CashLearning Privacy Policy
JC Beat (hereinafter "Company"), the provider of the CashLearning service, establishes and discloses this Privacy Policy to protect users' personal information in accordance with the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, and other related laws, and to promptly and smoothly handle related grievances.
Article 1 (Purpose of Processing Personal Information)
The Company processes personal information for the following purposes. Personal information being processed will not be used for purposes other than the following, and if the purpose of use changes, necessary measures will be taken such as obtaining separate consent.
1. Member Registration and Management
- Identity verification (mobile phone verification), personal identification, confirmation of intent to register
- Prevention of duplicate registration and fraud, restriction of re-registration after withdrawal
2. Service Provision
- Provision of economic news and learning content, management of learning records
- Accumulation and use of rewards (points and raffle tickets)
- Friend invitations (the inviting member is shown the invited friend's name and progress)
3. Gift Card Exchange and Raffle Prize Delivery
- Recipient verification, delivery of gift cards and prizes
4. Notifications
- Daily question reminders and service announcements (if the user agreed to push notifications)
- Notices the member needs to receive, such as raffle wins
5. Advertising
- Provision of advertising through Google AdMob and ad networks connected to AdMob, ad performance analysis
6. Service Improvement
- Service usage statistics analysis, error analysis, service quality improvement
7. Event News (Promotional Information) (with optional consent)
- Announcements of events and benefits
Article 2 (Processing and Retention Period of Personal Information)
1. The Company processes and retains personal information within the period of retention and use of personal information under the law or within the period of retention and use of personal information agreed upon when collecting personal information from data subjects.
2. The processing and retention periods for each category of personal information are as follows:
[Member Information]
- Retention Period: Until membership withdrawal
- Basis: User consent
[Re-registration Check Information of Withdrawn Members, such as Mobile Phone Number]
- Retention Period: 30 days after withdrawal
- Purpose: Restriction of re-registration after withdrawal and fraud prevention
- Basis: User consent
[Receiving Information for Gift Card Exchanges and Raffle Prizes]
- Retention Period: 3 months after delivery is completed
- Purpose: Delivery confirmation and handling inquiries
- Basis: User consent
[Access Logs]
- Retention Period: 3 months
- Basis: Protection of Communications Secrets Act
Article 3 (Items of Personal Information Processed)
The Company processes the following personal information items:
1. Items Collected at Registration (Required)
- Social login information: Unique identifier (ID), email address, name or nickname
- Mobile phone number (identity verification and prevention of duplicate registration)
- Device information: Device identifier, device name or model, OS and app version
2. Items Generated or Automatically Collected During Service Use
- Learning and question records, point and raffle ticket history, invitation records, inquiry history
- Access logs, IP address, advertising identifier (ADID/IDFA), push notification token, app error logs, app install source
3. Items Collected When Applying for Gift Card Exchange
- Receiving mobile phone number or email (Retention: 3 months after delivery is completed)
4. Items Collected When Winning a Raffle
- Name, mobile phone number (Retention: 3 months after prize delivery is completed)
5. Optional Items
- Consent status for event news (promotional information) and push notifications
Article 4 (Provision of Personal Information to Third Parties)
1. In principle, the Company processes users' personal information within the scope specified in Article 1 (Purpose of Processing Personal Information) and does not process it beyond the original scope or provide it to third parties without the consent of the data subject.
2. However, personal information may be provided to third parties in the following cases:
- When the user has given prior consent
- When required by law or requested by investigative agencies following procedures and methods prescribed by law for investigation purposes
3. A raffle winner's name is shown on the raffle screen partially masked (e.g., K*m) and is visible to other users.
Article 5 (Overseas Transfer of Personal Information)
The Company transfers personal information overseas as follows for service provision. The member database is stored in the Republic of Korea (Seoul) region.
1. Google LLC (United States)
- Purpose of Transfer: Login and mobile phone verification, push notification delivery, app usage statistics and error analysis (Firebase), advertising (AdMob)
- Items Transferred: Email address, name, mobile phone number, device identifier, advertising ID, push notification token, app usage records, IP address
- Date and Method of Transfer: Transmission through the network during service use
- Retention Period: Until membership withdrawal or achievement of the entrusted purpose (subject to Google's Privacy Policy)
2. Ad Networks (United States) — Meta Platforms, Inc. (Meta Audience Network), Unity Software Inc. (Unity Ads), Liftoff Mobile, Inc. (Vungle)
- Purpose of Transfer: Advertising
- Items Transferred: Advertising ID, device information, IP address
- Date and Method of Transfer: Transmission through the network when ads are displayed
- Retention Period: Subject to each company's privacy policy
3. Users may refuse the overseas transfer of personal information. If the overseas transfer of member information is refused, registration is not possible; transmission of the advertising ID can be limited as described in Article 10.
