GRAMPUS Inc. Privacy Policy
한국어 · English
Effective date: 10 September 2026
Versions: 10 September 2026
If you reside outside the Republic of Korea, this Privacy Policy applies to you. It does not apply to residents of the Republic of Korea, to whom the Korean-language Privacy Policy published at legal.grampus.co/privacy applies instead.
In the event of any discrepancy in interpretation between the two language versions, the Korean-language version prevails, except where mandatory law of your country of residence provides otherwise.
This Policy applies to all services provided by GRAMPUS Inc. (the “Company”, “we” or “us”), including games, content and related services (the “Services”). Please do not install or use the Services if you do not agree to this Policy.
1. Information We Collect
We collect only the information necessary to provide the Services. Where we collect optional information, we do so separately and with notice.
1.1 When you link an account through an external authentication service
| Type | Items |
|---|---|
| Required | Email address; the user identifier provided by the external authentication service |
- The items collected may vary according to the information you have chosen to share in the external authentication service.
- Where we collect items beyond those above, we give notice on the relevant authentication screen before collecting them.
1.2 When you participate in an event
- On entry: Member Number, nickname, email address
- On winning a prize: mobile telephone number and address, for delivery of the prize
- Where taxes and public charges apply: name, address, postal code and equivalent identifiers required by law
We obtain separate consent before collecting this information.
1.3 When you use a paid service
- Payment approval number, payment method information (such as the card issuer), date, time and amount of payment, and details of the item purchased
- We do not collect or store card numbers, bank account numbers or other payment authentication credentials. Those are handled by the seller of record or the payment agency.
- For refund processing: a document verifying the identity of the person making the request and, in the case of a minor’s payment, a document evidencing the relationship between the minor and the legal guardian
1.4 When a user below the applicable minimum age links an account
- The name and email address or mobile telephone number of the legal guardian, for the purpose of confirming consent
1.5 When you contact customer support
- Email address, nickname, Member Number, device information (device name, OS version and similar), and the content of your enquiry
1.6 Information generated automatically in the course of using the Services
- Service usage records, access records, authentication records, payment records, restriction records, advertising view records
- IP address, cookies and values stored in browser storage
- Device information (device details, browser type and version, operating system, mobile carrier, country)
- Advertising identifiers (ADID, IDFA)
1.7 How we collect information
- Automatically, in the course of your use of the Services
- Directly from you, through account linking, payment, customer support enquiries and event participation
2. How We Use Information
| Category | Purpose |
|---|---|
| Account information | Identifying users, storing and restoring service data, performing the service agreement, customer management, preventing misuse |
| Payment information | Providing paid services, settling charges, verifying purchase and refund history, resolving payment disputes |
| Event participation information | Running events, selecting winners and delivering prizes, handling taxes and public charges |
| Legal guardian information | Confirming legal guardian consent for the processing of a child’s personal data and for payments made by a minor |
| Automatically generated information | Service statistics and analysis, improvement of the Services and development of new services, detection of misuse and abnormal access, delivery of advertising |
| Enquiry information | Handling enquiries and notifying you of the outcome |
We process this information in order to perform our agreement with you, to comply with legal obligations, on the basis of your consent where consent is requested, and on the basis of our legitimate interests in operating and securing the Services.
3. Advertising and Personalised Advertising
- We display advertising within the Services in order to fund their operation. In this process, advertising providers may collect information through cookies and advertising identifiers. The providers concerned are listed in Section 5.
- Where we provide a Service whose primary audience is children, only contextual, non-personalised advertising is served in that Service.
- You can refuse the collection of information for advertising purposes as follows:
- Browser settings: refuse the storage of cookies
- Android: Settings → Google → Ads → reset or delete your advertising ID
- iOS: Settings → Privacy & Security → Tracking
- Where you move to an external site through an advertisement, the processing of your information on that site is governed by that site’s privacy policy, for which we are not responsible.
4. Sharing Information with Third Parties
We do not use your information beyond the purposes notified in Section 2, and do not provide it to third parties, except:
- where you have given prior consent; or
- where an investigative or other competent authority requests it under a lawful procedure provided by applicable law.
