The Cast Privacy Policy
BlacksmithIO Co., Ltd. ("Company") values the personal information of users and complies with applicable laws, including the Personal Information Protection Act of Korea and the Act on the Consumer Protection in Electronic Commerce, in operating The Cast mobile application, website, live commerce services, feed and short-form product discovery, seller or store showcase pages, customer inquiries, and partnership inquiry services (collectively, the "Service").
The Company establishes and discloses this Privacy Policy to protect users’ rights and to smoothly handle privacy-related complaints.
Notice date: September 19, 2026
Effective date: October 19, 2026
Article 1 (Items of Personal Information Collected and Collection Methods)
The Company collects the minimum personal information necessary to provide the Service and may collect the following information in connection with registration, orders, payments, delivery, customer support, partnership inquiries, events, and use of the Service.
- Registration and login: social account unique identifier, email address, profile name, nickname, profile photo (optional), and member identification information
- Profile and service use: profile information entered by the user, including the country selected by the user, followed sellers or stores, viewing, clicking, and purchase-linked history for live, feed, and short-form content, inquiry or counseling history, and posted or uploaded content
- Orders, payment, delivery, cancellation, return, and refund: name of orderer or recipient, phone number, delivery address, ordered product information, payment approval information, and information necessary for refund processing
- Customer support and partnership or seller inquiries: name or manager name, brand or company name, phone number, email address, inquiry type, discovery path, inquiry details, and consent to collection and use of personal information
- Notification services: app push token, consent to receive Kakao channel-based messages such as AlimTalk or FriendTalk, app push settings, and notification history for followed sellers or live opening alerts
- Skin analysis feature information: facial photos, up to three images, taken or uploaded by the user when the user optionally uses the skin analysis feature
- Service analytics events: app launch and termination, foreground and background transitions, screen name and screen entry or exit time, time spent on each screen, live-stream entry, exit, and cumulative viewing time, product-detail views, add-to-cart actions, payment initiation, and payment completion or cancellation confirmed by server-side order results
- Automatically collected device and access information: IP address, cookies, access time, access logs, anonymous session ID, pseudonymous analytics key, device identifiers, advertising identifiers such as ADID or IDFA, operating system type and version, browser information, app version, and device model
The Company collects personal information through registration, service use, customer inquiries, order and delivery processing, automatic collection through app events and log analysis tools, and confirmation of server-side order and payment results. Service analytics events record only screen names and exclude search terms, user-entered values, addresses, phone numbers, and payment-method information. Payment completion and cancellation are determined from server-side order results rather than app-generated events.
Country information is collected when a user directly selects it during registration or in the profile screen. The Company does not collect precise location information such as GPS solely for country-level usage statistics. If a feature using precise location information is introduced, the Company will separately disclose the purpose and items and obtain any required consent. Facial photos are collected only when the user optionally uses the skin analysis feature and chooses to take or upload such photos.
Article 2 (Purposes of Use of Personal Information)
The Company uses collected personal information for the following purposes.
- Member identification and account management: identity verification, member identification, prevention of fraudulent use, account security, and response to violations of service terms
- Provision of live commerce and shopping services: viewing live broadcasts, providing feed and short-form content, product discovery, order receipt, payment processing, delivery, cancellation, exchange, return, refund, and purchase history management
- Seller, store, and content linking: public profile display, following sellers, live opening alerts, content recommendations, and optimization of in-service exposure
- Customer support and dispute handling: responding to inquiries, delivering notices, handling complaints, and addressing purchase and delivery disputes
- Provision of the skin analysis feature: analyzing the user's skin condition using facial photos voluntarily provided by the user and providing customized skincare and cosmetic recommendations
- Service improvement and analytics: analysis of daily, weekly, and monthly active users (DAU, WAU, and MAU), return rate, views, time spent and exit rate by screen, cumulative live viewing time, conversion from product view to cart and payment stages, feature improvement, error response, security monitoring, and service stability management
- Country-level service analytics: aggregation of usage by the country selected by the user and improvement of service languages, content, and operations
- Personalized recommendations and marketing analytics: content or product recommendations, advertising targeting, and profiling based on individual behavior only where the user has provided separate optional consent
- Marketing and benefits notices: events, promotions, benefits, and live-opening or shopping-related notices. However, advertising or benefits-related messages through app push or Kakao channel-based messages such as AlimTalk or FriendTalk are sent only where separate consent is obtained as required by law.
