Privacy Policy
Privacy Policy
Last updated · September 14, 2026
This English version is a translation provided for convenience. If it differs from the Korean original, the Korean original prevails.
This document is a draft. Finalise it once legal review has confirmed how Vietnam's Personal Data Protection Decree (Decree 13/2023/ND-CP) and Korea's Personal Information Protection Act apply.
1General
Mate Today (the “Company”) takes Users' personal data seriously and handles it securely in accordance with applicable law. This Policy explains what data the Company collects and why, how long it keeps it, and what rights Users can exercise.
2Personal Data We Collect
The Company collects the following data.
| Type | Data | When collected |
|---|---|---|
| Required | Email address, password (stored encrypted) | At registration |
| Required | Whether the User is 16 or older | At registration |
| Required (under 16) | Legal guardian's name, email, relationship and time of consent | At registration |
| Required | Nickname | When first setting up a profile |
| Required | Gender (male · female) | When first setting up a profile (before hosting or joining a meetup) |
| Optional | Profile photo | When setting up or editing a profile |
| Optional | Short bio, interests, main area | When setting up or editing a profile |
| Optional | Phone number | When requesting phone verification |
| Optional | Location (device location, or a place chosen by search or on the map, stored to about 1 km), administrative area (ward) name | When using location lookup to set the main area |
| Generated | Meetup venue location (coordinates) and administrative area name | When choosing the venue by search or on the map while creating a meetup |
| Optional | ID images, face photo, date of birth (processed by the verification provider, not kept by the Company) | When requesting KYC adult verification |
| Generated | Adult verification result (pass or not), time of review | When KYC review completes |
| Automatic | IP address, access times, device and browser information | When using the Service |
| Generated | Meetups hosted or applied to, chat messages, manner score, mutual ratings | While using the Service |
| Generated | Report and block records | When using report or block features |
The Company does not collect sensitive data such as beliefs, political opinions, health or sex life. However, only where a User requests KYC verification, ID images and a face photo are processed for identity verification.
3How We Use Personal Data
The Company uses the data it collects only for the following purposes.
- Identifying members, login and account management
- Confirming legal guardian consent for Users under 16
- Hosting, applying to and approving meetups, and providing chat between participants
- Determining the administrative area of a member's main area and a meetup's venue, and showing it on a map
- Checking whether a User is 19 or older and awarding the verification badge
- Providing trust information between Users, such as calculating the manner score
- Preventing misuse, handling reports and responding to disputes
- Improving the Service and statistical analysis
- Complying with legal obligations and responding to lawful requests from investigative authorities
4Information Shown to Other Users
The following information is shown to other Users. Do not enter information you do not want to be shown.
| Information shown | Shown to |
|---|---|
| Nickname, short bio, interests | All Users |
| Gender, profile photo | All Users |
| Manner score, whether the User holds verification badges | All Users |
| Title, venue (including its map location) and time of meetups the User hosts | All Users |
| Chat messages | Participants in that chat room |
| Nickname · main area · interests · manner score in “Members nearby” results | Only if the User has agreed to “Receive invitations”, and only to Users who have completed KYC adult verification |
Members nearby is based on the main area chosen at registration. The Company does not track Users' location in real time. Only when a User chooses to use location lookup does it receive their position at that moment to determine their area; the coordinates are rounded to about 1 km, stored so that only the User can see them, and never shown to other Users. The distance shown on screen is the approximate distance between the centres of the two Users' registered areas. Only Users who have agreed to “Receive invitations” at registration or on the Edit profile screen appear in this search. Agreeing is optional and can be withdrawn at any time on the Edit profile screen; once withdrawn, the User no longer appears in search results.
Gender is always shown to other Users because of the nature of the Service, and there is no option to hide it. Profile photos have the extra information embedded in them (EXIF), such as where the photo was taken, removed on the User's device before they are stored. When a photo is deleted or replaced, the previous photo is also deleted from storage.
Email address, password, phone number, ID details, date of birth, IP address and legal guardian information are not shown to other Users. A verification badge shows only that verification was completed, not the information used for it.
