Privacy policy

This English version is provided for reference purposes only. In the event of any discrepancy or difference in interpretation between the Korean original and this English translation, the Korean version shall prevail.

PowerCraft (the “Company”) establishes and discloses this Privacy Policy in accordance with Article 30 of the Personal Information Protection Act of the Republic of Korea, in order to protect the personal information of data subjects and to handle related concerns promptly and appropriately. This Policy may be updated from time to time due to changes in laws, guidelines, or the Company’s internal policies, so please check it when you visit the site.

This Policy applies to robopwr.com (the POWERCRAFT online store) operated by PowerCraft. The site www.devicemall.co.kr, operated separately by the Company, is governed by the privacy policy posted on that site. The two sites are operated on different service infrastructures (hosting, payment, and inquiry channels), so their outsourcing arrangements differ and each site maintains its own policy.

Table of contents

  1. Purposes of processing personal information
  2. Personal information processed and collection methods
  3. Processing and retention periods
  4. Provision of personal information to third parties
  5. Outsourcing of processing and cross-border transfers
  6. Destruction procedures and methods
  7. Rights of data subjects and legal representatives, and how to exercise them
  8. Right to refuse consent and consequences of refusal
  9. Security measures
  10. Cookies and automatic data collection
  11. Privacy officer and department handling access requests
  12. Remedies for infringement of rights
  13. Changes to this Privacy Policy

Article 1 (Purposes of processing personal information)

The Company processes personal information for the following purposes and does not use it for any other purpose. If a purpose of use changes, the Company will take necessary measures such as obtaining separate consent under Article 18 of the Personal Information Protection Act.

  1. Membership registration and management — maintaining and managing membership, identity verification, preventing fraudulent or unauthorized use, checking purchase history, responding to inquiries, and delivering notices
  2. Supply of goods or services — receiving orders, processing payments, shipping products, handling withdrawal of orders, returns, exchanges and refunds, and issuing transaction statements and tax invoices
  3. Responding to quotation and technical inquiries — preparing and replying to quotations for custom battery packs, BMS and power conversion equipment, reviewing requested specifications, technical consultation, and contract- and delivery-related communication
  4. Complaint handling — verifying the identity of the complainant, confirming the matter, contacting and notifying for fact-finding, and communicating the outcome
  5. Website operation and security — managing access records necessary for the service, preventing fraudulent use, and analyzing service usage statistics

The Company does not use personal information for marketing or advertising purposes. If it intends to do so in the future, it will obtain separate consent, distinguished from other consents, in accordance with Article 22 of the Personal Information Protection Act, and will revise this Policy and give prior notice.

Article 2 (Personal information processed and collection methods)

1. Membership registration and management

Category Items
Required Email address
Optional Name, phone number, address
  • Collection method Entered directly by the data subject on the sign-up and account management screens
  • Legal basis Article 15(1)1 (consent) and 15(1)4 (performance of a contract) of the Personal Information Protection Act
  • The Company uses the customer account feature of its service platform (Shopify). Member authentication uses a one-time verification code sent by email instead of a password, so the Company does not collect or store member IDs or passwords.

2. Orders, payment and delivery of goods or services

Category Items
Required Name, phone number, email, shipping address, order details, payment method and payment approval information
Optional Delivery instructions
  • Collection method Entered directly by the data subject on the order and checkout screens
  • Legal basis Article 15(1)4 (performance of a contract) of the Personal Information Protection Act
  • Payment information Details of payment instruments such as credit card numbers and bank account numbers are collected and processed directly by the payment service provider, and the Company does not store them. The Company receives and keeps only the information needed to confirm the transaction, such as payment status, payment method type, and approval number.

3. Quotation / custom-build specification inquiries (website form)

Category Items
Required Company (organization) name, contact person’s name, phone number, email
Optional Inquiry details and requested specifications (application, voltage and capacity, form factor, installation conditions, etc., as entered)
  • Collection method Entered directly by the data subject in the website inquiry form and submitted
  • Legal basis Article 15(1)1 (consent of the data subject) of the Personal Information Protection Act

4. Information generated and collected automatically while using the website

IP address, cookies, access date and time, browser and operating system information, device information, service usage records

  • Collection method Generated and collected automatically through the website platform (Shopify) when the data subject accesses the website
  • Legal basis Article 15(1)4 (performance of a contract) and 15(1)6 (legitimate interests) of the Personal Information Protection Act

5. Information the Company does not collect

  • The Company does not collect or process sensitive information under Article 23 of the Personal Information Protection Act (ideology or beliefs, membership in or withdrawal from a trade union or political party, political opinions, health, sex life, race or ethnicity, genetic information, criminal records, etc.).
  • The Company does not collect or process unique identification information under Article 24 of the Act (resident registration number, passport number, driver’s license number, alien registration number).
  • The Company’s goods and services are intended primarily for businesses and organizations, and the Company does not collect personal information of children under the age of 14. Children under 14 may not register as members.
  • The Company does not make decisions that materially affect the rights or obligations of data subjects through fully automated systems (including systems applying artificial intelligence) under Article 37-2 of the Act.

