본 개인정보 처리방침은 이즈트래블(ISTRAVEL, 이하 “이즈트래블” 또는 “당사”)이 웹사이트 istraveler.com, 문의 양식, 이메일, 카카오톡 및 여행 상담·예약 서비스와 관련하여 개인정보를 어떻게 수집·이용·제공·보관 및 보호하는지 설명합니다.
이즈트래블은 독립적으로 운영되는 여행 자문 브랜드입니다. 이즈트래블을 통한 여행 예약은 온타리오 여행산업위원회(Travel Industry Council of Ontario, 이하 “TICO”)에 등록된 여행사인 Fora Travel Inc.를 통하여 처리됩니다.
ISTRAVEL (Affiliate of Fora Travel Inc.)
TICO 등록번호: 50027942
등록 주소: 1235 Bay Street, Suite 700, Toronto, ON M5R 3K4
이즈트래블의 개인정보 처리에는 적용 가능한 범위에서 캐나다 「개인정보 보호 및 전자문서법」(Personal Information Protection and Electronic Documents Act, 이하 “PIPEDA”), 캐나다 스팸방지법(Canada’s Anti-Spam Legislation, 이하 “CASL”), 「Travel Industry Act, 2002」, 「Ontario Regulation 26/05」 및 기타 관련 법령이 적용됩니다.
본 정책은 이즈트래블이 직접 관리하는 개인정보에 적용됩니다. Fora Travel Inc., 호텔, 크루즈 선사, 항공사, 결제처리업체 및 기타 독립된 제3자가 자체적으로 처리하는 개인정보에는 해당 업체의 개인정보 처리방침이 별도로 적용될 수 있습니다.
“개인정보”란 단독으로 또는 다른 정보와 결합하여 특정 개인을 식별할 수 있는 정보를 의미합니다.
개인정보에는 이름과 연락처뿐 아니라 여행 일정, 생년월일, 국적, 여권정보, 결제 관련 정보, 가족관계, 건강·식이·접근성 요청 및 온라인 식별정보 등이 포함될 수 있습니다.
특정 개인과 합리적으로 연결할 수 없도록 익명화된 정보는 관련 법률에서 달리 규정하지 않는 한 본 정책상 개인정보로 취급되지 않을 수 있습니다.
이즈트래블은 고객이 요청하는 서비스와 예약의 성격에 따라 다음과 같은 개인정보를 수집할 수 있습니다.
전체 카드번호, 유효기간 및 보안코드는 Fora가 지정한 보안 결제 시스템을 통해 수집·처리될 수 있습니다. 이즈트래블은 전체 카드정보를 일반 이메일, 카카오톡 또는 일반 문서로 요청하거나 직접 보관하지 않습니다.
고객이 요청하거나 여행서비스를 제공하는 데 필요한 경우 다음과 같은 민감정보를 수집할 수 있습니다.
이즈트래블은 이러한 정보를 관련 요청을 처리하는 데 필요한 범위에서만 수집하고 해당 공급업체에 전달합니다.
이즈트래블은 다음과 같은 방법으로 개인정보를 수집할 수 있습니다.
다른 사람의 개인정보를 이즈트래블에 제공하는 고객은 해당 정보를 제공할 적절한 권한이 있으며, 필요한 경우 해당 당사자 또는 법정대리인에게 개인정보 처리 내용을 알리고 필요한 동의를 받았음을 확인합니다.
이즈트래블은 다음과 같은 목적으로 개인정보를 이용할 수 있습니다.
새로운 목적으로 개인정보를 이용하려는 경우, 해당 목적이 기존 목적과 합리적으로 일치하지 않는 한 고객에게 이를 알리고 필요한 동의를 받습니다.
이즈트래블은 개인정보의 민감성, 수집 목적 및 고객의 합리적인 기대를 고려하여 명시적 또는 묵시적 동의를 받을 수 있습니다.
여권정보, 건강·접근성 정보, 결제정보 또는 고객이 합리적으로 예상하기 어려운 제3자 제공과 같이 민감하거나 중요한 개인정보 처리에는 상황에 따라 명시적 동의를 요청할 수 있습니다.
