NawaplayAX PRODUCT STUDIO
하는 일작업 사례만든 앱블로그소개
01하는 일02작업 사례03만든 앱04블로그05소개

Nawaplay Lunch Selector Service (What to Eat for Lunch?) Privacy Policy

Nawaplay (hereinafter referred to as the "Company") values the personal information of its members and complies with all applicable laws including the Personal Information Protection Act of the Republic of Korea. This Privacy Policy informs members of the purposes and methods under which their personal information is processed and the security measures enforced to safeguard their data.


Article 1 (Purpose of Processing Personal Information)

The Company processes personal information for the following purposes. Information will not be utilized for other purposes unless prior consent is obtained or required by law:

  1. Member Registration and Management
    • Confirming intent to join, user identification/authentication, maintaining memberships, preventing abuse, checking legal representative consent for minors under 14, delivering notices/notices of claim, and processing account withdrawals.
    • Dispatching push notifications (lunch menu alerts at 11:30 and dining log reminder alerts at 13:30) for Service retention and engagement.
  2. Service Provision and AI Recommendations
    • Analyzing Preference Profiles using artificial intelligence (AI) to suggest customized menus.
    • Performing reverse geocoding to display nearby dining places on maps based on location data.
    • Managing de-identified dining records and food photos in the Recommendation Pool.
  3. Report Auditing and Security
    • Reviewing and deactivating reported inappropriate photos and taking disciplinary actions against abusive accounts.
    • Analyzing system bugs and compiling statistical utilization data for Service improvements.

Article 2 (Processed Personal Information Items)

The Company collects and processes the minimum required personal information necessary for providing Services, based on Member consent.

  1. Member Accounts and Hashed Identifiers (Source and Items)
    • Anonymous Login (Temporary Account): Device Unique Identifier (UUID) (collected automatically from device configurations during initial launch).
    • Social Login Linking (Kakao, Google, Apple): Social account ID, nickname, profile picture URL, and email address (collected upon authorization through social authentication providers: Kakao Corp., Google LLC, and Apple Inc.).
  2. Data Collected during Service Use
    • Lunch Log Data: Photo files, menu names, ratings, dining place names, and map coordinates (latitude/longitude for restaurant matching).
    • Location Data: GPS coordinates or manually searched addresses for geocoding matchings (except when Place Type is set to "Cafeteria" or "Lunchbox", in which case location data collection is bypassed).
    • App Usage Logs: Device model, OS version, device identifiers, service access logs, and error/crash reports.
  3. Special Purging Policies for Privacy Protection
    • Photo EXIF Metadata: EXIF headers (including camera specs, original photo location coordinates) are instantly purged and deleted upon server storage.
    • Real-Time GPS Logs (Raw Stream): Raw coordinates used to retrieve restaurant names are immediately destroyed after geocoding matching. Only the restaurant location (and not the user track) is kept in the Lunch Log database.

Article 3 (Provision and Delegation to Third Parties)

  1. The Company does not share personal information with third parties without consent, except as required by law.
  2. Food photos are processed and integrated into the Recommendation Pool to show suggestions to other users.
    • No personal identifiers (nickname, profile picture) are attached to these shared photos.
    • Members can opt out of recommendation pool sharing at any time via [MY Tab] ➡️ [Settings] inside the application.

Article 4 (Retention and Utilization Period)

  1. The Company processes and retains personal information within the retention period consented to by the Member or required by law.
  2. Retention periods are as follows:
    • Account Registration and Management Details: Retained until account withdrawal.
    • Lunch Logs, Preference Profiles, and Locations: Retained until account withdrawal.
    • Prevention of Abusive Behaviors: If an account is suspended or terminated for policy violations (e.g., repeatedly uploading inappropriate photos), the hashed identifier and log of sanctions are retained for 6 months after withdrawal to prevent immediate re-registration.
    • Statutory Retention Obligations: Internet access logs, access dates/times, and IP tracking logs are retained for 3 months (90 days) under Article 15-2 of the Protection of Communications Secrets Act.
    • Anonymized Data Retention: Food photos and ratings are stripped of all personal identifiers (nickname, profile, ID) upon account withdrawal. These completely anonymized datasets are retained permanently in the Recommendation Pool for algorithm continuity and data cold-start prevention. Deletion requests for anonymized resources cannot be accommodated after withdrawal.
    • Purge of Inactive Anonymous Accounts: If an anonymous account (UUID-based guest account with no linked Kakao/Google/Apple social account) remains inactive for 6 months, all UUID metadata, Lunch Logs, and profiles are automatically hard-deleted from servers and storage.
  3. Data Grace Period upon Account Withdrawal
    • Upon withdrawal request, data is not instantly deleted but is kept in a 30-day data retention grace period to allow recovery from accidental deletions.
    • During this period, the account is deactivated and hidden. Logging back in restores the account. After 30 days, the personal information is permanently destroyed.

