LEGAL

개인정보 처리방침

최종 업데이트: 2026년 8월 1일

1. 정책의 목적 및 적용범위

본 개인정보 처리방침은 이즈트래블(ISTRAVEL, 이하 “이즈트래블” 또는 “당사”)이 웹사이트 istraveler.com, 문의 양식, 이메일, 카카오톡 및 여행 상담·예약 서비스와 관련하여 개인정보를 어떻게 수집·이용·제공·보관 및 보호하는지 설명합니다.

이즈트래블은 독립적으로 운영되는 여행 자문 브랜드입니다. 이즈트래블을 통한 여행 예약은 온타리오 여행산업위원회(Travel Industry Council of Ontario, 이하 “TICO”)에 등록된 여행사인 Fora Travel Inc.를 통하여 처리됩니다.

ISTRAVEL (Affiliate of Fora Travel Inc.)
TICO 등록번호: 50027942
등록 주소: 1235 Bay Street, Suite 700, Toronto, ON M5R 3K4

이즈트래블의 개인정보 처리에는 적용 가능한 범위에서 캐나다 「개인정보 보호 및 전자문서법」(Personal Information Protection and Electronic Documents Act, 이하 “PIPEDA”), 캐나다 스팸방지법(Canada’s Anti-Spam Legislation, 이하 “CASL”), 「Travel Industry Act, 2002」, 「Ontario Regulation 26/05」 및 기타 관련 법령이 적용됩니다.

본 정책은 이즈트래블이 직접 관리하는 개인정보에 적용됩니다. Fora Travel Inc., 호텔, 크루즈 선사, 항공사, 결제처리업체 및 기타 독립된 제3자가 자체적으로 처리하는 개인정보에는 해당 업체의 개인정보 처리방침이 별도로 적용될 수 있습니다.

2. 개인정보의 의미

“개인정보”란 단독으로 또는 다른 정보와 결합하여 특정 개인을 식별할 수 있는 정보를 의미합니다.

개인정보에는 이름과 연락처뿐 아니라 여행 일정, 생년월일, 국적, 여권정보, 결제 관련 정보, 가족관계, 건강·식이·접근성 요청 및 온라인 식별정보 등이 포함될 수 있습니다.

특정 개인과 합리적으로 연결할 수 없도록 익명화된 정보는 관련 법률에서 달리 규정하지 않는 한 본 정책상 개인정보로 취급되지 않을 수 있습니다.

3. 수집하는 개인정보

이즈트래블은 고객이 요청하는 서비스와 예약의 성격에 따라 다음과 같은 개인정보를 수집할 수 있습니다.

3.1 신원 및 연락처 정보
  • 이름 및 여행서류에 표시된 법적 영문 성명
  • 이메일 주소
  • 전화번호 또는 카카오톡 연락정보
  • 거주 도시, 주·도 및 국가
  • 우편 주소 또는 청구 주소
  • 고객이 선호하는 연락방법
3.2 여행자 및 예약정보
  • 생년월일 및 출항일·투숙일 기준 나이
  • 공급업체가 예약을 위해 요구하는 성별 또는 호칭
  • 국적, 시민권 및 거주 상태
  • 여권 종류, 여권번호, 발급국가 및 유효기간
  • NEXUS, Known Traveller Number, 호텔·항공·크루즈 멤버십 번호
  • 항공편, 호텔, 크루즈, 교통편 및 기타 여행 일정
  • 객실·캐빈·침대·다이닝 및 기타 선호사항
  • 동행자, 가족관계 및 미성년자 보호자 정보
  • 결혼기념일, 생일 등 특별 행사 및 기념일 정보
  • 공급업체가 예약을 완료하기 위해 요구하는 기타 정보
3.3 결제 및 거래정보
  • 결제 승인 여부
  • 카드 소유자 이름
  • 카드 종류 및 카드번호 끝자리 등 제한된 결제정보
  • 결제금액, 통화, 결제일 및 결제상태
  • 보증금, 잔액, 환불 및 거래기록
  • 인보이스와 예약확인서

전체 카드번호, 유효기간 및 보안코드는 Fora가 지정한 보안 결제 시스템을 통해 수집·처리될 수 있습니다. 이즈트래블은 전체 카드정보를 일반 이메일, 카카오톡 또는 일반 문서로 요청하거나 직접 보관하지 않습니다.

3.4 건강, 식이 및 접근성 정보

고객이 요청하거나 여행서비스를 제공하는 데 필요한 경우 다음과 같은 민감정보를 수집할 수 있습니다.

  • 이동지원 및 접근성 요구사항
  • 휠체어 또는 의료기기 관련 정보
  • 알레르기 및 식이 제한
  • 임신 또는 여행에 영향을 주는 건강 관련 정보
  • 공급업체가 특별요청을 처리하기 위해 요구하는 정보
  • 응급상황에 합리적으로 필요한 정보

이즈트래블은 이러한 정보를 관련 요청을 처리하는 데 필요한 범위에서만 수집하고 해당 공급업체에 전달합니다.

3.5 문의 및 커뮤니케이션 기록
  • 문의 양식에 작성한 내용
  • 이메일 및 카카오톡 대화
  • 예약 요청, 특별요청 및 고객서비스 기록
  • 변경, 취소, 환불, 불만 및 분쟁 관련 기록
  • 고객이 제공한 문서와 첨부파일
3.6 웹사이트 및 기술정보
  • IP 주소
  • 브라우저 및 기기 유형
  • 운영체제
  • 접속 일시
  • 방문한 페이지 및 이전·이후 페이지
  • 웹사이트 이용 및 상호작용 기록
  • 쿠키, 분석도구 및 유사 기술을 통해 수집되는 정보
  • 보안 및 오류진단 기록

4. 개인정보의 수집 방법

이즈트래블은 다음과 같은 방법으로 개인정보를 수집할 수 있습니다.

