Legal
Privacy Policy
Effective date: May 19, 2026 · Last updated: June 27, 2026
This Privacy Policy describes how TheCapybaraCompany (Corporate Registry Number: 1200-03-031084; the “Business Operator,” “CapyClimb,” “we,” “us,” or “our”), located at B1, 5-61-4 Nakano, Nakano-ku, Tokyo 164-0001, Japan, collects, uses, shares, and protects the personal information of users of the CapyClimb mobile application (the “App”) and visitors to our climbing gym(s) (the “Gym”).
We handle personal information in accordance with Japan’s Act on the Protection of Personal Information (“APPI”), the amended Telecommunications Business Act (outbound transmission disclosure), and other applicable laws. The Japanese-language version of this Policy is the authoritative version; this English translation is provided for convenience only and the Japanese version controls in case of any conflict.
1. Business operator and personal information handler
- Business operator: TheCapybaraCompany
- Corporate Registry Number: 1200-03-031084
- Registered address: B1, 5-61-4 Nakano, Nakano-ku, Tokyo 164-0001, Japan
- Representative: Flavien Garnier
- Personal information protection manager: the Business Operator
- Contact: support@capyclimb.com (see §10 for inquiries and rights requests)
2. Personal information we collect
2.1 Information you provide
- Account credentials — email address, password (stored hashed), or federated sign-in identity (Apple ID, LINE).
- Profile — first name, last name, location (gym/home area), date of birth, gender, profile photo (optional).
- Membership and purchase information — pass and membership selections, purchase history, billing reference (not the full card number).
- Communications you send us — feedback messages, attached photos, check-in survey responses, support tickets.
- Parental consent records for Members aged 16–17.
- Climbing Waiver and Off-Hours Access Consent items (Terms of Use §7.5 and §6.4) — may include sensitive personal information; collected under §2.4 only with your explicit opt-in consent.
2.2 Information generated by your use
- Door access logs — timestamp, door identifier, Member ID for each entry and exit at the Gym.
- QR code logs — issuance and scan events.
- App telemetry — IP address, device model, operating system, app version, crash reports, and basic interaction events for diagnostics.
- CCTV footage (new) — video from cameras installed for safety and crime-prevention purposes inside the Gym; visitors’ images may be captured.
- Lost-item photos (new) — photographs taken by us of items left behind in the gym, used to identify the owner. Names, IDs, and other personally identifying details are masked or cropped within reason. See Terms of Use §6.6.
2.3 Information from third parties
- Federated sign-in — when you sign in with Apple or LINE, the provider transmits a unique identifier and, depending on your consent, your email address. We do not receive your Apple/LINE password.
- Payment provider — when you pay through the App, our payment provider transmits the transaction status, last four digits of the card, brand, and a tokenized reference. We do not receive your full card number.
2.4 Sensitive personal information (rewritten — opt-in required)
As a rule, we do not collect “sensitive personal information” (要配慮個人情報) as defined by Article 2(3) of APPI (medical history, mental or physical disability, health-check results, criminal proceedings, etc.). As exceptions, we collect such information only with your prior explicit consent and to the minimum extent necessary, in the following cases:
- Climbing Waiver and Consent (Terms of Use §7.5) — self-declared information on health condition, pre-existing injuries, current medications, and exercise restrictions. Your signature (or the parent/guardian’s signature for a minor) constitutes explicit consent. We use such information only for safety management and incident response.
- Emergency response in case of accident or injury — we may share medical information with emergency services and medical institutions under APPI Art. 18(3)(ii) (necessary for the protection of life or body, and obtaining consent is difficult).
- Off-Hours Access Consent — personal accident insurance information (insurer name, policy number) — used only to verify your self-declared insurance coverage.
If you voluntarily include sensitive personal information in feedback, photos, or other content, we will not use it intentionally and will delete or anonymize it as promptly as practicable.
3. Purposes of use
We use personal information for the following purposes, in accordance with APPI Articles 17 and 21:
- Operate the App and provide gym access — authentication, QR code generation, Membership/Pass management, and logging of consent (version and timestamp) to the Terms of Use and this Policy.
- Manage door entry/exit logs (matching Terms of Use §6.3) — safety management, capacity management, billing accuracy, and incident response.
- Off-hours (unstaffed period) identity and eligibility verification (Terms of Use §6.4) — confirming eligibility (age, completion of orientation, supervised-visit history) and self-declared personal-accident insurance coverage.
