This policy explains how MeetMeetNow handles your personal information.
1. About Us (Business Operator Handling Personal Information)
With respect to the handling of personal information in connection with the "MeetMeetNow" service (the "Service"), the business operator handling personal information under the Act on the Protection of Personal Information (the "APPI") is the following company (the "Company," "we," "us," or "our"). The Company is responsible for handling users' personal information appropriately and acquires, uses, and manages users' personal information in accordance with this Privacy Policy (this "Policy").
Trade name: MeetMeetNow, Inc.
Corporate number: 2011001170861
Head office address: Shibuya Dogenzaka Tokyu Building 2F-C, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo 150-0043
Representative: Kazuki Nishijima
Established: June 25, 2025
Business activities: Development and operation of a matching application
With respect to the personal information that the Company acquires in providing the Service, the Company specifies the purpose of use and handles such information appropriately within the scope necessary to achieve that purpose. Under the management framework that the Company has established for the handling of personal information, the Company endeavors to protect the rights and interests of its users.
The Company provides the Service as "in-person, real-time, instant matching at a designated meeting spot" in more than 4,000 cities across 194 countries, and, by its nature, the Service handles the personal information of users located around the world. The Service operates as an internet dating-introduction business and has filed a notification with the Public Safety Commission via the competent police authority (notification number 2025-104-0138), and the Company fulfills age-verification and other obligations under applicable laws and regulations.
Contact point for inquiries regarding the handling of personal information: For inquiries regarding the contents of this Policy, the Company's handling of personal information, requests for disclosure and the like, or any other matters, please contact us by email (contact[@]meetmeetnow[.]com) or via the inquiry form within the Service (/contact_us). Depending on the nature of the inquiry, we will respond within a reasonable period after verifying your identity.
Although the Company provides the Service broadly to users overseas as well, at present the Company has not appointed an EU representative or a UK representative under Article 27 of the EU General Data Protection Regulation (GDPR), nor a Data Protection Officer (DPO). Should circumstances arise that require such appointments, we will revise this Policy and provide separate notice.
2. Scope of Application and Eligibility
This Policy applies to the handling of users' personal information on the website, mobile and other applications relating to the Service operated by the Company, and on all services and features that the Company provides in connection therewith (collectively, the "Service"). When a user begins using the Service, the user is deemed to have understood the contents of this Policy and to have consented to the handling of personal information in accordance with it. For the general terms and conditions of use of the Service, please also refer to the separately established Terms of Service.
The Service may be used only by persons aged 18 or older. The Company does not intend the Service for persons under the age of 18 and does not knowingly acquire personal information from persons under the age of 18. As described below, a user's age is verified by the Company's review of an image of an official identification document, such as a passport, driver's license, or national ID card. Regardless of whether a parent or other legal guardian has given consent, persons under the age of 18 may not use the Service. If it comes to light that we have acquired the personal information of a person under the age of 18, the Company will promptly delete such information and take the necessary measures. For details on the handling of children and minors, please also refer to "18. Children and Minors" below.
The Service may include transitions to websites and services operated by third parties other than the Company (including payment providers' pages and other external links). The handling of personal information on such third-party sites and services is outside the scope of this Policy, and the Company bears no responsibility for it. When using such third-party sites and services, please review the privacy policies and the like of each operator. This Policy applies only to the personal information that the Company handles as a business operator handling personal information.
3. Categories of Personal Information Collected
In providing the Service, the Company acquires the following categories of personal information. The items acquired may differ depending on a user's usage and settings.
(1) Account and profile information Name (username), age (including the age bracket based on date of birth), gender, email address, profile photo, and the preferences a user sets for matching (the preferred gender of the other party, the bidirectional preferred age range, and the like). These are acquired in order to create and manage accounts and to provide the matching feature.
(2) Images of official identification documents For identity verification and age verification, images of passports, driver's licenses, national ID cards, or other official identification documents. The Company's administrators visually review these images and make determinations to approve, reject, or assign a dangerous flag. The images under this item are acquired and used solely for the purposes of identity verification, age verification, and fraud prevention, and are handled with particular care (see "7. Information Requiring Careful Handling" below).
(3) Location information Country-level location information determined based on the user's IP address, and, where the user grants permission, precise GPS location information obtained via the browser. Acquisition of GPS location information is optional, and where it is not permitted, the Company falls back to a determination based on the IP address. Location information is used to match users located in the same country and city.
(4) Matching attributes and behavioral information Matching participation status (whether a user is participating), matching history, preferences, usage and operation history of the Service, and technical information relating to the device and browser (device information, browser type, and the like). These are acquired in order to perform matching, to maintain and improve the quality of the Service, and to prevent fraud.
