Privacy Policy

Privacy Policy

Version 4.0

Announced: August 19, 2026 · Effective: September 18, 2026

This is the official English translation. In the event of any discrepancy, the Korean version shall prevail.

1. General Provisions

RunnersLikeMe (hereinafter the “Company”) complies with the Personal Information Protection Act of Korea (PIPA), the Act on the Protection and Use of Location Information of Korea, and other applicable laws, and through this Privacy Policy informs users of the purposes for which and the manner in which their personal information is processed, and how it is protected.

This Privacy Policy applies to the services provided by the Company. For details on the processing of location information, please also refer to the Location-Based Services Terms of Use.

2. Purposes of Processing Personal Information

The Company processes personal information for the following purposes. Personal information being processed is not used for any purpose other than those stated below, and if the purpose of use changes, the Company takes necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act of Korea (PIPA).

A. Member Registration and Management

Confirming the intent to register, identifying and authenticating members, age verification (blocking registration by children under the age of 14; applying minor-protection policies), verifying the consent of legal representatives of minor members, maintaining and managing membership, preventing fraudulent use of the service, delivering notices and notifications, and handling grievances

B. Service Provision

Providing search, viewing, and playback of courses and course guides; running host-guest matching; chat features; operating the review and rating system; managing the credit system; managing running records and running notes; and providing personalized services

C. Paid Services and Settlement

Processing payments for paid course guides, managing purchase history, handling withdrawal of purchase (cooling-off) and refunds, settling curators' sales revenue, and tax processing (fulfilling statutory obligations such as withholding tax and submitting payment statements)

D. Safety and Security

Preventing and sanctioning fraudulent use, handling reports and disputes, managing no-shows, detecting abnormal behavior and maintaining community safety, and cooperating with investigative authorities in the event of an incident

E. Marketing and Advertising (with separate consent)

Providing information on events and advertisements, compiling and analyzing service usage statistics, and providing personalized recommendation services

3. Personal Information Collected and Methods of Collection

A. Items Collected

CategoryItems CollectedRequired/Optional
Registration (social login)Social account identifier, email address, name, profile photo (if provided)Required
Registration (common)Phone number (SMS verification), date of birth (age verification)Required
Registration by minor membersLegal representative's name, contact information, and consent verification informationRequired (where applicable)
Onboarding (required)Real name, profile photo, city of residence, languages spoken, average pace, preferred distances, preferred timesRequired
Onboarding (optional)One-line bio, LinkedIn URL, Instagram username, Garmin profile URLOptional
Service useRunning records (distance, time, pace), course and course guide registration information, running notes, review content, chat messages, credit transaction history, report contentRequired
Use of paid servicesPurchase history, payment approval information (card issuer name, approval number, etc. — full card numbers are processed by the electronic payment gateway provider and are not stored by the Company)Required (where applicable)
Curator settlementAccount holder name, bank name, account number, and information legally required for tax processingRequired (where applicable)
External service integrationStrava running statistics (total distance, run count)Optional
Automatically collectedIP address, device information, browser type, access date and time, service usage records, cookiesRequired
Location informationGPS-based location information, running routes, running locationsOptional (collected with consent; however, required for the use of location-based features such as running records and location-based course guides)

Notice on sensitive information: The Company does not collect biometric measurement information relating to health (sensitive information) such as heart rate or blood pressure. Even when integrating external services (such as Strava), the Company receives only exercise statistics such as distance, run count, and pace, and health-related sensitive information is excluded from the received items. If the Company introduces a feature that requires the processing of sensitive information in the future, it will obtain separate consent in accordance with Article 23 of the Personal Information Protection Act of Korea (PIPA).

Children's personal information: The Company does not collect personal information from children under the age of 14. Any account confirmed to belong to a child under the age of 14 will be blocked from use without delay, and the information collected will be destroyed.

B. Methods of Collection

  • Entered directly by users during registration and onboarding
  • Automatically generated and collected during service use (running records, access records, etc.)
  • Received from external services with the user's consent when using social login (Google, etc.) or integrating external services (Strava, etc.)
  • Collected during phone number verification (SMS)
  • Collected through customer service inquiries and report submissions

4. Retention and Use Period of Personal Information

The Company destroys personal information without delay once the purpose of its collection and use has been achieved. However, the following information is retained for the periods specified below in accordance with applicable laws.

