오늘의배달(Rider One) 개인정보처리방침
시행일: 2026년 9월 22일
버전: 1.2.0
운영자·개인정보 보호책임자: 봄 스튜디오 대표 김태수, help@bomstudio.co.kr
정본: https://riderone.bomstudio.co.kr/privacy
이전 방침: https://riderone.bomstudio.co.kr/privacy/history
1. 적용 범위와 서비스 상태
이 방침은 봄 스튜디오가 제공하는 오늘의배달 앱과 위 법률 사이트에서 처리하는 개인정보에 적용됩니다. 핵심 퍼즐, 기기 내 프로필과 진행은 별도 앱 계정 없이 이용할 수 있습니다.
계정·원격 랭킹·Daily 제출·원격 콘텐츠·원격 지갑은 해당 기능을 실제로 제공하는 앱 버전에서만 처리됩니다. 2026년 9월 22일 현재 AWS 계정 서비스는 공개 서비스 범위에 포함되어 있지 않으며, 공개 서비스는 새 AWS 계정·원격 제출을 만들지 않습니다. 이 기능을 제공하는 배포본은 실제 처리 항목, 공개 범위, 보유 기간과 삭제 절차를 확정한 방침을 먼저 안내합니다.
2. 처리하는 정보와 목적
- 기기 내 게임: 닉네임·선택 라이더, 퍼즐 경로·완료·진행·연속 기록, 난이도·효과음·진동·광고 개인정보·알림·분석 선택, 충돌 및 재시도에 필요한 실행 정보를 기기 전용 저장소에 보관합니다. 게임과 설정을 유지하는 데 사용하며, 로컬 닉네임과 대표 라이더를 외부 분석 도구나 공개 랭킹에 보내지 않습니다.
- Google Play Games: Android에서 이용자가 연결하면 Google Play Games의 Player ID, 인증 상태와 일회성 서버 인증 코드가 플랫폼 연결 확인에 사용될 수 있습니다. 인증 코드와 접근 토큰은 확인·교환 뒤 앱이나 서비스 서버에 보관하지 않습니다. 플랫폼 표시 이름과 사진은 공개 랭킹 별칭으로 사용하지 않습니다.
- 이전 원격 계정: 2026년 9월 6일 이전 또는 당시의 원격 계정 기능을 사용한 경우, 계정 식별 정보, 연결 제공자 정보, 제공자가 동의 범위에서 전달한 계정 정보, 서버 생성 공개 별칭·아바타, 랭킹·Daily 기록이 남아 있을 수 있습니다. 해당 버전의 정확한 처리자, 항목, 공개 범위와 국외 이전 정보는 이전 방침 전문에서 확인할 수 있습니다.
- 광고와 동의 관리: Google Mobile Ads와 User Messaging Platform(UMP)은 광고 요청·노출·상호작용, 동의 상태, IP 주소, 앱·기기 정보, 광고 ID 또는 유사 식별자를 광고 제공·동의 관리·부정 이용 방지에 처리할 수 있습니다. 실제 광고 단위와 처리 범위는 배포 버전, 이용 지역 및 이용자의 선택에 따릅니다.
- Android 원격 푸시: 이용자가 앱에서 켜고 운영체제 권한을 허용하면 Firebase Cloud Messaging·Installations가 FCM 토큰, Installation ID, 언어별 주제 구독, 권한·설정과 앱·기기·네트워크 정보를 알림 전달에 처리할 수 있습니다. 운영자는 토큰을 자체 계정 서버에 저장해 개인별 발송에 사용하지 않습니다.
- 앱 업데이트·오류 진단: Firebase Remote Config·Installations는 최소 지원 버전 확인에 필요한 설치·앱·기기·네트워크 정보를 처리할 수 있습니다. Android 출시 빌드에서는 Firebase Crashlytics와 Sentry가 오류·ANR·스택·기기·앱 버전 등 진단 정보를 처리할 수 있습니다. 앱은 이 진단 경로의 사용자 식별자나 맞춤 값에 닉네임, 계정 식별자, 인증 토큰, 퍼즐 경로, 알림 내용 또는 임의 입력을 넣지 않습니다.
