Winglet

개인정보처리방침Privacy Policy

[운영자명](이하 "운영자")은 윙렛(이하 "서비스") 이용자의 개인정보를 「개인정보 보호법」 등 관련 법령에 따라 보호하며, 이 방침은 어떤 정보를 왜 수집하고 어떻게 처리하는지 설명합니다.

1. 수집하는 개인정보 항목 및 수집 방법

구분항목수집 방법
계정 (선택 — 동기화 이용 시)이메일, 이름, 프로필 사진 URL, 로그인 식별자Google/Apple 소셜 로그인
비행 기록항공편명, 날짜, 출발/도착 공항, 좌석·클래스, 메모이용자 직접 입력, 보딩패스 스캔, Gmail/CSV/로스터 가져오기
승무원 데이터 (크루 기능 이용 시)근무 역할, 블록 시각, 레이오버 메모, 소속 항공사, 홈베이스이용자 직접 입력, 로스터 파일 가져오기
알림 관련푸시 토큰, 기기 언어 설정알림 기능 사용 시 자동 수집
구독 정보구독 상태·등급, 익명 구매 식별자Apple·Google Play/RevenueCat 연동 (카드번호 등 결제 수단 정보는 수집하지 않음)
자동 수집앱 사용 이벤트, 기기 모델·OS 버전, 크래시 기록Firebase Analytics/Crashlytics
출시 알림 신청 (선택)이메일 주소, 관심 플랫폼(iOS·Android), 페이지 언어, 수신 동의 일시웹사이트 출시 알림 신청 폼

수집하지 않는 것: 기기 위치정보(GPS), 주민등록번호 등 고유식별정보, 연락처, 광고 식별자 기반 맞춤 광고 데이터.

2. 처리 목적

  1. 서비스 제공: 항공편 추적·알림, 비행 기록 저장·동기화, 통계·리포트, 승무원 기능
  2. 계정 관리: 로그인, 기기 간 동기화, 계정 삭제 처리
  3. 유료 서비스: 구독 상태 확인 및 기능 제공 (청구는 Apple이 수행)
  4. 서비스 개선: 사용 통계 분석, 오류·크래시 진단
  5. 고지·응대: 서비스 관련 공지, 문의 응대
  6. (별도 동의 시) 광고성 정보 전송

3. 제3자 제공

운영자는 개인정보를 제3자에게 제공하지 않습니다. 다만 법령에 근거한 적법한 요청이 있는 경우는 예외로 합니다.

4. 보유 및 이용 기간

데이터보존근거
비행 로그/크루 데이터계정 활성 동안 + 삭제 후 30일복구 유예
공유 flight 스냅샷영구 (개인정보 아님 — 항공편 공개 정보)서비스 자산
운영 로그30일장애 분석
분석 이벤트14개월 (Firebase 기본)통계
결제 기록Apple/RevenueCat 관리 (자체 저장 안 함)
CS 문의·분쟁 처리 기록3년전자상거래법 제6조
출시 알림 신청 이메일출시 안내 발송 후 삭제 (최대 12개월)신청 목적 달성 시 파기

5. 처리 위탁 및 국외 이전

서비스는 아래 수탁자(클라우드 사업자)를 통해 개인정보를 처리하며, 서버가 해외에 있어 개인정보가 국외로 이전됩니다.

이전받는 자국가이전 항목목적보유 기간
Google LLC (Firebase)미국 등 Google 인프라 소재국§1의 계정·비행 기록·승무원 데이터·푸시 토큰·분석/크래시 데이터인증, 데이터 저장·동기화, 알림 발송, 분석§4 보유 기간과 동일
RevenueCat, Inc.미국익명 구매 식별자, 구독 상태구독 상태 관리구독 관리 목적 달성 시까지
Apple Inc.미국결제 처리 정보 (Apple이 직접 수집, iOS)앱 내 결제Apple 정책에 따름
Google LLC (Google Play)미국결제 처리 정보 (Google이 직접 수집, Android)앱 내 결제Google 정책에 따름
Mapbox, Inc.미국IP 주소, 지도 요청 정보지도 표시Mapbox 정책에 따름

이전 방법: 앱 이용 시 네트워크를 통한 전송. 이용자는 국외 이전을 원하지 않을 경우 계정 동기화 기능을 사용하지 않거나(로컬 저장만 사용) 계정을 삭제할 수 있으며, 관련 문의는 support@flywinglet.com로 할 수 있습니다.

※ 항공편 조회 요청(편명·날짜)은 항공 데이터 공급자에게 전달되지만, 이용자를 식별할 수 있는 정보는 포함되지 않습니다.

6. 파기 절차 및 방법

보유 기간이 끝난 개인정보는 지체 없이 파기합니다. 전자적 파일은 복구할 수 없는 방법으로 삭제하며, §4의 30일 유예가 있는 데이터는 유예 만료 시 자동 삭제됩니다.