A. Retention Under Applicable Laws

Items RetainedRetention PeriodLegal Basis
Records concerning contracts or withdrawal of purchase (cooling-off)5 yearsAct on Consumer Protection in Electronic Commerce of Korea
Records concerning payment and the supply of goods, etc.5 yearsAct on Consumer Protection in Electronic Commerce of Korea
Records concerning consumer complaints or dispute resolution3 yearsAct on Consumer Protection in Electronic Commerce of Korea
Records concerning labeling and advertising6 monthsAct on Consumer Protection in Electronic Commerce of Korea
Books and supporting documents for transactions under tax law5 yearsFramework Act on National Taxes of Korea
Access records (login records, etc.) kept in preparation for the provision of communication confirmation data3 monthsProtection of Communications Secrets Act of Korea
Records confirming the use and provision of location information6 monthsAct on the Protection and Use of Location Information of Korea

B. Retention Under Internal Policy

Items RetainedRetention PeriodReason
Access logs of the personal information processing system (access records of administrators and handlers)At least 1 yearStandards for Ensuring the Safety of Personal Information (notification of the Personal Information Protection Commission of Korea)
Records of fraudulent use (sanction history; minimum information for determining re-registration restrictions)1 year after the sanction endsPrevention of repeated fraudulent use
Account information related to unpaid settlement amountsUntil payment is completedFulfillment of curator settlement obligations
Purchase records of paid course guides of withdrawn members (minimum information for restoring access rights)30 days after withdrawalRestoration of access rights upon re-registration (Article 30(7) of the Terms of Service)

5. Provision of Personal Information to Third Parties

The Company processes users' personal information within the scope of the purposes specified in Section 2 and does not provide it to third parties without the user's prior consent. However, the following cases are exceptions.

A. Provision Between Members for Service Delivery (within the scope of the user's consent when using the service)

RecipientItems ProvidedPurpose of ProvisionRetention and Use Period
Matched counterpart member (host and guest)Real name, profile photo, running-related information (pace, preferred distance, etc.), reviews and ratings, chat messagesIn-person running matching and communicationFor the duration of the matching relationship
Members purchasing paid course guidesSeller identification information such as the curator's nickname and profileFulfillment of the Company's obligation as a mail-order brokerage operator to provide seller identity informationFor the transaction record retention period
Counterpart member in the event of a paid-transaction disputeIdentity information prescribed by Article 20(2) of the Act on Consumer Protection in Electronic Commerce of Korea, such as the curator's name and contact methodConsumer redress and dispute resolutionUntil the dispute is resolved

B. Provision Required by Law

  • Where required by law
  • Where requested by investigative authorities for investigative purposes in accordance with the procedures and methods prescribed by law
  • Where ordered by a court

6. Outsourcing of Personal Information Processing

The Company outsources personal information processing tasks as follows to provide the service. When entering into outsourcing contracts, the Company stipulates the outsourcee's personal information protection obligations and supervises the outsourcee in accordance with Article 26 of the Personal Information Protection Act of Korea (PIPA).

OutsourceeOutsourced Tasks
Supabase, Inc.Database hosting, user authentication, file storage
Vercel, Inc.Website hosting
Google LLCSocial login (OAuth), sending verification and notification emails (Gmail SMTP), map services (Google Maps), push notifications (Firebase Cloud Messaging)
SOLAPI Co., Ltd.Sending domestic SMS verification messages
Twilio Inc.Sending international SMS verification messages
To be providedElectronic payment gateway services (processing credit card and other payments)

7. Cross-Border Transfer of Personal Information

Some of the cloud infrastructure used by the Company is located outside the Republic of Korea. The Company transfers personal information abroad as follows, based on Article 28-8(1)3 of the Personal Information Protection Act of Korea (PIPA) (outsourcing or storage of personal information processing necessary for the conclusion and performance of a contract with the data subject, where the details are disclosed in this Privacy Policy).

