Message in a Bottle — Privacy Policy
This document is not available in your language yet, so it is shown in its original language.
Pursuant to Article 30 of the Personal Information Protection Act of the Republic of Korea and Article 21-2 of the Act on the Protection and Use of Location Information (the "Location Information Act"), Beetrace (the "Company") establishes and discloses the following privacy policy in order to protect the personal information of data subjects and to handle related grievances promptly and smoothly.
This policy applies to the mobile application "Message in a Bottle" (the "Service") provided by the Company.
Article 1 (Purposes of Processing Personal Information)
The Company processes personal information for the purposes set out below. Personal information processed is not used for any purpose other than these, and where the purpose of use changes, the Company will take the necessary measures, such as obtaining separate consent, pursuant to Article 18 of the Personal Information Protection Act.
| Purpose | Details |
|---|---|
| Membership registration and management | Confirming intent to register, identifying and authenticating members in connection with member-only services, maintaining and managing membership status, verifying the consent of a legal representative when processing the personal information of a child under the age of 14, preventing improper use of the Service, various notices and communications, and handling grievances |
| Provision of the Service | Writing, posting, and discovering bottle letters and replying to them; creating and joining signposts and using their boards; providing public member profiles; sending notifications; providing content |
| Provision of location-based services | Searching for bottle letters and signposts near the user, determining the posting position of bottle letters, determining whether a signpost may be planted, and displaying distances |
| Handling of inquiries and complaints | Verifying the identity of the person raising the matter, confirming the details, contacting and notifying them for fact-finding, and reporting the outcome |
| Maintaining order in the use of the Service | Receiving and handling reports, confirming violations of the Terms of Service, imposing restrictions on use, and retaining records for dispute resolution |
| Service improvement and statistics | Analysing service usage, analysing the causes of errors and failures, developing new services, and analysing access frequency |
| Marketing and advertising | Providing events and promotional information (only to members who have consented) and verifying the effectiveness of the Service |
Article 2 (Categories of Personal Information Processed)
1. Information collected at registration
a. Registering with an e-mail address
- Required: e-mail address (account), password, name, nickname, date of birth, gender, mobile phone number
- Optional: whether consent is given to receive promotional information
b. Registering with an external authentication method (Google, Facebook, etc.)
- Required: the identifier provided by the external authentication service, e-mail address, name, nickname
- Optional: profile photo, whether consent is given to receive promotional information
- Where the external authentication service does not provide an e-mail address, the Company asks the member to enter one directly.
2. Information collected in the course of using the Service
- Optional: profile photo, one-line status, introduction, external links registered by the member (Instagram, YouTube, Facebook, and other links), and the profile visibility setting
- Posts written by the member: the body and attached photos of bottle letters, replies, the name, description, and cover image of signposts, and articles, comments, and attached photos on signpost boards
- When using the inquiry feature: the contents of the inquiry and contact details for a reply
- When a report is submitted: the reason for the report, its contents, and a copy of the reported post
3. Location information
- Personal location information: the location of a mobile device (latitude and longitude coordinates collected via satellite positioning systems, wireless LAN, base stations, and the like)
- Records confirming the collection, use, and provision of location information: the dates, times, and details of the collection, use, and provision of location information
The specifics of how location information is processed are governed by Article 4 and by the separate Location-Based Services Terms of Use.
4. Information generated and collected automatically while the Service is used
- Device information: device model, operating system and version, application version, and the device's time zone setting
- Access information: IP address, date and time of access, and service usage records
- Device token for push notifications
- Advertising identifiers (Android Advertising ID, iOS Identifier for Advertisers)
- Diagnostic information generated when an error or abnormal termination (crash) occurs
The Company does not include users' location coordinates, letter contents, nicknames, or e-mail addresses in error and crash diagnostic information. The only user identifier included in such diagnostic information is the member number assigned by the Company.
Article 3 (Processing and Retention Periods)
① The Company processes and retains personal information within the retention and use period prescribed by law, or the retention and use period consented to by the data subject at the time of collection.
② The processing and retention periods for each category are as follows.
| Category | Retention period |
|---|---|
| Information relating to membership registration and management | Until the account is deleted. However, in the following cases the information is retained until the relevant circumstances end: 1) where an investigation or inquiry is underway due to a violation of relevant laws, until that investigation or inquiry ends; 2) where claims or obligations arising from use of the Service remain, until they are settled |
| Posts written by members | Until deleted by the member. After account deletion, posts are not deleted and remain on the Service with the author shown as anonymous. |
| Personal location information | Destroyed immediately upon achieving the purpose of use. However, where the data subject has separately consented, it may be retained for up to one year. |
| Records confirming the collection, use, and provision of location information | Six months (Article 16, Paragraph 2 of the Location Information Act) |
| Records of inquiries and replies | Three years after handling is completed |
| Records of reports received and handled | Three years after handling is completed |
| Records of improper use (history of restrictions on use) | Three years after the restriction ends |
| Service usage records and access logs | Three months |
③ The following information is retained for the periods specified below in accordance with relevant laws.
