Effective: 2026-05-22 (v5 — External Transmission Rule compliance and GA4 deployment) / Previous: 2026-05-20 (v4)
SHIMOHA Inc. (“SHIMOHA”, “we”, “us”, “our”) provides this Privacy Policy (“Policy”) to explain how we collect, use, share, retain, and protect personal information through our website (https://www.shimoha.co.jp, “Site”), the cloud service, and the related client applications (Windows / iOS / Android) collectively provided by SHIMOHA (collectively, the “Service”). This Policy complies with Japan’s Act on the Protection of Personal Information (APPI) and is consistent with applicable foreign data protection laws including the GDPR, UK GDPR, and similar privacy laws where relevant.
1. Company Information
- Company: SHIMOHA Inc.
- Address: Kyoto, Japan
- Representative: Hiroya Shimohata
- Privacy Contact: privacy@shimoha.co.jp
2. Personal Information We Collect
2.1 Information collected via our Site
- Inquiry form: name, email, company, message body
- Comments: IP address, user-agent string, hashed email (for Gravatar)
- Site usage: cookies, access logs, referrer information
- Media uploads: EXIF metadata (including geolocation) if present
2.2 Information collected via the Service (cloud service)
From customers subscribing to the cloud portion of the Service through Microsoft Azure Marketplace, AWS Marketplace, or similar channels (“Subscribers”):
- Account information: subscriber name, email, company, organization tenant identifiers (e.g., Microsoft Entra ID), ZIP code, phone number
- Billing data: Marketplace subscription ID, metered usage, billing history (amount, period)
- Device metadata: IoT camera device identifiers, installation labels, firmware versions
- Image data: images and associated metadata uploaded from subscriber-owned camera devices
- Usage logs: API access history, dashboard operations, error logs
No payment information collection: SHIMOHA does not directly collect payment information (credit card numbers, bank account details) related to the Service. All payment processing is performed by the cloud marketplace operator selected by the Subscriber (Microsoft Azure Marketplace, AWS Marketplace, etc.) or by the app platform payment processor (Apple In-App Purchase, Google Play Billing, Stripe), and SHIMOHA only receives compensation through their settlement processes.
2.3 Camera Images and Personal Data
Images processed by the Service may contain identifiable elements (faces, license plates, etc.). The roles under APPI and GDPR are as follows:
- Subscriber: Data Controller. Responsible for legal basis, consent management, security, and responding to individual rights requests in their jurisdiction.
- SHIMOHA: Data Processor. Processes image data according to the Subscriber’s documented instructions.
No use for AI training: SHIMOHA does not use Subscriber image data for AI model training, dataset resale, product benchmarking, or any purpose unrelated to the provision of the Service, unless explicitly authorized in writing by the Subscriber. Statistical analysis of image metadata (timestamp, size, format, etc.) may be performed for service improvement and incident investigation, but individual image content is not the subject of such analysis.
2.4 Information collected via the client applications (Windows / iOS / Android)
From users of our desktop application (Windows) and mobile applications (iOS / Android) (collectively, the “App”):
- Device information: OS name and version, device model, App version, locale, time zone
- Local network information: hostnames, IP addresses, and mDNS records used to discover camera devices on the same local network (processed within the App; not transmitted to SHIMOHA servers)
- Account information: email address used to sign in (only when subscription features are used)
- Subscription identifiers: Apple ID-linked transaction ID (iOS), Google Play order ID (Android), Stripe customer ID (Windows)
- Crash and diagnostic data: anonymized stack traces and device metadata sent on unexpected App termination (may be transmitted to a crash analytics provider where applicable)
- Camera device integration data: configuration parameters, capture schedules, and firmware update history for camera devices paired through the App
No advertising identifiers: SHIMOHA does not collect or use iOS IDFA (Advertising Identifier), Android Advertising ID, or any other cross-site / cross-app tracking identifier. SHIMOHA does not display the iOS App Tracking Transparency consent prompt.
2.5 Permissions requested by the App
| Permission | Platform | Purpose | Required / Optional |
|---|---|---|---|
| Local network | iOS / macOS / Android / Windows | Discover camera devices on the local network (mDNS) | Required |
| Camera | iOS / Android | QR code scanning during initial setup (not the camera device’s own image capture function) | Optional |
| Storage / Photo library | iOS / Android / Windows | Locally store and view downloaded images | Optional |
| Notifications | iOS / Android / Windows | Camera anomaly and subscription status notifications | Optional |
Each permission may be revoked at any time from the OS settings on the device. Revoking a permission may disable the corresponding feature.