- CCTV monitoring for safety and crime prevention (Terms of Use §6.5) — using video footage for safety, security, incident response, and dispute resolution.
- Lost & Found administration and return of property (Terms of Use §6.6) — photographing items left behind in the gym, posting them on the in-App Lost & Found board, identifying owners and returning items, and filing with the local police station under the Lost Property Act. This purpose also falls within APPI Art. 18(3)(ii) (necessary for the protection of life, body, or property of any person, where obtaining consent is difficult).
- On-site filming for promotional and marketing purposes (Terms of Use §6.5) — where individuals are identifiable, we obtain separate consent. Unconsented imagery is anonymized or excludes the subject wherever practicable.
- Process payments and prevent fraud.
- Communicate with you about your account, transactions, renewals, safety notices, and service changes.
- Respond to your inquiries, feedback, and support requests.
- Improve the App, the Gym experience, route programming, and capacity planning (in anonymized or aggregated form where practicable).
- Comply with legal obligations (tax records, statutory disclosures, court orders).
- Investigate and prevent violations of our Terms of Use, the Climbing Waiver, or this Policy; harassment, theft, fraud; and safety incidents.
- Use of user-submitted content for promotion with your consent (Terms of Use §10) — only content for which you have specifically opted in may be used for promotion of the Gym and the App.
- Marketing communications with your opt-in consent — only categories you specifically toggle on in the App’s settings will be sent:
- New Memberships and Passes
- Gym events and competitions
- Partner and sponsor offers You may withdraw consent at any time (§9.6).
We will not use your personal information for purposes other than those listed above without your prior consent, except where permitted or required by law.
5. Retention period
We retain personal information only as long as necessary for the purposes set out in §3, and as follows:
- Active Account data — for the duration of your Membership/Account plus a reasonable wind-down period.
- Closed Account data — basic identifiers and transaction history are retained for 5 years after account closure, then deleted or fully anonymized. This corresponds to the 5-year statute of limitations for personal-injury tort claims under Article 724-2 of the Civil Code (from knowledge of the damage and the perpetrator).
- Door entry/exit logs — retained for up to 3 years after account closure, then deleted or anonymized.
- CCTV footage — retained for up to 30 days from recording; footage related to an incident or investigation may be retained for the period necessary for the response or for the defense of legal claims.
- Lost-item photos (in-App Lost & Found postings) — retained while the item is held at the gym plus 30 days thereafter (maximum 60 days total); deleted upon return to the owner or upon disposal/donation of the item.
- Payment-transaction metadata — retained per payment-provider audit rules and Japanese tax law (typically 7 years).
- Marketing consent records — retained while consent is active, then for 1 year after withdrawal as opt-out evidence.
- Feedback and survey responses — retained for 2 years in identified form, then anonymized for aggregate analysis.
We may retain data longer when required by law, court order, or to defend legal claims.
6. Security measures (revised — adds “awareness of the external environment”)
We implement the five categories of safeguards required by PPC guidance:
- Organizational measures — designation of a personal information protection manager, clarification of responsibilities and authorities, internal rules, and response procedures for incidents.
- Personnel measures — periodic training of officers and employees; non-disclosure agreements.
- Physical measures — access control to offices and gym premises; locked storage for paper records.
- Technical measures — encryption in transit (TLS) and at rest where the provider supports it; need-to-know access controls; logging and monitoring of administrative access.
- Awareness of the external environment (外的環境の把握) (new) — where personal data is handled in a foreign country by an entrustee or third-party recipient, we understand the personal-data protection regime of that country (laws, enforcement, supervisory authority) and, based on that understanding, take necessary and appropriate measures (contractual clauses, technical safeguards, periodic review). The countries and summaries are set out in §4.4.
No system is perfectly secure. Where a personal-information breach that may infringe individual rights and interests occurs, we will, under APPI Art. 26 and its implementing regulations, submit a preliminary report (速報) within approximately 3–5 days, a confirmed report (確報) within 30 days (or 60 days for unauthorized-access cases), and notify the affected individuals without delay.
7. Children’s data (revised — actual collection scope)
- We do not knowingly collect personal information from Members under 16 years of age through an individual Account.
- For Members aged 16 or 17, we require written consent from a parent or legal guardian (see Terms of Use §3.1) and retain that consent record alongside the Account for 5 years.
- For children under 16 who visit the Gym accompanied by a parent or guardian, we record: the parent’s identifier, the child’s first name, date of birth, emergency contact, and safety-related declarations contained in the Climbing Waiver (see §2.4 for sensitive-information treatment).
