Flowplit Privacy Policy

Last Updated: March 4, 2026 | Effective: March 4, 2026

1. Introduction

Flowplit (hereinafter "the Service") is a travel planning platform that values the privacy of its users and complies with applicable data protection laws, including the Personal Information Protection Act (PIPA) of Korea, the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA). This Privacy Policy describes the types of personal information we collect, the purposes for which we use it, retention periods, and third-party sharing practices.

Service Operator: Sungil Park (Individual Developer)
Bundle ID (iOS): com.triplab.flowplit

2. Personal Information We Collect

2.1 Information Collected via Social Login (OAuth2)

The Service does not offer direct registration. Users can only sign up through social login (OAuth2).

Login ProviderData CollectedRequired
AppleApple User IDRequired
Email addressOptional (user may hide)
NameOptional (first sign-up only)
GoogleGoogle User IDRequired
Email addressRequired
Profile image URLOptional
We do not collect passwords. Authentication is handled entirely by each social login provider.

2.2 Information Collected During Service Use

CategoryData CollectedPurpose
ProfileNickname, profile image, bio, website URL, friend search codeDisplay user profile and friend search
TravelTrip title, itinerary, places, budget, notes, routesProvide trip planning features
Social ActivityFollows, likes, comments, bookmarks, trip sharingProvide social features
ExpensesExpense records, settlement historyCost sharing and settlement
PhotosTravel photos, receipt imagesTravel records and receipt scanning
Saved PlacesPlace name, location, collectionProvide place saving features
SettingsDefault currency, language, timezone, profile visibilityPersonalization

2.3 Automatically Collected Information

Data CollectedPurpose
Device type (iOS)Service optimization
App versionCompatibility management
Access date and timeUsage statistics
Last active timeAccount activity management
Feed view historyContent recommendation improvement

2.4 Information Collected for Push Notifications

Data CollectedPurpose
Device push token (APNs)Sending push notifications
Push notifications can be disabled at any time in your device settings.

2.5 Location Information

Data CollectedPurposeCollection Method
Approximate location (country/region)Nearby place search, map displayCollected with user consent
Location information is only collected while the app is in use, not in the background. You can change location permissions in your device settings.

2.6 Photos and Camera

Data CollectedPurposeStorage Location
User-selected photosTravel records, profile image, feed postsGoogle Cloud Storage (cloud)
Camera-captured imagesTravel records, receipt scanning (OCR)Google Cloud Storage (cloud)
Receipt Scanning: Text recognition (OCR) of receipt images is processed on-device and recognized text is not sent to the server (iOS Vision framework on-device processing).

2.7 Information Automatically Collected via SDKs

The Service uses the following SDK to deliver advertisements, which automatically collects information.

SDKData CollectedPurposeRetention
Google AdMob SDKAdvertising identifier (IDFA), app usage data, approximate location (country/region), device informationPersonalized ad delivery and ad performance measurementPer Google's Privacy Policy
Data collection by the AdMob SDK is limited based on iOS ATT (App Tracking Transparency) consent. If you decline tracking, non-personalized ads are displayed instead.

2.8 Behavioral Information (Online Targeted Advertising)

The Service provides targeted advertising through Google AdMob. The following behavioral information is collected and used for this purpose.

CollectorBehavioral DataCollection MethodRetention
Google LLC (AdMob)App usage history, ad click history, interest-based profilesAutomatic collection via SDKPer Google's Privacy Policy
To opt out of behavioral data collection, disable tracking for Flowplit in iOS Settings > Privacy & Security > Tracking, or disable personalized ads in the app's Settings > Privacy.

3. Purpose of Collection and Use

PurposeDetails
Account ManagementSocial login authentication, identity verification, account management
Service DeliveryTrip planning, companion management, expense splitting
Social FeaturesTrip sharing, follows, likes, comments, bookmarks, invitations
PersonalizationLanguage, currency, and timezone preferences
Notification ServiceTrip schedule alerts, invitation alerts, social activity alerts
Service ImprovementUsage analytics, bug fixes, new feature development
Customer SupportInquiries, reports, announcements

4. Retention and Deletion

4.1 Retention Periods

Data TypeRetention PeriodLegal Basis
Account informationUntil account deletionService provision
Travel/social dataUntil account deletionService provision
Uploaded photosUntil account deletionService provision
Device push tokensUntil account deletion or token deactivationNotification service
Access logs1 yearLegal requirement
Report records3 yearsDispute resolution

