개인정보 처리방침
Vivaura Technologies는 이용자의 개인정보를 소중하게 생각합니다.
이 문서는 2026년 10월 13일까지 적용된 이전 처리방침입니다. 현행 처리방침 보기
시행일: 2026년 8월 3일 · 최종 업데이트: 2026년 10월 6일
Vivaura Technologies(이하 “Vivaura”)는 VIVASPORT 웹·모바일 서비스 운영 과정에서 필요한 범위의 개인정보만 처리하고, 기능별 권한과 이용 목적을 분리하여 관리합니다. 이 방침은 현재 운영 코드와 공개 기능을 기준으로 작성되었습니다.
1. 개인정보 처리 목적
- 계정 및 인증: 로그인, 계정 식별, 권한 관리, 부정 이용 방지 및 보안.
- 스포츠 이벤트: 이벤트 탐색, 참가 신청, 주최자 운영, 참가 상태 및 기록 확인.
- 활동·기기 연동: 사용자가 허용한 경우 활동 기록, 경로·위치, Health Connect 및 연결 기기의 동기화와 기록 검증.
- 문의 및 지원: 제품·파트너·운영 문의 접수와 답변, 장애 및 분쟁 대응.
- 서비스 안정성: 접속·오류·보안 이벤트 분석, 품질 개선 및 비정상 접근 방지.
2. 처리하는 개인정보 항목
- 계정: 인증 제공자가 제공하는 사용자 식별자, 이메일, 이름·프로필 정보 등.
- 이벤트 참가: 이름, 이메일, 휴대전화번호, 신청 종목·상태, 주최자가 참가 운영을 위해 정의한 추가 입력값. 필요한 경우 비상연락처·보호자 동의 등 해당 이벤트가 명시한 항목이 포함될 수 있습니다.
- 기념품 택배: 주최자가 기념품·배번 택배 수령을 연 이벤트에서 택배 대상인 참가자가 입력한 받는 분 이름, 휴대전화번호, 우편번호, 주소.
- 활동·웨어러블: 시작·종료 시각, 거리, 시간, 운동 종류, 기기·동기화 메타데이터. 사용자가 별도로 권한을 허용한 경우에만 경로·위치, 심박수, 칼로리 등 Health Connect 데이터가 처리될 수 있습니다.
- 기기 내 활동 기록: Android 앱은 운동 종료 시 계정·활동 식별 정보, 측정값과 동기화 상태를 기기에 먼저 저장합니다. 동기화 대기 기록은 같은 계정으로 앱을 다시 사용할 때 서버 전송을 재시도하며, 확인이 필요한 기록은 기기에 보관하고 안내합니다. 서버 반영 전 앱 데이터 삭제 또는 앱 제거로 기기 기록이 소실될 수 있습니다.
- 문의: 문의 유형, 이름, 이메일, 선택 입력한 전화번호, 제목, 문의 내용, 봇 방지 검증 정보.
- 서비스 로그: IP 주소, 요청·접속 기록, 브라우저·기기 관련 정보, 오류·보안 이벤트. 언어·테마 등 단순 환경설정은 브라우저 로컬 저장소에 보관될 수 있습니다.
현재 운영 범위: 상용 실결제 검증은 운영 승인 전까지 비활성화되어 있습니다. VIVASPORT는 현재 랜딩/참가 흐름에서 신용카드 번호나 은행계좌 비밀번호를 직접 수집한다고 표시하지 않습니다. 향후 유료 결제가 활성화되면 실제 결제사업자, 처리 항목과 보유 기준을 적용 전에 고지합니다.
3. 처리 및 보유 기간
- 계정·프로필: 회원 탈퇴 또는 계정 관계 종료 시까지. 다만 법령상 보존 의무 또는 분쟁 대응 필요가 있으면 해당 기간 동안 분리 보관할 수 있습니다.
- 이벤트 신청·참가 및 활동 기록: 해당 기능의 제공 목적이 달성되거나 사용자가 삭제를 요청할 때까지. 이벤트별 별도 보존 기준이 있으면 신청 화면 등에서 추가 고지합니다.
- 문의·지원 기록: 문의 처리와 후속 분쟁 대응에 필요한 기간 동안 보관하고 목적이 종료되면 삭제합니다.
- 보안·접속·오류 기록: 서비스 보안과 장애 대응에 필요한 범위와 기간 동안 보관합니다.
- 기념품 택배 주소: 해당 이벤트 종료 후 30일이 지나면 삭제합니다. 참가 신청을 취소하거나 회원을 탈퇴하면 그때 바로 삭제합니다.
