Cascade Inc. Privacy Policy
(Enacted February 5, 2025 / Last revised July 17, 2026)
Cascade Inc. (hereinafter the "Company") handles personal information and other information relating to users as set forth below, in connection with its provision of the AI marketing platform "Cascade" and its marketing consulting services (hereinafter collectively the "Service"), in accordance with the Act on the Protection of Personal Information (hereinafter the "APPI") and other applicable laws, regulations, and guidelines.
Article 1 Basic Policy
When the Company asks a Customer to provide personal information, it will specify the purpose of use in advance. Personal information provided by the Customer will be used only within the scope of the specified purpose of use. The Company will not use personal information for any purpose other than the specified purpose of use without the Customer's consent. In addition, the Company will not use information of end users (as defined in Article 2) that it handles on behalf of the Customer beyond the scope of the Customer's instructions.
Article 2 Definitions
In this Policy, the following terms have the meanings set forth below.
2. "End User" means a customer or prospective customer of the Customer, or any other person who is a target of the Customer's marketing activities.
3. "Integration Data" means data that the Company obtains from ad platforms, analytics tools, e-commerce platforms, CRMs, and other third-party services for which the Customer has authorized integration with the Company.
4. "Google User Data" means, among the Integration Data, data that is associated with a Google user account or a Google service.
5. "End User Data" means information relating to end users that the Company handles on behalf of the Customer through the measurement and integration functions of the Service.
Article 3 Information Collected and Methods of Collection
1. Information relating to the Customer
a. Information obtained directly from the Customer: name, company name, department and job title, contact details, billing and payment information, survey responses, inquiry details, and other information specified by the Company at the time of acquisition
b. Information obtained automatically: IP address, device information, browser type, date and time of access, pages viewed, operation logs, etc.
2. Integration Data: obtained from third-party services such as the following, to the extent that the Customer has authorized the integration.
- Ad platforms (Google, Meta (Facebook and Instagram), LINE Yahoo! (Yahoo! JAPAN Ads), TikTok, Microsoft, LinkedIn, Amazon, Apple, X, Pinterest, Snapchat, SmartNews, Reddit, OpenAI, etc.): advertising account information, campaign and ad settings and performance data, conversion data, etc.
- Analytics tools (Google Analytics 4, Google Search Console, etc.): site analytics data, search performance data, etc.
- E-commerce platforms and payment services (as set forth in Article 13): data on orders, products, sales, inventory, etc.
- CRM and sales support tools (as set forth in Article 14): deal and customer management data, etc.
3. End User Data: obtained by the following methods, based on the Customer's instructions.
a. Information obtained through the Company's measurement tags installed on the Customer's website and other properties: browser-level visitor identifiers issued by the Company, ad click identifiers (gclid, fbclid, etc.), URL parameters (utm, etc.), referrers, pages viewed, IP addresses, browser and device information, interaction events, etc.
b. Information obtained through the Customer's entry into forms or through integrated services (e-commerce, CRM, etc.): name, company name, email address, telephone number, inquiry and application details, purchase and deal history, etc.
Article 4 Purposes of Use
1. The Company uses the personal information and integration data (including Google user data) that it has acquired for the following purposes. The Company will not use such information beyond these purposes.
2. End User Data is handled only within the scope necessary to provide the functions used by the Customer (the scope of the Customer's instructions) among the purposes set forth in the preceding paragraph.
(1) Provision of the Service, identity verification, and billing and payment processing
(2) Support, incident investigation, and security measures
(3) Information about seminars, campaigns, and the like
(4) Improvement of the Service and enhancement of the quality of AI-based analysis, recommendation, and generation functions
(5) Creation and display of analytics reports, dashboards, and the like provided as functions of the Service
(6) Creation of customer lists for configuring ad targeting (including exclusion from delivery, delivery to returning visitors, and delivery to lookalike audiences) and the matching of such lists with ad platforms (Article 6)
(7) Transmission of conversion information to ad platforms for the purpose of measuring advertising effectiveness (Article 6)
(8) Detection of fraudulent clicks, applications, and the like, configuration of exclusions from ad delivery, and other anti-fraud measures
Article 5 Handling of End User Data (Entrustment by the Customer)
1. The Company handles end user data in accordance with the Customer's instructions, as a party entrusted by the Customer with the handling of personal data. The Customer shall be responsible, at its own risk, for specifying the purpose of use in connection with the acquisition and use of end user data, for giving notice or making a public announcement, for obtaining consent, and for performing other obligations under the APPI.
