Privacy policy
This English version is provided for reference purposes only. In the event of any discrepancy or difference in interpretation between the Korean original and this English translation, the Korean version shall prevail.
PowerCraft (the “Company”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal information of data subjects and to handle related concerns promptly and appropriately. This Policy may be updated from time to time due to changes in laws, guidelines, or the Company’s internal policies, so please check it when you visit the site.
This Policy applies to robopwr.com (the POWERCRAFT online store) operated by PowerCraft. The site www.devicemall.co.kr, operated separately by the Company, is governed by the privacy policy posted on that site. The two sites are operated on different service infrastructures (hosting, payment, and inquiry channels), so their outsourcing arrangements differ and each site maintains its own policy.
Table of contents
- Purposes of processing personal information
- Personal information processed and collection methods
- Processing and retention periods
- Provision of personal information to third parties
- Outsourcing of processing and cross-border transfers
- Destruction procedures and methods
- Rights of data subjects and legal representatives, and how to exercise them
- Right to refuse consent and consequences of refusal
- Security measures
- Cookies and automatic data collection
- Privacy officer and department handling access requests
- Remedies for infringement of rights
- Changes to this Privacy Policy
Article 1 (Purposes of processing personal information)
The Company processes personal information for the following purposes and does not use it for any other purpose. If a purpose of use changes, the Company will take necessary measures such as obtaining separate consent under Article 18 of the Personal Information Protection Act.
- Membership registration and management — maintaining and managing membership, identity verification, preventing fraudulent or unauthorized use, checking purchase history, responding to inquiries, and delivering notices
- Supply of goods or services — receiving orders, processing payments, shipping products, handling withdrawal of orders, returns, exchanges and refunds, and issuing transaction statements and tax invoices
- Responding to quotation and technical inquiries — preparing and replying to quotations for custom battery packs, BMS and power conversion equipment, reviewing requested specifications, technical consultation, and contract- and delivery-related communication
- Complaint handling — verifying the identity of the complainant, confirming the matter, contacting and notifying for fact-finding, and communicating the outcome
- Website operation and security — managing access records necessary for the service, preventing fraudulent use, and analyzing service usage statistics
The Company does not use personal information for marketing or advertising purposes. If it intends to do so in the future, it will obtain separate consent, distinguished from other consents, in accordance with Article 22 of the Personal Information Protection Act, and will revise this Policy and give prior notice.
Article 2 (Personal information processed and collection methods)
1. Membership registration and management
| Category | Items |
|---|---|
| Required | Email address |
| Optional | Name, phone number, address |
- Collection method Entered directly by the data subject on the sign-up and account management screens
- Legal basis Article 15(1)1 (consent) and 15(1)4 (performance of a contract) of the Personal Information Protection Act
- The Company uses the customer account feature of its service platform (Shopify). Member authentication uses a one-time verification code sent by email instead of a password, so the Company does not collect or store member IDs or passwords.
2. Orders, payment and delivery of goods or services
| Category | Items |
|---|---|
| Required | Name, phone number, email, shipping address, order details, payment method and payment approval information |
| Optional | Delivery instructions |
- Collection method Entered directly by the data subject on the order and checkout screens
- Legal basis Article 15(1)4 (performance of a contract) of the Personal Information Protection Act
- Payment information Details of payment instruments such as credit card numbers and bank account numbers are collected and processed directly by the payment service provider, and the Company does not store them. The Company receives and keeps only the information needed to confirm the transaction, such as payment status, payment method type, and approval number.
3. Quotation / custom-build specification inquiries (website form)
| Category | Items |
|---|---|
| Required | Company (organization) name, contact person’s name, phone number, email |
| Optional | Inquiry details and requested specifications (application, voltage and capacity, form factor, installation conditions, etc., as entered) |
- Collection method Entered directly by the data subject in the website inquiry form and submitted
- Legal basis Article 15(1)1 (consent of the data subject) of the Personal Information Protection Act
4. Information generated and collected automatically while using the website
IP address, cookies, access date and time, browser and operating system information, device information, service usage records
- Collection method Generated and collected automatically through the website platform (Shopify) when the data subject accesses the website
- Legal basis Article 15(1)4 (performance of a contract) and 15(1)6 (legitimate interests) of the Personal Information Protection Act
5. Information the Company does not collect
- The Company does not collect or process sensitive information under Article 23 of the Personal Information Protection Act (ideology or beliefs, membership in or withdrawal from a trade union or political party, political opinions, health, sex life, race or ethnicity, genetic information, criminal records, etc.).