3. Purposes of Use
3.1 General purposes
- Operating, maintaining, and improving the Site and the Service
- Analytics for feature improvement and new feature development (individual image content excluded)
- Customer inquiries and support
- Important notices (maintenance, incidents, terms updates)
- Billing and integration with Microsoft Azure Marketplace and AWS Marketplace
- Fraud prevention, security monitoring
- Legal compliance
3.2 Restrictions on Subscriber Information from Marketplaces
For “Subscriber Information” (data and information concerning Subscribers, Transactions, and use of the Service) obtained through AWS Marketplace, SHIMOHA will use such information only for the following purposes, in compliance with applicable AWS Marketplace terms regarding Subscriber Information:
- Providing support for the Service
- Facilitating the delivery of the Service
- Computation of SHIMOHA’s internal sales metrics
Any use outside these purposes is subject to prior written agreement with the Subscriber.
3.3 Legal Basis for Processing (GDPR / UK GDPR and similar laws)
For personal data of individuals located in the EU/EEA, the United Kingdom, or other jurisdictions where similar privacy laws apply, SHIMOHA processes personal data based on one or more of the following legal bases, whichever is applicable:
- Performance of a contract: to deliver the Service under the subscription agreement.
- Compliance with legal obligations: tax recordkeeping, responses to lawful authority requests, etc.
- Legitimate interests: fraud prevention, security operations, service improvement analytics, provided such interests do not override the rights and freedoms of data subjects.
- Consent: where consent is required by law (e.g., marketing communications, non-essential cookies).
4. Sharing and Sub-processors
4.1 Third-party disclosure
We do not share personal information with third parties without the data subject’s consent, except as required by law, to protect life, health, or property, for public health, or for cooperation with government agencies.
4.2 Sub-processors
We engage the following sub-processors to operate the Service. Each is contractually obligated to implement appropriate security measures:
| Sub-processor | Role | Location | Privacy Notice |
|---|---|---|---|
| Microsoft Corporation (Microsoft Azure / Microsoft Azure Marketplace) |
Cloud infrastructure, image storage, authentication, Marketplace billing | United States and region selected by Subscriber | Microsoft Privacy Statement |
| Amazon Web Services, Inc. (AWS / AWS Marketplace) |
Cloud infrastructure, image storage, Marketplace billing, payment processing | United States and region selected by Subscriber | AWS Privacy Notice |
| Stripe, Inc. | Subscription payment processing for the Windows App | United States and global | Stripe Privacy Policy |
| Apple Inc. | App Store In-App Purchase billing for the iOS App | United States and Subscriber region | Apple Privacy Policy |
| Google LLC | Google Play Billing for the Android App | United States and Subscriber region | Google Privacy Policy |
| Email, analytics, crash reporting, and support tool providers | Operational support and anomaly analysis | May include locations outside Japan | Provider-specific privacy policies |
The geographical region where Service data resides (AWS / Azure physical location) is selected by the Subscriber at the time of subscription and is visible from the Service dashboard.
4.3 Data Processing Agreement (DPA)
SHIMOHA may provide a Data Processing Agreement (DPA) upon request for enterprise customers. The DPA covers processor obligations under GDPR Article 28 and other applicable laws, sub-processor management, data subject rights handling, and international transfer safeguards. To request a DPA, contact privacy@shimoha.co.jp.
5. International Data Transfers
The Service operates on Microsoft Azure and AWS infrastructure that may reside in Japan or in another country (US, EU, etc.) depending on the region the Subscriber selects. SHIMOHA implements appropriate safeguards as required by APPI Article 28 for cross-border transfers.
For personal data of individuals subject to GDPR, UK GDPR, or similar applicable privacy laws, SHIMOHA uses Standard Contractual Clauses or equivalent mechanisms to ensure an adequate level of protection.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Site comments | Indefinite (for moderation) |
| Inquiry messages | 3 years |
| Service account information | Duration of subscription + 3 years |
| Image data | Duration of subscription + 30 days (backups up to 90 days) |
| Usage and API logs | 1 year (up to 3 years for investigation) |
| Billing records | 7 years (statutory requirement) |
7. Security Measures
7.1 Organizational
- Designated privacy contact and internal owner
- Documented policies, periodic reviews
- Need-to-know access scoping
- Sub-processor selection and oversight
7.2 Personnel
- Training and awareness programs
- Contractual confidentiality obligations
- Access deprovisioning upon departure
7.3 Physical
- Access control to work areas, locked storage
- Anti-theft / anti-loss controls for devices and media
- Secure disposal of media and documents
7.4 Technical
- Encryption in transit (HTTPS / TLS 1.2+)
- Encryption at rest
- Role-based access control (RBAC) and least-privilege access principles
- Multi-factor authentication (MFA) for administrative accounts
- Audit logging – collection, retention, and periodic review
- Encrypted, protected backups and tested recovery procedures
- Vulnerability management (dependency updates, periodic scanning)
- Network segmentation, firewalls, and intrusion detection
7.5 External Environment
- Continuous awareness of data-protection regimes in sub-processor jurisdictions (Microsoft Azure, AWS, etc.)