  • 고객이 웹사이트 문의 양식에 정보를 입력하는 경우
  • 고객이 이메일 또는 카카오톡으로 문의하는 경우
  • 고객이 예약 또는 결제 양식을 작성하는 경우
  • 고객이 여권정보 또는 기타 여행서류를 제공하는 경우
  • 고객이 특별요청이나 접근성 요청을 제출하는 경우
  • Fora 또는 공급업체가 예약상태나 변경사항을 전달하는 경우
  • 웹사이트에서 쿠키와 분석기술이 작동하는 경우
  • 고객이 동행자를 대신하여 정보를 제공하는 경우

다른 사람의 개인정보를 이즈트래블에 제공하는 고객은 해당 정보를 제공할 적절한 권한이 있으며, 필요한 경우 해당 당사자 또는 법정대리인에게 개인정보 처리 내용을 알리고 필요한 동의를 받았음을 확인합니다.

5. 개인정보의 이용 목적

이즈트래블은 다음과 같은 목적으로 개인정보를 이용할 수 있습니다.

  • 고객의 문의에 답변하고 여행 조건을 확인하기 위해
  • 적합한 호텔, 크루즈 및 기타 여행서비스를 검색하고 안내하기 위해
  • 견적, 예약, 결제 승인, 인보이스 및 예약확인서를 처리하기 위해
  • 여행자 정보를 Fora 및 관련 공급업체에 전달하기 위해
  • 객실, 캐빈, 다이닝, 기념일, 건강·식이·접근성 및 기타 특별요청을 처리하기 위해
  • 잔금기한, 온라인 체크인, 일정 변경 및 출발 준비를 안내하기 위해
  • 예약 변경, 취소, 환불, 고객지원 및 분쟁을 처리하기 위해
  • 여행서류 및 예약조건에 관한 법적 고지의무를 이행하기 위해
  • 정확한 예약·결제·인보이스 및 고객서비스 기록을 유지하기 위해
  • 사기, 무단거래, 보안사고 및 서비스 오용을 예방·조사하기 위해
  • 웹사이트를 운영, 유지, 보호 및 개선하기 위해
  • 법적·규제상 의무를 준수하고 법적 청구를 확립·행사·방어하기 위해
  • 고객이 별도로 동의한 경우 뉴스레터와 마케팅 정보를 발송하기 위해

새로운 목적으로 개인정보를 이용하려는 경우, 해당 목적이 기존 목적과 합리적으로 일치하지 않는 한 고객에게 이를 알리고 필요한 동의를 받습니다.

6. 동의 및 동의 철회

이즈트래블은 개인정보의 민감성, 수집 목적 및 고객의 합리적인 기대를 고려하여 명시적 또는 묵시적 동의를 받을 수 있습니다.

여권정보, 건강·접근성 정보, 결제정보 또는 고객이 합리적으로 예상하기 어려운 제3자 제공과 같이 민감하거나 중요한 개인정보 처리에는 상황에 따라 명시적 동의를 요청할 수 있습니다.

웹사이트를 방문하거나 본 개인정보 처리방침을 읽었다는 사실만으로 모든 개인정보 처리에 포괄적으로 동의한 것으로 간주하지 않습니다. 필요한 동의는 문의 양식, 예약 양식, 결제 양식, 이메일, 전자서명 또는 기타 적절한 방법을 통해 받을 수 있습니다.

고객은 언제든지 동의를 철회할 수 있습니다. 다만 다음과 같은 경우에는 동의 철회가 제한되거나 서비스 제공에 영향을 줄 수 있습니다.

  • 예약을 처리하거나 유지하기 위해 정보가 필요한 경우
  • 공급업체가 여행서비스를 제공하기 위해 정보를 요구하는 경우
  • 거래·세무·회계·TICO 및 기타 규제 기록을 보관해야 하는 경우
  • 환불, 보험청구, 분쟁 또는 법적 청구에 정보가 필요한 경우
  • 법률상 정보의 수집·이용·보관이 허용되거나 요구되는 경우

필수적인 예약정보 처리에 동의하지 않거나 관련 동의를 철회하면 이즈트래블이 예약을 진행, 유지 또는 관리하지 못할 수 있습니다.

마케팅 동의는 여행 상담 및 예약에 필요한 동의와 별도로 관리됩니다. 고객은 마케팅 이메일에 포함된 구독 취소 기능을 이용하거나 hello@istraveler.com으로 요청하여 언제든지 마케팅 동의를 철회할 수 있습니다.

7. 개인정보의 제공 및 수령자

이즈트래블은 여행서비스를 제공하고 예약을 관리하는 데 필요한 범위에서 개인정보를 다음과 같은 수령자에게 제공할 수 있습니다.

