개인정보 처리방침

시행일 2026-09-16 · 최종 개정 2026-09-01

Mapbox 보유기간(30일)은 Mapbox 공개 자료 기준이며 확인 중입니다. 이 방침은 제1부(개인정보)와 제2부(개인위치정보)로 구성되며, 제2부는 「위치정보의 보호 및 이용 등에 관한 법률」 제21조의2에 따른 개인위치정보 처리방침입니다. 웹사이트 주소: everyticket.kr/privacy (제2부 바로가기: everyticket.kr/privacy#location)

주식회사 고로켓컴퍼니(이하 "회사")는 Every Ticket(이하 "서비스") 이용자의 개인정보를 「개인정보 보호법」, 「위치정보의 보호 및 이용 등에 관한 법률」(이하 "위치정보법") 등 관련 법령에 따라 처리하며, 이 방침으로 어떤 정보를 어떤 근거로 얼마 동안 처리하는지, 이용자가 어떤 권리를 어떻게 행사할 수 있는지 알립니다.

한눈에 보기

제1부 개인정보 처리방침

제1조 (처리하는 개인정보의 항목, 목적, 근거, 보유 기간)

회사는 다음 개인정보를 처리합니다. 표에 적은 근거는 「개인정보 보호법」 제15조제1항의 각 호이며, 가입 시 이용자에게 이 내용을 알리고 개인정보 수집·이용에 대한 동의를 별도의 항목으로 받습니다.

구분항목수집 시점처리 목적근거보유 기간
계정전자우편 주소(Apple 로그인의 경우 Apple이 발급한 릴레이 주소일 수 있음), 이름(닉네임), 프로필 사진, 소셜 로그인 제공자(Google·Apple·카카오·네이버)가 발급한 회원 식별값로그인·가입 시회원 식별과 로그인, 여러 기기 간 데이터 동기화, 통지계약의 체결·이행(제4호)탈퇴 시까지
개인위치정보위도·경도·수집 시각·정확도(이동 동선), 컷 촬영·티켓 등록 시점의 위치이용자가 "기록 시작"을 누른 뒤 여행을 끝낼 때까지동선 표시, 도착 확인, 결과물 생성, 본인 계정 보관·복원위치정보법 제19조제1항 동의해당 여행 삭제·탈퇴·동의 철회 시까지 (제2부 참조)
계획목적지·장소·일정·메모·경비·체크리스트, 공동 계획의 동행자 목록(닉네임·색)계획 작성 시여행 계획 작성과 공동 편집계약의 체결·이행(제4호)계획 삭제·탈퇴 시까지
AI 초안 설문목적지, 출발지, 날짜, 동행, 예산 범위, 취향, 넣거나 피할 것에 대한 메모AI 초안 기능 사용 시설문 기반 여행 계획 초안 생성계약의 체결·이행(제4호)생성된 초안과 함께 계획에 저장, 계획 삭제·탈퇴 시까지
사진·영상·음성티켓·기념품 사진, 1초 영상(컷) 및 컷에 함께 녹음되는 현장음이용자가 직접 촬영·선택 시티켓 등록, 기록, 결과물(카드·필름) 생성, 기기 변경 시 복원계약의 체결·이행(제4호)해당 콘텐츠 삭제·탈퇴 시까지
티켓 정보종류·제목·장소·날짜·출발지·도착지·좌석 등 이용자가 입력하거나 AI가 추출하여 이용자가 확인한 값티켓 등록 시티켓 등록·분류, 결과물 생성계약의 체결·이행(제4호)티켓 삭제·탈퇴 시까지
결제스토어(Apple App Store·Google Play) 영수증 식별값, 구매 상품·시각, 스토어 국가, 구독 상태유료 결제 시결제 확인, 여행권·구독 관리, 환불·청약철회 처리계약의 체결·이행(제4호), 법령상 의무(제2호)탈퇴 시까지. 다만 「전자상거래 등에서의 소비자보호에 관한 법률」에 따라 계약·청약철회 기록과 대금결제·재화공급 기록은 5년, 소비자 불만·분쟁 처리 기록은 3년 보존
기기·알림푸시 알림 토큰, 기기 모델·OS 버전·앱 버전·언어·시간대, 앱 설치 참조값앱 설치·알림 허용 시서비스 알림 발송(기록·초대·결제·정책 변경), 기기별 복원계약의 체결·이행(제4호)탈퇴 또는 앱 삭제 시까지
광고성 알림(위 푸시 토큰의 이용)이용자가 별도 동의한 경우새 기능·이벤트·할인 안내동의(제1호)동의 철회 시까지, 2년마다 재확인
광고 식별자Android 광고 ID(GAID), iOS 공급업체 식별자(IDFV), IP 주소앱 설치·실행 시앱 설치 경로와 마케팅 성과 측정, 초대 링크 연결(디퍼드 딥링크)정당한 이익(제6호) · 이용자는 앱 설정에서 거부 가능탈퇴 시 또는 수탁자와의 계약 종료 시까지
이용 기록앱 사용 이벤트(화면·기능 이용, 시각), 기기 정보, 회사가 부여한 이용자 식별값앱 이용 중서비스 개선을 위한 이용 통계 분석정당한 이익(제6호) · 앱 설정에서 거부 가능수집일부터 1년
오류 진단오류(크래시) 로그, 기기 정보, 앱 상태오류 발생 시오류 진단과 안정성 개선정당한 이익(제6호)수집일부터 90일
문의전자우편 주소, 문의 내용, 첨부 자료문의 시문의·불만 처리, 권리 행사 요구 처리계약의 체결·이행(제4호), 법령상 의무(제2호)처리 완료 후 3년
접속 기록위치정보시스템·관리 콘솔 접근 기록시스템 운영 중안전성 확보, 침해사고 대응법령상 의무(제2호)1년

② 회사는 iOS의 앱 추적 투명성(ATT) 권한을 요청하지 않으며 광고 식별자(IDFA)를 수집하지 않습니다. Android 광고 ID는 기기 설정에서 재설정하거나 삭제할 수 있습니다.

③ 회사는 민감정보(사상·신념, 건강 등)와 고유식별정보(주민등록번호 등)를 수집하지 않습니다.

④ 회사는 가입 시 이용자가 만 14세 이상임을 확인하며, 만 14세 미만 아동의 개인정보는 수집하지 않습니다. 만 14세 미만의 이용이 확인되면 계정과 관련 정보를 지체 없이 파기합니다.

제2조 (개인정보의 수집 방법)

  1. 이용자가 앱과 웹사이트에서 직접 입력·촬영·선택하는 방법
  2. 소셜 로그인 시 이용자의 동의를 거쳐 Google·Apple·카카오·네이버가 회사에 전달하는 방법(카카오·네이버의 경우 제공자가 발급한 토큰을 회사 서버가 검증하여 회원 식별값·닉네임·프로필 사진·전자우편(동의 시)을 받습니다)
  3. 기록 중인 여행에 한해 단말의 위치정보 기능으로 자동 수집하는 방법
  4. 앱에 포함된 소프트웨어 개발 도구(SDK)가 자동으로 생성·수집하는 방법(제9조)
  5. 스토어가 결제 결과를 회사에 전달하는 방법

제3조 (개인정보의 이용 목적 외 처리)

회사는 제1조의 목적 범위에서만 개인정보를 이용하며, 목적이 바뀌면 「개인정보 보호법」 제18조에 따라 별도 동의를 받거나 법령이 허용하는 범위에서만 처리합니다. 이용자가 남긴 평점·한줄평을 다른 이용자에게 보여주는 기능을 도입하는 경우 개인을 식별할 수 없는 익명·집계 형태로만 제공하며, 이는 이 방침을 개정하여 알립니다.

제4조 (개인정보의 제3자 제공)

① 회사는 이용자의 개인정보를 원칙적으로 제3자에게 제공하지 않으며, 다음 경우에만 제공합니다.

제공받는 자제공 항목제공 목적근거제공받는 자의 보유 기간
공동 계획의 동행자이용자가 계획에 입력·등록한 장소·일정·경비·체크리스트·티켓 정보, 닉네임·색계획의 공동 편집이용자가 초대 링크를 만들어 동행자를 초대하는 행위(법 제17조제1항제1호)동행자의 계획 삭제·탈퇴 시까지

이용자의 이동 동선·컷·사진·감상은 어떤 경우에도 동행자에게 제공되지 않습니다. 장소 검색어와 지도 화면 범위는 회사 서버를 거쳐 Google Maps Platform으로 전달되지만 계정 정보·IP 주소·기기 정보는 함께 보내지 않으므로 개인정보의 제3자 제공에 해당하지 않으며, 투명성을 위해 제6조의 표에 적습니다.

② 법령에 특별한 규정이 있거나 수사기관이 법령이 정한 절차와 방법에 따라 요구하는 경우에는 그 범위에서 제공할 수 있으며, 회사는 요구의 적법성을 확인한 뒤 최소한으로 제공하고 그 내역을 기록합니다.

제5조 (개인정보 처리의 위탁)

① 회사는 서비스 제공을 위하여 다음과 같이 개인정보 처리를 위탁합니다.

수탁자위탁 업무위탁 항목
Google LLC (Firebase)회원 인증(Authentication), 데이터베이스(Firestore), 파일 저장(Cloud Storage), 서버 기능(Cloud Functions), 푸시 알림(FCM), 오류 진단(Crashlytics)계정, 계획, 티켓, 사진·컷, 동선, 기기·알림, 오류 진단
Google LLC (Gemini API, 유료 등급)티켓 사진 정보 추출, 설문 기반 여행 초안 생성티켓 사진 이미지, AI 초안 설문
Mapbox, Inc.지도 표시지도 화면 영역 좌표, IP 주소, 기기 정보(텔레메트리는 끔)
OpenWeather Ltd.여행 날짜의 날씨 조회계획 장소의 좌표·날짜
PostHog, Inc.이용 통계·제품 분석이용 기록, 기기 정보, 이용자 식별값
에이비일팔공㈜ (Airbridge)앱 설치 경로·마케팅 성과 측정, 초대 링크 연결광고 식별자(GAID·IDFV), 설치 참조값, 기기 정보, IP 주소, 가입·결제 등 전환 이벤트
RevenueCat, Inc.인앱결제 영수증 검증, 구독·구매 이력 관리결제, 이용자 식별값

② 회사는 위탁계약에 「개인정보 보호법」 제26조에 따라 위탁업무 목적 외 처리 금지, 기술적·관리적 보호조치, 재위탁 제한, 수탁자에 대한 관리·감독, 손해배상 등을 정하고, 수탁자가 개인정보를 안전하게 처리하는지 감독합니다.

③ 수탁자가 회사의 업무를 다시 위탁하는 경우 회사의 동의를 받으며, 재수탁자와 그 업무는 이 방침으로 공개합니다. 현재 수탁자들은 자사 클라우드 인프라(Google Cloud, Amazon Web Services)를 이용하여 업무를 수행합니다.

④ 위탁 업무의 내용이나 수탁자가 바뀌면 지체 없이 이 방침을 개정하여 알립니다.

⑤ Apple App Store와 Google Play는 회사의 수탁자가 아니라 이용자와 직접 결제 계약을 맺는 독립된 사업자이며, 결제 수단 정보는 스토어만 보유하고 회사에 전달되지 않습니다. 카카오·네이버·Google·Apple의 로그인 서비스도 각 사의 개인정보처리방침에 따릅니다.

제6조 (개인정보의 국외 이전)

① 회사는 「개인정보 보호법」 제28조의8제1항제3호가목(정보주체와의 계약 체결·이행을 위한 처리위탁·보관으로서 다음 사항을 개인정보 처리방침에 공개한 경우)에 따라 다음과 같이 개인정보를 국외에서 처리위탁·보관합니다. PostHog·Airbridge는 서비스 운영·개선과 초대 링크 기능에 필요한 처리위탁으로서 같은 호에 따르되 이용자가 언제든지 거부할 수 있습니다.

