📋 Table of Contents / 목차 보기 ▼
Data Protection & Privacy

Privacy Information (개인정보처리방침)

A transparent explanation of how KRiders collects, stores, and protects your information, and how community content and chat messages are treated.

Effective Date August 27, 2026
Data Minimization Principle Email-Only PII Collection
Compliance Baseline Korean PIPA, GDPR & CCPA
Commercial Advertising Zero Ad Trackers / No Data Selling
🛡️ Core Privacy Guarantee at a Glance
We collect only one item of Personally Identifiable Information (PII): your Email address. We require your email solely to verify and authenticate your identity. We do not require phone numbers, government IDs, or real names. Your private cryptographic key never leaves your device. We never sell your data or messages to advertisers.
Section 01

Our Privacy Commitment (개인정보 보호 원칙)

KRiders ("we", "us", or "our") respects the privacy rights of motorcycle adventurers and community members. We have engineered KRiders with a strict Privacy-by-Design and Data Minimization philosophy under the Personal Information Protection Act of the Republic of Korea (개인정보 보호법) and global privacy standards.

Traditional social networks collect names, telephone numbers, tracking cookies, and real-time location histories. In contrast, KRiders is purposely architected to require the absolute minimum amount of personal data necessary to establish a secure rider identity and allow community coordination.

Section 02

Personally Identifiable Information (PII): Email Collection (수집하는 개인정보: 이메일)

The only personally identifiable information we mandate and collect from you is your Email Address:

Data Item Collection Mechanism Sole Purpose of Processing Mandatory / Optional
Email Address User entry during Sign-Up or Login 1. Dispatching a 6-digit one-time verification code to authenticate user identity.
2. Preventing duplicate and fraudulent account spam.
3. Transmitting critical security or administrative service alerts.
Mandatory for Account

No Marketing Spam: We do not send promotional advertisements, unsolicited newsletters, or third-party marketing to your email address.

Section 03

Cryptographic Public-Key Authentication (공개키 기반 암호화 인증 체계)

Instead of storing sensitive passwords on our server, KRiders authenticates riders using client-side asymmetric cryptography:

  • Public Key (Stored on Server): A public cryptographic key generated on your device is transmitted to our server and stored alongside your account. It is used mathematically to verify your digital signatures on service requests. Public keys contain zero personal identifying data.
  • Private Key (Never Transmitted): Zero-Knowledge Your private cryptographic key is generated and stored locally in your device's secure enclave / storage. It is NEVER sent to KRiders servers. KRiders operators have no ability to view or decrypt your private key.
  • Push Notification Token: If you grant permission on iOS or Android, your device generates a Firebase Cloud Messaging (FCM) push token. This is used solely to deliver notifications (such as ride event invites or chat alerts) to your device. You can revoke push notification permissions anytime in your phone's OS settings.
Section 04

Handling of User Content: Posts, Media & Chat Messages (게시물, 미디어 및 채팅 메시지 처리 기준)

Because KRiders is a social community and touring platform, users create and exchange various forms of digital content. Here is how each type of data is classified, stored, and protected:

📝 Community Posts & Comments Public to Community

Nature: Travel logs, touring tips, spot recommendations, comments, and likes.
Visibility: Visible to other authenticated riders on the KRiders platform.
Storage: Structured data stored in our secure, encrypted database.
User Control: You can edit or delete your posts and comments at any time via the app.

📸 Photos & Media Uploads Cloud Object Storage

Nature: Photos attached to posts, events, groups, and rider profiles.
Processing: Upon upload, images are processed and resized into optimized variants for mobile data efficiency.
Storage: Hosted securely in isolated cloud storage.
Purging: When you delete a post or withdraw, all associated media files are queued for permanent deletion.

💬 Chat Messages & Channels Restricted Access

Nature: Real-time messages sent within group channels or direct channels.
Transmission: Transmitted via secure encrypted connections.
Access Restriction: Stored securely solely so that authorized members of that specific channel can view chat history across devices. Chat messages are never accessible to the public and are strictly isolated to authorized participants of that channel.
No Mining: We do NOT read, inspect, parse, or monetize the contents of your private chats for advertising, profiling, or machine learning training.

💡 Why Do We Store Posts and Chat History?
Posts and chat messages are stored on our servers strictly to deliver the essential functional features of the application—namely, allowing you and your riding companions to browse community feeds, recall shared routes, and read conversation histories across device restarts.
Section 05

Optional Profile, Motorcycle & Location Data (선택 정보: 프로필, 바이크 정보 및 위치)

To enhance your community experience, you may optionally provide the following information:

  • Rider Profile Details (Optional): Alias / Nickname, brief bio, and profile avatar photo. You may change or wipe these at any time.
  • Motorcycle Garage Information (Optional): Motorcycle brand and model name (e.g., "BMW R1250GS", "Honda Super Cub"). Used to display your ride setup to fellow riders.
  • Favorite Places & Event RSVPs: Tourist destinations or meetup spots you mark as favorites, and events you join. Stored in your personal profile data.
  • Location Information: KRiders integrates with Korea Tourism Organization Open APIs and Kakao Map APIs to display scenic spots and navigation information. KRiders does NOT continuously track, record, or store your background GPS location on our servers. Location permissions requested on your device are handled locally on the client to render maps and orient your position relative to nearby attractions.
Section 06

Purposes of Processing (개인정보의 처리 목적)

We process collected information exclusively for the following legitimate purposes:

