Privacy Policy
Effective date: August 18, 2026
This English version is provided for reference only. The Japanese version is the official text, and it shall prevail in the event of any discrepancy between the two.
GreatHack, Inc. (the "Company") recognizes that protecting personal information is a social responsibility of any business. The Company complies with the Act on the Protection of Personal Information and other related laws and regulations, and establishes this Privacy Policy to handle personal information appropriately.
Article 1 (Information about the Company)
This Policy sets forth how personal information is handled in "Shinome" (the "Service") provided by GreatHack, Inc. (the "Company"). The Company is responsible for the handling of personal information.
Article 2 (Personal Information We Collect)
In providing the Service, the Company collects the following information.
- Information required for applications and account issuance, such as organization name, name, email address, and telephone number
- Information that Users enter and register in the Service, such as supporter lists, income and expenditure records, and post content
- Information recorded automatically through use of the Service, such as access timestamps, operation history, and IP addresses
Article 3 (Purposes of Use)
The Company uses the personal information it collects within the scope of the following purposes. If the Company uses information beyond these purposes, it will obtain the consent of the individual in advance.
- To provide and maintain the Service and to authenticate and manage Users
- To confirm application details, issue accounts, and contact Users
- To respond to inquiries, consultations, and implementation and operational support
- To invoice fees and confirm payment
- To improve the quality of the Service, investigate defects, and consider new features
- To respond to acts that violate the Terms of Service
Article 4 (Third Parties' Personal Information Registered by Users)
With respect to the personal information of supporters and association members registered by Users in the Service, the Company acts as an entrusted party for the handling of that information. The Company handles such information only within the scope of the User's instructions and does not use it for the Company's own purposes. Notifying the individuals concerned and obtaining their consent when collecting such personal information is the responsibility of the User.
Article 5 (Provision to Third Parties)
Except in any of the following cases, the Company does not provide personal information to third parties without obtaining the prior consent of the individual.
- Where required by laws and regulations
- Where necessary to protect the life, body, or property of a person and it is difficult to obtain the consent of the individual
- Where cooperation is necessary for a national government body, a local government, or a party entrusted by either, to carry out affairs prescribed by law, and obtaining the consent of the individual is likely to impede the performance of those affairs
Article 6 (Subcontracting)
The Company may subcontract all or part of the handling of personal information to external parties within the scope necessary to achieve the purposes of use. In such cases, the Company appropriately assesses the subcontractor, requires proper management of personal information in the subcontracting agreement, and exercises necessary and appropriate supervision.
Article 7 (Security Control Measures)
The Company implements the following measures to prevent leakage, loss, or damage of personal information and to otherwise ensure its secure management.
- Data is logically separated for each office (tenant) so that data belonging to another office cannot be accessed.
- Credentials such as social media integration information are encrypted with AES-256-GCM before being stored.
- Passwords are not stored in plain text; they are hashed with PBKDF2-SHA256.
- Access to administrative screens that handle personal information is limited to authorized personnel of the Company.
- Communications are encrypted with TLS.
Article 8 (Retention Period)
The Company retains personal information only for the period necessary to achieve the purposes of use. Even after an agreement ends, the Company may continue to retain information to the extent necessary where a retention obligation exists under law or where retention is necessary for dispute resolution.
Article 9 (Requests for Disclosure, Correction, and Suspension of Use)
If an individual requests disclosure, correction, addition or deletion of content, suspension of use, erasure, or suspension of provision to third parties of personal information (collectively, "Disclosure and Other Requests"), the Company will verify the identity of the individual and respond without delay in accordance with applicable law. Please direct Disclosure and Other Requests to the contact point in Article 11.
Article 10 (Handling of Cookies)
The Service uses cookies to maintain login state. These cookies are necessary for providing the Service, and the Company does not provide them to third parties for advertising delivery or behavioral tracking.
Article 11 (Contact Point)
For inquiries about this Policy and for Disclosure and Other Requests regarding personal information, please contact: s.tanaka@great-hack.com
Article 12 (Changes to this Policy)
The Company may amend this Policy in response to changes in laws and regulations or changes to the content of the Service. The amended Policy takes effect when it is posted on this website.
End of document