Recipient (Contact)Destination CountryItems TransferredTiming and Method of TransferPurpose of UseRetention and Use Period
Supabase, Inc. (support@supabase.com)To be providedAll collection items listed in Section 3Transmitted and stored over the network when the service is usedDatabase hosting, authentication, storageUntil membership withdrawal or termination of the outsourcing contract
Vercel, Inc. (privacy@vercel.com)United StatesAccess records (IP address, device information, etc.)Transmitted over the network when accessing the serviceWebsite hosting and delivery optimizationUntil termination of the outsourcing contract
Google LLC (googlekrsupport@google.com)United StatesSocial login account information, email address, push tokens, map usage informationTransmitted over the network when the relevant feature is usedSocial login, email delivery, maps, push notificationsUntil membership withdrawal or termination of the outsourcing contract
Twilio Inc. (privacy@twilio.com)United StatesPhone number (limited to non-Korean numbers)Transmitted over the network when SMS verification is requestedInternational SMS deliveryUntil delivery processing is completed

If a user does not wish their personal information to be transferred abroad, the user may refuse the transfer through the contact listed in Section 14. However, because the cross-border transfer concerns infrastructure essential to providing the service, refusing the transfer may make it impossible or restricted to use the service. When transferring personal information abroad, the Company implements protective measures under Article 28-8(4) of the Personal Information Protection Act of Korea (PIPA) (encrypted transmission, contractual safeguards with outsourcees, etc.).

8. Destruction of Personal Information

  1. The Company destroys personal information without delay when it becomes unnecessary, such as upon expiration of the retention period or achievement of the purpose of processing.
  2. Electronic files are deleted using technical methods that make recovery impossible, and printed materials are shredded or incinerated.
  3. Upon membership withdrawal, personal information is destroyed within 30 days. This grace period exists to handle restoration requests in cases of accidental withdrawal and to prevent fraudulent re-registration aimed at evading sanctions; during the grace period, the relevant information is stored separately and is not used for any purpose other than destruction or restoration. Information subject to retention under Section 4 (“Retention and Use Period of Personal Information”) above, including retention under applicable laws and retention under internal policy, is stored and managed separately from other personal information during the retention period and then destroyed.
  4. The destruction of personal location information is governed with priority by Article 7 of the Location-Based Services Terms of Use, under which it is destroyed without delay upon withdrawal.

9. Rights of Data Subjects and Legal Representatives

  1. Users may exercise the following rights against the Company at any time.
    • Right to request access — access to their personal information being processed
    • Right to request correction and deletion — correction of errors and deletion
    • Right to request suspension of processing — suspension of the processing of personal information
    • Right to withdraw consent — withdrawal of consent to collection, use, and provision
    • Right to request transmission — transmission of personal information as prescribed by law
  2. Rights may be exercised through the following methods, and the Company notifies the user of the outcome within 10 days of receiving the request.
    • Directly edit or delete in Settings > Account Management
    • Withdraw consent in Settings > Marketing Preferences
    • Email: runnerslikeme@gmail.com
  3. Rights may also be exercised through a legal representative or an authorized agent. In such cases, a power of attorney under the Notification on the Methods of Personal Information Processing of Korea must be submitted.
  4. Requests for access and other rights may be restricted on grounds such as specific provisions in the law; in such cases, the Company notifies the user of the reason.

10. Notice on Automated Decisions

In accordance with Article 37-2 of the Personal Information Protection Act of Korea (PIPA), the Company provides the following notice regarding cases in which automated systems are involved in decisions that affect users.

  1. Temporary suspension based on accumulated reports: Accounts that have accumulated 5 or more reports may automatically be subject to temporary suspension. This is a temporary measure for community safety, and the final decision on sanctions is always made through human review by the Company. Users may request an explanation of, and file an objection to, the temporary measure (Article 26 of the Terms of Service).
  2. Matching and course recommendations: Recommendation algorithms based on profile information such as pace, language, and time zone are limited to providing reference information and do not independently make decisions that affect users' rights or obligations.
  3. Users may request an explanation and review of automated decisions through the contact listed in Section 14.

11. Measures to Ensure the Safety of Personal Information

The Company implements the following measures in accordance with Article 29 of the Personal Information Protection Act of Korea (PIPA) and the Standards for Ensuring the Safety of Personal Information.

