LEGAL
LEGAL
PRIVACY POLICY
MADISONBLUE Co., Ltd. (Representative Director: Mariko Jinushi; head office: Wind Building 3F, 7-4-8 Roppongi, Minato-ku, Tokyo 106-0032, Japan; "we," "us," or "our") recognizes the importance of protecting the personal information of customers who use the MADISONBLUE ONLINE STORE and other services we provide (collectively, the "Services"). We comply with the Act on the Protection of Personal Information (個人情報の保護に関する法律; the "APPI") and other applicable laws and regulations, and handle and protect personal information appropriately in accordance with this Privacy Policy (this "Policy").
In addition to customers in Japan, we may provide goods and services to customers located in other countries or regions through cross-border e-commerce. To the extent applicable, we take the measures necessary to comply with the EU General Data Protection Regulation (GDPR), the data protection laws of the United Kingdom, the consumer privacy laws of the State of California in the United States (CCPA/CPRA), and other applicable data protection laws.
We use "Shopify," an e-commerce platform provided by Shopify Commerce Singapore Pte. Ltd., as the operating infrastructure and payment-related functionality for the Services. We also use DHL for international shipping and Yamato Transport for domestic shipping.
1 Proper Acquisition and Use of Personal Information We Collect
In connection with providing the Services, we collect the following personal information from customers and others by lawful and fair means, and do not collect information via deception or other wrongful means. We handle such personal information as set out below, only in cases permitted under the APPI or the personal information laws of the applicable jurisdiction.
(1) Information collected directly from you
- Name, gender, date of birth
- Address, telephone number, email address
- Account registration information and shipping address information
- Content of inquiries
- Other information you provide to us
Purposes of Use
- Providing and operating the Services
- Membership registration and account management
- Order acceptance, payment, identity verification, shipment of products, and delivery management
- Returns, exchanges, refunds, and other after-sales services
- Responding to inquiries, consultations, and requests
- Providing information about products and services, events, campaigns, and other matters
- Delivering email newsletters and other marketing communications
- Analyzing use of the Services and improving our products, services, and website
- Planning and developing new products and services
- Detecting and preventing fraudulent orders, unauthorized use of credit cards, fraud, and other wrongful acts
- Responding to conduct that violates our terms, policies, or other rules
- Performing legal obligations and responding to disputes, claims, and other legal proceedings
- Creating statistical information processed into a form that cannot identify individuals
Method of Collection
- Membership registration and order and purchase of products
- Inquiry form, email, and other communications
Legal Basis for Processing
- Performance of a contract or steps prior to entering into a contract (Article 6(1)(b) of the GDPR): membership registration, order acceptance, payment, delivery, returns, exchanges, refunds and other after-sales services, and responding to inquiries
- Your consent (Article 6(1)(a) of the GDPR): delivering email newsletters and other marketing communications
- Legitimate interests of us or a third party (Article 6(1)(f) of the GDPR): improving the Services, planning and developing new products and services, detecting and preventing wrongful acts, and ensuring security
- Compliance with a legal obligation (Article 6(1)(c) of the GDPR): performing legal obligations and responding to disputes, claims, and other legal proceedings
(2) Transaction and payment information
- Order details, purchase history, return and exchange history
- Delivery status, payment status
- Information necessary to detect unauthorized use
- Credit card information and other payment information may be processed by the payment functionality provided through Shopify or by other payment service providers. As a general rule, we do not directly retain full credit card numbers themselves.
