개인정보 처리방침
1. 수집하는 개인정보 항목
① 계정: 이메일, 닉네임/이름, 소셜 로그인(카카오, 구글, 애플) 식별자 및 연동 정보. ② 프로필: 성별, 나이, 체중, 국적, 지역, 소속(체육관), 자기소개, 프로필/배너 이미지(선택). ③ 활동: 운동 기록, 인증 영상 링크, 피드, 댓글, 리뷰, 지도 핀, 업적, 팔로우 관계. ④ 결제: 스토어가 제공하는 검증된 거래 식별자, 구매 이력(카드번호 등 민감 결제정보는 회사가 수집/저장하지 않음). ⑤ 기기/기술: 기기 지역 설정(국적 기본값), 앱 이용 기록 등. ⑥ 건강, 운동 데이터(선택): 이용자가 건강 연동을 켠 경우에 한해 걸음 수, 심박수, 운동(러닝) 기록과 그 경로를 읽습니다(2-2 참고). ⑦ 위치정보(선택): 정확한 위치/대략적인 위치를 이용자의 허용 하에 수집합니다(2-1 참고). ⑧ 체육관 회원권: 실제 체육시설의 회원권 종류, 이름, 시작일, 종료일, 총 이용 횟수, 잔여 횟수, 홀딩 기간, 가입, 연장, 홀딩 신청 및 처리 상태. ⑨ 수업 예약, 출석: 계정, 체육관, 수업, 예약, 출석 식별자, 수업 날짜, 시간, 예약, 취소 내역과 시각, 수업별 출석 시각, 회원권 이용 횟수 차감 및 잔여 횟수 정보.
2. 이용 목적
회원 식별, 인증, 기록, 랭킹, 소셜, 지도 기능 제공, 실제 체육시설의 회원권 관리, 수업 이용 자격 확인, 예약, 취소, 출석 처리와 관련 알림 제공, 결제, 구독, 쿠폰 처리, 부정 이용, 제재 대응, 고객 문의 응대, 서비스 개선, 통계.
2-1. 위치정보의 수집, 이용
① 러닝 기록: 러닝 경로, 거리, 페이스를 기록하기 위해 위치정보를 수집합니다. 러닝을 기록하는 동안에는 화면이 꺼져 있거나 다른 앱을 사용할 때에도 위치정보를 수집합니다. 이 수집은 이용자가 러닝을 시작한 경우에만 이루어지고 러닝을 마치면 즉시 중단되며, 러닝 기록 외의 목적으로는 사용하지 않습니다. 앱은 '항상 허용'(백그라운드 위치) 권한을 요청하지 않으며, 러닝 중 Android에서는 위치 수집 중임을 알리는 알림이, iOS에서는 위치 사용 표시가 나타납니다. ② 주변, 지도 기능: 앱 사용 중 주변 체육관, 지도 핀 표시, 지도 중심 설정, 위치 기반 게임 방 찾기에 현재 위치를 사용합니다. ③ 국가 판별: 현재 위치로 국가를 판별해 국가별 랭킹, 국기 업적에 반영하며, 판별된 국가만 프로필에 저장합니다. ④ 저장: 러닝 경로 좌표는 이용자 기기에 저장되며(최근 기록 일부), 이용자가 러닝 기록을 피드에 게시하면 경로가 그려진 이미지가 게시물로 저장됩니다. 이용자가 직접 등록한 지도 핀 및 위치 기반 게임 방의 좌표는 서버에 저장됩니다. ⑤ 제공: 러닝 경로 지도 이미지 생성과 지도, 지오코딩을 위해 좌표가 Google Maps Platform에 전송될 수 있습니다. 위치정보는 광고, 마케팅에 사용되거나 판매되지 않습니다. ⑥ 거부/철회: 위치 권한은 선택 사항이며, 거부해도 위치 기능을 제외한 서비스는 이용할 수 있습니다. 기기 설정에서 언제든 권한을 변경/철회할 수 있습니다. ⑦ GPS 출석: 이용자가 체육관 출석을 직접 요청하면 현재 위치 좌표와 위치 정확도를 Supabase 서버로 전송해 체육관 주변의 허용 반경 안에 있는지 확인합니다. 원본 GPS 좌표는 출석 기록에 저장하지 않으며, 계정, 체육관, 수업 식별자, 출석 날짜, 시각, 체육관과의 거리(미터), 위치 정확도(미터)는 출석 정보로 저장합니다.
