FlyToGlow Privacy Policy
Version 1.1 · Effective Date: July 6, 2026
Company: FlyToGlow Pte. Ltd.
Website: flytoglow.com
Public-facing policy for users of FlyToGlow services, including AI Glow Check and medical tourism booking services.
Version Control
| Item | Details |
|---|---|
| Document | Privacy Policy |
| Version | 1.1 |
| Effective Date | July 6, 2026 |
| Company | FlyToGlow Pte. Ltd. |
| Website | flytoglow.com |
| Contact Email | admin@flytoglow.com |
| Registered Address | 68 Circular Road, #02-01, Singapore 049422 |
| UEN / Registration No. | 202628438C |
Table of Contents
3. Who is Responsible for Your Personal Data
5. Sensitive Information, Health-Related Information and Facial Images
6. How We Collect Personal Data
7. Purposes for Which We Use Personal Data
9. AI Glow Check and Automated Analysis
10. Cookies, Analytics and Similar Technologies
12. Disclosure of Personal Data
18. Withdrawal of Consent and Account Deletion
20. Third-Party Websites and Clinics
Annex A. Data Processing Matrix
1. Introduction
This Privacy Policy explains how FlyToGlow Pte. Ltd. collects, uses, discloses, stores, transfers and protects personal data when you use flytoglow.com, our mobile or web-based services, AI Glow Check, booking features, communications, promotional campaigns and related services.
FlyToGlow is designed as a cross-border medical tourism and K-beauty medical booking platform. We connect international users with independent medical institutions and clinics in the Republic of Korea. We are not a hospital, clinic, medical practitioner or emergency medical service provider.
This Policy should be read together with our Terms of Service, Refund and Cancellation Policy, Cookie Policy, and AI Glow Check Disclaimer. Where a separate consent notice or clinic-specific notice is presented to you, that notice will apply in addition to this Policy.
2. Scope of this Policy
This Policy applies to personal data that we process in connection with the Service, including data submitted through account registration, AI Glow Check, treatment interests, booking requests, consultation coordination, customer support, reviews, marketing communications and website analytics.
This Policy does not apply to personal data processed independently by Partner Clinics, hospitals, payment providers, travel providers, insurers, hotels, airlines, social media platforms, or other third parties that operate under their own privacy notices. Partner Clinics are independent controllers or responsible organisations for medical records, diagnosis, consultation notes, treatment decisions and post-treatment care records that they create or maintain.
3. Who is Responsible for Your Personal Data
FlyToGlow Pte. Ltd. is responsible for personal data that it collects and determines how to use for operation of the Service. For certain activities, Partner Clinics or payment processors may act as independent organisations responsible for their own processing.
For privacy questions, consent withdrawal requests, access requests, correction requests, deletion requests or complaints, you may contact us at admin@flytoglow.com. We will verify your identity before processing requests that affect personal data or account access.
We have designated a Data Protection Officer in accordance with the Singapore Personal Data Protection Act 2012. You may contact our Data Protection Officer by email at admin@flytoglow.com, marked for the attention of the Data Protection Officer.
4. Personal Data We Collect
We collect only personal data that is reasonably necessary for the purposes described in this Policy, unless additional consent is obtained or the law permits or requires otherwise.