(5) Payment and transaction information In connection with the payment of male users' monthly fees, transaction information acquired or confirmed through PayPal, the payment provider (the success or failure of the transaction, transaction identifiers, invoice number, payment amount and currency, the taxing jurisdiction, information necessary to issue a receipt, and the like). Full card information, such as credit card numbers, is processed by PayPal, and the Company does not receive or store it.
(6) Contact and report information The contents of inquiries and communications, and, where a user reports another user, the contents of the report (including the reason for the report). These are acquired and used to ensure safety and to respond to misconduct and harm.
(7) Security information Information relating to two-factor authentication (TOTP) and backup codes that a user optionally configures, and information relating to login and sessions. These are acquired to prevent unauthorized use of accounts.
Of the above, images of official identification documents and precise GPS location information are handled by the Company with particular care, in light of their significant impact on the rights and interests of users. The Company's handling of identification document images is limited to visual confirmation by administrators, and no automated matching of biometric data is performed. For details, including the Company's view that the handling of this information does not constitute a special category of personal data within the meaning of Article 9 of the GDPR, please refer to "7. Information Requiring Careful Handling" below.
4. Sources of Information
The Company acquires personal information from the following sources.
(1) Information acquired directly from the user When a user registers an account, uploads a profile photo and an image of an official identification document, sets preferences, makes an inquiry or contacts the Company, reports another user, or carries out a payment procedure, we acquire the information that the user enters, provides, or transmits. This information is provided directly by the user in order to provide the features of the Service.
(2) Information acquired automatically from the user's device and browser When a user accesses the Service, we automatically acquire the IP address (including the country-level location determined from it), precise location information where the user has permitted acquisition of GPS location information in the browser, and information relating to the device and browser as well as usage information, through cookies, sessions, and other technical means. For details on cookies, sessions, and tracking, please refer to "17. Cookies, Sessions, and Tracking" below.
(3) Information acquired from service providers (processors) From PayPal, to which payment processing is entrusted, we acquire the information necessary to confirm a transaction (the success or failure of the transaction, transaction identifiers, payment amount, and the like). This is acquired to confirm that a user's payment has been completed normally and to grant eligibility to use the Service.
5. Notice at Collection
When acquiring personal information from a user, the Company notifies the user of, or publicly announces, the purpose of use in a manner that is easy for the user to understand, at the specific point at which the acquisition takes place. This enables the user to confirm, at the time of acquisition, what information is acquired and for what purpose.
Specifically, in the following situations, we present a notice or explanation corresponding to the acquisition concerned.
At the time of account registration: In acquiring account and profile information such as name, age, gender, and email address, we indicate the purpose of use and present links to this Policy and to information regarding users' rights and opt-out.
When the GPS location permission dialog is presented: Acquisition of precise location information via the browser is carried out only after obtaining the user's permission through the permission dialog displayed by the browser. If permission is not granted, we fall back to a country-level determination based on the IP address.
When an official identification document is uploaded: In acquiring the image of the identification document, we explain that its purpose is identity verification, age verification, and fraud prevention, and explain the handling of the image (such as that it will be promptly deleted after the determination is completed).
At the time of registration, the Company presents links so that users can access the full text of this Policy as well as explanations regarding users' rights and the cessation of sale or sharing (opt-out). Through these notices and links, users can confirm at any time how personal information is handled in the Service.
6. Purposes of Use and Legal Bases
The Company handles the personal information it acquires for the following purposes of use (purposes of use under the APPI). For users to whom the General Data Protection Regulation of the European Union (EU) and the United Kingdom (UK) (the GDPR and the UK GDPR; collectively, the "GDPR") applies, we also indicate the legal basis for the processing corresponding to each purpose of use (each item of Article 6(1) of the GDPR). The Company does not handle personal information beyond the scope necessary to achieve the purposes of use set out here.
(1) Provision and operation of the matching service To provide in-person, instant matching at a designated meeting spot, to manage participation status, to establish a Dating (meet-up) and notify the parties thereof, to reload the other party's screen in real time, and to perform the incidental account management and provision of the Service, we handle name (username), gender, age and preferred age range, location information (country and city), participation status, profile photo, and the like. - Purpose of use under the APPI: provision of the Service, management and authentication of accounts, establishment and notification of meet-ups - Legal basis under the GDPR: performance of a contract with the user (Article 6(1)(b)). This is processing necessary to provide the Service.