이전받는 자 (연락처)이전 국가이전 항목이전 시기·방법이용 목적보유·이용 기간
Google LLC · Firebase Authentication (1600 Amphitheatre Pkwy, Mountain View, CA, USA · policies.google.com/privacy · support.google.com/policies/contact/general_privacy_form)미국 (인증 서비스는 미국에서만 처리)전자우편, 이름, 프로필 사진, 소셜 로그인 식별값, 로그인 토큰로그인 시 암호화된 네트워크(TLS)로 전송회원 인증·계정 관리탈퇴 시까지
Google LLC · Firestore·Cloud Storage·Cloud Functions대한민국(서울 리전)에 저장. 다만 Google의 글로벌 운영·기술지원 과정에서 미국 등 국외에서 조회될 수 있음계정, 계획, 티켓, 사진·컷(현장음 포함), 동선서비스 이용 시 TLS 전송, 서울 리전 저장데이터 저장·처리·백업삭제·탈퇴 시까지, 백업본 최대 7일
Google LLC · FCM·Crashlytics미국 등 Google 데이터센터(리전 지정 없음)푸시 토큰, 기기 정보, 오류 로그알림 발송·오류 발생 시 TLS 전송푸시 알림 발송, 오류 진단푸시 토큰: 탈퇴·앱 삭제 시까지 / 오류 로그: 90일
Google LLC · Gemini API(유료 등급)미국 등 Google 데이터센터(리전 지정 없음)티켓 사진 이미지, AI 초안 설문 내용이용자가 AI 기능을 실행할 때마다 회사 서버(서울)를 거쳐 TLS 전송티켓 정보 추출, 여행 초안 생성남용 감시 목적으로 최대 55일 보관 후 삭제. 모델 학습·제품 개선에 사용하지 않음
Google LLC · Google Maps Platform(Places·Routes)미국 등 Google 데이터센터이용자가 입력한 장소 검색어·목적지, 지도 화면의 대략적 좌표 (회사 서버를 거쳐 전송하며 계정 정보·IP 주소·기기 정보는 보내지 않음)장소 검색·AI 초안 실행 시 회사 서버(서울)를 거쳐 TLS 전송장소 검색, 장소 검증, 경로 안내Google 서버 로그 보유 기준(수집 후 9~18개월 내 익명화)에 따름. 회사는 좌표 결과를 30일 이내에서만 캐시
PostHog, Inc. (2261 Market St #4008, San Francisco, CA, USA · privacy@posthog.com)미국 (AWS us-east-1)이용 기록, 기기 정보, 이용자 식별값 (IP 주소는 수집 즉시 폐기)앱 이용 시 TLS 전송이용 통계·제품 분석1년
에이비일팔공㈜ Airbridge (서울특별시 강남구 테헤란로 419, 19·20층 · 개인정보 보호책임자 류원경 · compliance@ab180.co · airbridge.io/ko/gdpr)일본 (AWS 도쿄 리전)광고 식별자(GAID·IDFV), 설치 참조값, 기기 정보, IP 주소, 전환 이벤트앱 설치·실행·가입·결제 시 TLS 전송설치 경로·마케팅 성과 측정, 초대 링크 연결탈퇴 시 또는 회사와의 계약 종료 시까지. Airbridge 자체 보유 상한 최대 1년
RevenueCat, Inc. (San Francisco, CA, USA · revenuecat.com/privacy · support@revenuecat.com)미국스토어 영수증 식별값, 구매·구독 이력, 이용자 식별값결제 시 TLS 전송영수증 검증, 구독·구매 이력 관리탈퇴 또는 회사의 삭제 요청 시까지
Mapbox, Inc. (San Francisco, CA, USA · mapbox.com/legal/privacy · privacy@mapbox.com)미국지도 화면 영역 좌표, IP 주소, 기기 정보지도 표시 시 TLS 전송지도 타일 제공IP 주소는 서비스 제공·과금·보안 목적으로 보관 후 30일 뒤 삭제(Mapbox 제품 개인정보방침 기준). 그 밖의 요청 로그는 목적 달성 시까지
OpenWeather Ltd. (London, UK · openweather.co.uk/privacy-policy)영국계획 장소의 좌표·날짜날씨 조회 시 TLS 전송날씨 정보 제공 (요청 값을 보관하지 않음)조회 즉시

국외 이전을 거부하는 방법과 효과

③ 회사는 국외 이전 시 「개인정보 보호법」 제28조의8제4항과 시행령에 따른 보호조치(위탁계약 체결, 암호화 전송, 수탁자 감독)를 합니다.

제7조 (개인정보의 파기 절차와 방법)

① 회사는 보유 기간이 지나거나 처리 목적이 달성되면 지체 없이 개인정보를 파기합니다.

② 절차: 이용자가 앱에서 콘텐츠를 삭제하거나 계정을 삭제하면 회사 서버의 운영 데이터(Firestore·Cloud Storage의 계정·계획·티켓·사진·컷·동선·푸시 토큰, Firebase 인증 정보)와 단말의 로컬 데이터가 즉시 삭제되고, 카카오·네이버 등 소셜 로그인 연결이 해제됩니다. 일 1회 생성되는 서버 백업본은 최대 7일 이내에 자동으로 파기됩니다. 수탁자(PostHog·Airbridge·RevenueCat)에 저장된 이용자 식별값은 계정 삭제 시 삭제를 요청합니다.

③ 방법: 전자적 파일은 복구할 수 없는 방법으로 삭제하고, 출력물이 있는 경우 파쇄합니다.

④ 법령에 따라 보존하는 정보(제1조의 결제·문의 기록)는 다른 개인정보와 분리하여 보존하고 보존 목적 외로 이용하지 않으며, 기간이 지나면 파기합니다.

⑤ 1년 이상 서비스를 이용하지 않은 이용자의 개인정보도 파기하지 않고 유지합니다. 여행 기록의 장기 보관이 서비스의 목적이기 때문이며, 이용자는 언제든지 직접 삭제할 수 있습니다.

제8조 (정보주체와 법정대리인의 권리와 행사 방법)

① 이용자는 회사에 대하여 언제든지 다음 권리를 행사할 수 있습니다.

  1. 개인정보 열람 요구
  2. 오류가 있는 경우 정정·삭제 요구
  3. 처리정지 요구
  4. 동의 철회(광고성 알림, 콘텐츠 마케팅 이용, 국외 이전 동의 등)
  5. 완전히 자동화된 결정에 대한 거부·설명 요구(「개인정보 보호법」 제37조의2). 현재 서비스에는 이용자의 권리·의무에 중대한 영향을 주는 자동화된 결정이 없습니다.

② 행사 방법: 앱 → 마이페이지 → 계정(정보 수정·계정 삭제) / 앱 → 설정(알림·분석 데이터·AI 기능) / 개인위치정보는 마이페이지 → 위치정보 관리(제2부) / 그 밖의 요구는 제13조의 연락처로 전자우편. 회사는 요구를 받은 날부터 10일 이내에 처리하고 결과를 알립니다.

③ 이용자의 법정대리인이나 위임을 받은 사람은 위임장을 제출하여 권리를 대신 행사할 수 있습니다.

④ 열람·정정·삭제·처리정지 요구가 법령상 제한되는 경우(다른 법령에 보존 의무가 있는 경우 등) 회사는 그 사유를 알립니다.

⑤ 권리 행사에 따라 불이익을 주지 않습니다. 다만 서비스 제공에 필요한 정보의 삭제·처리정지를 요구하면 해당 기능을 이용할 수 없을 수 있습니다.

제9조 (개인정보 자동 수집 장치의 설치·운영과 거부)

① 회사의 앱에는 다음 SDK가 포함되어 있으며, 각 SDK가 자동으로 수집하는 정보와 거부 방법은 다음과 같습니다.

SDK수집 정보목적거부 방법
Firebase (Google)인증 토큰, 푸시 토큰, 기기 정보, 오류 로그인증·저장·알림·진단알림: 기기 설정에서 알림 권한 끄기 / 오류 로그: iOS 설정 → 개인정보 보호 및 보안 → 분석 및 향상 → "앱 개발자와 공유" 끄기, Android 설정 → Google → "사용 및 진단" 끄기
PostHog앱 사용 이벤트, 기기 정보, 이용자 식별값이용 통계앱 마이페이지의 "이용 통계·분석 데이터 보내기" 스위치 끄기
Airbridge광고 식별자(GAID·IDFV), 설치 참조값, 기기 정보, 전환 이벤트설치 경로·성과 측정앱 마이페이지의 "이용 통계·분석 데이터 보내기" 스위치 끄기. Android 설정 → Google → 광고 → 광고 ID 재설정·삭제
Mapbox지도 요청 시 화면 영역 좌표, IP, 기기 정보지도 표시텔레메트리(이용자 위치의 Mapbox 전송)는 회사가 꺼 두었습니다. 지도 표시 자체를 거부하려면 앱을 사용하지 않는 방법 외에는 없습니다
RevenueCat영수증 식별값, 이용자 식별값결제 검증유료 결제를 하지 않으면 전송되지 않습니다

② 세션 리플레이(화면 녹화)는 사용하지 않습니다. PostHog로 전송되는 IP 주소는 수집 즉시 폐기되도록 설정하였습니다.

③ 웹사이트(everyticket.kr)와 웹 계획 도구는 로그인 유지 등 서비스 제공에 필요한 브라우저 저장소만 사용하며, 광고·추적 목적의 쿠키를 쓰지 않습니다. 이용자는 브라우저 설정에서 쿠키를 거부할 수 있으며 이 경우 로그인이 유지되지 않을 수 있습니다.

제10조 (개인정보의 안전성 확보 조치)

회사는 「개인정보 보호법」 제29조와 「개인정보의 안전성 확보조치 기준」, 위치정보법 제16조와 「위치정보의 관리적·기술적 보호조치 기준」에 따라 다음 조치를 합니다.

  1. 관리적 조치: 개인정보 보호책임자·위치정보관리책임자 지정, 개인정보·위치정보 취급 지침 수립·운영, 취급 직원 교육, 수탁자 감독
  2. 접근 통제: 관리 콘솔 접근권한자를 최소화(현재 1명)하고 2단계 인증을 적용, 서비스 계정 키 미발급, 접근권한 부여·변경·말소 기록 5년 보존, 데이터베이스 보안 규칙으로 이용자 본인 계정 외 접근 차단
  3. 접근 기록: 데이터베이스·저장소·관리 콘솔의 접근 기록을 1년 이상 보존하고 정기 점검
  4. 암호화: 전송 구간 TLS 암호화, 저장 데이터 암호화(Google Cloud 저장 암호화), 단말 저장소 보호
  5. 백업·복구: 데이터베이스 일 1회 백업(서울 리전, 7일 보관)
  6. 침해사고 대응: 유출등이 발생하면 72시간 이내에 이용자에게 통지하고 법령이 정한 경우 개인정보보호위원회 또는 한국인터넷진흥원에 신고하는 절차를 운영(제15조)

제11조 (사진·영상·음성에 담긴 다른 사람의 정보)

① 이용자가 등록하는 티켓 사진과 컷에는 동행자의 이름·예약번호·얼굴·음성 등 다른 사람의 정보가 담길 수 있습니다. 회사는 이러한 정보를 이용자가 등록한 콘텐츠의 일부로서 서비스 제공(저장·표시·결과물 생성) 범위에서만 처리하며, 별도로 추출·저장하거나 마케팅에 이용하지 않습니다.

② AI 자동 채우기는 티켓 여부·종류·제목·장소·날짜·종료일·출발지·도착지·좌석의 9개 항목만 추출하도록 설계되어 있고, 예약번호·바코드·개인 식별번호는 추출하지 않도록 지시하며 서버에서 한 번 더 걸러 냅니다.

③ 이용자는 사진을 등록하기 전에 다른 사람의 정보를 가리는 것이 좋으며, 다른 사람의 정보를 외부에 공유할 때에는 그 사람의 동의를 얻어야 합니다.

④ 자신의 정보가 다른 이용자의 콘텐츠에 담겨 있다고 판단하는 사람은 제13조의 연락처로 삭제를 요청할 수 있으며, 「개인정보 보호법」 제20조에 따라 수집 출처와 처리 목적의 고지를 요구할 수 있습니다.

제12조 (생성형 AI의 이용)

서비스의 AI 초안과 티켓 정보 추출 기능은 Google LLC의 생성형 인공지능 모델(Gemini)을 사용합니다. 처리되는 정보, 전송 경로, 보관, 이용자의 선택권은 부록 1에 상세히 적었습니다. 회사는 AI 기능을 처음 실행할 때 이 사실을 앱 화면으로 한 번 더 알리고, AI가 만든 결과물에 "AI 생성" 표시를 붙입니다.

제13조 (개인정보 보호책임자와 열람청구 창구)

구분내용
개인정보 보호책임자유병욱 (대표이사)
전화010-2136-1530
전자우편everyticket@gorocket.me
열람·정정·삭제·처리정지 청구 접수위와 같음 (담당: 개인정보 보호책임자)

회사는 소상공인으로서 대표이사가 개인정보 보호책임자를 겸합니다. 이용자는 서비스 이용 중 생긴 개인정보 관련 문의·불만·피해구제를 위 연락처로 요청할 수 있으며, 회사는 지체 없이 답변·처리합니다.

