Privacy policy

Privacy Policy
Zig-Zag, Inc. (hereinafter referred to as the “Company”) establishes this Privacy Policy (hereinafter referred to as this “Policy”) regarding the acquisition and use of information concerning customers in connection with the services provided by the Company (hereinafter referred to as the “Company Services”), and shall comply with the GDPR (General Data Protection Regulation), the personal information protection laws of each country, and other applicable laws and regulations.

Article 1 (Definition of Customer Information)

For the purposes of this Policy, “Customer Information” means information entered by customers, customers’ activity histories on communication services, other information generated or stored on customers’ devices, and information concerning customers acquired in connection with services provided in cooperation with companies affiliated with the Company (hereinafter referred to as “Partner Companies”), which is collected by the Company pursuant to this Policy.

Article 2 (Customer Information Collected Through the Company Services)

In connection with the Company Services, the Company will promptly obtain Customer Information through the Company Services with the customer’s consent, as described below.

Customer Information includes the information set forth below. Customers who do not provide all or part of the Customer Information may be unable to use the Company Services.

The Company collects all Customer Information directly from customers.

(1) Information provided by customers

a. Basic Information:
Name (or corporate name), date of birth, gender, postal code, address (or business location), telephone number, and email address of the customer, including any delivery recipient designated by the customer.

b. Other Information:
Bank account information and other payment-related information, as well as information concerning purchased products.

c. Identity Verification Information:
Driver’s license information, passport information, and other information necessary to verify identity pursuant to the Secondhand Articles Dealer Act and other applicable laws and regulations.

(2) Information collected by the Company

a. Device Information:
The Company may collect device-specific information relating to devices used by customers, including device-specific IDs and other unique identifiers.

b. Log Information and Activity History Information:
The Company may collect customers’ purchase histories, product browsing histories, IP addresses automatically generated and stored when customers use the Company Services, the dates and times of customer requests, and information concerning customers’ activities on the Company website.

c. Cookies and Similar Technologies:
The Company may use technologies known as “Cookies,” as well as similar technologies such as IDFA, Advertising ID, location information technologies, and sensor information, in connection with the Company Services.

d. Information Related to Partner Services:
The Company may obtain information concerning agreements between customers and Partner Companies, types of partner services, effective dates, billing and payments, data collected through partner services, information sent or received by customers through partner services, usage histories, customers’ Facebook IDs, information concerning coupons and points, information obtained through surveys and monitoring studies, and other information obtained through the provision of partner services, including application histories, requests, and inquiries.

Article 3 (Consent)

By using the Company Services, customers are deemed to have consented to this Policy.

Customers may withdraw their consent at any time by contacting the Company. However, withdrawal of consent does not affect the lawfulness of the Company’s use of Customer Information prior to such withdrawal.

Customers under the age of 16 may not use the Company Services.

Article 4 (Purposes of Use)

1. The Company will not use Customer Information obtained through the use of the Company Services beyond the scope of the stated purposes of use without the customer’s consent.

Customer Information obtained by the Company will be handled appropriately within the scope necessary for each of the purposes set forth below.

Employees or agents of the Company may access Customer Information to the extent necessary to achieve the purposes listed below or as required by applicable laws and regulations.

[Required Items]

--------------------------

・Purpose of Use

Operation, provision, maintenance, and improvement of the Company Services

・Details of Purpose of Use

To verify the identity of customers and prevent unauthorized use of the Company Services

To enable customers to purchase products

To deliver products

To process procedures related to payment for products

To provide My Page functions

To lawfully conduct business as a mail-receiving service provider, commonly known as a private mailbox provider, under the Act on Prevention of Transfer of Criminal Proceeds

・Information Used

Basic Information:
Name, address, telephone number, email address

Other Information:
Information concerning purchased products

Identity Verification Information:
Driver’s license information, passport information, and other information necessary to verify identity pursuant to the Secondhand Articles Dealer Act and other applicable laws and regulations

--------------------------

・Purpose of Use

Notifications to and communications with customers

・Details of Purpose of Use

To provide information concerning the Company Services and respond to inquiries

To notify customers of or provide new services related to the Company Services

To notify customers of amendments to the Terms of Use or this Policy, suspension or discontinuation of the Company Services, termination of agreements, and other important notices concerning the Company Services

To resolve violations of the Terms of Use of the Company Services

To handle disputes and litigation

・Information Used

Basic Information:
Name, address, telephone number, email address

Other Information:
Bank account information and other payment-related information, and information concerning purchased products