Purposes of Use
- Order acceptance, payment, identity verification, shipment of products, and delivery management
- Returns, exchanges, refunds, and other after-sales services
- Planning and developing new products and services
Method of Collection
- Membership registration and order and purchase of products
- Inquiry form, email, and other communications
Legal Basis for Processing
- Performance of a contract or steps prior to entering into a contract (Article 6(1)(b) of the GDPR): order acceptance, payment, identity verification, shipment of products and delivery management, and returns, exchanges, refunds and other after-sales services
- Compliance with a legal obligation (Article 6(1)(c) of the GDPR): performing statutory retention obligations relating to taxation, accounting, and other matters
- Legitimate interests of us or a third party (Article 6(1)(f) of the GDPR): detecting and preventing fraudulent orders, unauthorized use of credit cards, and other wrongful acts, and planning and developing new products and services
(3) Information collected automatically
- IP address, Cookies, and other identifiers
- Browsing history, referrer information, date and time of access
- Device, browser, and operating system information
- Behavioral history on the Site, advertising identifiers
- Approximate location information
Purposes of Use
- Product suggestions and content display tailored to your interests
- Delivering advertising and measuring advertising effectiveness
- Ensuring security
Method of Collection
- Visits to our website
Legal Basis for Processing
- Your consent (Article 6(1)(a) of the GDPR): collection of information through Cookies other than strictly necessary Cookies, and product suggestions, content display, advertising delivery, and measurement of advertising effectiveness based on that information
- Legitimate interests of us or a third party (Article 6(1)(f) of the GDPR): ensuring the security of the Services and detecting and preventing wrongful acts (through strictly necessary Cookies)
(4) Information necessary for cross-border shipping and customs clearance
- Name, address, telephone number
- Order details and product information
- Other information required by the laws of the destination country or region, by customs authorities, or by DHL and other shipping and customs clearance providers
Purposes of Use
- Order acceptance, payment, identity verification, shipment of products, and delivery management
- Returns, exchanges, refunds, and other after-sales services
- Responding to inquiries, consultations, and requests
Method of Collection
- Membership registration and order and purchase of products
- Inquiry form, email, and other communications
- Provision from Shopify, DHL, and other service providers or contractors engaged by us
- Integration with third-party services to which you have provided consent
Legal Basis for Processing
- Performance of a contract or steps prior to entering into a contract (Article 6(1)(b) of the GDPR): international shipping of products and responding to related inquiries
- Compliance with a legal obligation (Article 6(1)(c) of the GDPR): import and export and customs clearance procedures and other statutory procedures of the destination country or region
2 Changes to the Purposes of Use
We may change the purposes of use within a scope that is reasonably deemed to be duly related to the purposes before the change. In such a case, we will notify or publicly announce the changed purposes of use in accordance with the applicable laws and regulations.
3 Restrictions on Use of Personal Information
Except as permitted by laws and regulations, we do not handle personal information beyond the scope necessary to achieve the purposes of use specified in advance. This does not apply where required by laws or regulations, where necessary to protect the life, body, or property of an individual, or in other cases permitted by laws and regulations.
4 Retention Period of Personal Information
We retain personal information only for the period necessary to achieve the purposes of collection, to perform contractual obligations, to comply with legal obligations, to respond to disputes, or for other legitimate business needs. Retention periods are determined by taking into account the type of information, the purposes of use, the duration of the transactional relationship, statutory retention obligations, and the need to respond to disputes or claims.
Specifically, retention periods are organized according to the following categories.
- (i) Information necessary while our relationship with the customer continues (membership information, order history, etc.): retained for five years from withdrawal of membership or from the date of last use.
- (ii) Information subject to statutory retention obligations (records relating to transactions, accounting, and taxation, etc.): retained for the period prescribed by the relevant laws. Specifically, books and records under the Corporation Tax Act (法人税法) must in principle be retained for seven years (ten years where loss carryforward deductions are taken under blue return filing), and accounting books under the Companies Act (会社法) for ten years. Where such period is longer than the period under the preceding item, the period under this item applies.
- (iii) Other information (information for which retention periods are set according to the individual purpose): retained for the period determined individually according to the purpose.
Information that is no longer necessary is deleted, destroyed, or anonymized in accordance with the applicable laws and regulations.
5 Security Control Measures
We implement organizational, personnel, physical, and technical security control measures to prevent unauthorized access to, and the loss, leakage, destruction, damage, or alteration of, personal information and related data. We also exercise necessary and appropriate supervision over our employees and service providers.
6 Provision to Third Parties and Outsourcing
Except as permitted by laws and regulations, we do not provide personal information to third parties without obtaining your prior consent. We may provide personal information to, or have it handled by, service providers necessary for the operation of the Services, including e-commerce platform providers, payment providers, shipping, logistics, and customs clearance providers, IT, cloud, and security providers, and analytics and advertising service providers, in accordance with the applicable laws and regulations.
We may also provide information in accordance with the applicable laws and regulations where required by laws or regulations or by a lawful request of a public authority, or in connection with a merger, company split, business transfer, or other business succession. We select service providers appropriately and exercise appropriate supervision, including the imposal of contractual obligations where necessary.
For provision of personal data to third parties located in foreign countries, please see Section 10.
7 Principal External Services We Use
We may use external services, including the following, for the purposes of Service provision, analytics, advertising, payment, shipping, and other purposes.