제14조 (권익침해 구제 방법)

이용자는 개인정보 침해에 대한 피해구제·상담을 다음 기관에 문의할 수 있습니다.

「개인정보 보호법」 제35조·제36조·제37조에 따른 열람·정정·삭제·처리정지 요구에 대한 회사의 처분에 불복하는 경우 「행정심판법」에 따라 행정심판을 청구할 수 있습니다(중앙행정심판위원회 110, simpan.go.kr).

제15조 (개인정보 유출 시 통지)

회사는 개인정보의 분실·도난·유출·위조·변조·훼손(유출등)을 알게 되면 「개인정보 보호법」 제34조에 따라 72시간 이내에 유출된 항목·시점·경위, 이용자가 할 수 있는 조치, 회사의 대응, 연락처를 이용자에게 통지하고, 법령이 정한 경우 개인정보보호위원회 또는 한국인터넷진흥원에 신고합니다.

제16조 (방침의 변경과 고지)

① 이 방침을 개정할 때에는 적용일 7일 전부터 앱 공지와 웹사이트에 개정 내용과 사유를 게시합니다. 법령에 따라 동의가 필요한 사항은 다시 동의를 받습니다.

② 이 방침과 이용약관의 내용이 다른 경우 이용자에게 유리한 것을 적용합니다.

③ 이전 버전은 웹사이트의 개정 이력에서 볼 수 있습니다.

제2부 개인위치정보 처리방침

이 부는 위치정보법 제21조의2와 같은 법 시행령 제25조의2에 따른 개인위치정보 처리방침입니다. 회사는 방송미디어통신위원회에 신고한 위치기반서비스사업자(제12279호, 2026. 9. 8.)이며, 개인위치정보의 수집·이용 조건은 「Every Ticket 위치기반서비스 이용약관」에 따릅니다.

제1조 (개인위치정보의 처리 목적과 보유 기간)

① 처리 목적

목적내용
여행 동선 표시이용자가 "기록 시작"을 누른 여행에 한해 단말 위치(위도·경도·시각·정확도)를 60~200m 간격으로 수집하여 지도에 동선을 표시하고 이동수단을 구분
계획 장소 도착 확인계획한 장소 근처에 머물면 도착으로 판단하여 티켓으로 남길지 물음
컷·티켓의 위치 표시컷 촬영·티켓 등록 시점의 위치를 동선 위에 표시
잠금화면·알림 안내기록 중 다음 목적지까지의 거리·이동수단 표시
결과물 생성·보관·복원여행 카드·필름 생성(단말 내), 이용자 본인 계정 보관, 기기 변경 시 복원

보유 목적과 보유 기간: 회사는 이용자가 기록한 동선을 본인이 보관·열람·재생하고 결과물을 만들 수 있게 할 목적으로 개인위치정보를 보유하며, 보유 기간은 이용자가 해당 여행을 삭제하거나 탈퇴하거나 동의를 철회할 때까지입니다. 그때 보유 목적이 달성된 것으로 보아 지체 없이 파기합니다.

③ 기록 중이 아닐 때에는 위치를 수집하지 않으며, 광고·마케팅·판매 목적으로 개인위치정보를 이용하지 않습니다.

④ 저장 위치: 회사가 임차한 Google Cloud Firebase 서울 리전(asia-northeast3)의 이용자 본인 계정 영역. 이용자 본인 계정에서만 열람할 수 있고 다른 이용자에게 보이지 않으며, 회사의 접근은 제9조의 보호조치에 따라 제한됩니다.

제2조 (위치정보 수집·이용·제공사실 확인자료의 보유 근거와 보유 기간)

① 회사는 위치정보법 제16조제2항에 따라 개인위치정보의 수집·이용·제공 사실을 확인할 수 있는 자료(확인자료)를 위치정보시스템에 자동으로 기록·보존합니다. 확인자료에는 좌표가 포함되지 않습니다.

② 항목: 여행별 수집 시작·종료 시각, 수집 방법(단말 위치정보 기능), 동의 버전·동의 시각, 이용 일시·목적·대상 여행, 제3자 제공 사실(해당 시), 이용자의 권리 행사 내역.

보유 근거: 위치정보법 제16조제2항. 보유 기간: 기록일부터 6개월. 기간이 지나면 자동으로 파기하며, 이용자가 동의를 철회하거나 탈퇴하면 그 이용자의 확인자료를 기간과 관계없이 지체 없이 파기합니다.

제3조 (개인위치정보의 파기 절차와 방법)

① 파기 시점: 이용자가 해당 여행 또는 동선을 삭제한 때, 탈퇴한 때(동의 철회를 포함하며 확인자료도 함께 파기), 동의를 철회한 때(확인자료 포함), 만 14세 미만의 이용이 확인된 때.

② 파기 방법: 클라우드 저장소의 운영 데이터를 즉시 삭제하고, 일 1회 생성되는 백업본은 최대 7일 이내에 자동 파기합니다. 이용자 단말의 사본은 앱 삭제 또는 로그아웃 시 삭제됩니다. 이용자가 이미 외부로 내보낸 결과물은 파기 대상이 아닙니다.

③ 확인자료는 제2조의 보유 기간이 지나면 자동으로 파기합니다.

제4조 (개인위치정보의 제3자 제공)

회사는 개인위치정보를 제3자에게 제공하지 않습니다. 공동 계획의 동행자에게 보이는 것은 이용자가 계획에 직접 입력·등록한 장소·일정·티켓 정보이며, 이용자의 이동 동선과 컷의 위치는 동행자를 포함한 누구에게도 제공되지 않습니다.

② 회사는 개인위치정보를 Google Cloud Firebase(서울 리전)에 저장하기 위하여 Google LLC에, 기록 중 지도를 표시하기 위하여 지도 화면 영역의 좌표를 Mapbox, Inc.(미국)에 처리위탁합니다(제1부 제5조·제6조). 이는 제3자 제공이 아닌 처리위탁이며, Mapbox의 텔레메트리(이용자 위치의 별도 전송)는 꺼 두었습니다.

③ 회사가 장래에 이용자가 지정하는 제3자에게 개인위치정보를 제공하는 서비스를 시작하려는 경우 제공받는 자와 제공 목적을 알리고 별도 동의를 받으며, 이 방침을 개정하여 공개합니다.

제5조 (제3자 제공 시 통보에 관한 사항)

회사가 제4조제3항에 따라 이용자가 지정하는 제3자에게 개인위치정보를 제공하는 경우, 위치정보법 제19조제3항에 따라 매회 제공받는 자·제공 일시·제공 목적을 개인위치정보를 수집한 단말로 즉시 통보합니다. 이용자는 별도 동의를 통해 최대 30일의 범위에서 횟수(10회·20회·30회) 또는 기간(10일·20일·30일) 단위로 모아서 통보받는 방법을 선택할 수 있고, 언제든지 즉시 통보로 되돌릴 수 있습니다.

제6조 (8세 이하의 아동등의 보호의무자의 권리·의무와 행사 방법)

① 8세 이하의 아동, 피성년후견인, 「장애인복지법」상 정신적 장애를 가진 중증장애인(장애인 등록을 한 사람에 한함)의 보호의무자가 그 사람의 생명 또는 신체의 보호를 위하여 개인위치정보의 수집·이용·제공에 동의하는 경우에는 본인의 동의가 있는 것으로 봅니다.

② 보호의무자는 8세 이하의 아동등의 성명·주소·생년월일, 보호의무자의 성명·주소·연락처, 목적이 생명·신체의 보호에 한정된다는 사실을 적고 서명한 서면동의서에 보호의무자임을 증명하는 서면을 첨부하여 제8조의 연락처로 제출합니다.

③ 보호의무자는 8세 이하의 아동등의 개인위치정보에 관하여 제7조의 권리를 행사할 수 있으며, 그 개인위치정보를 아동등의 생명·신체 보호 목적으로만 이용하고 아동등의 이익을 우선하여야 합니다.

④ 회사는 만 14세 미만 아동의 개인위치정보를 수집하지 않으며, 장래에 수집하려는 경우 위치정보법 제25조에 따라 법정대리인의 동의를 받고 확인합니다.

제7조 (개인위치정보주체의 권리와 행사 방법)

권리행사 방법처리
동의의 전부 또는 일부 철회앱 마이페이지 → 위치정보 관리 → "위치정보 동의 철회"즉시. 철회한 부분의 개인위치정보와 확인자료를 지체 없이 파기
수집·이용·제공의 일시중지기록 화면의 "일시중지" 또는 마이페이지 → 위치정보 관리 → "기록 일시중지"즉시
확인자료의 열람·고지, 제3자 제공 이유·내용의 열람·고지마이페이지 → 위치정보 관리 → "확인자료 열람"즉시(앱 화면)
확인자료의 정정마이페이지 → 위치정보 관리 → "문의" 또는 제8조의 연락처10일 이내
여행별 동선 삭제여행 상세 화면 → "동선 삭제" 또는 여행 삭제즉시, 백업본 7일 이내

단말 운영체제의 위치 권한을 끄는 것은 위치 수집을 기술적으로 막지만 위 동의 철회와는 별개이며, 이미 수집된 개인위치정보의 파기를 원하면 동의 철회 또는 삭제를 이용하시기 바랍니다.

제8조 (위치정보관리책임자)

구분내용
성명유병욱 (대표이사)
전화010-2136-1530
전자우편everyticket@gorocket.me
담당 업무개인위치정보 보호 정책 수립·시행, 이용자 권리 행사와 고충 처리, 보호조치 점검, 확인자료 관리

제9조 (위치정보의 보호조치)

회사는 위치정보법 제16조제1항과 「위치정보의 관리적·기술적 보호조치 기준」에 따라 위치정보 취급·관리 지침 수립, 접근권한자 최소화(현재 1명)와 2단계 인증, 접근권한 기록 5년 보존, 전송·저장 암호화, 데이터베이스 보안 규칙에 의한 본인 외 접근 차단, 위치정보시스템 접근기록 1년 보존, 확인자료 자동 기록·보존의 조치를 합니다(제1부 제10조 참조).

부록 1. 생성형 AI 처리 상세

구분내용
사용 모델·사업자Google LLC의 Gemini 모델, Gemini API(Developer API) 유료 등급
적용 기능① AI 자동 채우기(티켓 사진에서 정보 추출) ② AI 초안(설문 기반 여행 계획 초안)
전송되는 정보① 이용자가 선택한 티켓 사진 이미지 ② 설문 내용(목적지·출발지·날짜·동행·예산 범위·취향·메모). 이름·전자우편 등 계정 정보와 이용자 식별값은 전송하지 않음
전송 경로앱 → 회사 서버 기능(Cloud Functions, 서울) → Gemini API. AI 경로에서 회사 서버는 사진을 저장하지 않고 응답 후 폐기
Google의 보관Google은 이용 정책 위반(남용) 감시 목적으로 입력·출력을 최대 55일 보관한 뒤 삭제합니다. 유료 등급에서 입력·출력은 Google의 모델 학습·제품 개선에 사용되지 않습니다
추출 항목 제한티켓 여부, 종류, 제목, 장소, 날짜, 종료일, 출발지, 도착지, 좌석의 9개 항목만 추출. 예약번호·바코드·개인 식별번호는 추출하지 않도록 지시하고 서버에서 재차 걸러 냄
이용자의 확인추출 결과는 이용자가 확인·수정한 뒤에만 저장됨. AI 초안은 참고용이며 "AI 생성" 표시를 붙임
선택권AI 기능을 쓰지 않고 직접 입력 가능. AI 기능 첫 실행 시 이 내용을 앱 화면으로 안내
사람의 검토회사 직원은 AI 입력·출력을 개별적으로 열람하지 않음
관련 법령「인공지능 발전과 신뢰 기반 조성 등에 관한 기본법」 제31조(생성형 AI 고지·표시), 「개인정보 보호법」 제26조·제28조의8

부록 2. 개정 이력

버전시행일주요 변경
v12026-09-10최초 게시
v22026-09-16전면 개정: 항목별 근거·보유기간 표, 제3자 제공(동행자) 분리, 위탁·국외이전 항목별 기재(Firebase 인증 미국, Airbridge 일본, Gemini 55일 보관), 컷 영상의 클라우드 저장·현장음 명시, 파기 절차(백업 7일), SDK 거부 방법, 안전성 확보조치, 사진 속 다른 사람의 정보, 생성형 AI 부록, 제2부 개인위치정보 처리방침 신설, 책임자 실명 표기

이전 판본: 2026-09-10 개인정보처리방침 보기

← 홈으로

Privacy Policy

Effective 2026-09-16 · Revised 2026-09-01

The Mapbox retention period (30 days) is based on Mapbox's public materials and is being verified. This Policy consists of Part 1 (personal information) and Part 2 (personal location information); Part 2 is the personal location information processing policy under Article 21-2 of the Act on the Protection and Use of Location Information. Website address: everyticket.kr/privacy (direct link to Part 2: everyticket.kr/privacy#location). This is a translation of the Korean original. If the two differ, the Korean text prevails.

