← Back to K-Heritage Trail

Privacy Policy

offLAB (store display name offLAB, hereinafter the "Operator") establishes and discloses this privacy policy for K-Heritage Trail (hereinafter the "App") in accordance with the Personal Information Protection Act and applicable store policies, in order to protect users' personal information.

Core features can be used without signing up and without any data being sent to a server; an optional email login (magic link) is offered only when you want to sync and restore your visit records across devices. Apart from the login email, we don't collect other account information such as your name or phone number, and you can use every core feature without logging in.

The App is an unofficial travel planner for the Korea Heritage Visit campaign and does not represent, and has not been approved or affiliated by, any government body.

Effective date: July 10, 2026 · Last revised: July 10, 2026

Article 1 (Items Processed, Purpose, Legal Basis, and Retention Period)

Optional login and account sync (optional)

  • Items: Email address, session token (only its SHA-256 hash is stored on the server), login challenge (email and token hash)
  • Purpose: Syncing and restoring visit records across devices, account identification, and sending the magic-link email
  • Legal basis: Separate consent given in the app (login = consent to server sync)
  • Retention: Immediately on account deletion; 30 days after a login challenge expires; 30 days after a session expires or is revoked

Anonymous usage statistics (optional)

  • Items: Random app UUID, device secret (used for HTTPS authentication; only its hash is stored on the server), app launches, screen/course/stop views, visit/stamp marks, app language
  • Purpose: Usage analysis, feature improvement, and service security
  • Legal basis: Separate consent given in the app
  • Retention: Up to 365 days after the event is created

Server sync of visit records (optional)

  • Items: Random app UUID, device secret (used for HTTPS authentication; only its hash is stored on the server), visit/stamp status, visit timestamp, memos written by the user
  • Purpose: Server backup/sync requested by the user and confirmation of record ownership
  • Legal basis: Separate consent given in the app
  • Retention: Up to 730 days after the last device activity, or until the user requests deletion

Information error reports (direct submission)

  • Items: Random app UUID, device secret (used for HTTPS authentication; only its hash is stored on the server), place, category, freeform report content
  • Purpose: Review and correction of errors in place/operational information
  • Legal basis: Submission consent given by the user immediately before submitting
  • Retention: Unprocessed reports are kept until review is complete; up to 1,095 days after processing is complete, or up to 730 days if the inactive-device threshold is reached first

Network information for service protection

  • Items: API request IP, request time, request volume information. Ordinary app request IPs are not stored in the database or in persistent application logs
  • Purpose: Rate limiting, attack/error detection, and ensuring service stability
  • Legal basis: Legitimate interest in protecting personal information and providing a secure service
  • Retention: Discarded when the rate-limit window ends. Admin security audit logs follow a separate operational policy

Apart from the email used for optional login, the App does not request or collect your name, phone number, address, advertising ID, resident registration/passport number, contact details, photos, payment/health information, or precise current location or movement history. The login email is used only for account identification and sending the magic link, and never for advertising or profiling. The random app UUID is not linked to your real name, but because it groups server records by installation, it is protected as if it were personal information.

Article 2 (Timing of Collection and Consent)

  • Optional login (magic link) is off by default. The login screen first notifies you that logging in means consenting to server sync, and processing begins only after you enter your email to request a login link; you then finish signing in by pasting the code from the emailed link into the app. The login email is used only for account identification and sending the link.
  • Anonymous statistics and visit-record sync are each off by default. Data is transmitted only after the app first displays the items sent, purpose, retention, and deletion method, and you tap [Agree and turn on].
  • Information error reports are transmitted only after the app notifies you of the items sent and purpose immediately before submission, and you tap [Submit]. You are advised not to enter another person's personal information, such as a name, contact detail, or passport number.
  • You can use course exploration, maps, recommended routes, and local stamp records without giving consent.
  • Users under the age of 14 must not turn on optional server transmission features or submit reports without the consent of a legal guardian.

Article 3 (Third-Party Provision and External SDKs)

The Operator does not sell or provide user data to advertising networks or data brokers, and does not use it for personalized advertising or cross-app/cross-site tracking.

Opening the map screen causes the Kakao Maps SDK to communicate with Kakao's servers to provide map tiles and app authentication, which may process your IP address and device/connection/service usage information. The App does not request precise location permission, and the Operator does not combine this information with advertising profiles.

The Operator reviews the contracts, policies, and security measures of its processors and SDK providers, and manages them to apply protections equal to or greater than what this policy and applicable law require. If a third-party provision beyond these purposes becomes necessary, the Operator will confirm the legal basis and obtain separate consent where required.

Article 4 (Outsourced Processing and Cross-Border Transfer)

The Operator's personal deployment may use Railway Corp. for API/database hosting, Vercel Inc. for the public website, Kakao Corp. for map functionality, and Resend, Inc. for sending optional-login emails. The actual operating entity, region, and sub-processors are fixed by the deployment contract and configuration, and before any optional server feature of the App is made public, the cross-border transfer details below are fixed to actual values and posted in this policy and the consent screen.

