Privacy Policy
ReturnPixel Co., Ltd. (hereinafter the "Company") places importance on protecting users' personal information and complies with relevant laws and regulations, including the Personal Information Protection Act, the Protection of Communications Secrets Act, the Telecommunications Business Act, the Act on the Protection and Use of Location Information, and the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. Through this Privacy Policy, the Company informs users of the purposes and manner in which the personal information they provide is used, and of the measures taken to protect personal information.
This Privacy Policy may be changed from time to time due to changes in government laws and guidelines or changes in the Company's internal policies. When it is amended, the Company announces the changes through website notices (or individual notices) so that users can easily recognize them and view them at any time. Users are therefore requested to check the contents from time to time when visiting the site.
Article 1 (Items of Personal Information Collected and Methods of Collection)
- Items of personal information collected
- The Company collects the following personal information at the time of initial membership registration or service use in order to provide various services:
- (Required) Membership registration/login: Google Play ID, Facebook ID, Apple ID, nickname
- (Required) Customer support: e-mail, ID, nickname, device information (device name and OS version), user unique number, game version in use, name of the store in use
- (Optional) Events/promotions: name, e-mail, phone number, address, postal code
- (Optional) Recovery and refunds: carrier information, e-mail address, purchase-history confirmation details, and, to confirm the fact of payment made by someone other than the account holder, real name and proof of family relationship
- For services that do not have a separate consent procedure under Paragraph 1, required and optional items are not collected.
- The following information may be generated and collected during the course of service use or business processing:
- The user's mobile device information (model name, OS version, mobile firmware version, device unique number), IP address, cookies, last access location
- Records when using location-based services (location information)
- Access date and time, service usage records
- Methods of collection
- Collected by providing a consent procedure upon signing up for the Company's service
- Collected through a separate consent procedure for conducting promotions and events
- Collected automatically through platforms that have a partnership relationship with the Company in connection with service provision
- Collected upon the user's voluntary provision, or upon request as needed, during payment and customer support while using the service
- Members may refuse the collection and use of the above personal information. However, if a Member refuses the collection and use of personal information, use of some or all of the service may be difficult.
Article 2 (Purposes of Collecting and Using Personal Information)
The Company does not disclose collected personal information without the user's prior consent, and uses collected personal information for the following purposes:
- Identity verification for service use, customer support, and statistical analysis of the service
- E-mail, nickname, SNS identification information, phone model name, phone OS version, phone manufacturer, date and time information displayed on the phone, phone display resolution, mobile carrier information, Android Device ID
- Prevention of Members' improper use and prevention of unauthorized use
- Access IP information, service usage records, access logs, visit date and time, abusive-use records, date and time information set on the device
- Personal identification of users and information sharing
- Profile picture, photos registered within the service, SNS identification information
- Use for new service development and marketing/advertising
- New service development and provision of customized services, provision of services and placement of advertisements according to demographic characteristics, verification of the service's effectiveness, provision of events and advertising information and opportunities to participate, ascertaining access frequency, and statistical purposes regarding users' service use
Article 3 (Processing and Retention Period of Personal Information)
- As a rule, a Member's personal information is destroyed so that it cannot be recovered or reproduced, in accordance with the Personal Information Protection Act, once the purpose of collecting and using the personal information has been achieved. In accordance with the Terms of Service and internal policy, the Company completely deletes personal information upon a Member's withdrawal in order to prevent improper use.
- Notwithstanding Paragraph 1 of this Article, even where the purpose of collection or the purpose for which the information was provided has been achieved, the Company retains user information for a certain period prescribed by relevant statutes where there is a need to preserve it under the provisions of statutes such as the Commercial Act, or where there are grounds for information protection under internal policy or other relevant statutes. In such cases, the Company uses the retained information only for the purpose of that retention, and the retention periods are as follows:
- Records regarding contracts or withdrawal of subscription, etc.
- Basis for retention: Act on the Consumer Protection in Electronic Commerce, etc.
- Retention period: 5 years
- Records regarding payment and the supply of goods, etc.