Identity Verification Information:
Driver’s license information, passport information, and other information necessary to verify identity pursuant to the Secondhand Articles Dealer Act and other applicable laws and regulations

Log Information and Activity History Information

Device Information

Information Related to Partner Services

--------------------------

・Purpose of Use

Creation of statistical data and provision of such statistical data to third parties

・Details of Purpose of Use

To analyze the information listed below and create and use statistical data processed in a form that does not identify individuals (hereinafter simply referred to as “Statistical Data”)

To provide the above Statistical Data to third parties

The Company and third parties receiving Statistical Data concerning the information listed below may use such information for the following purposes:

・To display advertisements and other information suited to customers’ needs, interests, and preferences

・To analyze advertising effectiveness

・For market analysis and marketing purposes

・Information Used

Basic Information:
Address

Device Information

Log Information and Activity History Information

Cookies and Similar Technologies

Information Related to Partner Services

--------------------------

・Purpose of Use

Marketing of the Company Services

・Details of Purpose of Use

To provide information concerning the Company’s services and services of other companies suited to customers’ needs, interests, and preferences, information concerning Japan, and other various information

To provide services offered through the Company Services, including the issuance of coupons

・Information Used

Basic Information:
Name, address, telephone number, email address, date of birth, gender

Other Information:
Information concerning purchased products

Log Information and Activity History Information

--------------------------

[Optional Items]

--------------------------

・Purpose of Use

Provision of personal information to Meta Platforms, Inc. (hereinafter referred to as “Meta”) for the purpose of providing Meta’s marketing-related services

・Details of Purpose of Use

To enable Meta to provide marketing services that deliver information concerning third-party services suited to customers’ needs, interests, and preferences, information concerning Japan, and other various information

・Information Used

Basic Information:
Name, email address

--------------------------

2. With customers’ prior consent, the Company may mutually provide Customer Information, including personal information, to Partner Companies and other third parties to the extent necessary to achieve the purposes set forth in the preceding paragraph.

3. Except where permitted by applicable laws and regulations, the Company will not use Customer Information for automated decision-making.

Article 5 (Changes to the Purposes of Use)
The Company may change the purposes of use set forth in the preceding Article to the extent that the changed purposes are reasonably considered to be related to the original purposes of use.

If the purposes of use are changed, the Company will notify customers of the change and provide information related to such change by a method separately determined by the Company.


Article 6 (Acquisition of Customer Information)

The Company will acquire Customer Information appropriately and will not use false or other improper means.

If the Company acquires Customer Information by means other than through the customer’s use of the Company Services, the Company will notify the customer in advance of the purpose of use and any information that is required to be provided to the customer under applicable laws or regulations.


Article 7 (Security Management Measures, etc.)

1. The Company will take necessary and appropriate measures as described below to prevent the leakage, loss, or damage of Customer Information and otherwise ensure the secure management of Customer Information.

When providing personal data (meaning “personal data” as defined in Article 16, Paragraph 3 of the Act on the Protection of Personal Information, and the same shall apply hereinafter) to employees or contractors, including subcontractors, the Company will exercise necessary and appropriate supervision and comply with the personal information protection laws of each country.

(1) Establishment of a Basic Policy

The Company has established a basic policy to ensure the proper handling of personal data.

(2) Establishment of Rules for the Handling of Personal Data

The Company has established rules for the handling of personal data covering each stage of data handling, including acquisition, use, storage, provision, deletion, and disposal, as well as methods for establishing data-handling rules, the persons responsible and in charge, and their respective duties.

(3) Organizational Security Management Measures

The Company appoints a person responsible for administrative handling of personal data and clearly defines the employees who handle personal data and the scope of personal data handled by each employee.

The Company has also established a reporting and communication system under which any facts or indications of violations of personal information protection laws in each country or internal personal information handling rules are reported to the person responsible for administrative handling.

In addition, the Company periodically conducts self-inspections of the handling of personal data and also conducts audits by other departments or external parties.

(4) Personnel Security Management Measures

The Company provides employees with regular training regarding points of caution in the handling of personal data.

The Company also includes provisions concerning confidentiality obligations for personal data in its employment rules.

(5) Physical Security Management Measures

In areas where personal data is handled, the Company controls employee access and restricts devices and other items that may be brought into such areas, while also implementing measures to prevent unauthorized persons from viewing personal data.

The Company also takes measures to prevent theft or loss of devices, electronic media, documents, and other items containing personal data.

When such devices or electronic media are transported, including movement within business premises, the Company implements measures to prevent personal data from being easily identified.

(6) Technical Security Management Measures

The Company implements access controls to limit the persons in charge and the scope of personal information databases and other systems that may be accessed.

