BANILA CO Pink House

Pink House · Legal

BANILA CO: Pink House — Privacy Policy

Effective Date: May 29, 2026 Last Updated: May 29, 2026


1. Who We Are

BANILA CO: Pink House (the "App", "Service") is a mobile application operated by:

  • Publisher (Korean entity): F&Co. Co., Ltd. (operating the BANILA CO brand)
  • Headquarters address: 8 Teheran-ro 8-gil, Gangnam-gu, Seoul, Republic of Korea
  • US business unit: There is no separate US entity; the Service is operated directly by F&Co. Co., Ltd. (Republic of Korea) for the US market.
  • US contact address: c/o F&Co. Co., Ltd., 8 Teheran-ro 8-gil, Gangnam-gu, Seoul, Republic of Korea
  • Privacy contact email: `support@fnfcorp.com`
  • General support email: `support@fnfcorp.com`

In this Policy, "we", "us", and "our" refer to the publisher named above. "You" or "user" refers to the individual accessing or using the App.

If you have questions about this Policy, contact us at the privacy email above.


2. Scope

This Policy describes how we collect, use, share, and protect personal information when you:

  • Download, install, or use the Pink House mobile App on iOS or Android;
  • Sign in to the App using Apple Sign-In or Google Sign-In;
  • Participate in missions, the UGC League, or PINK League campaigns;
  • Receive points or cash rewards;
  • Submit user-generated content (UGC); or
  • Communicate with us for support.

Target market. The Service is offered to users located in the United States only. We do not currently target users in the European Economic Area (EEA), the United Kingdom, or other jurisdictions. If you are accessing the Service from outside the US, you do so at your own initiative, and certain features may be unavailable.


3. Information We Collect

We collect only the information needed to operate the Service, calculate rewards, prevent fraud, and meet legal obligations. We collect the following categories:

3.1 Account Information (collected at sign-up)

| Field | Source | Required | |---|---|---| | OAuth subject identifier (Apple `sub` / Google `sub`) | Apple / Google ID token | Yes | | Email address | Apple / Google ID token claims | Yes | | Display name | Apple / Google ID token claims (editable in-app) | Yes | | Profile image (avatar) | You upload, or default avatar | Optional |

We do not collect or store passwords. Authentication is delegated to Apple Sign-In and Google Sign-In; we receive only the identity claims described above.

3.2 Profile and Social Handles

For UGC mission submission and Affiliate identity verification, we collect:

  • Social handles you provide for Instagram, TikTok, YouTube, X (Twitter), or Threads;
  • Date of birth (only to confirm you are 13 or older — COPPA gate; we do not store full DOB beyond age verification);
  • Country / state of residence (US users only).

3.3 Content and Activity

  • UGC submissions — public URLs you submit (TikTok, Instagram, YouTube, etc.) and any associated metadata we fetch (e.g., video ID, likes count, view count, comment count) for league scoring.
  • Mission completion records — which missions you completed, when, and the submitted content.
  • Point ledger — all point earnings, redemptions, and adjustments, with timestamps and source type. *(Per our domain invariants, this ledger is append-only and preserved even if you delete your account, with PII anonymized.)*
  • Cash payout history — for Affiliates and eligible Creators: payout requests, amounts, statuses.

3.4 Device and Technical Data

  • Device identifier (Apple `IDFV` or Android equivalent);
  • Operating system and version;
  • App version and build number;
  • IP address (last octet zeroed in long-term logs);
  • Approximate region inferred from IP (no precise geolocation);
  • Push notification token (FCM token), if you enable push.

3.5 Usage and Telemetry

  • In-app events (screen views, button taps, mission interactions);
  • Application logs (route, status code, latency) — personal identifiers are masked in long-term logs;
  • Crash and error diagnostics.

Telemetry flows to Amazon CloudWatch (us-east-1) and to Datadog (US data region) as our observability stack; personal identifiers are masked in telemetry.

3.6 Payment and Tax Identity (only if you cash out)

If you become eligible to cash out points or receive an Affiliate prize, we collect, through our payout processor:

  • Legal name and address;
  • Tax identification (W-9 for US persons; W-8BEN for non-US persons);
  • Bank account or third-party wallet details (handled by our processor — we do not store full bank account numbers on our servers);
  • Payment history and 1099-NEC reporting data for users paid US $600 or more in a tax year.

3.7 Shopify Affiliate Tracking Data

When an Affiliate generates a tracking link and a customer purchases through that link on our Shopify store (`https://banilausa.com`), we collect:

  • Shopify order ID, line items, order amount, currency, financial status;
  • The Affiliate tracking token or coupon code used;
  • Customer relationship classification (`external`, `self_purchase`, or `member_cross_purchase`) — only `external` orders earn commission (see Terms of Service §11);
  • We do not receive payment card numbers, CVV, or full billing addresses from Shopify; we receive only the data needed to attribute the sale to the correct Affiliate.

3.8 OAuth Tokens (when you connect third-party accounts)

If you connect your TikTok account (post-launch feature), we store the OAuth access/refresh tokens encrypted at rest using AWS KMS envelope encryption. Tokens are revoked immediately on disconnect.