  • Fora Travel Inc.
  • 호텔, 리조트 및 기타 숙박업체
  • 크루즈 선사
  • 항공사, 철도회사 및 기타 운송업체
  • 투어, 익스커션, 지상교통 및 목적지 관리업체
  • 고객이 요청하거나 동의한 경우 여행보험사 또는 보험중개인
  • 결제처리업체 및 카드 네트워크
  • 웹사이트 호스팅, 문의 양식, 이메일, 고객관리, 클라우드 저장 및 업무자동화 제공업체
  • 고객이 승인한 동행자 또는 대리인
  • 법률·회계·보험 및 기타 전문 자문업체
  • 법률에 따라 권한을 가진 정부기관, 규제기관, 법원 또는 수사기관

여행 예약의 특성상 일부 공급업체는 개인정보를 수령한 후 독립적인 개인정보 관리주체로서 자체 개인정보 처리방침에 따라 정보를 처리할 수 있습니다.

이즈트래블은 개인정보를 판매하거나 임대하지 않습니다. 고객의 개인정보를 관련 없는 제3자의 독립적인 마케팅 목적으로 제공하지 않으며, 그러한 제공이 필요한 경우 고객의 별도 동의를 받습니다.

법률이 허용하는 경우, 사업의 재편, 이전, 합병 또는 승계와 관련하여 적절한 기밀유지 및 개인정보 보호 조건 아래 개인정보가 이전될 수 있습니다.

8. 해외 전송 및 처리

여행서비스의 국제적인 특성상 개인정보가 고객의 거주지 또는 캐나다 외 국가에 있는 Fora, 공급업체 및 서비스 제공자에게 전송·저장·처리될 수 있습니다.

예를 들어 해외 호텔, 크루즈 선사, 항공사 또는 현지 운영업체에 예약이나 특별요청을 제출하는 경우 해당 국가에서 여행자 정보가 처리될 수 있습니다.

다른 국가에서 처리되는 정보에는 해당 국가의 법률이 적용될 수 있으며, 합법적인 요청이 있는 경우 외국 정부기관이나 법집행기관이 정보에 접근할 수 있습니다.

이즈트래블은 당사의 관리 아래 있는 정보에 대해 합리적인 보호조치를 적용하고, 서비스 제공업체가 개인정보를 적절히 처리하도록 계약상 또는 기타 합리적인 조치를 취합니다.

국외 전송이 예약 이행에 필수적이지 않거나 고객이 합리적으로 예상하기 어려운 목적으로 이루어지는 경우에는 관련 법률에 따라 별도로 알리고 필요한 동의를 받습니다.

9. 결제정보 보호

이즈트래블은 일반 이메일, 카카오톡 또는 일반 문의 양식을 통해 전체 카드번호, 카드 유효기간 또는 카드 보안코드를 요청하지 않습니다.

결제정보는 Fora가 지정하거나 승인한 보안 결제 시스템을 통해 제공해야 합니다. 전체 결제카드 정보는 이즈트래블이 아닌 해당 결제 시스템, 결제처리업체 또는 공급업체가 직접 처리할 수 있습니다.

고객은 결제정보를 승인된 결제 양식에만 입력해야 하며 이메일이나 카카오톡 메시지로 전체 카드정보를 전송해서는 안 됩니다.

고객이 승인되지 않은 방법으로 전체 카드정보를 전송한 경우, 이즈트래블은 해당 정보를 안전하게 삭제하고 승인된 보안 결제 방법을 다시 안내하기 위해 합리적인 조치를 취할 수 있습니다.

10. 쿠키 및 분석기술

이즈트래블 웹사이트는 다음과 같은 목적으로 쿠키 및 유사 기술을 사용할 수 있습니다.

  • 웹사이트의 핵심 기능과 보안을 제공하기 위해
  • 사용자의 환경설정을 기억하기 위해
  • 웹사이트 방문과 이용 패턴을 분석하기 위해
  • 오류를 진단하고 성능을 개선하기 위해
  • 콘텐츠 및 마케팅 성과를 측정하기 위해

필수 쿠키는 웹사이트 운영과 보안을 위해 필요할 수 있습니다. 법률상 동의가 필요한 비필수 분석 또는 마케팅 쿠키는 해당되는 경우 사용자의 선택에 따라 설정됩니다.

고객은 브라우저 설정 또는 웹사이트에서 제공되는 쿠키 관리도구를 통해 쿠키를 차단하거나 삭제할 수 있습니다. 다만 일부 쿠키를 차단하면 웹사이트의 일부 기능이 정상적으로 작동하지 않을 수 있습니다.

이즈트래블은 웹사이트에서 사용하는 쿠키, 분석도구 또는 마케팅 기술이 변경되는 경우 본 정책 또는 별도의 쿠키 안내를 업데이트할 수 있습니다.

11. 마케팅 커뮤니케이션

이즈트래블은 고객이 동의했거나 관련 법률이 허용하는 경우에만 뉴스레터, 프로모션 및 기타 상업적 전자 메시지를 발송합니다.

마케팅 메시지에는 발신자 정보와 구독 취소 방법이 포함됩니다. 고객은 언제든지 구독을 취소할 수 있으며, 구독 취소 요청은 관련 법령에서 정한 기간 내에 처리됩니다.

예약확인, 결제안내, 일정 변경, 잔금기한, 온라인 체크인 및 출항 준비 안내와 같이 기존 문의 또는 예약을 관리하는 데 필요한 서비스 메시지는 마케팅 메시지가 아닙니다. 따라서 고객이 마케팅 수신을 거부한 후에도 필요한 서비스 메시지는 발송될 수 있습니다.

마케팅 수신 동의를 거부하거나 철회하더라도 여행 상담이나 예약서비스 이용에 불이익을 주지 않습니다.

