Version 4.0
Announced: August 19, 2026 · Effective: September 18, 2026
This is the official English translation. In the event of any discrepancy, the Korean version shall prevail.
RunnersLikeMe (hereinafter the “Company”) complies with the Personal Information Protection Act of Korea (PIPA), the Act on the Protection and Use of Location Information of Korea, and other applicable laws, and through this Privacy Policy informs users of the purposes for which and the manner in which their personal information is processed, and how it is protected.
This Privacy Policy applies to the services provided by the Company. For details on the processing of location information, please also refer to the Location-Based Services Terms of Use.
The Company processes personal information for the following purposes. Personal information being processed is not used for any purpose other than those stated below, and if the purpose of use changes, the Company takes necessary measures, such as obtaining separate consent, in accordance with Article 18 of the Personal Information Protection Act of Korea (PIPA).
Confirming the intent to register, identifying and authenticating members, age verification (blocking registration by children under the age of 14; applying minor-protection policies), verifying the consent of legal representatives of minor members, maintaining and managing membership, preventing fraudulent use of the service, delivering notices and notifications, and handling grievances
Providing search, viewing, and playback of courses and course guides; running host-guest matching; chat features; operating the review and rating system; managing the credit system; managing running records and running notes; and providing personalized services
Processing payments for paid course guides, managing purchase history, handling withdrawal of purchase (cooling-off) and refunds, settling curators' sales revenue, and tax processing (fulfilling statutory obligations such as withholding tax and submitting payment statements)
Preventing and sanctioning fraudulent use, handling reports and disputes, managing no-shows, detecting abnormal behavior and maintaining community safety, and cooperating with investigative authorities in the event of an incident
Providing information on events and advertisements, compiling and analyzing service usage statistics, and providing personalized recommendation services
| Category | Items Collected | Required/Optional |
|---|---|---|
| Registration (social login) | Social account identifier, email address, name, profile photo (if provided) | Required |
| Registration (common) | Phone number (SMS verification), date of birth (age verification) | Required |
| Registration by minor members | Legal representative's name, contact information, and consent verification information | Required (where applicable) |
| Onboarding (required) | Real name, profile photo, city of residence, languages spoken, average pace, preferred distances, preferred times | Required |
| Onboarding (optional) | One-line bio, LinkedIn URL, Instagram username, Garmin profile URL | Optional |
| Service use | Running records (distance, time, pace), course and course guide registration information, running notes, review content, chat messages, credit transaction history, report content | Required |
| Use of paid services | Purchase history, payment approval information (card issuer name, approval number, etc. — full card numbers are processed by the electronic payment gateway provider and are not stored by the Company) | Required (where applicable) |
| Curator settlement | Account holder name, bank name, account number, and information legally required for tax processing | Required (where applicable) |
| External service integration | Strava running statistics (total distance, run count) | Optional |
| Automatically collected | IP address, device information, browser type, access date and time, service usage records, cookies | Required |
| Location information | GPS-based location information, running routes, running locations | Optional (collected with consent; however, required for the use of location-based features such as running records and location-based course guides) |
Notice on sensitive information: The Company does not collect biometric measurement information relating to health (sensitive information) such as heart rate or blood pressure. Even when integrating external services (such as Strava), the Company receives only exercise statistics such as distance, run count, and pace, and health-related sensitive information is excluded from the received items. If the Company introduces a feature that requires the processing of sensitive information in the future, it will obtain separate consent in accordance with Article 23 of the Personal Information Protection Act of Korea (PIPA).
Children's personal information: The Company does not collect personal information from children under the age of 14. Any account confirmed to belong to a child under the age of 14 will be blocked from use without delay, and the information collected will be destroyed.
The Company destroys personal information without delay once the purpose of its collection and use has been achieved. However, the following information is retained for the periods specified below in accordance with applicable laws.
| Items Retained | Retention Period | Legal Basis |
|---|---|---|
| Records concerning contracts or withdrawal of purchase (cooling-off) | 5 years | Act on Consumer Protection in Electronic Commerce of Korea |
| Records concerning payment and the supply of goods, etc. | 5 years | Act on Consumer Protection in Electronic Commerce of Korea |
| Records concerning consumer complaints or dispute resolution | 3 years | Act on Consumer Protection in Electronic Commerce of Korea |
| Records concerning labeling and advertising | 6 months | Act on Consumer Protection in Electronic Commerce of Korea |
| Books and supporting documents for transactions under tax law | 5 years | Framework Act on National Taxes of Korea |
| Access records (login records, etc.) kept in preparation for the provision of communication confirmation data | 3 months | Protection of Communications Secrets Act of Korea |
| Records confirming the use and provision of location information | 6 months | Act on the Protection and Use of Location Information of Korea |
| Items Retained | Retention Period | Reason |
|---|---|---|
| Access logs of the personal information processing system (access records of administrators and handlers) | At least 1 year | Standards for Ensuring the Safety of Personal Information (notification of the Personal Information Protection Commission of Korea) |
| Records of fraudulent use (sanction history; minimum information for determining re-registration restrictions) | 1 year after the sanction ends | Prevention of repeated fraudulent use |
| Account information related to unpaid settlement amounts | Until payment is completed | Fulfillment of curator settlement obligations |
| Purchase records of paid course guides of withdrawn members (minimum information for restoring access rights) | 30 days after withdrawal | Restoration of access rights upon re-registration (Article 30(7) of the Terms of Service) |
The Company processes users' personal information within the scope of the purposes specified in Section 2 and does not provide it to third parties without the user's prior consent. However, the following cases are exceptions.
