Privacy Policy
Privacy Policy
Last Updated: 【21/08/2026】
RIFF GAMES Co., Ltd. (hereinafter referred to as the "Company") complies with the personal information protection regulations of relevant laws and regulations that information and communication service providers must comply with, such as the Protection of Communications Secrets Act, the Telecommunications Business Act, and the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. We are doing our best to protect the rights and interests of users by disclosing them on the company website (https://www.riffgames.net/) and establishing a personal information handling policy in accordance with relevant laws and regulations.
This Policy applies to all games, stores, sites, and related services provided by the Company (collectively, the "Services").
We use the term "your data" or "personal data" to refer to data that relates to you as an identified or identifiable individual (such as your name or email address), including non-personal data that can be combined with other data to identify you potentially. You must read and accept this Policy before accessing or using our Services so that you are aware of how and why we may use data relating to you. In addition to this Policy, we encourage you to carefully review our Terms of Service, which govern your use of our Services.
Personal Information Collected
First, the company collects the following personal information at the time of initial service subscription to provide various services when signing up for service. Unique identification number, username or nickname, device identification number (device ID or IMEI), cookie, etc. provided by the service of the user's platform operator.
Second, the following information may be generated and collected during the process of using the Service: User status information, date and time of visit, service usage records, records of improper use, cookies, etc.
Third, when unavoidably necessary for payment in the process of using free/paid services, telecommunication company information, purchase history and gift certificate number, and other payment-related information may be collected, and upon request for restoration and refund of paid content, for smooth customer service, additional personal information may be collected to confirm the e-mail address, purchase details, and whether payment was made by someone other than the person themselves.
The Company collects personal information in the following ways
Automatically collected through a platform affiliated with the Company and related to the provision of the Service, or voluntarily provided by users in the course of subscribing to or using the Service.
Purpose of Personal Information Collection and Use
When a user registers, the device identification number (device ID or UDID, IMEI) may be collected and stored and may be used to determine whether the user account is normal or not.
- Execution of contracts related to the provision of services and billing according to the provision of services, provision of free or paid content, sending invoices via purchase, verification of identity, purchase and payment, collection of fees.
- Membership management: Identity verification according to use of membership services, user verification according to use of game services, personal identification, prevention of fraudulent use and unauthorized use by members whose contract has been terminated due to violations, confirmation of intent to join, number of registrations, record keeping for restriction, identity verification and dispute resolution, handling of civil complaints such as complaint handling, delivery of notices.
- New service development and marketing/advertising usage: New service development and customized service provision, service provision and advertisement posting according to statistical characteristics, service validation, event and advertisement information provision and participation opportunities, identification of access frequency, member service usage statistics.
Sharing and Disclosure of Personal Information
The Company will use the User's personal information within the scope indicated in the "Purpose of Personal Information Collection and Use" and will not use the User's personal information beyond that scope or disclose the User's personal information to third parties without the User's prior consent. However, personal information may be used and disclosed with care in the following cases.
Where users have consented to disclosure in advance: Before information is collected, provided, or transferred, users will be informed of who the company's affiliates are, for how long, and how it will be protected/managed, and will be taken through the consent process. If you do not consent, we will not collect additional information or share it with affiliates. In the case of providing personal information with user consent, the recipient and purpose of use are as follows.
Recipients and Purpose of Use
The Company uses the personal information collected for the following purposes.
- Fulfill contracts related to the provision of services, provide content for billing according to the provision of services, deliver goods or send invoices, verify identity, purchase, and payment, collect fees.
- Membership management: Membership service use and identity verification, personal identification, prevention of illegal use and unauthorized use by members whose contract has been terminated due to violations, confirmation of intent to sign up, restriction of sign-up and number of sign-ups, retention of records for dispute mediation, processing of complaints, delivery of notices.
- Development of new services and marketing/advertising use: Development of new services and customized service provision, service provision and advertising according to statistical characteristics, service validation, provision of event and advertising information and participation opportunities, identification of access frequency, member service usage statistics.
Disclosing and Using Personal Information
The Company may entrust personal information to improve service and may notify changes as related matters progress.
Retention and Use of Personal Information
Generally, users' personal information is destroyed immediately when the purpose for which it was collected and used is achieved. However, the following information will be retained for the specified period of time for the following reasons.
1. Reasons for information retention according to internal Company policy
- Records of illegal use
2. Reasons for Retaining Information According to Relevant Laws and Regulations
Regarding the personal information collected under the member's consent, the Company may retain and use the Member's personal information during the Member's membership, and if the Member requests cancellation, the personal information will be completely deleted so that it cannot be viewed or used again. However, in order to recover and protect victims of personal information theft, the Company may retain Member information for up to 30 days from the date of cancellation for the period of time specified by the particular service, after which time it will be completely deleted. In addition, exceptions are made when the consent of individual members is obtained or when the retention is made in accordance with the provisions of related laws, such as the Commercial Act and the Consumer Protection in Electronic Commerce Act, etc.