The Company uses facial photos collected through the skin analysis feature solely to analyze skin condition and provide customized skincare and cosmetic recommendations, and does not use such photos for identity verification, facial recognition, biometric authentication, advertising, or user profiling.
Article 3 (Retention and Use Period of Personal Information)
The Company destroys personal information without undue delay when the purpose of collection and use has been achieved. However, where retention is required by law or consent has been obtained, the information may be retained for the applicable period.
- Member information: until account withdrawal. However, where retention is necessary for legal violations, fraudulent use, or dispute response, it may be retained until the relevant matter is resolved.
- Records on contracts or withdrawal of offers: 5 years
- Records on payment and supply of goods or services: 5 years
- Records on consumer complaints or dispute resolution: 3 years
- Electronic financial transaction records: 5 years
- Tax or legally required transaction evidence: for the period prescribed by applicable laws
- Access log records: 3 months
- Raw service analytics events and device information: until the earlier of 12 months from collection or withdrawal of service analytics consent. Upon expiration or withdrawal, the data is automatically deleted or converted into statistics that cannot identify an individual.
- Consent history for service analytics and personalized recommendation or marketing analytics: the consent version, consent time, and withdrawal time are retained for 5 years from the relevant consent or withdrawal.
- Partnership or seller inquiry records: up to 3 years after completion of response or for any longer period required by law
- Facial photos used for the skin analysis feature: used only temporarily during skin analysis processing and deleted immediately upon completion of the analysis. Such facial photos are not stored on the server.
Article 4 (Dormant Accounts, Long-Term Inactive Users, and Lifetime or Long-Term Account Retention Policy)
Because Korean law no longer imposes a uniform statutory obligation to separate or convert long-term inactive user accounts, the Company manages long-term inactive accounts under the following principles for user protection and secure data management.
- The Company may provide prior notice to accounts with no login or service use for one year or longer in order to confirm whether the account is long-term inactive.
- If the Company operates or changes a dormant-account policy, separate-storage policy, integrated management policy, or a lifetime or long-term account retention policy, it will provide prior notice of the details, effective date, objection procedure, and withdrawal method.
- If the Company restores previously segregated accounts to ordinary status or converts them to lifetime or long-term retention status, it will do so only through the member’s express consent or renewed consent, identity verification, and any additional required notice procedures.
- Even where a member does not use the Service for a long period, information that must be retained by law will be stored securely and separately and destroyed without undue delay when the retention period expires.
- Members may request confirmation of account status, access to personal information, correction, deletion, or withdrawal at any time through service settings, customer support, or email.
Article 5 (Destruction Procedure and Method)
- Procedure: Personal information is destroyed without undue delay once the purpose is achieved unless separate retention is required by law, in which case it is stored separately and destroyed when the relevant period expires.
- Electronic files: destroyed using technical methods that make recovery or reproduction impossible.
- Paper documents: destroyed by shredding, incineration, or similar methods.
- Raw service analytics events: automatically deleted or converted into de-identified aggregate information when the retention period expires or the user withdraws consent.
- Facial photos used for the skin analysis feature: used only temporarily during processing and deleted immediately upon completion of the analysis using methods that make recovery or reproduction impossible. Such facial photos are not stored on the server.
Article 6 (Provision of Personal Information to Third Parties)
The Company does not sell users’ personal information to outside parties or provide it for an independent third party’s marketing purposes without consent. However, the following minimum disclosures may occur as necessary for service provision.
- Seller Members or stores: orderer information, recipient information, and order details for order confirmation, customer support, exchange, return, and refund handling
- Delivery companies: recipient name, phone number, delivery address, and delivery instructions for shipment of goods
- Toss Payments and related payment institutions: information necessary for payment approval, payment method authentication, settlement, refund, electronic payment processing, and prevention of fraudulent transactions
- Authorities with lawful power to request information: information disclosed as required for investigations, supervision, taxation, dispute resolution, or similar legal requests
The Company does not sell or share facial photos collected through the skin analysis feature with third parties and does not provide such photos to third parties without the user's consent or a legal basis.
Article 7 (Entrustment of Personal Information Processing)
The Company directly develops and operates The Cast app and website and does not have a separate outsourced app operating company. However, the Company may connect to external services or entrust limited processing for the following functions in order to provide the Service smoothly.