웹사이트를 방문하거나 본 개인정보 처리방침을 읽었다는 사실만으로 모든 개인정보 처리에 포괄적으로 동의한 것으로 간주하지 않습니다. 필요한 동의는 문의 양식, 예약 양식, 결제 양식, 이메일, 전자서명 또는 기타 적절한 방법을 통해 받을 수 있습니다.
고객은 언제든지 동의를 철회할 수 있습니다. 다만 다음과 같은 경우에는 동의 철회가 제한되거나 서비스 제공에 영향을 줄 수 있습니다.
필수적인 예약정보 처리에 동의하지 않거나 관련 동의를 철회하면 이즈트래블이 예약을 진행, 유지 또는 관리하지 못할 수 있습니다.
마케팅 동의는 여행 상담 및 예약에 필요한 동의와 별도로 관리됩니다. 고객은 마케팅 이메일에 포함된 구독 취소 기능을 이용하거나 hello@istraveler.com으로 요청하여 언제든지 마케팅 동의를 철회할 수 있습니다.
이즈트래블은 여행서비스를 제공하고 예약을 관리하는 데 필요한 범위에서 개인정보를 다음과 같은 수령자에게 제공할 수 있습니다.
여행 예약의 특성상 일부 공급업체는 개인정보를 수령한 후 독립적인 개인정보 관리주체로서 자체 개인정보 처리방침에 따라 정보를 처리할 수 있습니다.
이즈트래블은 개인정보를 판매하거나 임대하지 않습니다. 고객의 개인정보를 관련 없는 제3자의 독립적인 마케팅 목적으로 제공하지 않으며, 그러한 제공이 필요한 경우 고객의 별도 동의를 받습니다.
법률이 허용하는 경우, 사업의 재편, 이전, 합병 또는 승계와 관련하여 적절한 기밀유지 및 개인정보 보호 조건 아래 개인정보가 이전될 수 있습니다.
여행서비스의 국제적인 특성상 개인정보가 고객의 거주지 또는 캐나다 외 국가에 있는 Fora, 공급업체 및 서비스 제공자에게 전송·저장·처리될 수 있습니다.
예를 들어 해외 호텔, 크루즈 선사, 항공사 또는 현지 운영업체에 예약이나 특별요청을 제출하는 경우 해당 국가에서 여행자 정보가 처리될 수 있습니다.
다른 국가에서 처리되는 정보에는 해당 국가의 법률이 적용될 수 있으며, 합법적인 요청이 있는 경우 외국 정부기관이나 법집행기관이 정보에 접근할 수 있습니다.
이즈트래블은 당사의 관리 아래 있는 정보에 대해 합리적인 보호조치를 적용하고, 서비스 제공업체가 개인정보를 적절히 처리하도록 계약상 또는 기타 합리적인 조치를 취합니다.
국외 전송이 예약 이행에 필수적이지 않거나 고객이 합리적으로 예상하기 어려운 목적으로 이루어지는 경우에는 관련 법률에 따라 별도로 알리고 필요한 동의를 받습니다.
이즈트래블은 일반 이메일, 카카오톡 또는 일반 문의 양식을 통해 전체 카드번호, 카드 유효기간 또는 카드 보안코드를 요청하지 않습니다.
결제정보는 Fora가 지정하거나 승인한 보안 결제 시스템을 통해 제공해야 합니다. 전체 결제카드 정보는 이즈트래블이 아닌 해당 결제 시스템, 결제처리업체 또는 공급업체가 직접 처리할 수 있습니다.
고객은 결제정보를 승인된 결제 양식에만 입력해야 하며 이메일이나 카카오톡 메시지로 전체 카드정보를 전송해서는 안 됩니다.
고객이 승인되지 않은 방법으로 전체 카드정보를 전송한 경우, 이즈트래블은 해당 정보를 안전하게 삭제하고 승인된 보안 결제 방법을 다시 안내하기 위해 합리적인 조치를 취할 수 있습니다.
이즈트래블 웹사이트는 다음과 같은 목적으로 쿠키 및 유사 기술을 사용할 수 있습니다.
필수 쿠키는 웹사이트 운영과 보안을 위해 필요할 수 있습니다. 법률상 동의가 필요한 비필수 분석 또는 마케팅 쿠키는 해당되는 경우 사용자의 선택에 따라 설정됩니다.
