Draft pending review. The company details, retention periods
and the privacy officer's contact in this document are placeholders marked
[CONFIRM]. They must be filled in and the whole document reviewed by
counsel before Fyer accepts real users or submits to an app store.
This policy explains what Fyer collects when you use the Fyer app, why we collect it, who else sees it, and how long we keep it. We have written it to describe what the service actually does rather than to cover every theoretical case.
- 01 Who we are
- 02 What we collect
- 03 How we handle your passport
- 04 Why we use it
- 05 Who we share it with
- 06 Blockchain data
- 07 How long we keep it
- 08 Your rights
- 09 How we protect it
- 10 Where your data goes
- 11 Children
- 12 Changes
- 13 Contact
01Who we are
Fyer is operated by RN2 Technology Co., Ltd. We decide what personal data is collected through the service and why, which makes us the controller of that data.
| Company | RN2 Technology Co., Ltd. [CONFIRM] |
|---|---|
| Business registration | 128-81-69024 [CONFIRM] |
| Representative | Kang Ho Kim [CONFIRM] |
| Address | 1F, 11, Dongtansandan 9-gil, Dongtan-gu, Hwaseong-si, Gyeonggi-do, Republic of Korea [CONFIRM] |
| Privacy officer | [CONFIRM — name, title, email] |
02What we collect
Everything below is collected because a specific part of the service needs it. We do not collect anything for advertising, and we do not track you across other apps or websites.
You give us
| Data | When |
|---|---|
| Full name, nationality, date of birth, passport expiry date | Identity check at sign-up |
| A one-way fingerprint of your passport number — never the number itself | Identity check at sign-up |
| Wallet address you deposit from | When you link a wallet |
The service records as you use it
| Data | Why it exists |
|---|---|
| Deposits, conversions, voucher issuance, spending and refunds | Your balance and history |
| Voucher records and remaining balances | So the amount shown at the counter is correct |
| App install identifier, platform, app version | Binding a session to one device and detecting hijacking |
| Push notification token | Only if you allow notifications |
| Risk signals on transactions | Detecting fraud and misuse |
| Access and change logs | Audit trail |
What we do not collect
- Your contacts, photos, calendar or location
- Advertising identifiers, and no third-party analytics or ad SDKs
- Your card or bank account details — the service never asks for them
- The private keys to any wallet
03How we handle your passport
Confirming who you are is required before Fyer can issue vouchers to you. Your passport is read by a specialist identity provider inside the app. What reaches Fyer's own systems is limited:
- We store your name, nationality, date of birth and passport expiry date.
- We store a one-way cryptographic hash of your passport number. The number itself is never written to our database. A hash lets us tell two accounts apart and stop the same passport being used twice; it cannot be turned back into your passport number.
- We do not keep the passport photo page image or the chip data after the check completes.
The identity provider handles the scan and chip read under its own privacy terms.
[CONFIRM — provider name, its policy URL, and what it retains]
04Why we use it
| Purpose | What it covers |
|---|---|
| Running the service | Creating your account, issuing vouchers, showing balances, processing refunds |
| Confirming identity | Checking you are who you say you are before value is issued |
| Preventing fraud and misuse | Risk scoring, duplicate-account detection, investigating suspicious activity |
| Keeping records straight | Reconciling our ledger against the voucher issuer's |
| Meeting legal obligations | Record-keeping and reporting duties that apply to us [CONFIRM with counsel] |
| Support | Answering you when you contact us |
We do not sell personal data, and we do not use it to build advertising profiles.
05Who we share it with
We share only what each party needs to do its job.
| Who | What they receive | Why |
|---|---|---|
| The tourism voucher issuer | Voucher identifiers, amounts and usage events | Vouchers are issued and settled on their system |
| Identity verification provider | Your passport scan and chip read, at the moment of the check | To confirm your identity |
| Cloud hosting (Amazon Web Services) | Stores the data on our behalf | Running the service |
| Apple and Google | Push notification tokens and message payloads | Delivering notifications you turned on |
| Authorities | Only what a valid legal request requires | Legal obligation |
[CONFIRM — exact legal names of the voucher issuer and identity provider, and links to their policies]
06Blockchain data
When you send stablecoins to Fyer, that transfer happens on a public blockchain. The deposit address, the amount and the time are public and permanent. Nobody — including us — can edit or delete them.
We do not publish your name or passport data on any blockchain. But be aware that if you tell someone your wallet address, they can look up its activity themselves.
07How long we keep it
| Data | Kept for |
|---|---|
| Identity check results and the passport hash | [CONFIRM] |
| Transaction and voucher records | [CONFIRM] |
| Access and audit logs | [CONFIRM] |
| Push tokens | Until you turn notifications off or the token stops working |
| Support messages | [CONFIRM] |
These periods are set by law rather than by preference, and the applicable retention rules have not been confirmed yet. Counsel must set each figure before this document is published as final.
When a period ends we delete the data or strip it of anything that identifies you.
08Your rights
You can ask us to:
- show you what we hold about you
- correct anything that is wrong
- delete your data, where we are not required to keep it
- pause our use of it while a dispute is open
- send you a copy in a portable format
- stop sending notifications — you can also do this in your device settings
Write to the address in section 13. We will respond within the period the law allows. Two limits are worth stating plainly: we cannot remove anything already written to a public blockchain, and we cannot delete records we are legally required to keep until that period ends.
09How we protect it
- Traffic is encrypted in transit, and the connection to the voucher issuer runs over a dedicated tunnel rather than the open internet.
- Your passport number is stored only as a one-way hash.
- Access to production systems is restricted and logged.
- Sensitive actions in the app require your PIN.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant authority as the law requires.
10Where your data goes
Fyer's systems run in the Republic of Korea. If you use the service from outside Korea, your data is processed in Korea. Push notifications are delivered through Apple and Google, which operate internationally.
11Children
Fyer is not for children. You must be at least 19 to use it, and the identity check at sign-up confirms your date of birth. If we learn that we hold data from a child, we delete it.
12Changes
When this policy changes we update the effective date at the top and post the new version here. If a change materially affects you, we will tell you in the app before it takes effect.
13Contact
Privacy questions and rights requests: contact@fypherusd.com
If you are not satisfied with our answer, you may complain to the data protection authority where you live, or to the Personal Information Protection Commission in Korea.