  • Railway Corp.: Random UUID, usage statistics, visit records/memos, reports, and credential hashes are transferred over HTTPS for API/DB hosting purposes when the relevant feature is used. The selected region is fixed among the US, Netherlands, or Singapore through operational configuration, and US-based operational access may occur. Retention periods follow those in Article 1.
  • Resend, Inc.: For optional login, the recipient's email address is processed in the US to send the magic-link email. The actual operating entity, region, sub-processors, and retention period are fixed to the cross-border transfer details above and posted before any optional server feature is made public.
  • Vercel Inc.: Web access information such as IP address, User-Agent, and request time may be processed at the point of access on US and global edge servers for static web delivery, security, and incident response. Logs accessible to the Operator are limited to a minimum period and follow the contract/plan's deletion settings.
  • Kakao Corp.: Provides map SDK, map tiles, and app authentication within the Republic of Korea.

Users who do not want their data transferred abroad may choose not to turn on anonymous statistics or server sync and not to submit reports, and can continue to use the core local features. If the operating environment changes to institutional infrastructure, or the country, operator, sub-processor, or retention period changes, this article will be updated and any necessary notice or consent obtained before the change takes effect.

Article 5 (Retention and Destruction)

  • When the retention period ends or the purpose is achieved, database rows are deleted in a manner that makes recovery difficult.
  • Where retention is required for legal, dispute, or security response purposes, the relevant data is stored separately with its basis and period, and destroyed once the purpose ends.
  • Deleting the app removes the encrypted data in the app's sandbox. Even if a key remains in OS-level secure storage per platform policy, records cannot be restored without the data file and are not transmitted to the server.

Article 6 (Rights of Users and Legal Guardians)

Users, or their lawful legal guardians, may request access to, correction or deletion of, suspension of processing of, and withdrawal of consent for personal information, as well as complaint handling.

  • Turning off statistics/sync: Further transmission stops immediately.
  • Server data deletion: Using your device credentials, statistics, visit records, reports, and device information are deleted, and a new UUID/secret is issued. Local records are preserved. Logged-in users can, via in-app account deletion, immediately delete their email, sessions, authentication information, and the visit records/events linked to the account in a single action; reports are linked to the anonymous device rather than the account and are deleted when the device is deleted.
  • Web account deletion: kheritage.offlab.kr/account/delete lets you verify with a code sent to your account email and delete the same account data — no app install required.
  • Resetting your anonymous ID alone does not immediately delete existing server records, so we recommend requesting server data deletion first.
  • Email request: contact@offlab.krYou can also make a request by email. To protect other users' data, we may request identity verification to the extent necessary, such as device credentials, and will process the request within the period required by law.

Article 7 (Security Measures)

  • HTTPS is enforced for all app-server communication, and plaintext communication is blocked on Android.
  • Local SQLite data is encrypted with AES, with keys stored separately in the Android Keystore/iOS Keychain.
  • The device secret's plaintext value is kept only on the device; only its SHA-256 hash is stored on the server.
  • Individual admin accounts, role separation, account lockout, session limits, and integrity audit logs are applied.
  • Input validation, rate limiting, data minimization, automatic retention/destruction, and regular security reviews are applied.

Article 8 (Cookies, Behavioral Information, and Automated Decisions)

The Operator does not use personalized advertising, advertising IDs, third-party advertising cookies, or session replay tools in the App or public website. The Operator does not make automated decisions that produce legal or similarly significant effects on users, and does not profile or re-identify individuals using anonymous statistics. If such features are added, this policy and store disclosures will be updated before they take effect.

Article 9 (Children's Personal Information)

The App is not a children-focused service and does not collect age information. Users under the age of 14 may use local features under a legal guardian's guidance, and optional server transmission must not be used without a legal guardian's consent. Legal guardians may request access to, deletion of, or suspension of processing of a child's data through the department listed below.

Article 10 (Responsible Department and Remedies for Rights Infringement)

  • Department responsible for privacy protection and complaint handling: offLAB Operations Team
  • Email: contact@offlab.kr

You may report privacy infringements to the Privacy Infringement Report Center (118, no area code needed), request dispute mediation from the Personal Information Dispute Mediation Committee (1833-6972), or consult the National Police Agency (182, no area code needed) for investigation-related inquiries.

Article 11 (Policy Changes)

Changes and their effective date are disclosed on this page. Matters requiring separate consent — such as adding a significant new collection purpose, third-party provision, cross-border transfer, or expanding the scope of consent — will not take effect before consent is obtained. Prior versions of this policy and the change history are available upon request.

Addendum

  • This policy takes effect on July 10, 2026.
  • July 10, 2026: Updated the legal basis, children's provisions, cross-border transfer, security measures, and rights/remedy procedures to align with the latest store and domestic requirements.