Privacy Policy
Last Updated: August 24, 2026 · Version: v1.3
This Policy complies with the Japanese Act on the Protection of Personal Information (APPI). For questions, contact support@everbundance.com.
Privacy Policy — CapsuleHunt
Effective Date: July 17, 2026
Last Updated: August 24, 2026
Version: v1.3
1. Introduction
At Everbundance ("CapsuleHunt," "we," "us," "our," or "Company"), we are committed to protecting your privacy. This Privacy Policy (the "Policy") explains how we collect, use, disclose, and otherwise process personal information in connection with our gashapon / capsule toy vending machine location and inventory search service (the "Service").
1.1 Scope of Application
This Policy applies to all users ("User," "you") who access the Service via web browser, mobile app, or API.
1.2 Your Consent
By using the Service, you consent to the collection and use of your information as described in this Policy. If you do not agree, please discontinue use of the Service.
1.3 Governing Law
This Privacy Policy is governed by the Act on the Protection of Personal Information (APPI) of Japan and other applicable Japanese laws and regulations.
2. Definitions of Personal Information
"Personal Information" under this Policy refers to personal information as defined in Article 2, Paragraph 1 of the APPI, and includes:
| Category | Examples |
|---|---|
| Identifying Information | Email address, username (display name), password (hashed), date of birth (for age verification) |
| Location Data | GPS coordinates (only when permitted by the User) |
| Search & Browsing History | Search keywords, viewed stores/products |
| Device Information | OS version, device ID, browser type and version |
| Activity & Submission History | Inventory reports, reviews, timestamps |
| Network Information | IP address, User-Agent, request time |
Note on Age Verification
We verify your age via your date of birth at registration.
Users under the age of 16 must obtain the consent of a parent or legal guardian to use the posting features.
Users aged 16 or 17 are asked at registration to confirm that they have obtained the consent of a parent or legal guardian.
Note on Target Region
The Service is provided for residents of Japan.
Browsing and searching inventory information are available to everyone regardless of location, but
account registration, posting features, and participation in rankings are limited to residents of Japan.
3. Information We Collect
Upon Registration
When you create an account, we collect:
- Email address (for account verification and login)
- Username (display name)
- Password (stored as an irreversible hash, e.g., bcrypt)
- Date of birth (for age verification)
- Parent's email address (only when a user under 16 requests parental consent)
Your date of birth is used solely for age verification (to determine minor status).
Regarding Google Account Login
When you sign in using your Google account, we only receive the following information from Google:
- Email address
We do not collect or store your name, profile picture, or any other information associated with your Google account.
Regarding Sign in with Apple
The iOS app supports signing in with your Apple account. In that case, we receive only the following from Apple:
- Email address (or the relay address issued by Apple's "Hide My Email" feature)
We do not collect or store your name or any other information associated with your Apple account. If you choose "Hide My Email," we receive only the Apple-issued relay address in the form @privaterelay.appleid.com, and we never learn your actual email address. Our emails are forwarded to you through Apple. If you disable forwarding on Apple's side, our emails (inventory notifications, important announcements, etc.) will no longer reach you.
During Service Use
When you use the Service, we may collect:
- Location data: GPS coordinates, collected only when you use the "Find Nearby" feature and have explicitly granted permission
- Permission mechanism: native browser or device permission prompt
- You may revoke location permission at any time
- Search history: Search keywords
- Inventory report data: Store ID, product ID, inventory status, submission timestamp
- Report contents: The target and reason of a report and anything you enter in the detail field. We use this only to act on violations and prevent recurrence, and we never tell the reported user who reported them
- Block settings: Which users you have blocked. We use this only to control what is displayed, and we never notify or disclose it to the blocked user
- Photos and images: Images you capture or select in order to submit an inventory report or register a product
- We request camera and photo library access only at the moment you take or choose a photo. We never read your entire library.
- Submitted images are published on the Service. Please take care not to capture people, vehicle license plates, or store staff.
- If you use the automatic product-name reading (OCR) feature, the image is transmitted for analysis to the AI image analysis processor (USA) described in Section 10.5. We use only the analysis result (text such as product name and price), and we do not permit that processor to use the data for model training.
