Privacy Policy
Version v2.1 (2026-06-15)
This is an English translation provided for convenience. The legally binding version is the Korean original; in case of any discrepancy, the Korean text prevails.
The operator of Bomul Yeojido (the “Service”) complies with the Personal Information Protection Act (PIPA) of Korea and establishes this Privacy Policy to protect users’ personal information.
Article 1 (Purpose of Processing)
| Account authentication & management | Google OAuth login, account identification, session |
| Visit record persistence & sync | Storing visited heritage records, cross-device sync |
| GPS visit verification (v0.4~) | Confirming on-site visits using location data |
| Service improvement & analytics | Usage analysis, error detection, feature improvement |
| Inquiry & feedback handling | Receiving, processing, and replying to user reports |
Article 2 (Items of Personal Information Processed)
2-1. Collected on login
| Email address | Google OAuth | Required |
| Name (display_name) | Google OAuth | Required |
| Profile picture URL | Google OAuth | Required (initials if absent) |
| Visited heritage ID, visit time, method | In-service stamp action | Required (when used) |
2-2. Location data (added with v0.4 GPS verification — not collected yet)
| Current coordinates (lat/lng) | Browser Geolocation API, once per button tap | Confirm within 100 m |
| Acquisition time (verified_at) | Same | Verification timestamp |
No continuous tracking (collected once per tap). Declining location permission only disables GPS verification; browsing remains available.
2-3. Feedback (including anonymous)
| Feedback type & content | Required (5–2,000 chars) |
| Reply email | Optional |
| Related heritage name/ID, page path | Optional / auto-collected |
| User ID | Auto (only when logged in; null otherwise) |
2-4. Automatically collected (non-identifying)
| Usage events, browser/device, region (anonymized IP) | Google Analytics 4 | Improvement & statistics |
| Visited heritage cache | localStorage bomul:visits:v0.1 | Temporary pre-login storage |
| Login flow state | sessionStorage bomul:pending_login | Deleted immediately on login |
IP anonymization: anonymize_ip: true is applied to Google Analytics 4 — full IP addresses are not stored.
Article 3 (Retention Period)
| Account, visit records | Until account deletion — deleted immediately (ON DELETE CASCADE) |
| GPS coordinates (lat/lng) | Erased immediately after verification — not stored on the server (Location Information Act Art. 23) |
| Usage-record evidence (location) | Excluding coordinates (user_id, treasure_id, time, IP) — retained for the statutory period (Art. 16(2)) |
| Feedback content | Until purpose fulfilled (up to ~1 year, then reassessed) |
| GA4 data | Per Google Analytics policy (default 14 months) |
| localStorage cache | While present in the browser; replaced by server data on login |
Exception (PIPA Art. 21(1) proviso): where a statutory retention duty arises, data may be retained after disclosing the legal basis and items. No such duty currently applies.
Article 4 (Provision to Third Parties)
The operator does not, in principle, provide personal information to external parties, except: (i) where the user has consented in advance; or (ii) where required by law or by a lawful request from an investigative agency.
Article 5 (Outsourcing & Cross-Border Transfer)
5-1. Domestic outsourcing
| Kakao Corp. (Korea) | Map API | Map tile requests (no separate location sent) |
5-2. Cross-border transfer — PIPA Art. 28-8(1)3(a) (outsourcing/storage for performing the service contract)
| Supabase, Inc. (USA) | DB & auth | Account, visit records, location, feedback |
| Google LLC (USA) | OAuth & GA4 | Email, name, profile URL / anonymized events |
| Vercel, Inc. (USA) | Serverless hosting & CDN | Server request logs (incl. IP) |
| Resend, Inc. (USA) | Operator notification email | Feedback summary & reply email (optional) |
To object to a transfer, contact the operator via the in-service feedback menu. As these transfers are essential to core features (login, visit records, GPS verification, feedback), declining may restrict or prevent use of those features.
Article 6 (User & Legal Representative Rights)
- Access, correction, deletion (withdrawal), suspension of processing
- Withdrawal of consent (account deletion)
- Withdrawal of location consent (v0.4~): decline browser permission or contact the operator
How to exercise: in-service feedback menu (include “Privacy” in the subject). Processed within 10 days of receipt, after identity verification.
Legal representative rights (PIPA Art. 30(1)5): a legal representative of a child under 14 may request access/correction/deletion/suspension. However, this Service does not accept members under the age of 14.
Article 7 (Destruction Procedure)
Upon withdrawal, the auth.users record is deleted and related rows in profiles/visits are automatically removed via ON DELETE CASCADE (including location data). Location data is erased immediately upon purpose fulfillment (Location Information Act Art. 23; usage-record evidence excepted). The user_id in feedback is set to NULL. Electronic files are permanently erased beyond recovery.
Article 8 (Users Under 14)
This Service does not accept membership (login) by users under the age of 14. By signing up via Google OAuth, the user is deemed to have confirmed that they are at least 14 years old.
Article 9 (Security Measures)
| Access control | Supabase Row Level Security (RLS) — own data only |
| Encryption in transit | HTTPS (TLS) throughout |
| Authentication security | PKCE & HttpOnly cookie-based sessions |
| Data minimization | GPS coordinates collected once at verification, no live tracking |
| Location protection (v0.4~) | Handling guidelines, designated access, automatic usage-record logging |
Article 10 (Cookies)
Cookies used: Supabase authentication cookies (HttpOnly, Secure) and Google Analytics cookies (_ga, _gid, etc.). You may block cookies in your browser settings (login features will be unavailable). To opt out of Google Analytics, use the Google Analytics Opt-out Browser Add-on.
Article 11 (Data Protection Officer)
| Name | Na Gwangsu |
| Contact | In-service feedback menu (include “Privacy” in the subject) |
Address: not stated — PIPA Art. 30(1) imposes no obligation to state an address. Under PIPA Art. 31(2), a small-scale operator’s representative acts as the data protection officer.
Article 12 (Changes to this Policy)
Changes are announced at least 7 days in advance within the Service, or 30 days in advance for material changes.
Effective date: 2026-06-15