If the company needs to preserve customers' personal information in accordance with the provisions of the relevant laws and regulations, the Company will keep the information for the period specified by the relevant laws and regulations. (However, records of service use restrictions are kept during the service period.)
Methods and procedures for destroying personal information
In principle, personal information of users is destroyed without delay when the purpose of collection and use of personal information is achieved. The Company's personal information destruction procedures and methods are as follows.
1. Destruction procedure
- The information entered by the user for service subscription, etc. will be transferred to a separate database after the purpose has been achieved and will be kept for a certain period of time according to internal policy and information protection reasons under other relevant laws (see Retention and Use Period) and then destroyed.
- This personal information will not be used for any purpose other than being retained unless otherwise required by law.
2. Method of Destruction
- Personal information printed on paper will be shredded or destroyed by incineration.
- Personal information stored in an electronic file will be deleted using a technical method that cannot reproduce the record.
Rights of Users and Legal Representatives and How to Exercise Them
Users and their legal representatives can view or modify their registered personal data, or the personal data of children under the age of 14, at any time through the Platform Operators or App Store Operators, and if they do not agree with the processing of personal data by the Company, they can refuse consent or terminate use of the Service. In this case, however, use of all or part of the Service may be restricted.
In order to view or modify the personal information of users or children under the age of 14, and to terminate use of the Service (withdrawal of consent) through "Withdrawal" in the Service or by contacting the Customer Center, you can directly view, correct, or withdraw after going through the confirmation process.
If a user requests correction of an error in personal information, the personal information will not be used or disclosed until the correction is completed. In addition, if inaccurate personal information has already been provided to a third party, the result of the correction will be promptly communicated to the third party so that the correction can be made.
The Company will treat personal information that has been cancelled or deleted at the request of the user or the user's legal representative in accordance with the "Retention and Use of Personal Information" section and prevent it from being viewed or used for any other purpose.
Matters Related to Installing/Operating and Opting Out of Automatic Personal Information Collection Devices
The Company may use "cookies" that store and retrieve user information from time to time in order to provide customized services to users.
A cookie is a small amount of information that the server used by the Company to operate sends to your browser and is sometimes stored on the hard drive of your computer.
In order to provide more convenient services, the Company may use cookies to analyze visits, access types, access times, etc. for each service of the Site visited by users.
Users have the right to choose cookies. Therefore, the user may allow all cookies, check each time a cookie is saved, or refuse to save all cookies through the privacy or cookie settings menu of their web browser.
However, if the user refuses to save cookies, services that require a login cannot be used.
The Company may automatically collect the device identification number (device ID or UDID, IMEI) when a user runs an application for the Game Service to create account information. In addition, a unique identification number and a unique identification number related to the friend list may be automatically collected from Platform Users in order to provide basic functions such as friend registration or friend recommendation.
If the user does not allow the automatic collection of this unique identification number or device identification number, game services such as inviting friends and gifts cannot be provided normally, and you cannot use our game services normally.
Technical/Administrative Safeguards for Personal Information
When handling users' personal information, the Company takes the following technical/managerial steps to ensure the security of personal information from loss, theft, disclosure, alteration or destruction.
- Countermeasures Against Hacking, etc. The Company will do its best to prevent the loss or damage of members' personal information due to hacking or computer viruses. In preparation for damage to personal information, data is frequently backed up, users' personal information or data is prevented from being leaked or damaged, and personal information is securely transmitted over the network through encrypted communication. In addition, we use an intrusion prevention system to control unauthorized access from outside, and we strive to equip all possible technical devices to ensure system security.
- The Company's personal information handling staff is limited to the persons in charge, who receive training. A separate password is assigned for this purpose and is regularly updated, and compliance with the Company's privacy policy is ensured through frequent training.
- The Company will monitor compliance with the Company's personal information handling policy and compliance by the persons in charge through the Company's personal information protection organization, and will make efforts to correct and rectify problems immediately if found. However, the Company does not take responsibility for problems arising from the leakage of personal information due to causes attributable to the user's own negligence and not attributable to the Company's intention or gross negligence.
Privacy Policy and Third Party Websites, Links, Advertisements and Services
You should be aware that while using the Services, you may be directed to other sites that are beyond our control and for which we are not responsible. In addition, when you use the Services, third parties may use your IP address or other technologies such as cookies, web beacons, etc. to serve advertisements and offer you various products and services. By using the Services, you consent to the third party's use of your personal information in accordance with the third party's privacy policy.