Profile Attributes (Optional — only if you provide them)
Through profile settings or surveys within the Service, you may optionally provide the following information. Providing it is optional, and the Service remains usable without it.
- Age group, gender, and region of residence (prefecture)
- Preference information such as favorite genres, titles, and motifs
- Survey responses such as capsule toy purchase frequency and budget range
We use this information for the purposes set out in Section 4 (including statistical analysis, data processing, and the data provision business). If you respond to a survey, we may grant points as a reward.
Automatically Collected Information
The following information is collected automatically when you access the Service:
- Cookie data: Session cookies and authentication tokens (see Section 6)
- Log data: IP address, User-Agent string, request time
- In-service activity logs (first party): Searches, product views, store views, and adding/removing favorites within the Service, together with the time of the action and the screen path
About activity logs and the anonymous ID
Activity logs are first-party logs recorded only in our own database. They are not provided to third parties for advertising purposes, and they are not used to track you across other companies' sites.
If you use the Service without signing in, we group actions from the same device using a random anonymous ID (
ch_anon_id) stored in your browser'slocalStorage. This anonymous ID alone cannot identify you, but if you later sign in on the same device, we may associate it with your account.Clearing your browser's site data also erases the anonymous ID, and your device is treated as a new one from then on.
We use activity logs as source material for the statistical information and anonymously processed information described in Sections 4(6), 4(8), 10.2, and 10.3.
4. How We Use Your Information
We use collected personal information only for the following purposes:
User authentication and account management
- Login and logout functionality
- Password reset
- Account deletion processing
Service provision
- Delivering location search functionality
- Sending inventory notification alerts
- Syncing favorites across devices
Service improvement and development
- Building and testing new features
- Bug fixes and quality improvements
- UI/UX optimization
Fraud detection and security
- Detecting and addressing spam and false inventory reports
- Preventing unauthorized access
- Identifying and stopping Service abuse
Legal compliance
- Responding to lawful requests from courts or law enforcement
- Cooperating with criminal investigations as required by law
Statistical analysis and data processing
- Anonymized and statistical analysis of user demographics and behavior
- Generating usage reports
- Creating the statistical information and anonymously processed information described in Section 10
Marketing (only with opt-in consent)
- Notifying users of new features and important updates
- Delivering email newsletters and surveys about gashapon and capsule toy content
Data provision business
- Providing statistical information and anonymously processed information that does not identify any individual to businesses that plan, manufacture, or sell capsule toys (including provision for a fee)
- Creating and providing market trend and demand analysis reports
5. Information Security
We implement the following measures to protect your personal information from unauthorized access, loss, disclosure, alteration, or destruction.
Technical Measures
- Encrypted communications: All data in transit is encrypted via SSL/TLS 1.2 or higher (HTTPS required)
- Password protection: Passwords are stored as irreversible hashes (e.g., bcrypt); plaintext passwords are never stored
- Data-at-rest protection: Personal information is protected by our database provider's at-rest encryption (AES-256)
- Access controls: Access to personal information is limited to the operator of the Service
Organizational Measures
The Service is operated by a single operator, and no employees other than the operator handle personal information. In addition, we implement the following measures:
- Periodic self-inspection of how personal information is handled
- Data protection agreements with, and necessary and appropriate supervision of, our service providers (Section 10.5)
- In the event of a data breach, reporting to the Personal Information Protection Commission and notifying affected individuals as required by the APPI
Physical Measures
- Storage in service providers' data centers with appropriate physical security measures
- Data redundancy through backups
Notice: No service delivered over the Internet can guarantee 100% security. While we implement reasonable security measures, we cannot entirely eliminate the risk of data breaches.
6. Cookies and Tracking
6.1 Cookies We Use
We currently use only the essential cookies required to keep you logged in. We do not use tracking cookies for advertising purposes, nor any third-party analytics cookies.
Separately from cookies, we record first-party activity logs for service improvement and statistics (see "Automatically Collected Information" in Section 3). These cover actions within the Service only; we do not track you across other companies' sites or apps.
