PRIVACY POLICY
How AdMosaic collects, uses, retains, transfers, and safeguards personal data, related information, cookies, and measurement data.
The Japanese version is the governing text. Users outside Japan may have additional rights under mandatory local law.
The data controller is the AdMosaic operator identified in the Commercial Transaction Disclosures. This Policy applies to site visitors, advertisers, applicants, business contacts, and people who contact us.
The service is for business use by people aged 18 or older. We do not knowingly collect data from anyone under 18 and will delete it unless retention is legally required.
We collect names, company or trading name, country, business address, email, telephone, optional tax ID, account and authentication data, enquiries, and Founding Partner application data.
We collect order and refund records, payment status, spaces, creatives, destinations, review and enforcement history, accepted document versions and timestamps, hashed IP data, user agent, business identity hashes used for promotion eligibility, payment-method identifiers supplied by Stripe, promotion review flags, and audit logs. Stripe directly processes card details; AdMosaic does not store card numbers.
We may collect page views, ad impressions and clicks, timestamps, referrer, UTM data, session identifiers, cookie choices, and device or browser information.
We process data to form and perform contracts, verify users, process payment and refunds, review and deliver advertisements, report performance, respond to enquiries, send important notices, and operate the Founding Partner programme.
We also process data to determine promotion eligibility and detect duplicate use, and for fraud prevention, security, diagnostics, quality improvement, rights protection, legal compliance, and disputes. Optional analytics are based on consent. Where overseas law applies, the bases may include contract, legal obligation, legitimate interests, and consent.
Essential storage supports authentication, security, language, reservations, and recording cookie choices. Disabling it may prevent core features from working.
Optional analytics cookies and Google Analytics are not loaded until express consent. Choices can be changed through Cookie settings. Before enabling Google Analytics, we will configure a measurement ID and update this Policy and the processor information.
We aggregate advertisement impressions and clicks for advertiser reports. For visitors who do not consent to analytics storage, we avoid storing an identifier on the device and use methods designed to reduce identifiability.
Short-lived session or hashed information may be used to filter fraud and duplicates. Advertisers do not receive information that identifies individual visitors.
We use Vercel for hosting, Neon for PostgreSQL database services in the Singapore region, Stripe for payment, Resend for email, and Cloudflare for R2 storage and Turnstile security. Each processes information only as required for its contracted role.
These providers may process information in Japan, Singapore, the United States, and other countries. We use contracts, access controls, provider security reviews, and safeguards required by applicable law. Material provider or location changes will be reflected in this Policy.
We do not disclose personal data to third parties except with consent, as required by law, to protect life, safety, or property, in a legitimate business succession, or through lawful processing arrangements.
Advertiser reports are generally aggregated. We do not disclose visitor names, emails, or payment data to advertisers, and we do not sell personal data.
Orders, payments, refunds, legal acceptance, and audit records are retained for seven years; impression and click events for 13 months; general enquiries and accepted applications for two years.
Rejected or withdrawn applications are retained for one year, and minimal account data for fraud and dispute handling for one year after closure. Creative files are normally deleted within one year after placement ends, subject to legal, dispute, backup, and security needs.
We apply risk-appropriate access restrictions, authentication and two-factor controls, encryption in transit, secret separation, audit logging, backup, vulnerability response, processor management, and incident handling.
Where a breach requires reporting or notice, we will notify relevant authorities and affected people as required by law. No internet service can guarantee absolute security.
Subject to law, you may request notice of purpose, access to retained personal data or disclosure records, correction, addition, deletion, restriction, erasure, or cessation of third-party disclosure. We respond after identity verification within the statutory or a reasonable period.
Where EEA, UK, or other regional law applies, rights may also include portability, objection, consent withdrawal, and complaint to a supervisory authority. Withdrawal does not affect prior lawful processing.
Send requests to the privacy contact in the Commercial Transaction Disclosures and identify the data and action requested. We may request evidence of identity or authority.
We may refuse or limit a request where law permits, another person's rights would be harmed, identity cannot be verified, or the information is no longer held. Requests are generally free; reasonable actual cost for repetitive or excessive requests will be notified in advance.
We may update this Policy for changes in law, service, or processors. Material changes will be notified before taking effect, and fresh consent will be obtained where required.
Send privacy complaints, enquiries, and rights requests to the contact listed in the Commercial Transaction Disclosures.