privacy policy

RestPass株式会社

RestPass Co., Ltd. (hereinafter referred to as “our company”) establishes a privacy policy (hereinafter referred to as “this policy”) as follows regarding the handling of personal information of users and facility providers (hereinafter collectively referred to as “users”) in the service “Restpass” (hereinafter referred to as “this service”) provided by our company.

Article 1 (Personal Information to be Collected)

In providing this service, we will obtain the following information by legal and fair means.

(1) User information: name, address, date of birth, gender, phone number, email address, etc.

(2) Settlement information: Settlement records (settlement date, amount, settlement status, receipt information, etc.), bank account information (for sales remittance to facility providers), etc. relating to purchases of passes (toilet use rights), etc. Note that card information, such as credit card numbers, is acquired and processed by a payment agency, and we do not directly hold it.

(3) Information on subscriptions (premium): billing metadata such as subscription status, product IDs, transaction identifiers, etc. relating to in-app purchases on the App Store or Google Play. Each store handles information on payment methods (card numbers, etc.), and we do not obtain it.

(4) Location information: User's current location information using the GPS function (for toilet search function)

(5) Health-related information (based on user input or cooperation):

a. Records related to defecation (shape [Bristol scale], color, amount, symptoms, memos, etc.)

b. Meal photos and meal records (including calories, nutrients, etc. estimated by AI)

U Medication registration details (name, classification, dosage, medication timing, etc.) and medication records

Daily aggregated values of number of steps, sleep time, and water intake obtained only with user permission through e-healthcare collaboration (iOS “health care” (HealthKit), etc.), and body weight entered by the user

Since this information is sensitive personal information or similar sensitive information, it is obtained only based on consent by the user himself/herself entering it within the application or by permitting cooperation, and is handled in accordance with the special rules stipulated in section 3.

(6) Usage history: Pass purchase date and time, usage facilities, evaluation/review details, log information

(7) Device information: IP address, device identifier, OS version, browser type, etc.

Article 2 (Purpose of Use)

We use collected personal information for the following purposes.

(1) To provide, maintain, protect, and improve this service

(2) For user identity verification, authentication, and calculation and billing of usage fees

(3) For matching and use contract brokerage between users and facility providers

(4) To display and aggregate health records (intestinal activity scores, etc.), provide weekly AI reports, menu suggestions, and other health record functions

(5) To manage subscription status and provide benefits

(6) To respond to information, inquiries, etc. relating to this service

(7) To respond to acts that violate the terms of use of this service and to prevent unauthorized use

(8) For factual confirmation and communication based on reports of equipment damage, contamination, etc. from facility providers

(9) For the preparation of statistical data processed into a format that cannot identify individuals and for marketing analysis (information on health is stipulated in Article 3)

Article 3 (Special Provisions for Health-Related Information)

1. Notwithstanding the provisions of the preceding article, we will use health information only within the scope of the following purposes.

(1) For display and aggregation of records (intestinal activity scores, etc.)

(2) To generate weekly AI reports and menu recipe suggestions

(3) To improve the quality of the health record function and investigate the cause of the problem

2. Health information can only be viewed by the user himself/herself. Information on personal health cannot be viewed from management screens for facility providers and our facility management and sales personnel.

3. We do not use health information for advertising or marketing purposes. Information obtained from HealthKit is not used for advertising or sold to third parties.

4. We do not provide health information to third parties without the consent of the individual, except when required by law. Notwithstanding the provisions of Article 6 (5), health information will not be provided to facility providers due to claims for damages, etc.

5. GPS location information is not added to health information such as defecation records.

Article 4 (AI analysis)

1. We use the basic model service “Amazon Bedrock” provided by Amazon Web Services to analyze meal photos (estimation of calories and nutrients) and generate weekly AI reports and menu suggestions (including outsourcing the handling of personal data).

2. The AI processing described in the previous section is completed in regions within Japan, and the data transmitted for analysis is not used to learn the basic AI model.

3. AI estimates and reports are intended to provide reference information to assist users in managing their own health, and do not replace medical diagnosis, treatment, or prevention (details are specified in the Terms of Use).

Article 5 (Handling of Subscription and Billing Information)

1. Premium (subscription) payments are made through in-app purchases on the App Store (Apple) or Google Play (Google), and we do not obtain credit card numbers, etc.

2. In order to manage subscription status, we use a subscription management service (RevenueCat, Inc.) to handle billing metadata such as subscription status, product IDs, and transaction identifiers.

