Privacy Policy
⚠️ The Korean version prevails. This English text is provided for convenience only.
In the event of any discrepancy, the Korean version of this Privacy Policy governs.
Article 1 (Purpose)
코디영 (the "Company") values users' personal information and complies with the Personal Information Protection Act and the Act on the Protection and Use of Location Information of the Republic of Korea. This policy explains how users' personal information is used and what measures are taken to protect it.
This policy applies to the mobile application Donnae (돈내한바퀴) (the "Service").
Article 2 (Personal Information Collected and How)
1) Collected at sign-up and during use
| Type | Items |
|---|---|
| Required | Member identifier received from the social login provider (Kakao, Google, Apple), nickname |
| Required | Device information — installation identifier (UUID) generated by the app, OS version, device model, app version, language, IP address |
| Optional | Profile photo |
| Merchants | Email address (one-time code login) |
2) Generated automatically during use
- Personal location information (latitude/longitude) — see Article 3 and the Location-Based Services Terms
- Course walking records, spot collection records, coin earning/spending history, voucher holding/usage history
- Inquiry content and the IP address at the time of writing
- Error and crash diagnostic information
3) Collection methods
- Entered directly by the user in the app, or provided by the social login provider with the user's consent
- Generated automatically in the course of using the Service
The Company does not collect advertising identifiers (AAID/IDFA). The installation
identifier used by the app is generated inside the app and is destroyed when the app is deleted.
Article 3 (Processing of Personal Location Information)
The Company uses personal location information only while the Service is in use, for:
| Purpose | Detail |
|---|---|
| Spot determination | Verifying whether the user is within a spot's radius to determine coin earning |
| Region recommendation | Showing regions nearest to the user first |
| Map display | Showing the current position on the map |
The Company does not store the location values (coordinates) themselves. Location information is used only for the determinations above and is discarded immediately. The server automatically records and retains only confirmation data on the fact that location information was used or provided (time of use, acquisition path, service provided), as required by Article 16(2) of the Act on the Protection and Use of Location Information.
The Company does not provide personal location information to third parties.
Background location is not collected. Location is used only while the app is in the foreground.
Details are governed by the Location-Based Services Terms.
Article 4 (Purposes of Processing)
- Member identification, confirmation of intent to join, maintaining login sessions
- Coin earning and voucher exchange/usage based on course walking and spot collection
- Prevention of and sanctions against abuse (location spoofing, duplicate earning, multiple accounts)
- Receiving and answering customer inquiries
- Diagnosing errors and improving service quality
- Fulfilling legal obligations
Article 5 (Retention and Use Period)
In principle, personal information is destroyed without delay upon withdrawal of membership, with the following exceptions.
| Item | Period | Basis |
|---|---|---|
| Coin earning/spending and voucher issuance/usage history | 5 years | Act on Consumer Protection in Electronic Commerce, Article 6 (records of contracts, withdrawal of subscription, payment and supply of goods) |
| Inquiry and response records | 3 years | Act on Consumer Protection in Electronic Commerce, Article 6 (records of consumer complaints and dispute handling) |
| Location use/provision confirmation data | 6 months or more | Location Information Act, Article 16(2) |
| Access logs (IP) | 3 months | Protection of Communications Secrets Act, Article 15-2 and Article 41 of its Enforcement Decree |
⚠️ Coin ledger and voucher usage history remain after withdrawal. These are records of
actual value exchanged; deleting them would make disputes impossible to verify. However,
information that can identify the user is anonymized in those records.
Article 6 (Provision to Third Parties)
The Company does not provide users' personal information to third parties, except where required by law or upon a lawful request from an investigative agency.
Article 7 (Entrustment and Overseas Transfer)
| Recipient | Items transferred | Purpose | Country | Retention |
|---|---|---|---|---|
| Functional Software, Inc. (Sentry) | Error diagnostics, member identifier, nickname | App error and crash monitoring | United States | 90 days |
| Google LLC | Social login authentication information | Member authentication | United States | Per that service's policy |
| Apple Inc. | Social login authentication information | Member authentication | United States | Per that service's policy |
Method of transfer: transmitted over the network at the time the Service is used.
Kakao login is authenticated through a domestic (Korean) operator and therefore does not
constitute an overseas transfer. Transfers of social login authentication information occur
only when the user chooses that login method.
⚠️ The Company **does not include location information, authentication tokens, or contact
details** in error diagnostics.
Article 8 (Destruction)
Personal information whose retention period has expired or whose purpose has been achieved is destroyed without delay. Electronic files are deleted by irrecoverable means; printed materials are shredded or incinerated.
Article 9 (Users' Rights and How to Exercise Them)
Users may at any time exercise the following rights:
- Request access to their personal information
- Request correction of errors
- Request deletion
- Request suspension of processing
How to exercise — in the app via My Info → Customer Inquiry, or rediscover.dev@gmail.com.
The Company will act on the request and notify the user of the outcome within 10 days of receiving it.
Membership withdrawal can be done directly in the app via My Info → Withdraw, and may also be requested without installing the app at https://donnae-api.cdy.kr/legal/en/account-deletion.html.
Article 10 (Security Measures)
- Passwordless social login and one-time codes — no passwords are stored
- Encryption in transit (HTTPS/TLS)
- Minimization of access privileges to personal information
- Location values are not stored (Article 3)
Article 11 (Children Under 14)
The Service does not permit sign-up or use by children under the age of 14.
The Company does not collect personal information from children under 14. If it is confirmed that such information has been collected, the Company will destroy the information and delete the account without delay.
A legal guardian may request deletion of such an account via My Info → Customer Inquiry in the app or at rediscover.dev@gmail.com.
Article 12 (Data Protection Officer)
| Name | 홍성범 |
| Title | 대표 (Representative) |
| Contact | rediscover.dev@gmail.com |
Article 13 (Remedies for Infringement)
- Personal Information Dispute Mediation Committee (privacy.go.kr / 1833-6972)
- Korea Internet & Security Agency Privacy Center (privacy.kisa.or.kr / 118)
- Supreme Prosecutors' Office Cybercrime Investigation (spo.go.kr / 1301)
- National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)
Article 14 (Changes to This Policy)
If this policy is added to, deleted from, or amended, the Company will give notice through the app at least 7 days before the change takes effect.
- Notified on: 2026-08-28
- Effective from: 2026-08-28