4.2 Deletion Procedure

4.3 Account Deletion

ItemAction
Account informationImmediately deleted
Private tripsImmediately deleted
Public tripsAnonymized or deleted (user's choice)
Uploaded photosImmediately deleted from cloud storage
Device tokensImmediately deleted
Comments/LikesAnonymized ("Deleted User")

5. Third-Party Sharing

We do not sell your personal information and do not share it with third parties, except in the following cases:

6. Service Providers

ProviderServiceData ProcessedRetention
Google Cloud Platform (GCP)Cloud infrastructure (Cloud Run, Cloud SQL, Cloud Storage, Cloud CDN)All data necessary for service operationUntil contract termination
Google AdMobAdvertising servicesAdvertising identifier, approximate location, app usage dataUntil contract termination
Google Maps PlatformMap display and place searchLocation information, place search queriesPer Google's Privacy Policy
Apple Push Notification service (APNs)iOS push notification deliveryDevice tokens, notification contentPer Apple's Privacy Policy

7. International Data Transfers

The Service transfers personal information to the following countries for operational purposes:

RecipientCountryData TransferredPurposeRetention
Google LLCUnited StatesAll service dataCloud infrastructure (GCP)Until contract termination
Google LLCUnited StatesAdvertising identifier, usage dataAdMob advertisingUntil contract termination
Apple Inc.United StatesDevice tokens, notification contentAPNs push notificationsPer Apple's policy
Data protection in the destination country (United States): The US does not have a single comprehensive federal data protection law but protects personal information through sector-specific legislation (CCPA, COPPA, HIPAA, etc.). Google LLC and Apple Inc. protect data through their own privacy policies and industry-standard security measures. Google maintains SOC 2/3 and ISO 27001 certifications.

8. Advertising

The Service displays advertisements through Google AdMob.

8.1 Data Collected for Advertising

8.2 App Tracking Transparency (iOS)

On iOS 14.5 and later, the Service requests App Tracking Transparency (ATT) consent for ad tracking. You may decline, and declining does not affect your use of the Service.

8.3 Opting Out of Personalized Ads

For more information, see Google's Privacy Policy.

9. Your Rights

9.1 Available Rights

RightDescription
Right of AccessRequest access to your personal data
Right to RectificationRequest correction of inaccurate data
Right to ErasureRequest deletion of your data
Right to Restrict ProcessingRequest to restrict processing of your data
Right to Data PortabilityRequest transfer of your data to another service
Right to Withdraw ConsentWithdraw consent for data collection and use

9.2 How to Exercise Your Rights

Response timelines: Korea within 10 days / US (CalOPPA) within 30 days / Japan (APPI) without delay.

10. Data Security

MeasureDetails
Encryption in TransitAll communications encrypted with SSL/TLS (HTTPS)
Authentication Token ManagementJWT tokens securely stored in iOS Keychain
Access ControlMinimized access privileges; API key-based client authentication
Rate LimitingServer-side rate limiting to block abnormal access
Content ModerationAutomated safety review of uploaded images
Audit LogsAccess logs to personal data systems are maintained and audited
Database SecurityEncrypted storage via Google Cloud SQL managed database

11. Data Breach Response

In the event of a personal data breach, we will take the following actions.

ActionDetailsDeadline
User NotificationBreached data categories, timing, circumstances, mitigation steps, contact informationWithin 72 hours of discovery
Regulatory ReportKorea: PIPC / Japan: PPC (個人情報保護委員会) / US: Per applicable state lawWithin 72 hours (Japan: preliminary 3-5 days, full report 30 days)
Damage ContainmentRoot cause analysis, vulnerability remediation, prevention measuresImmediately

12. Children's Privacy

The Service does not knowingly collect personal information from children below the following age thresholds. If we become aware that such a user has registered, we will promptly delete the account and all related data.

CountryMinimum AgeLegal Basis
KoreaUnder 14Personal Information Protection Act (PIPA)
United StatesUnder 13COPPA (Children's Online Privacy Protection Act)
JapanUnder 14 (Korean standard applied)APPI (no specific age provision)

13. Data Protection Officer

ItemDetails
OfficerSungil Park
Emailqkrtjddlf11@gmail.com

For inquiries, complaints, or requests related to personal data, please contact us at the above address.

14. Changes to This Policy

This Privacy Policy may be updated due to changes in law or the Service. We will notify you of any changes through in-app announcements and push notifications.

15. Governing Law and Dispute Resolution

16. Previous Versions