| Category | Examples |
|---|---|
| Account and identity data | Name, email address, password or authentication credentials, nationality, country of residence, preferred language, account ID and login information. |
| Contact data | Phone number, messaging account details, address or emergency contact details if voluntarily provided for a booking or concierge request. |
| Booking and service data | Preferred clinic, treatment category, appointment date, consultation request, travel date, treatment preferences, clinic communications and booking status. |
| Health-related and beauty concern data | Skin concerns, treatment interests, allergies, medication notes, prior procedure information, relevant health declarations and information submitted for consultation coordination. |
| Image and AI Glow Check data | Facial images, uploaded skin photos, AI analysis inputs and outputs, metadata associated with uploads and skin concern tags generated by the Service. |
| Payment-related data | Payment status, transaction reference, amount, currency, refund status and limited payment metadata. We do not store full card numbers; card payments are processed by third-party payment providers. |
| Technical and usage data | IP address, device identifiers, browser type, operating system, pages viewed, referral source, cookies, log data, error reports and service usage events. |
| Communications data | Customer support messages, emails, chat messages, survey answers, complaints, feedback and consent records. |
| Marketing and preference data | Marketing opt-in status, communication preferences, campaign interactions, promotion usage and interests. |
5. Sensitive Information, Health-Related Information and Facial Images
Because FlyToGlow supports medical tourism and aesthetic medical bookings, some information you provide may be sensitive or health-related. This may include treatment interests, skin concerns, medications, allergies, prior procedures, facial images and information shared for clinic consultation coordination.
You should not upload or submit unnecessary medical information. You should not submit information about another person unless you have authority to do so and have informed that person of this Policy. You should not use the Service for emergency medical situations.
Where we request consent for facial images, health-related information, AI Glow Check or cross-border clinic sharing, we will process that information for the disclosed purposes. If you do not wish to provide such information, some features, including AI Glow Check or clinic booking coordination, may not be available.
6. How We Collect Personal Data
- Directly from you when you create an account, submit a booking request, upload images, complete forms, contact support, submit reviews, respond to surveys or participate in promotions.
- Automatically when you use our website, including through cookies, server logs, analytics tools, device identifiers and security monitoring tools.
- From Partner Clinics when they confirm appointment availability, communicate booking outcomes, provide administrative updates or respond to coordination requests.
- From payment processors, authentication providers, analytics providers, messaging services and other service providers that support operation of the Service.
- From public or business sources where reasonably necessary for fraud prevention, compliance checks, dispute resolution or service integrity.
7. Purposes for Which We Use Personal Data
We may collect, use and disclose personal data for the following purposes:
- To register, authenticate, administer and secure user accounts.
- To provide the Service, including treatment discovery, clinic search, booking coordination, customer support and service notifications.
- To operate AI Glow Check, generate informational skin analysis results and present suggested treatment categories for user consideration.
- To share relevant booking and consultation information with selected Partner Clinics in Korea for appointment coordination and pre-consultation preparation.
- To process payments, refunds, chargebacks, invoicing, accounting and transaction records.
- To respond to inquiries, complaints, disputes, reviews, refund requests, clinic feedback and safety incidents.
- To improve, test, monitor, troubleshoot and develop the Service, including quality assurance, analytics, performance measurement and fraud prevention.
- To send transactional communications, appointment reminders, policy notices, security alerts and administrative messages.
- To send marketing communications where permitted by law and where any required consent has been obtained.
- To comply with legal obligations, regulatory requests, lawful enforcement requests, court orders, tax requirements, audit requirements and internal compliance policies.
- To protect the rights, property, safety, security and legitimate interests of FlyToGlow, users, Partner Clinics and the public.
8. Legal Bases and Consent
Singapore PDPA framework. We rely on notification, consent, deemed consent, contractual necessity, legitimate interests where applicable, legal obligations and other grounds permitted under Singapore privacy law. We aim to collect, use and disclose personal data only for purposes that a reasonable person would consider appropriate in the circumstances and that have been notified to you.
Consent. Where consent is required, you may provide consent by checking a box, clicking an acceptance button, submitting a form, uploading an image, making a booking request, choosing to receive marketing communications or otherwise indicating agreement. Certain consents, such as facial image processing, AI Glow Check, marketing and cross-border clinic sharing, may be requested separately.
GDPR-style rights and legal bases. If GDPR or similar laws apply to your use of the Service, our legal bases may include consent, performance of a contract, steps taken at your request before entering into a contract, legal obligation, vital interests in limited circumstances, and legitimate interests such as service security, fraud prevention, analytics, service improvement and dispute management. Where we rely on consent, you may withdraw it at any time, without affecting processing that occurred before withdrawal.