- Toss Payments: electronic payment gateway processing, payment approval, cancellation, refund, and fraud prevention
- Kakao messaging integration: sending Kakao channel-based messages such as AlimTalk or FriendTalk, for users who have consented to receive them, regarding orders, delivery, live opening notices, and benefits information
App push notifications and Kakao channel-based messages such as AlimTalk or FriendTalk are sent only to users who have consented or enabled the relevant settings. The Company supervises external integrated services as required by law and will disclose any additional or changed entrusted or integrated service providers through this Policy or the Service screen.
Before introducing an external analytics SDK or analytics service, the Company reviews and discloses through this Policy or a separate consent screen the processor and entrusted task, whether third-party provision or overseas transfer occurs, and, where applicable, the destination country, timing and method of transfer, transferred items, purpose, retention period, and refusal method, and obtains consent where required by law.
Article 8 (Users’ Rights and Methods of Exercise)
Users may request access to, correction of, deletion of, suspension of processing of, withdrawal of consent for, or withdrawal from membership relating to their personal information at any time.
- Withdrawal from membership or withdrawal of consent may be requested through in-app or website account settings, customer support, or email.
- Service analytics and personalized recommendation or marketing analytics are operated under separate, purpose-specific optional consents. Users may review the purpose, items, and retention period before consenting. Refusal or withdrawal does not restrict basic product-purchasing or broadcast-viewing services.
- The Company records the consent version, consent time, and withdrawal time, and users may withdraw each optional consent at any time through app settings or another method provided by the Company.
- Order, payment, delivery, and other transaction-related information may not be deleted immediately if retention is required by law.
- These rights may also be exercised through a legal representative or authorized agent, in which case the Company may verify proper authority.
Article 9 (Cookies, Advertising Identifiers, and Behavioral Information)
The Company may use cookies, advertising identifiers, access logs, anonymous session IDs, and service analytics events to improve convenience, maintain login status, and perform access analytics to which the user has optionally consented. If behavioral information combined with personal or device identifiers is used for individualized recommendations, targeted advertising, or profiling, the Company clearly discloses that fact and obtains separate optional consent.
- Behavioral information collected: app launch and termination and state transitions; screen name, entry, exit, and time spent; live-stream entry, exit, and cumulative viewing time; product views; add-to-cart actions; payment initiation; and server-confirmed payment completion or cancellation
- Collection method: automatic collection through app events, cookies and access logs, and server-side order results
- Purpose and retention: used for service usage and conversion analytics for up to 12 months from collection, then automatically deleted or converted into de-identified aggregate information upon expiration or consent withdrawal
- Refusal and withdrawal: available through service analytics and personalized recommendation or marketing analytics controls in app settings, browser cookie settings, and mobile operating-system advertising-identifier settings
- Users may refuse or delete cookies through browser settings.
- Advertising identifiers and push notification settings on mobile devices may be changed through operating system settings.
- The Company obtains separate consents for service analytics and personalized recommendation or marketing analytics and provides a withdrawal method for each optional consent.
Article 10 (Security Measures)
The Company implements the following measures to protect personal information.
- Minimization of access rights and establishment of an internal management plan
- Access control to systems processing personal information, log management, and security monitoring
- Technical protection measures such as encryption in transmission sections
- Training and authority management for personnel handling personal information
- Use of pseudonymous analytics keys and anonymous session IDs separated from member IDs
- Aggregate-first analytics dashboards, with access to individual-level information limited to cases of operational necessity
- Exclusion of phone numbers, addresses, and payment-method information from analytics events and dashboards
- Restriction of analytics access to authorized BlacksmithIO accounts and logging of access history
Article 11 (Personal Information of Children Under 14)
In principle, the Company does not allow membership registration by children under 14 and does not intentionally collect personal information from children under 14. If a situation requiring parental or legal guardian consent arises, the Company will follow procedures required by applicable laws.
Article 12 (Chief Privacy Officer and Contact Information)
For privacy-related inquiries, complaints, or requests for relief, please contact the following.
- Chief Privacy Officer: Song Seongha
- Title: Chief Executive Officer
- Email: ceo@blacksmithio.com
- Customer Center: +82-2-6011-8989
- Address: S Factory B-219, 11 Yeonmujang 15-gil, Seongdong-gu, Seoul, Republic of Korea
Article 13 (Remedies for Infringement of Rights)
Users may contact the following institutions for reporting or consultation regarding privacy infringement.
Article 14 (Changes to this Privacy Policy)
The Company will notify users in advance through this page if material matters concerning personal information processing change, including laws, service contents, collected items, retention periods, long-term inactive account policies, external analytics tools, or behavioral-information processing.