Privacy Policy

Effective Date: January 12, 2024 CARETBIO CO., LTD. (“CARETBIO,” “we,” “us,” and “our”) offers a software as a service platform to merchant customers (“Merchants”) that have contracted with CARETBIO to help manage and improve their consumers’ pre- and post-purchase experience, including delivery expectations, order tracking, delivery notifications, product return management, and customer support. CARETBIO may also offer direct-to-consumer services meant to make it easier for consumers to interact with Merchants (the “Consumer Services”). Our Privacy Policy is designed to help you understand how we collect, use and share your personal information and to assist you in exercising the privacy rights available to you. ‍Notice at Collection – Corporate Privacy Policy. At or before the time of collection, all of global customers may have a right to receive notice of our privacy practices applicable to our corporate website and related offerings (excluding the Consumer Services), including the categories of personal information to be collected, the purposes for which such information is collected or used, whether such information is sold or shared and how to opt-out of such uses, and how long such information is retained. You can find those details by clicking on the above links.‍ Notice at Collection – Consumer Services Privacy Policy. At or before the time of collection, all of global customers may have a right to receive notice of our privacy practices applicable the Consumer Services, including the categories of personal information to be collected, the purposes for which such information is collected or used, whether such information is sold or shared and how to opt-out of such uses, and how long such information is retained. You can find those details by clicking on the above links. SCOPE The body of this Privacy Policy applies to personal information processed by CARETBIO in the course of our direct business-to-business relationship with our Merchants and other individuals we may directly interact with, including on our website (“Site”) and our related online and offline offerings. The Consumer Services Privacy Policy Annex to this Privacy Policy describes CARETBIO’s processing of personal information in connection with the Consumer Services. The Consumer Services Privacy Policy Annex supplements, or applies in lieu of, the general disclosures CARETBIO makes in the body of its Privacy Policy regarding the collection, use, and disclosure of personal information. To make this Privacy Policy easier to read, our Site, Consumer Services, and our related offerings are collectively called the “Services.” Please note that unless stated otherwise herein, this Privacy Policy does not apply to or govern the processing of personal information by CARETBIO solely on behalf of our Merchants via CARETBIO’s software as a service platform (the “Merchant Services”). Merchants operate independently from us, and your agreements with the relevant Merchants and their privacy policies govern how they use and share this personal information. When CARETBIO processes personal information solely on behalf of Merchants via the Merchant Services, we act as a “processor” or “service provider” under applicable data protection laws and our processing is governed by agreements we have with our Merchants that require CARETBIO to only process personal information in accordance with our Merchant’s instructions. If you have any questions about how your personal information is processed via the Merchant Services, please refer to the relevant Merchant’s privacy policy. CARETBIO CORPORATE – PERSONAL INFORMATION WE COLLECT The categories of personal information we collect depend on how you interact with our Services. Information You Provide to Us Account Creation. If you create an account with CARETBIO (e.g., as an authorized user of a Merchant), we will collect your name, email address, job title, company name, phone number, and address. Your Communications with Us. We collect personal information from you such as email address, phone number, or mailing address when you use our products or Services, request information about our Services (including a demo), ask to download content (such as a whitepaper or an e-book), subscribe to our newsletter, or otherwise communicate with us. Surveys. We may contact you to participate in surveys. If you decide to participate, you may be asked to provide certain information which may include personal information. Interactive Features. We may offer interactive features such as review forums, blogs, chat and messaging services, and social media pages. We and others who use our Services may collect the information you submit or make available through these interactive features. Any content you provide on the public sections of these features will be considered “public” and is not subject to the privacy protections referenced herein. By using these interactive features, you assume the risk that the personal information provided by you may be viewed and used by third parties for their own purposes. Customer Service and Support. If you call or otherwise interact with CARETBIO’s customer service and support, we may collect the information you provide to our representatives. In addition, we may record telephone calls between you and our representatives for training and quality assurance purposes. Conferences, Trade Shows, and Other Events. We may attend conferences, trade shows, and other events where we collect personal information from individuals who interact with or express an interest in CARETBIO and/or the Services. If you provide us with any information at one of these events, we will use it for the purposes for which it was collected. Business Development and Strategic Partnerships. We may collect personal information from individuals and third parties to assess and pursue potential business opportunities. Information Collected Automatically Automatic Data Collection. We may collect certain information automatically when you use the Services. This information may include your Internet protocol (IP) address, user