12. 미성년자의 개인정보

이즈트래블의 웹사이트와 서비스는 미성년자가 독립적으로 이용하도록 설계되지 않았습니다. 그러나 가족여행을 예약하는 과정에서 부모, 법정대리인 또는 권한 있는 성인으로부터 아동의 개인정보를 수집할 수 있습니다.

수집되는 정보에는 아동의 이름, 생년월일, 국적, 여권정보, 가족관계, 식이·건강·접근성 요청 및 공급업체가 요구하는 기타 예약정보가 포함될 수 있습니다.

미성년자의 개인정보를 제공하는 사람은 해당 정보를 제공하고 여행 예약에 이용하도록 허용할 적절한 권한이 있음을 확인합니다.

이즈트래블이 적절한 권한 없이 미성년자로부터 직접 개인정보를 수집했다는 사실을 알게 된 경우, 법률상 보관이 필요한 경우를 제외하고 합리적인 조치를 통해 해당 정보를 삭제합니다.

13. 개인정보의 보관 및 삭제

이즈트래블은 다음과 같은 목적을 달성하는 데 필요한 기간 동안만 개인정보를 보관합니다.

  • 여행 문의 및 예약 관리
  • 거래, 결제 및 인보이스 기록 유지
  • 고객지원, 환불, 보험 또는 분쟁 처리
  • 세무·회계·TICO 및 기타 법적·규제상 의무 준수
  • 사기 예방 및 법적 청구의 확립·행사·방어

보관기간은 정보의 종류와 민감성, 예약상태, 법정 보관의무 및 합리적으로 예상되는 분쟁 가능성에 따라 달라질 수 있습니다.

개인정보가 더 이상 필요하지 않은 경우 합리적으로 안전한 방법을 통해 삭제, 파기 또는 익명화합니다. 제3자의 백업 시스템 또는 법정 보존 기록에는 일반적인 삭제주기에 따라 일정 기간 사본이 남아 있을 수 있습니다.

개인정보 열람, 정정 또는 이의제기 요청의 대상이 된 정보는 고객이 이용할 수 있는 관련 절차가 완료되는 데 필요한 기간 동안 보관될 수 있습니다.

14. 개인정보 보호조치

이즈트래블은 개인정보의 양, 형식 및 민감성에 적합한 합리적인 관리적·기술적·물리적 보호조치를 적용합니다.

이러한 보호조치에는 다음 사항이 포함될 수 있습니다.

  • 업무상 필요한 사람에게만 접근권한 부여
  • 비밀번호, 다중인증 및 계정 보안조치
  • Fora가 지정하거나 승인한 보안 결제 시스템 사용
  • 전송 또는 저장 과정에서의 암호화
  • 시스템 업데이트와 보안점검
  • 개인정보 최소수집
  • 서비스 제공업체에 대한 개인정보 보호조건 적용
  • 불필요해진 정보의 안전한 삭제
  • 개인정보 유출 및 보안사고 대응 절차

그러나 인터넷, 이메일, 메시징 서비스 또는 전자 저장 시스템을 통한 정보의 전송과 보관이 완전히 안전하다고 보장할 수는 없습니다.

고객은 여권 사본, 전체 카드정보 또는 민감한 건강정보를 일반 이메일이나 카카오톡으로 보내지 않아야 하며, 이즈트래블이 보안 전송 방법을 안내한 경우 해당 방법을 이용해야 합니다.

15. 개인정보 유출 대응

개인정보의 분실, 무단 접근, 이용, 공개, 복사 또는 변경이 발생하거나 의심되는 경우 이즈트래블은 해당 상황을 조사하고, 피해를 완화하며, 재발 가능성을 줄이기 위한 합리적인 조치를 취합니다.

PIPEDA에 따른 “중대한 피해의 실질적 위험”이 있다고 판단되는 개인정보 보호조치 위반은 법률에서 요구하는 방식과 시기에 따라 캐나다 개인정보보호위원회에 보고하고 영향을 받은 개인에게 통지합니다.

피해 가능성을 줄이거나 완화하는 데 도움이 되는 경우, 관련 금융기관, 공급업체 또는 기타 제3자에게도 필요한 정보를 제공할 수 있습니다.

이즈트래블은 PIPEDA가 적용되는 개인정보 보호조치 위반에 관한 기록을 법정 기간 동안 보관합니다. 현재 해당 기록의 최소 보관기간은 위반 사실을 확인한 날부터 24개월입니다.

16. 개인정보의 정확성

고객은 정확하고 최신의 여행자 정보를 제공해야 합니다. 특히 법적 성명, 생년월일, 국적, 여권정보 및 연락처의 오류는 예약 변경비용, 탑승 거절 또는 기타 불이익을 초래할 수 있습니다.

고객은 제공한 정보가 변경되거나 오류를 발견한 경우 가능한 한 신속히 이즈트래블에 알려야 합니다.

이즈트래블은 개인정보가 이용 목적에 필요한 범위에서 정확하고 완전하며 최신 상태로 유지되도록 합리적인 조치를 취합니다.

고객이 정정을 요청한 정보가 이미 공급업체에 전달된 경우, 이즈트래블은 합리적으로 가능한 범위에서 관련 공급업체에 정정 내용을 전달할 수 있습니다. 공급업체의 예약 변경에는 해당 업체의 수수료나 제한이 적용될 수 있습니다.

17. 고객의 개인정보 관련 권리

관련 법률과 적용 가능한 예외에 따라 고객은 다음과 같은 사항을 요청할 수 있습니다.

