MoneyMap (hereinafter referred to as “We”, “Us”, or “Our”) establishes and presents the privacy policy as follows, in order to protect the personal information of data subjects who use “MoneyMap” (both the application and any associated versions, collectively, “Application”), and resolve any relevant complaint.
We collect and use personal information for the following purposes:
Membership registration and management: confirmation of membership intent, identification/authentication, maintenance and management of membership, prevention of illegal use of services, sending various notices, etc.
Provision of goods or services: provision of service, delivery of contract/invoice, provision of basic service and customized service, verification of identity, age verification, bill payment and settlement, debt collection, etc.
Managing consumer complaints: identification of the data subject, confirmation of complaints, contact/notification for fact-finding, and notification of processing results.
Marketing and Advertising: provision of customized advertisements, opportunities to participate in events, statistics on the use of services by data subjects, etc.
Improvement of existing services and development of new and customized services.
Processing of pseudonymized information for statistical preparation, scientific research, and preservation of records in the public interest.
We collect and process the following personal information of users of the Application:
Information collected through membership registration (obligatory): email, password, nickname.
Information obtained from third-party companies through each membership registration method:
Registration through Google ID: Email, name, profile image, locale (geography and language).
Registration through Apple ID: Email.
Information collected when using paid services:
When paying by credit card: payment information such as the name of the card company and card number.
In case of bank transfer: payment information such as the name of the account holder, account number, and bank holding the account.
When paying by mobile phone number: payment information such as phone number and telecommunication company.
Information automatically collected through user’s input, user’s receiving of text messages or Application notices, or user’s reconnection to the Application:
Note: The received SMS is used for automatic entry of household account details. If you sign up as a member, it may be sent to the server for synchronization.
Android: Received SMS content, phone number, received time, SMS type (rcs, mms, sms), app package name, app name.
iOS: Received SMS content.
Information automatically created and collected when using the service: cookies, service use records (visit records, bad use records), device information (mobile phone model name, OS name, and version information), advertisement identifiers, etc.
For managing consumer complaints: necessary information collected and processed from the user among the items above.
We retain and use the user's personal information while the user uses services as a member. When either the user requests withdrawal from membership or the purpose of collection and use of personal information is achieved, we will immediately destroy the relevant personal information. However, if we terminate the service use contract according to the Terms of Use, the relevant personal information will be preserved for one year to prevent unauthorized re-registration and use of service, and the information is deleted immediately after the end of the relevant period.
Notwithstanding the foregoing, the following information is retained for the period specified for the following reasons:
Personal information related to use of service (log records): 3 months (under relevant Communications Privacy Acts).
Records on withdrawal of contract or subscription, etc., and records on payment and supply of goods: 5 years (under relevant Electronic Commerce Consumer Protection Acts).
Records on handling consumer complaints or disputes: 3 years (under relevant Electronic Commerce Consumer Protection Acts).
We may provide personal information to third parties only with the consent of the data subject or when there are special provisions prescribed by relevant laws and regulations.
We may provide pseudonymized information to a third party, and in that case, we shall fully comply with applicable statutory personal information protection requirements.
We entrust personal information processing tasks for smooth data management and cloud operations to third-party providers:
Consignee / Trust Company: Google Inc. (Google Cloud Platform)
Outsourced Work: Storage of data, provision of cloud service.
We may entrust personal information processing tasks to consignees who use servers located overseas for seamless operational continuity:
Twilio Inc.
Personal information transferred: e-mail address.
Country: United States of America.
Date and method of transfer: transfer through the network when using the service.
Consignee’s purpose of use: sending out e-mails.
Period of retention and use: until either the purpose of use for each personal information is achieved, or the user requests withdrawal from membership.
Zendesk, Inc.
Personal information transferred: e-mail and contents of inquiries.
Country: Japan, the United States of America.
Date and method of transfer: transfer through the network when writing a service inquiry or a review.
Consignee’s purpose of use: providing user consultation support services such as sending/posting answers to inquiries via email/comments to reviews/messenger services.
Period of retention and use: until either the purpose of use for each personal information is achieved, or the user requests withdrawal from membership.
