CharaFan Privacy Policy
This is a reference English translation of the CharaFan Privacy Policy. In the event of any discrepancy between the Japanese version and this English translation, the Japanese version shall prevail.
Shells, Inc. ("we", "us" or "our") establishes this Privacy Policy (this "Policy") as follows regarding the handling of personal information of all individuals who use or access the service we provide under the name "CharaFan" (the "Service") (including officers, employees, and other related persons who use the Service in the name of a corporation; "Users"). The meanings of the terms used in this Policy follow the Act on the Protection of Personal Information (the "Personal Information Protection Act").
1. Compliance with the Personal Information Protection Act, etc.
We comply with the Personal Information Protection Act and related guidelines (the "Relevant Guidelines") and other guidance regarding the handling of Users' personal information.2. Collection of Personal Information from Users and Purposes of Use
- Collection of personal informationNameAddressEmail addressInformation regarding accounts at banks and other financial institutionsDate of birth
- Collection of payment-related informationWhen a User performs payment procedures based on the "CharaFan Terms of Use" (the "Terms") separately established on the Service, we collect credit card information and other payment-related information through the payment agency business entities we engage (including Stripe, Inc. and the providers of payment methods such as PayPay offered through it). Such information is managed by those entities and is not retained by us.
- Collection of authentication informationWhen a User logs in to or registers as a member of the Service, we collect an email address and password, or the account information and profile information of an external service (including SNS such as X (formerly Twitter)) that the User uses for authentication.
- Collection of information relating to the use of OtayoriWhen a User sends Otayori (as defined in the Terms) on the Service, we collect the IP address and other connection information, the email address (only where the User enters it), and the content sent. Of these, the IP address and other connection information is used for the prevention of nuisance, for responding to a Registered User's block settings, and for other proper operation of the Service, and will not be disclosed to any third party, including the recipient Registered User, except where required by laws and regulations.
- Purposes of useWe use Users' personal information for the following purposes:To confirm that a User actually exists;Where a User registers based on the Terms, to confirm that there is no duplication with a User who has already registered;To respond to inquiries from Users;To give notice regarding changes to the Service or the Terms and other matters related to the Service;To provide paid functions and other services as set forth in the Terms;To carry out payment procedures as set forth in the Terms;To analyze and use Users' usage of the Service statistically, and to improve defects and enhance the quality of the Service;(Regarding date of birth) To ascertain the User's age in order to display content that is inappropriate for viewing by young people from the perspective of youth protection, such as sexual or violent expressions, only to Users of a certain age or older on the Service;To prevent nuisance or improper use in Otayori and other messaging functions, and to respond to Registered Users' block settings for refusing receipt;To review the appropriateness of the content of Otayori by mechanical means or other methods;To send to Senders replies from Registered Users regarding Otayori, thanks for support, and other notices.
3. Security Control Measures for Personal Data
- Development of rules regarding the handling of personal dataBased on the Relevant Guidelines, we clarify the methods for handling Users' personal data ("Personal Data") and inform all workers thereof.
- Organizational security control measuresUnder the leadership of our representative, we establish a system to organizationally implement security control measures for Personal Data, and address prompt and appropriate resolution in the event of any leakage, alteration, or other incident of Personal Data (an "Incident").For all workers who handle Personal Data, we clarify the scope within which they may handle Personal Data and their roles in the event of an Incident.We endeavor to keep records of the handling status of Personal Data and build a system in which the handling of Personal Data is continuously conducted appropriately within the company.In the event of a serious Incident, we promptly examine its cause and take necessary and appropriate measures such as reporting to the Personal Information Protection Commission, notifying the affected persons, and deciding measures to prevent recurrence.
- Human security control measuresWe conduct periodic educational activities for workers regarding matters to note in the handling of Personal Data, and have workers pledge to maintain the confidentiality of Personal Data.
- Physical and technical security control measuresWe store Personal Data exclusively as electronic data on cloud servers. In selecting cloud servers, we examine in advance whether strict information security measures, such as prevention of unauthorized access, are in place.We strictly manage access privileges to Personal Data stored on cloud servers, and take measures so that no worker other than those to whom access privileges have been granted in advance can access Personal Data.For all devices that may handle Personal Data, we take measures to prevent attacks and damage from information security threats.In designing the systems that constitute the Service, we take measures to ensure safety and periodically review such measures.