8. Your Rights – Access, Correction, Deletion
Data subjects (or their representatives) may request access, correction, addition, deletion, suspension of use, or suspension of third-party sharing of their personal information.
- Submit the request via the channel below.
- Contact: privacy@shimoha.co.jp
- We respond within 30 days of receipt as a general rule.
- We may request a copy of identification to verify the requester.
- Data we are legally required to retain may be exempt from deletion.
Service Subscribers can self-serve via the Service dashboard to view account information and export or delete image data.
9. Cookies and Disclosures under the External Transmission Rule
9.1 Use of Cookies on the Site
The Site uses cookies for the following purposes:
- Essential cookies: login session, basic site functionality.
- Functional cookies: comment form data (opt-in).
- Analytics cookies: aggregate site analytics (any tool introduced will be listed in the table at §9.2).
9.2 Disclosures under the External Transmission Rule (Japan Telecommunications Business Act, Article 27-12)
For Site operation and improvement, the following information may be transmitted from a user’s device to the external service providers listed below. Users may stop such transmissions by using the opt-out mechanism provided by each recipient or by disabling cookies in their browser. Disabling these transmissions may cause certain Site features to become unavailable.
| Recipient (Entity) | Information Transmitted | Purpose of Use | Privacy Policy / Opt-out |
|---|---|---|---|
| Automattic Inc. (Gravatar) | Hashed email address, IP address, and user-agent string at the time of comment submission | Display of the commenter’s avatar image | Automattic Privacy Policy |
| Google LLC (Google Analytics 4) | IP address (truncated upon collection), cookie ID, page URL viewed, referrer, browser and device information, interaction event data (page transitions, scrolls, clicks, etc.) | Web analytics, understanding of site usage, and analysis for site improvement | Google Privacy Policy / GA Opt-out Browser Add-on |
Note (integrations outside the scope of the External Transmission Rule): The following integrations operate entirely server-side and do not transmit information directly from the user’s device, and are therefore not listed in the table above:
- Google Search Console: SHIMOHA receives aggregated search-query, impression, and click data collected by Google’s search engine via API.
- Microsoft Bing Webmaster Tools: SHIMOHA receives aggregated search-performance data collected by Bing’s search engine.
- Site Kit by Google: a WordPress plugin that connects the above Google services to SHIMOHA’s WordPress dashboard via OAuth (server-to-server communication, not involving the visitor’s browser).
Future additions: When SHIMOHA introduces additional tools such as heatmap analytics (e.g., Microsoft Clarity), advertising measurement tags, or other analytics or marketing technologies, this table will be updated so that the information remains readily accessible to users.
9.3 Cookies set by Third-Party Embedded Content
Embedded content (videos, social media, etc.) may set cookies that are governed by the privacy policies of the respective third parties. You may disable cookies via your browser, though some Site features may not function.
9.4 Access from the EU/EEA, the United Kingdom, and other Consent-Required Jurisdictions
For visitors from the EU/EEA, the United Kingdom, or other jurisdictions where prior consent is required by law, SHIMOHA may obtain prior consent before the use of non-essential cookies.
10. Incident Response
In the event of a personal data breach or suspected breach affecting the Service, we will:
- Investigate the incident without undue delay
- Notify affected Subscribers without undue delay
- Report to the Personal Information Protection Commission of Japan and other supervisory authorities as required
- Report to relevant marketplace operators (Microsoft, AWS, etc.) as contractually required
- Implement corrective and preventive measures
11. Minors
The Service and the App are designed for business use (B2B) and are not directed at individuals under 13. SHIMOHA does not knowingly collect personal information from individuals under 13. Age ratings on the Apple App Store and Google Play are planned as “4+ / Everyone”, but the intended actual users are adult business users. Minors using the Service or the App should obtain parental or guardian consent.
12. Changes to This Policy
We may revise this Policy due to changes in laws, services, or other circumstances. Material changes will be announced in advance via the Site or by email to Subscribers. Revisions take effect upon publication on the Site.
13. App Uninstallation and Local Data Removal
When the App is uninstalled from a device, locally stored cache, settings, and downloaded images are removed in accordance with the OS’s standard behavior. To request deletion of Subscriber account information and image data retained on the server, please submit a request as described in §8.
14. Contact
SHIMOHA Inc.Privacy Contact
Email: privacy@shimoha.co.jp
Web: https://www.shimoha.co.jp/inquire/
Effective: 2026-05-22 (v5 — External Transmission Rule (Japan Telecommunications Business Act, Article 27-12) disclosures added; Google Analytics 4 and Site Kit by Google listed as service providers)
Previous: 2026-05-20 (v4 — Generic SaaS notation, client application scope expanded / AWS / Azure Marketplace dual-coverage / Windows / iOS / Android App coverage)