2. The Company provides sample descriptions (such as model privacy policy language) on its help pages and elsewhere for the Customer's reference in performing these obligations. When the functions described in Article 6 are enabled, the Company will ask the Customer to confirm its compliance status, and the Company will retain a record thereof.
3. Requests from end users themselves for disclosure, correction, suspension of use, or the like will, as a general rule, be handled through the Customer with which the relevant end user has a relationship. If the Company receives such a request directly, it will refer the end user to the relevant Customer or respond in accordance with the Customer's instructions.
Article 6 Data Integration with Ad Platforms (Matching of Customer Lists and Transmission of Conversion Information)
1. Synchronization of customer lists: If the Customer enables this function, the Company will, in accordance with the Customer's instructions, convert end users' email addresses, telephone numbers, and similar information into hash values (SHA-256) from which the original strings are difficult to restore, and will then transmit those hash values to the ad platform operators listed below. The transmitted hash values are used solely for configuring the targeting of the Customer's advertising (including exclusion from delivery, delivery to returning visitors, and delivery to lookalike audiences) through matching against each platform's member information.
2. Email addresses and telephone numbers are never transmitted to ad platforms in their original form. Ad platforms do not identify individuals from the matching results and disclose them to the Company or the Customer, and use for purposes other than the stated purposes is restricted under the terms of each platform.
3. Transmission of conversion information: If the Customer enables this function, the Company will transmit conversion information, such as ad click identifiers, hashed email addresses, and transaction amounts, currencies, and dates and times, to ad platform operators (Google LLC, Meta Platforms, Inc., Microsoft Corporation, etc.) for the purpose of measuring advertising effectiveness.
4. The data integrations described in the preceding paragraphs are carried out as the handling of personal data based on the Customer's entrustment and instructions (Article 5). Notification to end users (such as descriptions in the Customer's privacy policy) and securing the necessary consent or other legal basis shall be carried out by the Customer. The Company will ask the Customer to confirm this when the relevant function is enabled.
5. The Company retains management data such as the hash values necessary for managing incremental synchronization, and erases such data without delay when the corresponding customer list is deleted.
Examples of recipients: Google LLC, Meta Platforms, Inc., LY Corporation, TikTok Pte. Ltd., Microsoft Corporation, LinkedIn Corporation
Article 7 Provision to Third Parties
The Company will not provide personal data to third parties except in the following cases. The data integrations under Article 6 are carried out as handling based on the Customer's entrustment.
(1) Where the individual has consented
(2) Where the information has been processed into statistical information in a form that cannot identify individuals
(3) Where required by laws and regulations
(4) Where, in connection with a business succession, notice has been given by a reasonable method or individual notice has been given
(5) Where personal information is provided to a third party in a foreign country (where the Company provides personal information to a third party in a foreign country, it will provide information regarding the personal information protection regime of the destination country and the protective measures taken by the recipient, and will obtain the Customer's consent in advance.)
Article 8 Security Control Measures
In order to prevent the leakage, loss, or damage of personal data and otherwise ensure its secure management, the Company takes the following measures with reference to the control standards of ISO 27001 and SOC 2 Type II.
Details of the security control measures will be provided without delay in accordance with laws and regulations, in response to an inquiry made to the point of contact set forth in Article 18.
(1) Organizational security control measures: appointment of a person responsible for handling, and establishment of a framework for ascertaining and inspecting the status of handling
(2) Human security control measures: regular training for employees and pledges regarding confidentiality
(3) Physical and technical security control measures: minimization and management of access privileges, encryption of communications and stored data (in transit and at rest), logging and auditing, and measures against unauthorized access
Article 9 Cookies, Measurement Tags, and the Like
1. The Company's website may use cookies and similar technologies that identify the Customer's browser in order to improve convenience. Receipt of cookies can be declined through browser settings; in that case, however, some functions of the website may become unavailable.