- 사용량 분석: 분석 기능이 포함된 배포본에서는 이용자가 앱에서 명시적으로 동의한 경우에만 Firebase Analytics·Google Analytics 4에 화면·게임 결과·선택 동작 등의 집계 이벤트를 전송합니다. 동의 전에는 수집을 켜지 않으며, 설정에서 철회할 수 있습니다.
- 웹사이트와 문의: Cloudflare는 이 법률 사이트 제공 중 IP 주소, 요청 시각, User-Agent 같은 표준 접속 정보를 처리할 수 있습니다. 지원 이메일에는 이용자가 보낸 내용과 회신에 필요한 연락처가 포함될 수 있습니다.
3. 외부 제공자와 국외 처리
기능 제공에 필요한 서비스 제공자는 아래 정보의 범위에서 개인정보를 처리할 수 있습니다. 각 항목은 해당 기능을 이용하거나 진단·웹 접속이 발생한 때 HTTPS/TLS로 전송되며, 제공자가 정한 서비스별 보존 설정과 정책이 적용됩니다.
- Google LLC(미국 등 Google 데이터센터 소재 국가): Play Games, Google Mobile Ads·UMP, Firebase Analytics·Cloud Messaging·Remote Config·Crashlytics를 제공합니다. 플랫폼·설치·기기·앱 정보, 분석 이벤트, 광고·동의 정보, 오류 진단 정보 및 알림 등록 정보가 각 기능의 제공, 보안 및 품질 개선에 사용될 수 있습니다. 정책: https://policies.google.com/privacy
- Functional Software, Inc. / Sentry(미국): Android 출시 빌드의 오류 이벤트 식별자, IP 주소, 기기·운영체제·앱 버전, 오류 스택과 제한된 진단 기록을 장애·성능 진단에 처리할 수 있습니다. 보유 기간은 Sentry 프로젝트의 실제 설정과 계약에 따릅니다. 정책: https://sentry.io/privacy/
- Cloudflare, Inc.(미국 및 글로벌 네트워크 거점): 법률 사이트 접속 시 IP 주소, 요청 시각, 브라우저·기기 정보를 웹 제공·보안·장애 대응에 처리할 수 있습니다. 보유 기간은 Cloudflare의 로그 보존 설정과 정책에 따릅니다. 정책: https://www.cloudflare.com/privacypolicy/
- 이전 원격 계정 제공자(싱가포르): 이전 버전에서 계정 인증과 원격 랭킹을 제공했습니다. 그 제공자의 정확한 명칭, 처리 항목, 이전 시점과 보유 기준은 2026년 9월 6일 방침 전문에 보존되어 있습니다.
AWS 계정 서비스는 공개 서비스에서 아직 개인정보를 처리하지 않습니다. 이를 포함한 앱 버전을 제공하기 전에는 실제 운영 지역, 수탁자, 처리 항목, 보유·파기 기준과 계정·데이터 삭제 결과를 이 방침에 반영합니다.
4. 보유 기간과 삭제
기기 내 프로필·진행·설정은 앱 데이터가 유지되는 동안 보관되며, 앱 데이터 삭제 또는 앱 제거로 지울 수 있습니다. 알림을 끄면 앱은 주제 구독 해제와 FCM 토큰·Firebase Installation ID 삭제를 요청합니다. 이미 외부 제공자에게 전송된 광고·진단·알림 정보는 각 제공자의 정책과 이용자 설정에 따라 처리됩니다.
이전 원격 계정·인증 연결 정보와 관련 게임·랭킹 기록은 본인 확인을 거친 계정 및 데이터 삭제 요청의 처리까지 보관합니다. 법령상 보존 의무가 있는 정보와 제한된 장애 복구 백업은 필요한 목적·기간 동안 접근을 제한해 별도로 남을 수 있습니다. 지원 문의 내용은 문의·권리 행사 요청을 처리하고 법령상 필요한 기간 동안만 보관합니다.
앱 데이터 삭제나 앱 제거는 기기 안의 자료만 지우며, 이미 만들어진 이전 원격 계정과 기록을 자동으로 삭제하지 않습니다. 이전 원격 계정 또는 특정 원격 데이터의 삭제·열람·정정·처리정지는 https://riderone.bomstudio.co.kr/account-deletion 또는 help@bomstudio.co.kr 로 요청할 수 있습니다.