Act on the Consumer Protection in Electronic Commerce (applies only where paid services have been used)
- Records of labelling and advertising: six months
- Records of contracts and withdrawal of subscription: five years
- Records of payment and the supply of goods: five years
- Records of consumer complaints or dispute handling: three years
Article 4 (Processing of Personal Location Information)
Pursuant to Article 21-2 of the Location Information Act, the Company discloses the following regarding the processing of personal location information.
1. Purposes and retention period
| Item | Details |
|---|---|
| Purposes | Searching for bottle letters and signposts near the user, determining the posting position of bottle letters, determining whether a signpost may be planted, and displaying the distance between the user and posts |
| Retention period | Destroyed immediately upon achieving the purpose of use. However, where the personal location information subject has separately consented, it may be retained for up to one year from the time of consent. |
When a member posts a bottle letter, the Company does not store the member's actual location coordinates as they are; it stores coordinates adjusted to a random point within a certain radius. This is a measure to prevent the member's residence or similar location from being identified, and the member's actual location cannot be inferred in reverse from the position of a posted bottle letter.
2. Basis and period of retention of records confirming the collection, use, and provision of location information
- Basis: automatically recorded and preserved in the location information system pursuant to Article 16, Paragraph 2 of the Location Information Act.
- Period: six months
3. Procedure and method for destroying personal location information
- Procedure: personal location information whose purpose of use has been achieved is classified for destruction without delay and destroyed.
- Method: information in the form of electronic files is deleted using technical methods that make restoration and reproduction impossible; printed materials and the like are shredded or incinerated.
4. Provision of personal location information to third parties
The Company does not provide personal location information to third parties. The following are exceptions.
- Where the personal location information subject has consented in advance
- Where an emergency rescue agency requests emergency rescue or the transmission of an alert
- Where a police authority makes a request
- Where other statutes provide otherwise
Where the Company provides a service that supplies personal location information to a third party designated by the personal location information subject, it shall, pursuant to Article 19, Paragraph 3 of the Location Information Act, immediately notify the subject on each occasion of the recipient, the date and time of provision, and the purpose of provision. The Company does not currently provide such a service.
5. Use of location information for the protection of children aged 8 or under and others
The Company does not provide location information services for the protection of children aged 8 or under and others under Article 26 of the Location Information Act. Accordingly, the rights, obligations, and methods of exercise of guardians under that Article are not applicable.
6. Location information manager
The location information manager designated in Article 13 handles the protection of personal location information and related grievances.
Article 5 (Provision of Personal Information to Third Parties)
① The Company processes personal information only within the scope specified in Article 1, and provides personal information to third parties only where Articles 17 and 18 of the Personal Information Protection Act apply, such as with the consent of the data subject or under special provisions of law.
② There is currently no third party to which the Company regularly provides personal information.
③ Where an investigative agency or similar body requests personal information through lawful procedures under relevant laws (a warrant, an official request, etc.), the Company may provide it within the scope prescribed by those laws.
Article 6 (Outsourcing of Personal Information Processing)
① For the smooth provision of the Service, the Company outsources the processing of personal information as follows.
| Contractor | Outsourced work | Retention and use period |
|---|---|---|
| Google LLC | App usage analytics (Firebase Analytics), collection of error and abnormal termination data (Firebase Crashlytics), delivery of push notifications (Firebase Cloud Messaging), external authentication (Firebase Authentication, Google Sign-In) | Until the outsourcing agreement ends or the account is deleted |
| Amazon Web Service | Servers and data storage for operating the Service | Until the outsourcing agreement ends or the account is deleted |
| Amazon Web Service | Identity verification and delivery of informational messages | Until the outsourcing agreement ends or the account is deleted |
② When entering into an outsourcing agreement, the Company specifies in the contract or another document, pursuant to Article 26 of the Personal Information Protection Act, the prohibition on processing personal information for purposes other than performing the outsourced work, technical and administrative protective measures, restrictions on sub-outsourcing, supervision of the contractor, liability including damages, and related matters, and supervises whether the contractor processes personal information safely.
③ Where the contents of the outsourced work or the contractor changes, the Company will disclose this through this privacy policy without delay.
