Who we are
[PLACEHOLDER — LEGAL ENTITY NAME AND ADDRESS]
Personal information we collect
[PLACEHOLDER — REQUIRES LEGAL REVIEW]
Editor: must enumerate actual data collected — name, address, email, phone, payment data, browsing data, cookies.
Purpose of use (利用目的)
[PLACEHOLDER — REQUIRES LEGAL REVIEW]
Editor: APPI requires the purpose of use to be specified and publicly stated. This section is legally load-bearing, not boilerplate.
Third parties
[PLACEHOLDER — REQUIRES LEGAL REVIEW]
Editor: must name Shopify, payment processors, carriers and analytics providers.
Cross-border transfer of personal data
[PLACEHOLDER — CRITICAL, REQUIRES LEGAL REVIEW]
Editor: this is the section most likely to be got wrong. Shopify stores data outside Japan, and if Finch staff in Sri Lanka access Japanese customer data, that is a cross-border transfer under APPI and triggers specific disclosure and consent obligations. Given Finch's structure this almost certainly applies. Flag to counsel explicitly.
Cookies
[PLACEHOLDER]
Disclosure, correction and deletion requests
[PLACEHOLDER — REQUIRES LEGAL REVIEW]
Editor: APPI grants these rights and requires a stated procedure for exercising them.
Contact regarding personal information
[PLACEHOLDER — PRIVACY CONTACT]
Status: REQUIRES LEGAL REVIEW. This is a structural skeleton, not a privacy policy. It has deliberately not been filled with generic text, because a plausible-looking but inaccurate privacy policy is worse than an obviously incomplete one.