5. Processors
We engage the following processors in order to provide the Services. In each case we enter into a contract containing the terms required by applicable law, and we supervise their handling of personal data.
| Processor | Purpose |
|---|---|
| Amazon Web Services, Inc. | Operation and maintenance of infrastructure |
| Vercel Inc. | Server and API hosting, content delivery |
| Neon Inc. | Database operation and management (used by certain Services) |
| Supabase Inc. | Account authentication, database operation (used by certain Services) |
| XSOLLA (USA), INC. | Web payment processing, refunds and payment-related customer support |
| Google LLC | Social login authentication, in-app purchase receipt verification |
| Apple Inc. | In-app purchase receipt verification |
| ONE store Co., Ltd. | In-app purchase receipt verification |
| AppLovin, Digital Turbine (Fyber), Google (AdMob), InMobi, ironSource, Liftoff (Vungle), Meta, Mintegral, Pangle, Unity | Delivery of advertising (limited to non-personalised advertising in Services whose primary audience is children) |
6. International Transfers
We use infrastructure and services operated by providers outside the Republic of Korea, and personal data is transferred and processed outside the Republic of Korea in this process.
| Recipient | Country | Items | Time and method | Purpose | Retention |
|---|---|---|---|---|---|
| Amazon Web Services, Inc. | Republic of Korea, Japan, Singapore, United States and other countries where the provider operates data centres | IP address, access records, service usage records | Transmitted over the network in encrypted form when the Services are used | Operation and maintenance of infrastructure | Until the end of the processing contract or account deletion |
| Vercel Inc. | Republic of Korea, Japan, Singapore, United States and other countries where the provider operates data centres | IP address, access records, service usage records | Transmitted over the network in encrypted form when the Services are used | Server and API hosting, content delivery | Until the end of the processing contract or account deletion |
| Neon Inc. | Republic of Korea, Japan, Singapore, United States and other countries where the provider operates data centres | Member Number, email address, service usage records, payment records | Transmitted over the network in encrypted form when the Services are used | Database operation and management | Until the end of the processing contract or account deletion |
| Supabase Inc. | Republic of Korea, Japan, Singapore, United States and other countries where the provider operates data centres | Member Number, email address, user identifier from the external authentication service | Transmitted over the network in encrypted form when the Services are used | Account authentication and database operation | Until the end of the processing contract or account deletion |
| XSOLLA (USA), INC. | United States | Email address, payment approval number, date, time and amount of payment, details of the item purchased | Transmitted over the network in encrypted form when the Services are used | Web payment processing, refunds and payment-related customer support | The period required by applicable law (up to 5 years) |
| Google LLC | United States and other countries where the provider operates data centres | Email address, user identifier from the external authentication service, purchase receipt information | Transmitted over the network in encrypted form when the Services are used | Social login authentication, in-app purchase receipt verification | Until the end of the processing contract or account deletion |
| Apple Inc. | United States and other countries where the provider operates data centres | Purchase receipt information | Transmitted over the network in encrypted form when the Services are used | In-app purchase receipt verification | Until the end of the processing contract or account deletion |
| AppLovin, Digital Turbine (Fyber), Google (AdMob), InMobi, ironSource, Liftoff (Vungle), Meta, Mintegral, Pangle, Unity | United States, Singapore, Israel, China and other countries where the providers operate data centres | Advertising identifiers (ADID, IDFA), cookies and values stored in browser storage, service usage records, advertising view records, device information | Transmitted over the network in encrypted form when the Services are used | Delivery of advertising and frequency capping | The period set out in each provider’s privacy policy |
The countries of transfer may change according to each provider’s data centre policy and the need to maintain service quality. Where they change, we will disclose the change through this Policy.
7. Retention
We destroy personal data without delay once the purpose of collection and use has been achieved, except where we retain it for the periods below.
7.1 Under our internal policy
| Item | Reason | Period |
|---|---|---|
| Data of users who have requested account deletion | To allow withdrawal of the request | 7 days from the date of the request |
| Records of misuse | Preventing recurrence and protecting other users | 1 year |
| Documents submitted for identity verification | Destroyed immediately after verification | None |
7.2 Under applicable law
| Item | Basis | Period |
|---|---|---|
| Records of contracts and withdrawal of subscription | Act on the Consumer Protection in Electronic Commerce, Etc. | 5 years |
| Records of payment and supply of goods | Act on the Consumer Protection in Electronic Commerce, Etc. | 5 years |
| Records of consumer complaints and dispute handling | Act on the Consumer Protection in Electronic Commerce, Etc. | 3 years |
| Records of display and advertising | Act on the Consumer Protection in Electronic Commerce, Etc. | 6 months |
| Access records | Protection of Communications Secrets Act | 3 months |
7.3 Event and marketing information
- Purpose: selecting winners and running events
- Period: up to 3 months (the period stated on the relevant event page takes precedence)
7.4 Inactive users
Where a user has not accessed the Services for one year from the date of last access, we may store their personal data separately or destroy it. We notify the user 30 days before doing so.
