Article 1 (Acquired Personal Information)
Aoto to Mori Co., Ltd. (hereinafter referred to as "the Company") acquires the following personal information from customers when providing this service: (1) information necessary for order and delivery, such as name, address, telephone number, and email address; (2) payment information, such as credit card information (acquired and stored via a payment processing company); (3) order history, wish lists, and inquiry details; and (4) automatically acquired information, such as cookies, IP addresses, browser information, device information, and browsing history. The Company does not acquire personal information beyond the minimum necessary scope.
Article 2 (Purpose of Use)
Acquired personal information will be used for the following purposes: (1) shipping products, processing payments, and responding to inquiries; (2) account management, saving order history, and providing wishlist functionality; (3) sending emails regarding order confirmations, shipping status, product information, and campaign information (marketing-related emails will only be sent with prior consent); (4) creating statistical data and improving services (used in a form that does not identify individuals); and (5) preventing fraudulent use and ensuring compliance with laws and regulations. If the purpose of use changes, customers will be notified in advance and necessary consent will be obtained.
Article 3 (Provision to and Entrustment with Third Parties)
We will not provide personal information to third parties without the customer's consent. However, we may provide personal information to the extent necessary in the following cases: (a) when required by law, (b) when necessary to protect a person's life, body, or property, or (c) when outsourcing services to delivery companies (such as Yamato Transport, Sagawa Express), payment processing companies (such as Shopify Payments, Stripe), email distribution services (such as Klaviyo), customer support tools, or analytical tools (such as Google Analytics). We will enter into contracts with our subcontractors that require them to implement security measures equivalent to our own.
Article 4 (Cookies, Access Analysis, and Advertising Distribution)
This service uses cookies, local storage, pixel tags, and other technologies to improve the user experience, analyze usage, and optimize ad delivery. Examples of tools used include Google Analytics 4, Meta Pixel, Klaviyo, Judge.me, ShopApp, etc. These tools acquire information such as IP addresses and browsing history, but they are not linked to personally identifiable information. Cookies can be disabled in your browser settings, but some features may become unavailable. You can choose your preferences from the Cookie Settings at the bottom of the site.
Article 5 (Transfer of Personal Data to Foreign Countries)
Your personal data may be stored and processed by some of the cloud services we use (e.g., Shopify Inc. (Canada, USA), Google LLC (USA), Meta Platforms (USA)). These countries either meet the personal data protection standards recognized by Japan's Personal Information Protection Commission or have implemented appropriate safeguards such as Standard Contractual Clauses (SCCs). We operate in compliance with cross-border transfer regulations under the amended Act on the Protection of Personal Information (APPI) 2022.
Article 6 (Customer's Rights Regarding Retained Personal Data)
Customers have the right to request (1) notification of purpose of use, (2) disclosure (including disclosure by electromagnetic record), (3) correction, addition, or deletion, (4) suspension of use or cessation of provision to third parties, and (5) disclosure of records of provision to third parties, regarding personal data held by the Company. Please direct your request to the inquiry contact at the end of this policy. We will verify your identity and respond in accordance with laws and regulations. As a general rule, no fee will be charged, but actual costs may be incurred if disclosure requests are repeated multiple times.
Article 7 (Safety Management Measures)
Our company implements organizational, human, physical, and technical security measures to prevent the leakage, loss, or damage of personal information. Examples include: (a) minimizing and regularly reviewing access privileges, (b) encrypting data during transmission and storage (TLS/SSL), (c) providing regular training to personnel, (d) establishing selection criteria and oversight for third-party contractors, and (e) promptly reporting incidents to the Personal Information Protection Commission and notifying affected individuals. In the event of a data breach, we will respond appropriately in accordance with Article 26 of the Act on the Protection of Personal Information.
Article 8 (Revisions and Inquiries)
This policy may be revised in response to changes in laws and regulations, or changes in service content. Significant changes will be notified on this service. Please check the "Last Updated" date on this page for the latest version. Contact for personal information handling: Aotomori Inc. Personal Information Protection Administrator Email: privacy@aotomori.jp Address: 2-12-8-606 Ropponmatsu, Chuo-ku, Fukuoka-shi, Fukuoka 810-0044 Japan Business hours: Weekdays 10:00 AM - 6:00 PM (excluding Saturdays, Sundays, holidays, and New Year holidays)