*This translation is provided for convenience. If there is any inconsistency between this translation and the Korean original, the Korean original prevails.*
NineThirty Co., Ltd. (the "Company") protects the personal information of users of the haps service (the "Service") in accordance with the Personal Information Protection Act of the Republic of Korea and other applicable laws, and establishes and discloses this Privacy Policy as follows.
1. Items of Personal Information Processed and Collection Methods
Sign-up and account operation (required)
- Phone number, email address, date of birth, gender, nickname, interest hashtags, profile photo
- Device information: device platform (iOS/Android), push token, language setting, app installation identifier (a random value generated by the app)
- Verification process information: verification codes and requesting IP addresses are not stored in their original form; they are kept only as one-way hashed values for a short validity period and then destroyed
- Collection methods: entered directly by the user or generated automatically during the sign-up process and the use of the Service
Generated in the course of using the Service (required)
- Group records: photos, videos, written text, time of the record, area label (the processing of location information is governed by the Location-Based Services Terms of Use)
- Chats and notes: chat messages, note contents. Where a user includes contact information (a phone number or Instagram account) in a note, the information the user entered directly
- Usage records: access and activity timestamps, login session information, report and block history, original text of inputs caught by the prohibited-word filter
- Payment records: app market purchase receipt information, Sparks crediting and usage ledger. Payment method details such as card numbers are processed by the app market operators and are not collected by the Company.
Optional
- Items processed for receiving marketing communications are governed by the Marketing Information Use and Communications Notice.
2. Purposes of Processing Personal Information
- Member sign-up, identity verification (phone number verification, email verification, new-device verification), account management
- Provision of the Service: group formation, logging, and delivery of recaps; interaction between groups (discovery, knocks, chats, notes); sending push notifications
- Safe operation of the Service: preventing fraudulent use and sign-ups by minors, managing usage restriction history, handling reports, responding to disputes
- Processing purchases and refunds of paid services (including provision of the minimum information necessary for app market refund reviews)
- Compliance with legal obligations
- (With optional consent) sending marketing communications such as events and offers
3. Retention and Use Period of Personal Information
- In principle, the Company destroys or anonymizes personal information without delay upon a Member's withdrawal. Processing upon withdrawal is as follows:
- Destroyed immediately: phone number and its hashed identifier, email address and its hashed identifier, gender, date of birth, interest hashtags, profile photo (file deleted after being unlinked from the account), photos and clips uploaded by the Member (excluding group covers), push token and device registration information, notification inbox, notification settings, records confirming the use and provision of location information (except where retention is required by law), login sessions
- Preserved after anonymization: in records and chats/notes shared with a group, user identifiers such as nicknames are anonymized as "former member" and preserved for the group's members (where a retention period is set for a given item, preserved within that period). If all members of a group have withdrawn, that group's records (photos, clips, and recaps) are destroyed within 24 hours.
- In the following cases, information is stored separately for the designated period and then destroyed.
| Item | Retention period | Basis |
|---|---|---|
| Re-registration restriction information for withdrawn accounts with an effective usage restriction (sanction) history (hashed identifiers of phone number and email, device installation identifier) | 1 year from the date of withdrawal | Prevention of fraudulent use (Article 12 of the Terms of Service) |
| Preservation of evidence for reported content | 90 days after the report has been processed | Report handling and dispute response |
| Original text of chat messages | 90 days | Safe operation of the Service |
| Original text of inputs caught by the prohibited-word filter | 90 days | Prevention of fraudulent use |
| Notification inbox data | 30 days | Provision of the Service |
| Block markers for attempted sign-ups by minors (one-way hashed identifiers of the phone number and device) | 7 days | Prevention of sign-ups by minors |
| Records of contracts, cancellations of purchase, payments, and supply of goods (payment receipts, item ledger) | 5 years | Act on the Consumer Protection in Electronic Commerce, etc. of the Republic of Korea |
| Records of handling consumer complaints and disputes | 3 years | Act on the Consumer Protection in Electronic Commerce, etc. |
| Access log records | 3 months | Protection of Communications Secrets Act |
4. Provision of Personal Information to Third Parties
The Company does not provide users' personal information to third parties, except in the following cases:
- Where the user has separately consented
- Where there is a legal basis under applicable laws
- Response to app market refund reviews: where an app market operator (Apple, Google) reviews a refund, the Company provides that operator with the minimum information necessary for the review, such as whether the purchased item has been used, the remaining balance, and account status, in accordance with Article 6 of the Terms of Service.
5. Outsourcing of Personal Information Processing
The Company outsources the processing of personal information as follows in order to provide the Service.
| Contractor | Outsourced work |
|---|---|
| Amazon Web Services, Inc. | Operation of data storage and processing infrastructure, sending of verification code text messages |
| Email delivery service provider | Sending of verification and informational emails |
Outsourcing agreements stipulate compliance with personal information protection laws, restrictions on sub-outsourcing, and management and supervision matters. The list of contractors is updated as the Service is operated, and changes are disclosed through this Policy.
