Privacy

OHMYPLAY Gym Privacy Policy

How OHMYPLAY Gym handles personal information about gym operators, staff, instructors, and members.

Effective · August 26, 2026Version · gym-privacy-2026-08-26-v2

OHMYPLAY Inc. (the “Company,” “we,” or “us”) respects the privacy of gym operators, staff, instructors, and members who use OHMYPLAY Gym. We process personal information in accordance with the Personal Information Protection Act of the Republic of Korea (“PIPA”) and other laws that apply to us.

This English version is provided for convenience. If there is any inconsistency between the Korean and English versions, the Korean version controls to the extent permitted by applicable law.

This Policy applies to the gym management website, the OHMYPLAY Gym member app, and the kiosk and display features (collectively, the “Service”). MatchCAM, OMP Scoreboard, StudioCAM, and the Company website are governed by their own privacy policies.

1. The Roles of OHMYPLAY and Gym Operators

OHMYPLAY is the controller of personal information for Service accounts, authentication, security, payments, customer support, and other purposes for which we determine how and why information is processed.

When a gym operator enters information about its members, instructors, or staff for its own gym operations, the gym operator is the controller and OHMYPLAY processes that information as the gym's processor or service provider. We process it under the Service agreement and data-processing terms, manage subprocessors and safeguards, and help the gym return or delete information and respond to privacy requests.

OHMYPLAY is an independent controller for OHMYPLAY accounts, authentication and security, payments made to us, customer support, and legal obligations for which we determine the purposes and means. A request about information entered by a gym is normally referred to that gym, and we cooperate with the gym when a request is submitted to us.

2. Personal Information We Process, Why, and Where It Comes From

The information we process depends on the features you use. If you do not provide optional information, only the related optional feature may be unavailable.

2.1 Operator and Staff Accounts

  • Information: email address, name, internal user ID, sign-in provider and provider identifier, authentication and sign-in records, and account role
  • Purposes: registration, sign-in, identity and access verification, gym administration, account security, and support
  • Sources: information you enter, Google·Apple·Kakao sign-in, and information generated by our authentication systems

2.2 Gym Operations

  • Gym and contact details: gym name, address, time zone, SMS sender number, and operational settings
  • Members and instructors: name, phone number, status, affiliation, skill level, notes, instructor biography and specialties, and a four-digit kiosk PIN
  • Reservations and activity: facility and court bookings, schedules, event and lesson registrations and cancellations, participation, check-in and check-out, queues and court assignments, and match, score, ranking, and activity records
  • Content and communications: notices, SMS recipient number, message content and delivery result, uploaded poster and banner images, and display settings
  • Purposes: operating memberships, facilities, lessons, and events; managing venue entry, queues, matches, and rankings; sending notices; and controlling displays
  • Sources: gym operators, staff, and members; information generated through the app or kiosk; and connected services selected by the operator

Gym operators must not enter sensitive information, national identification numbers, or similar government identifiers in free-form fields, notes, notices, or images. We do not intentionally collect health information, biometric identifiers, or precise geolocation because they are not needed to provide the Service.

2.3 OHMYPLAY Gym Member App

  • Account and profile: sign-in provider identifier, email address and provider profile name, internal user ID, display name, phone number, profile image URL if provided, and the time of minimum-age confirmation for an independent account
  • Gym connection: linked member and gym IDs, active gym, and membership status
  • Service use: event and lesson registrations and cancellations, price and currency snapshots, check-in and check-out, queue and court status, match and ranking participation history, and kiosk PIN settings
  • Notifications: notification permission status, Firebase Cloud Messaging (“FCM”) token, and device platform
  • Purposes: social sign-in, linking an app account to an existing gym membership, providing registration and venue features, and sending necessary Service notifications

When you link an existing gym membership to an app account, we send a six-digit code to the phone number registered by the gym. We do not store the code itself. We store a verification value produced using a server secret, its expiration time, the number of attempts, and the result. The code is valid for five minutes.