고객은 브라우저 설정 또는 웹사이트에서 제공되는 쿠키 관리도구를 통해 쿠키를 차단하거나 삭제할 수 있습니다. 다만 일부 쿠키를 차단하면 웹사이트의 일부 기능이 정상적으로 작동하지 않을 수 있습니다.
이즈트래블은 웹사이트에서 사용하는 쿠키, 분석도구 또는 마케팅 기술이 변경되는 경우 본 정책 또는 별도의 쿠키 안내를 업데이트할 수 있습니다.
이즈트래블은 고객이 동의했거나 관련 법률이 허용하는 경우에만 뉴스레터, 프로모션 및 기타 상업적 전자 메시지를 발송합니다.
마케팅 메시지에는 발신자 정보와 구독 취소 방법이 포함됩니다. 고객은 언제든지 구독을 취소할 수 있으며, 구독 취소 요청은 관련 법령에서 정한 기간 내에 처리됩니다.
예약확인, 결제안내, 일정 변경, 잔금기한, 온라인 체크인 및 출항 준비 안내와 같이 기존 문의 또는 예약을 관리하는 데 필요한 서비스 메시지는 마케팅 메시지가 아닙니다. 따라서 고객이 마케팅 수신을 거부한 후에도 필요한 서비스 메시지는 발송될 수 있습니다.
마케팅 수신 동의를 거부하거나 철회하더라도 여행 상담이나 예약서비스 이용에 불이익을 주지 않습니다.
이즈트래블의 웹사이트와 서비스는 미성년자가 독립적으로 이용하도록 설계되지 않았습니다. 그러나 가족여행을 예약하는 과정에서 부모, 법정대리인 또는 권한 있는 성인으로부터 아동의 개인정보를 수집할 수 있습니다.
수집되는 정보에는 아동의 이름, 생년월일, 국적, 여권정보, 가족관계, 식이·건강·접근성 요청 및 공급업체가 요구하는 기타 예약정보가 포함될 수 있습니다.
미성년자의 개인정보를 제공하는 사람은 해당 정보를 제공하고 여행 예약에 이용하도록 허용할 적절한 권한이 있음을 확인합니다.
이즈트래블이 적절한 권한 없이 미성년자로부터 직접 개인정보를 수집했다는 사실을 알게 된 경우, 법률상 보관이 필요한 경우를 제외하고 합리적인 조치를 통해 해당 정보를 삭제합니다.
이즈트래블은 다음과 같은 목적을 달성하는 데 필요한 기간 동안만 개인정보를 보관합니다.
보관기간은 정보의 종류와 민감성, 예약상태, 법정 보관의무 및 합리적으로 예상되는 분쟁 가능성에 따라 달라질 수 있습니다.
개인정보가 더 이상 필요하지 않은 경우 합리적으로 안전한 방법을 통해 삭제, 파기 또는 익명화합니다. 제3자의 백업 시스템 또는 법정 보존 기록에는 일반적인 삭제주기에 따라 일정 기간 사본이 남아 있을 수 있습니다.
개인정보 열람, 정정 또는 이의제기 요청의 대상이 된 정보는 고객이 이용할 수 있는 관련 절차가 완료되는 데 필요한 기간 동안 보관될 수 있습니다.
이즈트래블은 개인정보의 양, 형식 및 민감성에 적합한 합리적인 관리적·기술적·물리적 보호조치를 적용합니다.
이러한 보호조치에는 다음 사항이 포함될 수 있습니다.
그러나 인터넷, 이메일, 메시징 서비스 또는 전자 저장 시스템을 통한 정보의 전송과 보관이 완전히 안전하다고 보장할 수는 없습니다.
고객은 여권 사본, 전체 카드정보 또는 민감한 건강정보를 일반 이메일이나 카카오톡으로 보내지 않아야 하며, 이즈트래블이 보안 전송 방법을 안내한 경우 해당 방법을 이용해야 합니다.
개인정보의 분실, 무단 접근, 이용, 공개, 복사 또는 변경이 발생하거나 의심되는 경우 이즈트래블은 해당 상황을 조사하고, 피해를 완화하며, 재발 가능성을 줄이기 위한 합리적인 조치를 취합니다.
