Legal
Privacy Policy
Last updated: August 31, 2026
SPCREATE株式会社 (the “Operator”) provides this Privacy Policy for JAPAN API STORE.
1. Information we collect
We process account identifiers received from our authentication provider, including name, email address, email-verification state, external identity identifier, organization and session metadata. We also process organization, project, API-key metadata, subscription and invoice status, support communications, security audit events, and aggregate API usage such as endpoint, status class, latency, timestamp, and request counts. For the separately licensed Windows desktop app, we process the purchase email address, license status, app-generated installation identifier in HMAC-digested form, app version, activation timestamps, HMAC-digested network identifiers, aggregate activity windows, anomaly scores, warnings, and enforcement state. Product discovery counters record aggregate page views, live-demo outcomes, documentation or console views, and API-key call-to-action events without storing the demo query, cookies, user agent, or a visitor identifier.
2. Information we deliberately avoid
We do not store your password. Full API-key secrets are shown only once and are not stored in plaintext. Desktop license keys and installation identifiers are also not stored in plaintext. Complete payment-card numbers are processed by Stripe and are not stored by JAPAN API STORE. Japanese address query text is not written to normal access logs, usage dashboards, or Operations snapshots. Authentication tokens, refresh tokens, payment secrets, license signing secrets, and webhook signing secrets are not logged.
3. Purposes of processing
We use information to authenticate users, provide and secure accounts, issue and revoke API keys, operate the API, enforce limits, measure usage, administer subscriptions and invoices, prevent abuse, investigate incidents, provide support, maintain audit records, improve reliability, comply with law, and establish or defend legal claims.
4. Cookies and sessions
We use secure, HttpOnly cookies for authentication, PKCE/state protection, session rotation, reauthentication, CSRF protection, and logout. We do not use these authentication cookies for advertising. Session cookies are scoped and protected according to the security settings described by the service.
5. Service providers and external services
WorkOS provides authentication and account-security functions. Stripe provides payment, subscription, invoice, and billing-portal functions. RapidAPI processes marketplace subscriber and commercial information for requests purchased through its marketplace; JAPAN API STORE stores only a pseudonymous marketplace identity and separated operational usage. When a visitor follows a first-party RapidAPI link, we store the selected product, campaign labels, timestamp, and referring hostname for aggregate traffic measurement. We do not store the visitor's IP address, email address, cookie, form input, API payload, or full referring URL in this referral record. Infrastructure, email, and official-data providers may process limited information needed to deliver their services.
6. Sharing and international processing
We do not sell personal information. We disclose data to service providers only as needed to operate the service, when you direct us, in a business reorganization subject to appropriate safeguards, or where law, security, or the protection of rights requires it. Providers may process information outside your country under their own safeguards and applicable law.
7. Logs and data sources
Operational logs are designed to exclude full address queries and credentials. Business Mix query analytics retain only daily aggregate classifications such as input type, writing-system category, endpoint, source, and outcome; the original company query is not stored in analytics. Japan Post and Digital Agency ABR datasets are public data sources used to produce API results; they are maintained separately from account and billing records. Data-source version differences are exposed rather than hidden.
8. Retention
We retain account and project records while an account is active and for a reasonable period afterward where needed for security, recovery, disputes, and legal obligations. Billing, invoice, audit, abuse-prevention, and usage records are retained for the periods required by operational and legal needs. Public datasets may be replaced when new validated versions are activated. We delete or de-identify information when it is no longer needed, subject to backup cycles and mandatory retention.
9. Security
We use managed authentication, MFA policy controls, encryption in transit, restricted network exposure, hashed API-key secrets, signed webhooks, access controls, audit records, encrypted backups, and secret-redacted logging. No system is completely risk free; please report suspected exposure promptly.
10. Your choices and requests
Subject to applicable law, you may request access, correction, deletion, restriction, or information about eligible personal data. Some records may be retained for billing, security, dispute resolution, or legal compliance. You may revoke API keys, cancel subscriptions, and sign out through the product interfaces.
11. Changes and contact
We may update this Policy when our processing or legal obligations change. Material changes will be identified by the updated date. Contact support@japanapistore.com for privacy requests, and do not include passwords, tokens, full API keys, payment-card data, or full address queries.