  • 이즈트래블이 본인의 개인정보를 보유하고 있는지 확인
  • 보유 중인 개인정보에 대한 열람
  • 개인정보가 어떻게 이용되거나 제공되었는지에 관한 설명
  • 부정확하거나 불완전한 개인정보의 정정
  • 더 이상 필요하지 않은 개인정보의 삭제
  • 동의의 철회
  • 마케팅 메시지 수신 거부
  • 개인정보 처리 관행에 대한 이의제기 또는 불만 제기

이즈트래블은 요청을 처리하기 전에 요청자의 신원을 확인하기 위한 합리적인 정보를 요구할 수 있습니다.

법률상 공개가 금지되거나, 다른 사람의 개인정보, 법적 특권이 적용되는 정보, 기밀 상업정보 또는 수사와 관련된 정보가 포함된 경우에는 열람이 제한될 수 있습니다.

열람 또는 삭제 요청을 전부 또는 일부 거절하는 경우 이즈트래블은 법률이 허용하는 범위에서 그 이유를 설명합니다.

삭제 요청이 있더라도 법적·규제상 보관의무, 진행 중인 예약, 거래기록, 분쟁, 사기 예방 또는 법적 청구를 위해 필요한 정보는 삭제하지 못할 수 있습니다.

개인정보 관련 요청은 hello@istraveler.com으로 제출할 수 있습니다.

18. 개인정보 관련 질문 및 불만

개인정보 처리에 관한 질문, 요청 또는 불만은 먼저 이즈트래블 개인정보 보호책임자에게 제출해 주시기 바랍니다.

개인정보 보호책임자
ISTRAVEL
1235 Bay Street, Suite 700
Toronto, ON M5R 3K4
이메일: hello@istraveler.com

이즈트래블은 개인정보 관련 요청이나 불만을 공정하게 검토하고 합리적인 기간 내에 답변하기 위해 노력합니다.

이즈트래블의 답변에 만족하지 못하는 경우 캐나다 개인정보보호위원회에 문의하거나 불만을 제기할 수 있습니다.

캐나다 개인정보보호위원회
Office of the Privacy Commissioner of Canada
웹사이트: priv.gc.ca

TICO 등록 또는 여행업 규정과 관련된 사안은 TICO에 문의할 수 있습니다. 다만 TICO는 일반적인 개인정보 보호 민원을 담당하는 주된 개인정보 감독기관이 아닐 수 있습니다.

19. 외부 웹사이트 및 제3자 서비스

이즈트래블 웹사이트에는 Fora, 호텔, 크루즈 선사, 보험사, 결제업체, 소셜미디어 또는 기타 외부 웹사이트로 연결되는 링크가 포함될 수 있습니다.

이즈트래블은 독립된 제3자의 웹사이트, 보안조치 또는 개인정보 처리방침을 관리하지 않습니다. 고객은 외부 웹사이트에 개인정보를 제공하기 전에 해당 제3자의 개인정보 처리방침을 확인해야 합니다.

외부 링크가 웹사이트에 포함되어 있다는 사실만으로 이즈트래블이 해당 제3자의 개인정보 처리 방식이나 보안을 보증한다는 의미는 아닙니다.

20. 본 정책의 변경

이즈트래블은 서비스, 기술, 공급업체 또는 법적 요구사항의 변경을 반영하기 위해 본 정책을 수정할 수 있습니다.

개정된 정책은 새로운 “최종 업데이트” 날짜와 함께 웹사이트에 게시됩니다.

중요한 변경이 고객의 권리나 개인정보 이용 방식에 중대한 영향을 주는 경우, 이즈트래블은 이메일, 웹사이트 공지 또는 기타 적절한 방법으로 추가 안내를 제공하고 법률상 필요한 경우 새로운 동의를 받습니다.

정책 변경은 관련 법률이 허용하지 않는 범위에서 기존에 수집한 개인정보의 이용 목적을 소급하여 확대하지 않습니다.

21. 언어

본 정책은 고객의 편의를 위해 한국어와 영어로 제공될 수 있습니다. 두 언어의 정책은 동일한 의미를 전달하도록 작성됩니다.

번역본 사이에 중요한 불일치가 있는 경우 적용 법률이 허용하는 범위에서 영어본이 우선합니다.

다만 이러한 우선순위 조항은 고객에게 실제로 제공된 고지, 관련 법률에 따라 포기할 수 없는 고객의 권리 또는 의미 있는 동의에 관한 요건을 제한하지 않습니다.

1. Purpose and Scope

This Privacy Policy explains how ISTRAVEL (“ISTRAVEL,” “we,” “our” or “us”) collects, uses, discloses, retains and protects personal information in connection with istraveler.com, inquiry forms, email, KakaoTalk and our travel consultation and booking services.

ISTRAVEL is an independently operated travel advisory brand. Travel bookings made through ISTRAVEL are processed through Fora Travel Inc., a travel agency registered with the Travel Industry Council of Ontario (“TICO”).

ISTRAVEL (Affiliate of Fora Travel Inc.)
TICO Registration No. 50027942
Registered Address: 1235 Bay Street, Suite 700, Toronto, ON M5R 3K4

Where applicable, ISTRAVEL’s handling of personal information is governed by Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), Canada’s Anti-Spam Legislation (“CASL”), the Travel Industry Act, 2002, Ontario Regulation 26/05 and other applicable laws.

This Policy applies to personal information under ISTRAVEL’s control. Fora Travel Inc., hotels, cruise lines, airlines, payment processors and other independent third parties may separately process personal information under their own privacy policies.

