App Name: Lunch Pay

Developer: Mochabase

Privacy Policy

Effective Date: September 10, 2026 | Last Updated: September 3, 2026

1. Personal Information We Collect

We process the following information to provide the service.

  • Required items: Social login identifier information (account unique identifier), service user identifier, and authentication token information
  • Service usage information: Order/payment/point/transaction history, access logs, and device/app information
  • Phone-number check information (Android only, when enabled for the user's app version and requested before product exchange): Mobile phone number retrieved from the SIM/device after the user grants Phone permission and provides consent, collection consent date, consent notice version, and block status
  • Abuse prevention and block operation information: Mobile phone number, social account identifier (social_id), reason code, reason note, and block/unblock processing history
  • Optional items (when using certain features): Camera-captured image files and capture time (for displaying lunch verification history)
  • When using ads/reward integrations: Advertising identifier (AD_ID) and device information collected by ad SDKs

2. Purpose of Using Personal Information

  • User identification, login authentication, and account/session management
  • Providing lunch verification, point accumulation, and order/payment/history inquiry features
  • Providing service-related notifications in accordance with user settings and applicable device permissions.
  • Linking a mobile phone number to a service account, checking whether the number is registered on the abuse block list, preventing repeated abuse, and restricting product exchanges associated with blocked numbers
  • Preventing abuse, ensuring service stability, and responding to errors
  • Providing ads/rewards (offerwall), settlement, and performance measurement

3. Retention and Use Period of Personal Information

We delete personal information without delay once the purpose of collection has been fulfilled. However, if retention is required by applicable laws, we retain it for the required period.

  • Member information: Deleted or anonymized when membership is canceled or service use ends, except for information retained under applicable laws or for the abuse prevention purposes described below
  • Mobile phone number linked to a service account and related consent records: Retained until the abuse prevention purpose is fulfilled
  • Mobile phone number separately registered on the abuse block list and related block history: Retained until the block is lifted or the abuse prevention purpose is fulfilled
  • E-commerce/payment-related records: Retained for the period prescribed by applicable laws
  • Lunch verification images/local history stored on the device: May be deleted when removed by the user or when the app is uninstalled

4. Third-Party Sharing and External Service Integrations

To provide the service, we may use the external services below, and information may be processed within the necessary scope.

  • Google/Firebase: Social login authentication and account linking
  • Offerwall (ads/rewards) SDK: May process advertising identifier (AD_ID), device information, and usage information
  • Mobile phone numbers collected for abuse prevention are not shared with offerwall or advertising SDK providers.
  • When required to comply with legal obligations or valid requests from investigative authorities

5. App Permissions

The app requests only the minimum permissions required to provide the service.

  • Optional permission: Camera (requested only when taking lunch verification photos)
  • Even if camera permission is denied, other app features remain available; only the photo capture feature may be limited.
  • Optional permission: Notifications (POST_NOTIFICATIONS, Android 13+) for service-related alerts.
  • Even if notification permission is denied, core app features remain available; only notification delivery may be limited.
  • Optional permission: Phone (READ_PHONE_NUMBERS and READ_PHONE_STATE, Android only) to retrieve the mobile phone number stored on the SIM/device for abuse prevention before product exchange.
  • If Phone permission is denied, other app features remain available, but product exchange may be restricted.
  • Lunch Pay does not perform SMS verification and does not request permission to read or send SMS messages, access call logs, or make phone calls.
  • Users can change permission settings at any time in device settings.
  • AD_ID is not subject to runtime permission pop-ups and is used only within the scope of ad SDK integration purposes.

6. Procedures and Methods for Destruction of Personal Information

Personal information subject to destruction is securely deleted using methods that make recovery or restoration impossible.

  • Electronic files: Deleted using technically irreversible methods
  • Printed documents and similar materials: Shredded or incinerated

7. User Rights and How to Exercise Them

Users may request access, correction, deletion, or suspension of processing of their personal information at any time. We will take action without delay in accordance with applicable laws.

8. Account Deletion (Membership Withdrawal)

If you want to delete your account, you can proceed directly using the methods below.

  • In-app request: Immediate withdrawal via [Settings > Delete Account]
  • Email request: Request account deletion via customer support (Mochabase) email

Upon withdrawal, account access is disabled and personal information is deleted or anonymized without delay when it is no longer needed. Information required under applicable laws or reasonably necessary to prevent repeated abuse may be retained only for the periods described in Section 3 and is not used for unrelated purposes.

9. Contact

For inquiries related to personal information, please contact the department below.

10. Notice of Changes

If this Privacy Policy is added to, deleted, or modified, notice will be provided through in-service announcements at least 7 days before the effective date.

This policy may be updated in accordance with changes to service operation policies and applicable laws.