FairFare policy
개인정보 처리방침 · Privacy Policy
가격 확인에 필요하지 않은 개인정보는 받지 않고, 증빙 원본은 비식별 처리 후 삭제하는 것을 기본 원칙으로 합니다.
시행일 · Effective date: 2026-07-12
Secure request channel
개인정보 권리 요청
열람·정정·삭제 등 요청을 안전하게 접수합니다. 필요한 경우 본인 확인을 요청할 수 있습니다.
한국어
1. 처리하는 정보
가격 확인에는 선택한 여행지·가격 구역·품목·금액·통화·장소 유형이 사용됩니다. 현재 위치 기능은 브라우저가 제공한 좌표로 가까운 출시 여행지를 기기에서 찾으며, 정확한 좌표를 FairFare API에 저장하지 않습니다.
가격을 제보하면 여행지, 선택한 가격 구역, 품목, 지불 금액, 통화, 수량·단위, 장소 유형, 관측 시각과 선택 메모가 저장됩니다. 계정 이름이나 연락처는 필수 입력이 아닙니다. 앱 또는 브라우저는 FairFare 전용 무작위 식별자를 만들며, 서버는 원문 대신 비밀키 해시만 저장해 독립 기여자·중복·남용을 구분합니다.
2. 선택 증빙
영수증·메뉴판 등의 이미지는 선택 사항입니다. 업로드 원본은 비공개 저장소에 최대 7일 보관되고, 운영자가 이름·결제정보·QR 코드 등 개인정보 영역을 마스킹하면 원본을 삭제합니다. 비식별 사본은 최대 180일 후 삭제됩니다. 무결성 검사에 실패한 파일은 즉시 삭제 대상이 됩니다.
3. 이용 목적과 공개 범위
제보는 가격 범위 계산, 이상치·중복 검토, 데이터 신선도와 출처 다양성 확인에 사용됩니다. 개별 제보자의 식별정보나 증빙 원본은 공개하지 않습니다. 비식별 증빙도 검수 승인 전에는 신뢰도 계산에 포함하지 않습니다.
앱 열기, 화면 이용, 가격 판정 같은 이용 통계는 수집하지 않습니다. 제보 남용 방지 시 네트워크 주소는 원문을 저장하지 않고 비밀키 해시로 변환하며, 해당 단기 제한 기록은 최대 25시간 후 삭제합니다. 보안과 장애 대응을 위한 네트워크 로그는 별도로 최대 7일 보관될 수 있습니다.
4. 제공자와 보안
서비스 운영에는 Sites/Cloudflare, OCI, PostgreSQL과 private R2가 사용될 수 있습니다. 운영자 화면은 공개 도메인 없이 서버의 loopback 포트와 SSH 터널, 별도 관리자 자격증명으로 보호합니다. 저장소 자격증명과 관리자 토큰은 공개 브라우저 코드에 포함하지 않습니다.
5. 보유·삭제와 권리
가격 제보와 비밀키로 해시한 기여자 값은 통계의 시간 경과 비교, 독립 기여자 계산과 분쟁 대응에 필요한 기간 보관하며, 공개 집계에는 최근 관측 창만 사용합니다. 무작위 식별자는 계정·광고 식별자와 결합하지 않고 추적 광고에 사용하지 않습니다. 증빙 보존기간은 위 기준을 따릅니다. 위 폼에서 열람·정정·삭제·처리 제한·이동·이의 제기 요청을 제출할 수 있습니다. 연락처와 요청 내용은 저장 시 암호화되고 권한이 있는 운영자만 처리 화면에서 확인합니다. 본인 확인이 필요할 수 있으며, 요청 종료 후 최대 365일이 지나면 연락처와 요청 내용을 삭제합니다. 요청 제출만으로 본인 확인이나 요청 이행이 확정되지는 않으며, 적용 법률에 따라 처리합니다.
6. 광고
현재 AdSense 승인 집중 기간에는 게시자 광고 태그와 광고 단위를 불러오지 않으며, 광고 목적의 Google 요청도 보내지 않습니다. 승인 후 광고를 활성화할 때는 광고 태그보다 먼저 모든 광고 동의 신호를 ‘거부’로 설정해 쿠키를 사용하지 않는 제한 광고만 제공하고 개인화 광고는 제공하지 않습니다. Google은 제한 광고 제공·측정과 부정 사용 방지를 위해 네트워크 계층의 IP 주소와 브라우저·기기 정보를 처리할 수 있습니다. 가격 범위·검색 순위·신뢰도와 FairFare 전용 무작위 식별자는 광고 프로파일에 사용하지 않습니다.
English
1. Data we process
A price check uses the selected destination, optional price zone, item, amount, currency, and venue type. The location feature uses browser-provided coordinates on the device to select the nearest launch destination; FairFare does not store the precise coordinates in its API.
A contribution stores the destination, optional zone, item, paid amount, currency, quantity and unit, venue type, observation time, and an optional note. A name or contact address is not required. The app or browser creates a random FairFare-only identifier; the server stores only a secret-keyed hash to distinguish independent contributors, duplicates, and abuse.
2. Optional evidence
Receipt or menu images are optional. Originals stay in private storage for no more than seven days. After an operator masks names, payment details, QR codes, and other private regions, the original is deleted. The redacted derivative expires after 180 days. Files that fail integrity checks are scheduled for immediate deletion.
3. Purpose and public output
Contributions support price ranges, duplicate and outlier review, freshness, and source diversity. FairFare does not publish contributor identifiers or original evidence. Redacted evidence affects verification counts only after operator approval.
FairFare does not collect usage statistics such as app opens, screen interactions, or price-check counts. For contribution abuse prevention, a network address is transformed into a secret-keyed hash without storing the raw address; that short-term limit record expires within 25 hours. Separate network security and incident logs may be retained for up to seven days.
4. Providers and security
FairFare may use Sites/Cloudflare, OCI, PostgreSQL, and private R2 to operate the service. The operations console has no public domain and is protected by a server-loopback port, an SSH tunnel, and separate administrator credentials. Storage credentials and administrator tokens are never shipped in public browser code.
5. Retention, deletion, and rights
Price observations and the secret-keyed contributor hash are retained as needed for historical comparison, independent-contributor counts, and dispute handling, while public aggregates use a recent observation window. The random identifier is not combined with an account or advertising identifier and is not used for tracking advertising. Evidence follows the limits above. The form above accepts requests for access, correction, deletion, restriction, portability, and objection. Contact details and request text are encrypted at rest and are visible only to authorized operators in the processing console. Identity verification may be required. Contact and request content are deleted no later than 365 days after the request is closed. Submission alone does not establish identity or guarantee the requested outcome; requests are handled under applicable law.
6. Advertising
FairFare currently does not load publisher ad tags or ad units and sends no advertising request to Google during its AdSense approval-focus period. If advertising is enabled after approval, every advertising consent signal will be set to “denied” before the ad tag loads, so only limited ads that do not use cookies are served; personalized advertising will not be offered. Google may process network-level IP addresses and browser or device information to deliver and measure limited ads and prevent abuse. Price ranges, rankings, trust calculations, and the FairFare-only random identifier are not used for advertising profiles.