Before entering member information, a gym operator must provide its own privacy notice or venue notice and establish an appropriate legal basis for processing, venue displays, and SMS delivery. We provide product notices and privacy-request support to help gyms meet those obligations.

2.4 Payments, Support, and Optional Integrations

  • Payments: order ID, order name, amount, status, request and approval time, receipt URL, and transaction information returned by the payment processor. We do not directly store full card numbers or card passwords.
  • Support: name, email address, message, and any attachment or contact information you choose to provide
  • Reservation and calendar integrations: when enabled by an operator, a Naver or other reservation account, an encrypted application password, an encrypted Google Calendar iCal URL, and reservation name, phone number, service, time, and status
  • Purposes: subscriptions and payment records, responding to requests, and synchronizing a gym’s reservations and schedules

An integration operates only when selected by a gym operator. The privacy policy of the connected third-party service also applies.

2.5 Information Generated Automatically

  • IP address, request time, access and security logs, browser or device, operating system, app version, language and time zone, and error, crash, and performance diagnostics
  • Cookies or similar technologies used for sign-in sessions and language or theme preferences
  • Purposes: maintaining sessions, preventing misuse, troubleshooting, security, and improving Service reliability

We do not provide personalized advertising and do not use Service activity for decisions that produce legal or similarly significant effects solely by automated means.

3. Legal Bases for Processing

Depending on the context and applicable law, we process personal information on one or more of the following bases:

  • performing a contract with you or a gym and taking steps requested before entering a contract;
  • your consent for an optional feature;
  • complying with legal obligations, including applicable transaction, tax, and dispute requirements; and
  • legitimate interests such as account and network security, fraud and abuse prevention, and Service reliability, after documenting that the processing is necessary, reasonably expected, proportionate, and not overridden by the affected individual's rights.

4. Disclosures and Venue Displays

We do not sell personal information or share it for cross-context behavioral advertising. We do not disclose it to a third party except when:

  • you separately consent to a specific disclosure;
  • disclosure is required by law or a valid legal process; or
  • applicable law permits disclosure to protect an urgent interest in life, physical safety, or property.

An event participant’s name, queue position, court assignment, match score, and ranking may be visible to other people at the selected gym on its kiosk or venue display. This is an on-site display for event and match operations, not publication to the open internet. You may ask the gym or OHMYPLAY to correct or limit inappropriate display information.

5. Retention

We retain information only as long as needed for the purposes described above and delete it without undue delay when the purpose ends.

  • Account, profile, and social sign-in links: until the account is deleted
  • Gym member, instructor, and operational information: for the retention period set by the gym as controller, until the gym instructs us to delete it, or until the Service agreement ends; legal-hold and dispute records are separated
  • Event, lesson, check-in, queue, and match records: for the period instructed by the gym for member history and operations, or until a gym instruction or valid deletion request is completed
  • SMS verification records: the verification value is valid for five minutes; used, failed, and expired verification records are deleted within 30 days after creation
  • API rate-limit records: deleted within 24 hours after their last update
  • Push tokens: until account deletion, token invalidation, or the notification feature is discontinued
  • Support enquiries: one year after the enquiry is completed
  • Payment and transaction records: where required by law, up to five years for contract, payment, and supply records and up to three years for consumer complaints or disputes
  • Access, security, and error records: for the minimum period needed for security and incident investigation; a record needed for an incident or legal obligation is separated until that reason ends, and provider retention is configured to the shortest practical period

Information subject to a legal hold is segregated and not used for unrelated purposes. Backup copies are deleted through regular backup rotation.

6. Service Providers

We use service providers to operate the Service and require them by contract to protect personal information and use appropriate safeguards.