The following third parties may receive your personal information:
- Facebook : https://www.facebook.com/about/privacy/
- Google : https://policies.google.com/privacy
- Apple : https://www.apple.com/legal/privacy/
For more detailed information, please refer to the third party's privacy policy.
Contact Information of the Person in Charge of Personal Information Management and the Department
You can report complaints regarding the protection of personal information that occur while using the Company's services to the person in charge of personal information management or the relevant department. The Company will provide prompt and sufficient responses to users' reports.
- Department in charge: Operations Team, RIFF GAMES Co., Ltd.
- Contact: support@riffgames.net / TEL: 010-2684-3610
YOUR RIGHTS
With respect to our processing of your data, you may:
- access, correct, or request the deletion of your data,
- request us to restrict our processing of your data,
- object to our use of your data for automated decision-making for direct marketing purposes,
- be informed about which third parties have received your data,
- request a copy in the machine-readable format of the personal data we have collected from you under this Policy,
- where technically feasible, request that your data be transmitted to another controller.
You may also withdraw your consent for processing your data at any time. Please be aware that we may continue processing your data despite your withdrawal of consent if we also have another lawful basis. To access your data in our Games or to request its deletion, please get in touch with us at support@riffgames.net.
To exercise your rights, you may also contact us at support@riffgames.net. When you submit a request to exercise your rights, we must verify that you are the consumer to whose personal information the request relates, or a person authorized to act on that consumer's behalf. We may ask you to provide further details on the account to which the request relates, enabling us to confirm that you are the account holder or acting on their behalf upon the request.
While we will usually not do so, we reserve the right to charge you an appropriate fee for exercising your requests permitted by applicable laws and regulations. If you believe that we have infringed your privacy rights, please get in touch with us at support@riffgames.net so we can try to resolve the issue. If you are an EU resident, you have the right to complain to your local supervisory authority.
INTERNATIONAL TRANSFER
RIFF GAMES is a company based in the Republic of Korea, and to provide you the Services, your data will be transferred to the Republic of Korea for processing and stored on Amazon Cloud Service. By using RIFF GAMES's Services, you acknowledge and consent to the processing of your data in these locations.
The European Commission adopted an adequacy decision for the Republic of Korea under art. 45 of the General Data Protection Regulation ("GDPR") on 17 December 2021, and the United Kingdom has adopted equivalent adequacy regulations. Transfers of your data from the European Economic Area or the United Kingdom to the Republic of Korea therefore take place on the basis of that adequacy finding.
Where your data is transferred to a country not covered by an adequacy decision, RIFF GAMES relies on specific appropriate safeguards and derogations for safe transfer provided in art. 46 and 49 of the GDPR. Namely, RIFF GAMES collects and transfers your data only due to the following circumstances: 1) because we entered into a contract with Amazon Web Services or another service provider incorporating standard data protection clauses; 2) to perform a contract (providing you with the Services under our Terms of Service); 3) your consent.
NOTE FOR CALIFORNIA RESIDENTS
If you are a California resident, please be aware that under the California Consumer Privacy Act of 2018, as amended ("CCPA"), you are entitled to specific rights regarding your data. Besides other rights outlined in this Policy, California residents have the following rights:
– The right to opt-out of the sale of your personal information. We do not sell your personal information in exchange for money. However, we may disclose a limited amount of your personal information (i) to our advertising partners to enable them to deliver an ad that is relevant to you or (ii) to our marketing or licensing partners to enable them to send you relevant offers when you have opted into such communication.
This includes the following categories of your personal information:
- identifiers (generally including an advertising ID and your IP address for ad partners, and name and email for marketing or licensing partners); and
- internet or other electronic network activity information (including technical information required to select and deliver the appropriate ad type and format).
Because this disclosure of information could be deemed a "sale" in the meaning of the CCPA, we ask for your explicit consent to disclose your personal information to our advertising or marketing partners for the above purposes. You can contact us at support@riffgames.net to exercise your right to opt out.
– Non-Discrimination. You have the right not to be discriminated against for exercising your rights under the CCPA.
AGE LIMIT
By accepting our Terms of Service and using our Services, you represent that you are at least 13 years of age. Therefore, if you are under 13 years of age, please do not provide your data to us or use the Services to make your data available to others. If we discover that we unintentionally hold personal data relating to a user under 13 years of age, we will promptly delete the data from our records. If you have reason to believe we hold personal data relating to a user under 13 years of age, please contact us.
CHANGES
We may update this Policy from time to time due to changes in our operations or the legal obligations that apply to us. Updates will be made available here. We may also inform you of any changes by other means appropriate to the significance of the changes.