Kasasa Privacy Policy — English (condensed reference translation)
1. Operator. Derrick Mortimer Noe (trading as Kasasa), 3-13-12 Kajiwara, Kamakura, Kanagawa 247-0063, Japan. Contact: kasasa.exp@gmail.com.
2. Information we collect. Account details (name, email, hashed password, organisation, department, role). Chat identifiers (LINE, Slack, WhatsApp, Telegram user IDs). Receipt images and the data extracted from them — merchant, date, amount, currency, tax rate, payment method, card brand and last four digits, qualified invoice registration number, attendee counts and names, purpose. Transit expense details. Calendar events (read-only, only if you enable the integration). Billing status and processor-issued identifiers — we never receive or store card numbers. Usage logs, IP address, browser and device information, cookies, and audit trails.
3. Purposes. Operating, maintaining and improving the service; authentication; extracting and checking receipt data; dashboards, analytics and exports; billing; notifications and digests; support; enforcing our Terms; incident investigation; aggregate statistics in non-identifying form; legal compliance.
5. Third-party disclosure. We do not disclose personal information to third parties without consent, except as required by law or in the limited circumstances set out in the Act on the Protection of Personal Information.
6. Processors and cross-border transfers. We use: Supabase (database and storage, hosted in Tokyo; US company), Vercel (hosting, US), OpenAI (receipt OCR and analysis, US — configured so your data is not used for training), Stripe (payments, US/Ireland), Resend (email, US), LINEヤフー (Japan), Slack/Salesforce (US), Meta (US), Telegram FZ-LLC (UAE), Google (US, calendar only if enabled). Transfers to processors outside Japan constitute cross-border transfers under Article 28 of the Act. Information on other countries' data protection regimes is published by the Personal Information Protection Commission.
7. Security. TLS in transit and encryption at rest; Row-Level Security isolating each organisation's data; AES-256-GCM encryption of third-party credentials; role-based access control; append-only audit logging; token expiry and rotation. Primary data is stored in Japan; some processing occurs abroad as listed above.
8. Sensitive personal information. We do not deliberately collect it. However, receipts you upload may be issued by clinics or pharmacies and may therefore contain health information, which is 要配慮個人情報 under Japanese law. You are responsible for obtaining the necessary consent from the individual before uploading such images. We recommend avoiding them.
9. Your employees' data. Where your organisation's users or third parties appear in submitted data, we act as a processor on your instructions. Obligations to notify and obtain consent from those individuals rest with you.
10–11. Cookies and retention. Authentication cookies are essential. We retain data as long as needed for the stated purposes; after account closure, data is deleted 90 days later, except where law requires longer retention. Export your data before closing your account.
12–14. Your rights. You may request notification of purpose, disclosure, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, and disclosure of third-party provision records. Contact us at the address above; we verify identity and respond without delay, free of charge. Breaches are reported to the Personal Information Protection Commission and affected individuals as required. Complaints may also be directed to the Commission at https://www.ppc.go.jp/.
15. Changes. We may update this policy; changes take effect on posting, except where law requires consent.
Effective date: 15 August 2026