Privacy Policy
Effective: August 2026
Uraia is built with minimal data collection by design. We only collect what is necessary to provide the service. This policy explains exactly what that is.
What we collect
When you create an account
You sign in through a third-party provider (Google, Microsoft, or Apple). We receive and store only your email address and a provider-specific identifier used to link your account. We do not store your name, profile picture, phone number, or any other personal information from these providers.
If you register with a username and password instead of SSO, we store your username and a securely hashed password. We never store passwords in plain text.
When you use the platform
We maintain an authenticated session using an encrypted, HttpOnly cookie. Your session expires after 30 minutes of inactivity. We log your IP address and user-agent string for the duration of the session for security purposes.
When someone scans a QR code or opens a URL
Scan events are logged for analytics that you, the product creator, see in your dashboard. We record:
- Truncated IP address — the last octet is removed before storage (e.g. 192.168.1.x becomes 192.168.1.0). The full IP is never stored.
- Approximate location — country, region, and city derived from the truncated IP using a local database. No external geolocation services are called.
- Device information — device type, operating system, and browser, parsed from the user-agent string.
- Referrer and UTM parameters — if present in the URL.
- A one-way fingerprint hash — used only to count unique visitors. This hash cannot be reversed to identify a person.
Scans are anonymous. They are never linked to user accounts.
When you get in touch
You do not need an account to contact us. If you book a call, our scheduling provider collects your name and email address, plus anything you choose to add in the optional questions (company or brand, website, and what you sell). If you send your details through our enquiry form instead, we receive your email address and the same optional fields.
We use this only to reply to you and to prepare for the conversation. It is not linked to any account, never used for advertising, and never passed to anyone outside the providers listed below. Ask us at any time and we will delete it.
What we do not collect
- No phone numbers or physical addresses
- No names from platform use — a name is collected only if you book a call, where our scheduling provider requires one
- No payment card numbers, expiry dates, or billing addresses — all payment processing is handled by our payment provider (Whop)
- No cookies for advertising or cross-site tracking
- No third-party analytics (no Google Analytics, no tracking pixels, no Sentry)
- No device fingerprinting beyond the one-way hash described above
Third-party services
We use the following third-party services, each receiving only the minimum data required:
- Google, Microsoft, Apple — authentication only. We verify your identity token; no ongoing data exchange occurs after login.
- Whop — payment processing. Whop receives your payment details directly. We store only your subscription status and membership identifier.
- Google Maps Platform — map rendering for QR experiences. Google receives standard API requests; no user-identifying data is sent.
- Calendly — call scheduling. Used only if you book a call. Calendly receives and stores the name, email address, and optional answers you enter on their booking page. Their page opens in a new tab; no Calendly code runs on this site and Calendly sets no cookies here.
- Notion — enquiry form and the record of enquiries. Used only if you send us your details. Notion receives and stores what you enter on their form. Their form opens in a new tab; no Notion code runs on this site.
We do not sell, rent, or share your data with any other third party.
Infrastructure and security
- Hosted on Google Cloud Platform with IAM-authenticated database access
- All secrets managed via GCP Secret Manager — no hardcoded credentials
- Data encrypted in transit (TLS) and at rest
- Two isolated databases — authentication data is stored separately from product data
- QR code integrity protected by CRC checksums
- Sessions are HttpOnly, SameSite=Strict, Secure — protected against XSS and CSRF
- Rate limiting on all public endpoints
Data retention
Account data is retained for the lifetime of your account. Scan analytics are collected in anonymized form (IP addresses are truncated, no user identifiers are stored) and retained for up to 24 months to provide ongoing dashboard insights. Sessions expire after 30 minutes and are cleaned up automatically.
Enquiries and booking details are kept only while we are still in contact with you about getting set up, and are deleted once that conversation has clearly ended or at your request, whichever comes first.
Data residency
All production data — accounts, products, scan analytics, and sessions — is stored in Google Cloud Platform's asia-northeast1 (Tokyo, Japan) region. Platform data does not leave Japan for service delivery. Development environments may use other regions but do not process or store production user data.
Enquiries and bookings are the exception. If you book a call or send us your details, that information is held by Calendly and Notion on their own infrastructure, which is located outside Japan, primarily in the United States. It is never copied into our production databases. If you would rather not have your details stored outside Japan, email us instead and we will handle your enquiry directly.
Your rights
Under Japan's Act on the Protection of Personal Information (APPI), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA), you have specific rights regarding your personal data. Our minimal data collection means most of these rights are straightforward to exercise:
- Access and disclosure — your dashboard shows all scan analytics associated with your products. You may also request a copy of your retained personal data in electronic or written form.
- Deletion and cessation of use — request deletion of your account and all associated personal data. Anonymized scan analytics may be retained.
- Export — request a portable export of your account data.
- Rectification — request correction of inaccurate personal data.
- Object to processing — you may object to processing of your data where we rely on legitimate interest, or request cessation of third-party provision.
- Non-discrimination — exercising your privacy rights will not affect the service you receive.
To exercise any of these rights, email us at jtc.business.a@gmail.com or contact us through our LinkedIn page. We will respond to verified requests without delay, and no later than 30 days.
Regulatory compliance
Uraia is operated by 株式会社TiviTi (TiviTi Inc.), a Japanese Kabushiki Kaisha (KK). We comply with the following data protection frameworks:
- APPI (Japan) — Act on the Protection of Personal Information, including the 2022 amendments. Our primary governing framework.
- GDPR (EU) — General Data Protection Regulation, applicable when serving EU residents.
- CCPA (California, US) — California Consumer Privacy Act, applicable when serving California residents.
Legal basis for processing
Under GDPR and APPI, we process your data on the following bases:
- Contract performance — account creation, session management, and service delivery.
- Legitimate interest — scan analytics, security logging, and service improvement.
- Legal obligation — where required by law.
Cross-border data transfers
Production data is stored exclusively in Japan (GCP asia-northeast1). Authentication tokens are verified against OAuth provider endpoints (Google, Microsoft, Apple) as part of the sign-in process. Payment processing is handled by Whop as an entrusted processor. No bulk personal data is transferred outside Japan.
Cookies
We use two functional cookies. An authentication session cookie (encrypted, HttpOnly, 30-minute expiry) and an anonymous chat session cookie (HttpOnly, 4-hour expiry, scoped to the chat endpoint). Neither stores personal information. We do not use cookies for tracking, advertising, or analytics.
Changes to this policy
We may update this policy as our service evolves. Significant changes will be communicated through the platform. The effective date at the top of this page reflects the most recent update.
Contact
For privacy questions or data requests, email jtc.business.a@gmail.com or reach us through our LinkedIn page.