8. Destruction
- Procedure: personal data whose purpose has been achieved is destroyed without delay after the retention period in Section 7 has elapsed.
- Method: information in electronic form is deleted by a technical method that makes it irrecoverable; information in printed form is shredded or incinerated.
9. Your Rights
- You may at any time request access to, correction of, deletion of, or restriction of the processing of your personal data, and you may withdraw consent where processing is based on consent.
- You may request a copy of your personal data in a structured, commonly used and machine-readable format, and request that it be transmitted to another controller, where applicable law provides such a right.
- You may object to processing carried out on the basis of our legitimate interests, and you may object at any time to processing for direct marketing purposes.
- To exercise these rights, use the settings screen within the Services or contact privacy@grampus.co. We will verify your identity and act without undue delay.
- Where we must decline a request for a legitimate reason, we will notify you and explain the reason.
- Where an account is deleted, data you have generated and accumulated while using the Services may be deleted together with your personal data.
- We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you.
- You have the right to lodge a complaint with a supervisory authority in your country of residence.
10. Cookies and Similar Technologies
- We use cookies and browser storage (such as Local Storage) in order to provide the Services and improve convenience.
- You can allow or refuse the storage of cookies and site data through your browser settings:
- Chrome: Settings → Privacy and security → Third-party cookies / Site data
- Safari: Settings → Privacy → Cookies and website data
- Edge: Settings → Cookies and site permissions
- If you refuse the storage of cookies and site data, some parts of the Services may be restricted.
11. Device Permissions
- Where the Services require access to information or functions on your device, we distinguish between required and optional permissions, clearly explain each item and the reason for it, and obtain your consent.
- Declining an optional permission does not prevent you from using the Services.
- You can withdraw or reset a permission you have already granted at any time, using the functions provided by your device’s operating system or browser.
12. Security
We take the following measures to protect personal data against loss, theft, leakage, alteration and damage.
Technical measures
- Encryption of unique identifiers and authentication credentials at rest
- Encryption of service traffic in transit
- Access control to prevent unauthorised external access
- Retention and periodic review of access logs to systems processing personal data
- Regular backups
Organisational measures
- Access limited to the minimum number of personnel required
- Regular training for personnel and processors handling personal data
- Periodic review of compliance with this Policy
Physical measures
- Systems processing personal data are operated in cloud environments, preventing physical access by unauthorised persons
We are not responsible for problems arising from your own actions, such as loss of a device or deletion of data stored in your browser, where we have fulfilled the obligations above.
13. Children
- The Services are not directed to children below the minimum age at which a person may consent to the processing of personal data under the law of their country of residence.
- Where we become aware that we have collected personal data from a child below that age without the consent of a legal guardian, we delete that data without delay.
- Where we collect a child’s personal data with the consent of a legal guardian, we use the guardian’s information solely to confirm that consent and to handle requests for access to, correction of or deletion of the child’s personal data.
- We encourage legal guardians to supervise their children’s use of the Services. If you believe a child has provided us with personal data, contact privacy@grampus.co.
14. Privacy Officer and Contact
Privacy Officer
- Name: Jiin Kim
- Position: CEO
- Email: privacy@grampus.co
Responsible department
- Department: Business Division
- Email: biz@grampus.co
You may report any privacy-related complaint arising from your use of the Services to the contacts above.
15. External Links
We may provide links to other companies’ websites or materials. We have no control over those external sites and materials and are not responsible for the services or materials they provide. Where you move to another site through a link, please review that site’s privacy policy.
16. Changes to this Policy
Where applicable law or our internal policy changes, we will give notice of the change and the reason for it within the Services or on our website at least 7 days before it takes effect (30 days before, where the change materially affects your rights).
Addendum
This Policy takes effect on 10 September 2026.