Privacy Policy
Effective date · 2026-09-01
This policy explains what personal information millio collects when you book, how we use it, and your choices. millio is operated by Pinomad Corp. (주식회사 핀노마드).
1. Information we collect
- Booking details: name, phone number, email, country, the place, the item you book (service, menu item, or rental item) and the time you choose, the number of people, and the names of anyone you add to the booking.
- Account information if you sign up (email, or your social login profile such as Google or LINE).
- Messages you exchange with the place about your booking, and anything you type into our support chat.
- Payment status. Full card numbers are handled by PayPal — millio never receives or stores them.
- Where your booking asks it: what you tell us will be on your nails when you come in (bare, polish, gel, extensions, or not sure). We ask once per person on the booking.
- Reference photos, if you add them to a booking that takes them: up to 3 pictures, 4MB each — the look you want, or how things look right now, so a picture may show part of you (your hands, your hair, your face). Adding them is optional and only possible while you are signed in; add none and there is nothing here to collect. Your browser re-saves each picture before sending it and our server processes it again, which strips out where and when it was taken and what device took it — we never receive the location of your photos.
- Links, if you paste them into a booking that takes them: up to 3 addresses of posts on the social apps we accept. We never visit the address ourselves — no fetching, no preview — and we strip the tracking parameters out before saving it.
- A note, if you write one on a booking that asks for it: up to 500 characters in your own words, plus the Korean translation we make of it. This is where you tell the place something they should know before your appointment, so it may include something about your health — a procedure you had, a pregnancy, an allergy, how your skin or scalp has been. We only collect it if you tick the separate box next to it (see below). Write nothing and there is nothing here to collect.
- Review photos, if you add them to a review: up to 4 pictures. These are different from reference photos — they are meant to be public. They can appear on the place's page, and the image file itself has a permanent public address, so anyone who has that address can open it even while the review is hidden. We strip out where and when the picture was taken.
About that note. Under Korean law, information about your health is handled separately from everything else, and we may only collect it if you agree to that on its own — not bundled into the agreement you give for the rest. So the note has its own box, right underneath it, and the box only appears once you have written something. Here is what you are agreeing to: the note (and its Korean translation) is read by the place you booked — the owner and the person assigned to you — and by millio's operators, and by no one else; it goes through Anthropic in the United States to be translated into Korean, because the person doing your treatment reads Korean; it is never put in an email or a text message; and it is kept with your booking and deleted when your booking is. You can say no. Leave the note empty and book exactly as usual — nothing about your booking changes, and we ask for nothing.
2. How we use it
- To create and manage your booking and pass it to the place you booked — or, where millio books on your behalf, to request that booking there for you.
- To pass your reference photos, links and note — and, where your booking asks it, what will be on your nails — to the place you booked, so the right preparation can be made before you arrive. We use reference photos and your note for nothing else — not advertising, not reviews, not training AI, not analytics.
- To publish the reviews and review photos you write on the place's page.
- To send booking confirmations and updates.
- To provide customer support and issue coupons or discounts.
- To keep the service secure and comply with legal obligations.
3. Who we share it with
We share the information needed to fulfil your booking with the place you booked — your name, your contact details, what and when you booked, how many people are coming (with any companion names you entered), and, where your booking asks it, what will be on your nails.
Only three people can open a reference photo, a link you pasted, or a note you wrote: the owner of the place you booked, the staff member assigned to your booking, and millio's own operators. No one else sees them. They sit in private storage in the Seoul region of Korea with no public address — this is not an “anyone with the link can open it” setup — and the place opens them inside the millio console, never by email.
We also use service providers to run the service on our behalf: cloud hosting, database and file storage (Supabase, Vercel), transactional email (Resend), machine translation and the support chat assistant (Anthropic), online payment and refunds (PayPal), and a Korean messaging provider that notifies the place by KakaoTalk or SMS (Solapi). We do not sell your personal information.
4. Where your data is processed, and transfers outside Korea
millio's database and application servers run in the Seoul region of the Republic of Korea, and the place you book is in Korea. Your booking record is stored there. Our hosting providers are companies headquartered outside Korea, but the region your data is stored and processed in is Korea.
Some features do send data outside Korea. Korea's Personal Information Protection Act (Article 28-8) requires us to tell you exactly which, so here they are:
- Resend, Inc. — United States. Sent over an encrypted connection each time we email you: your email address, your name, and the booking details contained in the message (the place, the item you booked — service, menu item, or rental item —, date and time, number of people, amounts, and your booking management link). The notification we send to the place also contains your country and the contact method you entered (phone number or messenger ID). Purpose: delivering that email. Retained until the purpose is met or our contract with the provider ends.
