Yuikiri Privacy Policy
The operator providing the online service "Yuikiri" handles user information regarding the service as follows.
Article 1 (Basic Policy and Scope)
- The Operator complies with Japan’s Act on the Protection of Personal Information (the “APPI”), other applicable laws and regulations, and relevant guidelines, and handles User information appropriately.
- This Policy applies to the handling of User information in connection with the Service’s website, purchase process, provision of the ritual, email delivery, and support inquiries.
Article 2 (Definitions)
- “Personal Information,” “Personal Data,” and “Retained Personal Data” have the meanings given to them under the APPI.
- “Ritual Text” means text entered by a User during the writing and declaration stages of the ritual.
Article 3 (Information Collected or Stored)
The following information is collected or stored in order to provide the Service.
- Purchaser information: email address
- Order information: order ID, plan, language, amount, Stripe Checkout Session ID, payment status, and creation time
- Entrance information: a difficult-to-guess access token used to generate the Entrance URL
- Ritual progress information: ritual ID, associated order ID, current stage, fire or water selection, completion time, and update time
- Email delivery information: order ID, email type, delivery ID issued by the email service provider (Resend), and delivery time
- Display preference stored on the device: ritual presentation intensity. This information is stored in the User’s browser sessionStorage and is not sent to the server.
- Information automatically obtained through access: IP address, User-Agent, access time, request information, error information, and similar information may be obtained or recorded by infrastructure providers such as Cloudflare.
Article 4 (Information Not Sent or Stored)
- Ritual Text is not sent to or permanently stored on the Operator’s servers and is not recorded in databases, storage, application logs, email, or error-monitoring tools.
- Credit card numbers and other card details are handled by Stripe, the payment service provider, and are not retained on the Operator’s servers.
Article 5 (Purposes of Use)
Collected information is used only for the following purposes.
- Processing purchases, confirming payments, and managing orders
- Issuing Entrance URLs, sending email, storing ritual progress, enabling resumption, and processing completion
- Responding to inquiries, verifying identity, issuing refunds, and providing other support
- Preventing and responding to misuse, security incidents, and service failures
- Improving the quality, safety, and functionality of the Service
- Creating and retaining records required by law
Article 6 (Service Providers)
- The Operator outsources all or part of the handling of Personal Data to the following service providers in order to provide the Service.
- Cloudflare: delivery of the website and API, storage of data in the D1 database, and security measures
- Stripe: payment processing, including Checkout Sessions and webhooks
- Resend: delivery of purchase confirmation emails
- The Operator selects service providers after considering the level of safeguards they apply to Personal Data and supervises their handling of Personal Data through necessary and appropriate means.
Article 7 (Provision to Third Parties)
- The Operator does not provide Personal Data to a third party without the prior consent of the individual, except in the following circumstances.
- Where required by law
- Where necessary to protect a person’s life, body, or property and it is difficult to obtain the individual’s consent
- Where the handling of Personal Data is outsourced within the scope necessary to achieve the purposes of use
- Where Personal Data is provided in connection with a business succession resulting from a merger or other event
- When providing Personal Data to a third party, the Operator carries out the confirmations and creates and retains the records required by law.
Article 8 (Handling in Foreign Countries)
- Service providers to which the handling of Personal Data is outsourced include businesses located outside Japan. The principal service providers and their countries of location are as follows.
- Cloudflare, Inc. (United States of America)
- Stripe (United States of America)
- Resend (United States of America)
- These service providers may store data in their respective countries and process it through global infrastructure. The Operator takes necessary measures, including through its agreements with each service provider, to ensure that Personal Data is handled appropriately.
- Information about personal information protection systems in the countries where the service providers are located and the measures taken by those providers is available upon request through the contact point stated in Article 14.
Article 9 (Cookies and Storage on the Device)
- The Service stores the ritual presentation intensity setting in the User’s browser sessionStorage. This information is not sent to the server.
- The Service may use a cookie to retain the User’s language selection. This cookie is used only to maintain the display language and is not used to track User behavior.
- The Service currently does not include advertising tags or analytics tags. If such technologies are introduced in the future, this Policy will be updated to state the names, providers, purposes, retention periods, and methods of refusal for the relevant cookies or similar technologies, and consent will be obtained where required by law.
Article 10 (Security Measures)
The following measures are taken to prevent leakage, loss, or damage of Personal Data and otherwise manage it securely.
- HTTPS communications and security headers, including Content Security Policy
- Separation of permissions so that database access is limited to the API server
- Management of API keys and other secrets in encrypted storage provided by Cloudflare Secrets
- Use of difficult-to-guess access tokens in Entrance URLs
- A design that does not send, store, or log Ritual Text
- Use of placeholders and value binding to prevent SQL injection
- Measures against unauthorized access using WAF and Rate Limiting
- Reporting to Japan’s Personal Information Protection Commission and notifying affected individuals as required by law if a data breach or similar incident occurs
Article 11 (Retention and Deletion)
- Order and payment records are retained for the periods required by law, based on statutory record-keeping obligations and tax and accounting requirements.
- Email addresses, Entrance URL access tokens, ritual progress information, and email delivery records are retained for as long as necessary to provide the Service, including renewed access through an Entrance URL and prevention of duplicate delivery, and to provide support. When they are no longer required, they will be deleted without undue delay or processed into a form that does not identify an individual.
- The retention periods for access logs and similar information recorded on service-provider infrastructure are determined by the relevant service provider.
Article 12 (Requests for Disclosure, Correction, Suspension of Use, and Similar Measures)
- In accordance with the APPI, a User may request notification of the purpose of use, disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of provision to third parties in relation to Retained Personal Data.
- Requests under the preceding paragraph are accepted through the contact point stated in Article 14. The identity of the requester will be verified through an application sent from the email address registered at purchase or another reasonable method.
- No fee is charged for these requests.
- After receiving a request, the Operator will conduct the necessary review without undue delay and, in principle, respond to the registered email address within two weeks.
- If a request cannot be fulfilled under applicable law, the User will be notified of that fact and the reason without undue delay.
Article 13 (Information Concerning Persons Under 18)
- The Service is not intended for persons under 18 years of age.
- If the Operator learns that it has obtained Personal Information relating to a person under 18, it will respond appropriately, including by deleting that information without undue delay.
Article 14 (Contact)
Requests and inquiries concerning the handling of Retained Personal Data are accepted through the contact point stated in the Disclosure under the Act on Specified Commercial Transactions in Japanese.
Article 15 (Changes to this Policy)
- This Policy may be changed in response to amendments to laws and regulations, changes to the Service, or other needs.
- If this Policy is changed, the revised content and effective date will, in principle, be announced on the official website at least one week before the effective date. The User’s prior consent will be obtained for any material change where consent is required by law.
Supplementary Provision
- Established: July 18, 2026
- Effective: July 18, 2026