- The Company does not collect or process unique identification information under Article 24 of the Act (resident registration number, passport number, driver’s license number, alien registration number).
- The Company’s goods and services are intended primarily for businesses and organizations, and the Company does not collect personal information of children under the age of 14. Children under 14 may not register as members.
- The Company does not make decisions that materially affect the rights or obligations of data subjects through fully automated systems (including systems applying artificial intelligence) under Article 37-2 of the Act.
Article 3 (Processing and retention periods)
As a rule, the Company destroys personal information without delay once the purpose of collection and use has been achieved, and processes and retains personal information only within the retention period required by law or agreed to by the data subject at the time of collection.
| Purpose | Retention period | Basis |
|---|---|---|
| Membership registration and management | Until membership withdrawal (destroyed without delay upon withdrawal, except for the statutory retention items below) | Consent to collection and use |
| Quotation and technical inquiries | Destroyed without delay after one year from completion of the inquiry | Consent to collection and use |
| Records on contracts or withdrawal of offers | 5 years | Article 6, Act on Consumer Protection in Electronic Commerce |
| Records on payment and supply of goods | 5 years | Article 6, Act on Consumer Protection in Electronic Commerce |
| Records on consumer complaints or dispute resolution | 3 years | Article 6, Act on Consumer Protection in Electronic Commerce |
| Records on labeling and advertising | 6 months | Article 6, Act on Consumer Protection in Electronic Commerce |
| Books and supporting documents (tax invoices, transaction statements, etc.) | 5 years | Article 85-3 of the Framework Act on National Taxes; Value-Added Tax Act |
| Website visit (log) records | 3 months | Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement Decree |
- If a contract is still in progress or a dispute is ongoing after the retention period has expired, the information is retained until the matter is concluded and destroyed without delay thereafter.
- Records subject to statutory retention are stored in a separate database for the period required by the relevant laws even after membership withdrawal, and are not used for any purpose other than retention.
Article 4 (Provision of personal information to third parties)
The Company processes personal information only within the scope specified in Article 1, and provides personal information to third parties only where this falls under Articles 17 and 18 of the Personal Information Protection Act, such as with the consent of the data subject or under special statutory provisions.
The Company does not currently provide personal information to any third party. Transfers of personal information to external companies for order processing, payment, or delivery constitute outsourced processing under Article 5, not third-party provision.
However, personal information may be provided in the following cases in accordance with applicable laws:
- Where required by law, or where requested by an investigative agency in accordance with statutory procedures and methods for investigative purposes
- Where the data subject has given prior consent to the provision
Article 5 (Outsourcing of processing and cross-border transfers)
The Company outsources personal information processing as set out below, limited to the minimum information necessary to achieve the relevant purpose.
| Processor (trustee) | Outsourced work | Items transferred | Destination country | Retention and use period |
|---|---|---|---|---|
| Shopify Inc. | Website hosting, customer account management, order and payment processing infrastructure | Member information, order and delivery information, access records | Canada, the United States, and other countries where servers of Shopify and its sub-processors are located | Until termination of the outsourcing contract |
| Google LLC | Receipt and storage of quotation and technical inquiry emails via Google Workspace | Information entered in the quotation form | The United States and other countries where Google’s servers are located | Until termination of the outsourcing contract |
| Korea PortOne Co., Ltd. (PortOne Payments) | Online payment processing and payment authentication | Name, phone number, email, payment information | Republic of Korea | Until termination of the outsourcing contract (including statutory retention periods) |
| Lotte Global Logistics, Ilyang Logistics, and other domestic parcel carriers | Delivery of ordered products | Recipient’s name, phone number, shipping address | Republic of Korea | Until completion of delivery |
- When concluding outsourcing contracts, the Company specifies in the contract documents, pursuant to Article 26 of the Personal Information Protection Act, matters such as the prohibition of processing beyond the outsourced purpose, technical and managerial safeguards, restrictions on sub-outsourcing, supervision of the trustee, and liability for damages.
- If the outsourced work or the trustee changes, the Company will disclose the change through this Privacy Policy without delay.
Notice of cross-border transfers (Article 28-8 of the Act)
Shopify Inc. and Google LLC in the table above are located outside the Republic of Korea, and personal information is transferred abroad for the performance of the outsourced work. The items, countries, trustees, purposes, and retention periods are as shown in the table above, and the transfer method is transmission via information and communications networks.
Data subjects may refuse the cross-border transfer of their personal information under Article 28-8(5) of the Personal Information Protection Act. However, because website operation, customer accounts, order processing, and inquiry handling all depend on these services, refusal will limit your ability to register, order, or submit inquiries through the website. In that case, you may contact us and transact through the channels below.
