Privacy Policy
Newelse, Inc. ("we," "us," or "our") operates the Kicks Pass mobile application (the "App"). This Privacy Policy explains how we collect, use, and protect your information when you use the App.
1. Information We Collect
1.1 Information You Provide
- Account Information: The App does not require account registration. An anonymous user ID is automatically generated upon first use.
- Preferences: Shoe size, preferred brands, monitored sites, and notification settings you configure within the App.
1.2 Information Collected Automatically
- Device Information: Device model, operating system version, language settings, and unique device identifiers (for push notification delivery only).
- Usage Data: App usage patterns, features accessed, notification interaction data, and session duration.
- Push Notification Tokens: Required for delivering restock alerts. Managed through Apple Push Notification Service (APNs) or Firebase Cloud Messaging (FCM).
1.3 Information We Do NOT Collect
- We do not collect your name, email address, phone number, or physical address.
- We do not collect payment or financial information (subscriptions are processed entirely through Apple's App Store or Google Play).
- We do not collect precise geolocation data.
- We do not track you across other apps or websites.
2. How We Use Your Information
We use the information we collect solely to:
- Deliver restock notifications based on your preferences.
- Improve the accuracy and speed of restock detection.
- Analyze aggregate usage patterns to improve the App (no individual tracking).
- Communicate service updates or changes.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. Third-Party Services and SDKs
The App uses the following third-party services and SDKs:
| Service | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|
| Firebase Authentication | Anonymous user ID generation | Anonymous user ID | Google Firebase |
| Firebase Cloud Messaging (FCM) | Push notification delivery | Device token, notification payload | Google Firebase |
| Firebase Analytics | Aggregate usage analytics (opt-out available in app settings) | Anonymous event data, app interactions | Google Firebase |
| Firebase App Check | Abuse prevention | Device integrity attestation | Google Firebase |
| RevenueCat | Subscription management & entitlement validation | Anonymous user ID, subscription status | RevenueCat |
| Apple App Store / Google Play | Subscription billing & payment processing | Payment data (handled entirely by Apple/Google) | Apple / Google |
| Google AdMob | Advertising (free tier only) | Advertising identifier, ad interaction data | Google AdMob |
These services may collect information as described in their respective privacy policies. We encourage you to review them.
3.1 Cookies and Tracking Technologies
The App itself does not use HTTP cookies. However, the SDKs listed above may use device-level identifiers (such as IDFA on iOS or AAID on Android), anonymous event logs, and similar technologies for analytics, crash reporting, and advertising. You can:
- Disable Firebase Analytics collection through the in-app Settings → Privacy → Analytics toggle.
- Limit ad tracking via iOS Settings → Privacy & Security → Tracking or Android Settings → Google → Ads.
4. Data Retention
- Preferences and settings are stored locally on your device and on our servers to enable cross-session functionality.
- Anonymous usage data is retained for up to 12 months and then deleted or anonymized.
- If you delete the App, your anonymous ID and locally stored data are permanently removed. Server-side data associated with your anonymous ID will be deleted within 30 days.
5. Data Security
We implement industry-standard security measures to protect your information, including:
- Encrypted data transmission (TLS/SSL).
- Secure server infrastructure (Google Cloud Platform).
- Access controls and authentication for administrative access.
- Regular security reviews.
However, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
5.1 Security Incident Notification
In the unlikely event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk to affected users, we will also notify users without undue delay through in-app notice, push notification, or other appropriate means.
6. Children's Privacy
The App is not directed to children under the age of 13 (or 16 for users in the EU/EEA under GDPR, or as required by applicable law in your jurisdiction). We do not knowingly collect information from children.
- United States (COPPA): We do not knowingly collect personal information from children under 13.
- EU/EEA (GDPR): We do not knowingly process personal data of children under 16 without verifiable parental consent.
- Japan (APPI): Use by minors should be supervised by a parent or guardian.
If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us at support@newelse.com and we will promptly delete the information.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Deletion ("Right to be forgotten"): Request deletion of your data.
- Restriction: Request that we restrict processing of your data.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Withdraw consent where processing is based on consent.
- Opt-Out: Disable analytics in the app, or push notifications in device settings.
7.1 How to Exercise Your Rights
To exercise any of these rights, please contact us by email at support@newelse.com with:
- A description of the right you wish to exercise.
- The anonymous user ID displayed in Settings → About → User ID (so we can locate your data).
- Any additional information needed to verify your request.
We will respond within 30 days of receiving a valid request (or 45 days where additional time is required and permitted by law).
7.2 For California Residents (CCPA / CPRA)
We do not sell or share personal information as defined under the CCPA/CPRA. You have the right to:
- Know what personal information we collect, use, disclose, and for what purposes.
- Request deletion of your personal information.
- Opt out of any future sale or sharing (we currently do not sell or share).
- Non-discrimination for exercising your rights.
7.3 For EU/EEA/UK Residents (GDPR / UK GDPR)
Legal bases for processing:
- Contract performance (Art. 6(1)(b)): Delivering the restock notification service you requested.
- Consent (Art. 6(1)(a)): Firebase Analytics, AdMob personalized advertising (where applicable).
- Legitimate interests (Art. 6(1)(f)): Service improvement, fraud prevention, App Check abuse prevention.
Supervisory authority: You have the right to lodge a complaint with your local data protection authority. A list of EU DPAs is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
7.4 For Japan Residents (APPI)
We handle personal information in accordance with the Act on the Protection of Personal Information (個人情報保護法). You may request disclosure, correction, suspension of use, or erasure of your retained personal data. Complaints may be submitted to the Personal Information Protection Commission (個人情報保護委員会).
8. International Data Transfers
Your information may be transferred to and processed in Japan and the United States, where our servers and third-party service providers are located. Where data is transferred outside the EU/EEA/UK, we rely on appropriate safeguards including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions where available (e.g., Japan has an EU adequacy decision).
- Additional technical and organizational measures (encryption in transit and at rest).
By using the App, you acknowledge these transfers.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted within the App or on our website. Your continued use of the App after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:
- Email: support@newelse.com
- Website: https://kicks-pass.web.app/privacy
- Company: Newelse, Inc., Tokyo, Japan
- Response time: We aim to respond to all privacy inquiries within 5 business days and fulfill formal rights requests within 30 days.