Session Cookies (Required)
| Type | Expiry | Purpose |
|---|---|---|
| Authentication token | End of session | User authentication and maintaining login state |
| Session refresh token | End of session | Session management |
6.2 Opt-Out
- Browser settings: You may disable cookies via your browser settings. Note that disabling required cookies (such as session cookies) will prevent login and other core Service functionality
6.3 Mobile App
The iOS app does not use cookies. Authentication tokens are stored in the secure storage on your device (the Keychain).
In addition, the iOS app does not:
- Collect or use the advertising identifier (IDFA)
- Track you across other companies' services or apps for advertising purposes
- Embed third-party advertising or analytics SDKs
For this reason, no App Tracking Transparency (ATT) permission prompt is shown.
6.4 Future Changes
If we introduce web analytics (such as Google Analytics) in the future, we will update this Policy and provide a means of obtaining consent where required.
7. Location Data
7.1 Collection and Use
GPS and other location data is collected and used solely for the following purpose:
- Powering the "Find Nearby Stores / Vending Machines" feature
We do not use location data for marketing, targeted advertising, or any other purpose, and we do not share it with third parties.
7.2 Retention
- Location data is not stored in our database. It is used only to process your "Find Nearby" search request and is not retained afterward.
- We do not accumulate location data as an activity or movement history tied to your account.
Note on transmission logs
The "Find Nearby" search sends the coordinates at the center of your search as part of the request to our servers. As a result, those coordinates may be temporarily recorded, as the content of that request, in the transmission (access) logs held by our hosting and security providers (Section 10.5).
Those transmission logs are retained only for each provider's defined retention period for the purposes of incident response and protection against unauthorized access. We do not consult, analyze, or provide them to third parties as an individual movement history.
7.3 User Control
- You can grant or revoke location permission at any time via your browser or device settings
- In the iOS app, location access is limited to "While Using the App." We do not collect location in the background or track you continuously.
- Revoking location permission disables the "Find Nearby" feature, but all other features remain available
7.4 Note on Privacy
- We do not accumulate location data in our database, and we do not track individual movement patterns.
- We do not use location data for marketing or provide it to advertising businesses.
- When displaying maps, information necessary to render the map is transmitted to the map service provider:
- Web: The coordinates of the visible map area, your IP address, and related data are transmitted to Mapbox, Inc. (USA). See the "Transmission to External Services" section of our Cookie Policy for details.
- iOS app: We use Apple's mapping functionality (MapKit) to display maps, search place names, and generate directions links. In that case, the information necessary for map display and search is handled by Apple Inc. under its privacy policy.
8. Data Retention
While Your Account Is Active
| Data Type | Retention Period |
|---|---|
| Identifying information (email, username) | Until account deletion |
| Submission history (inventory reports, etc.) | Until account deletion |
| Location data | Not stored in our database (used transiently for search only; see the note on transmission logs in Section 7.2) |
Upon Account Deletion
When you delete your account, you are immediately signed out and can no longer log in, and your posts are no longer publicly visible (effectively a deleted state).
Your personal information and posted content (email address, password, settings, display name, inventory reports and other posts, and usage history such as points and referrals) are retained for 90 days from the deletion request, so that we can address misuse and respond to legal or lawful disclosure requests, and are then permanently deleted.
| Stage | Status |
|---|---|
| Immediately after deletion | Posts are unpublished (no longer visible to other users). Posting and notifications are also suspended |
| For 90 days after deletion | Data preserved for misuse response and lawful disclosure requests. During this period only, you can restore your account yourself (see below) |
| After 90 days | Personal information and posted content permanently deleted |
Restoring your account
Within 90 days of the deletion request, you can restore your account from within the app by signing in with the same account (the same email address, or the same Google or Apple account). Restoring returns your posts, points, and favorites to their state before the deletion request. After 90 days the data is permanently deleted and cannot be restored.
After permanent deletion, and except for records subject to the "Legal Retention Obligations" below, the data cannot be restored. Statistical information and anonymously processed information already derived from your posts (which cannot identify you or any individual post) continue to be used after deletion.
