Privacy

개인정보 처리방침

버전 2026-09-15 · 시행일 2026-09-15

1. 처리하는 정보

카드 수집 계정과 체육관 회원 서비스에서 전화번호(휴대전화 번호), 표시 이름, 계정·세션 식별값, 필수 동의 기록, 소속 체육관 및 회원 기록을 처리합니다. 카드 수집 과정에서는 카드 소유 기록, QR의 안전한 확인값, 카드 종류 판정값을 처리합니다.

실물 상품 주문 시 주문자·수령인 이름과 휴대전화 번호, 우편번호, 배송지, 배송 메모, 주문 상품·수량·금액, 결제·취소·배송 상태와 송장 정보를 처리합니다. 결제 화면은 토스페이먼츠가 제공합니다. 카드번호·계좌번호 등 원본 결제수단 정보는 LEVEL CHANGE가 직접 입력받거나 보관하지 않습니다.

카드 앞면 인식 이미지는 판정에만 일시적으로 사용하고 판정 직후 즉시 삭제합니다. 원본 인식 이미지를 카드 도감이나 계정 기록으로 보관하지 않습니다.

체육관 공지 알림을 허용하면 기기의 푸시 알림 식별값(Expo Push Token)과 운영체제 종류를 로그인 세션에 연결하여 처리합니다. 알림 허용은 선택 사항입니다.

Android 앱의 Firebase Cloud Messaging은 앱 실행 시 설치 식별값과 메시지 전달용 토큰을 자동 생성하여 Google에 전달할 수 있습니다. 이 생성과 전달은 알림 허용 여부와 별개입니다. 이 정보는 알림 전달 서비스의 동작에 사용합니다.

2. 처리 목적과 인증 메시지

처리하는 정보는 계정 생성·로그인, 체육관 회원 연결, 카드 소유 확인, 부정 이용 방지, 문의 대응에 사용합니다. 휴대전화 번호로 인증번호를 보내기 위해 NAVER Cloud SENS(SENS)를 사용합니다. 카메라는 카드 QR 스캔과 카드 앞면 촬영에 사용합니다. 신규 출시 버전에는 카드 AR 기능을 포함하지 않습니다.

주문 정보는 결제 확인, 본사 상품 출고, 배송 조회, 취소·환불과 고객 문의 처리에 사용합니다. 결제 승인·취소는 토스페이먼츠가 처리합니다. 배송에 필요한 수령인과 배송지 정보는 실제 배송을 맡는 택배사에 전달될 수 있습니다.

현재 선택한 체육관의 새 공지를 알리기 위해 Expo Push Service를 사용합니다. 기기 운영체제에 따라 Android에서는 Firebase Cloud Messaging을, iOS에서는 Apple Push Notification service를 사용합니다. 알림 전달 과정에서 푸시 식별값, 체육관 이름, 공지 제목과 공지·체육관 식별값을 해당 서비스로 전송합니다. 휴대전화 설정에서 앱 알림을 끌 수 있습니다.

이전에 배포된 Android 테스트 버전의 AR 기능은 Google Play Services for AR(ARCore)을 사용하며, Google 이용약관 및 Google 개인정보처리방침의 적용을 받습니다. 해당 이전 버전에서는 Google 계정 사용자 ID 또는 기기 ID, 성능·진단 정보, ARCore API 사용과 앱 활동이 처리될 수 있습니다. AR을 제거한 새 버전에는 ARCore를 포함하지 않습니다.

체육관 영상은 YouTube 내장 플레이어로 제공합니다. 등록된 영상의 플레이어를 불러오면 앱 식별값과 네트워크 요청이 Google로 전달됩니다. 영상 서비스에는 Google 개인정보처리방침이 적용됩니다. LEVEL CHANGE 로그인 토큰이나 회원 전화번호를 플레이어에 전달하지 않습니다. 모바일 앱은 YouTube 개인정보 보호 강화 모드를 사용합니다. 영상 서비스 제공 과정에서 Google 등 제3자가 쿠키 또는 유사한 기술과 재생 정보를 처리할 수 있습니다. 영상에 광고가 표시될 수 있습니다.

배송지 검색은 Kakao 우편번호 서비스를 사용합니다. 검색어는 주소 검색을 위해 해당 서비스에 전달됩니다. 선택한 주소와 우편번호는 주문 배송지에 입력됩니다. 검색만으로 주문이 생성되지는 않습니다.

초기 모바일 릴리스에는 Branch 네이티브 SDK와 설치 후 자동 인계를 포함하지 않습니다. 앱이 설치되지 않은 상태에서 카드 QR을 연 경우에는 먼저 회원 앱을 설치하거나 실행합니다. 그다음 실물 카드의 QR 코드를 다시 스캔하여 수집을 진행합니다.

