📋 Table of Contents / 목차 보기 ▼
Privacy Information (개인정보처리방침)
A transparent explanation of how KRiders collects, stores, and protects your information, and how community content and chat messages are treated.
Our Privacy Commitment (개인정보 보호 원칙)
KRiders ("we", "us", or "our") respects the privacy rights of motorcycle adventurers and community members. We have engineered KRiders with a strict Privacy-by-Design and Data Minimization philosophy under the Personal Information Protection Act of the Republic of Korea (개인정보 보호법) and global privacy standards.
Traditional social networks collect names, telephone numbers, tracking cookies, and real-time location histories. In contrast, KRiders is purposely architected to require the absolute minimum amount of personal data necessary to establish a secure rider identity and allow community coordination.
Personally Identifiable Information (PII): Email Collection (수집하는 개인정보: 이메일)
The only personally identifiable information we mandate and collect from you is your Email Address:
| Data Item | Collection Mechanism | Sole Purpose of Processing | Mandatory / Optional |
|---|---|---|---|
| Email Address | User entry during Sign-Up or Login |
1. Dispatching a 6-digit one-time verification code to authenticate user identity. 2. Preventing duplicate and fraudulent account spam. 3. Transmitting critical security or administrative service alerts. |
Mandatory for Account |
No Marketing Spam: We do not send promotional advertisements, unsolicited newsletters, or third-party marketing to your email address.
Cryptographic Public-Key Authentication (공개키 기반 암호화 인증 체계)
Instead of storing sensitive passwords on our server, KRiders authenticates riders using client-side asymmetric cryptography:
- Public Key (Stored on Server): A public cryptographic key generated on your device is transmitted to our server and stored alongside your account. It is used mathematically to verify your digital signatures on service requests. Public keys contain zero personal identifying data.
- Private Key (Never Transmitted): Zero-Knowledge Your private cryptographic key is generated and stored locally in your device's secure enclave / storage. It is NEVER sent to KRiders servers. KRiders operators have no ability to view or decrypt your private key.
- Push Notification Token: If you grant permission on iOS or Android, your device generates a Firebase Cloud Messaging (FCM) push token. This is used solely to deliver notifications (such as ride event invites or chat alerts) to your device. You can revoke push notification permissions anytime in your phone's OS settings.
Handling of User Content: Posts, Media & Chat Messages (게시물, 미디어 및 채팅 메시지 처리 기준)
Because KRiders is a social community and touring platform, users create and exchange various forms of digital content. Here is how each type of data is classified, stored, and protected:
Nature: Travel logs, touring tips, spot recommendations, comments, and likes.
Visibility: Visible to other authenticated riders on the KRiders platform.
Storage: Structured data stored in our secure, encrypted database.
User Control: You can edit or delete your posts and comments at any time via the app.
Nature: Photos attached to posts, events, groups, and rider profiles.
Processing: Upon upload, images are processed and resized into optimized variants for mobile data efficiency.
Storage: Hosted securely in isolated cloud storage.
Purging: When you delete a post or withdraw, all associated media files are queued for permanent deletion.
Nature: Real-time messages sent within group channels or direct channels.
Transmission: Transmitted via secure encrypted connections.
Access Restriction: Stored securely solely so that authorized members of that specific channel can view chat history across devices. Chat messages are never accessible to the public and are strictly isolated to authorized participants of that channel.
No Mining: We do NOT read, inspect, parse, or monetize the contents of your private chats for advertising, profiling, or machine learning training.
Optional Profile, Motorcycle & Location Data (선택 정보: 프로필, 바이크 정보 및 위치)
To enhance your community experience, you may optionally provide the following information:
- Rider Profile Details (Optional): Alias / Nickname, brief bio, and profile avatar photo. You may change or wipe these at any time.
- Motorcycle Garage Information (Optional): Motorcycle brand and model name (e.g., "BMW R1250GS", "Honda Super Cub"). Used to display your ride setup to fellow riders.
- Favorite Places & Event RSVPs: Tourist destinations or meetup spots you mark as favorites, and events you join. Stored in your personal profile data.
- Location Information: KRiders integrates with Korea Tourism Organization Open APIs and Kakao Map APIs to display scenic spots and navigation information. KRiders does NOT continuously track, record, or store your background GPS location on our servers. Location permissions requested on your device are handled locally on the client to render maps and orient your position relative to nearby attractions.
Purposes of Processing (개인정보의 처리 목적)
We process collected information exclusively for the following legitimate purposes:
- User Authentication: Verifying email ownership via 6-digit codes and validating digital signatures.
- Community Provision: Enabling riders to publish posts, join groups, participate in meetup events, and communicate through channels.