| Recipient | Items Provided | Purpose of Provision | Retention and Use Period |
|---|---|---|---|
| Matched counterpart member (host and guest) | Real name, profile photo, running-related information (pace, preferred distance, etc.), reviews and ratings, chat messages | In-person running matching and communication | For the duration of the matching relationship |
| Members purchasing paid course guides | Seller identification information such as the curator's nickname and profile | Fulfillment of the Company's obligation as a mail-order brokerage operator to provide seller identity information | For the transaction record retention period |
| Counterpart member in the event of a paid-transaction dispute | Identity information prescribed by Article 20(2) of the Act on Consumer Protection in Electronic Commerce of Korea, such as the curator's name and contact method | Consumer redress and dispute resolution | Until the dispute is resolved |
The Company outsources personal information processing tasks as follows to provide the service. When entering into outsourcing contracts, the Company stipulates the outsourcee's personal information protection obligations and supervises the outsourcee in accordance with Article 26 of the Personal Information Protection Act of Korea (PIPA).
| Outsourcee | Outsourced Tasks |
|---|---|
| Supabase, Inc. | Database hosting, user authentication, file storage |
| Vercel, Inc. | Website hosting |
| Google LLC | Social login (OAuth), sending verification and notification emails (Gmail SMTP), map services (Google Maps), push notifications (Firebase Cloud Messaging) |
| SOLAPI Co., Ltd. | Sending domestic SMS verification messages |
| Twilio Inc. | Sending international SMS verification messages |
| To be provided | Electronic payment gateway services (processing credit card and other payments) |
Some of the cloud infrastructure used by the Company is located outside the Republic of Korea. The Company transfers personal information abroad as follows, based on Article 28-8(1)3 of the Personal Information Protection Act of Korea (PIPA) (outsourcing or storage of personal information processing necessary for the conclusion and performance of a contract with the data subject, where the details are disclosed in this Privacy Policy).
| Recipient (Contact) | Destination Country | Items Transferred | Timing and Method of Transfer | Purpose of Use | Retention and Use Period |
|---|---|---|---|---|---|
| Supabase, Inc. (support@supabase.com) | To be provided | All collection items listed in Section 3 | Transmitted and stored over the network when the service is used | Database hosting, authentication, storage | Until membership withdrawal or termination of the outsourcing contract |
| Vercel, Inc. (privacy@vercel.com) | United States | Access records (IP address, device information, etc.) | Transmitted over the network when accessing the service | Website hosting and delivery optimization | Until termination of the outsourcing contract |
| Google LLC (googlekrsupport@google.com) | United States | Social login account information, email address, push tokens, map usage information | Transmitted over the network when the relevant feature is used | Social login, email delivery, maps, push notifications | Until membership withdrawal or termination of the outsourcing contract |
| Twilio Inc. (privacy@twilio.com) | United States | Phone number (limited to non-Korean numbers) | Transmitted over the network when SMS verification is requested | International SMS delivery | Until delivery processing is completed |
If a user does not wish their personal information to be transferred abroad, the user may refuse the transfer through the contact listed in Section 14. However, because the cross-border transfer concerns infrastructure essential to providing the service, refusing the transfer may make it impossible or restricted to use the service. When transferring personal information abroad, the Company implements protective measures under Article 28-8(4) of the Personal Information Protection Act of Korea (PIPA) (encrypted transmission, contractual safeguards with outsourcees, etc.).
In accordance with Article 37-2 of the Personal Information Protection Act of Korea (PIPA), the Company provides the following notice regarding cases in which automated systems are involved in decisions that affect users.
The Company implements the following measures in accordance with Article 29 of the Personal Information Protection Act of Korea (PIPA) and the Standards for Ensuring the Safety of Personal Information.
The Company also provides its service to users outside the Republic of Korea and provides the following notice.
The Company designates the following Chief Privacy Officer to oversee personal information processing and to handle data subjects' complaints and provide remedies.
Chief Privacy Officer
Users may submit any inquiries, complaints, or requests for remedies related to personal information arising from the use of the service to the contact above, and the Company will respond and process them without delay.
Users may apply to the following organizations for dispute resolution or consultation to obtain relief from personal information infringement.
| Organization | Contact | Website |
|---|---|---|
| Personal Information Infringement Report Center (KISA) | 118 (no area code) | privacy.kisa.or.kr |
| Personal Information Dispute Mediation Committee | 1833-6972 (no area code) | www.kopico.go.kr |
| Cyber Investigation Division, Supreme Prosecutors' Office | 1301 (no area code) | www.spo.go.kr |
| Cyber Investigation Bureau, Korean National Police Agency | 182 (no area code) | ecrm.police.go.kr |
| Version | Effective Date | Major Changes |
|---|---|---|
| v1.0 | 2026-01-26 | Initial enactment |
| v2.0 | 2026-02-06 | Wording revised |
| v4.0 | 2026-09-18 | Added cross-border transfer section; reflected outsourcing audit (corrected SMS and email delivery channels); added paid services and settlement items; added notice on automated decisions; added notice for overseas users (GDPR); reorganized safety measures into three categories; added provisions on children and sensitive information |
Effective Date: September 18, 2026