Gorocket Company Co., Ltd. (the "Company") processes the personal information of users of Every Ticket (the "Service") in accordance with the Personal Information Protection Act, the Act on the Protection and Use of Location Information (the "Location Information Act"), and other applicable laws. This Policy explains what information we process, on what basis, and for how long, and what rights users have and how to exercise them.

At a glance

Part 1 Privacy Policy

Article 1 (Items, Purposes, Basis, and Retention Period of Personal Information Processed)

The Company processes the following personal information. The basis given in the table refers to the subparagraphs of Article 15 (1) of the Personal Information Protection Act; at sign-up, the Company informs the user of this content and obtains consent to the collection and use of personal information as a separate item.

CategoryItemsWhen collectedPurposeBasisRetention period
AccountEmail address (for Apple sign-in, this may be a relay address issued by Apple), name (nickname), profile photo, member identifier issued by the social sign-in provider (Google, Apple, Kakao, Naver)At sign-in and sign-upIdentifying members and signing in, syncing data across devices, notificationsFormation and performance of a contract (subparagraph 4)Until withdrawal
Personal location informationLatitude, longitude, collection time, accuracy (route of travel); location at the time of Cut capture and ticket registrationFrom when the user taps "Start recording" until the trip endsRoute display, arrival confirmation, output creation, storage and restoration in the user's own accountConsent under Article 19 (1) of the Location Information ActUntil the trip is deleted, the user withdraws, or consent is withdrawn (see Part 2)
PlanDestination, places, itinerary, notes, expenses, checklists, list of companions in a shared plan (nickname, colour)When creating a planCreating trip plans and co-editingFormation and performance of a contract (subparagraph 4)Until the plan is deleted or the user withdraws
AI draft surveyDestination, origin, dates, companions, budget range, preferences, notes on what to include or avoidWhen using the AI draft featureGenerating a survey-based trip plan draftFormation and performance of a contract (subparagraph 4)Stored in the plan with the generated draft; until the plan is deleted or the user withdraws
Photos, video, audioTicket and keepsake photos, one-second videos (Cuts) and the ambient sound recorded with CutsWhen the user captures or selects themTicket registration, recording, creation of outputs (cards, films), restoration when changing devicesFormation and performance of a contract (subparagraph 4)Until the content is deleted or the user withdraws
Ticket informationType, title, place, date, origin, destination, seat, etc., entered by the user or extracted by AI and confirmed by the userWhen registering a ticketTicket registration and classification, output creationFormation and performance of a contract (subparagraph 4)Until the ticket is deleted or the user withdraws
PaymentStore (Apple App Store, Google Play) receipt identifier, product purchased and time, store country, subscription statusWhen making a paid purchasePayment confirmation, Trip Pass and subscription management, refunds and withdrawal of offerFormation and performance of a contract (subparagraph 4), legal obligation (subparagraph 2)Until withdrawal. However, under the Act on Consumer Protection in Electronic Commerce, records of contracts and withdrawal of offer and records of payment and supply of goods are kept for 5 years, and records of handling consumer complaints and disputes for 3 years
Device and notificationsPush notification token, device model, OS version, app version, language, time zone, app install referrerAt app install and when notifications are allowedSending service notifications (recording, invitations, payment, policy changes), restoration per deviceFormation and performance of a contract (subparagraph 4)Until withdrawal or app deletion
Advertising notifications(Use of the push token above)Where the user has given separate consentAnnouncing new features, events, discountsConsent (subparagraph 1)Until consent is withdrawn; reconfirmed every 2 years
Advertising identifiersAndroid Advertising ID (GAID), iOS identifier for vendor (IDFV), IP addressAt app install and launchMeasuring app install sources and marketing performance, connecting invitation links (deferred deep links)Legitimate interest (subparagraph 6) · users may refuse in the app settingsUntil withdrawal or the end of the contract with the processor
Usage recordsApp usage events (screens and features used, time), device information, user identifier assigned by the CompanyDuring app useUsage statistics analysis to improve the ServiceLegitimate interest (subparagraph 6) · may be refused in the app settings1 year from collection
Error diagnosticsError (crash) logs, device information, app stateWhen an error occursError diagnosis and stability improvementLegitimate interest (subparagraph 6)90 days from collection
EnquiriesEmail address, enquiry content, attachmentsWhen making an enquiryHandling enquiries and complaints, handling requests to exercise rightsFormation and performance of a contract (subparagraph 4), legal obligation (subparagraph 2)3 years after handling is complete
Access logsAccess logs of the location information system and management consoleDuring system operationEnsuring security, responding to security incidentsLegal obligation (subparagraph 2)1 year

② The Company does not request the iOS App Tracking Transparency (ATT) permission and does not collect the advertising identifier (IDFA). The Android Advertising ID can be reset or deleted in the device settings.

③ The Company does not collect sensitive information (thoughts and beliefs, health, etc.) or unique identifying information (resident registration number, etc.).

④ At sign-up the Company confirms that the user is 14 or older, and does not collect the personal information of children under 14. If use by a person under 14 is found, the account and related information are destroyed without delay.

Article 2 (How Personal Information Is Collected)

  1. The user enters, captures, or selects it directly in the app or on the website
  2. On social sign-in, Google, Apple, Kakao, or Naver passes it to the Company with the user's consent (for Kakao and Naver, the Company's server verifies the token issued by the provider and receives the member identifier, nickname, profile photo, and email (where consented))
  3. Automatic collection through the device's location feature, only for a trip being recorded
  4. Automatic generation and collection by software development kits (SDKs) included in the app (Article 9)
  5. The store passes the payment result to the Company

Article 3 (Processing Beyond the Purpose of Use)

The Company uses personal information only within the scope of the purposes in Article 1, and if the purpose changes, processes it only with separate consent under Article 18 of the Personal Information Protection Act or within the scope permitted by law. If a feature is introduced that shows users' ratings and one-line reviews to other users, they are provided only in an anonymised, aggregated form from which individuals cannot be identified, and this Policy is revised to announce it.

Article 4 (Provision of Personal Information to Third Parties)

① In principle the Company does not provide users' personal information to third parties, and provides it only in the following cases.

RecipientItems providedPurposeBasisRecipient's retention period
Companions in a shared planPlace, itinerary, expense, checklist, and ticket information the user has entered or registered in the plan; nickname and colourCo-editing the planThe user's act of creating an invitation link and inviting companions (Article 17 (1) 1 of the Act)Until the companion deletes the plan or withdraws

The user's route of travel, Cuts, photos, and impressions are never provided to companions. Place search terms and the map view area are passed to Google Maps Platform through the Company's server, but account information, IP address, and device information are not sent with them, so this is not provision of personal information to a third party; for transparency it is listed in the table in Article 6.

② Where there is a special provision in law, or an investigative agency requests it in accordance with the procedures and methods prescribed by law, the Company may provide information within that scope; the Company verifies the legality of the request, provides the minimum necessary, and records the details.

Article 5 (Outsourcing of Personal Information Processing)

① To provide the Service, the Company outsources personal information processing as follows.

ProcessorOutsourced workItems
Google LLC (Firebase)Member authentication (Authentication), database (Firestore), file storage (Cloud Storage), server functions (Cloud Functions), push notifications (FCM), error diagnostics (Crashlytics)Account, plans, tickets, photos and Cuts, routes, device and notifications, error diagnostics
Google LLC (Gemini API, paid tier)Ticket photo information extraction, survey-based trip draft generationTicket photo images, AI draft survey
Mapbox, Inc.Map displayMap view area coordinates, IP address, device information (telemetry is off)
OpenWeather Ltd.Weather lookup for trip datesCoordinates and dates of planned places
PostHog, Inc.Usage statistics and product analyticsUsage records, device information, user identifier
AB180 Inc. (Airbridge)Measuring app install sources and marketing performance, connecting invitation linksAdvertising identifiers (GAID, IDFV), install referrer, device information, IP address, conversion events such as sign-up and payment
RevenueCat, Inc.In-app purchase receipt verification, subscription and purchase history managementPayment, user identifier

② In its outsourcing contracts the Company stipulates, under Article 26 of the Personal Information Protection Act, the prohibition of processing beyond the outsourced purpose, technical and managerial protective measures, restrictions on sub-outsourcing, management and supervision of the processor, and compensation for damages, and supervises whether the processor handles personal information safely.

③ Where a processor sub-outsources the Company's work, it obtains the Company's consent, and the sub-processor and its work are disclosed in this Policy. The current processors carry out their work using their own cloud infrastructure (Google Cloud, Amazon Web Services).

④ If the content of outsourced work or a processor changes, this Policy is revised without delay to announce it.

⑤ The Apple App Store and Google Play are not processors of the Company but independent businesses that enter into payment contracts directly with users; payment method details are held only by the store and are not passed to the Company. The sign-in services of Kakao, Naver, Google, and Apple are also governed by each company's privacy policy.

Article 6 (Cross-Border Transfer of Personal Information)

① Under Article 28-8 (1) 3 (a) of the Personal Information Protection Act (outsourcing of processing or storage for the formation and performance of a contract with the data subject, where the following matters are disclosed in the privacy policy), the Company outsources processing and storage of personal information abroad as follows. PostHog and Airbridge are outsourced processing needed for operating and improving the Service and for the invitation link feature, and fall under the same subparagraph, but users may refuse at any time.

Recipient (contact)CountryItems transferredWhen and howPurposeRetention and use period
Google LLC · Firebase Authentication (1600 Amphitheatre Pkwy, Mountain View, CA, USA · policies.google.com/privacy · support.google.com/policies/contact/general_privacy_form)United States (the authentication service is processed only in the United States)Email, name, profile photo, social sign-in identifier, sign-in tokensSent over an encrypted network (TLS) at sign-inMember authentication and account managementUntil withdrawal
Google LLC · Firestore, Cloud Storage, Cloud FunctionsStored in the Republic of Korea (Seoul region). However, it may be accessed from abroad, including the United States, in the course of Google's global operations and technical supportAccount, plans, tickets, photos and Cuts (including ambient sound), routesTLS transmission during Service use, stored in the Seoul regionData storage, processing, and backupUntil deletion or withdrawal; backups within 7 days at most
Google LLC · FCM, CrashlyticsGoogle data centres including the United States (no region designated)Push token, device information, error logsTLS transmission when sending notifications or when an error occursSending push notifications, error diagnosticsPush token: until withdrawal or app deletion / error logs: 90 days
Google LLC · Gemini API (paid tier)Google data centres including the United States (no region designated)Ticket photo images, AI draft survey contentTLS transmission via the Company's server (Seoul) each time the user runs an AI featureTicket information extraction, trip draft generationKept for at most 55 days for abuse monitoring, then deleted. Not used for model training or product improvement
Google LLC · Google Maps Platform (Places, Routes)Google data centres including the United StatesPlace search terms and destinations entered by the user, approximate coordinates of the map view (sent through the Company's server; account information, IP address, and device information are not sent)TLS transmission through the Company's server (Seoul) when running place search or AI draftsPlace search, place verification, route guidanceFollows Google's server log retention standard (anonymised within 9 to 18 months of collection). The Company caches coordinate results for no more than 30 days
PostHog, Inc. (2261 Market St #4008, San Francisco, CA, USA · privacy@posthog.com)United States (AWS us-east-1)Usage records, device information, user identifier (the IP address is discarded immediately on collection)TLS transmission during app useUsage statistics and product analytics1 year
AB180 Inc., Airbridge (19th and 20th floors, 419 Teheran-ro, Gangnam-gu, Seoul · Privacy officer Wongyeong Ryu · compliance@ab180.co · airbridge.io/ko/gdpr)Japan (AWS Tokyo region)Advertising identifiers (GAID, IDFV), install referrer, device information, IP address, conversion eventsTLS transmission at app install, launch, sign-up, and paymentMeasuring install sources and marketing performance, connecting invitation linksUntil withdrawal or the end of the contract with the Company. Airbridge's own retention cap is at most 1 year
RevenueCat, Inc. (San Francisco, CA, USA · revenuecat.com/privacy · support@revenuecat.com)United StatesStore receipt identifier, purchase and subscription history, user identifierTLS transmission at paymentReceipt verification, subscription and purchase history managementUntil withdrawal or a deletion request by the Company
Mapbox, Inc. (San Francisco, CA, USA · mapbox.com/legal/privacy · privacy@mapbox.com)United StatesMap view area coordinates, IP address, device informationTLS transmission when displaying mapsProviding map tilesThe IP address is kept for service provision, billing, and security and deleted after 30 days (per Mapbox's product privacy policy). Other request logs are kept until the purpose is achieved
OpenWeather Ltd. (London, UK · openweather.co.uk/privacy-policy)United KingdomCoordinates and dates of planned placesTLS transmission when looking up weatherProviding weather information (request values are not stored)Immediately on lookup

How to refuse cross-border transfer, and the effect

③ For cross-border transfers the Company takes the protective measures under Article 28-8 (4) of the Personal Information Protection Act and its Enforcement Decree (concluding outsourcing contracts, encrypted transmission, supervising processors).