If you decline or withdraw consent for necessary processing, we may not be able to provide certain features, booking coordination, AI Glow Check, customer support, refunds or account services.
9. AI Glow Check and Automated Analysis
AI Glow Check is an informational feature that may process facial images and related skin concern data to generate automated observations or suggested treatment categories. It does not provide medical diagnosis, medical advice, treatment prescription, professional consultation or emergency care.
We may use AI Glow Check data to operate the feature, display results, troubleshoot errors, prevent abuse, improve user experience and maintain service quality. We do not use identifiable facial images to train third-party foundation models without your separate, explicit consent.
AI outputs may be inaccurate, incomplete, biased, outdated or unsuitable for your personal circumstances. You must consult a licensed healthcare professional before making any medical decision, undergoing any treatment, purchasing any medication, or relying on any procedure recommendation.
We may retain AI Glow Check inputs and outputs for the retention periods described in this Policy, unless you request deletion and deletion is legally, technically and operationally feasible. Deletion may not remove copies already lawfully shared with a Partner Clinic for a booking you requested, where the clinic is independently required to retain records.
10. Cookies, Analytics and Similar Technologies
We may use cookies, pixels, tags, local storage, SDKs and similar technologies to operate the website, remember preferences, improve security, measure performance, understand user behavior and support marketing. Our separate Cookie Policy provides additional details.
Cookie categories may include strictly necessary cookies, preference cookies, analytics cookies and marketing cookies. You may be able to manage cookie preferences through our consent banner, browser settings or device settings. Blocking some cookies may affect website functionality.
11. Marketing Communications
We may send marketing communications, newsletters, offers, treatment information, event announcements or promotional messages where permitted by law and, where required, with your consent. You can unsubscribe by using the unsubscribe mechanism in the message or by contacting us.
Transactional, service-related and legal communications are not marketing messages. Even if you opt out of marketing, we may still send booking confirmations, refund notices, security alerts, policy updates and administrative messages.
If marketing messages are sent to Singapore telephone numbers, we will seek to comply with applicable Do Not Call Registry and consent requirements where they apply.
12. Disclosure of Personal Data
We may disclose personal data to the following categories of recipients for the purposes described in this Policy:
- Partner Clinics, hospitals, doctors, clinic coordinators and medical tourism service providers selected by you or relevant to a booking request.
Our affiliates, including our Korean subsidiary registered (where required by Korean law) as a foreign patient attraction agency, where they support booking coordination, patient introduction, customer support or local operations on our behalf.
- Payment processors, banks, card networks, fraud prevention providers, refund processors and accounting service providers.
- Cloud hosting providers, data storage providers, cybersecurity providers, authentication tools, analytics providers, customer support tools, email delivery providers and messaging providers.
- Professional advisers, insurers, auditors, lawyers, accountants, compliance consultants and potential investors or acquirers subject to appropriate confidentiality arrangements.
- Regulators, law enforcement authorities, courts, government agencies or other parties where required or permitted by law.
- Other users or the public where you choose to publish reviews, ratings, testimonials, comments or other user-generated content.
We do not sell personal data as a standalone business model. If we engage in targeted advertising, retargeting or analytics that may be regulated as sharing or sale under certain privacy laws, we will provide applicable notices and choices where required.
13. Cross-Border Transfers
FlyToGlow is based in Singapore and connects users to Partner Clinics in South Korea. Your personal data may therefore be transferred to, stored in, accessed from or processed in Singapore, South Korea and other countries where our service providers, cloud infrastructure, payment processors, analytics providers or support teams operate, and may be shared with our affiliates, including our Korean subsidiary, for the purposes described in this Policy.
Cross-border transfers may include transfer of booking details, contact information, treatment interests, skin concerns, facial images, AI Glow Check outputs and administrative communications to Partner Clinics in South Korea when you request booking coordination or consultation support.
