Amoring Legal Document

Amoring Privacy Policy

Effective Date: April 30, 2026

SocialPoint Co., Ltd. (hereinafter "Company") complies with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and the Act on the Protection and Use of Location Information, and establishes and discloses the following Privacy Policy to protect users' personal information and handle related grievances.

Article 1 (Categories of Personal Information Collected and Collection Methods)

1. Categories of Information Collected

① Required Information

Membership registration and identity verification: Name (nickname), date of birth, gender, mobile phone number, email address

Profile: Profile photo, self-introduction, occupation, interests

Payment: Apple/Google transaction ID, payment amount, payment date and time

② Optional Information

Additional profile details: Height, education, language, religion, smoking status, and other information voluntarily entered by the Member

Information provided by third-party platforms upon social login

③ Automatically Collected Information

Location data: Current GPS coordinates (during app use and in the background, when permission is granted)

Device information: Device identifier (IDFA/GAID), OS/app version, device model, carrier

Usage records: Access date and time, session duration, matching records, message send/receive records, click and browsing history

Behavioral data: Preferred profile characteristics, response rates, and overall in-app activity patterns

Technical information: IP address, cookies, advertising identifiers, push tokens

2. Collection Methods

Direct input by Member (during registration, profile setup, and payment)

Automatic collection during app use

Collection via identity verification services

Apple App Store / Google Play Store in-app purchase integration

Collection through third-party integrations (advertising networks, analytics tools, partner companies)

Article 2 (Purposes of Processing Personal Information)

The Company processes collected personal information for the following purposes. If purposes change, separate consent will be obtained in accordance with applicable law.

Membership registration and management: Identity verification, age verification, membership maintenance, fraud detection and prevention

Service provision: Location-based matching, GPS check-in, chat features, personalized content recommendations

Paid service operations: Payment and refund processing, Apple/Google refund verification

Service enhancement: Matching algorithm improvement, user behavior analysis, A/B testing, new feature development

Personalized marketing and advertising: Personalized ads, events, and offers based on user interests and behavioral data (with consent)

Third-party partnerships: Joint service improvement and research/analysis with partner companies (with consent)

Legal compliance: Record retention required by the Electronic Commerce Act and other laws; dispute resolution

De-identified data use: Aggregated statistics, market analysis, external publications — used without restriction in non-personally identifiable form

Article 3 (Retention Period of Personal Information)

The Company destroys personal information once the collection purpose is achieved. However, information is retained for the following specified periods:

① Retention Under Internal Company Policy

Records for fraud prevention and dispute resolution after account withdrawal: 3 years post-withdrawal

Customer inquiry and dispute records: 5 years

Matching and behavioral records (including de-identified data): Throughout the service operation period

② Retention Required by Applicable Law

Records of contracts and cancellation of purchases: 5 years (Electronic Commerce Act)

Records of payment and supply of goods/services: 5 years (Electronic Commerce Act)

Records of consumer complaints and dispute resolution: 3 years (Electronic Commerce Act)

Records of labeling and advertising: 6 months (Electronic Commerce Act)

Log records under the Protection of Communications Secrets Act: 3 months

③ De-identified Data

Data processed so that individuals cannot be identified is exempt from retention period requirements and may continue to be used for service improvement, statistical analysis, and research purposes.

Article 4 (Provision of Personal Information to Third Parties)

The Company does not, in principle, provide users' personal information to third parties. However, exceptions apply in the following cases:

Where the user has given prior consent

Where required by law or lawfully requested by investigative authorities for criminal investigation, trial, or administrative proceedings

Where Apple Inc. requests transaction information for refund verification purposes (limited to the relevant transaction data)

Where necessary for collaboration with partner companies for service provision (with separate consent)

In connection with corporate restructuring events such as mergers, spin-offs, or business transfers (with prior notice to users)

Even in the above cases, the Company minimizes the scope of information provided, limited to what is necessary for the stated purpose.

Article 5 (Entrustment of Personal Information Processing)

The Company entrusts personal information processing tasks as follows to ensure smooth service provision:

SubcontractorTasks EntrustedRetention Period
[Identity Verification Provider] — To be updated upon confirmationIdentity verificationUntil purpose is achieved
Apple Inc. / Google LLCIn-app payment processingPer each company's policy
Amazon Web ServicesServer operation and data storageUntil service termination
[Push Notification Provider] — To be updated upon confirmationPush notification deliveryUntil purpose is achieved
[Analytics Tool Provider] — To be updated upon confirmationService usage analysis and A/B testingUntil purpose is achieved
[Ad Network Provider] — To be updated upon confirmationPersonalized ad deliveryUntil purpose is achieved

Article 6 (Processing of Location Information)

The Company processes users' personal location information in accordance with the Act on the Protection and Use of Location Information.

