Information Security Policy
Information Security Policy
Hitline Co., Ltd. (hereinafter referred to as the "Company") provides the service "HitBoost" (hereinafter referred to as the "Service"), including API integration with e-commerce platforms, system development, application development, data integration, operational support, sales support, and order, inventory, and delivery management support, to e-commerce operators, sellers, business partners, and related businesses.
The Company regards information assets, business data, authentication information, data obtained through API integration, logs, system configuration information, and confidential information learned in the course of business that are handled in the Service as important assets, and works to manage information security appropriately based on the following policy.
The Company's handling of personal information is governed by the separately published "Personal Information Protection Policy" and "Handling of Personal Information." This Policy supplements those policies concerning the handling of personal information and establishes the Company's policy regarding information security, e-commerce platform API data, authentication information, system operations, and security management in the Service.
1. Scope of Application
This Policy applies to information assets and systems that the Company acquires, stores, views, processes, transmits, uses, deletes, or disposes of in connection with the provision of the Service.
The covered information and systems include the following:
- Business information concerning e-commerce operators, sellers, business partners, and their representatives.
- Information acquired through APIs, webhooks, administration screens, CSV files, integration functions, or other means of e-commerce platforms, etc.
- Business data concerning products, inventory, orders, deliveries, returns, refunds, sales, advertisements, sales analysis, and similar matters.
- Authentication information such as access tokens, refresh tokens, API keys, webhook secrets, connection configuration information, and related information.
- Information necessary for system operations, including operation logs, authentication logs, API communication logs, error logs, audit logs, and similar information.
- Applications, databases, servers, networks, backups, development environments, and operational environments that constitute the Service.
- Confidential information, non-public information, and information that must be protected under contracts and that the Company handles in connection with the Service.
2. Definition of E-Commerce Platforms, etc.
In this Policy, "E-Commerce Platforms, etc." means e-commerce malls, marketplaces, sales support services, delivery, inventory, and order management related services, advertising and analytics related services, and other external services that are subject to integration, development, operational support, sales support, or data processing by the Company in the Service.
E-Commerce Platforms, etc. include the following:
- Amazon
- Rakuten Ichiba
- Yahoo! Shopping
- TikTok Shop
- STOREE SAISON
- Qoo10
- au PAY Market
- JRE MALL
- ANA Mall
- Mercari Shops
- Other e-commerce related services that the Company integrates with or supports in connection with the Service.
3. Basic Policy
The Company establishes the following basic policy for information security management.
- The Company will comply with laws and regulations, guidelines, contracts, the terms of E-Commerce Platforms, etc., and various policies to which the Company has agreed.
- The Company will limit the information it acquires to the scope necessary for the provision, maintenance, improvement, incident response, security assurance, contract performance, and legal compliance of the Service.
- The Company will handle only the minimum information necessary for business operations and will not use information for unintended purposes.
- The Company will restrict access rights to information to the minimum necessary and manage them appropriately through authentication, authorization, access control, log management, and similar measures.
- The Company will implement technical and organizational security management measures, including encryption in transmission and storage, authentication information management, vulnerability countermeasures, backups, and log monitoring.
- If the Company detects a security incident or suspected security incident, it will promptly investigate, confirm the scope of impact, contain the incident, restore affected systems, prevent recurrence, and notify relevant parties as necessary.
- The Company will continuously review and improve this Policy and related internal rules.
4. Information Acquired or Handled
The Company may acquire or handle the following information to the extent necessary to provide the Service.
4.1 Information Concerning Business Partners and Business Communications
- Company name, trade name, department name, and representative name.
- Email address, telephone number, and address.
- Information necessary for contracts, billing, payment, inquiries, and support.
- Information concerning business discussions, business communications, configuration requests, operational requests, and incident response.
4.2 Information Concerning Integration with E-Commerce Platforms, etc.
- Identifiers concerning shops, stores, sellers, accounts, applications, and integration settings.
- Product information, SKUs, JAN codes, prices, inventory, categories, images, and descriptions.
- Order numbers, order dates and times, order status, payment status, delivery status, and return/refund status.
- Information necessary for order processing, delivery, direct shipment, returns, inquiry handling, and similar operations.
- Information concerning sales, sales performance, advertisements, campaigns, access analysis, and sales analysis.
- Logs concerning API integration, webhooks, synchronization processing, errors, and access history.
