Pinly
Back to home

This is a translation provided for convenience. If it differs from the Korean version, the Korean version prevails.

Pinly Privacy Policy

WAFFLE (the "Company") complies with applicable laws of the Republic of Korea, including the Personal Information Protection Act and the Act on the Protection, Use, etc. of Location Information (the "Location Information Act"), and establishes and discloses this Privacy Policy to protect users' personal information and respect their rights and interests.

This Privacy Policy applies to "Pinly" (the "Service"), a family location-sharing service, and includes in Article 9 the Personal Location Information Processing Policy required by the Location Information Act. Specific matters concerning the collection, use, and provision of location information are also set out in the separate Location-Based Services Terms.

  • Effective date: 2026-07-01

Article 1 (Personal Information Collected and How It Is Collected)

The Company collects the following personal information during sign-up, use of the Service, and customer support.

  1. Sign-up and authentication

    • Email sign-up: email address, password
    • Social login (Google, Kakao, Apple): name or nickname, email address, profile photo
    • If a user chooses to hide their email with Sign in with Apple or similar, a relay email address may be collected.
  2. Profile information

    • Display name, profile photo, phone number (optional)
  3. Location information (processed under separate terms)

    • Latitude and longitude coordinates, location accuracy, device battery level, charging status
    • Location history (routes traveled within a set period)
    • The location information above is collected periodically, including while the app is in the background and not in use, when the user has granted permission, in order to provide family location sharing, the core feature of the Service.
  4. Device and notification information

    • Push notification token (FCM token), platform (iOS/Android), per-installation device identifier
  5. Information generated and collected automatically

    • Service usage records, access logs, error and diagnostic information, advertising identifier (when ads are shown)
  6. Payment information

    • Pro subscription payments are made through the Apple App Store and Google Play. Payment method information such as card numbers is processed by those stores, and the Company does not store it. The Company processes only subscription status and receipt verification results.

How it is collected: entry in the app, transfer from social login providers, automatic collection based on device permissions, and automatic generation in the course of using the Service.

Article 2 (Purposes of Collection and Use)

The Company uses the personal information it collects only for the following purposes:

  1. Real-time location sharing among members of a family (group)
  2. Geofence-based alerts, such as arrival and departure alerts for places and low-battery alerts
  3. Immediately sharing location and device status with family members and sending alerts in an emergency (SOS)
  4. Sending push notifications
  5. Member registration and management, identity verification, and prevention of fraudulent use
  6. Checking Pro subscription status and providing paid features
  7. Showing non-personalized ads to free users (the Company does not collect age information and does not show personalized ads)
  8. Responding to customer inquiries and improving the Service

Article 3 (Retention Period and Destruction)

  1. As a rule, the Company destroys personal information without delay once the purpose of its collection and use has been achieved.

  2. Location history (location_history) is deleted automatically by a server scheduler 30 days after it is collected.

  3. When a member deletes their account, the Company destroys that member's personal information and location information without delay. However, items that must be retained under applicable laws are stored separately for the required period.

  4. In accordance with Article 16 of the Location Information Act, records confirming the collection, use, and provision of location information are recorded and preserved automatically and retained for at least 6 months.

  5. Retention under applicable laws

    • Under the Act on the Consumer Protection in Electronic Commerce, records of contracts and payments are retained for 5 years. The retained items are the email address at the time of payment, member identifier, payment date and time, product name, payment amount and currency, payment store, and transaction ID. These are stored separately from other personal information even after the member deletes their account, and destroyed automatically after 5 years.
    • Service usage records required under laws such as the Protection of Communications Secrets Act are retained for the period set by those laws.
  6. Destruction method: electronic files are permanently deleted in a way that makes recovery or reproduction impossible, and printed materials are shredded or incinerated.

