Privacy Policy

Who we are

[PLACEHOLDER — LEGAL ENTITY NAME AND ADDRESS]

Personal information we collect

[PLACEHOLDER — REQUIRES LEGAL REVIEW]

Editor: must enumerate actual data collected — name, address, email, phone, payment data, browsing data, cookies.

Purpose of use (利用目的)

[PLACEHOLDER — REQUIRES LEGAL REVIEW]

Editor: APPI requires the purpose of use to be specified and publicly stated. This section is legally load-bearing, not boilerplate.

Third parties

[PLACEHOLDER — REQUIRES LEGAL REVIEW]

Editor: must name Shopify, payment processors, carriers and analytics providers.

Cross-border transfer of personal data

[PLACEHOLDER — CRITICAL, REQUIRES LEGAL REVIEW]

Editor: this is the section most likely to be got wrong. Shopify stores data outside Japan, and if Finch staff in Sri Lanka access Japanese customer data, that is a cross-border transfer under APPI and triggers specific disclosure and consent obligations. Given Finch's structure this almost certainly applies. Flag to counsel explicitly.

Cookies

[PLACEHOLDER]

Disclosure, correction and deletion requests

[PLACEHOLDER — REQUIRES LEGAL REVIEW]

Editor: APPI grants these rights and requires a stated procedure for exercising them.

Contact regarding personal information

[PLACEHOLDER — PRIVACY CONTACT]


Status: REQUIRES LEGAL REVIEW. This is a structural skeleton, not a privacy policy. It has deliberately not been filled with generic text, because a plausible-looking but inaccurate privacy policy is worse than an obviously incomplete one.