Privacy Policy

Privacy Policy | LOTTE RENTAL

Privacy Policy

LOTTE RENTAL Co., Ltd. (hereinafter the "Company") places great importance on the personal data of its online and offline members (hereinafter "Users") in accordance with the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Credit Information Use and Protection Act, the Personal Information Protection Act, and other relevant laws and regulations. Through this Privacy Policy, the Company provides detailed information on how the personal data provided by Users is used, and what measures are taken to protect it.

Article 1 (Status of Personal Data Processing)

① The Company processes Users' personal data for the following purposes. Personal data processed by the Company is not used for any purpose other than those listed below, and if the purpose of processing changes, separate consent will be obtained in accordance with Article 18 of the Personal Information Protection Act.

② Personal data items processed without the data subject's consent

Purpose of CollectionItems CollectedRetention PeriodLegal Basis
Membership service operation Name, mobile phone number, ID, password, email address Until membership withdrawal Article 15(1)(4) of the Personal Information Protection Act
Membership registration (Buyer Plus) Personal data items contained in the business registration certificate document Until membership withdrawal or loss of membership status Article 15(1)(4) of the Personal Information Protection Act
Inquiries about products for sale (1:1 Inquiry) Email address Until membership withdrawal Article 15(1)(4) of the Personal Information Protection Act
Seller membership registration (member management and identity verification, customer inquiry response, payment settlement) Name, date of birth, nationality, mobile phone number, email address (used for receiving electronic tax invoices, buyer consultation, etc.), customer number (assigned by LOTTE RENTAL Co., Ltd. for customer management purposes) Until membership withdrawal or loss of membership status Article 15(1)(4) of the Personal Information Protection Act

③ Personal data items processed with the data subject's consent

Purpose of CollectionItems CollectedRetention PeriodLegal Basis
Processing of personal data for service promotion and sales solicitation Name, phone number, email address, ID Until membership withdrawal or withdrawal of consent Article 15(1)(1) of the Personal Information Protection Act
Seller membership registration (member management and identity verification, customer inquiry response, payment settlement) Name (management/settlement contact), phone number (management/settlement contact), address (management/settlement contact) Until membership withdrawal or loss of membership status Article 15(1)(1) of the Personal Information Protection Act

Article 2 (Procedures and Methods for Destruction of Personal Data)

① The Company destroys personal data without delay once the purpose of collection has been achieved or the retention/use period consented to has expired. However, where records must be retained pursuant to relevant laws such as the Act on Consumer Protection in Electronic Commerce even after the purpose has been achieved or the retention period has expired, such records are retained for the applicable period before destruction.

② Personal data that must be retained for a certain period pursuant to relevant laws is as follows.

Legal BasisPurposePeriod
Act on Consumer Protection in Electronic Commerce, etc. Records on contracts or withdrawal of subscription 5 years
Records on payment and supply of goods, etc.5 years
Records on consumer complaints or dispute resolution3 years
Records on labeling/advertising6 months
Protection of Communications Secrets Act Website visit records 3 months
Framework Act on National Taxes Books and supporting documents on all transactions prescribed by tax law 5 years
Customs Act Import declaration certificates and import transaction contracts (or documents in lieu thereof), data on determination of import goods prices, contracts (or documents in lieu thereof) related to transactions of intellectual property rights falling under any subparagraph of Article 235(1) of the Act 5 years
Export declaration certificates, return declaration certificates, data on determination of export/return goods prices, export/return transaction contracts (or documents in lieu thereof)3 years
Data on bonded cargo entry/exit, cargo manifest data, bonded transport data2 years

③ The procedures and methods for destruction of personal data are as follows.

1) Destruction Procedure

Personal data collected during service use, such as membership registration, is stored for the period prescribed by internal policy and relevant laws after the purpose has been achieved, and is then automatically destroyed by the system. Personal data collected offline (not through the system) is manually destroyed once the retention period has expired or the purpose has been achieved.

2) Destruction Method

Personal data recorded and stored in electronic file form is destroyed using technical methods that render the records unrecoverable, and personal data recorded and stored on paper documents is destroyed by shredding or incineration.