Article 7 (Procedure and Method of Destroying Personal Information)

① The Company destroys personal information without delay when the retention period has passed or the purpose of processing has been achieved.

② Procedure: when the user deletes content or deletes their account in the app, the operational data on the Company's servers (account, plans, tickets, photos, Cuts, routes, and push tokens in Firestore and Cloud Storage, and Firebase authentication information) and the local data on the device are deleted immediately, and social sign-in links such as Kakao and Naver are disconnected. The server backup created once a day is destroyed automatically within 7 days at most. The Company requests deletion of the user identifiers stored with processors (PostHog, Airbridge, RevenueCat) when the account is deleted.

③ Method: electronic files are deleted in a way that cannot be recovered, and any printouts are shredded.

④ Information kept under law (the payment and enquiry records in Article 1) is stored separately from other personal information, is not used beyond the purpose of retention, and is destroyed when the period has passed.

⑤ The personal information of users who have not used the Service for 1 year or more is also kept rather than destroyed. This is because long-term storage of travel records is the purpose of the Service, and users may delete it themselves at any time.

Article 8 (Rights of Data Subjects and Legal Representatives and How to Exercise Them)

① Users may exercise the following rights against the Company at any time.

  1. Request access to personal information
  2. Request correction or deletion where there is an error
  3. Request suspension of processing
  4. Withdraw consent (advertising notifications, marketing use of content, consent to cross-border transfer, etc.)
  5. Refuse, or request an explanation of, a fully automated decision (Article 37-2 of the Personal Information Protection Act). The Service currently has no automated decisions that materially affect users' rights or obligations.

② How to exercise: App → My Page → Account (edit information, delete account) / App → Settings (notifications, analytics data, AI features) / for personal location information, My Page → Location settings (Part 2) / other requests by email to the contact in Article 13. The Company handles requests within 10 days of receipt and informs the user of the result.

③ A user's legal representative or an authorised person may exercise the rights on the user's behalf by submitting a power of attorney.

④ Where a request for access, correction, deletion, or suspension of processing is restricted by law (for example, where another law imposes a retention obligation), the Company informs the user of the reason.

⑤ No disadvantage results from exercising rights. However, requesting deletion or suspension of processing of information needed to provide the Service may make the feature concerned unavailable.

Article 9 (Installation and Operation of Automatic Collection Devices and How to Refuse)

① The Company's app includes the following SDKs; the information each collects automatically and how to refuse are as follows.

SDKInformation collectedPurposeHow to refuse
Firebase (Google)Authentication tokens, push tokens, device information, error logsAuthentication, storage, notifications, diagnosticsNotifications: turn off the notification permission in device settings / Error logs: iOS Settings → Privacy & Security → Analytics & Improvements → turn off "Share with App Developers"; Android Settings → Google → turn off "Usage & diagnostics"
PostHogApp usage events, device information, user identifierUsage statisticsTurn off the "Send usage statistics and analytics data" switch on the app's My Page
AirbridgeAdvertising identifiers (GAID, IDFV), install referrer, device information, conversion eventsInstall source and performance measurementTurn off the "Send usage statistics and analytics data" switch on the app's My Page. Android Settings → Google → Ads → reset or delete the advertising ID
MapboxMap view area coordinates on map requests, IP, device informationMap displayThe Company has turned telemetry (sending the user's location to Mapbox) off. There is no way to refuse map display itself other than not using the app
RevenueCatReceipt identifier, user identifierPayment verificationNothing is sent unless you make a paid purchase

② Session replay (screen recording) is not used. The IP address sent to PostHog is set to be discarded immediately on collection.

③ The website (everyticket.kr) and the web planning tool use only the browser storage needed to provide the Service, such as keeping you signed in, and do not use cookies for advertising or tracking. Users may refuse cookies in their browser settings, in which case sign-in may not be kept.

Article 10 (Measures to Ensure the Safety of Personal Information)

The Company takes the following measures in accordance with Article 29 of the Personal Information Protection Act and the Standards for Measures to Ensure the Safety of Personal Information, and Article 16 of the Location Information Act and the Standards for Managerial and Technical Protective Measures for Location Information.

  1. Managerial measures: designating a privacy officer and a location information manager, establishing and operating guidelines for handling personal and location information, training staff who handle it, supervising processors
  2. Access control: minimising persons with access to the management console (currently 1) and applying two-factor authentication, not issuing service account keys, keeping records of granting, changing, and revoking access rights for 5 years, blocking access from any account other than the user's own through database security rules
  3. Access logs: keeping access logs for the database, storage, and management console for 1 year or more and inspecting them regularly
  4. Encryption: TLS encryption in transit, encryption of stored data (Google Cloud encryption at rest), protection of device storage
  5. Backup and recovery: daily database backup (Seoul region, kept for 7 days)
  6. Incident response: a procedure for notifying users within 72 hours of a breach and, where required by law, reporting to the Personal Information Protection Commission or the Korea Internet & Security Agency (Article 15)

Article 11 (Other People's Information in Photos, Videos, and Audio)

① Ticket photos and Cuts a user registers may contain other people's information such as companions' names, booking numbers, faces, and voices. The Company processes such information only as part of the content the user registered, within the scope of providing the Service (storage, display, output creation), and does not separately extract or store it or use it for marketing.

② AI autofill is designed to extract only nine fields: whether it is a ticket, type, title, place, date, end date, origin, destination, and seat. It is instructed not to extract booking numbers, barcodes, or personal identification numbers, and the server filters them out once more.

③ Users are advised to mask other people's information before registering a photo, and must obtain that person's consent when sharing another person's information externally.

④ A person who believes their information is contained in another user's content may request deletion through the contact in Article 13, and may request notice of the source of collection and the purpose of processing under Article 20 of the Personal Information Protection Act.

Article 12 (Use of Generative AI)

The Service's AI draft and ticket information extraction features use a generative artificial intelligence model (Gemini) of Google LLC. The information processed, the transmission path, retention, and the user's choices are set out in detail in Appendix 1. The Company announces this once more on an app screen when an AI feature is first run, and labels outputs made by AI as "AI generated".

Article 13 (Privacy Officer and Contact for Access Requests)

ItemDetails
Privacy officerByungwook Yoo (유병욱) (Chief Executive Officer)
Telephone+82 10-2136-1530
Emaileveryticket@gorocket.me
Receipt of requests for access, correction, deletion, and suspension of processingAs above (handled by the privacy officer)

As a small business, the Company's Chief Executive Officer also serves as privacy officer. Users may direct enquiries, complaints, and requests for remedy concerning personal information arising from use of the Service to the contact above, and the Company responds and handles them without delay.

Article 14 (Remedies for Infringement of Rights)

Users may contact the following bodies for remedy or advice concerning personal information infringement.

A person who objects to the Company's disposition of a request for access, correction, deletion, or suspension of processing under Articles 35, 36, and 37 of the Personal Information Protection Act may file an administrative appeal under the Administrative Appeals Act (Central Administrative Appeals Commission 110, simpan.go.kr).

Article 15 (Notification of Personal Information Breaches)

If the Company becomes aware of the loss, theft, leakage, forgery, alteration, or damage of personal information (a "breach"), it notifies users within 72 hours, in accordance with Article 34 of the Personal Information Protection Act, of the items, time, and circumstances of the breach, what users can do, the Company's response, and a contact point, and where required by law reports to the Personal Information Protection Commission or the Korea Internet & Security Agency.

Article 16 (Changes to and Notice of the Policy)

① When this Policy is revised, the revised content and reasons are posted in the app notices and on the website from 7 days before the effective date. Matters requiring consent under law are consented to again.

② Where this Policy and the Terms of Service differ, whichever is more favourable to the user applies.

③ Previous editions can be viewed in the revision history on the website.

Part 2 Personal Location Information Processing Policy

This Part is the personal location information processing policy under Article 21-2 of the Location Information Act and Article 25-2 of its Enforcement Decree. The Company is a location-based service provider reported to the Korea Communications Commission (No. 12279, 8 September 2026), and the conditions for collecting and using personal location information follow the "Every Ticket Location-Based Service Terms".

Article 1 (Purpose of Processing and Retention Period of Personal Location Information)

① Purposes of processing

PurposeDescription
Trip route displayOnly for a trip on which the user has tapped "Start recording", the device location (latitude, longitude, time, accuracy) is collected at 60 to 200 m intervals to show the route on the map and distinguish the mode of transport
Arrival confirmation at planned placesWhen the user stays near a planned place, arrival is inferred and the user is asked whether to keep it as a ticket
Location display for Cuts and ticketsThe location at the time of Cut capture or ticket registration is shown on the route
Lock-screen and notification guidanceDuring recording, the distance to the next destination and the mode of transport are shown
Output creation, storage, and restorationCreation of trip cards and films (on the device), storage in the user's own account, restoration when changing devices

Purpose and period of retention: the Company retains personal location information so that the user can keep, view, and replay the route the user recorded and create outputs from it, and the retention period lasts until the user deletes the trip, withdraws from the Service, or withdraws consent. At that point the purpose of retention is deemed achieved and the information is destroyed without delay.

③ Location is not collected when recording is not in progress, and personal location information is not used for advertising, marketing, or sales purposes.

④ Storage location: the user's own account area in the Seoul region (asia-northeast3) of Google Cloud Firebase leased by the Company. It can be viewed only from the user's own account and is not visible to other users, and the Company's access is restricted under the protective measures in Article 9.

Article 2 (Basis and Period of Retention of Records Confirming Collection, Use, and Provision of Location Information)

① In accordance with Article 16 (2) of the Location Information Act, the Company automatically records and keeps in its location information system materials that confirm the collection, use, and provision of personal location information (confirmation records). Confirmation records do not include coordinates.

② Items: start and end time of collection for each trip, method of collection (device location feature), consent version and consent time, date and time, purpose, and trip concerned for each use, any provision to third parties (where applicable), and the user's exercise of rights.

Basis for retention: Article 16 (2) of the Location Information Act. Retention period: 6 months from the date of the record. Records are destroyed automatically when the period has passed, and if the user withdraws consent or withdraws from the Service, that user's confirmation records are destroyed without delay regardless of the period.

Article 3 (Procedure and Method of Destroying Personal Location Information)

① When destroyed: when the user deletes the trip or route; when the user withdraws (including withdrawal of consent, with confirmation records destroyed together); when the user withdraws consent (including confirmation records); when use by a person under 14 is found.

② Method: operational data in cloud storage is deleted immediately, and the backup created once a day is destroyed automatically within 7 days at most. Copies on the user's device are deleted when the app is deleted or the user signs out. Outputs the user has already exported are not subject to destruction.

③ Confirmation records are destroyed automatically when the retention period in Article 2 has passed.

Article 4 (Provision of Personal Location Information to Third Parties)

The Company does not provide personal location information to third parties. What companions in a shared plan can see is the place, itinerary, and ticket information the user has directly entered or registered in the plan; the user's route of travel and the locations of Cuts are not provided to anyone, including companions.

② The Company outsources processing to Google LLC to store personal location information in Google Cloud Firebase (Seoul region), and to Mapbox, Inc. (United States) for the map view area coordinates in order to display the map during recording (Part 1, Articles 5 and 6). This is outsourced processing, not provision to a third party, and Mapbox telemetry (separate transmission of the user's location) is turned off.

③ Should the Company in future launch a service that provides personal location information to a third party designated by the user, it informs the user of the recipient and the purpose, obtains separate consent, and revises this Policy to disclose it.

Article 5 (Notification on Provision to Third Parties)

Where the Company provides personal location information to a third party designated by the user under Article 4 ③, it notifies the user each time, immediately, of the recipient, the date and time, and the purpose of provision, on the device from which the personal location information was collected, in accordance with Article 19 (3) of the Location Information Act. With separate consent, the user may choose to receive notifications in batches, within a maximum of 30 days, by number (10, 20, or 30 times) or by period (10, 20, or 30 days), and may return to immediate notification at any time.