5Retention and Deletion
| Data | Retention period |
|---|---|
| Account information, profile | 5 years after account closure (use suspended on closure, deleted after 5 years) |
| Legal guardian consent records | Same as member data (5 years after account closure) |
| Location coordinates (to about 1 km) | Replaced or deleted when the User changes location or chooses an area from the list; deleted immediately on account closure |
| Location lookup records (area names and result, without coordinates) | 30 days |
| Sign-up data of Users under 16 whose guardian consent was not confirmed | Deleted without delay if not consented within 7 days of registration, or if refused |
| ID images, face photo | Not kept by the Company (handled by the verification provider under its own policy) |
| Date of birth | Not kept by the Company. Only whether the User is 19 or older (pass/fail) is received and kept |
| Chat messages | 5 years after being written |
| Report and block records | 5 years after being resolved |
| Access logs (IP address etc.) | 3 months |
ID images and face photos are never sent to the Company's servers. Adult verification takes place directly on the screens of a specialist verification provider (Didit), and the Company receives and keeps only the result — ‘whether the User is 19 or older’ — and the time of review. The Company does not hold the captured images or the original date of birth; these follow the provider's retention policy.
When a member closes their account, the account is suspended immediately and the nickname, short bio and interests are deleted. However, data including report history and chat logs is kept for 5 years from the date of closure, for dispute handling and to block repeat offenders, and then deleted.
Where applicable law sets a separate retention period, that period applies.
6Processors and International Transfers
To provide the Service, the Company entrusts the processing of personal data to the following companies, whose servers are located outside Korea and Vietnam.
| Processor | Task | Storage location |
|---|---|---|
| Supabase, Inc. | Database, account authentication, file storage | United States etc. (selected region) |
| Vercel, Inc. | Web application hosting and deployment | United States etc. |
| Google LLC | Converting coordinates to administrative areas, address and place search, map display | United States etc. |
| Didit | ID authenticity checks, face matching, checking whether a User is 19 or older | Outside Korea and Vietnam |
| (To be completed: email delivery service used) | Sending legal guardian consent request emails | Outside Korea and Vietnam |
Users have the right to refuse international transfers, but if they refuse, use of the Service will be restricted. The Company signs data protection agreements with its processors and oversees their processing.
The Company does not provide personal data to third parties except with the User's separate consent or where the law provides a basis.
7Users' Rights
Users may exercise the following rights at any time.
- Request access to their personal data
- Request correction of errors
- Request deletion
- Request that processing stop
- Withdraw consent and close their account
Profile information can be viewed and corrected directly under ‘Edit profile’ in the Service. For other requests, contact us at the address below; we will act without delay and notify you of the outcome.
8Personal Data of Children Under 16
The Company obtains the consent of a legal guardian to process the personal data of children under 16. Korea's Personal Information Protection Act treats those under 14, and Vietnam's personal data protection law those under 16, as children requiring a legal guardian's consent, so the Company uses 16 as the threshold to meet both standards.
How consent is confirmed. The Company sends the consent details to the legal guardian's email address entered by the child at registration, and the legal guardian chooses whether to consent directly through the link in that email. The consent link is valid within 7 days of registration, and sending a new request makes the previous link unusable.
Until consent is confirmed, only the minimum data needed to request consent (the child's account email and the legal guardian's name, email and relationship) is processed, and use of the Service — creating a profile, hosting or applying to meetups, invitations, chat and so on — is restricted.
If consent is not confirmed within 7 days of registration, or the legal guardian refuses consent, the account and the data collected are deleted without delay.
Legal guardians may request access to, correction or deletion of, or suspension of processing of a child's personal data, and may withdraw consent. Contact the privacy officer below and we will act without delay.
Whether a User is 16 or older is confirmed by the User's own selection at registration. If it is found that a User under 16 registered by selecting otherwise, the Company may restrict use of the account and either carry out the legal guardian consent procedure or delete the data.
9Security Measures
- Passwords are stored encrypted in a way that cannot be reversed.
- HTTPS encryption is applied to all communication.
- Row-level access control (Row Level Security) is applied to the database so that Users can access only data they are authorised to see.
- Access to personal data is granted only to the minimum number of people who need it for their work.
10Cookies
The Company uses essential cookies to keep Users logged in. Users can refuse cookies in their browser settings, but they will then not stay logged in.
The Company does not use third-party cookies for advertising tracking.
11Privacy Officer
For questions about the handling of personal data, complaints and remedies, please contact us below.
| Item | Details |
|---|---|
| Officer | (To be completed) |
| Contact | info@matetoday.com |
| Company name / Business registration number | (To be completed) |
| Address | (To be completed) |
12Changes to This Policy
When this Policy changes, the effective date and reason for the change will be announced in the Service. Changes unfavourable to Users will be announced 30 days before the effective date.