Google Inc. (Google Firebase, Google Analytics)
Personal information transferred: app store/version used, country of residence, language setting, device model information, time of accessing the service/history of use, etc.
Country: United States of America.
Date and method of transfer: transfer through the network when using the service.
Consignee’s purpose of use: collection and analysis of usage history of Application and crash logs.
Period of retention and use: fourteen (14) months from collection.
We may use or provide personal information to a third party without the consent of the data subject, considering each of the following criteria within a reasonable scope and the original purpose of collection:
Whether or not it is related to the original purpose of collection: Judgment based on whether the original purpose of collection and the purpose of additional use and provision are related in terms of their nature or tendency;
Whether or not the further use or provision of personal information is predictable considering the circumstances in which the personal information was collected or the processing practices;
Whether the interests of the data subject are unreasonably infringed: Judgment based on whether the interests of the data subject are substantially infringed in relation to the additional purpose; and
Whether measures necessary to secure safety, such as pseudonymization or encryption, have been taken.
The user can exercise the right to read, correct, delete, and suspend processing his or her personal information at any time.
The exercise of the rights pursuant to Paragraph 1 can be made to us in writing or via e-mail, and we will take action without delay.
The exercise of rights pursuant to Paragraph 1 may be done through an agent such as a legal representative of the data subject or a person who has been delegated. In this case, a power of attorney must be submitted.
In accordance with applicable statutory restrictions, the exercise of the user's right to access, correct, delete, or suspend the processing of personal information may be restricted.
Request for correction and deletion of personal information cannot be requested if the information is required to be collected according to other statutory obligations.
We will verify whether the person who made the request holds such rights or is a legitimate agent.
We destroy personal information without delay when the data becomes unnecessary, such as in the cases of the expiration of the retention period or achievement of the purpose of processing.
If personal information needs to be preserved in accordance with relevant laws and regulations even when the personal information retention period agreed by the user has elapsed, the personal information will be moved to a different place or stored in a separate database (DB).
The destruction procedures and methods are as follows:
Destruction procedures: We select the personal information that needs to be destroyed and destroy it under secure managerial approval.
Destruction method: Personal information recorded and stored in electronic file format is destroyed using technical methods so that the information cannot be reproduced or recovered. Personal information recorded in paper documents is destroyed by shredding or incineration.
We take the following technical/administrative measures to ensure safety so that personal information is not lost, stolen, leaked, altered, or damaged:
Administrative measures: establishment and implementation of internal management plans for data protection, regular training, etc.
Technical measures: password encryption, security program installation, secure access controls, etc.
We use 'cookies' and similar identifiers to store and frequently retrieve usage information to provide users with individually customized services.
Purpose of using cookies: It is used for security management, improving services, developing new features, and providing customized experiences and advertisements by analyzing access frequency and session time.
Installation, operation, and rejection of cookies: Users have options regarding the installation of cookies. You can accept all cookies via options in your mobile device, request confirmation each time a cookie is saved, or refuse to save cookies entirely.
Note: If you refuse to store cookies, it may be difficult to use certain localized or synchronized features of the Application.
We may store, process, and transmit personal information in locations outside your region or country of residence. Data may also be stored locally on the device you use to access the service. When we transfer personal information internationally, we will endeavor to ensure that a similar degree of protection is afforded to it by validating appropriate security, cryptographic standards, or contractual clauses approved by governing jurisdictions.
Our service is not directed at children. We do not knowingly collect personal information of children under the age of 13 or an equivalent minimum age as prescribed in the laws of the relevant jurisdiction.
We have designated the management contact for handling personal information and inquiries as follows:
Support & Inquiries Contact: MoneyMap Team
Email: bmalsalemi@gmail.com
Users can submit all personal information protection-related inquiries, handling of complaints, or feedback that occurred while using the Application to our support email. We will respond and handle the inquiries without delay.
If there are any additions, deletions, or changes to the contents of this Privacy Policy, we will notify users through an announcement or notice within the Application in advance. Major changes regarding information collection practices will be communicated visibly before taking effect.
Effective Date: July 7, 2026