Article 6 (Rights and Obligations of Guardians of Children Aged 8 or Under, etc., and How to Exercise Them)

① Where the guardian of a child aged 8 or under, a person under adult guardianship, or a person with a severe mental disability under the Act on Welfare of Persons with Disabilities (limited to registered persons with disabilities) consents to the collection, use, or provision of that person's personal location information to protect that person's life or body, the person is deemed to have consented.

② The guardian submits to the contact in Article 8 a signed written consent form stating the name, address, and date of birth of the child aged 8 or under, etc., the name, address, and contact details of the guardian, and that the purpose is limited to protecting life or body, together with a document proving guardianship.

③ The guardian may exercise the rights in Article 7 regarding the personal location information of the child aged 8 or under, etc., and must use that personal location information only to protect the life or body of the child, etc., giving priority to the child's interests.

④ The Company does not collect the personal location information of children under 14, and should it intend to do so in future, obtains and confirms the consent of the legal representative under Article 25 of the Location Information Act.

Article 7 (Rights of Subjects of Personal Location Information and How to Exercise Them)

RightHow to exerciseHandling
Withdraw all or part of consentApp My Page → Location settings → "Withdraw location consent"Immediately. The personal location information and confirmation records for the withdrawn part are destroyed without delay
Temporarily suspend collection, use, and provision"Pause" on the recording screen, or My Page → Location settings → "Pause recording"Immediately
Access to or notification of confirmation records, and of the reason for and content of provision to third partiesMy Page → Location settings → "View confirmation records"Immediately (app screen)
Correction of confirmation recordsMy Page → Location settings → "Contact" or the contact in Article 8Within 10 days
Deletion of the route for each tripTrip detail screen → "Delete route" or delete the tripImmediately; backups within 7 days

Turning off the location permission in the device operating system technically prevents location collection but is separate from the withdrawal of consent above; to have already-collected personal location information destroyed, please use withdrawal of consent or deletion.

Article 8 (Location Information Manager)

ItemDetails
NameByungwook Yoo (유병욱) (Chief Executive Officer)
Telephone+82 10-2136-1530
Emaileveryticket@gorocket.me
DutiesEstablishing and implementing the personal location information protection policy, handling the exercise of users' rights and grievances, inspecting protective measures, managing confirmation records

Article 9 (Protective Measures for Location Information)

In accordance with Article 16 (1) of the Location Information Act and the Standards for Managerial and Technical Protective Measures for Location Information, the Company establishes guidelines for handling and managing location information, minimises persons with access (currently 1) and applies two-factor authentication, keeps access-right records for 5 years, encrypts data in transit and at rest, blocks access by anyone other than the user through database security rules, keeps access logs for the location information system for 1 year, and automatically records and retains confirmation records (see Part 1, Article 10).

Appendix 1. Details of Generative AI Processing

ItemDetails
Model and providerGoogle LLC's Gemini model, Gemini API (Developer API) paid tier
Features① AI autofill (extracting information from ticket photos) ② AI drafts (survey-based trip plan drafts)
Information sent① The ticket photo image selected by the user ② Survey content (destination, origin, dates, companions, budget range, preferences, notes). Account information such as name and email, and the user identifier, are not sent
Transmission pathApp → the Company's server function (Cloud Functions, Seoul) → Gemini API. On the AI path the Company's server does not store the photo and discards it after the response
Google's retentionGoogle keeps inputs and outputs for at most 55 days to monitor for violations of its usage policies (abuse), then deletes them. On the paid tier, inputs and outputs are not used for Google's model training or product improvement
Limit on extracted fieldsOnly nine fields are extracted: whether it is a ticket, type, title, place, date, end date, origin, destination, and seat. The model is instructed not to extract booking numbers, barcodes, or personal identification numbers, and the server filters them out again
User confirmationExtraction results are saved only after the user checks and edits them. AI drafts are for reference and carry an "AI generated" label
ChoiceYou can enter information manually without using AI features. This information is shown on an app screen when an AI feature is first run
Human reviewCompany staff do not individually view AI inputs or outputs
Applicable lawsArticle 31 of the Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust (disclosure and labelling of generative AI), Articles 26 and 28-8 of the Personal Information Protection Act

Appendix 2. Revision History

VersionEffectiveMain changes
v12026-09-10First posted
v22026-09-16Comprehensive revision: table of basis and retention period by item, separation of third-party provision (companions), itemised outsourcing and cross-border transfers (Firebase authentication in the US, Airbridge in Japan, Gemini 55-day retention), cloud storage of Cut videos and ambient sound stated, destruction procedure (7-day backups), how to refuse SDKs, safety measures, other people's information in photos, generative AI appendix, new Part 2 personal location information processing policy, officers named

Previous edition: View the 2026-09-10 Privacy Policy

← Home

プライバシーポリシー

施行日 2026-09-16 · 最終改定 2026-09-01

Mapboxの保有期間(30日)はMapboxの公開資料に基づくものであり、確認中です。本ポリシーは第1部(個人情報)と第2部(個人位置情報)で構成され、第2部は「位置情報の保護および利用等に関する法律」第21条の2に基づく個人位置情報処理方針です。ウェブサイトのアドレス:everyticket.kr/privacy(第2部への直接リンク:everyticket.kr/privacy#location)。本ポリシーは韓国語原文の翻訳であり、内容に相違がある場合は韓国語版が優先します。

株式会社ゴロケットカンパニー(Gorocket Company Co., Ltd.、以下「当社」)は、Every Ticket(以下「本サービス」)利用者の個人情報を「個人情報保護法」、「位置情報の保護および利用等に関する法律」(以下「位置情報法」)など関連法令に従って取り扱い、本ポリシーにより、どのような情報をどのような根拠でどれだけの期間取り扱うのか、利用者がどのような権利をどのように行使できるのかをお知らせします。

概要

第1部 プライバシーポリシー

第1条(取り扱う個人情報の項目、目的、根拠、保有期間)

当社は、次の個人情報を取り扱います。表に記載した根拠は「個人情報保護法」第15条第1項の各号であり、登録時に利用者にこの内容をお知らせし、個人情報の収集・利用への同意を別個の項目として取得します。

区分項目収集時点処理目的根拠保有期間
アカウント電子メールアドレス(Appleログインの場合、Appleが発行したリレーアドレスの場合あり)、氏名(ニックネーム)、プロフィール写真、ソーシャルログイン提供者(Google・Apple・カカオ・ネイバー)が発行した会員識別値ログイン・登録時会員の識別とログイン、複数端末間のデータ同期、通知契約の締結・履行(第4号)退会時まで
個人位置情報緯度・経度・収集時刻・精度(移動動線)、カット撮影・チケット登録時点の位置利用者が「記録開始」を押してから旅行を終えるまで動線表示、到着確認、成果物の生成、本人アカウントでの保管・復元位置情報法第19条第1項の同意当該旅行の削除・退会・同意撤回時まで(第2部参照)
プラン目的地・場所・日程・メモ・経費・チェックリスト、共同プランの同行者リスト(ニックネーム・色)プラン作成時旅行プランの作成と共同編集契約の締結・履行(第4号)プランの削除・退会時まで
AIドラフトのアンケート目的地、出発地、日付、同行者、予算の範囲、好み、入れたいもの・避けたいものに関するメモAIドラフト機能の使用時アンケートに基づく旅行プランのドラフト生成契約の締結・履行(第4号)生成されたドラフトとともにプランに保存、プランの削除・退会時まで
写真・動画・音声チケット・記念品の写真、1秒動画(カット)およびカットとともに録音される現場音利用者が直接撮影・選択した時チケット登録、記録、成果物(カード・フィルム)の生成、端末変更時の復元契約の締結・履行(第4号)当該コンテンツの削除・退会時まで
チケット情報種類・タイトル・場所・日付・出発地・到着地・座席など、利用者が入力し、またはAIが抽出して利用者が確認した値チケット登録時チケットの登録・分類、成果物の生成契約の締結・履行(第4号)チケットの削除・退会時まで
決済ストア(Apple App Store・Google Play)の領収書識別値、購入商品・時刻、ストアの国、サブスクリプションの状態有料決済時決済の確認、トリップパス・サブスクリプションの管理、返金・申込み撤回の処理契約の締結・履行(第4号)、法令上の義務(第2号)退会時まで。ただし「電子商取引等における消費者保護に関する法律」に基づき、契約・申込み撤回の記録および代金決済・財貨供給の記録は5年、消費者の苦情・紛争処理の記録は3年保存
端末・通知プッシュ通知トークン、端末モデル・OSバージョン・アプリバージョン・言語・タイムゾーン、アプリのインストール参照値アプリのインストール・通知許可時サービス通知の送信(記録・招待・決済・ポリシー変更)、端末ごとの復元契約の締結・履行(第4号)退会またはアプリ削除時まで
広告性通知(上記プッシュトークンの利用)利用者が別途同意した場合新機能・イベント・割引の案内同意(第1号)同意撤回時まで、2年ごとに再確認
広告識別子Android広告ID(GAID)、iOSベンダー識別子(IDFV)、IPアドレスアプリのインストール・起動時アプリのインストール経路とマーケティング成果の測定、招待リンクの接続(ディファードディープリンク)正当な利益(第6号)· 利用者はアプリ設定で拒否可能退会時または受託者との契約終了時まで
利用記録アプリの利用イベント(画面・機能の利用、時刻)、端末情報、当社が付与した利用者識別値アプリ利用中サービス改善のための利用統計分析正当な利益(第6号)· アプリ設定で拒否可能収集日から1年
エラー診断エラー(クラッシュ)ログ、端末情報、アプリの状態エラー発生時エラーの診断と安定性の改善正当な利益(第6号)収集日から90日
お問い合わせ電子メールアドレス、問い合わせ内容、添付資料問い合わせ時問い合わせ・苦情の処理、権利行使の請求の処理契約の締結・履行(第4号)、法令上の義務(第2号)処理完了後3年
アクセス記録位置情報システム・管理コンソールのアクセス記録システム運用中安全性の確保、侵害事故への対応法令上の義務(第2号)1年

② 当社は、iOSのアプリトラッキング透明性(ATT)の権限を要求せず、広告識別子(IDFA)を収集しません。Android広告IDは端末の設定でリセットまたは削除できます。

③ 当社は、機微情報(思想・信条、健康など)および固有識別情報(住民登録番号など)を収集しません。

④ 当社は、登録時に利用者が満14歳以上であることを確認し、満14歳未満の児童の個人情報は収集しません。満14歳未満の利用が確認された場合は、アカウントおよび関連情報を遅滞なく破棄します。

第2条(個人情報の収集方法)

  1. 利用者がアプリおよびウェブサイトで直接入力・撮影・選択する方法
  2. ソーシャルログイン時に利用者の同意を経て、Google・Apple・カカオ・ネイバーが当社に伝達する方法(カカオ・ネイバーの場合、提供者が発行したトークンを当社サーバーが検証し、会員識別値・ニックネーム・プロフィール写真・電子メール(同意時)を受け取ります)
  3. 記録中の旅行に限り、端末の位置情報機能で自動収集する方法
  4. アプリに含まれるソフトウェア開発キット(SDK)が自動的に生成・収集する方法(第9条)
  5. ストアが決済結果を当社に伝達する方法

第3条(個人情報の利用目的外の取り扱い)

当社は、第1条の目的の範囲内でのみ個人情報を利用し、目的が変わる場合は「個人情報保護法」第18条に基づき別途同意を取得するか、法令が許容する範囲内でのみ取り扱います。利用者が残した評価・一言レビューを他の利用者に表示する機能を導入する場合は、個人を識別できない匿名・集計の形態でのみ提供し、本ポリシーを改定してお知らせします。

第4条(個人情報の第三者提供)

① 当社は、利用者の個人情報を原則として第三者に提供せず、次の場合にのみ提供します。

提供先提供項目提供目的根拠提供先の保有期間
共同プランの同行者利用者がプランに入力・登録した場所・日程・経費・チェックリスト・チケット情報、ニックネーム・色プランの共同編集利用者が招待リンクを作成して同行者を招待する行為(法第17条第1項第1号)同行者のプラン削除・退会時まで

利用者の移動動線・カット・写真・感想は、いかなる場合も同行者に提供されません。場所の検索語と地図画面の範囲は当社サーバーを経由してGoogle Maps Platformに送られますが、アカウント情報・IPアドレス・端末情報は一緒に送らないため、個人情報の第三者提供には当たりません。透明性のため第6条の表に記載します。

② 法令に特別の規定がある場合、または捜査機関が法令の定める手続きと方法に従って要求する場合には、その範囲で提供することがあり、当社は要求の適法性を確認した上で最小限に提供し、その内訳を記録します。