(2) Identity verification and age verification Because the Service may be used only by persons aged 18 or older, we require all users to upload a profile photo and an image of an official identification document such as a passport, driver's license, or national ID card, and the Company's administrators visually review these and approve, reject, or assign a dangerous flag. Identity verification and age verification are intended to prevent unauthorized use and to verify age; they are not intended to guarantee safety or to investigate criminal history. Images of official identification documents are merely visually confirmed by the Company's administrators, and no automated matching of facial recognition or other biometric data is performed. Accordingly, such images do not constitute a special category of personal data under Article 9 of the GDPR, and their handling is not premised on the user's explicit consent. - Purpose of use under the APPI: verification of eligibility (age), identity verification, prevention of unauthorized use - Legal basis under the GDPR: for age verification, compliance with a legal obligation to which the Company is subject (Article 6(1)(c)), such as the fulfillment of the age-verification obligation of an internet dating-introduction business under the Act on Regulation of Acts of Soliciting Children Using Internet Dating Services and the like (the Act on Regulation of Internet Dating Services). For the prevention of unauthorized use, the legitimate interests of the Company and its users in ensuring the safety of the Service and its users (Article 6(1)(f)).
(3) Payment and tax processing To process male users' monthly fees, to handle payments (payment via a single monthly capture through PayPal; this is not auto-renewal but a method by which the fee is paid afresh manually each month), to issue receipts, and to calculate tax amounts and create and retain tax records, we handle information relating to payment (payment identifiers, invoice number, amount, taxing jurisdiction, payment status, and the like) and usage-related information. The Company does not receive or store full card information such as credit card numbers; such information is processed by PayPal. - Purpose of use under the APPI: billing and collection of fees, issuance of receipts, tax processing and the creation and retention of records under tax law - Legal basis under the GDPR: performance of a contract with the user (Article 6(1)(b); collection of fees and provision of the Service), and compliance with legal obligations such as record retention under tax and accounting laws (Article 6(1)(c)).
(4) Ensuring safety, fraud prevention, and handling of reports To ensure safety in in-person meetings between users, to detect and prevent misconduct, impersonation, and violations of the terms, to receive, investigate, and respond to reports from users (including reports concerning serious in-person harm such as sexual assault, violence, stalking, minors, drugs, theft, and fraud), and to assign a dangerous flag to a reported or rejected user, we handle the relevant information. The Company does not conduct any investigation of criminal history or any inquiry into sex offender information. - Purpose of use under the APPI: ensuring the safety of users, prevention of misconduct, receipt, investigation, and handling of reports - Legal basis under the GDPR: the legitimate interests of the Company and its users in ensuring the safety of the Service, its users, and third parties and in preventing fraud (Article 6(1)(f)), and compliance with a legal obligation where required under applicable laws (Article 6(1)(c)).
(5) Communications with users To send notifications of established matches, notifications of the results of identity verification, notifications regarding payments and receipts, important announcements, responses to inquiries, and other communications necessary for the operation of the Service, we handle email addresses and the like. - Purpose of use under the APPI: important notices and communications regarding the Service, responding to inquiries - Legal basis under the GDPR: performance of a contract with the user (Article 6(1)(b)), and the legitimate interest in smooth operational communications (Article 6(1)(f)).
(6) Compliance with laws and preservation of rights To comply with applicable laws and the requests of administrative agencies, courts, and other competent authorities, to protect the Company's rights and property and the safety of users and third parties, to respond to disputes, and to enforce the Terms of Service, we handle or disclose personal information to the extent necessary. - Purpose of use under the APPI: legal compliance, handling of disputes, protection of the rights and interests of the Company and third parties - Legal basis under the GDPR: compliance with a legal obligation (Article 6(1)(c)), and the legitimate interest in the establishment, exercise, and defense of the Company's rights (Article 6(1)(f)).
(7) Analysis and improvement of the Service To operate the Service stably, to maintain and improve quality, to enhance features, and to identify and resolve defects, we handle information relating to usage. - Purpose of use under the APPI: maintenance and improvement of the Service, quality improvement - Legal basis under the GDPR: the Company's legitimate interest in improving and maintaining the Service (Article 6(1)(f)).
Where the Company carries out processing in reliance on legitimate interests, the Company does so after weighing whether those interests are overridden by the interests, rights, and freedoms of the user. In accordance with "15. Users' Rights and How to Exercise Them" below, users may object to such processing on grounds relating to their particular situation.
7. Information Requiring Careful Handling (Precise Location and Identification Document Images)
The Company handles precise GPS location information and images of official identification documents with particular care as highly sensitive information. However, as explained below, this information does not constitute a special category of personal data under Article 9 of the GDPR (equivalent to special care-required personal information under the APPI).