PIPEDA에 따른 “중대한 피해의 실질적 위험”이 있다고 판단되는 개인정보 보호조치 위반은 법률에서 요구하는 방식과 시기에 따라 캐나다 개인정보보호위원회에 보고하고 영향을 받은 개인에게 통지합니다.
피해 가능성을 줄이거나 완화하는 데 도움이 되는 경우, 관련 금융기관, 공급업체 또는 기타 제3자에게도 필요한 정보를 제공할 수 있습니다.
이즈트래블은 PIPEDA가 적용되는 개인정보 보호조치 위반에 관한 기록을 법정 기간 동안 보관합니다. 현재 해당 기록의 최소 보관기간은 위반 사실을 확인한 날부터 24개월입니다.
고객은 정확하고 최신의 여행자 정보를 제공해야 합니다. 특히 법적 성명, 생년월일, 국적, 여권정보 및 연락처의 오류는 예약 변경비용, 탑승 거절 또는 기타 불이익을 초래할 수 있습니다.
고객은 제공한 정보가 변경되거나 오류를 발견한 경우 가능한 한 신속히 이즈트래블에 알려야 합니다.
이즈트래블은 개인정보가 이용 목적에 필요한 범위에서 정확하고 완전하며 최신 상태로 유지되도록 합리적인 조치를 취합니다.
고객이 정정을 요청한 정보가 이미 공급업체에 전달된 경우, 이즈트래블은 합리적으로 가능한 범위에서 관련 공급업체에 정정 내용을 전달할 수 있습니다. 공급업체의 예약 변경에는 해당 업체의 수수료나 제한이 적용될 수 있습니다.
관련 법률과 적용 가능한 예외에 따라 고객은 다음과 같은 사항을 요청할 수 있습니다.
이즈트래블은 요청을 처리하기 전에 요청자의 신원을 확인하기 위한 합리적인 정보를 요구할 수 있습니다.
법률상 공개가 금지되거나, 다른 사람의 개인정보, 법적 특권이 적용되는 정보, 기밀 상업정보 또는 수사와 관련된 정보가 포함된 경우에는 열람이 제한될 수 있습니다.
열람 또는 삭제 요청을 전부 또는 일부 거절하는 경우 이즈트래블은 법률이 허용하는 범위에서 그 이유를 설명합니다.
삭제 요청이 있더라도 법적·규제상 보관의무, 진행 중인 예약, 거래기록, 분쟁, 사기 예방 또는 법적 청구를 위해 필요한 정보는 삭제하지 못할 수 있습니다.
개인정보 관련 요청은 hello@istraveler.com으로 제출할 수 있습니다.
개인정보 처리에 관한 질문, 요청 또는 불만은 먼저 이즈트래블 개인정보 보호책임자에게 제출해 주시기 바랍니다.
개인정보 보호책임자
ISTRAVEL
1235 Bay Street, Suite 700
Toronto, ON M5R 3K4
이메일: hello@istraveler.com
이즈트래블은 개인정보 관련 요청이나 불만을 공정하게 검토하고 합리적인 기간 내에 답변하기 위해 노력합니다.
이즈트래블의 답변에 만족하지 못하는 경우 캐나다 개인정보보호위원회에 문의하거나 불만을 제기할 수 있습니다.
캐나다 개인정보보호위원회
Office of the Privacy Commissioner of Canada
웹사이트: priv.gc.ca
TICO 등록 또는 여행업 규정과 관련된 사안은 TICO에 문의할 수 있습니다. 다만 TICO는 일반적인 개인정보 보호 민원을 담당하는 주된 개인정보 감독기관이 아닐 수 있습니다.
이즈트래블 웹사이트에는 Fora, 호텔, 크루즈 선사, 보험사, 결제업체, 소셜미디어 또는 기타 외부 웹사이트로 연결되는 링크가 포함될 수 있습니다.
이즈트래블은 독립된 제3자의 웹사이트, 보안조치 또는 개인정보 처리방침을 관리하지 않습니다. 고객은 외부 웹사이트에 개인정보를 제공하기 전에 해당 제3자의 개인정보 처리방침을 확인해야 합니다.
외부 링크가 웹사이트에 포함되어 있다는 사실만으로 이즈트래블이 해당 제3자의 개인정보 처리 방식이나 보안을 보증한다는 의미는 아닙니다.