(1) Shopify
- Provider: Shopify Commerce Singapore Pte. Ltd. (Singapore)
- Main purposes: operating the e-commerce site, order management, customer management, payment-related functions through Shopify, security, and prevention of unauthorized use
- Information that may be shared: name, address, contact details, order information, payment-related information, device information, IP address, and other information necessary to provide the service
(2) AMS Co., Ltd.
- Provider: AMS Co., Ltd. (Japan)
- Main purposes: customer center operations (responding to inquiries, consultations, and requests) and issuance of shipping instructions on our behalf in connection with orders (communicating shipping instructions to the warehouse)
- Information that may be shared: name, address, telephone number, email address, order details, shipping address information, content of inquiries, and other information necessary to respond
(3) DHL
- Provider: DHL Japan, Inc. (Japan)
- Main purposes: international shipping, shipment tracking, import and export, customs clearance, and related procedures
- Information that may be shared: name, address, telephone number, email address, order details, product information, and other information necessary for shipping and customs clearance
(4) Yamato Transport
- Provider: Yamato Transport Co., Ltd. (Japan)
- Main purposes: domestic shipping, shipment tracking, and related procedures
- Information that may be shared: name, address, telephone number, email address, order details, product information, and other information necessary for shipping
(5) Google Analytics
- Provider: Google LLC (United States)
- Main purposes: site analytics, site improvement, and understanding usage
- Information that may be shared: Cookie identifiers, IP address, device information, and browsing and usage information
(6) Google advertising services
- Provider: Google LLC (United States)
- Main purposes: delivering advertising, measuring advertising effectiveness, and remarketing
- Information that may be shared: Cookie identifiers, advertising identifiers, and browsing and usage information
(7) Meta services
- Provider: Meta Platforms, Inc. (United States)
- Main purposes: delivering advertising on Facebook, Instagram, and similar platforms, measuring advertising effectiveness, and audience analysis
- Information that may be shared: Cookie identifiers, advertising identifiers, and browsing and usage information
(8) CRM and marketing services
- Provider: Klaviyo, Inc. (United States)
- Main purposes: customer management, delivering email newsletters and other marketing emails, customer communications, analysis of delivery effectiveness, and personalization
- Information that may be shared: name, email address, order and purchase history, email open and click activity, Cookie identifiers, and browsing and usage information
(9) Swym (Wishlist Plus)
- Provider: Swym Corporation (United States)
- Main purposes: providing the Wishlist function and delivering back-in-stock and other related notifications
- Information that may be shared: Cookie identifiers, session ID, email address, information on products added to the Wishlist, and browsing and usage information
8 Disclosure, Correction, and Deletion of Personal Information
Under the applicable laws and regulations, you may in certain cases request disclosure, correction, addition, deletion, suspension of use, erasure, withdrawal of consent, or cessation of provision to third parties with respect to your own personal information that we hold, or otherwise raise a request with us. We will respond in accordance with the applicable laws and regulations after confirming that the requester is the individual concerned or a duly authorized agent.
9 Disclosure of Records of Provision to Third Parties
Under the APPI and other applicable laws and regulations, you may in certain cases request disclosure of the records created when we provided personal information to, or received personal information from, a third party. We will respond in accordance with the applicable laws and regulations after verifying your identity.
10 Transfer of Personal Information to Third Parties in Foreign Countries
In connection with cross-border e-commerce, international payment processing, cloud services, site analytics, advertising, and other aspects of providing the Services, we may provide your personal information to businesses located outside Japan. This includes data processing by Shopify, international payment processing, overseas cloud or IT services, analytics and advertising services provided by Google, Meta, and others, email delivery and customer management by Klaviyo, provision of the Wishlist function by Swym, and fraud prevention and security services.
Except where consent is not required under laws and regulations, we provide personal data to such third parties in foreign countries only after obtaining your prior consent pursuant to Article 28, Paragraph 1 of the APPI. When obtaining your consent, we provide the following information pursuant to Article 28, Paragraph 2 of the APPI and Article 17 of the Enforcement Rules for the Act on the Protection of Personal Information (個人情報の保護に関する法律施行規則; the "Enforcement Rules").
(1) Names of the foreign countries to which data is transferred
- United States (certain Shopify functions, Google LLC, Meta Platforms, Inc., Klaviyo, Inc., Swym Corporation, etc.)