Images of official identification documents For identity verification and age verification, users upload images of official identification documents such as passports, driver's licenses, or national ID cards. Such images are only visually confirmed by the Company's administrators, and the Company does not perform automated matching of facial recognition or other biometric data (the mechanical processing of biometric information for the purpose of uniquely identifying an individual). Accordingly, such images do not constitute a special category of personal data under Article 9(1) of the GDPR, and the user's explicit consent is not required for their handling. Processing of such images is based on compliance with the legal obligation regarding age verification (Article 6(1)(c)) and the legitimate interest in fraud prevention (Article 6(1)(f)) (for details, see "6. Purposes of Use and Legal Bases (2)"). After the identity-verification determination (approval or rejection) is completed, such images are promptly deleted, and only a minimal record is retained as evidence that verification was carried out (for details on the retention period, see "12. Retention Periods").
Precise GPS location information As a rule, the Service determines a user's country based on the user's IP address. In addition, for the purpose of selecting the nearest city, the Service may obtain precise GPS location information via the browser. Acquisition of GPS location information is optional, and where the user declines acquisition in the browser's permission dialog or where there is no response, the Company falls back to a country determination based on the IP address. Location information is used solely to match users located in the same country and city, and raw coordinates are never displayed to the other party. Precise GPS location information does not constitute a special category of personal data under Article 9 of the GDPR, but the Company handles it with care as highly sensitive information.
Rights of California, USA users Users in the state of California, USA may, under the California Consumer Privacy Act (CCPA/CPRA), have the right to request that the use and disclosure of sensitive personal information be limited to certain purposes permitted by that law. The Company uses precise location information and information for identity verification solely for the limited purposes of identity verification, age verification, fraud prevention, and provision of the Service, and does not use sensitive personal information beyond these purposes. For how to exercise rights, please refer to "15. Users' Rights and How to Exercise Them" and "16. Cessation of Sale and Sharing (Opt-Out)."
Future changes to handling If the Company introduces automated matching of biometric data such as facial recognition in the future, such processing would constitute the handling of a special category of personal data under Article 9 of the GDPR, and the Company will carry it out only after satisfying the additional legal requirements, including obtaining the user's explicit consent, prior to its implementation.
8. Automated Processing and Matching
The Service performs certain automated processing in order to present matching candidates to users.
How matching works When a user sets their matching participation status to on (participating), the Service selects another user who simultaneously satisfies all of the following conditions and presents them as a candidate for a meet-up (Dating). - Participation status: the other party is also participating - Location: located in the same country and the same city - Age: mutually matching the preferred age ranges of both parties - Gender: mutually matching the gender preferences of both parties - For male users, that payment is within a valid period, and that the other party is not someone with whom a meet-up has ever been established before (a match between the same two people occurs only once in a lifetime)
Among the users satisfying the above conditions, the user whose wait began earliest is selected as the other party, a meet-up is created and both parties are notified, and the other party's screen is reloaded in real time.
No decisions based solely on automated processing The above matching presents matching candidates to users, and the Company does not make decisions based solely on automated processing that produce legal effects concerning the user or similarly significantly affect the user (automated individual decision-making within the meaning of Article 22 of the GDPR). The establishment of a match is not guaranteed.
User control Users can themselves set their gender preference, preferred age range, meeting spot (city), and the like, and can control their participation or non-participation in matching at any time by toggling their participation status. In this way, users can decide for themselves the extent to which they are subject to automated processing.
9. Provision to Third Parties (Service Providers)
To the extent necessary to provide and operate the Service, the Company entrusts the handling of, or provides, personal data to the following external service providers (entrusted parties) in accordance with their respective roles. With each entrusted party, the Company concludes an outsourcing agreement (including a data processing agreement) to ensure the safe management of personal data and its handling within the scope of the purpose of use in accordance with applicable laws, and exercises necessary and appropriate supervision over the entrusted parties. - PayPal: payment processing for monthly billing (execution of payments through PayPal Orders v2). It handles the information necessary for payment. Card information such as credit card numbers is processed by PayPal, and the Company does not receive or store it in full. - Amazon Web Services (AWS): provision of the cloud services that form the foundation of the Service. We use it for the storage of images (including profile photos and images of official identification documents), the delivery of email, real-time notifications such as the establishment of matches, and features for country determination based on the IP address. - Google (Google Translate v2): automatic translation of city and country names. It handles information within the scope necessary for this feature. - Quaderno: acquisition of tax rates used to calculate tax amounts, and the creation and retention of tax records. - ExchangeRate-API: acquisition of exchange rates for conversion to US dollars.