3.9 Information We Do NOT Collect

  • Passwords (we use Apple/Google OAuth);
  • Precise GPS location;
  • Health, biometric, or genetic data;
  • Sensitive demographic data (race, religion, political opinions);
  • Credit card numbers (handled exclusively by our payout processor and by Shopify);
  • Contacts, calendar, or photos beyond what you explicitly upload.

4. How We Use Information

We use your information for the following purposes:

| Purpose | Legal basis (US framing) | |---|---| | Create and operate your account; authenticate you | Performance of our agreement with you (Terms of Service) | | Deliver daily missions, calculate point earnings, run UGC and PINK leagues | Performance of our agreement | | Calculate Affiliate commissions on external customer orders only (per our compliance invariant INV-0820) | Performance of our agreement | | Process cash payouts and Affiliate prizes | Performance of our agreement | | Prevent fraud, abuse, multi-account creation, click manipulation | Our legitimate interest in protecting the Service | | Comply with tax law (W-9 collection, 1099-NEC issuance for US $600+ payouts) | Legal obligation | | Maintain audit logs and sales records (5-year retention) for compliance | Legal obligation / legitimate interest | | Send transactional notifications (mission reminders, payout status, account state changes) | Performance of our agreement | | Send marketing emails or push notifications about new campaigns | Your consent (opt-in); you may opt out at any time | | Improve the Service (aggregated analytics) | Legitimate interest | | Respond to your support requests | Performance of our agreement | | Defend legal claims | Legal obligation / legitimate interest |


5. How We Share Information

We do not sell your personal information. We share data only with the following categories of recipients, and only as needed:

5.1 Authentication providers

  • Apple Inc. — Apple Sign-In identity verification.
  • Google LLC — Google Sign-In identity verification.

5.2 Infrastructure and hosting

  • Amazon Web Services, Inc. (AWS) — application hosting, Aurora PostgreSQL database, S3 storage, KMS encryption, all in the US (us-east-1 region).

5.3 Observability and operations

  • Amazon CloudWatch — application and infrastructure logs.
  • Datadog, Inc. — observability platform. Personal identifiers are masked in telemetry; raw PII is not sent.
  • Discord, Inc. — administrative webhooks for internal operations alerts. No end-user PII is sent to Discord; only generic event notifications (e.g., "a new Affiliate application was approved").

5.4 Push notifications

  • Google Firebase Cloud Messaging (FCM) — delivery of push notifications. We send only your FCM token and the message payload.

5.5 Commerce

  • Shopify Inc. — operates our storefront and provides order data for Affiliate attribution. We share with Shopify only what is needed to issue tracking links and discount codes.

5.6 Payouts and tax

  • A third-party payout processor (to be designated) — handles KYC, bank transfers, and W-9 / W-8BEN / 1099-NEC processing. They are independent controllers of the personal data you submit to them; their privacy policy will apply to that processing.

5.7 Professional advisors

  • Legal, accounting, and audit advisors, under confidentiality obligations.

5.8 Legal compliance and safety

  • Law enforcement, regulators, or courts when we are required by law, subpoena, or to protect our or our users' rights and safety.

5.9 Corporate transactions

  • An acquirer, investor, or successor in the event of a merger, acquisition, financing, or sale of assets, subject to confidentiality and your continued protection under a substantially similar privacy policy.

We do not share your personal information with advertising networks or data brokers, and we do not allow third-party tracking SDKs in the App.


6. International Data Transfers

The Service is hosted in the United States (AWS region us-east-1). Because we are operated by a Korean entity, employees and contractors in the Republic of Korea may access your personal information for support, audit, fraud investigation, security, and compliance purposes.

When personal information is transferred from the US to Korea for these purposes, we rely on contractual safeguards (e.g., Standard Contractual Clauses or equivalent inter-company data processing agreements) and apply the same technical and organizational safeguards used in the US environment.

If you do not consent to such transfer, please do not use the Service.


7. Cookies and Similar Technologies

The Pink House mobile App does not use browser cookies. The App uses local secure storage (iOS Keychain / Android EncryptedSharedPreferences) to remember your authentication tokens.

Our customer-facing web pages (e.g., the public Privacy Policy page, Terms of Service page) may set strictly-necessary cookies for session integrity and security only. We do not use advertising or cross-site tracking cookies.