2. Meaning of Personal Information

“Personal information” means information about an identifiable individual, whether the individual can be identified from that information alone or in combination with other information.

Personal information may include names and contact details, travel itineraries, dates of birth, citizenship, passport information, payment-related information, family relationships, health, dietary or accessibility requests and online identifiers.

Information that has been anonymized so that it cannot reasonably be linked to an identifiable individual may not be treated as personal information under this Policy unless otherwise required by applicable law.

3. Personal Information We Collect

ISTRAVEL may collect the following personal information, depending on the services requested and the nature of the booking.

3.1 Identity and Contact Information
  • Name and full legal name as shown on travel documents;
  • Email address;
  • Telephone number or KakaoTalk contact information;
  • City, province or state and country of residence;
  • Mailing or billing address; and
  • Preferred method of communication.
3.2 Traveller and Booking Information
  • Date of birth and age as of the applicable sailing or check-in date;
  • Gender or title where required by a Supplier;
  • Citizenship, nationality and residency status;
  • Passport type, passport number, issuing country and expiry date;
  • NEXUS, Known Traveller Number and hotel, airline or cruise membership numbers;
  • Flight, hotel, cruise, transportation and other itinerary details;
  • Room, cabin, bedding, dining and other preferences;
  • Travel companions, family relationships and guardianship information for minors;
  • Birthdays, anniversaries and other special-occasion information; and
  • Other information required by a Supplier to complete a booking.
3.3 Payment and Transaction Information
  • Payment authorization status;
  • Cardholder name;
  • Limited payment information, such as card type and the last digits of the card number;
  • Payment amount, currency, date and status;
  • Deposit, outstanding balance, refund and transaction records; and
  • Invoices and booking confirmations.

Complete card numbers, expiry dates and security codes may be collected and processed through a secure payment system designated by Fora. ISTRAVEL does not request or directly retain complete payment card information through ordinary email, KakaoTalk or ordinary documents.

3.4 Health, Dietary and Accessibility Information

Where requested by the customer or necessary to provide travel services, ISTRAVEL may collect sensitive information such as:

  • Mobility assistance and accessibility requirements;
  • Wheelchair or medical-equipment information;
  • Allergies and dietary restrictions;
  • Pregnancy or other health information that may affect travel;
  • Information required by a Supplier to process a special request; and
  • Information reasonably necessary in an emergency.

ISTRAVEL collects and discloses such information only to the extent reasonably necessary to process the relevant request.

3.5 Inquiry and Communication Records
  • Information submitted through inquiry forms;
  • Email and KakaoTalk correspondence;
  • Booking instructions, special requests and customer-service records;
  • Amendment, cancellation, refund, complaint and dispute records; and
  • Documents and attachments provided by the customer.
3.6 Website and Technical Information
  • IP address;
  • Browser and device type;
  • Operating system;
  • Date and time of access;
  • Pages visited and referral or exit pages;
  • Website usage and interaction information;
  • Information collected through cookies, analytics and similar technologies; and
  • Security and diagnostic logs.

4. How We Collect Personal Information

ISTRAVEL may collect personal information:

  • When a customer completes a website inquiry form;
  • When a customer communicates with us through email or KakaoTalk;
  • When a customer completes a booking or payment form;
  • When a customer provides passport information or other travel documents;
  • When a customer submits a special or accessibility request;
  • When Fora or a Supplier provides booking status or change information;
  • Through cookies and analytics technologies used on the website; and
  • When a customer provides information on behalf of a travel companion.

A customer who provides another person’s personal information confirms that they have the appropriate authority to provide it and, where required, have informed that individual or their legal representative and obtained any necessary consent.

5. How We Use Personal Information

ISTRAVEL may use personal information to:

  • Respond to inquiries and understand the customer’s travel requirements;
  • Research and recommend suitable hotels, cruises and other travel services;
  • Prepare quotations and process bookings, payment authorizations, invoices and confirmations;
  • Communicate traveller information to Fora and applicable Suppliers;
  • Process room, cabin, dining, celebration, health, dietary, accessibility and other special requests;
  • Provide reminders regarding final payments, online check-in, itinerary changes and departure preparation;
  • Process booking amendments, cancellations, refunds, customer-support matters and disputes;
  • Fulfil legal disclosure obligations concerning travel documents and booking conditions;
  • Maintain accurate booking, payment, invoicing and customer-service records;
  • Prevent and investigate fraud, unauthorized transactions, security incidents and misuse of services;
  • Operate, maintain, protect and improve the website;
  • Comply with legal and regulatory obligations and establish, exercise or defend legal claims; and
  • Send newsletters and marketing information where the customer has separately consented.

If ISTRAVEL wishes to use personal information for a new purpose that is not reasonably consistent with the original purposes, the customer will be notified and consent will be obtained where required.

6. Consent and Withdrawal of Consent

ISTRAVEL may obtain express or implied consent depending on the sensitivity of the information, the purpose of collection and the customer’s reasonable expectations.

Express consent may be requested for sensitive or material processing, including passport information, health or accessibility information, payment information or a disclosure to a third party that the customer would not reasonably expect.

Merely visiting the website or reading this Privacy Policy does not constitute blanket consent to all processing of personal information. Required consent may be obtained through an inquiry form, booking form, payment form, email, electronic signature or another appropriate method.

