Skip to content
K-Trip Passport
Home

Legal

Privacy Policy

Effective date: 2026-08-29
Operator: DJ.H (Do Jin-hyeon)
App: K-Trip Passport (com.slt.ktrippassport)
Contact: cmjh951330@gmail.com

K-Trip Passport is a souvenir album. It is not issued by any government. The passport-style fields you enter (name, nationality, date of birth, and so on) are for the keepsake only — not for official identification.

Contents

  1. Introduction
  2. Controller
  3. Information we collect
  4. How we collect
  5. Purpose of use
  6. Legal basis
  7. Retention
  8. Sharing and processors
  9. International transfers
  10. Security
  11. Your rights
  12. Children
  13. Cookies and this website
  14. Changes
  15. Contact

1. Introduction

This Privacy Policy explains how K-Trip Passport (package ID com.slt.ktrippassport) collects, uses, stores, and shares personal information when you use the mobile app and this website (the “Service”).

The Service is a keepsake travel passport. You photograph culture moments, turn them into stamps, and collect them in themed visa pages. We do not sell personal information for advertising.

2. Controller

The personal information controller (operator) for K-Trip Passport is DJ.H (Do Jin-hyeon).

Privacy requests: cmjh951330@gmail.com

During launch the Service is operated as an independent product. We do not operate a separate corporate privacy office; the operator email above is the primary contact channel.

3. Information we collect

Depending on how you use K-Trip Passport, we may process the categories below. Exact fields can vary by sign-in provider and device platform.

Category Examples Notes
Account Firebase Auth UID; email if the provider supplies it; display name; auth provider type (email, Google, Apple) Required to sign in and restore your account on a new device.
Passport holder (keepsake) Portrait photo; surname; given names; nationality; date of birth; sex (F/M/X); place of birth; generated souvenir passport number and issue date Shown on the identity spread in the app. Not a government record. We do not ask for a resident registration number or similar official ID.
Stamps and decorations Photos you capture or pick; circular stamp images; original photos; crop and style settings; sticker placements; mission titles you type for personal stamps Stored with your signed-in account (Supabase database and Storage). A new device can restore the same book after you sign in.
Device Approximate OS / platform; app version; Mixpanel distinct id (Firebase Auth UID after you sign in) Helps us diagnose issues and understand how the app is used. Not an advertising ID.
Product analytics In-app actions such as sign-in, passport issue, stamp save, decorate, and share (no photos or names) Processed by Mixpanel as a product-analytics processor. Not used for advertising or ATT “tracking”.
Infrastructure logs IP address, connection metadata, and standard server access logs Collected automatically by hosting and auth infrastructure for security and reliability — not for advertising profiles.

We do not collect

  • Precise GPS or continuous location tracking. You pick missions yourself; the camera does not geotag as a feature of the Service.
  • Device contacts or address book.
  • Payment card details or in-app purchase receipts. This version has no paid features.
  • Health, fitness, or biometric templates. The camera is used to take a portrait and stamp photos, not to identify you biometrically.
  • Android advertising ID (GAID) or IDFA.

Camera and photo-library access are used only when you take or pick a passport portrait, capture a stamp, or save a shared image. We do not access those sensors in the background.

4. How we collect

  • Directly from you — when you sign in, complete onboarding, edit passport details, take or pick photos, place stickers, or contact support.
  • From authentication providers — identity assertions (UID, email or name when provided) via Firebase Auth (email, Google, or Sign in with Apple).
  • Automatically in the app — product-analytics events (screen and feature use) sent to Mixpanel after you use the Service. Events do not include your email, name, or photos.
  • From hosting and auth infrastructure — IP and connection metadata recorded by servers and gateways.

Stamp photos, originals, decorations, and the keepsake passport are stored with your account in our database and photo storage (Supabase), so they can restore after you sign in on a new device. A cache may also remain in the app’s private documents folder on the device you used.