- Access tokens, refresh tokens, API keys, webhook secrets, authentication information, connection configuration information, and related information granted or acquired from E-Commerce Platforms, etc.
4.3 Information Concerning System Operations
- Technical information such as IP addresses, user agents, devices, browsers, and operating systems.
- Operation logs, authentication logs, API request logs, error logs, and audit logs.
- System settings, job execution history, backup history, and incident response history.
- Information necessary for security investigations, vulnerability response, incident response, and audits.
5. Purposes of Use
The Company uses the information it acquires or handles for the following purposes:
- To provide, configure, operate, maintain, and improve the Service.
- To provide API integration, data synchronization, webhook processing, CSV processing, inventory synchronization, order synchronization, product registration, price updates, and related functions with E-Commerce Platforms, etc.
- To support product management, inventory management, order management, delivery management, return/refund handling, sales analysis, sales performance analysis, business efficiency improvement, and similar operations.
- To respond to inquiries, support requests, incident response, configuration changes, maintenance, and notifications from business partners.
- To detect, investigate, prevent, and respond to unauthorized access, unauthorized use, information leakage, vulnerabilities, failures, misconfigured permissions, and other security risks.
- To perform administrative procedures concerning contracts, billing, payment, accounting, tax, audits, and similar matters.
- To respond to legitimate requests from laws and regulations, contracts, the terms of E-Commerce Platforms, etc., administrative agencies, or operators of E-Commerce Platforms, etc.
- To improve the quality and functions of the Service, analyze usage, and improve business operations.
- To provide business support functions using AI, MCP, machine learning, data analysis, and other technologies based on the instructions or consent of business partners.
The Company will not use acquired information beyond the scope of the above purposes of use without the consent of the contracting party or another legitimate basis.
6. Handling of E-Commerce Platform API Data
The Company handles data acquired through APIs, webhooks, administration screens, CSV files, integration functions, and other means of E-Commerce Platforms, etc. in accordance with the following principles:
- The Company limits API scopes and access rights it acquires to the minimum necessary for the provision of the Service.
- Data acquired from E-Commerce Platforms, etc., including seller, purchaser, product, inventory, order, delivery, return, refund, sales, advertising, analytics, and other data, is used only for purposes necessary for providing services to contracting parties, maintenance, incident response, security response, contract performance, and legal compliance.
- The Company does not use data acquired from E-Commerce Platforms, etc. for sale or rental to third parties, advertising delivery, profiling unrelated to contracting parties, or purposes unrelated to the Service.
- Data restricted by the terms or API usage conditions of E-Commerce Platforms, etc. is handled in accordance with those terms or usage conditions.
- Access tokens, refresh tokens, API keys, webhook secrets, and other authentication information are handled as confidential information, and access restrictions, encryption, and leakage prevention measures are implemented.
- If API integration is terminated, a contract ends, or a contracting party requests deletion, related data will be deleted, anonymized, or disposed of in a manner that makes restoration difficult, except where retention is required by law, contract, or legitimate business necessity.
- The Company does not use, without authorization, data acquired from E-Commerce Platforms, etc. for other services, customers, business partners, or third parties for purposes unrelated to the Service.
7. Use of AI, MCP, and Data Analysis Technologies
The Company may use AI, MCP, machine learning, statistical analysis, and other data analysis technologies for purposes such as improving the quality of the Service, improving business efficiency, sales analysis, demand forecasting, inquiry response support, anomaly detection, and similar purposes.
When using AI, MCP, and data analysis technologies, the Company follows the policy below.
- AI, MCP, or data analysis functions are provided based on the consent of the contracting party or instructions from the contracting party.
- When data acquired from E-Commerce Platforms, etc. is used for AI, MCP, or data analysis technologies, its use is limited to the scope necessary for providing services to the contracting party, supporting the contracting party's business, maintaining or improving the Service, or ensuring security.
- The Company separates data, settings, permissions, workspaces, or processing environments for each contracting party and manages them appropriately so that data from different contracting parties is not mixed.
- When data containing personal information is used for AI, MCP, or data analysis technologies, the Company implements protection measures such as anonymization, pseudonymization, masking, aggregation, access control, and other measures as necessary.
- Without the consent of the contracting party or another legitimate basis, the Company does not use data acquired from E-Commerce Platforms, etc. for third-party advertising delivery, profiling for third parties, or training external models unrelated to the Service.