The Company has also introduced mechanisms to protect information systems handling personal data from unauthorized external access and malicious software.

(7) Understanding of External Environments

Prime Manpower Japan LLC, to which the Company outsources certain operations related to the processing of personal data, processes personal data in Makati City, Republic of the Philippines.

The Company implements security management measures after understanding the legal framework for personal information protection in the Republic of the Philippines.

Please note that customers’ personal data may be lawfully accessed by courts, law enforcement authorities, or other governmental bodies in the country where the data is stored.

Meta, to which the Company provides personal data as a third party, processes personal data in the United States of America.

The Company implements security management measures after understanding the legal framework for personal information protection in the United States.

Please note that customers’ personal data may be lawfully accessed by courts, law enforcement authorities, or other governmental bodies in the country where the data is stored.

2. If the Company outsources all or part of the handling of Customer Information to a third party, the Company will enter into a confidentiality agreement or similar agreement with such third party in advance, containing provisions consistent with this Policy, and will exercise necessary and appropriate supervision to ensure that Customer Information is securely managed by such third party.

The Company will notify all customers, by a method determined by the Company, of important information that must be communicated to all customers, including where the Company experiences a data breach that could materially affect customers.

Information regarding contractors engaged by the Company in the processing of Customer Information and the information entrusted to them shall be as described separately by the Company.

3. The Company takes all reasonable care to ensure the security of Customer Information, but cannot guarantee absolute security or the reliability of online communications.

If security is compromised, customers may be exposed to risks such as theft of personal information.

If such a security incident occurs, the Company will promptly take measures to mitigate the risk and will notify customers where there is a realistic risk of serious harm or where notification is required by law.

4. Customers’ personal information is generally stored in data centers located in Japan.


Article 8 (Joint Use)

The Company may jointly use customers’ personal information with Partner Companies to the extent necessary to provide partner services.

In such cases, the Company will publicly disclose in advance the name of the Partner Company, the purpose of the joint use, the types of information jointly used, and the party responsible for managing the jointly used information.


Article 9 (Information Collection Modules)

The Company Services incorporate the following information collection modules, as well as equivalent technologies, for the purpose of analyzing Customer Information.

Accordingly, the Company may provide Customer Information to the providers of such information collection modules.

These information collection modules use Cookies and similar technologies to collect Customer Information without including information that directly identifies individuals.

The collected information is managed in accordance with the privacy policies and other rules of the providers of the information collection modules.

For the privacy policies and opt-out information for each information collection module, please refer to the URLs below.

Google Analytics and Firebase Crashlytics provided by Google Inc.

Privacy Policy

https://policies.google.com/privacy?hl=en

Opt-Out Information

https://tools.google.com/dlpage/gaoptout?hl=en


ONE Intelligence provided by VMware, Inc.

Privacy Policy

https://www.vmware.com/jp/help/privacy.html

Opt-Out Information

https://www.vmware.com/jp/help/privacy/cookie-notice.html


Flurry provided by Flurry Inc.

Privacy Policy

https://legal.yahoo.com/us/en/yahoo/privacy/index.html

Opt-Out Information

https://legal.yahoo.com/us/en/yahoo/privacy/dashboard/index.html


PartyTrack provided by adjust株式会社

Privacy Policy

https://www.adjust.com/ja/terms/privacy-policy/

Opt-Out Information

https://www.adjust.com/ja/forget-device/


Facebook SDK provided by Meta

Privacy Policy

https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0

Opt-Out Information

https://www.facebook.com/help/568137493302217


Article 10 (External Services and Links)

1. The Company may provide services in cooperation with external services operated by Meta, X Corp. (United States), and others (hereinafter referred to as “External Services”).

If a customer chooses to use Company Services that are linked with an External Service, the Company may provide the relevant External Service provider with the following Customer Information:

address, date of birth, gender, postal code, location, telephone number, email address, and other information necessary to achieve the purposes set forth in Article 4.

Customers are deemed to have given prior consent to such provision.

However, customers may request that the Company stop providing such information to External Services.

For details regarding the relevant procedures, please contact the customer support desk.

2. When using the App on devices running iOS 9 or later, customers may use Spotlight Search to find information based on location information and date and time information stored within the service.

This feature is provided by the Company in accordance with the terms of use established by Apple.

Customers understand that information searched through Spotlight Search is stored only on the relevant device and consent to the provision of their information to Apple or third parties.

Unless Apple’s terms of use are changed, such information will not be provided to Apple or other third parties.