5. Purpose of use

We use personal information to:

  • Provide and operate the Service, including sign-in, the souvenir passport, stamp camera, decorations, sharing, and restoring the book on a device where you sign in.
  • Show you the identity spread and visa pages you created.
  • Link a Firebase Auth session to a Supabase session so the same account can load your passport and stamps.
  • Understand how the Service is used (product analytics via Mixpanel) so we can fix issues and improve features.
  • Send a hashed user identifier to an internal ops channel (Jandi) when a new account is created, so we can see sign-ups. That alert does not include your email or name.
  • Respond to support and account-deletion requests.

We do not sell personal information. We do not use advertising identifiers. We do not use your stamp photos to train public AI models.

6. Legal basis

Where GDPR or similar frameworks apply, we typically rely on: (a) performance of a contract — providing the account and keepsake passport you request; (b) legitimate interests — security and service improvement, balanced against your rights; and (c) consent — where required for optional camera or photo-library access.

Under Korean personal information law, we process information as necessary to provide the Service you use, to fulfill statutory obligations, and — where required — based on your consent for optional camera features.

7. Retention

  • Account — retained while your Firebase Auth login remains active.
  • Passport holder details, stamps, originals, and decorations — retained on our servers while the account remains, and in a local cache on devices you used until you reset the passport, delete the app data, or we complete an account-deletion request. Uninstalling the app removes the on-device cache but does not by itself delete the server copy.
  • Account deletion — see Delete Account. We aim to complete verified requests within 30 days.
  • Infrastructure logs — commonly 30–90 days unless an incident requires longer review.

8. Sharing and processors

We do not sell personal information. We share data with processors who help us run the Service:

  • Google Firebase — authentication (email, Google, Apple). The app sends a Firebase ID token so Supabase can recognize the same user.
  • Supabase — session via third-party auth; Postgres for the keepsake passport and stamp records; Storage buckets for passport portraits and stamp photos (including originals).
  • Mixpanel — product analytics (in-app events and a Mixpanel distinct id). Mixpanel processes this as our processor, not for advertising.

These processors act on our instructions. We may also disclose information if required by law, to protect the Service, or in connection with a transfer of the product, in which case this Policy would continue to apply or you would be notified.

9. International transfers

Firebase, Supabase, and Mixpanel may process data on servers outside your country, including regions in Asia and the United States. Our Supabase project is hosted in Asia Northeast (Seoul). By using the Service you understand that account information and product-analytics events may be transferred to those locations. We rely on the contractual and technical safeguards offered by those providers.

10. Security

We transmit account, database, and photo traffic over HTTPS. A cache of stamp files may remain in the app sandbox on the device. No method of transmission or storage is completely secure; we work to protect the Service with industry-standard practices. You are responsible for the device lock you use.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export personal information, to object to or restrict certain processing, and to withdraw consent for optional camera access. You can edit keepsake passport details in the app (Profile → Edit details). Delete the account in the app: Profile → Delete account. That removes the Firebase login and the souvenir data stored with the account. If you cannot open the app, email us as described on Delete Account. Profile → Reset passport clears the souvenir on the account; it does not delete the login.

Email cmjh951330@gmail.com to exercise these rights. We may need to verify that the request comes from the account holder.

12. Children

K-Trip Passport is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a person under 13 has created an account, contact us and we will delete it. Child sexual abuse and exploitation material is prohibited; we will remove it and report confirmed CSAM to the relevant authority.

13. Cookies and this website

This marketing website does not set advertising cookies. It is a static site. The browser may store ordinary technical data (such as IP address in host logs). We do not run ads, analytics pixels, or cross-site tracking on this site.

14. Changes

We may update this Policy. The effective date at the top will change when we publish a revision. Material changes may also be noted in the app or on this page.

15. Contact

Operator: DJ.H (Do Jin-hyeon)
Email: cmjh951330@gmail.com

See also: Terms of Service · Delete Account

© 2026 K-Trip Passport
Privacy Policy Terms of Service Delete Account Support Home

K-Trip Passport is a travel keepsake. It is not issued by any government and must not be confused with an official passport.