- Basis for retention: Act on the Consumer Protection in Electronic Commerce, etc.
- Retention period: 5 years
- Records regarding consumer complaints or dispute handling
- Basis for retention: Act on the Consumer Protection in Electronic Commerce, etc.
- Retention period: 3 years
- Records regarding electronic financial transactions
- Basis for retention: Electronic Financial Transactions Act
- Retention period: 3 years
- Records regarding display/advertising
- Basis for retention: Act on the Consumer Protection in Electronic Commerce, etc.
- Retention period: 6 months
- Records regarding identity verification
- Basis for retention: Act on Promotion of Information and Communications Network Utilization and Information Protection, etc.
- Retention period: 6 months
- Personal information related to service use (access records, usage records, IP information)
- Basis for retention: Protection of Communications Secrets Act
- Retention period: 3 months
Article 4 (Sharing and Provision of Personal Information)
- The Company uses a Member's personal information within the scope stated in the purposes of collecting and using personal information, and does not use it beyond the above scope, or provide or share it with others or other institutions, without the Member's prior consent. However, exceptions apply where the Member has consented in advance, or where the Member engages in conduct that violates the Company's Terms of Service or policies and operating rules separately established by the Company, and legal measures are required pursuant to relevant laws or for investigative purposes in accordance with the procedures and methods prescribed by statute, or where there is a request from a relevant investigative agency.
- The Company may provide or share a Member's personal information with partners for business reasons such as providing customized services for each Member or user and various other services. However, when providing or sharing personal information, the Company will, before providing the information, go through a procedure of notifying in advance and obtaining consent regarding the partner's name, the partnership purpose, the scope of personal information provided or shared, and how long it will be used/retained; and where the Member does not consent, it will not provide or share the information with the partner.
- "Where the Member has consented in advance" means where the Member has consented to the provision of personal information to a third party while participating in various promotions such as using a partner service, entering an event, participating in user research, or using a donation service. Even in such cases, the Company notifies the Member in advance of the recipient of the personal information, the recipient's purpose of use, the items of personal information provided, and the retention and use period of the personal information, and obtains explicit and individual consent thereto. Throughout all such processes, the Company does not collect additional information against the Member's will, or share information beyond the scope of consent with a third party.
Article 5 (Rights of Members and Legal Representatives and How to Exercise Them)
- A Member may at any time view, inquire about, or modify their own personal information, and may also request cancellation of membership or deletion of personal information. However, if personal information necessary for service provision is deleted, the related service may not be provided.
- Where a Member requests correction or deletion of their personal information, the Company takes the necessary measures immediately after verifying the Member's identity. In addition, upon a usage restriction under the Terms of Service, personal information such as the Member ID may be destroyed at the discretion of the person responsible for personal information protection.
- When the Company collects, uses, or provides the personal information of a child under the age of 14, it always obtains the consent of the legal representative.
- Viewing and modification of a Member's personal information is possible after identity verification, upon the request of the Member or the legal representative of a child under the age of 14.
- Where a request has been made to correct an error in personal information, the Company does not use or provide the relevant personal information until the correction is completed. In addition, where incorrect personal information has already been provided to a third party, the Company notifies the third party of the result of the correction without delay so that the correction is made.
- The Company processes personal information that has been cancelled or deleted at a Member's request in accordance with the terms stated in "the retention and use period of personal information collected by the Company," and processes it so that it cannot be viewed or used for any other purpose.
Article 6 (Matters Concerning the Installation and Operation of Devices for Automatic Collection of Personal Information, and Refusal Thereof)
- Items collected: visit records, access IP information, service usage records, advertising identifier, type of mobile telecommunications device, model name, operating system, OS version, region, number of first launches, app updates, cookies (a cookie is a small amount of information that the server (http) operating the service sends to the user's device, and is sometimes stored on the user's device).
- Types and methods of cookie use:
- Google Analytics: The Company uses a behavioral information analysis tool provided by Google, and GA collects the main actions (behavioral information) of the Company's service users through cookies. The collected information cannot identify individual users, but can be refused by the method below.
