Privacy & security policy
How A-Charge (I-S3 Co., Ltd.) handles personal data, payments, and communications.
Where a contract requires formal notices, that contract and this page (latest version) prevail.
What we collect
- We generally do not register users' names, phone numbers, or email addresses.
- Card numbers are handled only on the payment provider's (e.g. Stripe) pages; A-Charge does not store them. We keep operational records such as payment IDs, usage time, amounts, and bay IDs.
- Queues use anonymous digital tickets with no identity registration.
- Location is used only for an arrival radius check and is not stored.
Security measures
- HTTPS (TLS), plus HSTS, X-Content-Type-Options, Referrer-Policy and related headers.
- API and encryption keys are managed in Google Cloud Secret Manager.
- Sensitive owner fields such as bank account numbers are encrypted at the application layer before storage.
- Admin tools are limited to authenticated users on our corporate domain (i-s3.com).
- Cookies use Secure / HttpOnly / SameSite as appropriate.
Optional cameras
- Images may be captured for bay occupancy. Retention is limited (typically 24 hours; representative images up to about 30 days) with automatic deletion.
- Where plates are processed, site signage and terms apply. Image analysis may use external AI (e.g. Google Vertex AI).
Contact
Privacy inquiries: I-S3 Co., Ltd. · Mail: s_masuda@i-s3.com · TEL: +81-27-384-4646
Legal Notice (Specified Commercial Transactions Act)