- When using external AI services, MCP-related services, or data processing services, the Company reviews the service's data handling terms, whether data is used for training, retention periods, third-party provision, cross-border transfer, security management measures, and similar matters, and implements contractual or technical protection measures as necessary.
- If the terms, API usage conditions, or contracts of E-Commerce Platforms, etc. restrict the use of AI, MCP, or data analysis technologies, the Company complies with those restrictions.
8. Handling of Personal Information
When the Company handles personal information in connection with the Service, it handles such information appropriately in accordance with the separately published "Personal Information Protection Policy" and "Handling of Personal Information."
In the Service, the Company may handle personal information to the extent necessary for order processing, delivery, direct shipment, returns, inquiry handling, sales analysis, incident response, and similar purposes.
For data containing personal information, the Company implements appropriate security management measures based on its personal information protection management system, in addition to the information security management measures set forth in this Policy.
9. Security Management Measures
The Company implements the following security management measures to prevent leakage, loss, damage, unauthorized access, unauthorized use, alteration, erroneous transmission, misconfigured permissions, and similar incidents concerning information handled by the Company.
9.1 Organizational Security Management Measures
- Appointment of a person responsible for, or in charge of, information security.
- Establishment of rules for handling information assets, personal information, confidential information, and authentication information.
- Granting, changing, deleting, and periodically reviewing access rights.
- Establishment of operational procedures for security checks, vulnerability checks, backups, log reviews, and similar operations.
- Establishment of procedures for reporting, investigating, responding to, and preventing recurrence of incidents.
- Confirmation of compliance with laws and regulations, contracts, the terms of E-Commerce Platforms, etc., and internal rules.
9.2 Personnel Security Management Measures
- Establishment of confidentiality obligations for employees, officers, contractors, and other related parties.
- Education, communication, or reminders concerning information security and personal information protection.
- Prohibition of viewing, taking out, copying, or sharing information beyond the scope necessary for business.
- Deletion of access rights and review of authentication information upon retirement, contract termination, or change of assignment.
9.3 Technical Security Management Measures
- User authentication through Google ID authentication and other authentication methods.
- Recommendation of multi-factor authentication and enablement as necessary.
- Access control according to roles, assigned duties, or necessity.
- Encryption of communication channels using HTTPS and similar methods.
- Encryption of important information, including personal information, on a database field-by-field basis.
- Encryption or other protection measures for storage media or entire virtual disks.
- Secure storage of API keys, tokens, secrets, and other confidential information.
- Prevention of plaintext recording of confidential information in source code, public repositories, chat, email bodies, and similar places.
- Log acquisition, error monitoring, and confirmation of operation history.
- Acquisition of backups, generation management, and establishment of recovery procedures.
- Confirmation of vulnerability information, vulnerability scanning, and updates to plugins and related software.
9.4 Physical Security Management Measures
- Prevention of theft, loss, and unauthorized use of business terminals, recording media, and authentication information.
- Protection measures for business terminals, including authentication settings, locking, encryption, and similar measures.
- Protection of management information concerning servers, VPSs, cloud infrastructure, and other infrastructure.
- Management of storage, removal, and disposal when paper media or external recording media are used.
10. System Environment and Infrastructure Management
In providing the Service, the Company uses system environments managed by the Company, including Windows Server VPSs and SQL Server.
The Company manages its system environment as follows:
- The Company manages servers, databases, applications, and network settings to the extent necessary.
- The Company restricts unnecessary accounts, privileges, services, ports, and connection settings.
- Administrator privileges are limited to the minimum necessary personnel.
- The Company updates and responds to vulnerabilities in systems, middleware, plugins, dependency libraries, and similar components as necessary.
- The Company obtains and appropriately manages necessary logs to confirm signs of failures, abnormalities, errors, or unauthorized use.
- Specific information concerning VPS providers and other infrastructure providers is not stated in public documents for security reasons. However, if a contracting party, an operator of an E-Commerce Platform, etc., a supervisory authority, or another person with legitimate authority requests disclosure to the necessary extent, the Company will respond individually in accordance with laws and regulations, contracts, and confidentiality obligations.
11. Access Management
The Company limits access to information to personnel who need such access for business purposes.
- Administrator privileges are limited to the minimum necessary personnel.