We seek to use appropriate safeguards for cross-border transfers, which may include contractual commitments, confidentiality obligations, access controls, security measures, due diligence of service providers and data processing terms where appropriate. However, privacy laws may differ by country, and data may be subject to lawful access requests in jurisdictions where it is processed.
14. Data Retention
We retain personal data for as long as reasonably necessary to provide the Service, fulfil the purposes described in this Policy, comply with legal obligations, resolve disputes, prevent fraud, enforce agreements, maintain accounting records and protect legitimate business interests.
When personal data is no longer required, we will take reasonable steps to delete, anonymise or securely dispose of it, unless retention is required or permitted by law. Backup copies may persist for a limited period before scheduled deletion.
Partner Clinics may retain medical records independently under their own legal obligations and privacy policies. FlyToGlow does not control legally required retention by Partner Clinics once information has been provided to them for a booking or consultation requested by you.
15. Security Measures
We use reasonable administrative, technical and organisational measures designed to protect personal data against unauthorised access, collection, use, disclosure, copying, modification, disposal, loss and similar risks.
- Access controls and role-based restrictions for staff and service providers.
- Encryption or secure transmission where technically appropriate.
- Authentication, password protection and session management controls.
- Monitoring, logging, vulnerability management and incident response procedures.
- Confidentiality obligations for personnel and service providers handling personal data.
- Data minimisation, retention controls and deletion processes where practicable.
No online service can guarantee absolute security. Users should use strong passwords, protect account credentials, avoid sharing sensitive information unnecessarily and notify us promptly of suspected unauthorised account access.
16. Children and Minors
The Service is intended for adults. Users under the age of 18, or the age of majority in their place of residence if higher, should not use the Service, submit personal data, upload facial images, request bookings or receive marketing communications without consent and supervision of a parent or legal guardian.
If we learn that we have collected personal data from a minor without appropriate consent, we may delete the data, suspend the account or request verification of guardian consent.
17. Your Rights
Depending on applicable law, you may have rights to access, correct, update, delete, restrict, object to, withdraw consent for, or receive a copy of certain personal data. You may also have the right to lodge a complaint with a relevant privacy authority.
Singapore users and other eligible individuals may request access to personal data that we hold about them and request correction of inaccurate personal data, subject to exceptions permitted by law. We may charge a reasonable fee for access requests where permitted and will inform you before processing such requests.
Where GDPR or similar privacy laws apply, you may have additional rights including the right to data portability, right to object to certain processing, right to restriction of processing, right to erasure and rights related to automated decision-making. These rights are subject to legal limitations and verification requirements.
To exercise rights, contact admin@flytoglow.com. We may request identity verification and information needed to locate your account or records. We may decline requests where permitted by law, including where requests are manifestly unfounded, excessive, conflict with legal obligations, affect another person’s rights, or relate to records we do not control.
18. Withdrawal of Consent and Account Deletion
You may withdraw consent for certain processing by changing account settings, using unsubscribe tools, declining optional cookies or contacting us. Withdrawal of consent does not affect processing completed before withdrawal.
If you request account deletion, we will take reasonable steps to delete or anonymise account data that is no longer required. We may retain data where necessary for legal compliance, accounting, dispute resolution, fraud prevention, safety, security, backup management, enforcement of agreements or legitimate business purposes.
Withdrawal of consent for essential processing may prevent us from providing the Service, maintaining your booking, communicating with Partner Clinics, completing refunds or responding to support requests.
19. Data Breach Management
We maintain procedures for assessing and responding to suspected data incidents. Where a data breach is assessed as notifiable under applicable law, we will take steps to notify relevant authorities and affected individuals as required.
Users should promptly notify us at admin@flytoglow.com if they suspect unauthorised access to their account or personal data.
20. Third-Party Websites and Clinics
The Service may contain links to third-party websites, clinic pages, payment pages, social media pages or travel-related services. We are not responsible for the privacy practices, content, security or policies of third parties.
Partner Clinics independently determine clinical intake, consultation records, treatment records, medical photography, consent forms and post-treatment care documentation. You should review each clinic’s privacy notice and medical consent documents before receiving treatment.
