Privacy Policy
Privacy Policy
Last updated: June 2025
KADO Japan ("we," "us," or "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and what rights you have over your data. It applies to all personal data collected through the KADO Japan website (kadojapan.com) and related order processes.
If you are located in the European Economic Area (EEA) or United Kingdom, this policy also serves as our notice under the General Data Protection Regulation (GDPR) and the UK GDPR.
1. Who Is Responsible for Your Data
KADO Japan is the data controller responsible for the personal data described in this policy. For
privacy-related enquiries, contact us at:
privacy@kadojapan.com
2. What Personal Data We Collect
We collect the following categories of personal data when you use our store:
Data You Provide Directly
- Identity data: your first and last name
- Contact data: your email address and phone number
- Delivery data: your shipping address (street, city, postal code, country)
- Payment data: billing address and payment card information — note that full card details are processed and stored solely by our payment processor (Shopify Payments / Stripe) and are never stored on KADO Japan's systems
- Account data: if you create an account, your password (stored in hashed form) and order history
- Communications data: the content of emails or messages you send to us
Data Collected Automatically
- Technical data: IP address, browser type and version, device type, operating system, referral URL
- Usage data: pages visited, time spent on pages, clicks, and browsing behaviour on our site
- Cookie data: see our cookie usage section below
3. How We Use Your Personal Data
We use your personal data only for the following purposes, and only where we have a lawful basis to do so:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Processing and fulfilling your order | Identity, contact, delivery, payment | Contract performance |
| Sending order confirmation, tracking, and delivery updates | Identity, contact | Contract performance |
| Handling returns, disputes, and customer support | Identity, contact, communications | Contract performance / Legitimate interest |
| Fraud prevention and security | Identity, technical, payment | Legitimate interest / Legal obligation |
| Complying with legal and tax obligations | Identity, delivery, payment | Legal obligation |
| Improving our website and store performance | Usage data, technical data | Legitimate interest |
| Sending marketing emails (newsletters, promotions) | Identity, contact | Consent (you may opt out at any time) |
We will never use your data for purposes other than those listed above without your explicit consent. We do not sell your personal data to any third party.
4. Third Parties Who Receive Your Data
To operate our store and fulfil your orders, we share your data with a limited number of trusted service providers:
- Shopify Inc. — Our e-commerce platform. Shopify stores and processes all transaction data on our behalf, including payment card information via Shopify Payments (powered by Stripe). Shopify is certified PCI DSS Level 1 compliant. Shopify's privacy policy is available at shopify.com/legal/privacy.
- Japan Post / International Carriers — Your name, delivery address, and phone number are provided to our shipping carrier(s) to fulfil and track your order. Depending on your destination country, Japan Post may hand off your parcel to a domestic carrier (e.g., Royal Mail, USPS, Australia Post).
- Analytics Providers — We may use tools such as Google Analytics to understand how visitors use our site. These tools collect anonymised usage data (page views, session duration, device type) and do not receive your name, email, or order details. You may opt out of Google Analytics tracking at tools.google.com/dlpage/gaoptout.
- Email Service Providers — We use a third-party email service to send transactional emails (order confirmations, shipping updates) and, where you have consented, marketing emails. These providers process your email address and name on our behalf.
- Legal and Regulatory Authorities — We may disclose your data to law enforcement, customs authorities, tax authorities, or courts where required by law or to protect our legal rights.
We do not share your data with advertisers for targeted advertising purposes without your explicit consent. We do not use your data to build profiles for sale to data brokers.
5. International Data Transfers
KADO Japan operates from Japan. When you place an order, your data is processed and stored by Shopify's servers, which may be located in the United States or other countries. Shopify implements appropriate safeguards for international transfers, including Standard Contractual Clauses approved by the European Commission, to ensure your data is protected to GDPR standards.
By using our store, you acknowledge that your data may be transferred to and processed in countries outside your own, including Japan and the United States.
6. Cookies
Our website uses cookies — small text files stored on your device — to operate the store, remember your cart, and understand how our site is used. Cookies we use include:
- Strictly necessary cookies: Required for the store to function (shopping cart, login session, checkout). These cannot be disabled.
- Preference cookies: Remember your settings (e.g., currency or language preferences).
- Analytics cookies: Collect anonymous data about how visitors use our site. You may opt out via your browser settings or the analytics opt-out tools listed above.
Most web browsers allow you to control cookie behaviour through your browser settings. Disabling necessary cookies may prevent you from completing a purchase.
7. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes described in this policy:
- Order and transaction records are retained for 7 years to comply with Japanese tax and accounting law.
- Customer account data is retained for as long as your account is active, or until you request deletion.
- Marketing preferences are retained until you unsubscribe or request deletion.
- Support correspondence is retained for up to 3 years after the matter is resolved.
8. Your Rights
Depending on where you live, you may have the following rights regarding your personal data. Customers in the European Economic Area (EEA) and United Kingdom have these rights under the GDPR and UK GDPR. We aim to honour equivalent rights for all customers worldwide as far as reasonably practicable.
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): You may request deletion of your personal data, subject to legal retention obligations (e.g., we must retain transaction records for tax purposes).
- Right to restrict processing: You may ask us to stop actively using your data while a dispute is resolved.
- Right to data portability: You may request your data in a structured, commonly used, machine-readable format.
- Right to object: You may object to our use of your data for direct marketing or where we rely on legitimate interests as our legal basis.
- Right to withdraw consent: Where we rely on your consent (e.g., for marketing emails), you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at privacy@kadojapan.com with the subject line "Data Request — [your right]". We will respond within 30 days. We may need to verify your identity before processing your request.
If you are located in the EEA or UK and believe we have not handled your data lawfully, you have the right to lodge a complaint with your national data protection supervisory authority.
9. Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or alteration. Payment data is handled exclusively through Shopify's PCI DSS Level 1 compliant infrastructure — we never see or store your full card number. Nonetheless, no data transmission over the internet is 100% secure. You use our site at your own risk and should take steps to keep your account credentials secure.
10. Children's Privacy
Our store is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data without parental consent, please contact us at privacy@kadojapan.com and we will delete that data promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The updated policy will be posted on this page with a revised "last updated" date. For material changes, we will notify you by email (if you have an account) or by a prominent notice on our website. Continued use of our site after changes are posted constitutes acceptance of the revised policy.
12. Contact Us
For any privacy-related questions, data requests, or concerns:
Email: privacy@kadojapan.com
Response time: Within 30 days of receipt