- Access to production environments, customer data, personal information, authentication information, and API integration settings is performed only after confirming necessity.
- The Company keeps records or management logs of the granting, changing, and deletion of privileges.
- The access rights of retirees, persons whose contracts have ended, or persons no longer assigned to the relevant duties are promptly deleted.
- The Company obtains logs for important operations and reviews them as necessary.
- For user authentication, the Company uses Google ID authentication and other authentication methods, and recommends or implements multi-factor authentication, strong password management, suspension of unnecessary accounts, and similar measures to ensure account security.
12. Encryption and Confidential Information Management
The Company implements appropriate encryption or equivalent protection for personal information, authentication information, API keys, access tokens, refresh tokens, webhook secrets, confidential information, and similar information.
- The Company uses encrypted communication methods such as HTTPS for external communications.
- Important information, including personal information, is encrypted on a database field-by-field basis using AES-256-equivalent encryption.
- The Company implements encryption or other protection measures for storage media or entire virtual disks that store important information, including personal information.
- API keys, tokens, and secrets are not stored or shared in plaintext in source code, public repositories, chat, email bodies, or similar places.
- Confidential information is managed in an access-restricted environment.
- If leakage or suspected leakage of authentication information is detected, the Company promptly invalidates, reissues, investigates the impact of, and prevents recurrence of such leakage.
13. Logs and Audits
The Company obtains logs to the extent necessary for stable system operation, incident response, detection of unauthorized access, security audits, and confirmation of compliance with rules and terms.
The logs acquired may include the following:
- Access date and time.
- Operation details.
- Authentication history.
- Information concerning API requests and responses.
- Error details.
- Synchronization processing execution history.
- Administrative operation history.
- Records concerning security checks and vulnerability response.
The Company endeavors to record only the minimum necessary information in logs, and implements protection measures such as access restrictions, retention period management, deletion, or masking for logs that contain personal information or confidential information.
14. Backup and Recovery
The Company obtains backups of databases and related data in preparation for data loss, damage, failures, erroneous operations, security incidents, and similar events.
- The Company obtains database backups to the extent necessary.
- Backups are managed by generation.
- As a general rule, backups older than 30 days are deleted. However, this does not apply where necessary for legitimate reasons such as incident response, security investigations, laws and regulations, or contracts.
- If backup data contains personal information, confidential information, or authentication information, the Company implements security management measures equivalent to those for production data.
- The Company confirms and reviews recovery procedures as necessary.
15. Vulnerability Management and Security Checks
The Company endeavors to identify and address vulnerabilities in systems, applications, servers, databases, plugins, dependency libraries, API integration functions, and similar components related to the Service.
The Company performs the following operations:
- The Company conducts vulnerability scans once every three months.
- The Company conducts security checks at the end of every month.
- The Company checks for version updates to plugins and related software once every three months.
- The Company checks vulnerability information for plugins and related software at the end of every month using trusted sources such as JPCERT/CC and JVN.
- If a serious vulnerability is identified, the Company evaluates the scope of impact and implements fixes, configuration changes, workarounds, updates, and similar measures according to priority.
- During development, the Company pays attention to authentication, authorization, input validation, error handling, confidential information management, log output, and separation of privileges.
- The Company performs code reviews, security reviews, testing, and confirmation of compliance with external rules and terms as necessary.
16. Data Retention Period and Deletion
The Company retains acquired information only for the period necessary to achieve the purposes of use, the period necessary under contracts, the period required by law, or the period necessary for security, audit, or incident response.
Typical retention periods are as follows:
- Business data such as orders, deliveries, returns, refunds, and sales performance: at least one year, or the period required by laws and regulations, contracts, or the terms of E-Commerce Platforms, etc.
- Information concerning contracts, billing, accounting, and tax: the period required by laws and regulations or internal rules.
- API integration logs, operation logs, and error logs: the period necessary for security audits, incident response, unauthorized use investigations, and operational improvement.
- Authentication information such as access tokens and API keys: the period necessary for integration.
- Backup data: as a general rule, 30 days; however, this excludes cases where retention is necessary for legitimate reasons such as incident response, security investigations, laws and regulations, or contracts.
- Support inquiry information: the period necessary for follow-up inquiries, quality improvement, dispute prevention, and contract performance after the response is completed.
Information whose retention period has expired or that is no longer necessary after the achievement of the purposes of use will be deleted, anonymized, or disposed of in a manner that makes restoration difficult within a reasonable period.