Article 4 (Provision of Personal Information to Third Parties)

The Company does not provide users' personal information to third parties beyond the scope set out in this Policy, except in the following cases:

  1. When the user has given prior consent
  2. When, by the nature of the family location-sharing service, a user's location information, profile, and similar information are shared with other members of the group to which the user belongs (users can adjust the scope of disclosure themselves)
  3. When specifically required by law, or when requested by an investigative agency following lawful procedures

Because the Company does not show personalized ads, it does not provide advertising identifiers to advertising partners for ad personalization (profiling). Advertising identifiers may be used only for limited purposes, such as frequency capping of non-personalized ads and preventing invalid clicks, and users can reset their advertising identifier in their device settings.

Article 5 (Outsourcing of Personal Information Processing)

To provide the Service smoothly, the Company outsources personal information processing as follows.

Processor Outsourced task Notes
Supabase Cloud hosting for database, authentication, and file storage Server region: Republic of Korea (Seoul)
Google (Firebase Cloud Messaging) Sending push notifications
Google Map SDK and geocoding outside Korea, Google login, AdMob ads
Naver Map SDK within Korea
Kakao Kakao login
Apple Sign in with Apple, in-app subscription payment processing

When entering into outsourcing contracts, the Company specifies terms to ensure personal information is managed securely, and manages and supervises its processors. If the outsourced tasks or processors change, the Company will disclose the change through this Policy.

Article 6 (Transfer of Personal Information Overseas)

In the course of providing the Service, some personal information may be processed on servers located outside Korea.

  • The Company's core data (accounts, location information, etc.) is stored in the Republic of Korea (Seoul) region.
  • In processing certain features, such as push notifications (Google), maps, geocoding, and ads outside Korea (Google), and social login (Google/Apple), information may be transferred to those providers' servers outside Korea.

The information transferred, the destination countries, the date, time, and method of transfer, the recipients, and their purposes of use and retention periods follow each processor's policies. Users can check these matters through this Policy or by contacting customer support.

Article 7 (Rights of Users and Legal Guardians and How to Exercise Them)

  1. Users may view and correct their personal information at any time, and may request suspension of processing and deletion.

    • Viewing and correcting personal information: directly on the profile screen in the app
    • Adjusting location visibility: users can individually hide or show their location to each family member
    • Withdrawing consent and deletion: via Settings > Delete account
  2. The legal guardian of a child under 14 may request access to, correction of, deletion of, or suspension of processing of the child's personal information.

  3. Rights can also be exercised by contacting customer support (privacy@pinly.live), and the Company will act without delay.

Article 8 (Personal Information of Children Under 14, Children Aged 8 or Under, and Others)

  1. The Company does not collect users' age information to provide the Service. Children under 14 may use the Service only with the consent of their legal guardian (parent or guardian), and the legal guardian's consent is given through consent confirmation at sign-up or through the legal guardian's family (group) invitations and settings. In this case, the Company deems that it has obtained the legal guardian's consent to process the personal information of the child under 14, and the legal guardian exercises rights such as access, correction, deletion, and suspension of processing on behalf of the child.

  2. Under the Location Information Act, when a person with a duty of protection uses the location information of a child aged 8 or under, a person under adult guardianship, or a person with certain disabilities under the Act on Welfare of Persons with Disabilities, for that person's protection, the consent of the person with the duty of protection is deemed to be the consent of the person concerned, and the person with the duty of protection may exercise that person's rights.

Article 9 (Personal Location Information Processing Policy)

In accordance with the Location Information Act, the Company establishes and discloses the following matters concerning the processing of personal location information through this Privacy Policy. Specific matters concerning the collection, use, and provision of location information are also set out in the separate Location-Based Services Terms.

  1. Purposes of processing and retention period of personal location information

    • Purposes: real-time location sharing among family (group) members; alerts for arrival, departure, low battery, and similar events; location sharing in an emergency (SOS); providing location history (Article 2)
    • Items collected: latitude and longitude coordinates, location accuracy, device battery level, charging status (Article 1)
    • Retention period: destroyed without delay once the purpose of processing is achieved; location history is deleted automatically 30 days after it is collected (Article 3).
  2. Legal basis and retention period for records confirming the collection, use, and provision of personal location information

    • Legal basis: Article 16(2) of the Location Information Act
    • Retention period: recorded and preserved automatically in the location information system and retained for at least 6 months.
  3. Procedure and method for destroying personal location information