Article 6 (Entrustment of Personal Information Processing)
The Company entrusts personal information processing as follows for smooth service provision:
1. Google LLC
- Entrusted Tasks: Cloud servers and database (Firebase), sending mobile phone verification messages, push notification delivery, app analysis
- Personal Information Items: Member information, device identifier, service usage records, advertising ID
2. KT alpha Co., Ltd. (Giftishow Biz)
- Entrusted Tasks: Mobile gift card delivery
- Personal Information Items: Receiving mobile phone number
When concluding entrustment contracts, the Company stipulates necessary matters to ensure that personal information is safely managed in accordance with related laws.
Article 7 (Rights and Obligations of Data Subjects and Legal Representatives and Method of Exercise)
1. Users may exercise the following personal information protection rights against the Company at any time:
- Request to access personal information
- Request for correction if there are errors
- Request for deletion
- Request to suspend processing
2. Rights can be exercised by contacting Customer Service ("Contact Us" in the app settings, or email cashlearning1997@gmail.com). Membership withdrawal can be done directly in the app settings.
3. The Company does not accept registration from children under 14 years of age. If the Company becomes aware that personal information of a child under 14 has been collected, it will destroy it without delay.
4. If a user requests correction or deletion of errors in personal information, the Company will not use or provide the personal information until the correction or deletion is completed.
Article 8 (Destruction of Personal Information)
1. The Company destroys personal information without delay when personal information becomes unnecessary, such as when the retention period has expired or the processing purpose has been achieved.
2. If personal information must continue to be preserved under other laws despite the expiration of the retention period agreed upon by the user or the achievement of the processing purpose, the personal information is transferred to a separate database (DB) or stored in a different location.
3. Procedures and Methods for Destruction of Personal Information
- Destruction Procedure: The Company selects personal information for which destruction reasons have occurred and destroys the personal information with the approval of the Personal Information Protection Officer.
- Destruction Method: For information in electronic file format, technical methods that prevent record reproduction are used. Any personal information printed on paper is destroyed by shredding or incineration.
Article 9 (Measures to Ensure Security of Personal Information)
The Company takes the following measures to ensure the security of personal information:
1. Technical Measures
- Encryption in transit: Communication between the app and the servers is encrypted (HTTPS).
- Encryption at rest: Data stored on the servers is protected by the cloud provider's default encryption.
- Access control: Database access rules allow members to read and write only their own information, and important values such as points can be changed only by the server.
2. Administrative Measures
- The number of personal information handlers and administrator accounts is minimized, and access rights are managed.
Article 10 (Installation, Operation, and Rejection of Automatic Personal Information Collection Devices)
1. The Company uses the following automatic personal information collection technologies for service provision:
- Firebase Analytics: App usage statistics analysis
- Firebase Crashlytics: App error analysis
- Google AdMob and connected ad networks: Advertising (using advertising ID)
2. Users can refuse advertising ID collection in device settings:
- Android: Settings > Google > Ads > "Delete advertising ID" or "Opt out of Ads Personalization"
- iOS: Settings > Privacy > Tracking > Disable "Allow Apps to Request to Track"
3. Even if advertising ID collection is refused, service use is possible, but general ads may be displayed instead of personalized ads.
Article 11 (Personal Information Protection Officer)
The Company designates a Personal Information Protection Officer as follows to take overall responsibility for personal information processing and to handle user complaints and damage relief related to personal information processing:
Personal Information Protection Officer
- Position: Representative, JC Beat
- Contact: cashlearning1997@gmail.com
Department in Charge of Personal Information Protection
- Department: JC Beat Customer Support
- Contact: cashlearning1997@gmail.com
Article 12 (Request to Access Personal Information)
Users can make requests to access personal information under Article 35 of the Personal Information Protection Act through the following contact:
- Email: cashlearning1997@gmail.com
Additionally, users may apply for dispute resolution or consultation with the Personal Information Dispute Mediation Committee, Korea Internet & Security Agency Personal Information Infringement Report Center, etc., to receive relief for personal information infringement:
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- National Police Agency: 182 (ecrm.cyber.go.kr)
Article 13 (Changes to the Privacy Policy)
1. This Privacy Policy is effective from the effective date, and if there are additions, deletions, or corrections of changes according to laws and policies, they will be announced through in-app announcements or notifications from 7 days before the implementation of the changes.
2. This Privacy Policy is effective from October 1, 2026.