Purposes: Location-based matching, GPS check-in, discovery of nearby Members, location-based marketing (with consent)

By granting location access permissions within the app, users are deemed to have consented to the collection of their personal location information.

Users may revoke location access through their device settings; however, doing so will limit access to all location-based features.

The Company does not provide personal location information to third parties without user consent. However, aggregated and de-identified location data may be used without restriction for service improvement, commercial area analysis, and external research.

Records of location information use and provision are retained for 6 months in accordance with the Act on the Protection and Use of Location Information.

Article 7 (Destruction of Personal Information)

The Company destroys personal information without delay once the retention period has elapsed or the processing purpose has been achieved.

Electronic files are permanently deleted using methods that prevent recovery. Paper documents are shredded.

Personal information that must be retained under applicable law is stored separately and is not used for any other purpose.

De-identified data is exempt from destruction obligations and may continue to be used.

Article 8 (Rights of Data Subjects and How to Exercise Them)

Users may exercise the following rights at any time:

Request access to personal information

Request correction of errors

Request deletion (excluding information subject to mandatory retention under applicable law)

Request suspension of processing (note: suspension may restrict access to the Service)

Rights may be exercised via email (contact@amoring.info) or through in-app Settings > Privacy Management. The Company will take action within 10 days of receipt.

Notwithstanding a request to suspend processing, the Company may refuse such a request where grounds for refusal exist under Article 37(2) of the Personal Information Protection Act.

If a user requests deletion of their personal information, access to the Service may become immediately unavailable. The Company bears no liability for any resulting disadvantages, including the expiration of remaining paid items.

Article 9 (Installation and Operation of Automatic Data Collection Devices and Opt-Out)

The Company uses cookies, SDKs, and advertising identifiers (IDFA/GAID) to provide personalized services and optimize advertising.

Users may restrict ad tracking (e.g., by declining ATT prompts) through their device settings. However, doing so may limit personalized features and certain functionalities.

Aggregated analytical data processed in de-identified form will be collected and used regardless of advertising tracking preferences.

Article 10 (Measures to Ensure the Security of Personal Information)

The Company implements the following technical, administrative, and physical measures to ensure security pursuant to Article 29 of the Personal Information Protection Act:

Administrative measures: Establishment and implementation of internal management plans, regular employee training, minimization of access privileges

Technical measures: Encrypted storage and transmission (TLS), access control systems, anomaly detection

Physical measures: Access controls for server rooms

Article 11 (Privacy Officer)

The Company designates a Privacy Officer to oversee personal information processing and handle user complaints and remedies:

▶ Privacy Officer

Name: Hyun Taejun / Title: Representative Director

Contact: contact@amoring.info

Article 12 (Requesting Access to Personal Information)

Requests for access to personal information pursuant to Article 35 of the Personal Information Protection Act may be submitted to contact@amoring.info. The Company will process such requests within 10 days of receipt.

Article 13 (Remedies for Infringement of Rights)

Users may contact the following organizations to seek remedies for personal information infringement:

Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972

Personal Information Infringement Report Center: privacy.kisa.or.kr / 118

Supreme Prosecutors' Office Cyber Investigation Division: www.spo.go.kr / 1301

National Police Agency Cyber Investigation Bureau: cyberbureau.police.go.kr / 182

Article 14 (Amendments to Privacy Policy)

This Privacy Policy is effective as of April 30, 2026.

For material changes, notice will be given at least 30 days in advance; for other changes, at least 7 days in advance.

If a user does not raise an objection by the effective date stated in the notice, the user is deemed to have consented to the amended policy.

Previous versions of this Privacy Policy are available in the in-app notice section.

Supplementary Provisions

Company Name: SocialPoint Co., Ltd.

Representative Director: Hyun Taejun

Address: 302-Q05, 60 Jangji 1-gil, Gwangju-si, Gyeonggi-do, Republic of Korea

Privacy Inquiries: contact@amoring.info