Privacy

Privacy Policy

Privacy Policy

Effective date: 24 April 2026 · Amended effective date: 16 July 2026

This Privacy Policy (“Policy”) explains how HUSTLERS Corp. (“we”, “us”, “our”, the “Company”) collects, uses, shares, stores, and protects personal information when you use the Sanrio Characters Dream Travel mobile application (commonly known as “Yumetabi / ゆめたび”) on iOS or Android (the “Service”). It is designed to satisfy the transparency obligations of the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, and analogous obligations under the California Consumer Privacy Act as amended (“CCPA/CPRA”) and other applicable data protection laws.


1. Who is the controller of your personal data?

Controller HUSTLERS Corp., a company incorporated under the laws of the Republic of Korea
Registered address 1410, 40 Cheonggyecheon-ro, Jung-gu, Seoul, Republic of Korea
Business registration number 566-88-02374
General contact cs@hustlers.co.kr
Privacy contact cs@hustlers.co.kr
Data Protection Officer (DPO) Not appointed – cs@hustlers.co.kr

If you wish to contact us about this Policy, to exercise your rights, or to raise a complaint, please use the privacy contact above.

2. What personal data do we collect?

We collect the following categories of personal data, either directly from you, automatically when you use the Service, or from third-party authentication providers.

Category Examples Required / Optional
Account identifiers Local UUID, authentication provider type (LINE, Kakao, Google, Apple, Guest), provider-issued identifier and e-mail address (where disclosed) Required
Age confirmation Self-declared confirmation at sign-up that you meet the minimum age (14+ in the Republic of Korea) Required
Profile Nickname (15 characters), country code, app language, locale Required
Profile – optional Gender, date of birth, selected representative character Optional
Sleep settings Target bedtime, wake time, target sleep duration, alarm / smart alarm / snooze / vibration settings Required
Sleep session data Sleep start/end time, raw sensor epochs, actual sleep segments, sleep judgment result, streak records, passport stamps Required (for the core functionality)
Payment data In-app purchase receipts (issued by Apple / Google), product IDs, timestamps, processing status, retry history Required (when purchasing)
Game progress Mileage / Gem balance, costumes, tickets, items, gacha history, mate status, travel-place history Required
Device & logs Device OS and version, app version, push token (FCM / APNs), IP address, error logs, advertising identifiers (IDFA / AAID) Required (logs) / Optional (ad identifiers)
Analytics and marketing (optional) Event logs, screen navigation events, crash reports Optional (only with consent)
Customer inquiries & error reports Inquiry type, inquiry content (text you enter), attached images, reply e-mail address (if provided), diagnostic information at the time of submission (app version, device model, error logs, recent usage records) Optional

We do not knowingly collect special categories of personal data (Art. 9 GDPR). Sleep session data can reveal inferences about health; we process this data based on the performance of the contract to provide you the Service, and we apply appropriate safeguards. Where local law classifies such inferences as sensitive, we will obtain your explicit consent before further processing.

Diagnostic information sent together with an error report is collected only where you separately consent on the “Send Feedback” screen (your inquiry content is still submitted if you decline). We remove (mask) passwords, authentication tokens and payment-method details before transmission and collect only the minimum information necessary to diagnose the error. Unlike the always-on automatic collection of the “Device & logs” category above, this diagnostic information is transmitted only at the moment you report an error.

We do not knowingly collect personal data from children under the age of 16 in the EU/EEA and the United Kingdom, or under the age of 13 in the United States, or under the age of 14 in the Republic of Korea (whichever is stricter in your region).

We rely on the following legal bases under Article 6 GDPR:

Purpose Categories of data Legal basis
Creating and managing your account, authenticating you Account identifiers, profile Performance of a contract (Art. 6(1)(b))
Providing the core service (sleep tracking, character collection, virtual travel, gacha, currency system) Profile, sleep settings, sleep session data, game progress, device info Performance of a contract (Art. 6(1)(b))
Processing in-app purchases and detecting payment fraud Payment data, device info Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Keeping the Service secure, preventing abuse, detecting automated manipulation of sleep sessions or currency Device info, logs, game progress Legitimate interest (Art. 6(1)(f)) – keeping the Service safe
Responding to customer support requests and error reports submitted via the in-app “Send Feedback” feature Account identifiers, profile, the content of your request, diagnostic information (where you consent) Performance of a contract (Art. 6(1)(b))
Sending marketing communications and push notifications for marketing purposes Push token, account identifiers Consent (Art. 6(1)(a))
Improving the Service, performing product analytics Event logs, screen events, aggregated usage Consent (Art. 6(1)(a)) where required, otherwise legitimate interest (Art. 6(1)(f))
Complying with legal obligations (tax, accounting, consumer protection) Payment data, account identifiers Legal obligation (Art. 6(1)(c))
Managing guest accounts before account linking, including stale-account cleanup and abuse prevention Account identifiers, device identifiers, game progress, logs Performance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f))

Where we rely on consent, you may withdraw it at any time via Settings > Privacy in the app or via the Privacy contact. Withdrawal does not affect the lawfulness of processing before withdrawal.

Where we rely on legitimate interests, you may object at any time. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.

4. Automated decision-making (Article 22 GDPR)

The Service uses an algorithm that analyses raw sleep sensor epochs to determine when you entered sleep, to identify your actual sleep segments and to assign a pass/fail judgment to each session. The judgment drives your streak count and the release of certain in-app rewards.

  • You have the right to obtain human intervention, to express your point of view and to contest the decision.
  • You can request an explanation of the logic involved and of the consequences of the processing via the Privacy contact.
  • If you request not to use automated judgment for reward and streak decisions, the related reward and streak features may be limited.

5. Who we share your personal data with

We share personal data with the following categories of recipients, acting as processors or as separate controllers as indicated:

Recipient Role Location
Amazon Web Services, Inc. Processor – cloud hosting, CDN United States, with regional deployment in ap-northeast-2 (Seoul) and ap-northeast-1 (Tokyo)
Google LLC Processor / controller – Android in-app billing, Firebase Cloud Messaging, Firebase Analytics, Crashlytics, Sign in with Google United States
Apple Inc. Processor / controller – iOS in-app billing, APNs push, Sign in with Apple United States
LY Corporation Controller – LINE Login Japan
Kakao Corporation Controller – Kakao Login Republic of Korea
Self-operated (no external vendor) Processor – ticket handling Republic of Korea
Authorities, regulators and litigants Controller – only where required by law, court order, or to protect our rights Various

We do not sell personal data to third parties for monetary consideration. Where the CCPA/CPRA defines “sale” or “sharing” broadly to include cross-context behavioural advertising, the Service does not currently engage in such activity.

6. International transfers

Because the controller is located in the Republic of Korea and several of our processors are located in the United States and Japan, personal data that originates in the EU/EEA, the United Kingdom or other jurisdictions will be transferred outside of your country.

We rely on the following safeguards under Chapter V of the GDPR:

  • Adequacy decisions – The European Commission has adopted an adequacy decision for the Republic of Korea (17 December 2021) and for Japan (23 January 2019). Transfers to our Korean controller and to Kakao Corporation in Korea, and to LY Corporation in Japan, are therefore based on adequacy.
  • Standard Contractual Clauses (SCCs) – For transfers to the United States (AWS, Google, Apple) we rely on the EU Standard Contractual Clauses (Decision 2021/914), together with additional technical and organisational measures. Where Google and AWS are self-certified under the EU-US Data Privacy Framework, we rely on that adequacy mechanism.
  • UK International Data Transfer Addendum for UK transfers.

You may obtain a copy of the safeguards in place by writing to the Privacy contact.

7. How long we keep your data

Data Retention
Account and profile information Until you delete your account, plus 30 days for abuse-prevention identifiers
Unlinked guest account and device identifiers Until account linking or last use. Unlinked guest accounts with no game progress, Paid Content, payment, subscription, refund, dispute, or enforcement record may be deleted or de-identified after at least 30 days of inactivity. Free unlinked guest accounts with game progress may be retained for at least 180 days after last use before cleanup.
Sleep session and judgment data 1 year from collection (or upon deletion request / account deletion, whichever comes first)
In-app purchase records 5 years in Korea (Act on Consumer Protection in Electronic Commerce), 7 years in Japan, 7 years in the US where required
Consumer complaint records 3 years
Error-report diagnostic information 6 months after the error is resolved
Connection logs and IP addresses 3 months
Advertising / analytics identifiers (with consent) Until you withdraw consent, or 14 months (whichever is earlier)
Backups 90 days rolling, automatically overwritten

If a guest account has in-app purchase, subscription, Paid Content, refund, consumer-dispute, abuse, or enforcement records, those records may be retained separately for the legal, accounting, support, fraud-prevention, or dispute-handling period that applies, even if other guest data is deleted or de-identified.