Article 5 (Destruction Procedures and Methods)

  1. Personal information is immediately destroyed once retention periods expire or purposes of processing are achieved.
  2. Upon account withdrawal, personal information is destroyed immediately after the 30-day grace period under Article 4, Paragraph 3.
  3. Instant Deletion for Individual Logs: If a Member deletes an individual entry from the timeline, it bypasses the 30-day grace period and is immediately hard-deleted from database servers and storage.
  4. Destruction methods:
    • Electronic Files: Erased using technical methods that render records unrecoverable (low-level formats, secure overwriting).
    • Printed Paper: Shredded or incinerated.

Article 6 (Rights of Information Subjects)

  1. Members hold rights to request access to, correction of, deletion of, or suspension of processing of their personal information at any time.
  2. Inquiries and requests may be submitted via email or internal customer support options. The Company will address requests without delay.

Article 7 (Security Measures for Personal Information)

The Company enforces technical, physical, and administrative measures to secure personal information:

  1. Administrative: Establishing internal security guidelines and training data handling personnel.
  2. Technical: Utilizing encrypted data channels (HTTPS/SSL), encrypting hashed identifiers, and protecting server databases with access limits.
  3. Physical: Restricting access to hosting cloud databases (Supabase/AWS infrastructures).

Article 8 (Advertising Identifiers and Opt-Out Guides)

  1. No Cookies: The Company does not use cookies for tracking web sessions.
  2. Ad Tracking Identifiers (ADID/IDFA): The Service integrates advertising SDKs (Google AdMob, Kakao AdFit) which collect mobile advertising identifiers (ADID/IDFA) to deliver customized banner ads.
  3. Opt-Out Control Paths: Members can block ad tracking via OS system preferences:
    • Android: Settings ➡️ Security & Privacy ➡️ Privacy ➡️ Ads ➡️ Reset Ad ID or Delete Ad ID.
    • iOS: Settings ➡️ Privacy & Security ➡️ Tracking ➡️ Toggle OFF "Allow Apps to Request to Track" or block permissions individually.

Article 8-2 (International Data Transfers)

The Company utilizes Google Gemini API for AI photo analysis, which involves transferring non-identifying data (food photo files) to servers located outside the Republic of Korea:

  1. Recipient: Google LLC (https://policies.google.com/privacy)
  2. Recipient Country: United States of America (USA)
  3. Transfer Method and Date: Transmitted securely via HTTPS API requests in real time immediately when a user uploads a lunch photo.
  4. Purpose: Analyzing dining photo contents to categorize food types, extract menu names, and evaluate food composition.
  5. Transferred Items: Lunch photo files (photo metadata and EXIF location tags are already purged before transmission).
  6. Retention Period: Photos are analyzed and immediately destroyed or processed into a non-identifiable state on Google's API servers.

Article 9 (Data Protection Officer)

The Company has appointed a Data Protection Officer to address inquiries and resolve complaints:

  • Data Protection Officer / Department
    • Department: Nawaplay Operations Desk
    • Email: kenny@nawaplay.com
    • Contact Number: 0507-1469-0797

Article 10 (Changes to the Privacy Policy)

  1. This Privacy Policy is effective from the enforcement date. Any updates, amendments, or deletions will be notified via notices at least 7 days prior to implementation.
  • Announcement Date: June 23, 2026
  • Enforcement Date: June 23, 2026
NawaplayAX PRODUCT STUDIO

AI 웹·앱 개발과 업무 자동화를 실제로 쓰이는 제품으로 만듭니다.

이메일 전화
BUSINESS INFO
상호
나와플레이
대표자
이강호
사업자등록번호
822-13-00749
통신판매업신고
제 2026-경기김포-4470 호

경기도 김포시 김포한강9로75번길 190, 7층 713호 E14(구래동, 이너매스한강)

© 2017–2026 Nawaplay. ALL RIGHTS RESERVED.
서비스블로그이용약관개인정보처리방침고객센터