- Phone +82-2-982-7070 / Fax +82-2-6455-6461 / Email contact@devicemall.co.kr
Article 6 (Destruction procedures and methods)
When personal information becomes unnecessary due to the expiry of the retention period or the achievement of the processing purpose, the Company destroys it without delay (within five days from the date the cause arises).
a. Destruction procedure
Personal information whose retention period has expired is destroyed after confirmation by the privacy officer. Where retention is required by other laws, the information is moved to a separate database (or a separate filing cabinet, for paper records) and is not used for any purpose other than retention.
b. Destruction methods
- Personal information stored in electronic files Member and order information is deleted from the operating platform, and quotation and technical inquiry emails are permanently deleted from the mailbox (including trash and archive folders) using technical methods that prevent recovery
- Personal information printed on paper Shredded or incinerated
Article 7 (Rights of data subjects and legal representatives, and how to exercise them)
- Data subjects may at any time exercise against the Company the rights to access, correct, delete, or suspend the processing of their personal information, to withdraw consent, and to request transmission of their personal information.
- Right to request transmission (data portability) — Under Article 35-2 of the Personal Information Protection Act, data subjects may request that the Company transmit their personal information to themselves or to other personal information controllers or specialized institutions designated under that Article. This right may be exercised within the requirements and scope set by the Act and its Enforcement Decree (information about the data subject processed by computer or similar means and technically capable of transmission, etc.), and the Company will comply with lawful transmission requests absent justifiable grounds.
- Members may directly view and correct their information on the account management screen after logging in, and may also withdraw membership (withdraw consent) themselves. Requests may also be made in writing, by phone, by email, or by fax using the contact details in Article 11, and the Company will act on them without delay.
- If a data subject requests correction or deletion of an error in their personal information, the Company will not use or provide that personal information until the correction or deletion is completed. If incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction without delay so that it can be corrected.
- Rights may be exercised through a legal representative or an authorized agent. In that case, a power of attorney in the form of Annex No. 11 of the Notification on Methods of Personal Information Processing must be submitted.
- Requests for access or suspension of processing may be restricted under Articles 35(4) and 37(2) of the Personal Information Protection Act.
- Deletion cannot be requested for personal information that other laws designate as subject to collection (the statutory retention items in Article 3).
- The Company verifies that the person making a request is the data subject or a legitimate agent.
Article 8 (Right to refuse consent and consequences of refusal)
Data subjects have the right to refuse consent to the collection and use of their personal information. However, refusing consent to the required items below will limit the use of the corresponding services.
- Required items for membership Membership registration and member-only services (such as purchase history) will be unavailable
- Required items for orders and payment Order acceptance and product delivery will be unavailable
- Required items for quotation inquiries Quotation replies, technical consultation, and other inquiry handling will be unavailable
Refusing consent to optional items does not restrict the use of the essential services.
Article 9 (Security measures)
In accordance with Article 29 of the Personal Information Protection Act and Article 30 of its Enforcement Decree, the Company takes the following measures to prevent the loss, theft, leakage, forgery, alteration, or damage of personal information.
a. Managerial measures
- Minimization and training of staff handling personal information Staff handling personal information are limited to the minimum necessary (currently 3 persons) and are kept informed of personal information protection matters.
- Establishment and implementation of an internal management plan, and management of records of granting, changing, and revoking access rights
b. Technical measures
- Access control Access to systems where personal information is stored and processed (Shopify admin, Google Workspace) is granted only to the staff in charge.
- Two-factor authentication (2FA) Two-factor authentication is applied to all systems processing personal information (Shopify and Google Workspace).
- Password management Administrator account passwords are set to combinations that are difficult to guess and are changed periodically. Member authentication uses one-time email verification codes, so member passwords themselves are not stored.
- Separation of payment information Details of payment instruments such as card numbers are processed directly by the payment service provider and are not stored in the Company’s systems.
- Encryption in transit HTTPS (TLS) encryption is applied across the entire website.
- Intrusion prevention and anti-malware The website, order system, and mail system are protected by the intrusion prevention, detection, and anti-malware systems provided by the trustees (Shopify and Google), and access records are kept and reviewed.
c. Physical measures
- Documents and auxiliary storage media containing personal information are kept in locked storage, and access to storage locations is controlled.
Notwithstanding the above measures, the Company is not liable for incidents caused by the data subject’s own negligence or by risks inherent to the Internet. Please manage your account information appropriately.