Legal Retention Obligations
| Data Type | Retention Period |
|---|---|
| Tax records | 7 years (under Japanese tax law) |
| Security incident investigation records | Until investigation is complete |
Handling of Personal Information for Minor Users
We verify your age via your date of birth at registration.
Users under the age of 16 must obtain the consent of a parent or legal guardian to use the posting features. At registration, we send a consent confirmation email to the parent's email address, and posting features are enabled once the parent consents. Until consent is obtained, the user may only browse and search.
Japan's Act on the Protection of Personal Information (APPI) does not specify an age at which a person can validly give consent. Taking into account the guidelines of the Personal Information Protection Commission (which treat roughly ages 12 to 15 and under as the benchmark for lacking consent capacity), we apply our own standard of under 16 and obtain the consent of a parent or legal guardian for those users. If a parent wishes to delete their child's account, they can do so immediately via the link in the consent confirmation email.
Users aged 16 or 17 are minors under the Civil Code of Japan. Under Section 3.2 of the Terms of Service, they must obtain the consent of a parent or legal guardian in order to use the Service, and are asked at registration to confirm that such consent has been obtained. We retain the date and time of that confirmation as a record.
9. Your Rights (Access, Correction, Deletion)
Under the APPI and applicable law, you have the following rights:
9.1 Right to Access
You may request disclosure of personal information we hold about you.
How to request:
Email: support@everbundance.com
Subject: Personal Information Disclosure Request
Body: Include your username, the information you are requesting, and your reason for the request
Response time: Within 14 business days of receipt.
9.2 Right to Correction
If your personal information is inaccurate, you may request correction by:
- Editing directly in your account settings page
- Emailing
support@everbundance.com
9.3 Right to Deletion
You may request deletion of your personal information by:
- Using the "Delete Account" feature in your account settings
- Or emailing
support@everbundance.com
Processing time: Using the "Delete Account" feature immediately disables your account (login blocked, posts hidden); your data is then permanently deleted after the retention period. Email requests are handled in the same manner.
Note: When you delete your account, your posted content such as inventory reports is deleted as well (and is hidden from public view during the retention period).
9.4 Right to Restrict Use or Third-Party Sharing
You may request that we stop using or sharing your personal information if:
- We are using your information in violation of this Policy
- Your information is being used or shared without your consent
Contact: support@everbundance.com
10. Disclosure to Third Parties
10.1 Disclosure of Personal Data
Except in the following cases, we do not disclose information that identifies a specific individual (personal data) to third parties without your consent:
- Where you have consented
- Where required by law (Section 10.4)
- Where we entrust processing to service providers (Section 10.5)
- Disclosure to subsidiaries or affiliates of Everbundance that apply protections equivalent to or greater than this Policy
10.2 Provision of Statistical Information
We may aggregate and statistically process the information of multiple users to create statistical information that does not identify any specific individual. Because such statistical information is not personal information, we may provide it — whether for a fee or free of charge — to third parties, including businesses that plan, manufacture, or sell capsule toys.
10.3 Creation and Provision of Anonymously Processed Information
In accordance with the standards set out in Article 43 et seq. of the APPI, we may create "anonymously processed information" (kameishin-kakō jōhō) that is processed so that no specific individual can be identified and the original personal information cannot be restored, and may provide it to third parties.
- When we create anonymously processed information, we publish the categories of information about individuals contained therein on our Anonymously Processed Information page.
- When we provide anonymously processed information to a third party, we publish in advance the categories of information to be provided and the method of provision, and expressly indicate to the recipient that the information is anonymously processed information.
- In handling anonymously processed information, we do not collate it with other information for the purpose of identifying the individual to whom the original personal information relates.
Categories that may currently be provided (anonymously processed information)
| Category | Examples |
|---|---|
| Attributes | Age group, gender, region of residence (at the prefecture level) |
| Preferences | Favorite genres, titles, and motifs |
| Behavior | Trends in searching, browsing, favorites, and inventory reports |
| Purchasing | Purchase frequency and budget range (based on survey responses) |
- All of the above are handled only after being processed so that no specific individual can be identified.
