Privacy Policy
joayo (operated by Joayo Inc., the "Service") values your privacy. This policy explains what we collect, why we collect it, how we use and share it, and the rights you have as a user in Korea and internationally.
1. What we collect
When you create a joayo account, we collect identifiers you provide directly — typically your phone number, email address, display name, and profile photo (optional). If you sign in through a third-party provider such as Apple, Google, Naver, or Kakao, we receive the basic identifiers that provider releases to us.
When you use the app, we process device and usage signals: device model, operating system version, IP address, approximate location (and, with your explicit permission, precise location), app event logs, push notification tokens, and diagnostic data.
When you claim offers or redeem rewards, we record the claim time, the merchant, the offer, the location of redemption, and any loyalty progress tied to that merchant. We do not store payment card numbers — all payments are processed by our PCI-DSS-compliant payment partner.
2. How we use your information
We use your information to (a) operate the Service, including authenticating you, showing offers near you, and honoring claims at the merchant; (b) personalize the feed with categories and neighborhoods you interact with; (c) send transactional messages such as claim confirmations, reminders, and expiry alerts; (d) prevent fraud, abuse, and violations of our Terms; and (e) comply with Korean laws including 전자상거래법 (Act on Consumer Protection in Electronic Commerce) and 개인정보보호법 (Personal Information Protection Act, "PIPA").
We use aggregated, de-identified analytics to improve product quality — for example, which neighborhoods have unmet demand, or which offer windows perform best. Aggregated data cannot be used to re-identify any individual user.
3. When we share information
We share your claim with the merchant you chose, so the merchant can fulfill it. The merchant sees your display name and the claim code, not your phone number or address.
We use service providers under written data processing agreements: cloud hosting (AWS Seoul region), payments (Toss Payments), customer support tooling, email and SMS delivery, push notifications, and analytics. These providers act on our instructions and may not use your data for their own purposes.
We may disclose information to law enforcement or regulators if required by Korean law, including the 통신비밀보호법 (Protection of Communications Secrets Act), and will push back against requests that exceed legal authority.
We do not sell personal information to advertisers or data brokers.
4. Your rights (access, delete, export)
Under PIPA Article 35 and related provisions, you have the right to access your personal information, to correct inaccuracies, to request deletion, to restrict processing, and to withdraw consent at any time. You may exercise these rights in-app under Settings → Privacy, or by writing to privacy@joayo.app.
You may request a machine-readable export of your account data. We will respond within ten (10) days of a verified request, as required by PIPA. If your request affects pending claims or loyalty progress, we will explain the trade-offs before proceeding.
5. Security
We protect personal information in transit with TLS 1.2+ and at rest with AES-256 encryption where technically feasible. Access to production data is restricted to a small number of authorized engineers, logged, and reviewed quarterly.
No system is perfectly secure. If we become aware of a data incident affecting your account, we will notify you and the Korea Internet & Security Agency (KISA) in accordance with PIPA Article 34 and the Standard Personal Information Protection Guidelines.
6. Cookies and similar technologies
Our website and app use cookies, local storage, and device identifiers to keep you signed in, remember preferences, measure feature usage, and prevent fraud. For detail, see our Cookie Policy.
7. Children
joayo is not directed to children under the age of fourteen (14). We do not knowingly collect personal information from children. If you believe a child has created an account, please contact privacy@joayo.app and we will delete the account and associated data.
8. International transfers
Your data is primarily stored in the AWS Seoul region. Some service providers may process limited data outside Korea — for example, error monitoring or email delivery. When we transfer personal information abroad, we do so under PIPA Article 28-8, with equivalent safeguards, and we publish the categories of recipients and countries involved on this page.
9. Retention
We retain account information for as long as your account is active. After account deletion, we retain claim and transaction records for five (5) years as required by Korean commercial and tax law, then delete or anonymize them.
10. Changes to this policy
We may update this policy to reflect product, legal, or operational changes. Material changes will be notified at least seven (7) days in advance by in-app banner and email. The date at the top of this page reflects the latest effective version.
11. Contact
Joayo Inc., Data Protection Officer, Seongsu-dong, Seongdong-gu, Seoul. Email: privacy@joayo.app. If you are not satisfied with our response, you may file a complaint with the Personal Information Protection Commission (개인정보보호위원회) or KISA's Privacy Call Center (118).
For privacy questions, contact our Data Protection Officer at privacy@joayo.app.