Article 3 (Processing and retention periods)

As a rule, the Company destroys personal information without delay once the purpose of collection and use has been achieved, and processes and retains personal information only within the retention period required by law or agreed to by the data subject at the time of collection.

Purpose Retention period Basis
Membership registration and management Until membership withdrawal (destroyed without delay upon withdrawal, except for the statutory retention items below) Consent to collection and use
Quotation and technical inquiries Destroyed without delay after one year from completion of the inquiry Consent to collection and use
Records on contracts or withdrawal of offers 5 years Article 6, Act on Consumer Protection in Electronic Commerce
Records on payment and supply of goods 5 years Article 6, Act on Consumer Protection in Electronic Commerce
Records on consumer complaints or dispute resolution 3 years Article 6, Act on Consumer Protection in Electronic Commerce
Records on labeling and advertising 6 months Article 6, Act on Consumer Protection in Electronic Commerce
Books and supporting documents (tax invoices, transaction statements, etc.) 5 years Article 85-3 of the Framework Act on National Taxes; Value-Added Tax Act
Website visit (log) records 3 months Article 15-2 of the Protection of Communications Secrets Act and Article 41 of its Enforcement Decree
  • If a contract is still in progress or a dispute is ongoing after the retention period has expired, the information is retained until the matter is concluded and destroyed without delay thereafter.
  • Records subject to statutory retention are stored in a separate database for the period required by the relevant laws even after membership withdrawal, and are not used for any purpose other than retention.

Article 4 (Provision of personal information to third parties)

The Company processes personal information only within the scope specified in Article 1, and provides personal information to third parties only where this falls under Articles 17 and 18 of the Personal Information Protection Act, such as with the consent of the data subject or under special statutory provisions.

The Company does not currently provide personal information to any third party. Transfers of personal information to external companies for order processing, payment, or delivery constitute outsourced processing under Article 5, not third-party provision.

However, personal information may be provided in the following cases in accordance with applicable laws:

  • Where required by law, or where requested by an investigative agency in accordance with statutory procedures and methods for investigative purposes
  • Where the data subject has given prior consent to the provision

Article 5 (Outsourcing of processing and cross-border transfers)

The Company outsources personal information processing as set out below, limited to the minimum information necessary to achieve the relevant purpose.

Processor (trustee) Outsourced work Items transferred Destination country Retention and use period
Shopify Inc. Website hosting, customer account management, order and payment processing infrastructure Member information, order and delivery information, access records Canada, the United States, and other countries where servers of Shopify and its sub-processors are located Until termination of the outsourcing contract
Google LLC Receipt and storage of quotation and technical inquiry emails via Google Workspace Information entered in the quotation form The United States and other countries where Google’s servers are located Until termination of the outsourcing contract
Korea PortOne Co., Ltd. (PortOne Payments) Online payment processing and payment authentication Name, phone number, email, payment information Republic of Korea Until termination of the outsourcing contract (including statutory retention periods)
Lotte Global Logistics, Ilyang Logistics, and other domestic parcel carriers Delivery of ordered products Recipient’s name, phone number, shipping address Republic of Korea Until completion of delivery
  • When concluding outsourcing contracts, the Company specifies in the contract documents, pursuant to Article 26 of the Personal Information Protection Act, matters such as the prohibition of processing beyond the outsourced purpose, technical and managerial safeguards, restrictions on sub-outsourcing, supervision of the trustee, and liability for damages.
  • If the outsourced work or the trustee changes, the Company will disclose the change through this Privacy Policy without delay.

Notice of cross-border transfers (Article 28-8 of the Act)

Shopify Inc. and Google LLC in the table above are located outside the Republic of Korea, and personal information is transferred abroad for the performance of the outsourced work. The items, countries, trustees, purposes, and retention periods are as shown in the table above, and the transfer method is transmission via information and communications networks.

Data subjects may refuse the cross-border transfer of their personal information under Article 28-8(5) of the Personal Information Protection Act. However, because website operation, customer accounts, order processing, and inquiry handling all depend on these services, refusal will limit your ability to register, order, or submit inquiries through the website. In that case, you may contact us and transact through the channels below.