settings, MAC address, cookie identifiers, mobile advertising and other unique identifiers, details about your browser, operating system or device, location information (including inferred location based off of your IP address), Internet service provider, mobile carrier, pages that you visit before, during and after using the Services, actions that you take while using the Services, information about the links you click, information about how you interact with the Services, including the frequency and duration of your activities, and other information about how you use the Services. Information we collect may be associated with accounts and other devices. Cookies, Pixel Tags/Web Beacons, and other Technologies. We, as well as third parties that provide content, analytics, advertising or other functionality on the Services, may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through the Services. Technologies are essentially small data files placed on your device that allow us and our partners to record certain pieces of information whenever you visit or interact with our Services.For more information about the cookies and similar Technologies used on our Services, please refer to our Cookie Policy. Information from Other Sources Third Party Services and Organizations. We may supplement the information that we collect from you (such as your email address) with additional information about you and your company obtained from publicly available and third-party databases or services that provide information about business people and companies (including an individual’s name, job title, business contact information, and company information). This helps us update, expand and analyze our records, identify new customers, and provide products and services that may be of interest to you. Information We Process via the Merchant Services As stated above, this Privacy Policy does not apply to or govern CARETBIO’s processing of personal information via the Merchant Services. However, for purposes of transparency, we have provided several examples below that highlight how we may process personal information on behalf of Merchants via the Merchant Services. Tracking and Order Status. When consumers make a purchase from one of our Merchants and are the recipient of a package, they may have been provided a link to a CARETBIO’s tracking page in order to check the status of an order. When Merchants use our shipping and order tracking, alert, or return Services, we receive name, order, and shipping information from a carrier or one of our Merchants. Unless you opt-in to our Consumer Services, this information is governed by our Merchant’s privacy policy, not ours. SMS Alerts. The Merchant Services also allow Merchants to ensure that their consumers can obtain information about their orders via SMS. In this case, we will use phone number and other information submitted to us to provide the text messages associated with the SMS service. You may opt out of receiving text messages by replying "STOP" to a text message you have received from us or by otherwise contacting us. Chatbot. The Merchant Services can also allow Merchants to ensure that their consumers can obtain information about their orders via social media platforms such as Facebook Messenger (“Social Media Sites”). When consumers elect to receive this information and interact with CARETBIO’s chatbot on CARETBIO’s or the Social Media Sites (for example, they inquiry about estimated delivery date), we receive from Facebook and process the consumer’s publicly available social media profile information (including name, “locale”, and gender) on behalf of Merchants. Unless you opt-in to our Consumer Services, information shared with Social Media Sites will be governed by the specific privacy policies and terms of service of the Social Media Sites and our Merchants, not by this Privacy Policy. CARETBIO CORPORATE – HOW WE USE YOUR PERSONAL INFORMATION We use your personal information for a variety of business purposes, including: To Provide the Services or Information Requested, such as: • Fulfilling our contract with you or the organization on whose behalf you use the Services; • Responding to questions, comments, and other requests; • Providing access to certain areas, functionalities, and features of our Services; • Answering requests for customer or technical support. Administrative Purposes, such as: • Pursuing legitimate interests, such as direct marketing, research and development (including marketing research), network and information security, and fraud prevention; • Measuring interest and engagement in our Services; • Improving the Services; • Developing new products and services; • Ensuring internal quality control and safety; • Authenticating and verifying individual identities; • Carrying out audits; • Communicating with you about your account, activities on our Services and Privacy Policy changes; • Preventing and prosecuting potentially prohibited or illegal activities; • Enforcing our agreements; and • Complying with our legal obligations. Marketing Our Products and Services. We may use personal information to tailor and provide you with content and advertisements. We may provide you with these materials as permitted by applicable law. If you have any questions about our marketing practices or if you would like to opt out of the use of your personal information for marketing purposes, you may contact us at any time as set forth below. Consent. We may use personal information for other purposes that are clearly disclosed to you at the time you provide personal information or with your consent. De-identified and Aggregated Information Use. We may use personal information and other data about you to create de-identified and/or aggregated information, such as de-identified demographic information, de-identified location information, information about the device from which you access our Services, or other analyses we create. If we create or receive de-identified information, we will not attempt to reidentify such information, unless permitted by, or required to