- Review of security control measuresWe conduct periodic inspections and audits of the handling status of Personal Data, and review our security control measures periodically according to the results.
- Understanding of the external environmentWe endeavor to take security control measures after understanding the legal systems of the countries where the cloud servers handling Personal Data are located.
4. Provision of Personal Data to Third Parties
- Entrustment of the handling of personal dataTo the extent necessary to achieve the purposes of use, we may entrust the handling of Personal Data to a credit card payment agency business entity or other third party. In such case, we select an entrustee capable of appropriately handling Personal Data, conclude a contract with such third party regarding the handling of Personal Data, and provide necessary and appropriate supervision of such third party.
- Other provision of personal data to third partiesExcept where we entrust the handling of Personal Data as set forth in (1) and where we may lawfully provide Personal Data to a third party based on the Personal Information Protection Act or other laws and regulations, we do not provide Personal Data to third parties.
5. Procedures for Disclosure, etc. of Retained Personal Data
- Method of procedures for disclosure, etc.For a request or demand (a "Request") for notification of the purpose of use, disclosure, correction, addition, or deletion, or suspension of use, erasure, or suspension of provision to third parties (collectively, "Disclosure, etc.") of a User's retained personal data based on the Personal Information Protection Act, please make the Request by email to the window below, attaching image data of the following documents. We cannot accept requests for Disclosure, etc. by any other method.In the case of a request by the person themselves
A copy of a driver's license, health insurance card, or other identification document by which the identity of the person can be confirmedIn the case of a request by an agent
All of the following documents
(a) A driver's license, health insurance card, or other identification document in the name of the person themselves by which the identity of the person can be confirmed
(b) A document making clear that the agent has received a delegation from the person themselves (limited to a document created by the person themselves)(Request window)charafan.support@shells.co.jp - Matters to be stated in a request for Disclosure, etc.When making a request for Disclosure, etc. as set forth in (1), please state "Request for Disclosure, etc. of Retained Personal Data" in the title of the email, and prepare the body as follows.Please state the name and address of the person themselves.Where the request is made by an agent, please state the name and address of the agent.Please specifically state which request it is: notification of the purpose of use, disclosure, correction/addition/deletion, or suspension of use/erasure/suspension of provision to third parties of retained personal data.For disclosure of the purpose of use of retained personal data, please specifically and clearly identify the scope of the retained personal data to be disclosed.For correction/addition/deletion or suspension of use/erasure/suspension of provision to third parties of retained personal data, please clearly state the specific content requested and the reason therefor.For disclosure of the purpose of use of retained personal data, please state whether you wish disclosure as data by email or disclosure as a document by mail. Note that even where you wish disclosure as a document by mail, if we determine that disclosure of data by email is appropriate, we may make disclosure as data by email.Where there are other matters separately designated by us on the Service, please state such matters.
- Cases where we can respond to procedures for Disclosure, etc.Even where a request for Disclosure, etc. is made as set forth in (1), if there is a defect in the method of request, if the identity of the person themselves or the agent cannot be confirmed, or if we cannot respond to the procedures for Disclosure, etc. due to legal restrictions, we may be unable to respond to Disclosure, etc. In such case, we will reply that we cannot respond to Disclosure, etc.
6. Contact Window for Inquiries
For opinions, consultations, complaints, and other inquiries regarding our handling of personal information, please contact the window below.
[Window]
charafan.support@shells.co.jp
charafan.support@shells.co.jp
7. Information About Us
Company name: Shells, Inc.
Address: 7-3-16 Laketown, Koshigaya City, Saitama Prefecture, Japan
Representative: Junya Kawakami
Address: 7-3-16 Laketown, Koshigaya City, Saitama Prefecture, Japan
Representative: Junya Kawakami
8. Revision of This Policy
When we revise this Policy, we will announce, on the Service, the fact of the revision, the revision date, and the content after the revision.