When setting specific retention periods, we consider applicable legal minimums, the type and sensitivity of the information, the need to provide the Service and support account recovery, internal recordkeeping needs, fraud and security risks, potential disputes or legal claims, and the impact of retention or deletion on users.

8. Your rights

Depending on your jurisdiction, you may have the following rights:

8.1 EU/EEA and United Kingdom (GDPR / UK GDPR)

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure / “right to be forgotten” (Art. 17)
  • Right to restriction (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object to processing based on legitimate interests or direct marketing (Art. 21)
  • Right not to be subject to a decision based solely on automated processing (Art. 22)
  • Right to withdraw consent at any time (Art. 7(3))
  • Right to lodge a complaint with a supervisory authority (Art. 77). Concerns may be directed to your local EU/EEA supervisory authority or national data protection authority.

8.2 California (CCPA/CPRA)

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to correct inaccurate personal information
  • Right to opt-out of sale / sharing (although we do not sell data in the traditional sense, you can exercise this right via the Privacy contact)
  • Right to limit use of sensitive personal information
  • Right to non-discrimination for exercising your rights

8.3 Republic of Korea (PIPA)

See the Korean version of this Policy, including the right to data portability introduced on 13 March 2025.

8.4 Japan (APPI)

See the Japanese version of this Policy, including the right to request disclosure of records of third-party provision.

How to exercise your rights

Send a request to cs@hustlers.co.kr or use the in-app “Settings > Privacy > Data rights” menu. We will respond within one month under the GDPR (extendable by two further months for complex requests) and within 45 days under the CCPA. We may require reasonable verification of your identity.

9. Security

We apply technical and organisational measures appropriate to the risk, including:

  • TLS 1.2+ for all network traffic
  • Encryption at rest of authentication tokens in the iOS Keychain and Android EncryptedDataStore
  • CDN and storage access controls
  • Role-based access control on our back-office tooling
  • Regular patching, vulnerability scanning and dependency review
  • Documented incident response procedure and breach notification in line with GDPR Art. 33 / 34 and applicable national laws

10. Cookies, SDKs and tracking technologies

The Service is a mobile application and does not set traditional web cookies. We use mobile SDKs to provide the Service and to measure its performance. These SDKs may read or write identifiers on your device:

SDK / Technology Purpose Legal basis
Firebase Analytics Product analytics Consent
Firebase Crashlytics Crash reporting Legitimate interest
Firebase Cloud Messaging Push notifications (functional) Contract. Marketing push is consent-based.
Google Play Billing / Apple StoreKit Payment processing Contract / legal obligation
Apple App Tracking Transparency (ATT) Tracking consent (iOS 14.5+) Consent

You can control tracking through your device settings, by declining the ATT prompt on iOS, by disabling your Android advertising ID, and within the app at Settings > Privacy.

11. Children

The Service is not directed to children. At sign-up (or first use), users confirm by self-declaration that they meet the minimum age, and anyone below the minimum age is not permitted to register or use the Service. We do not knowingly collect personal data from users below 14 years of age (Republic of Korea), 13 years of age (United States, under COPPA), or the applicable digital-consent age in your EU/EEA member state (13 to 16). If we discover that we have collected personal data from a child below the applicable age, we will delete it and terminate the account without undue delay; a parent or guardian may request this via the Privacy contact.

12. Changes to this Policy

We may update this Policy from time to time. We will post the new version in the app and update the “Effective date” above. If changes are material, we will notify you through the app or by e-mail at least 30 days before they take effect (7 days for non-material changes), and, where required, we will request renewed consent.

13. Questions and complaints

If you have any questions or complaints, please contact cs@hustlers.co.kr. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

  • Version 1.1.1 – amended 16 July 2026

Back to home