PICK&RUN

Privacy Policy

Effective date: April 2, 2026

Haveajam Company (the “Company”) establishes and discloses this Privacy Policy pursuant to the Personal Information Protection Act and other applicable laws of the Republic of Korea, in order to protect users' personal information and to handle related grievances promptly.

This English text is provided for reference. In case of any discrepancy, the Korean version prevails.

1Article 1 (Purpose of Processing and Items Collected)

The Company processes the minimum personal information necessary within the following purposes.

1. Membership and Account Management

① Items collected upon standard sign-up

[Required] Email (login ID), password, mobile phone number (incl. SMS verification), nickname

[Optional] Name (family/given), gender, date of birth

* Profile image and bio are collected only if the member registers them in profile settings after sign-up.

② Items collected via social login

Google login

Email (required), Google account identifier (required), name (optional)

Kakao login

Email (required), Kakao account identifier (required), mobile phone number (required), name (optional), gender (optional), date of birth (optional)

Apple login

Email (required), Apple account identifier (required)

* Information collected via social login is used only for member identification and service provision. Mobile phone verification is also performed for social sign-ups.

③ Items collected upon DUPR account linking (optional)

DUPR ID, name registered with DUPR, singles/doubles ratings and reliability, match count, linking tokens

* DUPR linking data is deleted without delay upon unlinking or membership withdrawal.

④ Purpose of processing

Member identification and verification, account management and service provision, fraud prevention, customer support, in-service notifications

⑤ Retention period

Until membership withdrawal. After withdrawal, data is retained for 30 days to prevent fraudulent re-registration and to handle refunds or disputes, then destroyed.

However, where retention is required by applicable laws, data is kept for the legally required period and then destroyed.

2. Marketing Use (optional)

Only when a member consents at sign-up or in settings, the Company uses the nickname, email, and mobile phone number to deliver promotional information (events, promotions, benefits) and personalized updates.

■ Retention

Until consent is withdrawn or membership ends. The fact and time of consent are recorded and retained as required by law.

* Consent can be withdrawn anytime in Settings > Preferences > Notifications; refusing does not restrict service use. Night-time (21:00–08:00) promotional messages require separate consent.

2Article 2 (Personal Information of Children Under 14)

The Company does not allow children under 14 to register directly online. However, where a legal guardian consents through the procedure below, the Company may create an account on the child's behalf.

■ Guardian consent procedure

The legal guardian verifies their own mobile phone number on the guardian consent screen in the Company's service, reads the consent text displayed there and indicates consent. The Company then notifies the verified mobile number by text message that the indication was confirmed (Article 17-2(1)(1) of the Enforcement Decree of the Personal Information Protection Act). Once consent is confirmed, the Company creates the child's account and notifies the same number. The time of consent, the time the confirmation message was sent, the version of the consent text and connection information are kept as evidence of consent.

■ Items collected

[Child] Name, date of birth, email, mobile phone number (if any)

[Guardian] Name, relationship to the child, mobile phone number

[Evidence] Connection information at the time of consent (IP address, browser information)

* Guardian information is used only to confirm consent and to give legally required notices under Article 22-2 of the Personal Information Protection Act, and for no other purpose. If consent is not confirmed, or a request is rejected or cancelled, it is destroyed without delay; requests awaiting account creation are cancelled and destroyed automatically 30 days after receipt. Where consent is confirmed it is retained as evidence of consent until the child withdraws membership.

If a child under 14 is found to have registered without guardian consent, the Company deletes the account and its personal information without delay. A legal guardian may exercise access, correction, and deletion rights on behalf of the child.

3Article 3 (Event Application and Participation)

1. Default information (reuse of already collected data)

Nickname, profile image, email

■ Purpose

Participant identification, roster management, event operation support

2. Conditional information (only when requested by the organizer)

Name, gender, date of birth, mobile phone number, DUPR information (ID, ratings, reliability), application form entries (answers and attachments), and team name/member information for team entries

■ Purpose

Eligibility verification, event operation and contact, refund and settlement processing

3. Method and retention

The above information as of the time of application is stored separately in the participant roster (snapshot). For events with eligibility conditions, the items needed to verify them (gender restriction → gender, age restriction → date of birth, DUPR condition → DUPR information) are included.

■ Retention

Automatically destroyed 6 months after the event ends. De-identified data may be kept for statistical purposes in a form that cannot identify individuals. Where retention is required by law, data is kept for the required period.

4Article 4 (Payment and Refund Processing)

The Company brokers payments through a payment gateway (Toss Payments) and may process the following information.

■ Items processed

① Basic payment information

Order number, order name, payment method (card, easy pay, etc.), payment type, request time, approval time, transaction number, receipt URL

② Card payment information

Issuer code, acquirer code, masked card number, card type (credit/debit/gift), owner type (personal/corporate), installment months, interest-free status, approval number

③ Easy-pay information

Easy-pay provider, discount amount, canceled discount amount

④ Refund information

Refund amount, remaining refundable amount, refund reason, cancellation time, receipt key

⑤ Bank-transfer events

Organizer's settlement account (bank, account number, holder name) and a depositor identification code

* The Company does not store sensitive financial information such as full card numbers, CVC, or passwords.