10.4 Disclosure Required by Law
- In response to lawful requests from courts or law enforcement following due process. Except where notice is prohibited by law, we will consider notifying you.
10.5 Disclosure to Service Providers
To provide the Service, we may entrust the handling of personal data to service providers in the following categories. We execute data protection agreements with each provider and exercise necessary and appropriate supervision.
| Category | Purpose | Primary Location |
|---|---|---|
| Database & Authentication | User account management and database storage | USA |
| Hosting, CDN & Security | Website delivery and protection against unauthorized access | USA |
| Email Delivery | Email notification and survey delivery | USA |
| AI Image Analysis | Reading product names from submitted images (OCR) | USA |
| Map Services | Map display and tile delivery | USA |
For inquiries about specific service providers, please contact support@everbundance.com.
Additional note on AI image analysis (OCR)
Images are transmitted to the processor only when you use the automatic product-name reading feature. Under our contract with that processor, the transmitted images and analysis results may not be used to train its generative AI models. You may also enter product names manually without using this feature.
10.6 Provision to Third Parties Located in Foreign Countries
The service providers listed above include businesses located in foreign countries (primarily the United States). In accordance with Article 28 of the APPI, we provide personal data to third parties located in foreign countries (including by way of entrustment) only where:
- We have obtained your prior consent (obtained as part of your consent to this Policy at account registration); or
- The third party has established a system that conforms to standards for continuously implementing measures equivalent to those required under the APPI (including equivalent protections secured through our data processing agreements).
The United States does not have a comprehensive data protection law equivalent to Japan's APPI; however, we endeavor to secure a level of protection equivalent to Japanese law through our agreements with each provider. For information on the data protection regimes of foreign countries, please refer to the surveys published by Japan's Personal Information Protection Commission (https://www.ppc.go.jp/).
11. Contact Information
For questions, requests, or complaints regarding our handling of personal information, please contact:
Business name: Everbundance
Address: Hamamatsucho Daiya Bldg. 2F, 2-2-15 Hamamatsucho, Minato-ku, Tokyo 105-0013, Japan
Email: support@everbundance.com
Response time: Within 7 business days
Business Hours: Monday–Friday, 10:00–18:00 (JST)
In accordance with Article 32 of the APPI, the name of the business operator will be disclosed without delay upon request sent to the email address above.
12. Policy Updates
12.1 Right to Amend
We may amend this Policy from time to time in response to changes in applicable law, the Service, or other relevant factors.
12.2 Notice of Changes
- Minor changes: Posted to the Service without separate notification
- Material changes: Notified via email to your registered address and/or in-app announcement at least 30 days before taking effect
12.3 Deemed Consent
If you continue to use the Service after the updated Policy takes effect, you will be deemed to have consented to the revised Policy. If you do not agree, you may delete your account at any time. However, for material changes to the purposes of use or any other changes for which your consent is required by law, we will obtain your explicit consent rather than relying on deemed consent.
Revision History
| Version | Date | Summary of Changes |
|---|---|---|
| v1.0 | July 17, 2026 | Initial release |
| v1.2 | August 11, 2026 | Revised for the iOS app release. Added Sign in with Apple, photos/camera, transmission to AI image analysis, and in-service activity logs with an anonymous ID. Corrected the location data description to reflect transmission logs. Stated the 90-day account deletion preservation period. Added mobile app handling (no IDFA, no ATT prompt). |
| v1.3 | August 24, 2026 | Clarified in Section 8 that the under-16 parental consent threshold is our own standard rather than a statutory age. Added the parental consent confirmation for users aged 16 or 17, and the retention of that confirmation, to Sections 2 and 8. Added to Section 8 that an account can be restored by the user within 90 days of the deletion request. |
Copyright © Everbundance. All rights reserved.
Last Updated: August 24, 2026
Version: v1.3
Effective Date: July 17, 2026
Language: English
Governing Law: Act on the Protection of Personal Information (APPI), Japan
Related Documents