Contents
- 1. Operator
- 2. Information we collect
- 3. How we collect information
- 4. Purposes of use
- 5. Location and map information
- 6. Service providers and international processing
- 7. Disclosure to third parties
- 8. Security
- 9. Retention and deletion
- 10. Cookies and device storage
- 11. Analytics and error monitoring
- 12. Access, correction, and other requests
- 13. Minors
- 14. Changes to this Policy
- 15. Contact
1. Operator
The entity responsible for personal information under this Policy is Nowly Inc. Contact us at the address at the end of this Policy with questions about our handling of personal information.
2. Information we collect
- Name, email address, authentication data, account settings, and information needed to verify identity
- Workspace, membership, role, permission, and invitation information
- Store searches, saved routes, planned visits, check-ins, checkouts, and next-visit notes
- Sourced items, images, prices, shipping costs, estimated profit, decisions, and other submitted content
- Current location, selected places, routes, and map interactions when device permission is granted
- Device, browser, IP address, cookies, sessions, access times, activity, errors, and security logs
- Support requests, surveys, feedback, and communications with the Operator
- Plan, billing, and payment-status data for paid features; complete card data is handled by payment providers
3. How we collect information
We collect information you submit, information provided through device permissions, automatic service logs, authentication, map, route, email, and payment providers, support interactions, and lawfully available public sources. Location is collected only when permitted in your device or browser.
4. Purposes of use
- Creating accounts, authentication, session management, and identity verification
- Providing store search, route planning, visit management, sourcing records, profit calculations, and related features
- Managing workspace access, collaboration, subscriptions, billing, and contracts
- Responding to support, sending important notices, and communicating at your request
- Detecting, investigating, preventing, and responding to abuse, Terms violations, security incidents, and rights violations
- Troubleshooting, improving quality, developing features, analyzing usage, and making operational decisions
- Creating and using non-identifying statistics for analytics, publication, and business purposes
- Complying with laws and lawful requests from courts, regulators, and public authorities
5. Location and map information
We use current location to show nearby stores, create routes, and open directions from your location. We may send locations, destinations, and route conditions to map and route providers as needed to provide these features.
You may disable location access in device settings, but location-based features may stop working. Saved routes, check-ins, and visit records may remain until you delete them or delete your account.
6. Service providers and international processing
We may engage providers of cloud hosting, databases, authentication, email, maps, routes, payments, monitoring, analytics, and support to process information as necessary. We select and oversee providers using contracts and other appropriate controls.
A provider’s privacy policy may also apply. If information is transferred to a provider outside Japan, we provide information and take measures required by applicable law.
7. Disclosure to third parties
We do not provide personal data to third parties except with your consent, as required or permitted by law, to protect life, health, or property when consent is difficult to obtain, in connection with a business succession, or in another legally permitted case.
When collaboration features are used, your name, email, role, and shared records may be visible to other authorized members of the workspace.
8. Security
We use organizational, personnel, physical, and technical safeguards appropriate to the information and risk, including access controls, authentication, transport security, logging, backups, vulnerability response, permission management, and provider oversight.
We will describe safeguards on request to the extent doing so does not undermine security. No system is completely secure, and you are responsible for protecting your credentials and devices.
9. Retention and deletion
We retain information for as long as needed for the purposes above, contract performance, abuse prevention, backups, dispute handling, and legal compliance. Information that is no longer required is deleted or de-identified within a reasonable period.
After account deletion, some information may remain as required for legal retention, rights protection, audits, backup rotation, and abuse prevention.
11. Analytics and error monitoring
We use Google Analytics 4, provided by Google LLC, to understand and improve use of the Service. Google Analytics 4 may receive the URL of a viewed page without its query string or hash, page title, and device and browser information.
For a signed-in user, we send an internal user ID issued by the Service as the Google Analytics 4 User-ID so usage can be associated across devices. We do not use a name, email address, or workspace ID as the User-ID, and we do not set a User-ID for an anonymous user.
We use Google Tag Manager, provided by Google LLC, to manage approved measurement tags. The identity context that the Service places in the shared data layer is limited to an internal user ID or null for an anonymous user; it does not include a name, email address, workspace ID, URL query string, or URL hash.
We also use Sentry, provided by Functional Software, Inc., to detect and investigate failures. Sentry may receive error details, the location of a failure, and device and browser information. We disable default personal-information transmission, performance tracing, and session replay for Sentry.
12. Access, correction, and other requests
Subject to applicable law, you may request notice of purposes, access, correction, addition, deletion, suspension of use, erasure, suspension of third-party disclosure, and disclosure of third-party transfer records.
We may request identity verification and information needed to identify the records. If law permits us to decline a request, we will explain the reason. A reasonable fee reflecting actual cost may apply where permitted by law.
13. Minors
A minor must obtain consent from a legal representative before using the Service. We may request confirmation of consent or restrict use when reasonably necessary.
14. Changes to this Policy
We may revise this Policy as the Service, our processing, or applicable law changes. We will announce material changes through the Service, email, or another reasonable method. A revised Policy applies from its stated effective date.
15. Contact
Contact us at the address below with privacy questions, rights requests, or complaints.