Article 3 (Outsourcing of Personal Data Processing)

① The Company does not currently outsource any personal data processing to third parties. Should outsourcing occur in the future, the Company will disclose the identity of the recipient and the details of the outsourced work through this Privacy Policy, and will notify Users in advance where necessary.

② When entering into an outsourcing contract, the Company specifies in the contract or other documents matters such as the prohibition of processing personal data for purposes other than the performance of the outsourced work, technical and managerial protection measures, restrictions on re-outsourcing, supervision and management of the outsourcing party, and liability for damages, in accordance with Article 26 of the Personal Information Protection Act. The Company supervises whether the outsourcing party processes personal data safely, and requires its prior consent where the outsourcing party intends to re-outsource the Company's personal data processing work.

Article 4 (Provision of Personal Data to Third Parties)

① The Company processes data subjects' personal data only within the scope specified for the stated purpose of processing, and provides personal data to third parties only in cases falling under Articles 17 and 18 of the Personal Information Protection Act, such as with the data subject's consent or pursuant to special provisions of law. Personal data is not provided to third parties in any other case.

② For the smooth provision of services, the Company provides the minimum necessary scope of information in the following cases, with the data subject's consent, pursuant to Article 17(1)(1) of the Personal Information Protection Act.

RecipientPurpose of ProvisionItems ProvidedRecipient's Retention/Use Period
Vehicle export freight forwarders
(Myungsung Shipping, Able Global Logistics Co., Ltd., Phoenix Logistics, CIG Shipping Co., Ltd., East West Marine & Air)
Ocean transport and shipping of vehicles Buyer information (buyer name, nationality, vehicle destination)
Seller information (seller name, seller phone number, seller address)
Destroyed without delay after completion of transport/customs clearance (provided that where a separate retention period is set under relevant laws such as the Customs Act, such law shall apply)

Article 5 (Measures to Ensure the Safety of Personal Data)

① In processing Users' personal data, the Company takes the following measures to ensure that personal data is not lost, stolen, leaked, altered, or damaged.

1) Establishment and Implementation of an Internal Management Plan

  • The Company establishes and implements an internal management plan annually in accordance with the "Standards for Measures to Ensure the Safety of Personal Data."

2) Minimization and Training of Personnel Handling Personal Data

  • The Company limits access to Users' personal data to the minimum number of personnel and conducts regular training. Personnel with minimum access include the following:
    • a. Personnel who directly perform marketing work targeting Users
    • b. The Chief Privacy Officer, staff, and others who perform personal data management duties
    • c. Other personnel for whom the processing of personal data is unavoidable in the course of their duties

3) Access Control over Personal Data

  • The Company controls access to personal data by granting, changing, and revoking access rights to the database systems that process personal data, and controls unauthorized access from outside by using intrusion prevention and detection systems.

4) Encryption of Personal Data

  • Users' personal data is encrypted for storage and management. In addition, the Company uses encryption algorithms and other measures to safely transmit personal data over networks.

5) Retention of Access Records and Prevention of Forgery/Alteration

  • Access records to personal data processing systems are securely retained and managed for two years in accordance with the applicable legal basis.

6) Technical Measures Against Hacking

  • Access records to personal data processing systems are securely retained and managed for two years in accordance with the applicable legal basis.

7) Access Control for Unauthorized Persons

  • The Company designates computer rooms and document storage areas as protected zones and controls access to them.

Article 6 (Installation, Operation, and Refusal of Automatic Personal Data Collection Devices)

① The Company uses "cookies" that store and periodically retrieve usage information in order to provide individualized services and convenience to Users.

② A cookie is a small piece of information sent by the server (http) used to operate the website to the data subject's browser, and is stored on the data subject's PC or mobile device.

③ Users may set their web browser options to allow or block cookies. However, refusing to store cookies may cause difficulty in using customized services.