第5条(個人情報の取り扱いの委託)

① 当社は、本サービスの提供のため、次のとおり個人情報の取り扱いを委託します。

受託者委託業務委託項目
Google LLC(Firebase)会員認証(Authentication)、データベース(Firestore)、ファイル保存(Cloud Storage)、サーバー機能(Cloud Functions)、プッシュ通知(FCM)、エラー診断(Crashlytics)アカウント、プラン、チケット、写真・カット、動線、端末・通知、エラー診断
Google LLC(Gemini API、有料プラン)チケット写真からの情報抽出、アンケートに基づく旅行ドラフトの生成チケット写真の画像、AIドラフトのアンケート
Mapbox, Inc.地図表示地図画面領域の座標、IPアドレス、端末情報(テレメトリはオフ)
OpenWeather Ltd.旅行日の天気の照会プラン上の場所の座標・日付
PostHog, Inc.利用統計・プロダクト分析利用記録、端末情報、利用者識別値
AB180 Inc.(Airbridge)アプリのインストール経路・マーケティング成果の測定、招待リンクの接続広告識別子(GAID・IDFV)、インストール参照値、端末情報、IPアドレス、登録・決済などのコンバージョンイベント
RevenueCat, Inc.アプリ内課金の領収書検証、サブスクリプション・購入履歴の管理決済、利用者識別値

② 当社は、委託契約において「個人情報保護法」第26条に基づき、委託業務の目的外の取り扱いの禁止、技術的・管理的保護措置、再委託の制限、受託者に対する管理・監督、損害賠償などを定め、受託者が個人情報を安全に取り扱っているかを監督します。

③ 受託者が当社の業務を再委託する場合は当社の同意を取得し、再受託者とその業務は本ポリシーで公開します。現在の受託者は、自社のクラウドインフラ(Google Cloud、Amazon Web Services)を利用して業務を遂行しています。

④ 委託業務の内容または受託者が変わった場合は、遅滞なく本ポリシーを改定してお知らせします。

⑤ Apple App StoreおよびGoogle Playは当社の受託者ではなく、利用者と直接決済契約を結ぶ独立した事業者であり、決済手段の情報はストアのみが保有し、当社には伝達されません。カカオ・ネイバー・Google・Appleのログインサービスも、各社のプライバシーポリシーに従います。

第6条(個人情報の国外移転)

① 当社は、「個人情報保護法」第28条の8第1項第3号イ(情報主体との契約の締結・履行のための処理委託・保管であって、次の事項をプライバシーポリシーに公開した場合)に基づき、次のとおり個人情報を国外で処理委託・保管します。PostHog・Airbridgeは本サービスの運営・改善および招待リンク機能に必要な処理委託として同号に従いますが、利用者はいつでも拒否することができます。

移転先(連絡先)移転国移転項目移転時期・方法利用目的保有・利用期間
Google LLC · Firebase Authentication(1600 Amphitheatre Pkwy, Mountain View, CA, USA · policies.google.com/privacy · support.google.com/policies/contact/general_privacy_form)米国(認証サービスは米国でのみ処理)電子メール、氏名、プロフィール写真、ソーシャルログイン識別値、ログイントークンログイン時に暗号化されたネットワーク(TLS)で送信会員認証・アカウント管理退会時まで
Google LLC · Firestore・Cloud Storage・Cloud Functions大韓民国(ソウルリージョン)に保存。ただし、Googleのグローバルな運用・技術サポートの過程で、米国など国外から参照されることがあるアカウント、プラン、チケット、写真・カット(現場音を含む)、動線サービス利用時にTLS送信、ソウルリージョンに保存データの保存・処理・バックアップ削除・退会時まで、バックアップは最大7日
Google LLC · FCM・Crashlytics米国などGoogleのデータセンター(リージョン指定なし)プッシュトークン、端末情報、エラーログ通知送信・エラー発生時にTLS送信プッシュ通知の送信、エラー診断プッシュトークン:退会・アプリ削除時まで / エラーログ:90日
Google LLC · Gemini API(有料プラン)米国などGoogleのデータセンター(リージョン指定なし)チケット写真の画像、AIドラフトのアンケート内容利用者がAI機能を実行するたびに、当社サーバー(ソウル)を経由してTLS送信チケット情報の抽出、旅行ドラフトの生成不正利用の監視目的で最大55日保管した後に削除。モデルの学習・製品改善には使用しない
Google LLC · Google Maps Platform(Places・Routes)米国などGoogleのデータセンター利用者が入力した場所の検索語・目的地、地図画面のおおよその座標(当社サーバーを経由して送信し、アカウント情報・IPアドレス・端末情報は送らない場所検索・AIドラフトの実行時に当社サーバー(ソウル)を経由してTLS送信場所検索、場所の検証、経路案内Googleのサーバーログ保有基準(収集後9〜18か月以内に匿名化)に従う。当社は座標の結果を30日以内に限りキャッシュ
PostHog, Inc.(2261 Market St #4008, San Francisco, CA, USA · privacy@posthog.com)米国(AWS us-east-1)利用記録、端末情報、利用者識別値(IPアドレスは収集後直ちに廃棄)アプリ利用時にTLS送信利用統計・プロダクト分析1年
AB180 Inc. Airbridge(ソウル特別市江南区テヘラン路419、19・20階 · 個人情報保護責任者 リュ・ウォンギョン · compliance@ab180.co · airbridge.io/ko/gdpr)日本(AWS東京リージョン)広告識別子(GAID・IDFV)、インストール参照値、端末情報、IPアドレス、コンバージョンイベントアプリのインストール・起動・登録・決済時にTLS送信インストール経路・マーケティング成果の測定、招待リンクの接続退会時または当社との契約終了時まで。Airbridge自身の保有上限は最大1年
RevenueCat, Inc.(San Francisco, CA, USA · revenuecat.com/privacy · support@revenuecat.com)米国ストアの領収書識別値、購入・サブスクリプション履歴、利用者識別値決済時にTLS送信領収書の検証、サブスクリプション・購入履歴の管理退会または当社の削除要請時まで
Mapbox, Inc.(San Francisco, CA, USA · mapbox.com/legal/privacy · privacy@mapbox.com)米国地図画面領域の座標、IPアドレス、端末情報地図表示時にTLS送信地図タイルの提供IPアドレスはサービス提供・課金・セキュリティの目的で保管した後、30日後に削除(Mapboxの製品プライバシーポリシー基準)。その他のリクエストログは目的達成時まで
OpenWeather Ltd.(London, UK · openweather.co.uk/privacy-policy)英国プラン上の場所の座標・日付天気照会時にTLS送信天気情報の提供(リクエスト値は保管しない)照会後直ちに

国外移転を拒否する方法と効果

③ 当社は、国外移転にあたり「個人情報保護法」第28条の8第4項および施行令に基づく保護措置(委託契約の締結、暗号化送信、受託者の監督)を講じます。

第7条(個人情報の破棄手続きと方法)

① 当社は、保有期間が経過し、または処理目的が達成された場合、遅滞なく個人情報を破棄します。

② 手続き:利用者がアプリでコンテンツを削除し、またはアカウントを削除すると、当社サーバーの運用データ(Firestore・Cloud Storageのアカウント・プラン・チケット・写真・カット・動線・プッシュトークン、Firebase認証情報)および端末のローカルデータが直ちに削除され、カカオ・ネイバーなどソーシャルログインの連携が解除されます。1日1回作成されるサーバーのバックアップは、最大7日以内に自動的に破棄されます。 受託者(PostHog・Airbridge・RevenueCat)に保存された利用者識別値は、アカウント削除時に削除を要請します。

③ 方法:電子ファイルは復元できない方法で削除し、出力物がある場合は裁断します。

④ 法令に基づき保存する情報(第1条の決済・問い合わせ記録)は、他の個人情報と分離して保存し、保存目的外には利用せず、期間が経過すれば破棄します。

⑤ 1年以上本サービスを利用していない利用者の個人情報も、破棄せず維持します。旅行記録の長期保管が本サービスの目的であるためであり、利用者はいつでも自ら削除することができます。

第8条(情報主体と法定代理人の権利および行使方法)

① 利用者は、当社に対していつでも次の権利を行使することができます。

  1. 個人情報の閲覧請求
  2. 誤りがある場合の訂正・削除請求
  3. 処理停止の請求
  4. 同意の撤回(広告性通知、コンテンツのマーケティング利用、国外移転の同意など)
  5. 完全に自動化された決定に対する拒否・説明の請求(「個人情報保護法」第37条の2)。現在、本サービスには利用者の権利・義務に重大な影響を及ぼす自動化された決定はありません。

② 行使方法:アプリ → マイページ → アカウント(情報の修正・アカウント削除)/ アプリ → 設定(通知・分析データ・AI機能)/ 個人位置情報はマイページ → 位置情報の管理(第2部)/ その他の請求は第13条の連絡先への電子メール。当社は、請求を受けた日から10日以内に処理し、結果をお知らせします。

③ 利用者の法定代理人または委任を受けた者は、委任状を提出して権利を代わりに行使することができます。

④ 閲覧・訂正・削除・処理停止の請求が法令上制限される場合(他の法令に保存義務がある場合など)、当社はその理由をお知らせします。

⑤ 権利行使により不利益を与えることはありません。ただし、本サービスの提供に必要な情報の削除・処理停止を請求した場合、当該機能を利用できなくなることがあります。

第9条(個人情報自動収集装置の設置・運用と拒否)

① 当社のアプリには次のSDKが含まれており、各SDKが自動的に収集する情報と拒否方法は次のとおりです。

SDK収集情報目的拒否方法
Firebase(Google)認証トークン、プッシュトークン、端末情報、エラーログ認証・保存・通知・診断通知:端末設定で通知の権限をオフ / エラーログ:iOS 設定 → プライバシーとセキュリティ → 解析と改善 → 「Appデベロッパと共有」をオフ、Android 設定 → Google → 「使用状況と診断」をオフ
PostHogアプリ利用イベント、端末情報、利用者識別値利用統計アプリのマイページの「利用統計・分析データを送信」スイッチをオフ
Airbridge広告識別子(GAID・IDFV)、インストール参照値、端末情報、コンバージョンイベントインストール経路・成果の測定アプリのマイページの「利用統計・分析データを送信」スイッチをオフ。Android 設定 → Google → 広告 → 広告IDのリセット・削除
Mapbox地図リクエスト時の画面領域の座標、IP、端末情報地図表示テレメトリ(利用者の位置のMapboxへの送信)は当社がオフにしています。地図表示自体を拒否するには、アプリを使用しない方法しかありません
RevenueCat領収書識別値、利用者識別値決済の検証有料決済をしなければ送信されません

② セッションリプレイ(画面録画)は使用しません。PostHogに送信されるIPアドレスは、収集後直ちに廃棄されるよう設定しています。

③ ウェブサイト(everyticket.kr)およびウェブのプランニングツールは、ログイン維持など本サービスの提供に必要なブラウザストレージのみを使用し、広告・トラッキング目的のCookieは使用しません。利用者はブラウザ設定でCookieを拒否することができ、この場合ログインが維持されないことがあります。

第10条(個人情報の安全性確保措置)

当社は、「個人情報保護法」第29条および「個人情報の安全性確保措置基準」、位置情報法第16条および「位置情報の管理的・技術的保護措置基準」に従い、次の措置を講じます。

  1. 管理的措置:個人情報保護責任者・位置情報管理責任者の指定、個人情報・位置情報の取扱指針の策定・運用、取扱職員の教育、受託者の監督
  2. アクセス制御:管理コンソールのアクセス権限者を最小化(現在1名)し2段階認証を適用、サービスアカウントキーの未発行、アクセス権限の付与・変更・抹消記録の5年間保存、データベースのセキュリティルールによる利用者本人のアカウント以外からのアクセス遮断
  3. アクセス記録:データベース・ストレージ・管理コンソールのアクセス記録を1年以上保存し、定期的に点検
  4. 暗号化:通信区間のTLS暗号化、保存データの暗号化(Google Cloudの保存時暗号化)、端末ストレージの保護
  5. バックアップ・復旧:データベースの1日1回のバックアップ(ソウルリージョン、7日間保管)
  6. 侵害事故への対応:漏えい等が発生した場合、72時間以内に利用者に通知し、法令の定める場合は個人情報保護委員会または韓国インターネット振興院に届け出る手続きを運用(第15条)

第11条(写真・動画・音声に含まれる他人の情報)

① 利用者が登録するチケット写真およびカットには、同行者の氏名・予約番号・顔・音声など他人の情報が含まれることがあります。当社は、こうした情報を利用者が登録したコンテンツの一部として、本サービスの提供(保存・表示・成果物の生成)の範囲内でのみ取り扱い、別途抽出・保存したり、マーケティングに利用したりしません。