  1. User Authentication: Verifying email ownership via 6-digit codes and validating digital signatures.
  2. Community Provision: Enabling riders to publish posts, join groups, participate in meetup events, and communicate through channels.
  3. Notification Routing: Dispatching real-time event invitations and chat notifications to your mobile device.
  4. Service Stability & Security: Monitoring service health, preventing unauthorized access, mitigating automated abuse, and ensuring operational reliability.
  5. Compliance: Enforcing our Terms of Usage and complying with applicable statutory obligations under the laws of the Republic of Korea.
Section 07

Third-Party Service Providers (Sub-Processors) (개인정보 처리 위탁 및 국외 이전)

To maintain reliable, high-availability cloud infrastructure, we entrust certain technical operations to reputable third-party cloud service providers:

Service Provider Role / Delegated Task Transferred Information Location / Safeguards
Amazon Web Services (AWS) Cloud server hosting, database infrastructure, secure media storage, and verification email delivery. Email address, uploaded photos, chat records, and post data. Republic of Korea (Seoul data center). Protected by SOC 2, ISO 27001, and strict access controls.
Google Firebase (Google LLC) Dispatching push notifications to mobile devices. Device push notification tokens. Global infrastructure. Data encrypted in transit.
Kakao Corp. / Korea Tourism Organization Map rendering, route calculations, and public tourist spot open data queries. Search coordinates and place queries (Zero personal user data or email is transmitted). Republic of Korea.
🚫 Strict Non-Disclosure Pledge
KRiders does NOT sell, rent, trade, or monetize your personal information or chat records to any third-party marketing firms, advertisers, or data brokers.
Section 08

Data Retention & Automatic Erasure (개인정보의 보유 및 이용 기간)

We retain your personal information only for the duration of your active account membership:

  • Active Accounts: Your email address, public key, and active profile are maintained as long as you maintain your KRiders account.
  • Verification Codes: 6-digit email verification codes generated during sign-up or login are stored temporarily in secure memory and automatically expired and purged within 5 minutes.
  • Session Tokens: Authentication tokens automatically expire within 1 to 3 months, requiring re-authentication.
  • Server Access Logs: Diagnostic server access logs (IP address, device type, timestamp) are rotated and permanently purged within 30 days.
Section 09

Cryptographic Account Withdrawal & Complete Data Erasure (회원 탈퇴 및 파기 절차)

Under Article 21 of the Korean Personal Information Protection Act and GDPR Article 17 (Right to Erasure), you have the uncompromised right to permanently delete your account and personal data at any time.

🔒 The Cryptographic Withdrawal Mechanism
Because KRiders identities are protected cryptographically, account deletion cannot be triggered by an unauthorized party. In the app settings under Quit KRiders:
  1. You type the explicit confirmation phrase: "I agree to delete all information created by myself and withdraw from KRiders service."
  2. Your device computes a digital signature of a server challenge using your private key.
  3. Upon verification of your digital signature, the server immediately executes permanent data erasure.

What happens upon withdrawal:

  • Personal Data Erasure: Your email address, public key, and push notification tokens are permanently and irreversibly erased from our production database.
  • Media Deletion: Your profile photo and uploaded post photos are permanently purged from cloud storage.
  • Local Cleanup: The mobile client wipes all cached tokens and keys from device secure storage.
Section 10

Your Privacy Rights & Choices (정보주체의 권리 및 행사 방법)

As an information subject, you are entitled to exercise the following rights at any time:

  • Right of Access & Inspection: You may view your profile, uploaded posts, bike details, and saved favorite spots directly in the app.
  • Right to Rectification: You can edit your alias, bio, bike information, and post captions in real time.
  • Right to Erasure ("Right to be Forgotten"): You can delete individual posts, remove uploaded photos, or withdraw your entire account.
  • Right to Restrict or Withdraw Consent: You can toggle push notifications off at any time in your device's operating system settings.
Section 11

Technical & Organizational Security Safeguards (개인정보의 안전성 확보 조치)

In compliance with Article 29 of the Personal Information Protection Act, we implement robust technical safeguards:

  • Encryption in Transit: All communications between the mobile app and our servers are strictly encrypted using industry-standard protocols (HTTPS / TLS).
  • Cryptographic Digital Signatures: Account-level modifications and sign-in operations require cryptographic digital signatures verified against stored public keys.
  • Database Security: Production databases are isolated within private virtual networks, protected by firewalls and strict access authentication.
  • Zero Password Storage: Because authentication relies on one-time email codes and asymmetric keys, our database contains no passwords that could be leaked or compromised.
Section 12

Data Protection Officer & Privacy Inquiries (개인정보 보호책임자 및 고충처리)

If you have questions, feedback, or grievances regarding this Privacy Information policy or wish to exercise your data subject rights, you may contact our designated Privacy Operations lead:

📬 Privacy & Data Protection Contact
KRiders Data Privacy Team
Email: hbjw123@gmail.com
Service: KRiders
Inquiries Response Time: Within 7 business days

For regulatory complaints within the Republic of Korea, you may also contact the official statutory authorities:

  • Personal Information Dispute Mediation Committee (개인정보 분쟁조정위원회): 1833-6972 (kopico.go.kr)
  • Personal Information Infringement Report Center (개인정보침해신고센터): 118 (privacy.kisa.or.kr)
  • Supreme Prosecutors' Office Cybercrime Investigation (대검찰청 사이버수사과): 1301 (spo.go.kr)
  • National Police Agency Cyber Bureau (경찰청 사이버수사국): 182 (ecrm.police.go.kr)