21. Changes to this Policy
We may update this Policy from time to time to reflect changes in law, technology, business operations, service features, clinic arrangements, payment providers, analytics tools or privacy practices. The updated version will be posted on the website with a revised effective date.
Where changes materially affect your rights or how we use personal data, we may provide additional notice, request renewed consent or take other steps required by law.
22. Contact Details
FlyToGlow Pte. Ltd. 68 Circular Road, #02-01 Singapore 049422 Email: admin@flytoglow.com UEN / Business Registration Number: 202628438C
Please include your name, contact information, account email and a clear description of your request when contacting us about privacy matters. Do not send unnecessary medical information by email unless specifically requested through a secure channel.
Annex A. Data Processing Matrix
| Purpose | Data Categories | Typical Recipients | Retention Reference |
|---|---|---|---|
| Account registration | Name, email, password/authentication data, nationality, language | Authentication providers, cloud hosting, customer support tools | Account life plus legal/business retention period |
| AI Glow Check | Facial images, skin concern data, AI outputs, technical metadata | Cloud hosting, AI service infrastructure, support/security providers | AI Glow Check retention period or account deletion subject to exceptions |
| Clinic booking coordination | Contact data, booking details, treatment interests, health-related notes, images if submitted for booking | Partner Clinics in South Korea, messaging tools, customer support providers | Booking life plus dispute/accounting/legal retention period |
| Payments and refunds | Payment status, amount, currency, transaction reference, refund status | Payment processors, banks, accounting providers, auditors | Tax/accounting/legal retention period |
| Customer support | Messages, complaints, files voluntarily submitted, account and booking context | Support tools, email/messaging providers, relevant clinics | Support record retention period |
| Marketing | Email, consent status, preferences, campaign interaction data | Email marketing providers, analytics providers | Until opt-out plus suppression/legal record retention |
| Security and fraud prevention | IP address, logs, device/browser information, account events | Security providers, cloud providers, legal advisers if required | Security log retention period |
Annex B. Indicative Retention Schedule
The following schedule sets out the indicative retention periods that we apply. Where multiple retention periods apply, the longest necessary period may be used.
| Record Type | Indicative Retention Period |
|---|---|
| Account information | For the life of the account, then deleted or anonymised within a reasonable period unless retention is required for legal, accounting, dispute or security reasons. |
| Booking and clinic coordination records | Up to 5 years after the booking or last interaction, or longer where necessary for disputes, claims, legal obligations or accounting. |
| Payment and refund records | Up to 5 to 7 years, depending on accounting, tax, audit, chargeback and legal requirements. |
| Customer support records and complaints | Up to 3 to 5 years after resolution, or longer for disputes or legal claims. |
| AI Glow Check images and outputs | As configured in the Service and disclosed to users; ideally deleted or anonymised after the service purpose is fulfilled unless the user consents to longer retention or retention is required for support, safety or legal reasons. |
| Marketing consent records | Until opt-out plus a reasonable suppression and compliance record period. |
| Security logs | Typically 3 to 24 months depending on security needs, investigation needs and technical configuration. |
Annex C. Processor and Service Provider Categories
We use service providers in the categories listed below. We maintain an internal vendor register identifying each service provider, its processing location, security controls, contract status and the data categories it processes.
- Cloud hosting and storage providers.
- AI infrastructure or image processing providers.
- Payment processors and fraud prevention providers.
- Customer support and CRM providers.
- Email, SMS, push notification and messaging providers.
- Analytics, cookie management and marketing technology providers.
- Security monitoring, logging and vulnerability management providers.
- Professional advisers, auditors, insurers and compliance consultants.
- Partner Clinics and medical tourism coordination partners.
Revision History
| Version | Date | Description |
|---|---|---|
| 1.1 | July 6, 2026 | Public version: company registration details completed, Data Protection Officer designated, affiliate and cross-border disclosures added, internal drafting notes removed. |