- Notification Routing: Dispatching real-time event invitations and chat notifications to your mobile device.
- Service Stability & Security: Monitoring service health, preventing unauthorized access, mitigating automated abuse, and ensuring operational reliability.
- Compliance: Enforcing our Terms of Usage and complying with applicable statutory obligations under the laws of the Republic of Korea.
Third-Party Service Providers (Sub-Processors) (개인정보 처리 위탁 및 국외 이전)
To maintain reliable, high-availability cloud infrastructure, we entrust certain technical operations to reputable third-party cloud service providers:
| Service Provider | Role / Delegated Task | Transferred Information | Location / Safeguards |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud server hosting, database infrastructure, secure media storage, and verification email delivery. | Email address, uploaded photos, chat records, and post data. | Republic of Korea (Seoul data center). Protected by SOC 2, ISO 27001, and strict access controls. |
| Google Firebase (Google LLC) | Dispatching push notifications to mobile devices. | Device push notification tokens. | Global infrastructure. Data encrypted in transit. |
| Kakao Corp. / Korea Tourism Organization | Map rendering, route calculations, and public tourist spot open data queries. | Search coordinates and place queries (Zero personal user data or email is transmitted). | Republic of Korea. |
Data Retention & Automatic Erasure (개인정보의 보유 및 이용 기간)
We retain your personal information only for the duration of your active account membership:
- Active Accounts: Your email address, public key, and active profile are maintained as long as you maintain your KRiders account.
- Verification Codes: 6-digit email verification codes generated during sign-up or login are stored temporarily in secure memory and automatically expired and purged within 5 minutes.
- Session Tokens: Authentication tokens automatically expire within 1 to 3 months, requiring re-authentication.
- Server Access Logs: Diagnostic server access logs (IP address, device type, timestamp) are rotated and permanently purged within 30 days.
Cryptographic Account Withdrawal & Complete Data Erasure (회원 탈퇴 및 파기 절차)
Under Article 21 of the Korean Personal Information Protection Act and GDPR Article 17 (Right to Erasure), you have the uncompromised right to permanently delete your account and personal data at any time.
- You type the explicit confirmation phrase:
"I agree to delete all information created by myself and withdraw from KRiders service." - Your device computes a digital signature of a server challenge using your private key.
- Upon verification of your digital signature, the server immediately executes permanent data erasure.
What happens upon withdrawal:
- Personal Data Erasure: Your email address, public key, and push notification tokens are permanently and irreversibly erased from our production database.
- Media Deletion: Your profile photo and uploaded post photos are permanently purged from cloud storage.
- Local Cleanup: The mobile client wipes all cached tokens and keys from device secure storage.
Your Privacy Rights & Choices (정보주체의 권리 및 행사 방법)
As an information subject, you are entitled to exercise the following rights at any time:
- Right of Access & Inspection: You may view your profile, uploaded posts, bike details, and saved favorite spots directly in the app.
- Right to Rectification: You can edit your alias, bio, bike information, and post captions in real time.
- Right to Erasure ("Right to be Forgotten"): You can delete individual posts, remove uploaded photos, or withdraw your entire account.
- Right to Restrict or Withdraw Consent: You can toggle push notifications off at any time in your device's operating system settings.
Technical & Organizational Security Safeguards (개인정보의 안전성 확보 조치)
In compliance with Article 29 of the Personal Information Protection Act, we implement robust technical safeguards:
- Encryption in Transit: All communications between the mobile app and our servers are strictly encrypted using industry-standard protocols (HTTPS / TLS).
- Cryptographic Digital Signatures: Account-level modifications and sign-in operations require cryptographic digital signatures verified against stored public keys.
- Database Security: Production databases are isolated within private virtual networks, protected by firewalls and strict access authentication.
- Zero Password Storage: Because authentication relies on one-time email codes and asymmetric keys, our database contains no passwords that could be leaked or compromised.
Data Protection Officer & Privacy Inquiries (개인정보 보호책임자 및 고충처리)
If you have questions, feedback, or grievances regarding this Privacy Information policy or wish to exercise your data subject rights, you may contact our designated Privacy Operations lead:
Email: hbjw123@gmail.com
Service: KRiders
Inquiries Response Time: Within 7 business days
For regulatory complaints within the Republic of Korea, you may also contact the official statutory authorities:
- Personal Information Dispute Mediation Committee (개인정보 분쟁조정위원회): 1833-6972 (kopico.go.kr)
- Personal Information Infringement Report Center (개인정보침해신고센터): 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office Cybercrime Investigation (대검찰청 사이버수사과): 1301 (spo.go.kr)
- National Police Agency Cyber Bureau (경찰청 사이버수사국): 182 (ecrm.police.go.kr)