2-2. 건강, 운동 데이터 및 웨어러블(워치) 연동
① 연동 경로: iOS에서는 Apple 건강(HealthKit), Android에서는 Health Connect(헬스 커넥트)를 통해 연동합니다. Apple Watch, 갤럭시 워치(Samsung Health), 가민(Garmin Connect) 등 웨어러블 기기, 앱이 Apple 건강 또는 Health Connect에 기록한 데이터도 같은 방식으로 읽습니다. 회사는 가민 등 기기 제조사의 서버 API를 통한 직접 연동은 하지 않으며, 이용자 휴대폰의 Apple 건강, Health Connect에 동기화된 데이터만 기기에서 읽습니다. 다른 앱(Samsung Health, Garmin Connect 등)이 기록한 운동 경로는 Android에서 운동마다 Health Connect의 경로 공유 동의를 받은 경우에만 읽습니다. 다른 연동 방식을 제공하게 되면 수집 항목과 처리 방식을 시행 전에 본 방침에 추가로 고지합니다. ② 읽는 데이터(읽기 전용): 걸음 수, 심박수, 운동(러닝) 기록(시작, 종료 시각, 거리, 운동 시간, 운동 경로). 앱은 건강 데이터를 기록하거나 수정하지 않습니다. ③ 이용 목적: (가) 홈 화면에 오늘 걸음 수와 연동 이후 누적 걸음 수 표시, (나) 걸음 수, 최대 심박수 업적의 진행도 표시 및 해금, (다) 휴대폰 없이 워치로만 기록한 러닝을 이용자 확인 후 앱의 러닝 기록으로 가져와 운동 경로(GPS 좌표)대로 지도에 경로를 그리기. ④ 처리, 저장: 걸음 수, 심박수는 화면 표시와 업적 판정을 위해 앱 실행 중에만 기기 안에서 집계하며, 그 수치는 기기나 회사 서버에 저장/전송하지 않고 필요할 때마다 건강 앱에서 다시 읽습니다. 회사 서버에는 해금된 업적 항목과 건강 연동 시작 시점(날짜)만 저장됩니다. 가져온 러닝 기록(시각, 거리, 시간, 경로 좌표)은 이용자 기기의 러닝 기록에 저장되며, 지도 배경 이미지를 만들 때 경로 좌표가 Google Maps Platform에 전송될 수 있습니다. 이용자가 피드에 게시한 경우에만 게시 내용(경로가 그려진 이미지, 경로 모양, 거리, 시간)이 서버에 저장됩니다. ⑤ 제한적 사용: 건강 데이터는 위 목적에만 사용하며, 광고, 마케팅에 사용하거나 판매/제3자 제공하지 않고, 신용/보험/고용 등 자격 판단에 사용하지 않습니다. 이용자의 동의, 보안 목적, 법령상 의무가 있는 경우를 제외하고 사람이 열람하지 않습니다. Health Connect로 받은 데이터의 사용은 Health Connect 권한 정책(제한적 사용 요건 포함)을 따르며, HealthKit 데이터는 iCloud에 저장하지 않습니다. ⑥ 거부/철회: 건강 연동은 선택 사항이며, 앱 설정에서 언제든 끌 수 있습니다. 권한은 iOS 설정 > 건강 > 데이터 접근 및 기기, Android Health Connect 앱 > 앱 권한에서 철회할 수 있습니다.
3. 보관 및 파기
목적 달성 또는 회원 탈퇴 시 지체 없이 파기합니다. 계정 삭제 시 결제, 구독 거래 증빙(거래 식별자, 상품, 스토어, 결제, 만료일, 금액, 통화 등 필요한 거래 정보)만 거래일부터 5년간 분리 보관합니다. 프로필, 운동 기록, 사진은 거래 증빙에 포함하지 않으며, 보관 기간이 지난 증빙은 일일 자동 정리 작업으로 삭제합니다.
