> For the complete documentation index, see [llms.txt](https://onestore-dev.gitbook.io/dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://onestore-dev.gitbook.io/dev/eng/docs/review/one-store-review-guideline/personal-information-protection-and-security.md).

# Personal Information Protection and Security

## **Collection and Use of Personal Information**

* 'Personal Information' refers to individual identification information, financial and payment information, authentication information, and any other information that, even if not sufficient on its own to identify a specific individual, can easily be combined with other information to identify an individual.
* For products that collect personal information, you must adhere to the following:
  * Minimize access permissions to the extent required for the service.
  * Inform users of legal notices (items of collected personal information, processing purposes, retention periods, the right to refuse consent) and implement an explicit consent procedure.
  * When notifying users, specify the purpose and retention period of collecting personal information in detail. Process only the minimum necessary personal information within the scope required for the service purpose, and do not use it for purposes other than the intended one.
  * Additionally, disclose a privacy policy to make information about the processing of personal information easily understandable for users. Ensure that users' rights stipulated in relevant laws, such as the right to access and request information, are upheld. Furthermore, for matters beyond these, comply with personal data protection laws specific to each country, such as GDPR.
    * [Official Guideline for Privacy Policy(PIPC)](https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS217\&mCode=D010030000\&nttId=7909)
  * When collecting personal information from a child, it is mandatory to inform the legal guardian and obtain explicit consent before collection.
  * Data collection from children online must comply with privacy regulations in each country.
* For services that store and use location information, in accordance with the laws and regulations of the service country, we may request verification of registration or reporting details. If verification is not provided or if false information is provided, the sale of the product may be suspended.

## **Prevention of Malicious Behavior**

* We prohibit all malicious code or actions that may put users' data or devices at risk (e.g. viruses, spyware, trojan horses, adware, rooting, etc.).
* We prohibit codes or acts that harm users and others by using users' devices, programs, and networks (e.g. spam, DDoS, cryptojacking, etc.).
* We prohibit codes or actions that cause inconvenience to users or deceive users (e.g. phishing, fraudulent ads, etc.).