  • Supabase, Inc.: authentication, database, file storage, and backend functions
  • Vercel Inc.: management website and API hosting and request and security logging
  • Google LLC and relevant Google entities: Google sign-in, Firebase Cloud Messaging, Firebase crash diagnostics, and kiosk and display synchronization
  • Apple Inc.: Sign in with Apple
  • Kakao Corp.: Kakao sign-in
  • Alipeople Inc. (ALIGO): phone verification and gym SMS delivery
  • Toss Payments Co., Ltd.: payment processing and confirmation
  • Plus Five Five, Inc. (Resend): Service and support email delivery
  • Intuition Machines, Inc. (hCaptcha): contact-form bot and abuse prevention
  • Cloudflare, Inc. (Turnstile): contact-form bot and abuse prevention

Information is not sent to a provider when the relevant feature is not used or its configuration is not enabled. We will update this Policy if a material provider or processing task changes.

7. International Processing and Transfers

Our core Service database is operated in the Seoul region of the Republic of Korea. Global authentication, mobile notifications, crash diagnostics, and web hosting may require processing in other countries as described below. Information is encrypted in transit.

7.1 Supabase and Vercel

  • Recipients, countries, and contacts: Supabase, Inc. / United States / privacy@supabase.com; Vercel Inc. / United States and Republic of Korea / privacy@vercel.com
  • Information: account identifiers, profiles, gym operations, member, reservation, and activity information, uploaded files, and IP, request, and error logs
  • Purpose: authentication, data storage, API and web hosting, security, and troubleshooting
  • Timing and method: encrypted network transfer when you register, sign in, save data, or make a Service request
  • Retention: core data is stored in the Seoul region for the Section 5 periods. Account administration and security support may occur in the United States and are deleted after the support purpose or provider agreement ends.

7.2 Google Firebase and Google Sign-In

  • Recipients, countries, and contact: Google LLC and Google Asia Pacific Pte. Ltd. / United States and Singapore, including global infrastructure / Google privacy contact form
  • Information: sign-in identifier and provider profile, FCM token and platform, kiosk and display synchronization state, and app, device, error, and crash diagnostics
  • Purpose: sign-in, push notifications, real-time synchronization, and reliability analysis
  • Timing and method: encrypted network transfer when you use Google sign-in, receive a notification token, synchronize data, or encounter an error
  • Retention: until the sign-in link, account, or FCM token is deleted; crash diagnostics are retained for the period configured in Firebase or until the diagnostic purpose ends

7.3 Apple and Resend

  • Recipients, countries, and contacts: Apple Inc. / United States / Apple privacy contact; Plus Five Five, Inc. / United States / privacy@resend.com
  • Information and purposes: authentication identifier, email, and name when Sign in with Apple is selected / email recipient, name, content, and delivery status for Service emails
  • Timing and method: encrypted network transfer when you sign in or an email is sent
  • Retention: until the Apple sign-in connection or account is deleted / until email delivery and error handling are completed or the contractual retention period ends

7.4 hCaptcha and Cloudflare Turnstile

  • Recipients, countries, and contacts: Intuition Machines, Inc. / United States / support@hcaptcha.com; Cloudflare, Inc. / United States and European Economic Area / dpo@cloudflare.com
  • Information and purpose: contact-page IP address, browser and device details, request time, security signals, and CAPTCHA token / preventing automated submissions, spam, and abuse
  • Timing and method: encrypted network transfer when the CAPTCHA runs or the contact form is submitted
  • Retention: until the security purpose is completed and for the provider's applicable security-log retention period

Where international processing is necessary to perform the Service contract, you may decline by not creating an account or not using the optional feature. Declining a transfer essential to authentication, notification delivery, or hosting may make all or part of the Service unavailable. Contact us below to ask about an international transfer or request that optional processing stop.

8. Deletion

When a retention period ends or a processing purpose is fulfilled, we review and delete the information without undue delay. Electronic records are deleted using methods designed to prevent recovery. Any paper record is shredded or destroyed. Information under a statutory retention requirement is separated, access-restricted, and deleted when that period ends.

Member-app users can delete an account directly under Profile → Settings → Delete account. If the app is unavailable, follow the instructions at /account-deletion/en and submit a request from the account email address. Management-web users may use the deletion feature in account settings. Deletion removes the authentication account, member-app profile, social sign-in links, push tokens, and account-linked authentication records. Gym-controlled membership, participation, match, and payment records may remain for a legal obligation or multi-participant record integrity; you may ask the gym or OHMYPLAY to correct or delete those records.