7. Google 사용자 데이터 (Gmail 가져오기)

Gmail 가져오기 기능은 이용자가 명시적으로 실행할 때만 동작하며, 읽기 전용 권한(gmail.readonly)으로 항공권 확인 이메일에서 항공편 정보를 추출합니다.

  1. 이메일 원문은 기기 안에서만 항공편 정보 추출에 사용되며, 운영자 서버로 전송·저장되지 않습니다. 추출된 항공편 정보만 비행 기록으로 저장됩니다.
  2. 액세스 토큰은 앱에 보관하지 않습니다.
  3. Gmail 데이터를 광고에 사용하거나, 사람이 열람하거나, 제3자에게 판매·이전하지 않습니다.
  4. 이 앱의 Google API에서 받은 정보의 사용은 Limited Use 요건을 포함한 Google API Services User Data Policy를 준수합니다.
  5. 이용자는 Google 계정 보안 설정에서 언제든지 접근 권한을 철회할 수 있습니다.

8. 정보주체의 권리

이용자는 언제든지 다음을 할 수 있습니다.

  1. 열람·정정: 앱 안에서 자신의 기록을 직접 확인·수정
  2. 삭제: 개별 기록 삭제(30일 복구 유예) 또는 계정 삭제(§4)
  3. 내보내기: 비행 기록 CSV 내보내기 (데이터 이동권)
  4. 동의 철회: 광고성 알림 수신 동의 철회(설정), Gmail 접근 철회(§7-5)
  5. 그 밖의 요청·문의: support@flywinglet.com (지체 없이, 법정 기한 내 처리)

만 14세 미만 아동의 개인정보는 수집하지 않으며, 서비스는 만 14세 이상만 이용할 수 있습니다. 만 14세 미만 아동의 정보가 수집된 사실을 알게 되면 지체 없이 삭제합니다.

9. EEA·영국 거주자를 위한 추가 안내 (GDPR/UK GDPR)

  1. 처리의 법적 근거: 서비스 제공·계정 관리 = 계약 이행(제6조 1항 (b)) / 분석·크래시 진단 = 정당한 이익(제6조 1항 (f) — 서비스 안정성) / 광고성 정보·Gmail 접근 = 동의(제6조 1항 (a))
  2. 권리: 열람, 정정, 삭제, 처리 제한, 데이터 이동, 반대, 동의 철회. 행사는 support@flywinglet.com 또는 앱 내 기능으로.
  3. 역외 이전: §5의 수탁자들은 EU 표준계약조항(SCC) 등 적법한 이전 장치를 갖추고 있습니다.
  4. 거주 국가 감독기구에 민원을 제기할 권리가 있습니다.

10. 안전성 확보 조치

  1. 전송 구간 암호화(TLS) 및 저장 데이터 암호화(클라우드 기본 제공)
  2. 접근 통제: 데이터베이스 보안 규칙으로 본인 계정 데이터만 접근 가능
  3. 최소 수집·최소 권한 원칙 (읽기 전용 Gmail 스코프, 위치정보 미수집 등)
  4. 운영 로그의 개인 식별 정보 최소화(식별자 해시 처리) 및 30일 자동 파기

11. 개인정보 보호책임자

개인정보 관련 문의·불만·피해 구제는 위 연락처로 접수할 수 있습니다. 또한 개인정보분쟁조정위원회, 개인정보침해신고센터(privacy.kisa.or.kr, 국번 없이 118) 등에 분쟁 해결이나 상담을 신청할 수 있습니다.

12. 방침의 변경

이 방침이 변경되는 경우 시행 7일 전(중요한 변경은 30일 전)부터 앱 또는 웹사이트를 통해 공지합니다.

부칙: 이 방침은 [시행일]부터 시행됩니다.

[Operator Name] (the "Operator") protects the personal data of users of Winglet (the "Service") in accordance with applicable law, including the Korean Personal Information Protection Act. This policy explains what we collect, why, and how it is handled.

1. Data We Collect and How

CategoryItemsHow collected
Account (optional — for sync)Email, name, profile photo URL, sign-in identifierGoogle/Apple social sign-in
Flight recordsFlight number, date, departure/arrival airports, seat/cabin, notesDirect entry, boarding pass scan, Gmail/CSV/roster import
Crew data (if crew features used)Duty role, block times, layover notes, airline, home baseDirect entry, roster file import
NotificationsPush tokens, device languageCollected automatically when notifications are used
SubscriptionSubscription status/tier, anonymous purchase identifierApple/Google Play/RevenueCat integration (we never collect card numbers or other payment credentials)
AutomaticApp usage events, device model/OS version, crash reportsFirebase Analytics/Crashlytics
Launch notice sign-up (optional)Email address, platform of interest (iOS/Android), page language, time consent was givenSign-up form on the website

What we do NOT collect: device location (GPS), government ID numbers, contacts, or data for personalized advertising.