  • Phone +82-2-982-7070 / Fax +82-2-6455-6461 / Email contact@devicemall.co.kr

Article 6 (Destruction procedures and methods)

When personal information becomes unnecessary due to the expiry of the retention period or the achievement of the processing purpose, the Company destroys it without delay (within five days from the date the cause arises).

a. Destruction procedure

Personal information whose retention period has expired is destroyed after confirmation by the privacy officer. Where retention is required by other laws, the information is moved to a separate database (or a separate filing cabinet, for paper records) and is not used for any purpose other than retention.

b. Destruction methods

  • Personal information stored in electronic files Member and order information is deleted from the operating platform, and quotation and technical inquiry emails are permanently deleted from the mailbox (including trash and archive folders) using technical methods that prevent recovery
  • Personal information printed on paper Shredded or incinerated

Article 7 (Rights of data subjects and legal representatives, and how to exercise them)

  1. Data subjects may at any time exercise against the Company the rights to access, correct, delete, or suspend the processing of their personal information, to withdraw consent, and to request transmission of their personal information.
  2. Right to request transmission (data portability) — Under Article 35-2 of the Personal Information Protection Act, data subjects may request that the Company transmit their personal information to themselves or to other personal information controllers or specialized institutions designated under that Article. This right may be exercised within the requirements and scope set by the Act and its Enforcement Decree (information about the data subject processed by computer or similar means and technically capable of transmission, etc.), and the Company will comply with lawful transmission requests absent justifiable grounds.
  3. Members may directly view and correct their information on the account management screen after logging in, and may also withdraw membership (withdraw consent) themselves. Requests may also be made in writing, by phone, by email, or by fax using the contact details in Article 11, and the Company will act on them without delay.
  4. If a data subject requests correction or deletion of an error in their personal information, the Company will not use or provide that personal information until the correction or deletion is completed. If incorrect personal information has already been provided to a third party, the Company will notify the third party of the correction without delay so that it can be corrected.
  5. Rights may be exercised through a legal representative or an authorized agent. In that case, a power of attorney in the form of Annex No. 11 of the Notification on Methods of Personal Information Processing must be submitted.
  6. Requests for access or suspension of processing may be restricted under Articles 35(4) and 37(2) of the Personal Information Protection Act.
  7. Deletion cannot be requested for personal information that other laws designate as subject to collection (the statutory retention items in Article 3).
  8. The Company verifies that the person making a request is the data subject or a legitimate agent.

Article 8 (Right to refuse consent and consequences of refusal)

Data subjects have the right to refuse consent to the collection and use of their personal information. However, refusing consent to the required items below will limit the use of the corresponding services.

  • Required items for membership Membership registration and member-only services (such as purchase history) will be unavailable
  • Required items for orders and payment Order acceptance and product delivery will be unavailable
  • Required items for quotation inquiries Quotation replies, technical consultation, and other inquiry handling will be unavailable

Refusing consent to optional items does not restrict the use of the essential services.

Article 9 (Security measures)

In accordance with Article 29 of the Personal Information Protection Act and Article 30 of its Enforcement Decree, the Company takes the following measures to prevent the loss, theft, leakage, forgery, alteration, or damage of personal information.

a. Managerial measures

  • Minimization and training of staff handling personal information Staff handling personal information are limited to the minimum necessary (currently 3 persons) and are kept informed of personal information protection matters.
  • Establishment and implementation of an internal management plan, and management of records of granting, changing, and revoking access rights

b. Technical measures

  • Access control Access to systems where personal information is stored and processed (Shopify admin, Google Workspace) is granted only to the staff in charge.
  • Two-factor authentication (2FA) Two-factor authentication is applied to all systems processing personal information (Shopify and Google Workspace).
  • Password management Administrator account passwords are set to combinations that are difficult to guess and are changed periodically. Member authentication uses one-time email verification codes, so member passwords themselves are not stored.
  • Separation of payment information Details of payment instruments such as card numbers are processed directly by the payment service provider and are not stored in the Company’s systems.
  • Encryption in transit HTTPS (TLS) encryption is applied across the entire website.
  • Intrusion prevention and anti-malware The website, order system, and mail system are protected by the intrusion prevention, detection, and anti-malware systems provided by the trustees (Shopify and Google), and access records are kept and reviewed.

c. Physical measures

  • Documents and auxiliary storage media containing personal information are kept in locked storage, and access to storage locations is controlled.

Notwithstanding the above measures, the Company is not liable for incidents caused by the data subject’s own negligence or by risks inherent to the Internet. Please manage your account information appropriately.