9. Your Privacy Rights

You may request access to, correction or deletion of, restriction or cessation of processing of, or withdrawal of consent for your personal information. Where applicable, you may also request that an international transfer stop. Submit a request through a feature available in the app or management website or contact us below. We verify the requester’s identity, respond as required by applicable law, and explain any lawful limitation.

You may also ask the relevant gym to correct information that it entered. An authorized agent may act for you after providing appropriate proof of authority.

10. Children’s Privacy

The Service is not directed to children under 13 in the United States. A new independent member-app account must confirm at profile creation that the user is at least 14. We store the confirmation time but do not collect a date of birth. We do not currently offer a verifiable-parental-consent workflow, so a child under 14 may not create an independent account.

When a gym enters a minor member’s information for a youth sports program, the gym operator must give notices and obtain consent from the child and parent or legal guardian as required by applicable law. If we learn that information requiring parental consent was collected without appropriate consent, we will restrict the account and take steps to verify consent or delete the information. A gym that needs youth accounts must contact us before deployment.

11. Additional Notice for United States Residents

Information about U.S. users is processed in the Republic of Korea and may be transferred to the countries listed in Section 7. Privacy protections and lawful government access in those countries may differ from those in your state.

If an applicable U.S. state privacy law grants you rights, you may request confirmation, access to categories or specific pieces of personal information, correction, deletion, or a portable copy. You may also have rights to opt out of sale, sharing, targeted advertising, or qualifying profiling; to limit certain uses of sensitive personal information; to be free from discrimination for exercising a right; and to appeal a denied request.

We do not sell personal information for money, share it for cross-context behavioral advertising, use sensitive personal information to infer characteristics or for advertising, or knowingly sell or share the personal information of anyone under 16 for targeted advertising. We therefore do not currently provide a separate “Do Not Sell or Share My Personal Information” link. If our practices change or applicable law requires such a link, we will provide advance notice and the required choice.

Submit a request to the email address below with “U.S. Privacy Request” in the subject line. We may reasonably verify your identity and, for an authorized-agent request, the agent’s authority. We will not treat you adversely solely because you exercised a privacy right.

12. Cookies and App Permissions

The management website uses essential cookies for sign-in sessions, language, theme, and security. You may block cookies in your browser, but sign-in and related features may not work. The Gym Service does not currently use advertising cookies, cross-site tracking, or personalized advertising trackers. Because we do not sell or share information for advertising, Do Not Track and Global Privacy Control signals do not change an advertising activity; we will honor them where applicable law requires. hCaptcha and Turnstile process security signals on the contact form, and we do not use those signals for advertising.

The member app asks for notification permission when a notification-related feature is used. You may deny it and continue using core app features, but you may not receive queue or other Service notifications. You can change this permission in device settings.

13. Security

We use reasonable technical and organizational measures designed to protect personal information against loss, theft, unauthorized disclosure or access, falsification, alteration, and destruction, including:

  • encryption in transit and protection of authentication information;
  • role- and gym-based access controls, least privilege, and database row-level security;
  • restricted administrative and service access and security-log review;
  • encryption or verification-value processing for passwords and integration secrets; and
  • security updates, backup, and incident-response procedures.

No method of transmission or storage is completely secure, but we continue to improve safeguards appropriate to the risk.

14. Privacy Contact

  • Controller: OHMYPLAY Inc.
  • Chief Privacy Officer: Jaewoong Kang
  • Address: Unit 101, 1F, 24 Seongam-ro 11-gil, Mapo-gu, Seoul, Republic of Korea
  • Email: info@ohmyplay.com Phone: +82-2-6925-5543

Korean residents may also contact the Personal Information Dispute Mediation Committee at 1833-6972, the KISA Privacy Infringement Report Center at 118, or the Korean National Police Agency at 182.

15. Changes to this Policy

This Policy is effective August 26, 2026. If we make a material change, we will provide notice of the change and effective date through the Service or website before it takes effect. Previous versions are managed and can be provided on request.