Privacy Policy

Effective date: 24 April 2026 · Amended effective date: 16 July 2026

This Privacy Policy ("Policy") explains how HUSTLERS Corp. ("we", "us", "our", the "Company") collects, uses, shares, stores, and protects personal information when you use the Sanrio Characters Dream Travel mobile application (commonly known as "Yumetabi / ゆめたび") on iOS or Android (the "Service"). It is designed to satisfy the transparency obligations of the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, and analogous obligations under the California Consumer Privacy Act as amended ("CCPA/CPRA") and other applicable data protection laws.


1. Who is the controller of your personal data?

ControllerHUSTLERS Corp., a company incorporated under the laws of the Republic of Korea
Registered address1410, 40 Cheonggyecheon-ro, Jung-gu, Seoul, Republic of Korea
Business registration number566-88-02374
General contactcs@hustlers.co.kr
Privacy contactcs@hustlers.co.kr
Data Protection Officer (DPO)Not appointed – cs@hustlers.co.kr

If you wish to contact us about this Policy, to exercise your rights, or to raise a complaint, please use the privacy contact above.

2. What personal data do we collect?

We collect the following categories of personal data, either directly from you, automatically when you use the Service, or from third-party authentication providers.

CategoryExamplesRequired / Optional
Account identifiersLocal UUID, authentication provider type (LINE, Kakao, Google, Apple, Guest), provider-issued identifier and e-mail address (where disclosed)Required
Age confirmationSelf-declared confirmation at sign-up that you meet the minimum age (14+ in the Republic of Korea)Required
ProfileNickname (15 characters), country code, app language, localeRequired
Profile – optionalGender, date of birth, selected representative characterOptional
Sleep settingsTarget bedtime, wake time, target sleep duration, alarm / smart alarm / snooze / vibration settingsRequired
Sleep session dataSleep start/end time, raw sensor epochs, actual sleep segments, sleep judgment result, streak records, passport stampsRequired (for the core functionality)
Payment dataIn-app purchase receipts (issued by Apple / Google), product IDs, timestamps, processing status, retry historyRequired (when purchasing)
Game progressMileage / Gem balance, costumes, tickets, items, gacha history, mate status, travel-place historyRequired
Device & logsDevice OS and version, app version, push token (FCM / APNs), IP address, error logs, advertising identifiers (IDFA / AAID)Required (logs) / Optional (ad identifiers)
Analytics and marketing (optional)Event logs, screen navigation events, crash reportsOptional (only with consent)
Customer inquiries & error reportsInquiry type, inquiry content (text you enter), attached images, reply e-mail address (if provided), diagnostic information at the time of submission (app version, device model, error logs, recent usage records)Optional

We do not knowingly collect special categories of personal data (Art. 9 GDPR). Sleep session data can reveal inferences about health; we process this data based on the performance of the contract to provide you the Service, and we apply appropriate safeguards. Where local law classifies such inferences as sensitive, we will obtain your explicit consent before further processing.

Diagnostic information sent together with an error report is collected only where you separately consent on the "Send Feedback" screen (your inquiry content is still submitted if you decline). We remove (mask) passwords, authentication tokens and payment-method details before transmission and collect only the minimum information necessary to diagnose the error. Unlike the always-on automatic collection of the "Device & logs" category above, this diagnostic information is transmitted only at the moment you report an error.

We do not knowingly collect personal data from children under the age of 16 in the EU/EEA and the United Kingdom, or under the age of 13 in the United States, or under the age of 14 in the Republic of Korea (whichever is stricter in your region).

We rely on the following legal bases under Article 6 GDPR:

PurposeCategories of dataLegal basis
Creating and managing your account, authenticating youAccount identifiers, profilePerformance of a contract (Art. 6(1)(b))
Providing the core service (sleep tracking, character collection, virtual travel, gacha, currency system)Profile, sleep settings, sleep session data, game progress, device infoPerformance of a contract (Art. 6(1)(b))
Processing in-app purchases and detecting payment fraudPayment data, device infoPerformance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Keeping the Service secure, preventing abuse, detecting automated manipulation of sleep sessions or currencyDevice info, logs, game progressLegitimate interest (Art. 6(1)(f)) – keeping the Service safe
Responding to customer support requests and error reports submitted via the in-app "Send Feedback" featureAccount identifiers, profile, the content of your request, diagnostic information (where you consent)Performance of a contract (Art. 6(1)(b))
Sending marketing communications and push notifications for marketing purposesPush token, account identifiersConsent (Art. 6(1)(a))
Improving the Service, performing product analyticsEvent logs, screen events, aggregated usageConsent (Art. 6(1)(a)) where required, otherwise legitimate interest (Art. 6(1)(f))
Complying with legal obligations (tax, accounting, consumer protection)Payment data, account identifiersLegal obligation (Art. 6(1)(c))
Managing guest accounts before account linking, including stale-account cleanup and abuse preventionAccount identifiers, device identifiers, game progress, logsPerformance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f))

Where we rely on consent, you may withdraw it at any time via Settings > Privacy in the app or via the Privacy contact. Withdrawal does not affect the lawfulness of processing before withdrawal.

Where we rely on legitimate interests, you may object at any time. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.

4. Automated decision-making (Article 22 GDPR)

The Service uses an algorithm that analyses raw sleep sensor epochs to determine when you entered sleep, to identify your actual sleep segments and to assign a pass/fail judgment to each session. The judgment drives your streak count and the release of certain in-app rewards.