Article 7 (Cross-Border Transfer of Personal Information)
① Pursuant to Article 28-8, Paragraph 1, Item 3(a) of the Personal Information Protection Act, the Company transfers personal information overseas as set out below, to the extent that this constitutes the outsourcing of processing or storage necessary to perform its contract with the data subject, and discloses the details in this privacy policy.
| Item | Details |
|---|---|
| Recipient | Google LLC |
| Contact | beetrace2026@gmail.com |
| Countries of transfer | The United States and other countries in which Google LLC operates data centres |
| Time and method of transfer | Transmitted over the information and communications network at the time the Service is used |
| Personal information transferred | App usage records, device information, advertising identifiers, device tokens for push notifications, error and crash diagnostic information, external authentication identifiers, and e-mail addresses |
| Recipient's purposes of use | App usage analytics, error diagnostics, delivery of push notifications, and external authentication |
| Retention and use period | Until the outsourcing agreement ends or the account is deleted |
② Data subjects may refuse the cross-border transfer of their personal information. However, the items above are tied to functions essential to the Service (notification delivery, error diagnostics, and external authentication), so refusing may restrict the use of those functions. A data subject wishing to refuse may contact the personal information protection officer under Article 13, or disable the relevant functions through the in-app notification settings and the app's permission settings.
Article 8 (Procedure and Method for Destroying Personal Information)
① The Company destroys personal information without delay once it becomes unnecessary, for example because the retention period has elapsed or the purpose of processing has been achieved.
② Where personal information must continue to be preserved under other statutes even though the consented retention period has elapsed or the purpose of processing has been achieved, the Company moves that personal information to a separate database or stores it in a different location.
③ The procedure and method for destroying personal information are as follows.
- Procedure: the Company selects the personal information for which grounds for destruction have arisen and destroys it with the approval of its personal information protection officer.
- Method: personal information recorded and stored as electronic files is destroyed so that the records cannot be reproduced; personal information recorded and stored on paper is shredded or incinerated.
④ Upon account deletion, the member's account information is destroyed, but posts written by the member are not deleted and remain on the Service with the author shown as anonymous. A member who wishes to have their posts deleted must delete them personally before deleting their account.
Article 9 (Rights and Obligations of Data Subjects and Legal Representatives, and How to Exercise Them)
① Data subjects may exercise the following rights against the Company at any time.
- The right to be provided with information about the processing of their personal information
- The right to choose and decide whether to consent to the processing of their personal information and the scope of such consent
- The right to confirm whether their personal information is being processed and to request access to and transfer of it
- The right to request the suspension of processing, and the correction, deletion, and destruction of their personal information
- The right to prompt and fair relief for harm caused by the processing of their personal information
② Personal location information subjects additionally have the following rights under the Location Information Act.
- The right to withdraw, at any time, all or part of their consent to the collection, use, and provision of personal location information (Article 24, Paragraph 1). Where consent is withdrawn, the Company destroys the collected personal location information and the records confirming its collection, use, and provision without delay.
- The right to request the temporary suspension of the collection, use, and provision of personal location information (Article 24, Paragraph 2). The Company does not refuse such requests and maintains the technical means to comply with them.
- The right to request access to, or notification of, the records confirming the collection, use, and provision of location information concerning them and the reasons for and contents of any provision of their personal location information to third parties, and to request correction of any errors (Article 24, Paragraph 3)
③ The rights under Paragraphs 1 and 2 may be exercised as follows.
- Directly, through the account settings, member information edit, notification settings, and block management screens in the Service
- Through the in-app inquiry form
- By request to the Company's e-mail address (beetrace2026@gmail.com)
- By revoking the app's location permission in the device's operating system settings (temporary suspension of the collection of personal location information)
④ Upon receiving a request under Paragraph 3, the Company processes it without delay and notifies the data subject of the outcome. The periods within which access, correction, deletion, and similar requests may be made follow relevant laws.
⑤ Rights may be exercised through a representative, such as the data subject's legal representative or a person duly authorised by them. In such a case, a power of attorney in the form of Annex No. 11 of the Notice on Methods of Processing Personal Information must be submitted.
⑥ Requests to access personal information and to suspend its processing may be restricted under Article 35, Paragraph 4 and Article 37, Paragraph 2 of the Personal Information Protection Act.
⑦ Deletion may not be requested where other statutes expressly designate the personal information concerned as subject to collection.
⑧ Where a request for access, correction, deletion, or suspension of processing is made under a data subject's rights, the Company verifies whether the person making the request is the data subject or a duly authorised representative.
Article 10 (Measures to Ensure the Security of Personal Information)
The Company takes the following measures to ensure the security of personal information.
1. Administrative measures
- Establishment and implementation of an internal management plan
- Minimising the number of personnel who handle personal information and granting differentiated access rights
- Regular training for personnel who handle personal information
2. Technical measures
- Management of access rights to personal information processing systems and access control
- Encryption of personal information: passwords are stored using one-way encryption that cannot be decrypted, and sensitive data such as authentication tokens is encrypted and stored in the device's secure storage.