Article 10 (Installation, operation, and refusal of automatic data collection devices)
a. Purpose of cookies
The Company uses cookies to provide customized services and to understand website usage. A cookie is a small piece of information sent by the server operating the website to the user’s browser and stored on the user’s device. The Company uses cookies for the following purposes:
- Member identification and maintaining login status
- Maintaining shopping cart contents
- Understanding website visits and usage patterns
- Security and prevention of fraudulent use
b. Installation, operation, and refusal of cookies
Users have the right to choose whether to allow cookies. You can allow or refuse all cookies, or delete stored cookies, by adjusting your web browser options.
- Chrome Menu (top right) > Settings > Privacy and security > Third-party cookies
- Microsoft Edge Menu (top right) > Settings > Cookies and site permissions > Manage and delete cookies and site data
- Safari Settings (Preferences) > Privacy > Cookies and website data
- Firefox Settings > Privacy & Security > Cookies and Site Data
If you refuse cookies, you may experience difficulty using some services such as login and the shopping cart.
c. Third-party analytics and advertising tools
The Company currently does not install or operate third-party behavioral data collection, analytics, or advertising tools such as Google Analytics or Meta Pixel on the website. If such tools are introduced in the future, the Company will revise this Policy and give prior notice of the items collected, purposes, retention periods, and refusal methods.
Article 11 (Privacy officer and department handling access requests)
The Company designates the following privacy officer with overall responsibility for personal information processing and for handling complaints and providing remedies to data subjects in relation to personal information processing.
▶ Privacy officer
- Name : Doojin Choi
- Position : CEO
- Phone : +82-2-982-7070
- Fax : +82-2-6455-6461
- Email : master@devicemall.co.kr
▶ Department receiving and handling access requests
- Department : CEO’s Office
- Phone : +82-2-982-7070
- Email : contact@devicemall.co.kr
- Hours : Weekdays 09:00 – 18:00 (KST, closed on weekends and holidays)
Data subjects may direct all personal information inquiries, complaints, and requests for remedies arising from the use of the Company’s services to the privacy officer and the department above. The Company will respond to and handle inquiries without delay.
Article 12 (Remedies for infringement of rights)
Data subjects may apply to the following organizations for dispute resolution or counseling regarding personal information infringements. These organizations are independent of the Company; please contact them if you are not satisfied with the Company’s own handling of your complaint or need further assistance.
| Organization | Role | Phone | Website |
|---|---|---|---|
| Personal Information Infringement Report Center (KISA) | Reporting infringements, counseling | 118 (no area code) | privacy.kisa.or.kr |
| Personal Information Dispute Mediation Committee | Dispute mediation, collective dispute mediation (civil resolution) | 1833-6972 (no area code) | www.kopico.go.kr |
| Cybercrime Investigation Division, Supreme Prosecutors’ Office | Investigation of personal information crimes | 1301 (no area code) | www.spo.go.kr |
| Electronic Cybercrime Report & Management System (ECRM), Korean National Police Agency | Reporting personal information crimes | 182 (no area code) | ecrm.police.go.kr |
In addition, a person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to requests under Articles 35 (access), 36 (correction and deletion), or 37 (suspension of processing) of the Personal Information Protection Act may file an administrative appeal under the Administrative Appeals Act.
- Central Administrative Appeals Commission : Anti-Corruption and Civil Rights Commission, 110 (no area code) / www.simpan.go.kr
Article 13 (Changes to this Privacy Policy)
- This Privacy Policy takes effect on August 4, 2026, and was amended on August 18, 2026. (Amendments: reflection of the data subject’s right to request transmission under Article 35-2, and specification of the delivery trustees)
- If there are additions, deletions, or amendments due to changes in laws, policies, or security technology, the Company will announce the reasons and details on the website from 7 days before the changes take effect. For changes that materially affect the rights of data subjects, notice will be given 30 days in advance.
- Previous versions of this Privacy Policy are available from the Company upon request.
Business information
- Company : PowerCraft (POWERCRAFT)
- CEO : Doojin Choi
- Business registration number : 110-18-45202
- Mail-order business report number : 2017-Seoul Geumcheon-1310
- Address : A-706, Woolim Lions Valley, 168 Gasan digital 1-ro, Geumcheon-gu, Seoul 08507, Republic of Korea
- Phone : +82-2-982-7070 / Fax : +82-2-6455-6461
- Email : contact@devicemall.co.kr
Effective date : August 4, 2026 / Last amended : August 18, 2026
In the event of any difference in interpretation between the Korean original and this English translation, the Korean version shall prevail.