Article 10 (Installation, operation, and refusal of automatic data collection devices)

a. Purpose of cookies

The Company uses cookies to provide customized services and to understand website usage. A cookie is a small piece of information sent by the server operating the website to the user’s browser and stored on the user’s device. The Company uses cookies for the following purposes:

  • Member identification and maintaining login status
  • Maintaining shopping cart contents
  • Understanding website visits and usage patterns
  • Security and prevention of fraudulent use

b. Installation, operation, and refusal of cookies

Users have the right to choose whether to allow cookies. You can allow or refuse all cookies, or delete stored cookies, by adjusting your web browser options.

  • Chrome Menu (top right) > Settings > Privacy and security > Third-party cookies
  • Microsoft Edge Menu (top right) > Settings > Cookies and site permissions > Manage and delete cookies and site data
  • Safari Settings (Preferences) > Privacy > Cookies and website data
  • Firefox Settings > Privacy & Security > Cookies and Site Data

If you refuse cookies, you may experience difficulty using some services such as login and the shopping cart.

c. Third-party analytics and advertising tools

The Company currently does not install or operate third-party behavioral data collection, analytics, or advertising tools such as Google Analytics or Meta Pixel on the website. If such tools are introduced in the future, the Company will revise this Policy and give prior notice of the items collected, purposes, retention periods, and refusal methods.

Article 11 (Privacy officer and department handling access requests)

The Company designates the following privacy officer with overall responsibility for personal information processing and for handling complaints and providing remedies to data subjects in relation to personal information processing.

▶ Privacy officer

  • Name : Doojin Choi
  • Position : CEO
  • Phone : +82-2-982-7070
  • Fax : +82-2-6455-6461
  • Email : master@devicemall.co.kr

▶ Department receiving and handling access requests

  • Department : CEO’s Office
  • Phone : +82-2-982-7070
  • Email : contact@devicemall.co.kr
  • Hours : Weekdays 09:00 – 18:00 (KST, closed on weekends and holidays)

Data subjects may direct all personal information inquiries, complaints, and requests for remedies arising from the use of the Company’s services to the privacy officer and the department above. The Company will respond to and handle inquiries without delay.

Article 12 (Remedies for infringement of rights)

Data subjects may apply to the following organizations for dispute resolution or counseling regarding personal information infringements. These organizations are independent of the Company; please contact them if you are not satisfied with the Company’s own handling of your complaint or need further assistance.

Organization Role Phone Website
Personal Information Infringement Report Center (KISA) Reporting infringements, counseling 118 (no area code) privacy.kisa.or.kr
Personal Information Dispute Mediation Committee Dispute mediation, collective dispute mediation (civil resolution) 1833-6972 (no area code) www.kopico.go.kr
Cybercrime Investigation Division, Supreme Prosecutors’ Office Investigation of personal information crimes 1301 (no area code) www.spo.go.kr
Electronic Cybercrime Report & Management System (ECRM), Korean National Police Agency Reporting personal information crimes 182 (no area code) ecrm.police.go.kr

In addition, a person whose rights or interests have been infringed by a disposition or omission of the head of a public institution in response to requests under Articles 35 (access), 36 (correction and deletion), or 37 (suspension of processing) of the Personal Information Protection Act may file an administrative appeal under the Administrative Appeals Act.

  • Central Administrative Appeals Commission : Anti-Corruption and Civil Rights Commission, 110 (no area code) / www.simpan.go.kr

Article 13 (Changes to this Privacy Policy)

  1. This Privacy Policy takes effect on August 4, 2026, and was amended on August 18, 2026. (Amendments: reflection of the data subject’s right to request transmission under Article 35-2, and specification of the delivery trustees)
  2. If there are additions, deletions, or amendments due to changes in laws, policies, or security technology, the Company will announce the reasons and details on the website from 7 days before the changes take effect. For changes that materially affect the rights of data subjects, notice will be given 30 days in advance.
  3. Previous versions of this Privacy Policy are available from the Company upon request.

Business information

  • Company : PowerCraft (POWERCRAFT)
  • CEO : Doojin Choi
  • Business registration number : 110-18-45202
  • Mail-order business report number : 2017-Seoul Geumcheon-1310
  • Address : A-706, Woolim Lions Valley, 168 Gasan digital 1-ro, Geumcheon-gu, Seoul 08507, Republic of Korea
  • Phone : +82-2-982-7070 / Fax : +82-2-6455-6461
  • Email : contact@devicemall.co.kr

Effective date : August 4, 2026 / Last amended : August 18, 2026

In the event of any difference in interpretation between the Korean original and this English translation, the Korean version shall prevail.