2. Purposes of Processing

  1. Providing the Service: flight tracking and notifications, log storage and sync, statistics and reports, crew features
  2. Account management: sign-in, cross-device sync, account deletion
  3. Paid services: verifying subscription status and providing features (billing is handled by Apple)
  4. Service improvement: usage analytics, error and crash diagnostics
  5. Notices and support: service announcements, responding to inquiries
  6. (With separate consent) sending promotional messages

3. Disclosure to Third Parties

We do not disclose personal data to third parties, except where required by a lawful request under applicable law.

4. Retention Periods

DataRetentionBasis
Flight logs / crew dataWhile the account is active + 30 days after deletionRecovery grace period
Shared flight snapshotsPermanent (not personal data — public flight information)Service asset
Operational logs30 daysIncident analysis
Analytics events14 months (Firebase default)Statistics
Payment recordsManaged by Apple/RevenueCat (not stored by us)
Customer support / dispute records3 yearsKorean E-Commerce Act, Article 6
Launch notice sign-up emailDeleted once the launch notice is sent (12 months at most)Erased when the purpose is met

5. Processors and International Transfers

The Service processes personal data through the cloud providers below. Their servers are located abroad, so personal data is transferred internationally.

RecipientCountryItems transferredPurposeRetention
Google LLC (Firebase)USA and other Google infrastructure locationsAccount, flight records, crew data, push tokens, analytics/crash data (§1)Authentication, storage/sync, notifications, analyticsSame as §4
RevenueCat, Inc.USAAnonymous purchase identifier, subscription statusSubscription managementUntil purpose fulfilled
Apple Inc.USAPayment processing data (collected directly by Apple, iOS)In-app purchasesPer Apple's policies
Google LLC (Google Play)USAPayment processing data (collected directly by Google, Android)In-app purchasesPer Google's policies
Mapbox, Inc.USAIP address, map request dataMap displayPer Mapbox's policies

Transfer method: network transmission during app use. If you do not want international transfers, you may use the app without account sync (local storage only) or delete your account; inquiries: support@flywinglet.com.

※ Flight lookup requests (flight number and date) are sent to aviation data providers but contain no information that identifies you.

6. Destruction of Data

Personal data whose retention period has ended is destroyed without delay, using methods that prevent recovery. Data subject to the 30-day grace period in §4 is deleted automatically when the period expires.

7. Google User Data (Gmail Import)

The Gmail import feature runs only when you explicitly start it, and uses the read-only scope (gmail.readonly) to extract flight details from airline confirmation emails.

  1. Email content is used only on your device to extract flight details; it is never sent to or stored on the Operator's servers. Only the extracted flight details are saved to your log.
  2. Access tokens are not retained by the app.
  3. Gmail data is never used for advertising, read by humans, or sold or transferred to third parties.
  4. Winglet's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  5. You can revoke access at any time in your Google Account security settings.

8. Your Rights

You may at any time:

  1. Access and correct: view and edit your records directly in the app
  2. Delete: individual records (30-day recovery grace) or your entire account (§4)
  3. Export: export flight records as CSV (data portability)
  4. Withdraw consent: promotional notifications (in settings), Gmail access (§7-5)
  5. Other requests and inquiries: support@flywinglet.com (handled without undue delay, within statutory deadlines)

We do not knowingly collect personal data from children under 14; the Service requires users to be at least 14 years old. If we learn that data from a child under 14 has been collected, we delete it without delay.

9. Additional Information for EEA/UK Residents (GDPR/UK GDPR)

  1. Legal bases: providing the Service and account management = performance of a contract (Art. 6(1)(b)) / analytics and crash diagnostics = legitimate interests (Art. 6(1)(f) — service reliability) / promotional messages and Gmail access = consent (Art. 6(1)(a)).
  2. Rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent — exercised via support@flywinglet.com or in-app features.
  3. Transfers: the processors in §5 rely on lawful transfer mechanisms such as EU Standard Contractual Clauses (SCCs).
  4. You have the right to lodge a complaint with your local supervisory authority.

10. Security Measures

  1. Encryption in transit (TLS) and at rest (provided by the cloud platform)
  2. Access control: database security rules restrict access to your own account's data
  3. Data minimization and least privilege (read-only Gmail scope, no location collection, etc.)
  4. Operational logs minimize identifiers (hashed) and are automatically deleted after 30 days

11. Privacy Contact

Privacy inquiries, complaints, and requests for remedies can be submitted to the contact above. Korean users may also contact the Personal Information Dispute Mediation Committee or the Privacy Infringement Report Center (privacy.kisa.or.kr, dial 118).

12. Changes to This Policy

Changes will be announced in the app or on our website at least 7 days before taking effect (30 days for material changes).

Addendum: This policy takes effect on [Effective Date].