5. 이용자의 선택과 권리
이용자는 온라인 기능을 사용하지 않고 기본 퍼즐을 이용할 수 있습니다. 광고 개인정보 선택과 알림 권한은 앱 또는 운영체제 설정에서 변경할 수 있습니다. 분석 기능이 제공되는 배포본에서는 동의 선택과 철회 경로를 앱에서 제공합니다.
개인정보의 열람·정정·삭제·처리정지나 동의 철회, 이전 계정의 삭제 요청은 help@bomstudio.co.kr 로 접수할 수 있습니다. 다른 이용자의 자료가 삭제되지 않도록 최소한의 본인 확인을 요청할 수 있으나, 비밀번호, Play Games 인증 코드·토큰 또는 광고 ID 원문을 이메일로 요구하지 않습니다. 접수 뒤에는 처리 대상, 추가 확인 사항과 결과 또는 제한 사유를 이메일로 안내합니다.
6. 아동과 안전성
앱은 생년월일이나 보호자 연락처를 직접 입력받지 않습니다. 만 14세 미만 이용자의 개인정보 처리에 법정대리인 동의가 필요한 기능을 제공하기 전에는 필요한 절차를 마련합니다. 앱은 HTTPS 통신, 기능별 접근 통제와 필요한 정보만 처리하는 방식을 사용합니다.
7. 변경 이력과 문의
서비스 기능, SDK 또는 법령의 변경으로 처리 내용이 달라지면 이 방침의 내용과 시행일을 갱신하고 적절한 경로로 알립니다. 2026년 9월 6일 방침은 https://riderone.bomstudio.co.kr/privacy/history 에서 확인할 수 있습니다. 개인정보 및 데이터 삭제 문의: help@bomstudio.co.kr
Rider One Privacy Policy
Effective date: September 22, 2026
Version: 1.2.0
Operator and Privacy Officer: Bom Studio, Representative Taesu Kim, help@bomstudio.co.kr
Canonical version: https://riderone.bomstudio.co.kr/privacy
Previous policies: https://riderone.bomstudio.co.kr/privacy/history
1. Scope and Service Status
This Policy applies to personal information processed through the Rider One app provided by Bom Studio and through this legal website. The core puzzle, on-device profile, and progress can be used without a separate app account.
Accounts, remote leaderboards, Daily submissions, remote content, and remote wallets are processed only in app versions that actually provide those features. As of September 22, 2026, the AWS account service is not included in the public service, and the public service does not create new AWS accounts or remote submissions. Before any release provides those features, a policy reflecting the actual data processed, public exposure, retention period, and deletion procedures will be provided.
2. Information Processed and Purposes
- On-device game data: nickname and selected rider, puzzle routes, completion and progress records, streaks, difficulty, sound, vibration, advertising-privacy, notification and analytics choices, and runtime information needed for crash handling and retries are stored in app-specific device storage. They are used to maintain the game and settings. Local nicknames and representative riders are not sent to external analytics tools or public leaderboards.
- Google Play Games: when a user connects on Android, the Google Play Games Player ID, authentication status, and one-time server auth code may be used to verify the platform connection. Auth codes and access tokens are not retained by the app or service server after verification or exchange. Platform display names and photos are not used as public leaderboard aliases.
- Previous remote accounts: if a user used the remote-account features on or before September 6, 2026, account identifiers, connected-provider information, account information provided within the provider's consent scope, server-generated public aliases and avatars, and leaderboard or Daily records may remain. The exact processor, data fields, public exposure, and international-transfer information for that version are preserved in the previous policy.
- Advertising and consent management: Google Mobile Ads and User Messaging Platform (UMP) may process ad requests, impressions and interactions, consent status, IP address, app and device information, advertising IDs or similar identifiers for ad delivery, consent management, and fraud prevention. Actual ad units and processing scope depend on the release version, user region, and user choices.
- Android remote push notifications: when enabled in the app and permitted by the operating system, Firebase Cloud Messaging and Installations may process an FCM token, Installation ID, language-topic subscriptions, permission and settings information, and app, device, and network information to deliver notifications. The operator does not store the token on its own account server for individualized messaging.