- Singapore (Shopify Commerce Singapore Pte. Ltd.)
(2) Information on the personal information protection regimes of those foreign countries
For information on the personal information protection regimes of those foreign countries, please refer to the following materials published by the Personal Information Protection Commission of Japan (個人情報保護委員会).
- United States: https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_america/
- Singapore: https://www.ppc.go.jp/enforcement/infoprovision/laws/offshore_report_singapore/
(3) Information on the measures taken by the recipients to protect personal information
- We have entered into a data processing agreement or an equivalent contract with each recipient, setting out matters such as limitation of the purposes of handling, restrictions on sub-processing, security control measures, and notification in the event of a leakage.
- Each recipient publishes, in its own privacy policy, the information it collects, its purposes of use, retention periods, and the methods by which data subjects may exercise their rights. The locations of the recipients' privacy policies are set out in Section 7 of this Policy and in our separate Cookie Policy.
11 Cookies and Other Technologies
In the Services, we may use cookies, pixel tags, local storage, software development kits (SDKs), and other similar technologies (collectively, "Cookies").
For details such as the names of Cookies, the recipients, retention periods, and how to refuse them, please refer to our separate Cookie Policy.
(1) Purposes of use
- Providing the basic functions of the Site
- Maintaining login status and cart information
- Security and prevention of unauthorized use
- Analyzing usage and improving the Site
- Displaying content tailored to your interests
- Delivering advertising and measuring advertising effectiveness
(2) Categories of Cookies
- Strictly necessary Cookies: necessary for site operation, security, login, the shopping cart, payment, and similar functions
- Functional Cookies: used for remembering language, region, and other settings to improve convenience
- Analytics Cookies: used for understanding usage and for improving the Services
- Advertising and marketing Cookies: used for advertising tailored to your interests, retargeting, and measuring advertising effectiveness
(3) Management of consent to Cookies
- Where required by the applicable laws and regulations, we use analytics Cookies, advertising and marketing Cookies, and other Cookies requiring consent — other than strictly necessary Cookies — only after obtaining your consent.
- Through the Cookie banner or the Cookie settings screen on the Site, you will be able to "Accept all," "Reject all except strictly necessary Cookies," change settings by category, and change or withdraw a previous choice.
- Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
(4) Browser settings
- You may restrict or delete Cookies through your browser settings. However, if you disable strictly necessary Cookies, you may be unable to properly use some functions of the Services.
12 Site Analytics and Advertising
We may use Google Analytics and other site analytics services. We may also use Google Ads, Facebook and Instagram advertising services provided by Meta, and other advertising services to deliver advertising, conduct retargeting, and measure advertising effectiveness. In jurisdictions where consent is required under the applicable laws and regulations, we use these technologies only after obtaining the necessary consent.
13 Privacy Requests
You may exercise your rights regarding personal information under the applicable laws and regulations by submitting a request through our Privacy Request contact point. Subject to the applicable laws and regulations, such requests may include access or disclosure, correction, deletion, suspension of use, restriction of processing, cessation of provision to third parties, data portability, objection to direct marketing, withdrawal of consent, and opting out of the sale or sharing of personal information.
Privacy Contact: privacy@madisonblue.jp
We may ask you to verify your identity to the extent necessary to respond to your request. Where a request is made by an agent, we may request documents confirming the agent's authority.
14 Marketing Communications
In accordance with the applicable laws and regulations, we may provide information about products, services, events, campaigns, and other matters by email and other means. You may opt out of marketing emails at any time using the unsubscribe link included in each email or other methods we provide.
15 Privacy of Minors
The Services are not, in principle, designed for children who are below the age at which they can enter into a valid contract or give valid consent on their own under the applicable laws and regulations. If we become aware that we have collected a child's personal information without the guardian consent required by law, we will take appropriate measures in accordance with the applicable laws and regulations.
16 Contact Us
For inquiries and requests regarding this Policy, our handling of personal information, or privacy generally, please contact us at the following.
- MADISONBLUE Co., Ltd.
- Representative Director: Mariko Jinushi
- Address: Wind Building 3F, 7-4-8 Roppongi, Minato-ku, Tokyo 106-0032, Japan
- General inquiries: the inquiry form on our website
- Privacy inquiries: privacy@madisonblue.jp
17 Establishment and Revision of This Policy
Date of establishment: October 1, 2026
Date of last revision: to be inserted as necessary
We may revise this Policy in response to changes in laws and regulations, the content of the Services, the external services we use, or other circumstances. If we make a material change, we will notify you by posting said changes on our website or by other appropriate means.