17. Third-Party Provision and Outsourcing
Except where based on laws and regulations, where the contracting party has consented, where necessary for contract performance, or where outsourcing is necessary to provide the Service, the Company does not provide data acquired from E-Commerce Platforms, etc. or confidential information to third parties.
The Company may use external business operators such as E-Commerce Platforms, etc., authentication services, server/VPS providers, telecommunications carriers, maintenance providers, AI-related services, MCP-related services, specialists, and other external business operators to the extent necessary to provide the Service.
When using external business operators or outsourcing contractors, the Company checks, as necessary, their security management measures, confidentiality, re-outsourcing, data storage locations, incident response, data handling conditions, and similar matters, and manages them appropriately.
18. Handling Outside Japan
In connection with the use of E-Commerce Platforms, etc., authentication services, server/VPS services, cloud services, AI services, MCP-related services, development and operation tools, and similar services, the Company may store or process information on servers located outside Japan or through business operators outside Japan.
When handling information outside Japan, the Company implements necessary security management measures in accordance with applicable laws and regulations, contracts, and the terms of E-Commerce Platforms, etc.
19. Security Incident Response
If the Company detects an information leakage, unauthorized access, leakage of authentication information, malware infection, erroneous transmission, misconfigured permissions, exploitation of vulnerabilities, data alteration, system failure, or other security incident or suspected security incident, it will take the following actions:
- Confirm facts and investigate the scope of impact.
- Prevent expansion of damage and contain the incident.
- Invalidate, reissue, or change permissions for authentication information as necessary.
- Restore systems and preserve data.
- Analyze causes and implement measures to prevent recurrence.
- Notify contracting parties, relevant parties, operators of E-Commerce Platforms, etc., supervisory authorities, and others as necessary.
- Retain response records and make improvements.
20. Response to Requests from Contracting Parties
If the Company receives a request from a contracting party for data confirmation, correction, deletion, suspension of use, integration termination, export, or similar action, the Company will confirm the authority of the requester and respond within a reasonable scope in accordance with laws and regulations, contracts, and the terms of E-Commerce Platforms, etc.
Data stored on E-Commerce Platforms, etc. may include data that is managed by the contracting party or the operator of the relevant E-Commerce Platform, etc., and the Company may not be able to respond on its own. In such cases, the Company will coordinate with the contracting party or relevant parties as necessary.
21. Prohibited Matters
The Company will not perform the following acts with respect to information acquired in connection with the Service:
- Use beyond the scope of contracts, purposes of use, or the terms of E-Commerce Platforms, etc.
- Advertising delivery, sale, rental, or profiling unrelated to the Service.
- Provision to unauthorized third parties.
- Unauthorized scraping, reverse engineering, or unauthorized access.
- Use that violates the terms of E-Commerce Platforms, etc., API usage conditions, or laws and regulations.
- Improper sharing or disclosure of authentication information, API keys, tokens, or secrets.
- Acquisition or storage of personal information or sensitive information that is not necessary.
- AI model training, external provision, or secondary use without the contracting party's consent or another legitimate basis.
- Mixing, diversion, or sharing of data from different contracting parties without the consent of the contracting parties.
22. Continuous Improvement
The Company continuously reviews and improves this Policy and related security management measures in response to changes in laws and regulations, industry standards, the terms of E-Commerce Platforms, etc., technical environments, threat trends, and business activities.
23. Inquiry Desk
For inquiries regarding this Policy, the Company's information security management, security incidents, vulnerability reports, data deletion, and similar matters, please contact the inquiry desk below.
Hitline Co., Ltd.
3F Meieki Yutaka Building, 3-6-6 Meieki-minami, Nakamura-ku, Nagoya-shi, Aichi 450-0003, Japan
Email: info@hitline.co.jp
Complaints, consultations, and requests for disclosure, etc. concerning the handling of personal information are handled in accordance with the inquiry desk and procedures set forth in the Company's separately published "Personal Information Protection Policy" and "Handling of Personal Information."
24. Revisions
The Company may revise this Policy as necessary. In the event of any material change, the Company will notify users by posting the change on the Company's website or by another appropriate method.
Hitline Co., Ltd.
Representative Director: Koji Yamada
Established: June 12, 2026
Last revised: June 12, 2026
End