- How to install, operate, and refuse cookies: Collected cookies are transferred to and stored by Google and Facebook, located in the United States. You can refuse the storage of cookies by the following methods.
- For iPhone: Safari App > Clear History and Website Data > Confirm
- For Chrome: Chrome App > More (top right) > History > Clear browsing data > Select time range > Check the boxes next to "Cookies and site data" and "Cached images or files" > Clear browsing data
Article 7 (Procedures and Methods for Destroying Personal Information)
As a rule, a Member's personal information is destroyed without delay once the purpose of collecting and using the personal information has been achieved. The procedures and methods for destroying personal information are as follows:
- Destruction procedure The Company retains personal information during the retention period in accordance with the basis for retention, and then destroys it so that it cannot be recovered or reproduced.
- Destruction method
- Personal information printed on paper is destroyed by shredding with a shredder or by incineration.
- Personal information stored in the form of an electronic file is deleted so that the records cannot be recovered or reproduced.
Article 8 (Technical/Administrative Measures for the Protection of Personal Information)
- A Member's personal information is primarily protected by a password set by the user. Therefore, a Member must never disclose or share the password with others, and after completing use of the Company's service, must be sure to log out and close the web browser. In particular, when sharing a computer with others or using it in a public place, the above procedure is essential to prevent personal information from being disclosed to others.
- In processing a Member's personal information, the Company takes the following technical and administrative measures to ensure security so that personal information is not lost, stolen, leaked, altered, or damaged:
- Technical measures
- Members' passwords are encrypted so that each user's password cannot be known.
- In preparation for damage to personal information, the Company backs up information from time to time, and uses the latest antivirus programs to prevent Members' personal information and data from being leaked or damaged.
- Through encrypted communications, etc., the Company ensures that personal information can be transmitted safely over the network.
- Using an intrusion prevention system, the Company controls unauthorized access from the outside, and endeavors to equip itself with all possible technical devices to ensure systemic security.
- Administrative measures
- The Company limits the handling of personal information to the person responsible for personal information protection and a minimally composed group of personnel, and restricts other personnel's access rights to personal information.
- Through training for personnel who handle personal information, the Company always emphasizes related obligations such as the duty to protect personal information, and checks from time to time whether the Privacy Policy is being implemented and whether the persons in charge are complying with it, making its best efforts to correct and rectify any problems immediately upon discovery.
- The Company bears no responsibility whatsoever for the leakage or damage of personal information arising from the Member's own mistake or negligence or from other basic risks of the internet.
Article 9 (Contact Information of the Person Responsible for Personal Information Protection and the Department in Charge)
In protecting personal information, the person responsible for personal information protection bears all responsibility where an incident occurs, due to reasons attributable to the Company, that is contrary to the matters notified to users. However, the Company bears no responsibility whatsoever for the damage, infringement, or leakage of information caused by unexpected incidents arising from risks on the network such as hacking, despite technical protective measures having been taken, or for problems arising from the leakage of personal information caused by the user's fault.
To protect customers' personal information and handle complaints related to personal information, the Company designates a person responsible for personal information protection as follows:
Person Responsible for Personal Information Protection
- Affiliation/Position: ReturnPixel Co., Ltd. / Representative Director (CEO)
- Name: Kim Jeong-nam
- Phone number: 010-7131-7675
- E-mail: kinpc3@returnpixel.com
If you need to report or consult about other personal information infringements, please contact the following agencies:
- Personal Information Infringement Report Center (http://privacy.kisa.or.kr, tel. 118)
- Supreme Prosecutors' Office, Cyber Investigation Division (http://www.spo.go.kr, tel. 02-3480-2000)
- National Police Agency, Cyber Bureau (http://www.ctrc.go.kr, tel. 182)
- Personal Information Dispute Mediation Committee (http://www.kopico.go.kr, tel. 1833-6972)
Article 10 (Changes to the Privacy Policy and Notification)
Where there is any addition, deletion, or modification to the contents of this Privacy Policy, the Company will, as a rule, give notice through notices at least 7 days before the amendment; and changes that are unfavorable to Members will be notified at least 30 days before the amendment.