A customer may withdraw consent at any time, subject to legal, regulatory and contractual restrictions. Withdrawal may be limited or may affect the services where:

  • The information is required to process or maintain a booking;
  • A Supplier requires the information to provide the travel services;
  • Transaction, tax, accounting, TICO or other regulatory records must be retained;
  • The information is required in connection with a refund, insurance claim, dispute or legal claim; or
  • Collection, use or retention is otherwise permitted or required by law.

If a customer does not consent to or withdraws consent for the processing of information necessary for a booking, ISTRAVEL may be unable to make, maintain or administer the booking.

Marketing consent is managed separately from consent required to provide travel consultation and booking services. Customers may withdraw marketing consent at any time by using the unsubscribe function in a marketing email or contacting hello@istraveler.com.

7. Disclosure of Personal Information

ISTRAVEL may disclose personal information to the following recipients to the extent reasonably necessary to provide and administer travel services:

  • Fora Travel Inc.;
  • Hotels, resorts and other accommodation providers;
  • Cruise lines;
  • Airlines, rail companies and other transportation providers;
  • Tour, excursion, ground transportation and destination-management providers;
  • Travel insurers or insurance intermediaries where requested or authorized by the customer;
  • Payment processors and card networks;
  • Website hosting, inquiry-form, email, customer-management, cloud-storage and business-automation providers;
  • Travel companions or representatives authorized by the customer;
  • Legal, accounting, insurance and other professional advisors; and
  • Government authorities, regulators, courts or law-enforcement bodies authorized by law.

Because of the nature of travel bookings, some Suppliers may process personal information as independent organizations under their own privacy policies after receiving it.

ISTRAVEL does not sell or rent personal information. Personal information is not disclosed for an unrelated third party’s independent marketing purposes unless the customer separately consents.

Where permitted by law, personal information may be transferred as part of a business reorganization, transfer, merger or succession, subject to appropriate confidentiality and privacy protections.

8. International Transfers and Processing

Because of the international nature of travel services, personal information may be transferred to, stored in or processed by Fora, Suppliers and service providers located outside the customer’s province, country of residence or Canada.

For example, when a booking or special request is submitted to an overseas hotel, cruise line, airline or local operator, traveller information may be processed in the relevant destination country.

Information processed in another country may be subject to that country’s laws and may be accessible to foreign government or law-enforcement authorities in response to a lawful request.

ISTRAVEL applies reasonable safeguards to personal information under its control and uses contractual or other reasonable measures to require service providers to handle the information appropriately.

Where an international transfer is not necessary to fulfil a booking or is made for a purpose that the customer would not reasonably expect, ISTRAVEL will provide separate notice and obtain any consent required by applicable law.

9. Protection of Payment Information

ISTRAVEL does not request complete card numbers, card expiry dates or card security codes through ordinary email, KakaoTalk or a general inquiry form.

Payment information must be submitted through a secure payment system designated or approved by Fora. Complete payment card information may be processed directly by that payment system, payment processor or Supplier rather than by ISTRAVEL.

Customers should enter payment information only into an authorized payment form and should not send complete card information by email or KakaoTalk.

If a customer sends complete card information through an unauthorized method, ISTRAVEL may take reasonable steps to securely delete it and redirect the customer to an authorized payment method.

10. Cookies and Analytics Technologies

ISTRAVEL’s website may use cookies and similar technologies to:

  • Provide essential website functionality and security;
  • Remember user preferences;
  • Analyze website visits and usage patterns;
  • Diagnose errors and improve performance; and
  • Measure content and marketing performance.

Essential cookies may be required for the operation and security of the website. Non-essential analytics or marketing cookies that require consent will, where applicable, be used according to the user’s choices.

Customers may block or delete cookies through their browser settings or an available cookie-management tool. Disabling certain cookies may prevent parts of the website from functioning properly.

ISTRAVEL may update this Policy or provide a separate cookie notice if the cookies, analytics tools or marketing technologies used on the website change.

11. Marketing Communications

ISTRAVEL sends newsletters, promotions and other commercial electronic messages only where the customer has consented or where otherwise permitted by applicable law.

Marketing messages will identify the sender and include a method of unsubscribing. Customers may unsubscribe at any time, and unsubscribe requests will be implemented within the period required by applicable law.

Operational communications necessary to administer an existing inquiry or booking—including booking confirmations, payment notices, itinerary changes, final-payment reminders, online check-in and departure information—are not marketing messages and may continue after a customer unsubscribes from marketing.

Declining or withdrawing marketing consent will not adversely affect the customer’s ability to receive travel consultation or booking services.

12. Personal Information of Minors

ISTRAVEL’s website and services are not designed for independent use by minors. However, when arranging family travel, ISTRAVEL may collect a child’s personal information from a parent, legal guardian or authorized adult.

This information may include the child’s name, date of birth, citizenship, passport information, family relationship, dietary, health or accessibility requests and other booking information required by a Supplier.

A person who provides a minor’s personal information confirms that they have the appropriate authority to provide the information and authorize its use for the travel booking.

If ISTRAVEL learns that it collected personal information directly from a minor without appropriate authorization, it will take reasonable steps to delete the information unless retention is required by law.

13. Retention and Disposal

ISTRAVEL retains personal information only for as long as reasonably necessary to:

  • Administer travel inquiries and bookings;
  • Maintain transaction, payment and invoicing records;
  • Address customer service, refund, insurance or dispute matters;
  • Comply with tax, accounting, TICO and other legal or regulatory requirements; and
  • Prevent fraud and establish, exercise or defend legal claims.

Retention periods may vary according to the type and sensitivity of the information, booking status, statutory requirements and the reasonable likelihood of a dispute.

