Privacy Policy

Privacy Policy Device Agency Inc. (“Company”) establishes this Privacy Policy (“Policy”) as follows with respect to the handling of personal information obtained through Luggage Dock and other services provided by the Company (“Service”). The Company complies with the Act on the Protection of Personal Information (“APPI”) and other applicable laws and regulations. Article 1. Definition of Personal Information In this Policy, “personal information” means personal information as defined under the APPI, namely information relating to a living individual that falls under any of the following: 1. information by which a specific individual can be identified by name, date of birth, or other descriptions, including information that can be easily matched with other information and thereby identify a specific individual; or 2. information containing an individual identification code. Article 2. Scope of Application 1. This Policy applies only to personal information obtained by the Company in connection with the Service. 2. This Policy does not apply to personal information obtained or managed by external services linked from the Service, including login services such as Google, Facebook, and Apple. When using external services, please refer to the privacy policy of each external service. Article 3. Types of Personal Information Collected The Company obtains the following personal information in providing the Service: 1. Account information: account information provided through login via external services such as Google, Facebook, and Apple (“External Services”), including email addresses. The scope of information provided by External Services is governed by the privacy policy of each External Service. 2. Email address: obtained when the User logs in or registers using an email address. 3. Payment information: processed through Stripe Checkout. Payment data such as credit card information is managed by Stripe, Inc., and is not retained by the Company. 4. Usage history and log information: usage date and time, Site, usage duration, unlock logs, and similar information. 5. Cookies and access logs: IP address, browser information, browsing and operation history of the Service web application, and similar information. Article 4. Purposes of Use of Personal Information The Company uses the personal information it obtains for the following purposes: 1. provision, operation, maintenance, and improvement of the Service; 2. payment processing and billing management; 3. notices and communications regarding excess use and uncollected items; 4. response to inquiries and support requests; 5. prevention and investigation of unauthorized use and security incidents; 6. sending notices and important information regarding the Service; 7. service improvement through usage statistics and analysis; and 8. response required by laws and regulations, and cooperation with administrative and judicial authorities. Article 5. Provision to Third Parties The Company does not provide obtained personal information to third parties except in the following cases: 1. when the User has given consent; 2. when required by laws and regulations, including legal requests from investigative or administrative authorities; 3. when necessary to protect human life, body, or property, and it is difficult to obtain the User’s consent; 4. when personal information is provided to a contractor in connection with business outsourcing, as set forth in Article 6; or 5. when personal information is transferred as part of business succession due to merger, company split, business transfer, or other reasons. In such cases, the information will be handled only within the scope necessary to achieve the purposes of use prior to the succession. Article 6. Outsourcing and Provision to External Services The Company may provide personal information to, or outsource processing to, the following external services to the extent necessary to achieve the purposes of use. The Company requires such contractors to implement appropriate security management measures. 1. Payment processing: Stripe, Inc., for processing credit card information through Stripe Checkout. 2. Electronic contracts: Bengo4.com, Inc., for compensation agreement procedures through CloudSign. 3. Access analytics: Google LLC, for analyzing usage of the Service web application through Google Analytics. When logging in through External Services, information may be shared with such External Services, including Google, Facebook, and Apple. The handling of such information is governed by the privacy policy of each External Service. Article 7. Use of Cookies and Access Logs 1. The Company obtains cookies and access logs in the Service web application. These are used to improve convenience, analyze usage, and ensure security. 2. Users may refuse cookies through their browser settings. However, if cookies are disabled, some functions of the Service may become unavailable. 3. The Company uses Google Analytics to collect and analyze access information. Google Analytics uses cookies to collect traffic data, and the collected data is managed in accordance with Google’s privacy policy. Users who do not wish to have data collected by Google Analytics may use the Google Analytics Opt-out Browser Add-on. Article 8. Security Management of Personal Information 1. The Company takes necessary and appropriate measures as follows to prevent leakage, loss, damage, and other risks concerning obtained personal information. 1. Organizational security management measures The Company appoints a person responsible for handling personal information and regularly checks the status of personal information handling. The Company maintains internal rules regarding the handling of personal information and establishes rules concerning the acquisition, use, storage, provision, and disposal of personal information. The Company also maintains a reporting system and response procedures in the event of incidents such as leakage of personal information. 2. Personnel security management measures The Company provides education and training on personal information protection to officers and employees who handle personal information. The Company imposes confidentiality obligations concerning personal information on officers, employees, and contractors. 3. Physical security management measures The Company appropriately manages documents and recording media containing personal information, including locked storage and other suitable controls. Personal information that is no longer necessary is disposed of or deleted by methods that prevent restoration. 4. Technical security management measures The Company limits access rights to personal information to the minimum necessary personnel. The Company implements security measures against unauthorized external access, malicious software, and similar threats. 2. The Company provides appropriate supervision and training to employees who handle personal information. 3. When outsourcing the handling of personal information, the Company appropriately selects and manages the contractor. Article 9. Retention Period The Company retains personal information for the period necessary to achieve the purposes of use. If laws and regulations prescribe a retention period, the Company follows such period. Personal information for which the purpose of use has been achieved will be promptly deleted or anonymized. Article 10. Requests for Disclosure, Correction, Deletion, etc. 1. Users may request disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of provision to third parties of their own personal information held by the Company, in accordance with the APPI. 2. To make a request under the preceding paragraph, please contact the inquiry desk below. After confirming the identity of the requester, the Company will respond within a reasonable period to the extent required by laws and regulations. 3. If any fee is required for a request, the Company will provide prior notice. Article 11. Changes to the Privacy Policy 1. The Company may change this Policy due to amendments to laws and regulations, changes to the Service, or other reasons. 2. In the case of important changes, the Company will provide prior notice by posting on the Service or by notification to the registered email address. 3. If the User uses the Service after the change, the User shall be deemed to have agreed to the revised Policy. Article 12. Contact Desk For inquiries regarding this Policy, or requests for disclosure, correction, deletion, or other handling of personal information, please contact the following: Personal Information Contact Desk Company name: Device Agency Inc. Address: 1F Harada Building, 4-17-18 Minamihorie, Nishi-ku, Osaka 550-0015, Japan TEL: 06-6585-9865 FAX: 06-6585-9875 Email: info@device-agency.co.jp Person in charge: Personal Information Protection Manager Established: March 2026