이즈트래블은 서비스, 기술, 공급업체 또는 법적 요구사항의 변경을 반영하기 위해 본 정책을 수정할 수 있습니다.
개정된 정책은 새로운 “최종 업데이트” 날짜와 함께 웹사이트에 게시됩니다.
중요한 변경이 고객의 권리나 개인정보 이용 방식에 중대한 영향을 주는 경우, 이즈트래블은 이메일, 웹사이트 공지 또는 기타 적절한 방법으로 추가 안내를 제공하고 법률상 필요한 경우 새로운 동의를 받습니다.
정책 변경은 관련 법률이 허용하지 않는 범위에서 기존에 수집한 개인정보의 이용 목적을 소급하여 확대하지 않습니다.
본 정책은 고객의 편의를 위해 한국어와 영어로 제공될 수 있습니다. 두 언어의 정책은 동일한 의미를 전달하도록 작성됩니다.
번역본 사이에 중요한 불일치가 있는 경우 적용 법률이 허용하는 범위에서 영어본이 우선합니다.
다만 이러한 우선순위 조항은 고객에게 실제로 제공된 고지, 관련 법률에 따라 포기할 수 없는 고객의 권리 또는 의미 있는 동의에 관한 요건을 제한하지 않습니다.
This Privacy Policy explains how ISTRAVEL (“ISTRAVEL,” “we,” “our” or “us”) collects, uses, discloses, retains and protects personal information in connection with istraveler.com, inquiry forms, email, KakaoTalk and our travel consultation and booking services.
ISTRAVEL is an independently operated travel advisory brand. Travel bookings made through ISTRAVEL are processed through Fora Travel Inc., a travel agency registered with the Travel Industry Council of Ontario (“TICO”).
ISTRAVEL (Affiliate of Fora Travel Inc.)
TICO Registration No. 50027942
Registered Address: 1235 Bay Street, Suite 700, Toronto, ON M5R 3K4
Where applicable, ISTRAVEL’s handling of personal information is governed by Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), Canada’s Anti-Spam Legislation (“CASL”), the Travel Industry Act, 2002, Ontario Regulation 26/05 and other applicable laws.
This Policy applies to personal information under ISTRAVEL’s control. Fora Travel Inc., hotels, cruise lines, airlines, payment processors and other independent third parties may separately process personal information under their own privacy policies.
“Personal information” means information about an identifiable individual, whether the individual can be identified from that information alone or in combination with other information.
Personal information may include names and contact details, travel itineraries, dates of birth, citizenship, passport information, payment-related information, family relationships, health, dietary or accessibility requests and online identifiers.
Information that has been anonymized so that it cannot reasonably be linked to an identifiable individual may not be treated as personal information under this Policy unless otherwise required by applicable law.
ISTRAVEL may collect the following personal information, depending on the services requested and the nature of the booking.
Complete card numbers, expiry dates and security codes may be collected and processed through a secure payment system designated by Fora. ISTRAVEL does not request or directly retain complete payment card information through ordinary email, KakaoTalk or ordinary documents.
Where requested by the customer or necessary to provide travel services, ISTRAVEL may collect sensitive information such as:
ISTRAVEL collects and discloses such information only to the extent reasonably necessary to process the relevant request.
ISTRAVEL may collect personal information:
A customer who provides another person’s personal information confirms that they have the appropriate authority to provide it and, where required, have informed that individual or their legal representative and obtained any necessary consent.
ISTRAVEL may use personal information to:
If ISTRAVEL wishes to use personal information for a new purpose that is not reasonably consistent with the original purposes, the customer will be notified and consent will be obtained where required.
ISTRAVEL may obtain express or implied consent depending on the sensitivity of the information, the purpose of collection and the customer’s reasonable expectations.
Express consent may be requested for sensitive or material processing, including passport information, health or accessibility information, payment information or a disclosure to a third party that the customer would not reasonably expect.
Merely visiting the website or reading this Privacy Policy does not constitute blanket consent to all processing of personal information. Required consent may be obtained through an inquiry form, booking form, payment form, email, electronic signature or another appropriate method.