5. Who we share your personal data with

We share personal data with the following categories of recipients, acting as processors or as separate controllers as indicated:

RecipientRoleLocation
Amazon Web Services, Inc.Processor – cloud hosting, CDNUnited States, with regional deployment in ap-northeast-2 (Seoul) and ap-northeast-1 (Tokyo)
Google LLCProcessor / controller – Android in-app billing, Firebase Cloud Messaging, Firebase Analytics, Crashlytics, Sign in with GoogleUnited States
Apple Inc.Processor / controller – iOS in-app billing, APNs push, Sign in with AppleUnited States
LY CorporationController – LINE LoginJapan
Kakao CorporationController – Kakao LoginRepublic of Korea
Self-operated (no external vendor)Processor – ticket handlingRepublic of Korea
Authorities, regulators and litigantsController – only where required by law, court order, or to protect our rightsVarious

We do not sell personal data to third parties for monetary consideration. Where the CCPA/CPRA defines "sale" or "sharing" broadly to include cross-context behavioural advertising, the Service does not currently engage in such activity.

6. International transfers

Because the controller is located in the Republic of Korea and several of our processors are located in the United States and Japan, personal data that originates in the EU/EEA, the United Kingdom or other jurisdictions will be transferred outside of your country.

We rely on the following safeguards under Chapter V of the GDPR:

You may obtain a copy of the safeguards in place by writing to the Privacy contact.

7. How long we keep your data

DataRetention
Account and profile informationUntil you delete your account, plus 30 days for abuse-prevention identifiers
Unlinked guest account and device identifiersUntil account linking or last use. Unlinked guest accounts with no game progress, Paid Content, payment, subscription, refund, dispute, or enforcement record may be deleted or de-identified after at least 30 days of inactivity. Free unlinked guest accounts with game progress may be retained for at least 180 days after last use before cleanup.
Sleep session and judgment data1 year from collection (or upon deletion request / account deletion, whichever comes first)
In-app purchase records5 years in Korea (Act on Consumer Protection in Electronic Commerce), 7 years in Japan, 7 years in the US where required
Consumer complaint records3 years
Error-report diagnostic information6 months after the error is resolved
Connection logs and IP addresses3 months
Advertising / analytics identifiers (with consent)Until you withdraw consent, or 14 months (whichever is earlier)
Backups90 days rolling, automatically overwritten

If a guest account has in-app purchase, subscription, Paid Content, refund, consumer-dispute, abuse, or enforcement records, those records may be retained separately for the legal, accounting, support, fraud-prevention, or dispute-handling period that applies, even if other guest data is deleted or de-identified.

When setting specific retention periods, we consider applicable legal minimums, the type and sensitivity of the information, the need to provide the Service and support account recovery, internal recordkeeping needs, fraud and security risks, potential disputes or legal claims, and the impact of retention or deletion on users.

8. Your rights

Depending on your jurisdiction, you may have the following rights:

8.1 EU/EEA and United Kingdom (GDPR / UK GDPR)

8.2 California (CCPA/CPRA)

8.3 Republic of Korea (PIPA)

See the Korean version of this Policy, including the right to data portability introduced on 13 March 2025.

8.4 Japan (APPI)

See the Japanese version of this Policy, including the right to request disclosure of records of third-party provision.

How to exercise your rights

Send a request to cs@hustlers.co.kr or use the in-app "Settings > Privacy > Data rights" menu. We will respond within one month under the GDPR (extendable by two further months for complex requests) and within 45 days under the CCPA. We may require reasonable verification of your identity.

9. Security

We apply technical and organisational measures appropriate to the risk, including:

10. Cookies, SDKs and tracking technologies

The Service is a mobile application and does not set traditional web cookies. We use mobile SDKs to provide the Service and to measure its performance. These SDKs may read or write identifiers on your device:

SDK / TechnologyPurposeLegal basis
Firebase AnalyticsProduct analyticsConsent
Firebase CrashlyticsCrash reportingLegitimate interest
Firebase Cloud MessagingPush notifications (functional)Contract. Marketing push is consent-based.
Google Play Billing / Apple StoreKitPayment processingContract / legal obligation
Apple App Tracking Transparency (ATT)Tracking consent (iOS 14.5+)Consent

You can control tracking through your device settings, by declining the ATT prompt on iOS, by disabling your Android advertising ID, and within the app at Settings > Privacy.

11. Children

The Service is not directed to children. At sign-up (or first use), users confirm by self-declaration that they meet the minimum age, and anyone below the minimum age is not permitted to register or use the Service. We do not knowingly collect personal data from users below 14 years of age (Republic of Korea), 13 years of age (United States, under COPPA), or the applicable digital-consent age in your EU/EEA member state (13 to 16). If we discover that we have collected personal data from a child below the applicable age, we will delete it and terminate the account without undue delay; a parent or guardian may request this via the Privacy contact.

12. Changes to this Policy

We may update this Policy from time to time. We will post the new version in the app and update the "Effective date" above. If changes are material, we will notify you through the app or by e-mail at least 30 days before they take effect (7 days for non-material changes), and, where required, we will request renewed consent.

13. Questions and complaints

If you have any questions or complaints, please contact cs@hustlers.co.kr. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.