- Encryption in transit: communication between users and the server takes place over an encrypted channel (HTTPS).
- Retention of access logs and prevention of forgery and alteration
- Installation and updating of security programs, and installation and operation of intrusion prevention systems
3. Protective measures for location information (Article 16, Paragraph 1 of the Location Information Act)
- Establishment of guidelines for handling and managing location information and designation of persons authorised to access it
- Installation of firewalls and use of encryption software
- Automatic recording and preservation of records confirming the collection, use, and provision of location information in the location information system
4. Physical measures
- Access control for servers and locations where data is stored
Article 11 (Installation and Operation of Devices that Automatically Collect Personal Information, and Refusal Thereof)
① The Company may collect the device's advertising identifier (Android Advertising ID, iOS Identifier for Advertisers) for the purposes of usage analytics and error diagnostics.
② Data subjects may refuse or reset the collection of advertising identifiers as follows.
- Android: Settings > Privacy > Ads > Delete advertising ID
- iOS: Settings > Privacy & Security > Tracking > turn off "Allow Apps to Request to Track"
③ Refusing the collection of advertising identifiers does not restrict use of the Service.
④ Because the Company provides the Service in the form of an app, it does not operate internet access information files (cookies).
Article 12 (Processing the Personal Information of Children Under the Age of 14)
① The Company does not accept membership registration from children under the age of 14.
② Where it is necessary to process the personal information of a child under the age of 14, the Company obtains the consent of that child's legal representative and verifies that the legal representative has given consent, pursuant to Article 22-2 of the Personal Information Protection Act and Article 25 of the Location Information Act.
③ In order to obtain the consent of a legal representative, the Company may collect the minimum information necessary (the legal representative's name and contact details) directly from the child without the legal representative's consent.
④ When informing a child under the age of 14 about matters relating to the processing of personal information, the Company uses an easily understandable format and clear, plain language.
⑤ A legal representative may exercise the rights under Article 9 with respect to a child's personal information.
Article 13 (Personal Information Protection Officer and Location Information Manager)
① The Company designates the following officers to take overall responsibility for the processing of personal information and personal location information and to handle data subjects' complaints and provide relief for harm relating to the processing of personal information.
Personal information protection officer and location information manager
- Name: Seol Dong-hyuk
- Position: Representative
- Telephone: +821086786479
- E-mail: beetrace2026@gmail.com
Department responsible for personal information protection
- Department: Information Security
- Telephone: +821086786479
- E-mail: beetrace2026@gmail.com
② Data subjects may direct to the personal information protection officer and the responsible department any inquiries, complaints, or requests for relief relating to the protection of personal information arising while using the Service. The Company will respond and act on such inquiries without delay.
Article 14 (Remedies for Infringement of Rights)
① Data subjects may apply to the following bodies for dispute resolution or counselling in order to obtain relief for infringement of their personal information.
| Body | Function | Contact |
|---|---|---|
| Personal Information Dispute Mediation Committee | Applications for personal information dispute mediation and collective dispute mediation | 1833-6972 (no area code) / www.kopico.go.kr |
| Privacy Infringement Report Centre | Reports of personal information infringement and counselling | 118 (no area code) / privacy.kisa.or.kr |
| Supreme Prosecutors' Office, Cybercrime Investigation Division | Criminal cases involving personal information infringement | 1301 (no area code) / www.spo.go.kr |
| National Police Agency, Cyber Investigation Bureau | Criminal cases involving personal information infringement | 182 (no area code) / ecrm.police.go.kr |
② Where an agreement cannot be reached, or no agreement is possible, between the parties to a dispute relating to location information, an application may be made to the Broadcasting, Media and Communications Commission for adjudication, or to the Personal Information Dispute Mediation Committee for mediation, pursuant to Article 28 of the Location Information Act.
③ A person whose rights or interests have been infringed by a disposition or omission of the Company in response to a request under Article 35 (access to personal information), Article 36 (correction or deletion of personal information), or Article 37 (suspension of processing of personal information) of the Personal Information Protection Act may file an administrative appeal as prescribed by the Administrative Appeals Act.
- Central Administrative Appeals Commission: 110 (no area code) / www.simpan.go.kr
Article 15 (Amendments to This Privacy Policy)
① This privacy policy applies from its effective date.
② Where content is added, deleted, or modified due to changes in laws, policies, or security technology, the Company will give notice through in-app notices from seven days before the changes take effect. However, where the changes materially affect the rights of data subjects, notice will be given 30 days in advance.
③ The Company retains previous versions so that the history of amendments to this privacy policy can be reviewed.
Addendum
- Date of announcement: 01 September 2026
- Effective date: 01 October 2026
- Version: v1.0
Loading the document