A customer may withdraw consent at any time, subject to legal, regulatory and contractual restrictions. Withdrawal may be limited or may affect the services where:
If a customer does not consent to or withdraws consent for the processing of information necessary for a booking, ISTRAVEL may be unable to make, maintain or administer the booking.
Marketing consent is managed separately from consent required to provide travel consultation and booking services. Customers may withdraw marketing consent at any time by using the unsubscribe function in a marketing email or contacting hello@istraveler.com.
ISTRAVEL may disclose personal information to the following recipients to the extent reasonably necessary to provide and administer travel services:
Because of the nature of travel bookings, some Suppliers may process personal information as independent organizations under their own privacy policies after receiving it.
ISTRAVEL does not sell or rent personal information. Personal information is not disclosed for an unrelated third party’s independent marketing purposes unless the customer separately consents.
Where permitted by law, personal information may be transferred as part of a business reorganization, transfer, merger or succession, subject to appropriate confidentiality and privacy protections.
Because of the international nature of travel services, personal information may be transferred to, stored in or processed by Fora, Suppliers and service providers located outside the customer’s province, country of residence or Canada.
For example, when a booking or special request is submitted to an overseas hotel, cruise line, airline or local operator, traveller information may be processed in the relevant destination country.
Information processed in another country may be subject to that country’s laws and may be accessible to foreign government or law-enforcement authorities in response to a lawful request.
ISTRAVEL applies reasonable safeguards to personal information under its control and uses contractual or other reasonable measures to require service providers to handle the information appropriately.
Where an international transfer is not necessary to fulfil a booking or is made for a purpose that the customer would not reasonably expect, ISTRAVEL will provide separate notice and obtain any consent required by applicable law.
ISTRAVEL does not request complete card numbers, card expiry dates or card security codes through ordinary email, KakaoTalk or a general inquiry form.
Payment information must be submitted through a secure payment system designated or approved by Fora. Complete payment card information may be processed directly by that payment system, payment processor or Supplier rather than by ISTRAVEL.
Customers should enter payment information only into an authorized payment form and should not send complete card information by email or KakaoTalk.
If a customer sends complete card information through an unauthorized method, ISTRAVEL may take reasonable steps to securely delete it and redirect the customer to an authorized payment method.
ISTRAVEL’s website may use cookies and similar technologies to:
Essential cookies may be required for the operation and security of the website. Non-essential analytics or marketing cookies that require consent will, where applicable, be used according to the user’s choices.
Customers may block or delete cookies through their browser settings or an available cookie-management tool. Disabling certain cookies may prevent parts of the website from functioning properly.
ISTRAVEL may update this Policy or provide a separate cookie notice if the cookies, analytics tools or marketing technologies used on the website change.
ISTRAVEL sends newsletters, promotions and other commercial electronic messages only where the customer has consented or where otherwise permitted by applicable law.
Marketing messages will identify the sender and include a method of unsubscribing. Customers may unsubscribe at any time, and unsubscribe requests will be implemented within the period required by applicable law.
Operational communications necessary to administer an existing inquiry or booking—including booking confirmations, payment notices, itinerary changes, final-payment reminders, online check-in and departure information—are not marketing messages and may continue after a customer unsubscribes from marketing.
Declining or withdrawing marketing consent will not adversely affect the customer’s ability to receive travel consultation or booking services.
ISTRAVEL’s website and services are not designed for independent use by minors. However, when arranging family travel, ISTRAVEL may collect a child’s personal information from a parent, legal guardian or authorized adult.
This information may include the child’s name, date of birth, citizenship, passport information, family relationship, dietary, health or accessibility requests and other booking information required by a Supplier.
A person who provides a minor’s personal information confirms that they have the appropriate authority to provide the information and authorize its use for the travel booking.
If ISTRAVEL learns that it collected personal information directly from a minor without appropriate authorization, it will take reasonable steps to delete the information unless retention is required by law.
ISTRAVEL retains personal information only for as long as reasonably necessary to:
Retention periods may vary according to the type and sensitivity of the information, booking status, statutory requirements and the reasonable likelihood of a dispute.
When personal information is no longer required, it will be securely deleted, destroyed or anonymized using reasonable methods. Copies may temporarily remain in third-party backup systems or legally retained records until the applicable deletion cycle expires.