관계 법령이 별도의 보존 기간을 요구하는 경우에는 그 법정 기간을 우선합니다.
4. 제3자 제공
Vivaura는 원칙적으로 이용자의 개인정보를 처리 목적 범위를 넘어 제3자에게 제공하지 않습니다. 다만 이용자가 특정 이벤트에 참가를 신청하면, 신청 과정에서 고지·동의한 범위에서 해당 이벤트 주최자에게 참가 운영에 필요한 이름, 연락처, 신청 종목·상태 및 주최자 정의 입력값이 제공될 수 있습니다. 기념품 택배 대상이면 받는 분 이름, 휴대전화번호, 우편번호, 주소가 배송을 위해 주최자에게 제공되며, 주최자는 이를 배송 업체에 전달할 수 있습니다. 법령에 특별한 근거가 있는 경우에도 해당 법령 범위 안에서만 제공합니다.
5. 서비스 제공업체와 처리 위탁
서비스 운영에 사용하는 주요 인프라·서비스 제공업체는 다음과 같습니다. 각 제공업체는 해당 기능 제공에 필요한 범위에서 개인정보를 처리합니다.
| 제공업체 | 목적 |
|---|---|
| Cloudflare | 웹·API 호스팅, 데이터베이스·객체 저장소, 보안·봇 방지, 트랜잭션 이메일 인프라 |
| Google Firebase | 사용자 인증 및 계정 식별 |
| Sentry | 애플리케이션 오류·성능 진단 |
| Resend | 트랜잭션 이메일 전송 경로가 활성화된 경우 이메일 전달 |
해외 사업자의 글로벌 인프라를 사용하는 과정에서 국외 처리가 발생할 수 있습니다. 국외 이전의 세부사항은 실제 처리 위치와 계약 조건을 확인해 개인정보처리방침에 반영하며, 관련 법령상 별도 고지 또는 동의가 필요한 처리에는 해당 절차를 제공합니다.
6. 이용자의 권리와 행사 방법
이용자는 관계 법령에 따라 자신의 개인정보에 대한 열람, 정정, 삭제, 처리정지, 동의 철회 등을 요청할 수 있습니다. 계정·앱에서 제공하는 기능을 이용하거나 개인정보 보호 담당 창구로 요청할 수 있습니다. 필수 데이터 삭제 시 일부 서비스 이용이 제한될 수 있습니다.
7. 개인정보의 파기
처리 목적 달성, 보유기간 종료 또는 적법한 삭제 요청으로 개인정보가 더 이상 필요하지 않게 되면 지체 없이 삭제하거나 복구하기 어려운 방법으로 파기합니다. 법령에 따라 보존해야 하는 정보는 다른 정보와 분리하여 해당 기간 동안만 보관합니다.
8. 안전성 확보 조치
Vivaura는 접근권한 제한, 인증·권한 분리, 전송구간 보호, 비밀정보의 서버 측 보관, 로그의 개인정보 마스킹, 감사·보안 이벤트 기록 등 서비스 규모와 위험에 맞는 기술적·관리적 보호조치를 적용합니다.
9. 쿠키·로컬 저장소와 자동 수집
인증·보안·서비스 제공에 필요한 쿠키 또는 유사 저장 기술이 사용될 수 있습니다. 이 랜딩 페이지는 언어와 Light/Dark 테마 선택을 브라우저 로컬 저장소에 저장합니다. 브라우저 설정에서 저장 데이터를 삭제하거나 제한할 수 있으며, 필수 인증·보안 저장을 차단하면 일부 기능이 동작하지 않을 수 있습니다.
10. 개인정보 보호 문의
담당부서: Vivaura Technologies 개인정보 보호 담당
연락처: privacy@vivaura.tech
개인정보 처리와 관련한 문의, 권리 행사, 불만 또는 피해구제 요청은 위 창구로 접수할 수 있습니다. 개인정보 관련 문의와 권리 행사는 위 담당부서 이메일로 접수할 수 있습니다.
11. 권익침해 구제
개인정보 침해와 관련하여 개인정보침해신고센터(privacy.kisa.or.kr, 118), 개인정보분쟁조정위원회(kopico.go.kr, 1833-6972) 등 관계 기관에 상담 또는 구제를 요청할 수 있습니다.
12. 처리방침 변경
이 방침의 중요한 내용이 변경되면 적용 전에 서비스 또는 홈페이지를 통해 알립니다. 시행일은 2026년 8월 3일이며, 현재 공개본의 마지막 업데이트는 2026년 10월 6일입니다.
