Privacy Policy
Privacy Policy
PayON Mobile POS · Effective September 16, 2026
KNBON Inc. (the “Operator”) processes personal information only to the extent necessary to provide the PayON Mobile POS service.
1. Information We Process and Its Purpose
| Category | Information | Purpose |
|---|---|---|
| Merchant registration and review | Business registration number, representative’s contact number, email address, merchant type (individual/corporate), representative classification (domestic/foreign), version and timestamp of privacy and third-party-provision consent, business registration certificate, representative’s identification document, copy of the settlement bank account, and an exterior photograph showing the storefront sign. For a foreign representative, the front and back of the Alien Registration Card are additionally processed. | PayON and requested payment-channel merchant review, supplemental review, and payment-channel setup |
| Service agreement and electronic signature | Application and signer identifiers, agreement text and version, integrity hash, consent and submission timestamps, handwritten signature stroke data, representative or agency verification, and acceptance and notification records | Review, formation and performance of the PayON Mobile POS agreement, and dispute handling |
| Business-status verification | Business registration number, normalized business status, and verification timestamp | Verification through the National Tax Service business-status API via the Public Data Portal |
| Employees and installed devices | Employee identifiers, mobile number, app installation identifier, authentication token, and app version | Authorized-device verification, fraud prevention, and server configuration |
| Payments and receipts | Merchant name, business registration number, business address, representative name, merchant phone number and TID; transaction identifier, date and time, amount, result, method, sub-method, channel, approval number and time, NEX transaction number, payment brand, issuer information, masked card number, cancellation or failure reason, and receipt recipient phone number | Payment processing, transaction lookup, and mobile receipt creation and delivery |
| Draft application data | Merchant application data and captured documents | Temporary storage for up to 24 hours in app-specific device storage to restore an interrupted application |
Raw business-status response fields, such as tax type and closure date, are processed transiently for the status decision and are not separately retained.
2. External Transfers and Processing
| Recipient | Purpose | Information Provided | Retention and Use Period |
|---|---|---|---|
| Smartro | Merchant onboarding review, supplemental review, and VAN payment-channel setup | Business registration number, representative’s contact number, email address, merchant and representative classification, business registration certificate, representative’s identification document, copy of the settlement bank account, exterior photograph showing the storefront sign, and the front and back of the Alien Registration Card for a foreign representative; business-status verification result and timestamp; and privacy and third-party-provision consent records | For the period necessary for merchant review, the contractual relationship, and payment service provision. Where retention is required by law, the information is stored separately for the applicable period and then deleted. |
| NEX QR | QR merchant applications and status inquiries with consent, and QR payment authorization and cancellation for approved merchants | For applications: merchant and representative names, business registration number, phone, email, business address, settlement account information, consent records, business certificate, identity document, bankbook copy, storefront exterior photo, and Alien Registration Card front/back where applicable. For payments: MID, TID, amount, transaction number, cancellation reason code and transaction-processing data | For payment service provision and any period required by applicable law |
| National Tax Service (via the Public Data Portal) | Business-registration status verification | Business registration number | For the period necessary to process the status inquiry |
NEX QR applications are transmitted by a separate administrator action after the relevant consent and review of documents and entered information. An app application alone does not trigger immediate automatic transmission. Integration-test and live merchant-opening environments are managed separately, and the destination environment is shown to the administrator.
During payment processing, information necessary for the relevant transaction may be transmitted to VAN providers, card issuers, card networks, and QR payment providers.
| Processor | Service | Data | Processing Period |
|---|---|---|---|
| Aligo (Kakao Alimtalk delivery integration) | Delivery of mobile receipts, merchant-review and document-correction notices, and one-time password verification codes | Recipient mobile number, merchant name, receipt details including amount, status, approval date and number, payment method, issuer and masked card number, receipt URL depending on the integration, review result, correction reason, affected document labels, and one-time verification code | For delivery processing and any period required by law or the processor’s policy |
3. Retention and Deletion
Under the Operator's contract-record retention policy, concluded PayON agreements and related signature, consent and acceptance records are retained with restricted access for 10 years after contract termination and then deleted. Unnecessary agreement and signature data for applications that do not result in a contract are deleted without delay after processing ends. Electronic contract evidence is stored encrypted.
Registration documents and account information are retained for the period necessary for merchant review, the contractual relationship, and payment service provision, and are deleted without delay when the purpose is fulfilled or a merchant termination and data-deletion request is completed. Payment and contract records required by law are stored separately for the applicable statutory period and then deleted.
Draft application data and captured documents are temporarily stored in app-specific device storage for up to 24 hours and are deleted after successful submission. Mobile receipts are retained for 90 days by default. The full receipt-recipient number is used only for delivery, and only the last four digits are stored by the Operator. A cash-receipt customer identifier is transmitted to Smartro/the VAN for issuance or cancellation and is not retained in raw form in the app’s transaction history or on the Operator’s server.
4. Account and Data Deletion
You may submit a request through the PayON app settings or the Merchant Termination and Data Deletion page. When an in-app request is received, access for the employee account and installed device is revoked. Server-side data is deleted after the Operator completes verification and processing, while legally required records are kept separately for the applicable period and then deleted. Local transaction history and temporary data remaining on the device can be removed through the operating system’s app-data deletion function or by uninstalling the app.
5. Security Measures
The Operator applies safeguards including encryption in transit, protection of device authentication information, restricted administrative access, card-number masking, and access-log management.
6. Privacy Inquiries
- Operator
- KNBON Inc. (주식회사 케이앤비온)
- Representative
- Kwon Young-sik (권영식)
- Address
- 476 Yangcheon-ro, Gangseo-gu, Seoul, Republic of Korea
- kys@knbon.com
- Phone
- +82 70-4517-1725