    • Procedure: personal location information whose retention period has passed or whose purpose of processing has been achieved is classified for destruction and destroyed.
    • Method: personal location information in electronic file form is permanently deleted in a way that makes recovery or reproduction impossible (Article 3).
  4. Provision of personal location information to third parties

    • The Company does not provide personal location information to third parties without the user's consent. However, by the nature of the family location-sharing service, a user's location information is shared with other members of a group the user has consented to join, and the user can control whether their location is visible to each member individually (individual hiding) (Article 4).
  5. Notification when provided to a third party designated by the data subject

    • When the Company provides personal location information to a third party designated by the user, it immediately notifies the user's device each time of the recipient, the date and time of provision, and the purpose of provision. However, if the user has chosen a specific notification method in advance, that method is followed.
  6. Rights and obligations of persons with a duty of protection for children aged 8 or under and others, and how to exercise them

    • When a person with a duty of protection uses the location information of a child aged 8 or under, a person under adult guardianship, or a person with certain disabilities under the Act on Welfare of Persons with Disabilities, to protect that person's life or body, the consent of the person with the duty of protection is deemed to be the consent of the person concerned. In this case, the person with the duty of protection may exercise the rights of the person concerned on their behalf, such as withdrawing consent, temporarily suspending the collection, use, and provision of location information, and requesting access or correction (Article 8).
  7. Internal access to personal location information and access records

    • To the minimum extent necessary for operating the Service, such as responding to service failures and providing technical support, operators who have been granted access rights may view a user's location history.
    • For such access, access records including the date and time of access, the person who accessed, and the subject of access are recorded and preserved automatically (Article 16(2) of the Location Information Act).
    • The Company does not view or use personal location information for any purpose other than the above, and does not use it for marketing or user profiling.
  8. Contact for the Location Information Manager

Article 10 (Security Measures for Personal Information)

The Company takes the following measures to protect personal information:

  1. Administrative measures: establishing and implementing an internal management plan; minimizing and managing access rights
  2. Technical measures: secure storage of passwords, encryption in transit (TLS), access control and access rights management, retention of access logs
  3. Physical measures: access control for data centers operated by the cloud infrastructure providers

Article 11 (Automatic Collection Tools and Advertising Identifiers)

  1. The Company may use automatic collection tools such as advertising identifiers for service analytics and to show ads.
  2. Users can reset their advertising identifier in their device's operating system settings.
  3. Ads are not shown to Pro subscribers.
  4. In accordance with the Google AdMob Families policy, the Company shows all users only family-friendly, non-personalized ads, and does not engage in profiling for personalized ads. For this reason, it does not collect age information.

Article 12 (Chief Privacy Officer and Location Information Manager)

The Company designates the following persons to oversee the processing of personal information and to handle user complaints and remedies for damage.

Article 13 (Remedies for Infringement of Rights)

Users may contact the following Korean agencies for consultation and remedies regarding infringement of personal information:

  • Personal Information Dispute Mediation Committee (1833-6972, www.kopico.go.kr)
  • Personal Information Infringement Report Center (118, privacy.kisa.or.kr)
  • Supreme Prosecutors' Office Cyber Investigation Division (1301, www.spo.go.kr)
  • Korean National Police Agency Cyber Investigation Bureau (182, ecrm.police.go.kr)

Article 14 (Changes to This Policy)

This Privacy Policy may be revised in accordance with changes in laws or the Service. Revisions will be announced through in-app notices or this document, and material changes will be announced a certain period before they take effect.

  • Announcement date: 2026-07-01
  • Effective date: 2026-07-01

Business information

  • Company name: WAFFLE
  • Representative: Chongwook Lim
  • Business registration no.: 493-65-00536
  • Mail-order sales registration no.: 2026-고양일산동-1610
  • Address: 702-156, 1068 Jungang-ro, Ilsandong-gu, Goyang-si, Gyeonggi-do, 10447, Republic of Korea
  • Customer support: privacy@pinly.live