Legal · プライバシーポリシー
Privacy Policy.
Effective 29 April 2026
Who we are
NiCards is operated by Your Planning Co., Ltd., a Japanese corporation with its registered office at 4-4-5 Sakuragaoka, Itami-shi, Hyogo 664-0897, Japan. Corporate number 7140001139701. We are the data controller for the personal data described below.
What we collect
We collect personal data in three ways:
- When you place an order. Name, shipping address, email, phone (optional), and the items in your cart. Payment-card details are submitted directly to Stripe — we do not see, store, or transmit your card number.
- When you create an account. Email and a hashed password, or — if you sign in with Google — the email and profile name returned by Google OAuth. Order history is linked to your account.
- Automatically. Server logs (IP address, user-agent, request timestamps) for security and debugging. Essential cookies for authentication, cart, and Stripe checkout. Google Analytics for aggregate traffic measurement and the Meta Pixel for advertising attribution and audience modelling on Facebook and Instagram (see Cookies, below).
Why we use it
We use your personal data to fulfil your order, provide customer support, comply with our legal obligations as a Japanese registered antique dealer (which requires us to keep transaction ledgers), prevent fraud, and improve the storefront. We do not sell or share personal data with advertisers.
Lawful basis (EEA / UK customers)
For customers in the EEA and the UK, we process personal data on the following bases under GDPR / UK-GDPR:
- Performance of a contract — to process and fulfil your order.
- Legal obligation — to maintain transaction records under Japan's Secondhand Articles Dealer Act.
- Legitimate interest — to prevent fraud and secure the service.
- Consent — where required for non-essential processing; withdrawable at any time.
Who we share it with
We share the minimum necessary data with the service providers that operate the storefront:
- Stripe (United States, Ireland) — Payment processing.
- Convex (United States) — Database, authentication, and order records.
- Google (United States) — OAuth sign-in, only if you choose to sign in with Google.
- Google Analytics (United States) — Aggregate site analytics — page views, referrer, device type, country. We do not enable advertising features, audience sharing, or Google Signals.
- Meta Platforms Inc. (United States, Ireland) — Meta Pixel for advertising attribution, conversion measurement, and audience modelling on Facebook and Instagram. The Pixel sends page-view, content, and purchase events tied to a hashed identifier so we can measure ad performance and reach similar customers. No card numbers or precise location are sent.
- Vercel (United States) — Website hosting and edge network.
- Shipping carriers — Japan Post, FedEx, DHL — name, address, and phone for delivery.
International transfers
We are based in Japan. If you are in the EEA or UK, your data will leave your home jurisdiction. Japan has been recognised by the European Commission and the UK as providing an adequate level of data protection (the “Japan adequacy decision”), so transfers are lawful without additional safeguards.
Transfers to US-based processors (Stripe, Convex, Google, Vercel) are made under the EU/UK Standard Contractual Clauses or equivalent.
How long we keep it
Order records are retained for 7 yearsas required by Japan's Secondhand Articles Dealer Act and tax law. Account data is kept until you ask us to delete your account, at which point we delete profile data and anonymise the historical order records we are legally obliged to keep.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or port the personal data we hold about you, and to object to certain processing. Customers in California (CCPA), the EEA/UK (GDPR), and Japan (APPI) have specific statutory rights — we honour them all globally.
To exercise any right, email us via /contact. We respond within 30 days.
Cookies
We use the following categories of cookies:
- Essential. Authentication session, cart state, and Stripe Embedded Checkout. The site does not function without these.
- Analytics. Google Analytics 4 sets _ga and _ga_<id> cookies (typical lifespan up to 24 months) to count visits and report aggregate traffic. We do not enable advertising features, audience sharing, or Google Signals on this property.
- Advertising. The Meta Pixel sets _fbp (and, if you visit via a Facebook/Instagram ad, _fbc) cookies for ad attribution and audience modelling. Lifespan up to 90 days. We do not run remarketing on Google, TikTok, LinkedIn, or any other network.
You can opt out of Google Analytics measurement by installing the Google Analytics opt-out browser add-on or by blocking cookies for this domain. You can adjust how Meta uses your data for ads via your Facebook Ad Preferences and Instagram privacy settings. Stripe, Google, and Meta may set their own cookies during their respective flows; their privacy policies govern those.
Children
The storefront is not directed at children under 13 (US) or under 16 (EEA/UK). We do not knowingly collect data from children. If you believe a child has submitted data to us, contact us and we will delete it.
Updates
We may update this Policy. Material changes will be flagged on this page and dated at the top. Continued use of the storefront after an update means you accept the revised Policy.
Contact
Privacy questions or requests: /contact. Postal address: Your Planning Co., Ltd., 4-4-5 Sakuragaoka, Itami-shi, Hyogo 664-0897, Japan. Phone +81 80 6536 7443.