comply with, applicable laws. De-identified and/or aggregated information is not personal information, and we may use and disclose such information in a number of ways, including research, internal analysis, analytics, and any other legally permissible purposes. CARETBIO CORPORATE – DISCLOSING YOUR PERSONAL INFORMATION TO THIRD PARTIES We may share your personal information with the following categories of third parties: Merchants. In cases where you use our Services on behalf of our Merchants (e.g., your employer), our Merchants may access information associated with your use of the Services including usage and other data. Please note that your information may also be subject to our Merchant’s privacy policy. We are not responsible for the privacy or security practices of our Merchants. Service Providers. We may share any personal information we collect about you with our third-party service providers. The categories of service providers to whom we entrust personal information include service providers for: (i) the provision of the Services; (ii) the provision of information, products, and other services you have requested; (iii) marketing and advertising; (iv) payment and transaction processing; (v) customer service activities; and (vi) the provision of IT and related services. Business Partners. We may provide personal information to business partners to provide you with a product or service you have requested. We may also provide personal information to business partners with whom we jointly offer products or services. Affiliates. CARETBIO may share personal information with our affiliated entities, including members of our corporate family in Australia, France, India, Japan and the United Kingdom. Advertising Partners. Through our Services, we may allow third party advertising partners to set Technologies and other tracking tools to collect information regarding your activities and your device (e.g., your IP address, cookie identifiers, page(s) visited, location, time of day). These advertising partners may use this information (and similar information collected from other websites) for purposes of delivering targeted advertisements to you when you visit third party services within their networks. This practice is commonly referred to as “interest-based advertising” or “personalized advertising.” If you would like to opt-out of receiving personalized advertisements from these advertising partners, you may follow the instructions in our Cookie Policy. APIs and Software Development Kits. We may use third party APIs and software development kits (“SDKs”) as part of the functionality of our Services. APIs and SDKs may allow third parties including advertising partners to collect your personal information in order to provide content that is more relevant to you. For more information about our use of APIs and SDKs, please contact us as set forth below. Disclosures to Protect Us or Others We may access, preserve, and disclose any information we store in association with you to external parties if we, in good faith, believe doing so is required or appropriate to: (i) comply with lawful requests of public authorities, including law enforcement or national security requests and legal process, such as a court order or subpoena; (ii) protect your, our, or others’ rights, property, or safety; (iii) enforce our policies or contracts; (iv) collect amounts owed to us; or (v) assist with an investigation and prosecution of suspected or actual illegal activity. Disclosure in the Event of Merger, Sale, or Other Asset Transfer If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, purchase or sale of assets, or transition of service to another provider, then your information may be sold or transferred as part of such a transaction, as permitted by law and/or contract. INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION All personal information processed by us may be transferred, processed, and stored anywhere in the world, including but not limited to, the United States, India, or other countries, which may have data protection laws that are different from the laws where you live. We endeavor to safeguard your personal information consistent with the requirements of applicable laws. If we transfer personal information which originates in the European Economic Area, Switzerland, and/or the United Kingdom to a country that has not been found to provide an adequate level of protection under applicable data protection laws, one of the safeguards we may use to support such transfer is the EU Standard Contractual Clauses. For more information about the safeguards we use for international transfers of your personal information, please contact us as set forth below. YOUR PRIVACY CHOICES AND RIGHTS YOUR PRIVACY CHOICES The privacy choices you may have about your personal information are determined by applicable law and are described below. Email Communications. If you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails. Note that you will continue to receive transaction-related emails regarding products or Services you have requested. We may also send you certain non-promotional communications regarding us and our Services, and you will not be able to opt out of those communications (e.g., communications regarding the Services or updates to our Terms or this Privacy Policy). “Do Not Track”. Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers. YOUR PRIVACY RIGHTS In accordance with applicable law, you may have the right to: (i) confirm whether we are processing your personal information (the right to know); (ii) request access to or a copy of your personal information; (iii) request an electronic copy of personal information that you have provided to us, or ask us to send that information to another company in a structured, commonly used, and machine readable format (the “right of data portability”); (iv) restrict or object to our processing of your personal information; (v) request correction or amendment of your personal information where it is inaccurate, untrue, incomplete, outdated or improperly processed personal information; (vi) withdraw your consent to our processing of your personal information (Note: if you withdraw your consent to processing, some features of the service may not be available); (vii) request erasure, anonymization, or blocking of your personal information; (viii) be informed about third parties with which your personal information has been shared; (ix) request the review of decisions taken exclusively based on automated processing if that could affect data subject rights, subject to certain exceptions prescribed by law; (x) request to opt-out of certain processing activities including, as applicable, if we process your personal information for “targeted advertising” (as “targeted advertising” is defined by applicable privacy laws), if we “sell” your personal information (as “sell” is defined by applicable privacy laws), or if we engage in “profiling” in furtherance of certain “decisions that produce legal or similarly significant effects” concerning you (as such terms are defined by applicable privacy laws); and (xi) limit our use and disclosure of your “sensitive personal information”. If you would like to exercise any of these rights, please contact us by e-mail, idoo21c@caretbio.com We will process such requests in accordance with applicable laws. We may choose to delete personal information by de-identifying and/or aggregating it. To protect your privacy, we will take steps to reasonably verify your identity before fulfilling requests submitted under applicable privacy laws. These steps may involve asking you to provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative. Examples of our verification process may include asking you to confirm the email address we have associated with you. Only you, or someone legally authorized to act on your behalf in certain jurisdictions, may make a request to exercise the rights listed above regarding your personal information. If your personal information is subject to a law that allows an authorized agent to act on your behalf in exercising your privacy rights and you wish to designate an authorized agent, please contact us using the information set forth in “Contact Us” below for further instructions. Some laws may allow you to appeal our decision if we decline to process your request. If applicable laws grant you an appeal right and you would like to appeal our decision with respect to your request, you may do so by informing us of this and providing us with information supporting your appeal. Please note that CARETBIO is not able to fulfill requests it receives from individuals about personal information that is processed via the Merchant Services. If you have a request related to personal information processed via the Merchant Services, please contact the relevant Merchant. RETENTION OF PERSONAL INFORMATION We store the personal information we receive as described in this Privacy Policy for as long as you use our Services or as necessary to fulfill the purpose(s) for which it was collected, provide our Services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable laws. To determine the appropriate retention period for personal information, we may consider applicable legal requirements, the amount, nature, and sensitivity of the personal information, certain risk factors, the purposes for which we process your personal information, and whether we can achieve those purposes through other means. For example, we may retain personal information of job applicants who are not hired for the purposes of considering such applicants for another similar position in the future. We may also retain applicant personal information (including job applications) to process, compare, and analyze this personal information for accuracy, consistency, trends, fraud prevention, insights, and other purposes. CARETBIO CORPORATE – SUPPLEMENTAL NOTICE FOR CALIFORNIA RESIDENTS This Supplemental Notice for California Residents supplements our Privacy Policy and only applies to our processing of personal information that is subject to the California Consumer Privacy Act of 2018 (as amended from time to time) (“CCPA”). It does not apply to the Consumer Services. The Consumer Services Privacy Policy Annex contains a separate Supplemental Notice for California Residents that applies to the Consumer Services. The CCPA provides California residents with the right to know what categories of personal information CARETBIO, in its capacity as a business, has collected about them, whether CARETBIO disclosed that personal information for a business purpose (e.g., to a service provider), whether CARETBIO “sold” that personal information, and whether CARETBIO “shared” that personal information for “cross-context behavioral advertising” in the preceding 12 months. California residents can find this information below: Category of Personal Information Collected by CARETBIO Category of Third Parties to Whom Personal Information Is Disclosed for a BusinessPurpose Category of Third Parties to Whom Personal Information Is Sold and/or Shared Identifiers Service providers Merchants Advertising partners Personal information categories listed in the California CustomerRecords statute (Cal. Civ. Code § 1798.80(e)) Service providers Merchants N/A Protected classification characteristics under California or federal law Service providers N/A Commercial information Service providers N/A Internet or other electronic network activity Service providers Advertising partners Professional or employment-related information Service providersMerchants N/A Inferences drawn from other personal information to create a profile about a consumer Service providers Advertising partners Personal information that revealsa consumer’s account log-in,financial account, debit card, orcredit card number in combinationwith any required security oraccess code, password, orcredentials allowing access to anaccount Service providers N/A The categories of sources from which we collect personal information and our business and commercial purposes for using and disclosing personal information are set forth in “CARETBIO Corporate – Personal