 보호책임자 | 스페이스케이랩 대표 |
| 이메일 | [email protected] |
| 문의 방법 | 이메일 또는 서비스 내 "의견 보내기" |
개인정보 침해에 관한 신고나 상담은 개인정보침해신고센터(국번없이 118) 등 관계 기관을 이용할 수 있습니다.
법령, 서비스 또는 개인정보 처리 방식의 변경이 있는 경우 변경 내용을 반영하여 본 방침을 개정합니다. 중요한 변경이 있는 경우 시행일 및 변경 내용을 서비스 내 또는 본 페이지를 통해 알립니다.
이 개인정보처리방침은 2026-09-11부터 적용됩니다.
SpaceKLab (the "Operator") complies with applicable privacy laws, including Korea's Personal Information Protection Act, to protect users of TripAgit (the "Service"). This policy describes the personal data actually processed by the Service and its external integrations.
| Data | When | Purpose |
|---|---|---|
| Email address, account identifier | Google sign-in | Account identification and login |
| Trip title, dates, notes, budget | Creating/editing a trip | Trip storage and display |
| Place name, address, coordinates, time, notes | Adding itinerary items | Itinerary and map features (place search uses the Google Places API) |
| Expense amount, currency, item, notes, payer, split | Adding expenses | Expense management |
| Checklist item, assignee | Adding checklist items | Trip preparation |
| Voucher title, confirmation number, date, link, notes | Adding vouchers | Booking-information management |
| Emergency contact name, phone, notes | Adding emergency contact | Emergency contact management |
| Companion role and invitation email | Inviting a companion | Companion features |
| Comment author name and body | Posting comments | Comments on shared trips |
| Feedback, optional contact, page path, language, browser information, IP hash | Feedback, or sent automatically when an error occurs | Support, quality improvement and spam prevention |
| Access IP and User-Agent | Service access | Security, troubleshooting, hosting and operation |
We do not store a separate password and use Google OAuth authentication. Automatic error reports may be sent without any action from you when the Service encounters an error; in that case only the error message, its location, and the page path are sent — never content you typed into a form.
We generally retain member data while the account remains active. When a user deletes a trip or item, it is deleted through the Service's deletion process. When an account is deleted, trips owned by that member and related underlying data are deleted.
Comments posted on another user's trip may remain with the author label changed to "deleted user" to preserve conversation context.
Google Places data used for search (name, address, coordinates) is automatically refreshed in the background if it is more than 30 days old, per Google's policy.
Data that must be retained under applicable law is kept for the legally required period and used only for that purpose.
Users may enter third-party information such as emergency-contact details or a companion's email. Users must comply with applicable law and, where required, obtain consent or take other lawful measures before entering, using or sharing such information. The Operator does not separately request consent from the third party.
Emergency-contact information is generally visible only to the trip owner and may be exposed through a share link only when the owner enables the relevant sharing option.
Itineraries may reveal travel timing and location and potentially the absence of a person from home. We therefore minimize access.
Personal data is destroyed without undue delay when the retention period ends or the processing purpose is achieved. Electronic files are deleted in a manner designed to prevent recovery. Data retained under law is segregated and destroyed after the legal retention period.
| Right | How |
|---|---|
| Access / correction | Edit directly in the Service or contact us |
| Deletion | Dashboard → Settings → Delete account, or delete individual data |
| Data export | Dashboard → Settings → Export my data |
| Stop/reduce sharing | Trip detail → Share settings, or reissue the link |
We process requests without undue delay except where restricted by applicable law.
We do not sell personal data or disclose it to third parties for advertising. Information may be disclosed when a user chooses to use sharing features or transact directly with an external provider.
| Recipient | Data | Purpose |
|---|---|---|
| People accessing a shared link | Trip information selected for sharing | Trip sharing |
| External booking/affiliate provider selected by the user | Information the user chooses to enter or transmit | Booking or purchase |
To operate the Service, personal data or service-use information may be processed by external providers or transmitted through external APIs. Processing is limited to what is necessary for each function.
| Provider | Information | Purpose |
|---|---|---|
| Supabase | Account information and stored Service data | Database, authentication and operation |
| Cloudflare | IP, User-Agent and page-view information | Hosting, CDN, analytics and operation |
| Google Maps Platform | Search terms, coordinates and required API request data | Maps and place search |
| Google Sign-In | Email and account identifier | OAuth login |
| Mapbox | Coordinates and required API request data | Travel-time and fallback map features |
| OpenStreetMap Nominatim | Search terms, coordinates and required API request data | Fallback place search |
| Open-Meteo | Coordinates and dates | Weather |
| open.er-api.com | Currency codes | Exchange rates |
| Wikidata / Wikimedia Commons | City names | Travel images and information |
| Wikipedia | City names, coordinates | Destination information |
| Google Fonts / jsDelivr | Connection information associated with file requests | Fonts and libraries |
The Supabase project region is ap-northeast-2. External providers may process requests through global infrastructure, so information may be processed or transferred outside Korea.
Because the Service integrates with global external providers, personal data or information that may be combined with personal data may be transferred outside Korea. Where an international transfer occurs, the Operator applies a lawful transfer mechanism under applicable privacy law and discloses the relevant transfer information in this policy.
| Recipient | Location | Data | Purpose | Method |
|---|---|---|---|---|
| The United States and other countries where Google's global processing infrastructure is located | Information required for Google sign-in, maps and place search | Login, maps, place search | Transmitted when the feature is used | |
| Cloudflare | The United States and other Cloudflare global network processing locations | IP, User-Agent and related access information | Hosting, CDN, operation | Automatically transmitted on access |
| Mapbox | The United States and other global processing locations provided by Mapbox | Coordinates and required API data | Maps and travel-time features | Transmitted when the feature is used |
| Other API providers | Server locations designated by each provider | Minimum information required for the API function | Weather, exchange rates and travel information | Transmitted when the feature is used |
Provider infrastructure and processing locations may change. We will update this section when the actual integrations or applicable transfer conditions change.
We use Google Maps Platform. Google's applicable terms and privacy policy may also apply to Google Maps services.
We do not use cookies for advertising. Browser storage may be used to provide the Service and remember user environment settings.
| Storage | Content / Purpose |
|---|---|
| localStorage | Theme/language settings and an offline snapshot of the last trip viewed |
| sessionStorage | Temporary guest-mode data |
| Supabase authentication token | Keeping the user signed in |
| Service Worker cache | Static files for offline use |
External analytics such as Cloudflare Web Analytics may be used. Cookie use and processing depend on the provider's current policy.
The Service is not directed at children under 14 and does not knowingly collect their personal data. If we learn that such data has been provided without an appropriate legal basis, please contact us.
| Role | Contact |
|---|---|
| Privacy Officer | Representative of SpaceKLab |
| [email protected] | |
| Other contact | "Send feedback" in the Service |
For privacy-related complaints or consultations in Korea, users may also contact the Personal Information Infringement Report Center at 118.
We may update this policy when laws, the Service or data-processing practices change. Material changes will be announced through the Service or this page with the effective date.
This Privacy Policy takes effect on September 11, 2026.