Privacy Policy · Tier 3 — Service Apps
Contents
This policy applies to ORIOTI apps that provide a regulated or identity-restricted service and therefore need to verify who you are. We collect more data here than in our other apps, strictly because the service cannot legally or functionally operate without it (for example, confirming you meet a minimum age, or that you are the account holder for support/refund purposes). We apply data minimization: we only collect what a given app actually needs, and a specific app's in-app disclosure will tell you exactly which of the categories below applies to it.
| Category | Examples | Source |
|---|---|---|
| Account identifiers | Email address, phone number, social login ID | Provided by you |
| Identity data | Full name, gender, date of birth / age | Provided by you, or via an identity-verification provider |
| Contact & address | Phone number, mailing address (where relevant to the service, e.g. shipping or billing) | Provided by you |
| Verification records | Confirmation that identity verification succeeded (we design our verification flow to avoid retaining raw government ID images/numbers ourselves wherever a third-party verification provider can retain them instead) | Identity-verification provider |
| Payment data | Billing name, masked card/payment info, transaction history (raw card numbers are handled by our payment processor, not stored by ORIOTI) | Payment processor |
| App activity & device data | In-app activity, device model, OS version, push token, crash/diagnostic logs, IP address | Automatically collected |
Where a specific app requires identity verification, we use it strictly to confirm the minimum facts necessary (e.g. that you are above a required age, or that your name matches your payment method) and rely on licensed identity-verification providers rather than storing raw government-issued ID documents or national ID numbers ourselves wherever possible. In Korea specifically, we do not collect your resident registration number (주민등록번호) unless a specific law explicitly requires it for that transaction, and we will obtain your separate, explicit consent before doing so, as required under the Personal Information Protection Act.
We do not collect other special categories of data (health, biometric, religious, or political data) unless a specific app feature requires it and you are separately informed and asked for explicit consent at that time.
We process your data under: contract (to provide the service you signed up for), legal obligation (identity verification and record-keeping required by law), legitimate interest (fraud prevention, security, product improvement), and consent (marketing, and any sensitive data processing). You may withdraw consent at any time without affecting past lawful processing.
| Category | Purpose | Examples |
|---|---|---|
| Cloud infrastructure | Hosting, database, authentication | Google Cloud / Firebase |
| Identity verification | Confirming age/identity without ORIOTI retaining raw ID documents | Licensed KYC/identity-verification vendor engaged for that app |
| Payment processing | Handling payments and billing | PCI-DSS compliant payment processor |
| Analytics & crash reporting | Product improvement, stability | Google Firebase Analytics/Crashlytics |
| Legal & regulatory | Compliance with law enforcement, court orders, tax authorities | As required by applicable law |
We do not sell your personal data. We do not share identity or payment data with advertisers. Any additional sharing not listed here will be separately disclosed and, where required, subject to your consent.
Because these apps involve identity verification and, in many cases, payments or regulated services, they are intended for users who meet the applicable minimum age for that service (which may be higher than 13/14 depending on the app and local law — check the specific app's terms). We do not knowingly collect data from users below the required minimum age. If we discover an account was created by an underage user, we will suspend the account and delete or anonymize the associated data, subject to any legal retention obligation.
We retain personal data only as long as necessary for the purposes above, generally: for the life of your account plus a limited period after closure to handle disputes, and longer where required by law — for example, transaction and billing records are typically retained for 5 years under Korean e-commerce/tax record-keeping requirements. Identity verification confirmations are retained only for as long as needed to demonstrate compliance; underlying ID documents, where handled by a third-party verification vendor, are retained per that vendor's own regulatory retention schedule, not indefinitely by ORIOTI.
We apply encryption in transit and at rest where supported by our infrastructure provider, role-based access controls, and minimize direct storage of sensitive identity/payment data by delegating it to specialized, regulated processors. In the event of a data breach affecting your personal data, we will notify affected users and the relevant regulator (e.g. Korea's Personal Information Protection Commission, or an EU/UK supervisory authority) as required by applicable law and without undue delay.
You have the right to access, rectify, erase, or restrict processing of your data, to data portability, to object to processing based on legitimate interest, to withdraw consent, and to lodge a complaint with your local supervisory authority. Some rights (e.g. erasure) may be limited where we have a legal obligation to retain data (e.g. transaction records).
California residents have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of "sale" or "sharing" of personal information. We do not sell personal data for money and do not share identity/payment data for cross-context behavioral advertising. To exercise these rights, contact support@orioti.com.
You have the right to request access, correction, deletion, or suspension of processing of your personal information, and to withdraw consent, by contacting our Privacy Officer (Section 13). Where identity verification involves unique identifying information, we obtain separate consent as required under Article 24 of the PIPA. You may report concerns to the Personal Information Protection Commission (privacy.go.kr, ☎ 118).
Users in other jurisdictions (e.g. Canada's PIPEDA, Brazil's LGPD, Australia's Privacy Act, Singapore's PDPA) have broadly comparable rights to access, correct, delete their data, and to lodge a complaint with the relevant local authority. Contact us and we will respond consistent with applicable local law.
ORIOTI is based in the Republic of Korea. Where our infrastructure, identity-verification, or payment providers process data outside your home country (including in the United States), we require appropriate safeguards such as Standard Contractual Clauses for EEA/UK-originating data, and take reasonable steps to ensure an equivalent level of protection.
We may update this policy periodically. Material changes will be reflected by updating the "Last updated" date above, and, where required by law or where the change affects how we use previously collected sensitive data, we will provide advance notice and, where required, seek your renewed consent.
ORIOTI
Business Registration No. 424-46-01289
Representative & Privacy Officer: Yunju Jeong
Email: support@orioti.com