- The operator is a Singapore company. Data is processed and stored outside your country. (see section 7)
- There is no sign-up. We do not collect your name or any national identification number.
- To calculate rewards and prevent abuse we process device identifiers, wallet addresses and activity records.
- Location and camera are accessed only when you use the relevant feature and only with your permission.
- You can ask to access or delete your data at any time. Transactions recorded on a blockchain cannot be deleted.
11. Personal data we collect
We collect only what the Service needs. Because there is no sign-up, we do not collect identifying details such as your name, date of birth or any national identification number.
| Basis | Data | When collected |
|---|---|---|
| Required | Device identifier (including advertising ID), OS and device model, app version | Automatically on first launch |
| Required | Blockchain wallet address, transaction hashes | On wallet connection and reward payout |
| Required | Activity records (accruals, timestamps, booster multiplier), invitation code and acquisition source | Automatically during use |
| Optional | Location data (GPS coordinates, distance travelled) | When you use the walking reward (after consent) |
| Optional | Photographs and capture metadata | When you use the photo feature (after consent) |
| Optional | Push notification token | When you opt in to notifications |
| Optional | Email address | When you enter it to contact or report to us |
| Automatic | IP address, access timestamps, cookies, usage records, error logs | Automatically during use |
22. Why we use it
- Providing the Service — recognising activity, calculating MOL accrual, paying rewards, showing history
- Preventing abuse — detecting duplicate accounts, automation and location spoofing
- Managing invitations — attributing installs to invitation links and paying both sides
- Improving the Service — usage analytics, error diagnosis, feature development
- Support — receiving and answering enquiries and reports
- Notices — essential announcements about terms, reward policy and maintenance (marketing messages only where you have opted in)
- Legal compliance — obligations under Singapore and Korean law, sanctions screening, and responding to lawful requests from authorities
33. Retention
We destroy personal data without delay once the purpose of collection has been achieved, except as set out below.
| Data | Retention | Basis |
|---|---|---|
| Device identifiers and activity records | 30 days after termination | Preventing repeat abuse and handling enquiries |
| Abuse records | 3 years | Preventing recurrence and handling disputes |
| Location data | Destroyed immediately after each use (only aggregate distance is kept) | Location data legislation |
| Support and enquiry records | 3 years | Consumer complaint and dispute records |
| Access logs and IP addresses | 3 months | Communications privacy legislation |
| Anti-money-laundering records | 5 years | Applicable Singapore and Korean law |
44. Disclosure to third parties
We do not disclose personal data to third parties, except in the following cases.
- Where you have given prior, express consent
- Where a law so provides, or where a Korean or Singapore investigative authority makes a request following the procedure prescribed by law
- Where data is provided in a form from which no individual can be identified, for statistical or academic purposes
55. Processors
We engage the following processors so that the Service can run. Each contract sets out data protection obligations clearly, and we supervise performance against them.
| Processor | Purpose | Retention |
|---|---|---|
| Cloud infrastructure provider | Server operation and data storage | Until the contract ends |
| Push notification provider | Sending app push messages | Until the contract ends |
| Advertising network | Serving rewarded ads and verifying views | Until the contract ends |
| Analytics provider | Usage analytics and error collection | Until the contract ends |
66. Your rights
You may exercise the following rights at any time.
- Access your personal data
- Have inaccurate data corrected
- Have data deleted (except where retention is required by law)
- Ask us to stop processing
- Withdraw consent (for optional items)
- Refuse cross-border transfer (which may make the Service unavailable to you)
You can exercise these rights through the in-app settings or by writing to privacy@digmol.com. We respond within 10 days of receiving a request. Where you ask for deletion, we destroy the data so that it cannot be restored or reconstructed.
77. Cross-border transfer
The following disclosure is made in accordance with Article 28-8 of the Personal Information Protection Act of the Republic of Korea and the transfer limitation obligation under the Singapore PDPA.
| Item | Detail |
|---|---|
| Recipient | BUKCS PTE. LTD. (service operator) and the processors listed in section 5 |
| Destination | Singapore and the countries in which each processor's servers are located |
| Data transferred | All items listed in section 1 |
| Timing and method | Transmitted on an ongoing basis over encrypted network connections as you use the Service |
| Purpose | All purposes listed in section 2 |
| Retention | As set out in section 3 |
| How to refuse | Write to privacy@digmol.com. Because the transfer is essential to providing the Service, refusing it may restrict or prevent your use of it. |
We apply protection to transferred data comparable to the standard required by the law of your country, including encryption in transit and access controls.
88. Children
We do not collect personal data from children under 14 and the Service is not directed at them. If we find that we hold such data, we destroy it immediately and suspend the account. Where the law of your country sets a higher age of consent, that threshold applies.
99. Cookies and similar technologies
On the website we use cookies and local storage to keep track of invitation attribution and to understand how the Service is used.
- Essential cookies — preserving invitation codes and language preference, maintaining a session. Required for the Service.
- Analytics storage — page visit statistics and error diagnosis.
You can refuse cookies in your browser settings. Blocking essential cookies may prevent invitation rewards from being attributed correctly.
1010. Security measures
- Technical — encryption in transit (HTTPS/TLS), encryption of sensitive data at rest, least-privilege access, intrusion prevention
- Organisational — minimising the number of staff who handle personal data, regular training, an internal management plan, retention and review of access logs
- Physical — access control at the facilities where data is stored
1111. Contact
We have appointed the following person to oversee personal data processing and handle complaints.
- Data protection officer: (to be appointed)
- Contact: privacy@digmol.com
Complaints about personal data handling may also be raised with a supervisory authority.
- Singapore — Personal Data Protection Commission (PDPC), pdpc.gov.sg
- Republic of Korea — Personal Information Dispute Mediation Committee, kopico.go.kr / 1833-6972
- Republic of Korea — Privacy Infringement Report Centre, privacy.kisa.or.kr / 118
1212. Changes to this policy
This policy may be revised to reflect changes in law, policy or the Service. Changes and their effective date are announced in the app or on the website at least 7 days in advance. Where a change materially affects your rights, notice is given 30 days in advance and, where necessary, separate consent is obtained.