2. The Service's measurement tags are installed on the Customer's website and other properties, and the information described in Article 3, Paragraph 3(a) is transmitted to the Company from end users' devices. Explanations to end users in connection with the installation of the tags (including compliance with the external transmission rules under the Telecommunications Business Act) shall be provided by the Customer on the Customer's website.
3. Where the Company's website uses a tool that transmits information from a user's device to an external operator, the Company will publish on its website the name of that operator, the information transmitted, and the purpose of use.
Article 10 Protection of Personal Information at Linked Sites
The Company's website may contain links to third-party websites. The Company is not responsible for the handling of personal information at such linked sites. Please review the privacy policy of each linked site before using it.
Article 11 Retention Period and Deletion of Personal Information and Integration Data
1. The Company retains the personal information, integration data (including Google user data), and end user data that it has acquired only for such period as is necessary for purposes such as providing the Service, billing and payment, support, and compliance with laws and regulations.
2. Information that is required by laws and regulations to be retained for a certain period will be retained for the period prescribed by such laws and regulations.
3. Raw data such as the ad click identifiers used to determine advertising attribution is automatically deleted approximately 90 days after acquisition. Data such as the hash values used to manage the synchronization of customer lists is erased when the corresponding customer list is deleted (Article 6, Paragraph 5).
4. Information for which the retention period described above has elapsed and which has reasonably become unnecessary will be deleted or anonymized without delay by secure means.
5. If the Customer wishes to terminate the Service or delete its account, or wishes to have its data, including Google user data, deleted, please contact the point of contact set forth in Article 18. Except for information that the Company is required by law to retain, the Company will delete or anonymize such data within a reasonable period.
Article 12 Use of the Google APIs and Disclosures Regarding Google User Data
1. In providing the Service, the Company uses APIs provided by Google (including Google Ads, Google Analytics 4, Google Search Console, Google Data Manager, and other Google services) and accesses Google user data to the extent that the Customer has expressly authorized the integration with the Company.
2. The processing that the Company performs through the Google APIs includes, in addition to the acquisition and analysis of advertising data and the preparation of reports, the creation and modification of ads in the Customer's own Google Ads account, the upload of customer lists (Article 6, Paragraph 1), and the transmission of conversion information (Article 6, Paragraph 3), in each case based on the Customer's instructions.
3. The purposes of use of Google user data are limited to the scope set forth in Article 4. The Company does not sell Google user data or provide it to third parties for advertising purposes.
4. The Company's use of information received from the Google APIs, and its transfer of such information to any other application, will adhere to the Google API Services User Data Policy (including the Limited Use requirements).
5. The Company will not provide Google user data to third parties, except where required by laws and regulations, where the Customer has consented, or in the cases set forth in Article 7 (Provision to Third Parties).
Article 13 Handling of Data in E-Commerce Platform Integrations
1. Shopify integration (Cascade Data Connector)
1. Through "Cascade Data Connector" (hereinafter the "App"), which the Company provides on the Shopify App Store, the Company accesses a merchant's store data (hereinafter "Shopify Data") via the Shopify Admin API, to the extent that the Shopify store owner (hereinafter the "Merchant") has expressly authorized the integration with the Company through OAuth.
2. The Shopify Data obtained by the App is limited to the scope authorized by the following OAuth scopes.
a. read_customers — customers' purchasing behavior data (in aggregated form)
b. read_orders — order IDs, products, amounts, shipping regions, dates and times, etc.
c. read_products — product IDs, titles, prices, SKUs, inventory, etc.
d. read_reports — aggregated reports of the Shopify store
e. read_returns — return IDs, reasons for return, amounts, etc.
In addition, customers' names, email addresses, telephone numbers, detailed addresses, and other personally identifiable information are not stored; only aggregated values are retained.
3. The purposes of use of Shopify Data are limited to the provision of the Service, analysis, service improvement, and security measures set forth in Article 4. The Company does not sell Shopify Data or provide it to third parties for advertising purposes.
4. Shopify Data is stored in cloud storage located in Japan, encrypted using AES-256-GCM, and protected in transit using TLS 1.3 or higher. The retention period is as set forth in Article 11; provided, however, that such data will be deleted within 30 days from the time the Merchant uninstalls the App or from the time the Company receives a request for deletion of data from the Merchant or its customers.