인증 요청의 과도한 반복과 부정 이용을 막기 위해 요청 횟수 제한 기록을 남깁니다. 이 기록에는 접속 IP 자체가 아니라 서버 비밀값으로 만든 IP 기반 식별값을 사용합니다. 이 식별값은 계정에 연결하지 않습니다.

3. 보유·삭제

인증번호는 평문으로 저장하지 않으며 5분 후 만료됩니다. 로그인 세션은 기본 30일 후 만료됩니다. 계정과 동의 기록은 계정 삭제 전까지 보유합니다. 계정 삭제는 /account/delete에서 본인 인증 후 요청할 수 있습니다.

푸시 알림 등록은 연결된 로그인 세션을 삭제할 때 함께 삭제합니다. 서버에서 로그아웃이나 계정 삭제가 완료되면 해당 등록도 삭제합니다. 만료된 세션에는 공지를 발송하지 않습니다.

계약·청약철회와 대금결제·재화 공급 기록은 전자상거래 관련 법령에 따라 5년 보관합니다. 소비자 불만·분쟁 처리 기록은 같은 법령에 따라 3년 보관합니다. 계정을 삭제해도 이 주문 기록은 계정 연결을 해제한 상태로 법정 기간 동안 보관한 뒤 파기합니다.

요청 횟수 제한 기록은 고정 시간 구간별로 관리합니다. 새 구간의 첫 요청 때 24시간보다 오래된 기록을 정리합니다. 따라서 정확히 24시간에 즉시 삭제되는 방식은 아닙니다.

삭제 시 계정, 세션, 미완료 카드 인계와 인증 기록은 삭제합니다. 이때 연결된 체육관 회원과 주문 기록의 계정 연결은 해제합니다. 이미 소유 처리된 카드는 QR 재사용을 막기 위해 CLAIMED 상태를 유지합니다. 다만 계정 식별자와는 분리하여 익명 처리합니다. 법령 또는 체육관 계약에 따라 별도 보존해야 하는 회원·주문 기록은 그 범위에 따릅니다.

4. 이용자 권리와 연령

이용자는 열람, 정정, 삭제와 처리 정지를 요청할 수 있습니다. 카드 수집 서비스는 만 14세 이상을 대상으로 합니다. 만 14세 미만인 경우 법정대리인을 통해 아래 연락처로 문의해 주세요.

문의 및 삭제 관련 연락: 대표 고민호 | 전화 010-5110-8180 | 이메일 minhotaurs@level-change.net

5. 보호 조치와 변경

전송 구간 HTTPS, 인증번호와 로그인 토큰의 평문 미저장, 접근 제어와 요청 횟수 제한을 적용합니다. 본 방침이 바뀌면 이 페이지에 새 버전과 시행일을 게시합니다.

English summary

We process collector account and phone verification data, collection and card-ownership records, linked gym-member records, session identifiers, required consent records, and physical-goods order, recipient, delivery, payment-status, and purchase-history data. Toss Payments collects raw payment credentials on its hosted checkout; LEVEL CHANGE does not receive or retain card or bank account numbers. Branch native SDK and automatic post-install handoff are not included in this initial release. If the app is not installed, open or install the member app and rescan the original card QR. SENS processes SMS verification. The camera is used for card QR scanning and front-image recognition. Card AR is excluded from the new release.

Earlier Android test builds included Google Play Services for AR (ARCore), governed by Google Terms and Privacy Policy. Those builds may process Google Account or device identifiers, diagnostics, and ARCore usage. The new release excludes ARCore.

Optional gym notice notifications link an Expo Push Token and platform to the login session. Expo Push Service and FCM (Android) or APNs (iOS) receive the push identifier, gym name, notice title, and notice and gym identifiers to deliver the alert. Notifications can be disabled in device settings. Registration is deleted with its session after successful server logout or account deletion; expired sessions are excluded from notice delivery.

On Android, Firebase Cloud Messaging may automatically generate and send installation identifiers and messaging tokens to Google when the app starts, independently of notification permission, to operate the messaging service.

Gym videos use the YouTube embedded player. Loading a registered video player sends the app identifier and player network requests to Google under its Privacy Policy; the app does not forward the LEVEL CHANGE login token or member phone number to the player. The mobile app uses YouTube Privacy Enhanced Mode. Google or other third parties may process cookies or similar technologies and playback information to provide the video service, and videos may include advertisements. Shipping address search uses Kakao Postcode and sends the search query to that service. The selected address and postal code fill the checkout form; searching does not create an order.

Recognition images are used only for the immediate card decision and disposed of immediately. We do not retain raw recognition images or raw media URLs in the collection. Claimed physical-card records stay anonymously CLAIMED after deletion to prevent QR reuse.

You can delete an authenticated app account in the app settings or use the public web deletion path at /account/delete. The service is for ages 14 and over; contact representative 고민호, phone 010-5110-8180, email minhotaurs@level-change.net. This summary is version 2026-09-15.

이용약관도 함께 확인해 주세요.