Annex
<Personal Data Subject to the GDPR>
The following applies to personal data as defined in the EU General Data Protection Regulation (the "GDPR") (such data, "GDPR Personal Data"). The following supplements the Privacy Policy set out above (the "Privacy Policy"), and in the event of any conflict with the Privacy Policy, the following prevails with respect to GDPR Personal Data.
1. Controller and Contact Details
The controller of GDPR Personal Data is us, as follows.
- Name: MADISONBLUE Co., Ltd.
- Address: Wind Building 3F, 7-4-8 Roppongi, Minato-ku, Tokyo 106-0032, Japan
- Representative Director: Mariko Jinushi
- Contact point for GDPR matters: privacy@madisonblue.jp
2. Use and Management of GDPR Personal Data
The GDPR Personal Data we collect from customers and others is as set out in Section 1 of the Privacy Policy (Proper Acquisition and Use of Personal Information We Collect).
3. Cross-Border Transfers of GDPR Personal Data
GDPR Personal Data of customers and others is transferred to the following countries or regions outside the EEA.
- Japan (the location of our head office): transferred on the basis of the adequacy decision of the European Commission (Article 45 of the GDPR).
- Singapore (Shopify Commerce Singapore Pte. Ltd.): transferred on the basis of the Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR.
- United States (Google LLC, Meta Platforms, Inc., Klaviyo, Inc., Swym Corporation, etc.): because the adequacy decision covers only entities participating in the EU-US Data Privacy Framework (DPF), transfers are made on the basis of that framework where the recipient participates in it, and on the basis of the standard contractual clauses (SCCs; Article 46(2)(c) of the GDPR) where it does not.
Customers and others may request a copy of the standard contractual clauses referred to above, or information on other appropriate safeguards, from the contact details below.
4. Special Categories of Personal Data
We do not collect special categories of personal data as set out in Article 9(1) of the GDPR (for example, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation).
5. Automated Decision-Making and Profiling
We do not carry out decisions based solely on automated processing that produce legal effects concerning customers and others or similarly significantly affect them (Article 22(1) of the GDPR). We may analyze browsing and purchase history obtained through Cookies in order to display product suggestions and advertising tailored to the interests of customers and others; however, such processing does not produce legal effects concerning them or similarly significantly affect them.
6. Retention of GDPR Personal Data
Unless a longer retention period is required by law, GDPR Personal Data we have collected is retained until a deletion request is received from the customer or other data subject, or until the expiry of the retention period we determine. We determine retention periods to the extent necessary for the purposes of use of GDPR Personal Data.
7. Your Rights
Customers and others have the following rights with respect to their GDPR Personal Data held by us. These rights may be exercised using the contact details set out in Section 8 below.
- The right to request access to GDPR Personal Data
- The right to have GDPR Personal Data rectified or erased without undue delay (except where we have a legal basis for retaining the GDPR Personal Data)
- The right to have the processing of GDPR Personal Data restricted
- The right to receive GDPR Personal Data in a commonly used, machine-readable format, and to transmit that data to another organization without hindrance
- The right to object to processing of GDPR Personal Data for the interests of us or a third party, and to object to processing for direct marketing purposes
- The right not to be subject to an evaluation or decision based on automated processing, including profiling, that produces legal effects concerning the individual or similarly significantly affects them
- The right to withdraw, at any time, consent given in relation to the processing of GDPR Personal Data (provided that such withdrawal does not affect the lawfulness of processing or transfers of GDPR Personal Data carried out before the withdrawal)
- The right to lodge a complaint with the competent supervisory authority or with our contact point if you are dissatisfied with our handling of GDPR Personal Data
Customers and others may contact the contact point set out in Section 1 above, or our representative in Europe set out in Section 8 below, in relation to the exercise of the rights above and any complaint. Customers and others may also lodge a complaint with the supervisory authority of the Member State of their habitual residence, place of work, or the place where the alleged infringement occurred (Article 77 of the GDPR). As our representative in Europe is located in France, the French supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL).
8. Our Group's Establishments in Europe
- Our representative in Europe: MADISON BLUE SAS
- Address: 36 rue Bonaparte, 75006 Paris
- Email: office.paris@madisonblue.jp