1. Data collected
Account: social login (Google/Apple) identifier, email, name (email and password for email sign-up). Contact: owner name, mobile phone number. Verification: business registration certificate image (for venue verification). Document vault: image/PDF files of contracts and certificates you upload to run your venue (business registration, business report, health certificates, employment/service/lease/rights contracts, etc.) and the fields auto-recognized (AI) from them (business name, registration number, representative, expiry date, employee name, etc.). These may include personal and sensitive data of third parties such as employees (e.g., health-related information on a health certificate), uploaded by you (the owner) as the controlling party. Employee information: login identifier, name, and email of employees invited to and joining your venue. Attendance records: employees' clock-in/out times, break time, and notes (recorded by you as the controlling party to help confirm and settle working time). Reservation: guest name, contact, party size, requests, and expected visit time passed along during reservation handling, plus a summary of the guest's reservation history at that venue (visit / no-show / cancellation counts). Usage: notification tokens, access/usage logs, device information.
2. Purpose
Verifying your venue, managing venue information, receiving/responding to and helping fulfill reservation requests, sending (push) notifications, handling inquiries, preventing abuse, and improving the service. We also use it to store, view, and share (time-limited links) document-vault files, to send reminders before their expiry, and to record and aggregate employees' working time (attendance).
3. Retention & deletion
(i) Personal data is destroyed without delay once its purpose is achieved, and account data is destroyed without delay upon account closure. (ii) Verification documents such as the business registration certificate are stored encrypted in a private store with restricted access and destroyed once verification/dispute-handling purposes end. (iii) Records that must be kept under applicable law are retained only for the statutory period and then destroyed (e.g., access logs for 3 months under the Protection of Communications Secrets Act). (iv) Contracts and certificates uploaded to the document vault are stored encrypted in a private store and destroyed without delay when you delete them in the app. However, because these belong to the venue (business) and are shared with approved co-managers, they may remain with other managers for venue-management purposes even after a particular user closes their account. Account/data deletion follows the 'Yumi Partners Account & Data Deletion' guide.
4. Processing delegation & overseas transfer
To operate the Service, the Company delegates personal data processing as follows, and some processors are located overseas, with appropriate safeguards. Authentication/database: Supabase, Inc. (USA). App/API infrastructure: Vercel Inc. (USA). Push notifications: Expo (Expo Application Services), Apple Push Notification service (Apple Inc.), Firebase Cloud Messaging (Google). Document auto-recognition (AI parsing): OpenAI, L.L.C. (USA) - processes the images/PDFs you upload to the document vault to read fields such as expiry dates and names for display; this data is used only for recognition and not for separate model training. Transferred items are limited to what each task requires and are transferred over the network.
5. Third-party provision
We do not provide personal data to third parties except as required by law or with your consent.
6. Security measures
The Company applies encrypted transport (HTTPS), least-privilege access and access controls, encrypted storage of verification documents, and regular audits. In particular, document-vault files are kept in a private store and are viewed/shared only via short-lived signed URLs.
7. Your rights
You may at any time request access, correction, deletion, or suspension of processing of your personal data; account/data deletion can be requested in-app or via the contact below.
8. Children's data
The Service targets business owners and does not collect personal data from children under 14.
9. Privacy officer
Privacy Officer Yuhyun. Contact: ixplorer@hidemeplease.xyz
Governed by Korea's PIPA. Material changes are announced within the Service before they take effect.