Information We Collect,” “CARETBIO Corporate – How We Use Your Personal Information,” and “CARETBIO Corporate – Disclosing Your Personal Information to Third Parties” above, respectively. We will retain personal information in accordance with the time periods set forth in “Retention of Personal Information.” We “sell” and “share” your personal information to provide you with “cross-context behavioral advertising” about CARETBIO’s products and services. Additional Privacy Rights for California Residents Opting Out of “Sales” of Personal Information and/or “Sharing” for Cross-Context Behavioral Advertising under the CCPA. California residents have the right to opt out of the “sale” of personal information and the “sharing” of personal information for “cross-context behavioral advertising.” California residents may exercise these rights by clicking on the following link and following the instructions on that page: Privacy Settings Disclosure Regarding Individuals Under the Age of 16. CARETBIO does not have actual knowledge of any “sale” of personal information of minors under 16 years of age. CARETBIO does not have actual knowledge of any “sharing” of personal information of minors under 16 years of age for “cross-context behavioral advertising.” Disclosure Regarding Opt-Out Preference Signals. California residents may opt out of “sales” of personal information and “sharing” of personal information for “cross-context behavioral advertising” that are carried out on https://global.caretstore.co.kr/ by broadcasting the opt-out preference signal known as the Global Privacy Control (GPC) (on the browsers and/or browser extensions that support such a signal). To download and use a browser supporting the GPC browser signal, visit the Global Privacy Control website. If you choose to use the GPC signal, you will need to turn it on for each supported browser or browser extension you use to visit https://global.caretstore.co.kr/. Disclosure Regarding Sensitive Personal Information. CARETBIO only uses and discloses sensitive personal information for the following purposes: To perform the services or provide the goods reasonably expected by an average consumer who requests those goods or services • To prevent, detect, and investigate security incidents that compromise the availability, authenticity, integrity, and or confidentiality of stored or transmitted personal information. • To resist malicious, deceptive, fraudulent, or illegal actions directed at CARETBIO and to prosecute those responsible for those actions. • To ensure the physical safety of natural persons. • To verify or maintain the quality or safety of a product, service, or device that is owned, manufactured, manufactured for, or controlled by CARETBIO, and to improve, upgrade, or enhance the service or device that is owned, manufactured by, manufactured for, or controlled by CARETBIO. • For purposes that do not infer characteristics about individuals. Non-Discrimination. California residents have the right not to receive discriminatory treatment by us for the exercise of their rights conferred by the CCPA. OUR LAWFUL BASIS FOR PROCESSING For purposes of the EU or UK General Data Protection Regulation, CARETBIO’s processing of your personal information may be supported by the following lawful bases: Performance of a Contract: CARETBIO may need to process your personal information to perform our contract with you or our Merchant. Legitimate Interest: CARETBIO may process your personal information to further our legitimate interests but only where our interests are not overridden by your interests or fundamental rights and freedoms. Consent: In some cases, CARETBIO may also rely on your consent to process your personal information. Compliance with Legal Obligations: CARETBIO may process your personal information to comply with our legal obligations. SUPERVISORY AUTHORITY If your personal information is subject to the applicable data protection laws of the European Economic Area, the United Kingdom, Switzerland, or Brazil you have the right to lodge a complaint with the competent supervisory authority if you believe our processing of your personal information violates applicable law. • Swiss Federal Data Protection and Information Commissioner (FDPIC) • UK Information Commissioner’s Office (ICO) • Autoridade Nacionalde Proteçãode Dados (ANPD) • EEA Data Protection Authorities (DPAs) THIRD PARTY WEBSITES/APPLICATION The Services may contain links to other websites/applications and other websites/applications may reference or link to our Services. These third-party services are not controlled by us. We encourage our users to read the privacy policies of each website and application with which they interact. We do not endorse, screen or approve, and are not responsible for, the privacy practices or content of such other websites or applications. Providing personal information to third-party websites or applications is at your own risk. CHILDREN’S INFORMATION The Services are not directed to children under 16 (or other age as required by local law outside of the United States), and we do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, you may contact us as set forth below. If we learn that a child has provided us with personal information in violation of applicable law, we will delete any personal information we have collected, unless we have a legal obligation to keep it, and terminate the child’s account, if applicable. CHANGES TO OUR PRIVACY POLICY We may revise this Privacy Policy from time to time in our sole discretion. If there are any material changes to this Privacy Policy, we will notify you as required by applicable law. You understand and agree that you will be deemed to have accepted the updated Privacy Policy if you continue to use the Services after the new Privacy Policy takes effect. CONTACT US If you have any questions about our privacy practices or this Privacy Policy, or to exercise your rights as detailed in this Privacy Policy, please contact us at: CARETBIO CO., LTD. 2F., SHINBO Building. 235 BAEKBEOM-RO, MAPO-GU, SEOUL, 04193 REPUBLIC OF KOREA