IDAEO Privacy Policy
Washin Co., Ltd. (株式会社和心) ("we," "us," or "our") sets out in this Privacy Policy how we handle user information in IDAEO (the services provided at idaeo.ai and its subdomains; the "Service").
This Policy applies together with our "Personal Information Protection Policy" (https://idaeo.ai/legal/privacy). This Policy specifically governs the handling of information in the AEO and IDA plans and in external account connections authorized by the business (including Google APIs). If the two documents differ regarding data obtained from Google APIs, this Policy prevails.
1. Operator
- Name: Washin Co., Ltd. (株式会社和心)
- Corporate Number: 8011401020677
- Address: R-Cube Aoyama 3F, 1-3-1 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan
- Contact: idaeo@idaeo.ai
- Covered service: IDAEO (https://idaeo.ai/, https://aeo.idaeo.ai/ and other subdomains of idaeo.ai)
2. About the Service
The Service helps a store or business (the "business") check whether AI assistants and search engines read and display its information correctly, and supports its improvement. The plans are Free AEO, AEO+, IDA, and IDA+. The contents and prices of each plan are shown on the Service.
3. Information We Collect
We collect the following information.
3-1. Account information
- When a user logs in with a Google, LINE, Apple, or Facebook account, the identifier, display name, email address, profile image, and other information provided by that provider, to the extent the user has consented to provide it through that provider
- We do not receive your passwords for these accounts.
3-2. Information entered or registered by users
- The website URLs registered in "My URLs" and the labels set by the user
- Business information provided or corrected by the business (opening hours, reservation methods, phone number, address, etc.)
- The content of inquiries
3-3. Payment information
- Payments for paid plans are processed through a payment service provider (currently Stripe). Card numbers are handled by the payment service provider, and we do not store card numbers. We receive information such as whether a payment succeeded, the plan, the billing period, and the customer identifier issued by the payment service provider.
3-4. Information we record ourselves
- Access records for pages of the Service (business pages, AEO pages, IDA pages, articles, etc.): date and time, IP address, user agent, and referrer. We use records from Cloudflare and our own servers.
- Records of use of the reservation, call, and directions buttons on business pages, and of our domain's short URLs and QR codes (including those placed on the business's official website, social media, printed materials, etc.): date and time, referrer, and type of action
- Cookies used to identify visits through referral links (valid for 30 days) and cookies used to keep users logged in
3-5. Public information
- Publicly available pages of the websites at URLs registered by users
- Registration information published by public bodies, such as corporate registries
- Responses given when AI services are asked about a business
3-6. Information from accounts the business has authorized for connection (optional)
On paid plans, we obtain information from the following services only when the business has authorized it. The basic functions of the Service can be used without authorizing any connection. Each connection is offered in phases, and connections that are available are shown on the Service. We do not obtain information for connections not yet offered.
- Google Business Profile: the business's information (name, address, phone number, opening hours, website, category), search and view performance data, and reviews posted to the business's own locations
- Google Search Console: data such as search queries, impressions, clicks, and indexing status
- Google Analytics 4: aggregated data such as visits, traffic sources, and events like reservations and inquiries
- Bing Webmaster Tools: data on appearances and citations in search and AI answers
- Cloudflare: access records such as those from AI crawlers, and configuration status
- Social media accounts: posts the business has made public (announcements, temporary closures, etc.)
- Reservation, lodging, and POS systems (IDA+): information on availability, prices, and reservations
4. Purposes of Use
We use the information we obtain only for the following purposes.
- Identity verification, login, and account management
- Inspecting registered URLs, displaying inspection results and improvement methods, and creating PDFs
- Weekly re-inspections and notification of results and alerts by email (for example, when an AI gave incorrect information or an AI can no longer access the site)
- Creating and publishing business pages and IDA pages, and creating and publishing articles (those for which the business chose automatic publication or batch approval)
- Displaying figures and trends in the business's dashboard, and creating monthly reports (including the number of uses of short URLs and QR codes)
- Billing and granting referral benefits (including matching the user, email address, and payment customer identifier to prevent self-referral)
- Responding to inquiries
- Preventing misuse, responding to incidents, and ensuring security
- Improving the Service (provided, however, that for Google user data described in Section 5, Section 5 prevails)
- Responding as required by law
5. Handling of Data Obtained from Google APIs
5-1. Data and scopes we obtain
Only when a business has authorized the connection with the Service through its Google account, we obtain the following data through Google APIs. Each API connection is offered in phases, and for those not yet offered, we do not request permissions on the consent screen either. In the initial stage we only read data, and we do not post to or edit the Business Profile.
- Google Business Profile APIs (scope https://www.googleapis.com/auth/business.manage): business information, performance data, and reviews of the business's own locations
- Google Search Console API (read-only scope): search performance and indexing status
- Google Analytics Data API (read-only scope): aggregated data on visits and events
We use data only for the locations and sites, among those viewable with the connected Google account, that the business has selected in the Service. If we offer features in the future that write data (such as updating information), we will update this Policy and obtain the business's consent each time before doing so.
5-2. How we use it
Data obtained from Google APIs is used only to provide and improve the following features for the business that authorized the connection.
- Using the business information obtained with the business's permission as a baseline, comparing it with AI answers and the contents of business pages, and notifying the business of discrepancies
- Displaying performance data, search queries, and access data in the business's dashboard and reports
- Using Search Console search queries and analytics data to select article topics for that business and to write report text
- Displaying and organizing reviews in the business's private dashboard
- Content obtained from Google Business Profile is not published as-is on public pages such as IDA pages. Facts on public pages are based on the business's official website, public registrations, and information the business entered directly into the Service.