Customers may change Spotlight settings to disable indexing and search within the service, although doing so may limit certain search functions.


Article 11 (Disclosure and Sharing of Customer Information)

1. The Company will not disclose or share personal information included in Customer Information with third parties without the customer’s consent, except where disclosure is permitted under the personal information protection laws of each country or other applicable laws and regulations.

However, the following cases are exceptions:

(1) Where the Company outsources all or part of the handling of personal information to a third party to the extent necessary to achieve the purposes of use

(2) Where the Company entrusts the personal information of customers using the Company Services to payment system providers, credit card companies, or banks for the purpose of charging service fees

(3) Where personal information is provided to information collection module providers or External Service providers in accordance with the preceding two Articles

(4) Where the Company needs to take necessary measures in response to a customer engaging in, or attempting to engage in, conduct within the Company Services that causes harm to others or violates public order and morals

(5) Where there is an imminent danger to human life, property, or other interests and urgent action is required

(6) Where personal information is provided in connection with a transfer of business resulting from a merger or other cause

(7) Where disclosure is requested by courts, police, or other public authorities pursuant to applicable laws and regulations

2. The Company may transfer Customer Information to third countries or international organizations other than countries or international organizations that the European Commission has determined ensure an adequate level of protection for personal data.

In such cases, the Company will take measures required by applicable laws and regulations, including implementing appropriate safeguards, and will obtain the customer’s explicit consent after providing information regarding the risks associated with the transfer.


Article 12 (Targeted Advertising)

1. For the purpose of implementing targeted advertising by the Company or third parties such as advertising distribution operators, meaning advertising delivered according to customers’ needs, interests, and preferences, the Company may use information collection modules when providing the Company Services or partner services to collect, store, or use the following information:

(1) Activity History Information

Information such as histories of use of the Company Services, including product purchase histories, that may be accumulated and used to analyze customers’ needs, interests, and preferences, but does not itself identify a specific individual.

(2) Device Information

(3) Account Information

2. The Company may provide the information collected under the preceding Paragraph to businesses that distribute behaviorally targeted advertising (hereinafter referred to as “Advertising Distribution Operators”) for the following purposes:

(1) Provision of Services

To improve the convenience of services for customers

To provide content considered useful to customers

(2) Advertising and Marketing

To deliver advertisements suited to each customer

To use the information as statistical data

3. The Company may use the following identifiers:

(1) Cookies

Cookies are an industry-standard technology used by web servers to identify customers’ computers.

Cookies can identify a customer’s computer but cannot identify the customer personally.

Customers may access the Company website and disable all or part of the Cookie functions through the Cookie settings screen.

However, disabling Cookies may make all or part of the Company Services unavailable, and customers are requested to acknowledge this in advance.

4. The Company will retain Activity History Information and similar information collected from customers only for the period that is lawful and legitimately necessary for business purposes.

5. When providing Activity History Information and similar information to Advertising Distribution Operators, the Company will endeavor to require the following measures to prevent leakage, loss, or damage of such information and otherwise ensure its secure management:

(1) Not to disclose the mechanisms used to encrypt Activity History Information and similar information

(2) To provide such information to Advertising Distribution Operators subject to the condition that it be used only within the scope of the purposes of use set forth in Paragraph 2

(3) Where an Advertising Distribution Operator further provides Activity History Information or similar information to another third party, to require the Advertising Distribution Operator to impose on such third party the same conditions as those set forth in the preceding item


Article 13 (Customer Rights, etc.)

1. With respect to personal information provided by customers and the processing of such information, customers who wish to:

request disclosure, correction, addition, duplication, deletion, or restriction of processing in writing;

exercise the right to object to processing;

exercise the right of access; or

exercise the right to data portability,

should submit a request through the contact point specified in Article 19 and provide information identifying the customer, such as name, email address, and address.

The Company may, where necessary, request the customer to submit additional information or documents.

2. Where a request is made under the preceding Paragraph and the customer’s identity has been verified, the Company will, in principle, disclose Customer Information or take other appropriate action within one month of receiving the request and to a reasonable extent.

However, this shall not apply where the Company is not legally obligated to make such disclosure or take such action under the Act on the Protection of Personal Information or other applicable laws and regulations, where the same request is repeatedly made without legitimate reason, or in other similar circumstances.

If the Company is unable to comply with a request for disclosure or similar action, the Company will notify the customer accordingly.

3. If the Customer Information held by the Company is inaccurate, customers may request correction, addition, or deletion by contacting the inquiry desk specified in Article 19 and providing information identifying the customer, such as name and email address.

The Company may, where necessary, request the customer to submit additional information or documents.

