ORIOTI

Privacy Policy · Tier 3 — Service Apps

Privacy Policy

Effective date: July 9, 2026 · Last updated: July 9, 2026

Applies to: ORIOTI service apps that verify your identity to provide the service — for example, apps that need to confirm your name, gender, or age to comply with law, prevent fraud, or enable age-restricted or account-holder-restricted features. This is the highest data-sensitivity tier of our apps; if an app only needs an email/login, see the Account Apps Privacy Policy instead.

Contents

  1. Overview
  2. Data We Collect
  3. Identity Verification & Sensitive Data
  4. How We Use Your Data
  5. Legal Basis for Processing
  6. Sharing with Third Parties
  7. Children's Privacy & Age Restrictions
  8. Data Retention
  9. Security & Breach Notification
  10. Your Rights (by Region)
  11. International Data Transfers
  12. Changes to This Policy
  13. Contact Us / Privacy Officer

1. Overview

This policy applies to ORIOTI apps that provide a regulated or identity-restricted service and therefore need to verify who you are. We collect more data here than in our other apps, strictly because the service cannot legally or functionally operate without it (for example, confirming you meet a minimum age, or that you are the account holder for support/refund purposes). We apply data minimization: we only collect what a given app actually needs, and a specific app's in-app disclosure will tell you exactly which of the categories below applies to it.

2. Data We Collect

CategoryExamplesSource
Account identifiersEmail address, phone number, social login IDProvided by you
Identity dataFull name, gender, date of birth / ageProvided by you, or via an identity-verification provider
Contact & addressPhone number, mailing address (where relevant to the service, e.g. shipping or billing)Provided by you
Verification recordsConfirmation that identity verification succeeded (we design our verification flow to avoid retaining raw government ID images/numbers ourselves wherever a third-party verification provider can retain them instead)Identity-verification provider
Payment dataBilling name, masked card/payment info, transaction history (raw card numbers are handled by our payment processor, not stored by ORIOTI)Payment processor
App activity & device dataIn-app activity, device model, OS version, push token, crash/diagnostic logs, IP addressAutomatically collected

3. Identity Verification & Sensitive Data

Where a specific app requires identity verification, we use it strictly to confirm the minimum facts necessary (e.g. that you are above a required age, or that your name matches your payment method) and rely on licensed identity-verification providers rather than storing raw government-issued ID documents or national ID numbers ourselves wherever possible. In Korea specifically, we do not collect your resident registration number (주민등록번호) unless a specific law explicitly requires it for that transaction, and we will obtain your separate, explicit consent before doing so, as required under the Personal Information Protection Act.

We do not collect other special categories of data (health, biometric, religious, or political data) unless a specific app feature requires it and you are separately informed and asked for explicit consent at that time.

4. How We Use Your Data

  • Verify your identity/eligibility to use the service (e.g. age gating, account-holder confirmation)
  • Create, secure, and authenticate your account
  • Process transactions, billing, and refunds
  • Comply with legal, tax, and record-keeping obligations
  • Provide customer support
  • Detect and prevent fraud, abuse, and security incidents
  • Send service and, with your consent, marketing communications
  • Improve the service through aggregate analytics

5. Legal Basis for Processing (GDPR)

We process your data under: contract (to provide the service you signed up for), legal obligation (identity verification and record-keeping required by law), legitimate interest (fraud prevention, security, product improvement), and consent (marketing, and any sensitive data processing). You may withdraw consent at any time without affecting past lawful processing.

6. Sharing with Third Parties

CategoryPurposeExamples
Cloud infrastructureHosting, database, authenticationGoogle Cloud / Firebase
Identity verificationConfirming age/identity without ORIOTI retaining raw ID documentsLicensed KYC/identity-verification vendor engaged for that app
Payment processingHandling payments and billingPCI-DSS compliant payment processor
Analytics & crash reportingProduct improvement, stabilityGoogle Firebase Analytics/Crashlytics
Legal & regulatoryCompliance with law enforcement, court orders, tax authoritiesAs required by applicable law

We do not sell your personal data. We do not share identity or payment data with advertisers. Any additional sharing not listed here will be separately disclosed and, where required, subject to your consent.

7. Children's Privacy & Age Restrictions

Because these apps involve identity verification and, in many cases, payments or regulated services, they are intended for users who meet the applicable minimum age for that service (which may be higher than 13/14 depending on the app and local law — check the specific app's terms). We do not knowingly collect data from users below the required minimum age. If we discover an account was created by an underage user, we will suspend the account and delete or anonymize the associated data, subject to any legal retention obligation.

8. Data Retention

We retain personal data only as long as necessary for the purposes above, generally: for the life of your account plus a limited period after closure to handle disputes, and longer where required by law — for example, transaction and billing records are typically retained for 5 years under Korean e-commerce/tax record-keeping requirements. Identity verification confirmations are retained only for as long as needed to demonstrate compliance; underlying ID documents, where handled by a third-party verification vendor, are retained per that vendor's own regulatory retention schedule, not indefinitely by ORIOTI.

9. Security & Breach Notification

We apply encryption in transit and at rest where supported by our infrastructure provider, role-based access controls, and minimize direct storage of sensitive identity/payment data by delegating it to specialized, regulated processors. In the event of a data breach affecting your personal data, we will notify affected users and the relevant regulator (e.g. Korea's Personal Information Protection Commission, or an EU/UK supervisory authority) as required by applicable law and without undue delay.

10. Your Rights (by Region)

European Economic Area / UK (GDPR / UK GDPR)

You have the right to access, rectify, erase, or restrict processing of your data, to data portability, to object to processing based on legitimate interest, to withdraw consent, and to lodge a complaint with your local supervisory authority. Some rights (e.g. erasure) may be limited where we have a legal obligation to retain data (e.g. transaction records).

California (CCPA / CPRA)

California residents have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of "sale" or "sharing" of personal information. We do not sell personal data for money and do not share identity/payment data for cross-context behavioral advertising. To exercise these rights, contact support@orioti.com.

Republic of Korea (PIPA)

You have the right to request access, correction, deletion, or suspension of processing of your personal information, and to withdraw consent, by contacting our Privacy Officer (Section 13). Where identity verification involves unique identifying information, we obtain separate consent as required under Article 24 of the PIPA. You may report concerns to the Personal Information Protection Commission (privacy.go.kr, ☎ 118).

Other Regions

Users in other jurisdictions (e.g. Canada's PIPEDA, Brazil's LGPD, Australia's Privacy Act, Singapore's PDPA) have broadly comparable rights to access, correct, delete their data, and to lodge a complaint with the relevant local authority. Contact us and we will respond consistent with applicable local law.

11. International Data Transfers

ORIOTI is based in the Republic of Korea. Where our infrastructure, identity-verification, or payment providers process data outside your home country (including in the United States), we require appropriate safeguards such as Standard Contractual Clauses for EEA/UK-originating data, and take reasonable steps to ensure an equivalent level of protection.

12. Changes to This Policy

We may update this policy periodically. Material changes will be reflected by updating the "Last updated" date above, and, where required by law or where the change affects how we use previously collected sensitive data, we will provide advance notice and, where required, seek your renewed consent.

13. Contact Us / Privacy Officer

ORIOTI
Business Registration No. 424-46-01289
Representative & Privacy Officer: Yunju Jeong
Email: support@orioti.com

· Mini Games Privacy Policy · Account Apps Privacy Policy · Service Apps Privacy Policy

© 2026 ORIOTI. All rights reserved.