5-3. Compliance with Limited Use
IDAEO's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically:
- We do not use it for anything other than providing and improving the business-facing features in 5-2 above.
- We do not transfer it to third parties, except where necessary to provide the above features with the business's consent, where necessary for security purposes (such as investigating misuse), where necessary to comply with law, or in connection with a merger, acquisition, or sale of business for which we have obtained the business's prior explicit consent.
- We do not sell it. We do not transfer or sell it to advertising providers, data brokers, or information resellers.
- We do not use it to serve advertisements (including retargeting, personalized advertising, and interest-based advertising).
- We do not use it to determine creditworthiness or for lending purposes.
- Our personnel view the data only where the business has consented to the viewing of specific data (such as at a support request), where necessary for security purposes, where necessary to comply with law, or where the data is aggregated and anonymized and used for our internal operations. However, content obtained from Google Business Profile is not aggregated or processed for storage.
- We do not use data obtained from Google APIs to train general-purpose AI or machine learning models.
- Data obtained from Google Business Profile is not sent to external AI services. Comparison with AI answers is performed by our own programs.
- Data obtained from Google Search Console and Google Analytics may be sent to the APIs of the generative AI providers in Section 7 only where necessary for features for that business (such as selecting article topics and drafting report text). Even in that case, we use APIs under terms by which the provider does not use the data for model training.
- We do not use data obtained from Google APIs for statistics or features intended for other businesses.
- We require our employees and contractors to comply with these requirements as well.
5-4. Storage and deletion
- Data obtained from Google APIs and authentication tokens are stored on the cloud infrastructure described in Section 7, with access permissions restricted. Communications are encrypted (HTTPS).
- Content obtained from Google Business Profile is kept only as a small amount of temporary storage to improve the display performance of the Service, in accordance with the Google Business Profile APIs policy, is not processed or aggregated, and is not stored for more than 30 days. To display trends, we obtain it from the API each time it is needed.
- Data obtained from other Google APIs is stored while the connection is active, to the extent necessary to provide the above features.
- A business can revoke access at any time through the Google account's "Third-party apps & services" page (https://myaccount.google.com/connections). We will also make it possible to disconnect in the Service's dashboard. We also accept disconnection requests by contacting idaeo@idaeo.ai.
- After revocation or disconnection, we stop obtaining new data, delete authentication tokens, and delete data obtained from Google APIs, except for data we are required by law to retain.
- Data obtained through a connection is displayed only to the user who authorized that connection. Other administrators of the same URL (including a new top-level administrator) must authorize a connection themselves to use the data. If the user who authorized the connection ceases to be an administrator of that URL, we will disconnect the connection and carry out the deletion described above.
- Information received when you sign in with a Google account (Section 3-1) is used for identity verification and account management, sending email notifications, and preventing misuse of referral benefits (matching the same user and the same email address), and is handled separately from a business's connection data. After the account is deleted, it is deleted in accordance with the retention periods in our Personal Information Protection Policy (https://idaeo.ai/legal/privacy).
6. Provision to Third Parties
We do not provide users' personal information to third parties, except in the following cases.
- When the person has consented
- When required by law
- When necessary to protect a person's life, body, or property and it is difficult to obtain the person's consent
- When in connection with succession of the business through a merger or other reason (data obtained from Google APIs is subject to Section 5)
We do not sell personal information or user information.
7. Contractors
To operate the Service, we may entrust the handling of information to businesses such as the following. Contractors may be located outside Japan (such as in the United States). We appropriately supervise our contractors.
- Cloud infrastructure: Cloudflare, Inc. (United States); Amazon Web Services, Inc. (United States)
- Payment processing: Stripe, Inc. (United States)
- Email delivery and customer support: Google LLC (United States)
- Generative AI and other external APIs: OpenAI, L.L.C. (United States), Google LLC (United States), Anthropic, PBC (United States), and others (for inspection and for writing and translating text; the handling of data obtained from Google APIs is subject to Section 5)
The list of contractors is also provided in Appendix 2 of the Personal Information Protection Policy.
8. Information Published on Public Pages
IDA pages and business pages publish business information that is public on the business's official website or in public registrations, such as the business's name, address, phone number, opening hours, and prices, together with information provided by the business. We endeavor not to publish individuals' phone numbers other than those made public as the business's contact details. To request correction or deletion of published content, please contact idaeo@idaeo.ai.
9. Cookies
The Service uses cookies to keep users logged in and to identify referral links (30 days). You can disable cookies in your browser settings, but some functions such as login will become unavailable.
10. Security Measures
We take reasonable security measures to prevent leakage, loss, or damage of information, such as encrypting communications, restricting access permissions, and managing authentication credentials.
11. Requests for Disclosure, Correction, Deletion, and Suspension of Use
Users may request disclosure, correction, addition, deletion, or suspension of use of their own information that we hold. Please contact idaeo@idaeo.ai. After confirming that you are the person concerned, we will respond in accordance with law. Account deletion is accepted through the same contact.
12. Minors
The Service is intended for businesses and is not directed at persons under 13 years of age.
13. Revisions
If we revise this Policy, we will announce it on this page. If we change how data obtained from Google APIs is used, we will notify the business before the change and obtain consent again.
14. Language
The Japanese version of this Policy is the authoritative version. The Traditional Chinese, Simplified Chinese, and English versions are reference translations, and if there is any discrepancy, the Japanese version prevails.