3. Health information will not be provided to each store or billing management business/payment agency.

Article 6 (Provision to Third Parties)

We will not provide personal information to third parties without obtaining the user's consent in advance, except in the following cases.

(1) When required by law

(2) When it is necessary to protect a person's life, body, or property, and it is difficult to obtain the consent of the person

(3) When it is particularly necessary to improve public health or promote the healthy development of children, and it is difficult to obtain the consent of the individual

(4) When it is necessary for a national agency or local public body or a person entrusted by it to cooperate in carrying out the affairs stipulated by law, and there is a risk that obtaining the consent of the person concerned will interfere with the execution of the affairs

(5) Provision for damages claims, etc.: When a user damages or soils the facility provider's equipment, and the facility provider needs it to claim damages or exercise other rights, it is necessary for the protection of property, and it is difficult to obtain the consent of the person concerned, information such as the user's name and contact information may be provided to the facility provider to the minimum extent necessary. Even in this case, no health-related information is provided.

Article 7 (Outsourcing and Use of External Services)

1. We may outsource all or part of the handling of personal information or use external services to the extent necessary to achieve the purpose of use. The main contractors and external services are as follows.

・Payment agency: Square (card payment), DEGICA Co., Ltd. (KOMOJU code payment)

・Subscription Management: RevenueCat, Inc.

・Authentication and usage analysis: Google LLC (Firebase)

・Cloud infrastructure (data storage/processing/email transmission) and AI analysis: Amazon Web Services (Tokyo region)

・Bug monitoring: Functional Software, Inc. (Sentry)

・Push Notifications/App Distribution: Expo

・Map display: Google LLC (Google Maps)

2. Contractors include businesses located in foreign countries such as the United States. In accordance with the Act on the Protection of Personal Information, we will confirm the personal data handling system of the relevant business and take necessary and appropriate measures for safe management. For information on the name of the country where the contractor is located and the personal information protection system in that country, please contact the inquiry desk.

3. The Company will request proper management of personal information from outsourcers and will carry out necessary and appropriate supervision.

Article 8 (Safety Management Measures)

In order to prevent leakage, loss, or damage of the personal information we handle and the safety management of other personal information, in addition to establishing basic policies, we take organizational, human, physical, and technical safety management measures (access control, authority management, encryption of communication and stored data, etc.), and also grasp the external environment when personal data is handled in a foreign country.

Article 9 (Handling of Location Information)

This service acquires location information in order to provide a search function for toilet facilities based on current location. Users can stop sending location information according to device settings, but in that case, some functions of this service may not be available.

Article 10 (Period of Retention and Deletion of Personal Information)

1. We hold personal information only for the period necessary to achieve the purpose of use.

2. Meal photos are automatically deleted after 1 year (365 days) from the date they were recorded. Recorded numerical data (estimated calories, nutrients, etc.) is retained even after photos are deleted. Health records, including photographs, can be deleted at any time by user action.

3. When a user cancels an account, health-related information (defecation records, food records (including photos), medication records, health care cooperation data, AI reports, etc.) is deleted, and other information that can identify individuals is also deleted. However, records (settlement records, etc.) based on accounting, tax, or other legal storage obligations may be processed into a form where individuals cannot be identified and then held for a period specified by law (as a general rule, 7 years).

Article 11 (Request for Disclosure, etc.)

Users can request the Company to notify, disclose, correct, add, delete, stop using, delete, or stop providing their personal information to a third party in accordance with the provisions of the Act on the Protection of Personal Information. When making a request, we will confirm your identity and respond without delay in accordance with laws and regulations. Requests will be accepted at the counter described in Section 14.

Article 12 (Use by Minors)

If a minor uses this service, please obtain the consent of a legal representative such as a parent or guardian before using this service. The same applies to the function for recording health-related information.

Article 13 (Changes to this Policy)

We may revise this policy in response to changes in laws and regulations or changes in service content. When important changes are made, they will be notified by posting on this service or by other appropriate methods.

Article 14 (Contact Information Desk)

For opinions, questions, complaints, and other inquiries regarding the handling of personal information (including requests for disclosure, etc.) regarding this policy, please contact the following office.

Osaka-shi Chuo-ku Doshomachi 4-1-1 Takeda Midosuji Building 2F

RestPass Co., Ltd.

Customer consultation desk

support@restpass.co.jp

Last revised: July 22, 2026