- App updates and diagnostics: Firebase Remote Config and Installations may process installation, app, device, and network information needed to check minimum supported versions. Android release builds may use Firebase Crashlytics and Sentry to process errors, ANRs, stack traces, device and app-version information, and other diagnostic data. The app does not place nicknames, account identifiers, auth tokens, puzzle routes, notification contents, or free-form user input into user identifiers or custom values on those diagnostic paths.
- Usage analytics: in builds that include analytics, aggregated events such as screens, game results, and selected actions are sent to Firebase Analytics / Google Analytics 4 only after the user explicitly consents in the app. Collection is not enabled before consent and can be withdrawn in settings.
- Website and support: while serving this legal website, Cloudflare may process standard access information such as IP address, request time, and User-Agent. Support emails may contain information submitted by the user and contact details needed to reply.
3. External Providers and International Processing
Service providers required for app functions may process personal information within the following scope. Data is transmitted over HTTPS/TLS when the relevant function is used or when diagnostics or web access occurs, and each provider's service-specific retention settings and policies apply.
- Google LLC (United States and other countries where Google data centers are located): provides Play Games, Google Mobile Ads and UMP, Firebase Analytics, Cloud Messaging, Remote Config, and Crashlytics. Platform, installation, device and app information, analytics events, advertising and consent information, diagnostics, and notification-registration information may be used to provide, secure, and improve the relevant services. Policy: https://policies.google.com/privacy
- Functional Software, Inc. / Sentry (United States): may process error-event identifiers, IP address, device, operating-system and app-version information, error stacks, and limited diagnostic records from Android release builds for reliability and performance diagnostics. Retention follows the actual Sentry project settings and agreement. Policy: https://sentry.io/privacy/
- Cloudflare, Inc. (United States and global network locations): may process IP address, request time, browser and device information when this legal site is accessed for website delivery, security, and incident response. Retention follows Cloudflare log settings and policy. Policy: https://www.cloudflare.com/privacypolicy/
- Previous remote-account provider (Singapore): provided account authentication and remote leaderboards in an earlier version. The provider's exact name, processed data, transfer timing, and retention basis are preserved in the September 6, 2026 policy.
The AWS account service does not yet process personal information in the public service. Before an app version using it is released, this Policy will be updated to reflect the actual operating region, processors, processed data, retention and deletion rules, and account/data deletion results.
4. Retention and Deletion
On-device profile, progress, and settings remain while app data is retained and can be removed by clearing app data or uninstalling the app. When notifications are turned off, the app requests topic unsubscription and deletion of the FCM token and Firebase Installation ID. Advertising, diagnostic, and notification information already sent to external providers is handled under each provider's policy and the user's settings.
Previous remote accounts, authentication links, and associated game and leaderboard records are retained until an account/data deletion request is processed after identity verification. Information subject to legal retention obligations and limited disaster-recovery backups may remain separately with restricted access for the necessary purpose and period. Support inquiries are retained only as needed to handle the inquiry or rights request and for any legally required period.
Clearing app data or uninstalling the app deletes only information on the device and does not automatically delete a previous remote account or records. Requests to delete, access, correct, or restrict processing of a previous remote account or specific remote data can be made at https://riderone.bomstudio.co.kr/account-deletion or help@bomstudio.co.kr.
5. User Choices and Rights
Users may use the core puzzle without online features. Advertising-privacy choices and notification permissions can be changed in the app or operating-system settings. Builds that provide analytics also provide in-app consent and withdrawal controls.
Requests to access, correct, delete, or restrict personal information, withdraw consent, or delete a previous account can be sent to help@bomstudio.co.kr. Minimal identity verification may be requested to avoid deleting another user's data, but passwords, Play Games auth codes or tokens, and raw advertising IDs will not be requested by email. After submission, the user will be informed by email about the processing scope, any additional verification needed, and the result or reason for limitation.
6. Children and Security
The app does not directly request date of birth or guardian contact information. Before providing a feature that requires legal-representative consent for processing personal information of a user under age 14, the required procedure will be implemented. The app uses HTTPS communications, feature-based access controls, and data minimization.
7. Changes and Contact
If processing changes because of service features, SDKs, or law, this Policy and its effective date will be updated and notice will be provided through an appropriate channel. The September 6, 2026 policy is available at https://riderone.bomstudio.co.kr/privacy/history. Privacy and data-deletion inquiries: help@bomstudio.co.kr