8. Data Retention

Different categories of information are retained for different periods, balancing your privacy with our legal and operational needs.

| Category | Retention period | Reason | |---|---|---| | Account profile (email, display name, OAuth `sub`) | Until you delete your account; then anonymized within 30 days | Account operations | | Authentication refresh tokens | 30 days; rotated on use | Session management | | Point ledger and cash payout ledger | Preserved indefinitely as anonymized records after account deletion | Audit, tax, fraud defense (append-only by design) | | Shopify order data and Affiliate commission records | 5 years from order date | Sales / commission compliance (per our domain invariant INV-0821) | | Audit log (admin actions, security events) | 5 years (1-year hot in DB, then archived to AWS S3 Glacier) | Compliance, incident investigation | | Tax records (W-9, W-8BEN, 1099-NEC) | At least 4 years from the latest tax filing, per IRS rules | Legal obligation | | Application logs (with PII masked) | 90 days | Operations, security | | Backups (encrypted) | Up to 35 days | Disaster recovery | | Marketing email opt-out records | Until you re-opt-in or 5 years, whichever is longer | Honor your preference |

Anonymization on account deletion. When you delete your account, we replace your identifiers (`email`, `display_name`) with anonymous values (e.g., `deleted+<id>@anon.fanhouse`, `deleted user`). The underlying point and cash ledger entries remain for audit and tax purposes but are no longer linked to a recoverable individual.


9. Your Rights and Choices

You have the following rights with respect to your personal information. To exercise any right, contact us at the privacy email in §1. We will respond within 45 days (extendable by an additional 45 days where reasonable, with notice).

9.1 Access and portability

Request a copy of the personal information we hold about you, in a structured machine-readable format (JSON).

9.2 Correction

Request that we correct inaccurate or incomplete information. Some fields are editable directly in the App (display name, avatar, social handles).

9.3 Deletion

Request that we delete your account and associated personal information. We will anonymize identifiers and delete what we are not legally required to keep. The append-only ledger entries (with identifiers removed) will be retained per §8.

9.4 Opt-out of marketing

Unsubscribe from marketing emails using the unsubscribe link in every marketing email, or disable marketing push notifications in the App settings. Transactional notifications (payout status, account security) cannot be opted out while you have an active account.

9.5 California residents (CCPA / CPRA)

If you are a California resident, you have the right to:

  • Know what categories of personal information we have collected, used, disclosed, or sold/shared in the past 12 months;
  • Request deletion;
  • Request correction;
  • Opt out of "sale" or "sharing" of personal information.

We do not sell or share personal information for cross-context behavioral advertising. You may submit a verifiable consumer request via the privacy email in §1.

9.6 Other US states (Virginia, Colorado, Connecticut, Utah, Texas, etc.)

We extend the access, correction, deletion, and opt-out rights described in §9.1 – §9.4 to all US users, regardless of state. If your state grants additional rights, contact us and we will honor them where required.

9.7 Authorized agents

You may designate an authorized agent to make a request on your behalf, subject to verification of the agent's authority.

9.8 Appeals

If we decline to honor a request, we will explain why and provide an appeal mechanism via the privacy email in §1.

9.9 EEA / UK

Not in scope. The Service does not target EEA or UK users, and we do not offer EEA/UK-specific rights. If you are an EEA/UK resident who used the Service, contact us and we will treat your request under the closest comparable US framework.


10. Security

We protect your information using industry-standard safeguards:

  • Encryption in transit — TLS 1.2 or higher for all client–server connections; HTTPS-only.
  • Encryption at rest — Aurora PostgreSQL storage encryption (AWS-managed) plus column-level KMS envelope encryption for the most sensitive fields (OAuth tokens, payout account details).
  • Key management — AWS KMS customer-managed keys, with separate keys for secrets, database, S3, logs, JWT, and payouts.
  • Access control — least-privilege IAM roles; admin access requires Microsoft Entra ID single sign-on (corporate domain only) and full audit logging.
  • Network isolation — VPC private subnets, security-group whitelisting, WAF in front of public endpoints.
  • Logging and audit — append-only audit log of administrative actions; PII access is itself logged and monitored.
  • Mobile — secure storage (iOS Keychain / Android EncryptedSharedPreferences), TLS pinning, OWASP MASVS conformance.
  • Dependency hygiene — automated CVE scanning with patch SLAs.
  • Incident response — documented runbook with severity tiers and notification procedures.

No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us at the support email in §1 immediately.


11. Children's Privacy

Pink House is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. We use a date-of-birth gate during onboarding to enforce this minimum.

If we learn that we have collected personal information from a child under 13, we will delete that information promptly. If you believe a child under 13 has provided us with personal information, contact us immediately at the privacy email in §1.


12. Third-Party Services

The App may link out to third-party services (e.g., Shopify storefront, TikTok video pages, Instagram, YouTube). Once you leave the App, you are subject to those services' own privacy policies, which we do not control. We encourage you to review them.


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will:

  • Update the "Last Updated" date at the top;
  • Post the new policy in the App and on our public privacy page;
  • For material changes, notify you via in-app notification or email, at least 30 days before the change takes effect.

Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of the updated terms.


14. Contact Us

For privacy questions, requests, or complaints:

  • Privacy email: `support@fnfcorp.com`
  • Postal mail: c/o F&Co. Co., Ltd., 8 Teheran-ro 8-gil, Gangnam-gu, Seoul, Republic of Korea
  • App Store / Play Store listing: the most current contact information is also shown on our store listings.

We aim to acknowledge your inquiry within 5 business days and provide a substantive response within 45 days.


15. Document History

| Version | Date | Notes | |---|---|---| | 1.0 | May 29, 2026 | Initial published version |


End of Privacy Policy

Back to Pink House