A. Administrative Measures

  • Establishment and implementation of an internal management plan
  • Minimization of personal information handlers and differentiated granting and management of access rights
  • Personal information protection training

B. Technical Measures

  • Encrypted storage of passwords and key information
  • Encryption of data in transit via SSL/TLS
  • Access control for the personal information processing system and retention and inspection of access logs for at least 1 year
  • Installation and regular updating of security programs

C. Physical Measures

  • Physical access control for the cloud infrastructure where personal information is stored (verification of outsourcees' data center security certifications — SOC 2, ISO 27001, etc.)

12. Cookies and Automatic Collection Devices

  1. The Company uses cookies to keep users logged in, save preference settings, and analyze service usage statistics.
  2. Users may refuse the storage of cookies in their browser settings. However, some features, such as staying logged in, may be restricted.
  3. The Company does not use behavioral information collection tools that provide users' online activity to third-party advertising networks. If such tools are introduced in the future, the Company will disclose this in this Privacy Policy and obtain the necessary consent.

13. Notice for Overseas Users

The Company also provides its service to users outside the Republic of Korea and provides the following notice.

  1. Legal bases for processing (EU/EEA residents): The personal information of users to whom the EU General Data Protection Regulation (GDPR) applies is processed on the following bases.
    • Performance of a contract (GDPR Art. 6(1)(b)) — service provision, matching, payment
    • Compliance with a legal obligation (Art. 6(1)(c)) — retention of transaction records, etc.
    • Legitimate interests (Art. 6(1)(f)) — prevention of fraudulent use, service security
    • Consent (Art. 6(1)(a)) — marketing, location information, optional items
  2. Rights of EU/EEA residents: EU/EEA residents have the right of access, the right to rectification, the right to erasure (right to be forgotten), the right to restriction of processing, the right to data portability, the right to object, and rights related to automated decision-making, and may exercise them through the contact listed in Section 14. The Company responds within one month.
  3. Complaints to supervisory authorities: EU/EEA residents have the right to lodge a complaint with the Data Protection Authority in their place of residence.
  4. Users in other countries hold the rights granted by the mandatory laws of their respective countries, and the Company respects those rights.

14. Chief Privacy Officer

The Company designates the following Chief Privacy Officer to oversee personal information processing and to handle data subjects' complaints and provide remedies.

Chief Privacy Officer

  • Name: To be provided
  • Title: CEO (Head of Service Operations)
  • Email: runnerslikeme@gmail.com
  • Phone: Coming soon

Users may submit any inquiries, complaints, or requests for remedies related to personal information arising from the use of the service to the contact above, and the Company will respond and process them without delay.

15. Remedies for Infringement of Rights

Users may apply to the following organizations for dispute resolution or consultation to obtain relief from personal information infringement.

OrganizationContactWebsite
Personal Information Infringement Report Center (KISA)118 (no area code)privacy.kisa.or.kr
Personal Information Dispute Mediation Committee1833-6972 (no area code)www.kopico.go.kr
Cyber Investigation Division, Supreme Prosecutors' Office1301 (no area code)www.spo.go.kr
Cyber Investigation Bureau, Korean National Police Agency182 (no area code)ecrm.police.go.kr

16. Changes to the Privacy Policy

  1. If the contents of this Privacy Policy are added to, deleted, or amended, notice will be given through in-service announcements starting 7 days before the effective date. However, for changes significant to users' rights, such as changes to the items collected, purposes of use, third-party provision, or cross-border transfer, notice will be given 30 days in advance, and separate consent will be obtained where necessary.
  2. The version history of this Privacy Policy is as follows. Previous versions are kept by the Company and are available for review upon request.
    VersionEffective DateMajor Changes
    v1.02026-01-26Initial enactment
    v2.02026-02-06Wording revised
    v4.02026-09-18Added cross-border transfer section; reflected outsourcing audit (corrected SMS and email delivery channels); added paid services and settlement items; added notice on automated decisions; added notice for overseas users (GDPR); reorganized safety measures into three categories; added provisions on children and sensitive information

Effective Date: September 18, 2026