6. Cross-Border Transfer of Personal Information
The following cross-border transfers occur in the course of operating the Service infrastructure and delivering notifications.
| Recipient | Country | Items transferred | Method and timing of transfer | Purpose |
|---|---|---|---|---|
| Amazon Web Services, Inc. | United States and other countries where regions are located | Items processed under Section 1 | Network transmission and storage during use of the Service | Infrastructure operation |
| Google LLC (FCM) | United States | Push token, notification delivery information | When notifications are sent | Delivery of push notifications |
| Apple Inc. (APNs) | United States | Push token, notification delivery information | When notifications are sent | Delivery of push notifications |
Users may refuse the cross-border transfer; however, in that case the Service cannot be provided. Refusal may be exercised by not signing up or by withdrawing from membership.
7. Destruction and Secure Storage of Personal Information
- Personal information for which grounds for destruction have arisen is destroyed without delay. Electronic files are deleted using methods that make recovery impossible.
- Information retained pursuant to law is stored separately and destroyed after the retention period has elapsed.
- Key items such as phone numbers, email addresses, push tokens, and payment receipts are stored in encrypted form, and where lookups such as duplicate checks are necessary, one-way hashed values are used instead of the original data.
8. Rights of Data Subjects and How to Exercise Them
- Users may at any time request access to, correction of, deletion of, or suspension of the processing of their personal information.
- Rights may be exercised through in-app features (profile editing, content deletion, withdrawal) or through the channel below.
- Email: support@ninethirty.io
- Withdrawn users and non-members may also exercise their rights via the email address above.
- The Company will notify the requester of the outcome within 10 days of receiving the request.
- Where rights are exercised through an agent, a power of attorney may be required.
How to Delete Your Account
You can delete your haps account and personal information (withdraw from membership) in either of the following two ways.
- Directly in the app: Me > Account > Delete account deletes it immediately.
- By email: If you cannot access the app, send a request to support@ninethirty.io with the phone number used at sign-up, and we will process it after verifying your identity.
The scope and periods of immediate destruction, anonymization, and separate retention under applicable laws upon withdrawal are governed by Section 3.
9. Measures to Ensure the Security of Personal Information
- Encryption of personal information: encryption in transit; encrypted storage of key identifiers, contact information, push tokens, and payment receipts
- Minimization of access privileges, access controls, and retention of access records
- Requirement to enter a reason when operators view personal information, with audit records (audit logs of all operations in the administration tools)
- Establishment and implementation of an internal management plan
10. Processing of Behavioral Information
The Company processes behavioral information for advertising performance measurement and personalized advertising based on the user's optional consent ("Consent to Provide Personal Information to Third Parties for Personalized Ads"). The items processed are advertising identifiers (IDFA and ADID), app event information such as app installs and launches, and hashed email addresses and mobile phone numbers for creating custom and lookalike audiences, and the recipients are Meta Platforms, Inc. and Google LLC. Details and how to refuse or withdraw consent are set out in a separate notice (Personalized Advertising and Third-Party Provision Notice). The Company does not collect or provide behavioral information of users who have not consented for personalized advertising purposes, and does not display advertisements in the app.
11. Children's Personal Information
The Service may be used only by persons 18 years of age or older (19 or older for residents of the Republic of Korea), and the Company does not collect children's personal information. If a person is identified as a minor during the sign-up process, the entered information is not stored; only a block marker (a one-way hashed identifier) to prevent repeated attempts is kept for 7 days and then destroyed.
12. Chief Privacy Officer and Contact
- Chief Privacy Officer: Sangrok Lee, CEO
- Contact: support@ninethirty.io, 070-8970-8697
Users may seek reporting or consultation regarding personal information infringements from the following organizations:
- Personal Information Dispute Mediation Committee: 1833-6972
- Personal Information Infringement Report Center: 118
- Supreme Prosecutors' Office: 1301; National Police Agency: 182
13. Additional Notices by Country
- For users outside the Republic of Korea, additional notices required by the laws of their region may apply.
- An appendix on the rights of residents of certain U.S. states (such as California), including the rights of access, deletion, and opting out of sale and sharing, will be added to this section following legal review.
- The direct marketing notice for residents of Hong Kong is included in the Marketing Information Use and Communications Notice.
14. Changes to this Policy
If this Policy is changed, notice will be given 7 days before the change takes effect (30 days for material changes), and previous versions can be found on the website. The Korean version of this Policy is the authoritative text, and in the event of any discrepancy with a translation, the Korean version prevails.
- Date of announcement: September 7, 2026
- Effective date: September 7, 2026