Information that is the subject of an access, correction or privacy challenge may be retained for as long as necessary to allow the individual to exhaust the applicable procedures and available recourse.
ISTRAVEL uses reasonable administrative, technical and physical safeguards appropriate to the volume, format and sensitivity of the personal information.
These safeguards may include:
No transmission or storage system using the internet, email, messaging services or electronic storage can be guaranteed to be completely secure.
Customers should not send passport copies, complete card information or sensitive health information through ordinary email or KakaoTalk and should use a secure method designated by ISTRAVEL where one is available.
If personal information is lost or is subject to suspected or confirmed unauthorized access, use, disclosure, copying or modification, ISTRAVEL will investigate, mitigate the effects and take reasonable steps to reduce the risk of recurrence.
A breach of security safeguards that creates a “real risk of significant harm” under PIPEDA will be reported to the Office of the Privacy Commissioner of Canada, and affected individuals will be notified, in the manner and within the time required by law.
Relevant financial institutions, Suppliers or other third parties may also be notified where doing so may reduce or mitigate the risk of harm.
ISTRAVEL maintains records of breaches of security safeguards subject to PIPEDA for the period required by law. The current minimum retention period for such records is 24 months after the date on which the breach is determined to have occurred.
Customers must provide accurate and current traveller information. Errors in legal names, dates of birth, citizenship, passport information or contact details may result in amendment costs, denial of boarding or other adverse consequences.
Customers should notify ISTRAVEL as soon as reasonably possible if information changes or an error is identified.
ISTRAVEL takes reasonable steps to maintain personal information that is accurate, complete and current to the extent necessary for the purposes for which it is used.
If corrected information has already been disclosed to a Supplier, ISTRAVEL may communicate the correction to the relevant Supplier where reasonably possible. Supplier fees or restrictions may apply to changes made to an existing booking.
Subject to applicable law and permitted exceptions, an individual may request to:
ISTRAVEL may request reasonable information to verify the requester’s identity before processing a request.
Access may be restricted where disclosure is prohibited by law or would reveal another person’s information, legally privileged information, confidential commercial information or information relating to an investigation.
If an access or deletion request is refused in whole or in part, ISTRAVEL will explain the reason to the extent permitted by law.
Even where deletion is requested, ISTRAVEL may be unable to delete information required for legal or regulatory retention obligations, an active booking, transaction records, a dispute, fraud prevention or a legal claim.
Privacy requests may be submitted to hello@istraveler.com.
Questions, requests or complaints concerning personal information should first be submitted to ISTRAVEL’s Privacy Officer.
Privacy Officer
ISTRAVEL
1235 Bay Street, Suite 700
Toronto, ON M5R 3K4
Email: hello@istraveler.com
ISTRAVEL will review privacy requests and complaints fairly and make reasonable efforts to respond within an appropriate period.
If an individual is not satisfied with ISTRAVEL’s response, they may contact or submit a complaint to:
Office of the Privacy Commissioner of Canada
Website: priv.gc.ca
Matters concerning TICO registration or travel-industry requirements may also be directed to TICO. However, TICO may not be the primary regulator responsible for general privacy complaints.
ISTRAVEL’s website may contain links to Fora, hotels, cruise lines, insurers, payment providers, social media platforms and other external websites.
ISTRAVEL does not control an independent third party’s website, security safeguards or privacy practices. Customers should review the relevant third party’s privacy policy before providing personal information through an external website.
The inclusion of an external link does not mean that ISTRAVEL guarantees or endorses the third party’s privacy or security practices.
ISTRAVEL may amend this Policy to reflect changes in its services, technologies, Suppliers or legal requirements.
The revised Policy will be posted on the website with a new “Last Updated” date.
If a material change significantly affects individual rights or how personal information is used, ISTRAVEL will provide additional notice by email, website notice or another appropriate method and will obtain new consent where required by law.
A change to this Policy will not retroactively expand the purposes for which previously collected personal information may be used where doing so is not permitted by applicable law.
This Policy may be provided in Korean and English for the customer’s convenience. The two versions are intended to convey the same meaning.
If there is a material inconsistency between the translations, the English version will prevail to the extent permitted by applicable law.
This language provision does not limit any notice actually provided to the customer, any non-waivable right under applicable law or the requirements for meaningful consent.