8. Device identifiers, outbound transmission, and personal-related information (fully rewritten)
8.1 Identifiers used
The App uses the following device identifiers:
- Apple IDFV / Android App Instance ID — for fraud prevention, crash diagnostics, and app functionality.
- Account ID issued by us (UUID) — for authentication and session management.
The App does not transmit data to third-party behavioral-advertising providers. We do not engage in targeted advertising based on your in-app behavior.
8.2 Outbound Transmission Disclosure (Telecommunications Business Act Art. 27-12)
The App is subject to the “outbound transmission disclosure” rule under Art. 27-12 of the amended Telecommunications Business Act (in force June 2023). The categories of user information transmitted from the App to external services, the recipients, the purposes of transmission, the recipients’ purposes of use, and opt-out methods are set out on a dedicated “Outbound Transmission Disclosure” page accessible from this Policy and from the App’s settings screen.
8.3 Provision of personal-related information
Where we provide information that is not “personal data” at our end (e.g., device identifiers) to a third party where it is reasonably foreseeable that the recipient will receive it as personal data, we will confirm under APPI Art. 31 that the recipient has obtained your consent, and retain the related records.
9. Your rights as a data subject (revised — 2022 amendments)
Under APPI, you have the following rights with respect to your personal information held by us:
9.1 Right of disclosure (開示請求)
You can request a copy of the personal information we hold about you and information about how we use it. You may specify the format of disclosure — written, electronic data (PDF or CSV), or another method (APPI Art. 33(1)). Where you request electronic disclosure, we will comply with your specified method except where doing so is technically very difficult.
9.2 Disclosure of third-party provision records (第三者提供記録の開示)
You may also request disclosure of the records of third-party provision we maintain under APPI Articles 29 and 30 (APPI Art. 33(5)).
9.3 Right of correction (訂正・追加・削除請求)
You can request that we correct, add to, or delete personal information that is inaccurate.
9.4 Right of suspension of use (利用停止・消去請求) (revised — 2022-expanded grounds)
You can request that we stop using or delete your personal information where any of the following applies (APPI Art. 35):
- We have used it beyond the disclosed purposes (Art. 35(1)).
- It was obtained improperly (Art. 35(1)).
- We no longer need to use the personal data (Art. 35(5)).
- A serious breach event has occurred under APPI Art. 26(1) (Art. 35(5)).
- Other circumstances where your rights or legitimate interests may be infringed (Art. 35(5)).
9.5 Right of suspension of third-party provision
You can request that we stop providing your personal information to third parties (other than entrustees acting on our behalf).
9.6 Withdrawal of marketing consent
You can withdraw consent for marketing communications (§3 item 13(a)–(c)) at any time, through the App’s settings or by emailing us. Transactional and service messages will continue.
9.7 How to exercise
Send a written request from the email address on your Account to support@capyclimb.com, or by post to the address in §1. We may need to verify your identity (e.g., last four digits of the latest transaction, photo ID). We will respond without undue delay (target: within 30 days of receiving a valid request); if a case requires more time, we will inform you. We do not charge a fee for these requests except as permitted under APPI.
10. Inquiries and complaints
For questions about this Policy or about how we handle your personal information:
- Email: support@capyclimb.com
- Postal: TheCapybaraCompany, B1, 5-61-4 Nakano, Nakano-ku, Tokyo 164-0001, Japan
- In-app: Use the “Talk with us” button in the top-right of the home screen.
If you are not satisfied with our response, you may also contact the Personal Information Protection Commission (個人情報保護委員会):
- Website: https://www.ppc.go.jp/
- Hotline: 03-6457-9849 (verified against PPC’s website at the time of publication)
11. Changes to this Policy
We may update this Policy from time to time. Changes will be made only where they (i) conform to the general benefit of users, or (ii) do not conflict with the purpose of the relationship and are reasonable in light of the necessity of the change, the substance of the change, the timing of effect, and other relevant circumstances.
When changes are made, we will:
- Post the updated Policy in the App and on our website with a new “Last updated” date.
- For material changes affecting your rights and obligations (e.g., expansion of purposes of use or scope of third-party provision), obtain a new consent where required by law and notify you in the App and by email to your registered address at least 30 days before the change takes effect.
12. Language
The Japanese-language version of this Policy (プライバシーポリシー) is the authoritative version. This English translation is provided for convenience only. In the event of any conflict, the Japanese version controls. See also our Terms of Use.