When personal information is no longer required, it will be securely deleted, destroyed or anonymized using reasonable methods. Copies may temporarily remain in third-party backup systems or legally retained records until the applicable deletion cycle expires.

Information that is the subject of an access, correction or privacy challenge may be retained for as long as necessary to allow the individual to exhaust the applicable procedures and available recourse.

14. Security Safeguards

ISTRAVEL uses reasonable administrative, technical and physical safeguards appropriate to the volume, format and sensitivity of the personal information.

These safeguards may include:

  • Restricting access to individuals with a business need to know;
  • Password, multi-factor authentication and account-security measures;
  • Secure payment systems designated or approved by Fora;
  • Encryption during transmission or storage;
  • System updates and security reviews;
  • Limiting the amount of personal information collected;
  • Privacy and security requirements for service providers;
  • Secure deletion of information that is no longer required; and
  • Privacy breach and security-incident response procedures.

No transmission or storage system using the internet, email, messaging services or electronic storage can be guaranteed to be completely secure.

Customers should not send passport copies, complete card information or sensitive health information through ordinary email or KakaoTalk and should use a secure method designated by ISTRAVEL where one is available.

15. Privacy Breach Response

If personal information is lost or is subject to suspected or confirmed unauthorized access, use, disclosure, copying or modification, ISTRAVEL will investigate, mitigate the effects and take reasonable steps to reduce the risk of recurrence.

A breach of security safeguards that creates a “real risk of significant harm” under PIPEDA will be reported to the Office of the Privacy Commissioner of Canada, and affected individuals will be notified, in the manner and within the time required by law.

Relevant financial institutions, Suppliers or other third parties may also be notified where doing so may reduce or mitigate the risk of harm.

ISTRAVEL maintains records of breaches of security safeguards subject to PIPEDA for the period required by law. The current minimum retention period for such records is 24 months after the date on which the breach is determined to have occurred.

16. Accuracy of Personal Information

Customers must provide accurate and current traveller information. Errors in legal names, dates of birth, citizenship, passport information or contact details may result in amendment costs, denial of boarding or other adverse consequences.

Customers should notify ISTRAVEL as soon as reasonably possible if information changes or an error is identified.

ISTRAVEL takes reasonable steps to maintain personal information that is accurate, complete and current to the extent necessary for the purposes for which it is used.

If corrected information has already been disclosed to a Supplier, ISTRAVEL may communicate the correction to the relevant Supplier where reasonably possible. Supplier fees or restrictions may apply to changes made to an existing booking.

17. Individual Privacy Rights

Subject to applicable law and permitted exceptions, an individual may request to:

  • Confirm whether ISTRAVEL holds personal information about them;
  • Access personal information held by ISTRAVEL;
  • Receive an account of how the information has been used or disclosed;
  • Correct inaccurate or incomplete personal information;
  • Delete personal information that is no longer required;
  • Withdraw consent;
  • Unsubscribe from marketing communications; and
  • Challenge or complain about ISTRAVEL’s privacy practices.

ISTRAVEL may request reasonable information to verify the requester’s identity before processing a request.

Access may be restricted where disclosure is prohibited by law or would reveal another person’s information, legally privileged information, confidential commercial information or information relating to an investigation.

If an access or deletion request is refused in whole or in part, ISTRAVEL will explain the reason to the extent permitted by law.

Even where deletion is requested, ISTRAVEL may be unable to delete information required for legal or regulatory retention obligations, an active booking, transaction records, a dispute, fraud prevention or a legal claim.

Privacy requests may be submitted to hello@istraveler.com.

18. Privacy Questions and Complaints

Questions, requests or complaints concerning personal information should first be submitted to ISTRAVEL’s Privacy Officer.

Privacy Officer
ISTRAVEL
1235 Bay Street, Suite 700
Toronto, ON M5R 3K4
Email: hello@istraveler.com

ISTRAVEL will review privacy requests and complaints fairly and make reasonable efforts to respond within an appropriate period.

If an individual is not satisfied with ISTRAVEL’s response, they may contact or submit a complaint to:

Office of the Privacy Commissioner of Canada
Website: priv.gc.ca

Matters concerning TICO registration or travel-industry requirements may also be directed to TICO. However, TICO may not be the primary regulator responsible for general privacy complaints.

19. Third-Party Websites and Services

ISTRAVEL’s website may contain links to Fora, hotels, cruise lines, insurers, payment providers, social media platforms and other external websites.

ISTRAVEL does not control an independent third party’s website, security safeguards or privacy practices. Customers should review the relevant third party’s privacy policy before providing personal information through an external website.

The inclusion of an external link does not mean that ISTRAVEL guarantees or endorses the third party’s privacy or security practices.

20. Changes to This Policy

ISTRAVEL may amend this Policy to reflect changes in its services, technologies, Suppliers or legal requirements.

The revised Policy will be posted on the website with a new “Last Updated” date.

If a material change significantly affects individual rights or how personal information is used, ISTRAVEL will provide additional notice by email, website notice or another appropriate method and will obtain new consent where required by law.

A change to this Policy will not retroactively expand the purposes for which previously collected personal information may be used where doing so is not permitted by applicable law.

21. Language

This Policy may be provided in Korean and English for the customer’s convenience. The two versions are intended to convey the same meaning.

If there is a material inconsistency between the translations, the English version will prevail to the extent permitted by applicable law.

This language provision does not limit any notice actually provided to the customer, any non-waivable right under applicable law or the requirements for meaningful consent.