4. 제3자 처리, 위탁
① 백엔드, 인증, 저장: Supabase. ② 인앱 결제, 영수증 검증: Apple App Store, Google Play(및 결제 검증 제공자 RevenueCat). ③ 소셜 로그인: 카카오, 구글, 애플. ④ 지도, 지오코딩: Google Maps Platform. 위 사업자는 각자의 개인정보 정책에 따라 처리하며, 회사는 서비스 제공에 필요한 최소 범위로만 연동합니다. ⑤ 체육관 운영: 체육관 소유자 및 권한을 부여받은 매니저는 해당 체육관 회원의 회원권, 신청, 예약, 취소, 출석 정보를 부여된 관리 권한 범위에서 조회, 처리합니다. 이 정보는 해당 체육관의 회원권 관리, 수업 운영, 예약, 출석 확인 및 관련 알림에 이용됩니다.
5. 이용자 권리
이용자는 자신의 개인정보 열람, 정정, 삭제, 처리정지 및 동의 철회(탈퇴)를 요청할 수 있습니다. 앱 내 [프로필] 또는 웹 계정 삭제(aboardfit.com/delete-account.html)에서 직접 삭제할 수 있습니다. 웹에서는 등록된 이메일 인증과 최종 확인 후 삭제하며, 위에 안내한 거래 증빙만 보관합니다.
6. 아동/미성년자
미성년자의 결제는 법정대리인의 동의가 필요할 수 있으며, 관련 법령에 따른 보호 조치를 적용합니다.
7. 보안
전송 구간 암호화, 접근 권한 통제(RLS) 등 합리적 보호조치를 적용합니다. 다만 인터넷 전송의 절대적 안전은 보장되지 않습니다.
8. 문의 및 개인정보 보호책임자
개인정보 관련 문의, 권리 행사는 앱 내 문의 또는 아래 개인정보 보호책임자에게 접수할 수 있습니다. - 개인정보 보호책임자: 조은우(대표) - 이메일: aboardfit@naver.com - 전화: 010-9703-3740
Privacy Policy
1. Personal Data We Collect
① Account: email, nickname/name, social login (Kakao/Google/Apple) identifier and linkage info. ② Profile: gender, age, weight, nationality/region, affiliation (gym), bio, profile/banner image (optional). ③ Activity: workout records and verification-video links, feed/comments/reviews, map pins, achievements, following relationships. ④ Payments: verified transaction identifiers and purchase history provided by the store (sensitive payment data such as card numbers is not collected or stored by the Company). ⑤ Device/technical: device region setting (default nationality), app usage logs, etc. ⑥ Health & fitness data (optional): only if you turn on health sync, we read step count, heart rate, and workout (running) records with their routes (see 2-2). ⑦ Location (optional): precise and approximate location, collected with your permission (see 2-1). ⑧ Gym memberships: membership type/name at a physical gym, start/end dates, total and remaining visit counts, hold periods, membership enrollment/renewal/hold requests and their status. ⑨ Class bookings and attendance: account, gym, class, booking and attendance identifiers; class dates/times; booking/cancellation records and timestamps; per-class check-in timestamps; membership visit deductions and remaining counts.
2. Purpose of Use
Member identification/authentication; providing record, ranking, social, and map features; managing physical gym memberships, checking class eligibility, processing bookings, cancellations and attendance, and providing related notifications; processing payments, subscriptions, and coupons; responding to fraud and sanctions; handling customer inquiries; service improvement and statistics.
2-1. Collection and Use of Location Data
① Run tracking: location data is collected to record your running route, distance and pace. While a run is being recorded, location data is collected even when the screen is off or you are using other apps. This collection happens only after you start a run, stops as soon as you finish the run, and is not used for any purpose other than run tracking. The app does not request "Allow all the time" (background location) access. During a run, Android shows a notification that location is being collected, and iOS shows its location-in-use indicator. ② Nearby & map features: while you use the app, your current location is used to show nearby gyms and map pins, center the map, and find location-based game rooms. ③ Country detection: your current location is used to determine your country for country rankings and flag achievements; only the detected country is saved to your profile. ④ Storage: run route coordinates are stored on your device (a few recent runs). If you post a run to the feed, an image with the route drawn on it is stored as the post. Coordinates of map pins you register and location-based game rooms you create are stored on our servers. ⑤ Sharing: coordinates may be sent to Google Maps Platform to render run-route map images and for maps/geocoding. Location data is never used for advertising or marketing, and is never sold. ⑥ Opting out: location access is optional; you can use the service except location features without it. You can change or revoke the permission at any time in your device settings. ⑦ GPS check-in: when you request a gym check-in, your current coordinates and location accuracy are sent to the Supabase server to verify that you are within the allowed radius of the gym. Raw GPS coordinates are not stored in the attendance record. Account, gym and class identifiers, check-in date/time, distance from the gym (meters), and location accuracy (meters) are stored as attendance information.