- Anthropic PBC — United States. Sent over an encrypted connection at the moment the feature runs: messages you exchange with the place (for translation), a note you wrote on a booking after ticking the separate box next to it (to translate it into Korean for the person doing your treatment), what you type into the support chat (to generate the reply), and the place's listing written in Korean — its description, address, and the names of the items it offers (services, menu items, or rental items), and, where the place assigns staff, their names and profiles (for translation). Purpose: producing the translation or the reply. Retained until the purpose is met or our contract with the provider ends.
- PayPal — United States. Sent when you pay or are refunded: the amount, the currency, and an identifier for your booking. Your card or PayPal account details are entered with PayPal directly and do not pass through millio. Purpose: processing the payment or refund. Retained for as long as PayPal must keep payment records.
A note you write is the one thing here that does leave Korea: it goes to Anthropic to be translated into Korean, and only if you ticked the box next to it. It is never emailed, so it never reaches Resend.
Reference photos go to none of them. They are not attached to email (they never reach Resend), they are not translated (they never reach Anthropic), and they have nothing to do with payment (they never reach PayPal). They stay in private storage in the Seoul region of Korea.
You may refuse these transfers. Because they are how we email your confirmation, take payment, and translate what the place writes to you, refusing means we cannot complete a booking for you. To refuse, or to ask anything about a transfer, contact us at the address below before you book.
5. Retention
We keep your booking information while your account is active and for as long as needed to provide the service and meet legal, tax, and dispute-resolution requirements, after which it is deleted or anonymized.
Links you paste, and any note you write (with its Korean translation), are kept with the booking itself and go when it does — there is no separate schedule for them, because there is no file to delete. If you delete your account, we remove them from your past bookings straight away.
Reference photos are deleted on a fixed schedule, automatically — you do not have to ask:
- 90 days after the day you visited
- If the place never confirmed it and your booking stayed a request: 90 days after the date you had asked for
- If you added pictures but never sent the request: 24 hours after you uploaded them
- If you delete your account: straight away
Review photos stay while the review is up. If you ask us to take a review down, the pictures go with it. If you delete your account, we delete your review photos and the name and email attached to your reviews; the text stays, with nothing left to say who wrote it, because it is about the place's work rather than about you.
6. Your rights
You may access, correct, or delete your information, and you can cancel eligible bookings from “My bookings”. To make a request, contact us using the details below.
7. Cookies
We use only essential cookies and similar storage to keep you signed in and remember your language. We do not use them to sell your data.
8. Contact
Notice of amendment — the note you can write on a booking. Posted 2026-09-01, effective 2026-09-01, the same day. Some bookings now ask for a note in your own words — something the place should know before your appointment. Because what you write there may be about your health, we treat it differently from everything else on this page: we ask for it separately, and only collect it if you agree separately. Sections 1 to 5 change as a result, and what we collect does change. From 2026-09-01, bookings that ask for it show the note box when you are signed in. Nothing is collected unless you write in it and tick the separate consent that appears underneath — leave it empty and there is nothing here for us to collect. Another amendment took effect on the same date: the one below, about reference photos and links. It is a separate amendment.
We post a notice inside the service at least 7 days before an amendment takes effect. This one did not get those 7 days — it takes effect the day we posted it. We first posted this amendment as effective 2026-09-08 and changed it the same day to take effect immediately. This was our decision, made on 2026-09-01, and it is on us. The two amendments below did not get those 7 days either, and when we posted them we said the next one would — this is that next one, and it did not. This is also the one that least deserved it: it is the amendment that adds health information to what we collect. Why we did it anyway: millio is not open to the public yet, the note is optional, and nothing is collected unless you write something and tick the separate box. So we are not making that promise again in the same words. Once millio is open to the public, every amendment will keep the full 7 days, without exception. Until then, we will skip the 7 days only for an amendment that adds an optional box — one where nothing is collected if you write nothing — and we will say so here on the day it takes effect, as we are doing now.
Earlier notice — effective 2026-09-01. Bookings can now carry reference photos and links (both optional) and tell the place what will be on your nails. Sections 1 to 5 changed as a result: what we collect and how long we keep it changed. Review photos had always been part of the service but were missing from this policy and were written in then. That amendment took effect on the day we posted it — we did not give 7 days, and we would rather write that down than let it pass unsaid. It also carried the change announced on 2026-08-27, which describes the purpose of our processing by what we do rather than by industry; that one was posted 5 days before it took effect, not 7.
For any privacy question or request, contact Pinomad Corp. (주식회사 핀노마드) at support@millio.co.
- Data Protection Officer: Soyoung Park — kathy@millio.co
- Operator: 주식회사 핀노마드 (Pinomad Corp.) · Business registration number 535-86-03642
- Address: 3F 311-558, 127 Gimpohangang 10-ro 133beon-gil, Gimpo-si, Gyeonggi-do, Republic of Korea