ClubLog Privacy Policy

Effective date: 19 August 2026 · Updated: 2026-10-03 · Operator: 유주환 (Toris)

ClubLog processes only the information needed to operate recreational sports clubs, schedules, match records and friendly-match coordination.

Information processed and its purposes

For email sign-in, we process the email address and account identifier needed for authentication. For Kakao login, we process the Kakao account identifier and profile information you consent to share. Club names, sports and activity areas; member display names and permissions; schedules and attendance; match scores and events; friendly-match requests and messages; and external video links and bookmarks are used to provide team operations and records. IP addresses, device and browser information, access times and error logs are used for security and incident response.

Optional usage analytics (Google Analytics/Firebase)

To improve ClubLog, we send usage analytics to Google Analytics (Firebase Analytics in the app) only from devices where you have consented in advance. Data includes app or web platform, language, sport, feature-use events such as team, schedule and record features, random analytics identifiers generated by the SDK (pseudonymous IDs), device and browser information, and approximate location inferred from masked IP addresses. We do not send names, emails, messages, invite links or match details. We do not collect data for advertising or collect advertising IDs. Analytics identifiers are not linked to sign-in accounts or team and match data stored on our server.

You can use every feature equally without consenting. Your choice applies separately to each device. You can consent or withdraw anytime by choosing Do not consent in Analytics settings on the sign-in screen or Optional usage analytics → Settings on the account screen.

Analytics processing abroad and retention

After consent, analytics data is sent over HTTPS during service use to Google LLC’s global servers and may be processed outside the Republic of Korea. See the Google Privacy Policy for processing details. The retention period for event-level and user-level data is set to 2 months; expired data is deleted through Google’s periodic deletion process. This retention setting does not apply to aggregated reports, which may remain separately.

Withdrawing consent stops new analytics transmissions and resets the local analytics identifier on this device. It does not immediately delete records already stored by Google. Past pseudonymous analytics records are not matched to individual accounts, so an account deletion request by email does not automatically identify and delete those records. They are handled under the retention conditions above.

Transmission and storage

All app and web communications are encrypted in transit using HTTPS/TLS. Authentication uses Amazon Cognito and Kakao. Service data is stored encrypted in the AWS Seoul region. Amazon CloudFront delivers web content.

Retention and deletion

Account and club data is retained until you leave the service or request deletion. Authentication and security logs are kept for up to 7 days, and support enquiries for 3 years after resolution. If a legal retention obligation applies, the information is stored separately for the required period. When an account is deleted, shared team records may remain as team-owned data after the author’s identifying information is removed.

Your rights

You may request access, correction, deletion, suspension of processing and withdrawal of consent. You can make a request through the app’s Team tab or the account and data deletion instructions.

Children’s privacy

The service is not intended for children under 14. If we learn that information was processed without consent from a legal guardian, we delete it without delay.

Contact

Privacy contact: 유주환 · korea@toris.kr · club.toris.kr