2-2. Health & Fitness Data and Wearable (Watch) Integration
① How we connect: on iOS through Apple Health (HealthKit), and on Android through Health Connect. Data that wearables and their apps—such as Apple Watch, Galaxy Watch (Samsung Health) and Garmin (Garmin Connect)—write to Apple Health or Health Connect is read the same way. We do not connect directly to device makers’ server APIs (such as Garmin’s); we only read, on your device, data synced to Apple Health or Health Connect on your phone. On Android, workout routes recorded by other apps (such as Samsung Health or Garmin Connect) are read only after you approve route sharing for that workout in Health Connect. If we add another integration method, we will update this policy with the data collected and how it is handled before it takes effect. ② Data we read (read-only): step count, heart rate, and workout (running) records (start/end time, distance, duration, workout route). The app never writes or modifies health data. ③ Purpose: (a) showing today's step count and your cumulative steps since you connected on the home screen, (b) showing progress toward and unlocking step and maximum-heart-rate achievements, and (c) after you confirm, importing runs recorded on your watch without your phone into the app's run history and drawing them on the map along their workout route (GPS coordinates). ④ Processing & storage: step count and heart rate are tallied on your device only while the app is running, for display and achievement checks. These values are never stored on your device or sent to or stored on our servers; they are read again from the health app whenever needed. Our servers store only the achievements you have unlocked and the date you started health sync. Imported runs (start/end time, distance, duration, route coordinates) are stored in the run history on your device, and route coordinates may be sent to Google Maps Platform to render a map background image. Only if you post a run to the feed is the post content (image with the route drawn on it, route shape, distance, time) stored on our servers. ⑤ Limited use: health data is used only for the purposes above. It is never used for advertising or marketing, never sold or shared with third parties, and never used to determine eligibility for credit, insurance or employment. No person reads it except with your consent, for security purposes, or where required by law. Use of data received from Health Connect complies with the Health Connect Permissions policy, including the Limited Use requirements, and HealthKit data is never stored in iCloud. ⑥ Opting out: health sync is optional and can be turned off at any time in the app settings. You can revoke access in iOS Settings > Health > Data Access & Devices, or in the Android Health Connect app > App permissions.
3. Retention & Destruction
Data is destroyed without delay once its purpose is achieved or upon account deletion. Only payment/subscription transaction evidence (transaction identifiers, product, store, purchase/expiry dates, price/currency and necessary transaction details) is retained separately for five years from the transaction. Profiles, workout records and photos are not retained as transaction evidence. Expired evidence is deleted by a daily cleanup task.
4. Third-Party Processing & Outsourcing
① Backend/authentication/storage: Supabase. ② In-app payments & receipt verification: Apple App Store / Google Play (and the payment-verification provider RevenueCat). ③ Social login: Kakao, Google, Apple. ④ Maps & geocoding: Google Maps Platform. The above providers process data under their own privacy policies, and the Company integrates only to the minimum extent necessary to provide the service. ⑤ Gym operations: gym owners and authorized managers can access and process their gym members’ membership, request, booking, cancellation and attendance information within their assigned management permissions. This information is used for that gym’s membership management, class operations, booking/attendance verification and related notifications.
5. User Rights
Users may request access, correction, deletion, restriction of processing, or withdrawal of consent. Delete your account in the app under [Profile] or on the account deletion webpage (aboardfit.com/delete-account.html). The web flow verifies your registered email and requires final confirmation. Only the transaction evidence described above is retained.
6. Children & Minors
Payments by minors may require the consent of a legal guardian, and protective measures under applicable law are applied.
7. Security
Reasonable safeguards such as in-transit encryption and access control (RLS) are applied. However, absolute security of internet transmission cannot be guaranteed.
8. Inquiries & Data Protection Officer
Privacy inquiries and exercise of rights can be submitted through in-app inquiry or to the data protection officer below. - Data protection officer: Eunwoo Jo (조은우), CEO - Email: aboardfit@naver.com - Phone: +82 10-9703-3740