1) Allowing/Blocking Cookies in Web Browsers

  • a. Chrome: Select "⋮" in the top right of the browser → New Incognito window (shortcut: Ctrl + Shift + N)
  • b. Edge: Select "…" in the top right of the browser → New InPrivate window (shortcut: Ctrl + Shift + N)

2) Allowing/Blocking Cookies on Mobile Browsers

  • a. Chrome: Select "⋮" in the top right of the mobile browser → New Incognito tab
  • b. Safari: Device Settings → Apps → Safari → Advanced → Block All Cookies
  • c. Samsung Internet: Select the "Tabs" icon at the bottom of the mobile browser → Turn on Secret mode → Start

Article 7 (Rights and Obligations of Data Subjects and Legal Representatives, and Methods of Exercising Rights)

① Users may, at any time, exercise their rights against the Company to request access to, correction of, deletion of, or suspension of processing of, and withdrawal of consent to, their personal data, as well as to refuse or request an explanation of automated decisions (hereinafter "Exercise of Rights").

② Exercise of Rights may be made against the Company in writing, by email, by fax, or by other means, pursuant to Article 41(1) of the Enforcement Decree of the Personal Information Protection Act, and the Company will take action without delay.

③ Exercise of Rights may also be made through a legal representative of the data subject or an authorized agent. In this case, a power of attorney in the form prescribed in Annex Form No. 11 of the "Notification on Methods of Processing Personal Data" must be submitted.

④ A data subject's right to request access to and suspension of processing of personal data may be restricted pursuant to Article 35(4) and Article 37(2) of the Personal Information Protection Act.

⑤ Deletion of personal data may not be requested where such personal data is specified as a subject of collection under other laws.

⑥ The Company verifies whether the person exercising rights is the data subject or a legitimate agent.

⑦ Exercise of Rights may be made to the Chief Privacy Officer or the department in charge of personal data affairs, and the Company will endeavor to process the data subject's exercise of rights promptly.

Article 8 (Chief Privacy Officer and Department in Charge of Personal Data Affairs)

① The Company has overall responsibility for personal data processing affairs and has designated a Chief Privacy Officer as follows to handle User complaints and remedy damages related to personal data processing.

1) Chief Privacy Officer
a. Name: Han-min Park
b. Department/Title: Information Security Division / Team Leader
c. Email: privacy_rental@lotte.net
2) Department in Charge of Personal Data Customer Response Services
a. Department: CS Team
b. Contact: +82-2-3404-9734
c. Email: rentalcs@lotte.net

② Users may direct any inquiries, complaints, or requests for remedy relating to personal data protection arising in connection with the use of the Company's services to the Chief Privacy Officer or the relevant department, and the Company will respond to and process such inquiries without delay.

Article 9 (Remedies for Infringement of Data Subjects' Rights)

① Users may apply for dispute resolution or consultation regarding infringement of personal data with the Personal Information Dispute Mediation Committee, the Korea Internet & Security Agency's Personal Information Infringement Report Center, and other relevant organizations. For other reports or consultations regarding personal data infringement, please contact the organizations below.

  • 1) Personal Information Infringement Report Center (privacy.kisa.or.kr / 118, no area code required)
  • 2) Personal Information Dispute Mediation Committee (www.kopico.go.kr / 1833-6972, no area code required)
  • 3) Supreme Prosecutors' Office Cyber Investigation Division (www.spo.go.kr / 1301, no area code required)
  • 4) National Police Agency Cyber Bureau (ecrm.police.go.kr/minwon/main / 182, no area code required)

② The Company strives to guarantee data subjects' right to self-determination of personal data and to provide consultation and remedy for damages arising from personal data infringement. If you need to file a report or receive consultation, please contact the Chief Privacy Officer or the department in charge of personal data affairs.

Article 10 (Amendment of the Privacy Policy)

① This Privacy Policy was amended on August 17, 2026. In the event of any addition, deletion, or amendment of its contents due to changes in government policy or security technology, prior notice will be given through the "Notice" section of the website before such amendment takes effect.

② Previous versions of the Privacy Policy can be viewed by selecting the relevant version at the top of the page.