5. The Company supports the following mandatory compliance webhooks prescribed by Shopify, and verifies the signature of each of them using HMAC-SHA256.
a. customers/data_request — If the Company receives a request to access a customer's personal data, it will provide such data to the Merchant within 30 days.
b. customers/redact — If the Company receives a request to delete a customer's personal data, it will delete such data within 30 days.
c. shop/redact — If the Company receives a deletion request triggered 48 hours after a Merchant uninstalls the App, it will delete all data for that store within 30 days.
6. The Company will not provide Shopify Data to third parties, except where required by laws and regulations, where the Merchant has consented, or in the cases set forth in Article 7 (Provision to Third Parties).
7. Merchants and their customers have the right to access, rectify, and erase Shopify Data, the right to restrict its processing, and the right to data portability. To exercise these rights, please submit a request to the contact point set forth in Article 18.
2. Integrations with other e-commerce and sales channels
To the extent that the Customer has authorized the integration, the Company obtains data relating to orders, products, sales, inventory, and end users' purchasing behavior from e-commerce platforms and payment services such as BASE, Colorme Shop, Rakuten Ichiba, Yahoo! Shopping, Qoo10, SHOPLINE, Shopee, TikTok Shop, Amazon, and Stripe, and uses such data for the purposes set forth in Article 4 (integrated analysis of sales and advertising performance, preparation of reports, etc.). As a general rule, the Company retains such data in aggregated or statistical form, and retains personally identifiable information of end users only to the minimum extent necessary to provide the relevant functions. The handling of such data upon termination of the integration or upon the Customer's request for deletion is governed by Article 11.
Article 14 Handling of Data in Integrations with CRMs and Other External Services
1. To the extent that the Customer has authorized the integration, the Company obtains deal and customer management data (such as representatives, contact details, deal amounts, and stages) from CRM and sales support services (HubSpot, Salesforce, etc.) and uses such data for the purposes set forth in Article 4, including analysis of cost-effectiveness by matching the data against advertising performance and the preparation of reports. Personal data of end users contained in such data is handled in accordance with the framework set forth in Article 5 (Entrustment).
2. If the Customer configures a notification integration (Slack, Chatwork, Microsoft Teams, etc.), the Company will send reports and notifications to the destinations designated by the Customer.
3. With respect to integrations with mobile app measurement services (Adjust, etc.) and other analytics services as well, the Company obtains only data within the scope authorized by the Customer, and this Article applies mutatis mutandis.
Article 15 Requests for Disclosure and the Like of Retained Personal Data
1. A Customer or its agent may request notification of the purpose of use, disclosure, correction, addition, or deletion, and the suspension of use, erasure, or suspension of provision to third parties, with respect to the Company's retained personal data. Such requests are accepted at the point of contact set forth in Article 18.
2. When making a request, you may be asked to submit documents that verify your identity (or, in the case of a request made by an agent, the agent's authority). For requests for notification of the purpose of use and for disclosure, the Company may charge a fee equivalent to its actual costs, within the scope permitted by laws and regulations.
3. Responses to requests relating to End User Data are governed by Article 5, Paragraph 3.
Article 16 Compliance with Applicable Laws and Other Standards
The Company complies with the APPI and other applicable laws, regulations, and guidelines, and endeavors to establish an internal framework for the protection of personal information and to continuously review and improve it.
Article 17 Changes to this Privacy Policy
The Company may revise this Privacy Policy from time to time in response to changes in laws and regulations or changes in its business. Any revision will be promptly posted on the Company's website and will take effect on the date of posting. In the case of a material change, the Company will give advance notice by appropriate means.
Article 18 Business Operator Information and Contact Point
Name of business operator: Cascade Inc.
Address: Ami Hall, 1-1-3 Shibuya, Shibuya-ku, Tokyo, Japan
Representative: Representative Director & CEO Kazuki Miyauchi
Inquiries regarding this Privacy Policy and the Company's handling of personal information, as well as requests for disclosure and the like, are accepted through the contact form on this corporate website.
Version 5, revised July 17, 2026