■ Purpose

Payment processing and confirmation, refund processing and history, settlement, legal compliance

■ Retention

Retained for 5 years under the Act on Consumer Protection in Electronic Commerce, or longer where required by applicable laws.

5Article 5 (Provision to Third Parties)

The Company provides personal information to third parties only with the user's consent, as follows.

1. Event organizers

■ Recipient

The organizer of the event applied for (including managers of the hosting channel)

■ Items provided

[Default] Nickname, profile image, email

[Conditional] Name, gender, date of birth, mobile phone number, DUPR information, application form entries, team name/member information

* For events with eligibility conditions, items needed to verify them (gender → gender, age → date of birth, DUPR condition → DUPR information) are included.

■ Purpose

Participant verification and roster management, eligibility checks, event operation and contact, cancellation/refund and settlement

■ Retention

6 months after the event ends, or longer where required by applicable laws.

This consent covers the provision of personal information to the organizer upon event application. Users may refuse; refusal may restrict event applications. Organizers may use the provided information only for the purposes above and may not reuse or re-provide it.

2. DUPR, LLC

For members who link a DUPR account, match results are transmitted to DUPR for rating calculation. See Article 7 (Overseas Transfer) for details.

6Article 6 (Outsourcing of Processing)

The Company outsources the following processing tasks for smooth service provision.

ProcessorTaskRetention
NAVER Cloud Corp.Sending SMS verification messagesUntil the outsourcing contract ends
Toss PaymentsPayment gateway and refund processingStatutory retention period
Cloudflare, Inc.Storage and delivery (CDN) of images and attachmentsUntil the outsourcing contract ends
Kakao Corp.Customer support and guardian consent confirmation via KakaoTalk channelUntil the outsourcing contract ends

The Company specifies safety measures in outsourcing contracts and supervises processors as required by law. If a new processor (e.g., a web analytics tool) is introduced, this Policy will be revised and notified beforehand.

7Article 7 (Overseas Transfer)

Personal information may be transferred overseas in the course of using the service, as follows.

RecipientCountryItemsMethodRetention
DUPR, LLCUSADUPR ID, name, ratings and match recordsAPI transfer upon DUPR account linkingUntil unlinking or withdrawal
Cloudflare, Inc.USA and othersImages and attachments uploaded by membersNetwork transfer during service useUntil the outsourcing contract ends
Google LLCUSAVenue search text (when using address autocomplete)Network transfer during service useUntil the purpose is achieved

Users may refuse consent to overseas transfer. Transfer to DUPR does not occur unless an account is linked. Refusal may restrict the related features (rating integration, image upload, address autocomplete).

8Article 8 (Automatic Collection Tools and Opt-Out)

The Company uses cookies (authentication tokens) and browser storage (display settings such as theme) to maintain login sessions and provide the service.

The web server may also keep access logs (IP address, access time, requested URL, browser information) for stable operation, security, and troubleshooting.

Users may refuse cookies via browser settings; however, refusing cookies may restrict some features such as login.

9Article 9 (Retention and Destruction)

The Company destroys personal information without delay once the retention period expires or the purpose of processing is achieved.

■ Destruction process

Membership withdrawal: service access is blocked immediately, and after a 30-day grace period, personal information in the account, profile, and participation records is automatically destroyed (de-identified).

Event participation data: personal information in participant rosters and application form answers is automatically destroyed 6 months after the event ends.

Error logs collected for troubleshooting are automatically deleted after 90 days.

■ Destruction method

Electronic files: permanently deleted in an unrecoverable manner

Paper documents: shredded or incinerated

■ Retention required by law

ItemLegal basisPeriod
Records of contracts and withdrawals of offersE-Commerce Act5 years
Records of payment and supplyE-Commerce Act5 years
Records of consumer disputesE-Commerce Act3 years
Service access records (web server logs)Protection of Communications Secrets Act3 months

10Article 10 (Rights of Data Subjects)

Users may request access to, correction or deletion of, suspension of processing of, and withdrawal of consent regarding their personal information.

The Company handles such requests without delay in accordance with applicable laws, and within 10 days where special circumstances exist.

Identity is verified via mobile phone authentication or equivalent means when exercising these rights.

11Article 11 (Privacy Officer)

Name: Busung Kim

Email: busung99@haveajam.com

Business name: Haveajam Company

Business registration no.: 318-11-02720

Address: 5F, 175-5, Pungseong-ro, Gangdong-gu, Seoul, Republic of Korea

12Article 12 (Remedies)

For reports or consultations regarding personal information infringement, users may contact the following organizations.

  • •Personal Information Infringement Report Center (privacy.go.kr)
  • •Personal Information Dispute Mediation Committee (kopico.go.kr)
  • •Cybercrime Investigation Division, Supreme Prosecutors' Office
  • •Cyber Bureau, Korean National Police Agency

13Article 13 (Changes to This Policy)

This Policy takes effect on April 2, 2026. Changes will be announced on the website in advance.

© 2026 해버잼 컴퍼니. All rights reserved.