4. Where a request is made under the preceding Paragraph and the customer’s identity has been verified, the Company will promptly conduct an investigation to a reasonable extent and, in principle, correct, add, or delete the Customer Information based on the results of the investigation within one month of receiving the request.

However, this shall not apply where the Company is not legally obligated to do so under the Act on the Protection of Personal Information or other applicable laws and regulations, where the same request is repeatedly made without legitimate reason, or in other similar circumstances.

5. If a customer requests the suspension of use, restriction of processing, deletion, or similar action with respect to Customer Information (hereinafter referred to as “Suspension of Use, etc.”) on the grounds that:

the Customer Information is being handled beyond the scope of the purposes of use previously notified; or

the Customer Information was acquired through deception or other improper means,

and the request is found to be justified under the Act on the Protection of Personal Information or other applicable laws, regulations, or rules, the Company will verify that the request is made by the customer concerned and then promptly carry out the Suspension of Use, etc., and notify the customer.

However, this shall not apply where the Company is not legally obligated to carry out the Suspension of Use, etc.

If the Company is unable to comply with the request, it will notify the customer accordingly.

6. Customers have the right to lodge a complaint with the relevant supervisory authority regarding the Company’s use of Customer Information.

7. Where certain requirements are met, customers have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significant effects on them.

8. Where the Company lifts a restriction on the processing of personal information that had previously been subject to restricted processing, the Company will notify the customer in advance.

9. Customers have the right to request an explanation from the Company regarding the rules governing the handling of personal information.

10. Customers have the right to obtain redress through prompt and fair procedures for harm arising from the processing of personal information.

11. The Company will not treat customers differently from other customers on the grounds that they have exercised rights granted by applicable laws or this Policy.


Article 14 (Handling, Storage, and Disposal of Customer Information)

1. All officers and employees who require access to Customer Information in order to carry out the purposes stated in this Policy, or as otherwise required or permitted by law, will handle Customer Information.

2. The Company will make reasonable efforts to ensure that Customer Information remains accurate and complete at all times.

3. The Company will not retain Customer Information once it is no longer necessary for the purposes of use or for purposes not stated in this Policy.

Customer Information will be disposed of after the retention period established by the Company has expired, unless the Company is required by law or regulation to retain such personal information.

As specific methods of disposal:

Customer Information stored as electronic records will be deleted in a manner that prevents restoration.

Personal information recorded on paper documents will be destroyed by incineration or dissolution.


Article 15 (Organization and Management Structure)

The Company designates its Representative Director and President as the person responsible for management and will implement appropriate management and continuous improvement of Customer Information.


Article 16 (Disclaimer)

The Company assumes no liability in the following cases:

(1) Where the customer personally discloses Customer Information to a third party using the functions of the Company Services or by other means

(2) Where the customer becomes personally identifiable as a result of information that the customer has voluntarily entered into the Company Services


Article 17 (Changes to this Policy)

The Company will periodically review the operational status of its handling of Customer Information and strive for continuous improvement.

The Company may amend this Policy as necessary without obtaining customers’ prior approval.

Unless otherwise specified by the Company, the amended Policy will take effect immediately after being posted on the Company website.

However, where an amendment requires customer consent under applicable law, the Company will obtain such consent by a method determined by the Company.


Article 18 (Other Notes)

The services provided by the Company may contain links to services that are not managed by the Company.

The Company assumes no responsibility for the content of such external services or for the protection of Customer Information within such services.


Article 19 (Contact Information)

For comments, questions, complaints, or other matters concerning the Company’s handling of Customer Information, please contact:

Hatchery Shibuya 3F
14-1 Sakuragaoka-cho, Shibuya-ku,
Tokyo 150-0031, Japan

株式会社ジグザグ

Data Protection Officer

privacy@zig-zag.co.jp

Email inquiries are accepted 24 hours a day. However, depending on the time of inquiry, responses may be delayed. Thank you for your understanding.


Article 20 (Local Representatives: UK and EU)

The Company respects customers’ privacy and their rights as data subjects and has appointed Prighter Group and its local partners (collectively, “Prighter”) as the Company’s representatives and customer contact points in the following regions:

・United Kingdom (UK)

・European Union (EU)

Prighter provides an easy way for customers to exercise their privacy rights, including requesting access to or deletion of personal data.

To contact the Company through Prighter as the Company’s representative, or to exercise your rights as a data subject, please visit the following website:

https://prighter.com/q/14759318372


Supplementary Provisions

Established: February 1, 2016

Revised: March 19, 2020

Revised: June 1, 2024