This is the previous notice, in effect until October 13, 2026. See the current notice
Effective: August 3, 2026 · Last updated: September 17, 2026
Vivaura Technologies (“Vivaura”) processes only the personal data needed to operate VIVASPORT web and mobile services. Permissions and purposes are separated by feature. This notice reflects the currently verified service behavior and production configuration.
1. Why we process personal data
- Accounts and authentication: sign-in, identity, permissions, fraud prevention, and security.
- Sports events: event discovery, registration, organizer operations, participation status, and records.
- Activities and connected devices: when you grant permission, activity records, route/location, Health Connect data, connected-device synchronization, and record verification.
- Support: product, partner, and operations inquiries, troubleshooting, and dispute handling.
- Reliability and security: access, error, and security-event analysis, quality improvement, and abuse prevention.
2. Data we process
- Account: user identifier, email, name, and profile information supplied by the authentication provider.
- Event participation: name, email, phone number, selected event/race, application status, and organizer-defined fields. An event may also request clearly identified fields such as emergency contact or guardian consent when required for that event.
- Activity and wearable data: start/end time, distance, duration, exercise type, device and sync metadata. Route/location, heart rate, calories, and other Health Connect data are processed only when you separately grant the relevant permission.
- On-device activity records: on Android, finishing an activity first saves its account/activity identifiers, measurements and sync state on the device. Pending records are retried when the same account uses the app again; records requiring review remain on the device with a notice. Clearing app data or uninstalling before server synchronization may remove these local records.
- Inquiries: inquiry type, name, email, optional phone number, subject, message, and bot-verification information.
- Service logs: IP address, request/access records, browser/device information, and error/security events. Simple preferences such as language and theme may be stored locally in your browser.
Current production boundary: live commercial payment verification remains disabled pending operational approval. VIVASPORT does not represent that it directly collects raw card numbers or bank-account passwords in the current landing or registration flow. Before paid transactions are enabled, the actual payment provider, processed fields, and retention rules will be disclosed.
3. Retention
- Account/profile data: until account deletion or the account relationship ends, except where law or dispute handling requires limited retention.
- Event participation and activity records: until the feature purpose ends or you request deletion. Event-specific retention rules, if any, are disclosed in the relevant flow.
- Support inquiries: for the period needed to resolve the inquiry and related disputes, then deleted unless law requires otherwise.
- Security/access/error records: for the period reasonably required for security, reliability, and incident response.
Where applicable law requires a specific retention period, the statutory period takes precedence.
4. Sharing with third parties
Vivaura does not share personal data beyond the stated purposes as a general rule. When you register for a specific event, information needed to operate that event—such as your name, contact details, race/application status, and organizer-defined fields—may be provided to the relevant event organizer within the scope disclosed and agreed to during registration. We may also disclose data where specifically required or permitted by law.
5. Service providers and processing
The following providers support the service infrastructure. Each provider processes personal data only to the extent required for the applicable function.
| Provider | Purpose |
|---|---|
| Cloudflare | Web/API hosting, database and object storage, security/bot protection, and transactional email infrastructure |
| Google Firebase | User authentication and account identity |
| Sentry | Application error and performance diagnostics |
| Resend | Transactional email delivery when that delivery path is enabled |
Use of global infrastructure may involve processing outside Korea. International-transfer details will be reflected based on the actual processing location and contractual terms, and any legally required notice or consent procedure will be provided for the applicable processing.
6. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, or withdrawal of consent. You may use the available account/app controls or contact the privacy desk below. Deleting data required for a feature may make that feature unavailable.
7. Deletion
When personal data is no longer needed because its purpose or retention period has ended, or following a valid deletion request, Vivaura deletes or destroys it in a manner designed to prevent recovery. Data that must be retained by law is separated and kept only for the required period.
8. Security
Vivaura applies safeguards appropriate to the service and risk, including access control, authentication and permission separation, transport protection, server-side secret storage, privacy-aware log masking, and audit/security event records.
9. Cookies, local storage, and automatic collection
Cookies or similar storage may be used where necessary for authentication, security, and service delivery. This landing site stores language and Light/Dark theme preferences in browser local storage. You can delete or restrict stored data in your browser, although blocking essential authentication or security storage may prevent some features from working.
10. Privacy contact
Desk: Vivaura Technologies Privacy
Contact: privacy@vivaura.tech
You can use this contact for privacy questions, rights requests, complaints, or remedies. We do not publish invented officer names or telephone numbers where those details have not been verified.
11. External remedies
In Korea, you may also seek advice or remedies from the Personal Information Infringement Report Center (privacy.kisa.or.kr, 118) or the Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972).
12. Changes to this notice
Material changes are announced through the service or website before they take effect. This policy is effective August 3, 2026. This public version was last updated September 17, 2026.