② AI自動入力は、チケットか否か・種類・タイトル・場所・日付・終了日・出発地・到着地・座席の9項目のみを抽出するよう設計されており、予約番号・バーコード・個人識別番号は抽出しないよう指示し、サーバーでもう一度フィルタリングします。

③ 利用者は、写真を登録する前に他人の情報を隠すことが望ましく、他人の情報を外部に共有する際にはその人の同意を得なければなりません。

④ 自身の情報が他の利用者のコンテンツに含まれていると判断する方は、第13条の連絡先に削除を請求することができ、「個人情報保護法」第20条に基づき、収集元および処理目的の告知を請求することができます。

第12条(生成型AIの利用)

本サービスのAIドラフトおよびチケット情報の抽出機能は、Google LLCの生成型人工知能モデル(Gemini)を使用します。取り扱われる情報、送信経路、保管、利用者の選択権は付録1に詳しく記載しています。当社は、AI機能を初めて実行する際にこの事実をアプリ画面でもう一度お知らせし、AIが作成した成果物には「AI生成」の表示を付します。

第13条(個人情報保護責任者と閲覧請求窓口)

区分内容
個人情報保護責任者ユ・ビョンウク(유병욱)(代表取締役)
電話+82 10-2136-1530
電子メールeveryticket@gorocket.me
閲覧・訂正・削除・処理停止の請求受付上記と同じ(担当:個人情報保護責任者)

当社は小規模事業者として、代表取締役が個人情報保護責任者を兼ねます。利用者は、本サービスの利用中に生じた個人情報に関する問い合わせ・苦情・被害救済を上記の連絡先に請求することができ、当社は遅滞なく回答・処理します。

第14条(権益侵害の救済方法)

利用者は、個人情報の侵害に対する被害救済・相談を次の機関に問い合わせることができます。

「個人情報保護法」第35条・第36条・第37条に基づく閲覧・訂正・削除・処理停止の請求に対する当社の処分に不服がある場合、「行政審判法」に基づき行政審判を請求することができます(中央行政審判委員会 110、simpan.go.kr)。

第15条(個人情報漏えい時の通知)

当社は、個人情報の紛失・盗難・漏えい・偽造・変造・毀損(漏えい等)を知った場合、「個人情報保護法」第34条に基づき、72時間以内に漏えいした項目・時点・経緯、利用者が取れる措置、当社の対応、連絡先を利用者に通知し、法令の定める場合は個人情報保護委員会または韓国インターネット振興院に届け出ます。

第16条(ポリシーの変更と告知)

① 本ポリシーを改定するときは、適用日の7日前からアプリのお知らせおよびウェブサイトに改定内容と理由を掲示します。法令上同意が必要な事項は、改めて同意を取得します。

② 本ポリシーと利用規約の内容が異なる場合は、利用者に有利なものを適用します。

③ 旧版はウェブサイトの改定履歴で確認できます。

第2部 個人位置情報処理方針

本部は、位置情報法第21条の2および同法施行令第25条の2に基づく個人位置情報処理方針です。当社は韓国放送メディア通信委員会に届け出た位置情報基盤サービス事業者(第12279号、2026年9月8日)であり、個人位置情報の収集・利用条件は「Every Ticket 位置情報サービス利用規約」に従います。

第1条(個人位置情報の処理目的と保有期間)

① 処理目的

目的内容
旅行動線の表示利用者が「記録開始」を押した旅行に限り、端末の位置(緯度・経度・時刻・精度)を60〜200m間隔で収集して地図に動線を表示し、移動手段を区別
プラン上の場所への到着確認プランした場所の近くにとどまると到着と判断し、チケットとして残すかを尋ねる
カット・チケットの位置表示カット撮影・チケット登録時点の位置を動線上に表示
ロック画面・通知での案内記録中、次の目的地までの距離・移動手段を表示
成果物の生成・保管・復元旅行カード・フィルムの生成(端末内)、利用者本人のアカウントでの保管、端末変更時の復元

保有目的と保有期間:当社は、利用者が記録した動線を本人が保管・閲覧・再生し、成果物を作成できるようにする目的で個人位置情報を保有し、保有期間は利用者が当該旅行を削除し、退会し、または同意を撤回するまでです。その時点で保有目的が達成されたものとみなし、遅滞なく破棄します。

③ 記録中でないときは位置を収集せず、広告・マーケティング・販売の目的で個人位置情報を利用しません。

④ 保存場所:当社が借り受けたGoogle Cloud Firebaseソウルリージョン(asia-northeast3)の利用者本人のアカウント領域。利用者本人のアカウントからのみ閲覧でき、他の利用者には表示されず、当社のアクセスは第9条の保護措置に従って制限されます。

第2条(位置情報の収集・利用・提供事実確認資料の保有根拠と保有期間)

① 当社は、位置情報法第16条第2項に基づき、個人位置情報の収集・利用・提供の事実を確認できる資料(確認資料)を位置情報システムに自動的に記録・保存します。確認資料に座標は含まれません。

② 項目:旅行ごとの収集開始・終了時刻、収集方法(端末の位置情報機能)、同意バージョン・同意時刻、利用日時・目的・対象の旅行、第三者提供の事実(該当時)、利用者の権利行使の内訳。

保有根拠:位置情報法第16条第2項。保有期間:記録日から6か月。 期間を経過すると自動的に破棄し、利用者が同意を撤回し、または退会した場合は、その利用者の確認資料を期間にかかわらず遅滞なく破棄します。

第3条(個人位置情報の破棄手続きと方法)

① 破棄時点:利用者が当該旅行または動線を削除した時、退会した時(同意の撤回を含み、確認資料もあわせて破棄)、同意を撤回した時(確認資料を含む)、満14歳未満の利用が確認された時。

② 破棄方法:クラウドストレージの運用データを直ちに削除し、1日1回作成されるバックアップは最大7日以内に自動破棄します。利用者の端末の複製は、アプリの削除またはログアウト時に削除されます。利用者がすでに外部に書き出した成果物は破棄の対象ではありません。

③ 確認資料は、第2条の保有期間を経過すると自動的に破棄します。

第4条(個人位置情報の第三者提供)

当社は、個人位置情報を第三者に提供しません。 共同プランの同行者に見えるのは、利用者がプランに直接入力・登録した場所・日程・チケット情報であり、利用者の移動動線とカットの位置は、同行者を含む誰にも提供されません。

② 当社は、個人位置情報をGoogle Cloud Firebase(ソウルリージョン)に保存するためにGoogle LLCに、記録中に地図を表示するために地図画面領域の座標をMapbox, Inc.(米国)に処理委託します(第1部第5条・第6条)。これは第三者提供ではなく処理委託であり、Mapboxのテレメトリ(利用者の位置の別途送信)はオフにしています。

③ 当社が将来、利用者が指定する第三者に個人位置情報を提供するサービスを開始しようとする場合、提供先と提供目的をお知らせして別途同意を取得し、本ポリシーを改定して公開します。

第5条(第三者提供時の通報に関する事項)

当社が第4条第3項に従って利用者が指定する第三者に個人位置情報を提供する場合、位置情報法第19条第3項に基づき、その都度、提供先・提供日時・提供目的を、個人位置情報を収集した端末に直ちに通報します。利用者は別途の同意により、最大30日の範囲で回数(10回・20回・30回)または期間(10日・20日・30日)の単位でまとめて通報を受ける方法を選択することができ、いつでも即時通報に戻すことができます。

第6条(8歳以下の児童等の保護義務者の権利・義務と行使方法)

① 8歳以下の児童、被成年後見人、「障害者福祉法」上の精神的障害を有する重度障害者(障害者登録をした者に限る)の保護義務者が、その者の生命または身体の保護のために個人位置情報の収集・利用・提供に同意する場合は、本人の同意があるものとみなします。

② 保護義務者は、8歳以下の児童等の氏名・住所・生年月日、保護義務者の氏名・住所・連絡先、目的が生命・身体の保護に限られる旨を記載して署名した書面の同意書に、保護義務者であることを証明する書面を添付して、第8条の連絡先に提出します。

③ 保護義務者は、8歳以下の児童等の個人位置情報に関して第7条の権利を行使することができ、その個人位置情報を児童等の生命・身体の保護の目的でのみ利用し、児童等の利益を優先しなければなりません。

④ 当社は、満14歳未満の児童の個人位置情報を収集せず、将来収集しようとする場合は、位置情報法第25条に基づき法定代理人の同意を取得して確認します。

第7条(個人位置情報主体の権利と行使方法)

権利行使方法処理
同意の全部または一部の撤回アプリのマイページ → 位置情報の管理 → 「位置情報同意の撤回」即時。撤回した部分の個人位置情報および確認資料を遅滞なく破棄
収集・利用・提供の一時停止記録画面の「一時停止」またはマイページ → 位置情報の管理 → 「記録の一時停止」即時
確認資料の閲覧・告知、第三者提供の理由・内容の閲覧・告知マイページ → 位置情報の管理 → 「確認資料の閲覧」即時(アプリ画面)
確認資料の訂正マイページ → 位置情報の管理 → 「お問い合わせ」または第8条の連絡先10日以内
旅行ごとの動線の削除旅行詳細画面 → 「動線の削除」または旅行の削除即時、バックアップは7日以内

端末OSの位置情報権限をオフにすることは、位置の収集を技術的に防ぎますが、上記の同意の撤回とは別のものであり、すでに収集された個人位置情報の破棄を希望する場合は、同意の撤回または削除をご利用ください。

第8条(位置情報管理責任者)

区分内容
氏名ユ・ビョンウク(유병욱)(代表取締役)
電話+82 10-2136-1530
電子メールeveryticket@gorocket.me
担当業務個人位置情報保護方針の策定・実施、利用者の権利行使と苦情の処理、保護措置の点検、確認資料の管理

第9条(位置情報の保護措置)

当社は、位置情報法第16条第1項および「位置情報の管理的・技術的保護措置基準」に従い、位置情報の取扱い・管理指針の策定、アクセス権限者の最小化(現在1名)と2段階認証、アクセス権限記録の5年間保存、送信・保存の暗号化、データベースのセキュリティルールによる本人以外のアクセス遮断、位置情報システムのアクセス記録の1年間保存、確認資料の自動記録・保存の措置を講じます(第1部第10条参照)。

付録1. 生成型AIの処理の詳細

区分内容
使用モデル・事業者Google LLCのGeminiモデル、Gemini API(Developer API)有料プラン
適用機能① AI自動入力(チケット写真からの情報抽出) ② AIドラフト(アンケートに基づく旅行プランのドラフト)
送信される情報① 利用者が選択したチケット写真の画像 ② アンケート内容(目的地・出発地・日付・同行者・予算の範囲・好み・メモ)。氏名・電子メールなどのアカウント情報および利用者識別値は送信しない
送信経路アプリ → 当社サーバー機能(Cloud Functions、ソウル)→ Gemini API。AI経路において当社サーバーは写真を保存せず、応答後に廃棄
Googleの保管Googleは、利用ポリシー違反(不正利用)の監視目的で入力・出力を最大55日保管した後に削除します。有料プランでは、入力・出力はGoogleのモデル学習・製品改善に使用されません
抽出項目の制限チケットか否か、種類、タイトル、場所、日付、終了日、出発地、到着地、座席の9項目のみを抽出。予約番号・バーコード・個人識別番号は抽出しないよう指示し、サーバーで再度フィルタリング
利用者の確認抽出結果は利用者が確認・修正した後にのみ保存。AIドラフトは参考用であり、「AI生成」の表示を付す
選択権AI機能を使わずに直接入力可能。AI機能の初回実行時にこの内容をアプリ画面で案内
人による確認当社の職員はAIの入力・出力を個別に閲覧しない
関連法令「人工知能の発展と信頼基盤の造成等に関する基本法」第31条(生成型AIの告知・表示)、「個人情報保護法」第26条・第28条の8

付録2. 改定履歴

バージョン施行日主な変更
v12026-09-10初回掲示
v22026-09-16全面改定:項目別の根拠・保有期間の表、第三者提供(同行者)の分離、委託・国外移転の項目別記載(Firebase認証は米国、Airbridgeは日本、Geminiは55日保管)、カット動画のクラウド保存・現場音の明示、破棄手続き(バックアップ7日)、SDKの拒否方法、安全性確保措置、写真に含まれる他人の情報、生成型AIの付録、第2部個人位置情報処理方針の新設、責任者の実名表記

旧版:2026-09-10 プライバシーポリシーを見る

← ホームへ