Other disclosures In addition to the foregoing entrustments, the Company may disclose personal data to the extent necessary where any of the following applies. - Where required by law, or where a lawful request is received from an administrative agency, court, or other competent authority - Where necessary to protect the life, body, property, or rights of the Company, a user, or a third party and it is difficult to obtain the consent of the individual, or where otherwise necessary to prevent misconduct or ensure safety - Where personal data is provided in connection with the succession of a business due to a merger, company split, business transfer, or other cause (in which case the handling by the successor shall be in accordance with this Policy)
No sale of personal data The Company does not sell users' personal data to third parties. The provision to the entrusted parties above is in each case carried out within the scope necessary to provide and operate the Service, and is not a sale to third parties for purposes such as advertising. For details on sale and sharing, please refer to "16. Cessation of Sale and Sharing (Opt-Out)," and for cross-border transfers, please refer to "11. Cross-Border Data Transfers."
10. Information Disclosed to a Match
The Service provides in-person, real-time, instant matching at a designated "meeting spot." By its nature, when a match is established, certain information about a user's profile is disclosed to the user who becomes the other party. Specifically, the user's profile photo, age, gender, and meeting spot (the gathering place within the same country and city) are displayed to the other party. This is information within the scope necessary for users to meet in person safely and smoothly, and is based on what the user has registered and set in the Service.
When a match is established, the Company sends a notification of the establishment to both users. The notification is made by a real-time screen update (an update of the other party's screen) and by email. This allows both users to confirm the fact that a match with the other party has been established and the information necessary for the meet-up. The Company does not disclose the other party's precise location information (raw coordinates) to a user. Location information is used only internally for matching within the same country and city.
As a safety note, the information that the Service discloses to the other party when a match is established is limited to the foregoing, and the Company does not automatically disclose to the other party a user's phone number, social media account, address, or other contact details or personally identifiable information. Whether and to what extent to share such additional information with the other party is to be decided at the user's own judgment and responsibility. When meeting in person, please bear in mind that the other party may not necessarily be a trustworthy person, and exercise caution in providing contact details and other sensitive information. Although the Company conducts identity verification, it does not guarantee the interactions between users or the relationships after meeting in person, and bears no responsibility for the handling of information disclosed or shared between users.
11. Cross-Border Data Transfers
Because the Service is provided globally, users' personal information may be transferred across borders or processed on servers located outside the user's country. The Company uses external services for image storage and delivery, real-time notifications, location headers, payment, translation, email delivery, and the like, and in connection with this processing, users' personal information is processed in the United States (Amazon Web Services, Google, and PayPal) and in Japan.
When transferring the personal information of users in the European Union (EU), the UK, or other parts of the European Economic Area (EEA) to the United States, the Company implements appropriate safeguards. Amazon Web Services and Google, the transferees, are certified under the EU-US Data Privacy Framework (EU-US DPF) (including its UK Extension and Swiss Extension), and the Company ensures an adequate level of data protection at the transferee by relying on DPF compliance under contracts with these entrusted parties, or on Standard Contractual Clauses (SCCs).
With respect to users in Japan, where the Company provides personal data to a third party located in a foreign country (including the entrusted parties located in the United States referred to above), the Company implements the necessary measures under Article 28 of the APPI. This includes providing the necessary information so that the individual can understand the handling of personal information at the transferee, or confirming that the transfer is to a recipient that has established a framework conforming to the standards set forth in that Act.
12. Retention Periods
The Company retains personal information only for the period necessary to achieve the purpose of use, and after that period has elapsed or the purpose of use has been achieved, deletes it without delay, except where retention is required by law. The retention periods for the principal information are as follows.
Account information (profile, registration information, settings, and the like): retained while the user is using the Service. Upon withdrawal (deletion of the account), this information is deleted, except for information subject to a statutory retention obligation.
Images of official identification documents (passports, driver's licenses, national ID cards, and the like): promptly deleted after the identity-verification determination (approval or rejection) is completed. As evidence of identity verification, the Company retains only a minimal record of the fact that verification was carried out and its result, and does not continuously store the identification document images themselves.
Accounting books and tax-related documents (payment records, receipts, tax records, and the like): retained for 7 years in order to satisfy statutory retention obligations.
Even after withdrawal, information whose retention is required by law (including accounting and tax-related documents), as described above, is retained until the prescribed period has elapsed. Information for which these statutory retention periods have elapsed is appropriately deleted or anonymized in accordance with the Company's policy.
13. Security Measures
The Company implements necessary and appropriate security measures to prevent the leakage, loss, or damage of the personal information it handles and to otherwise manage the security of personal information. Specific measures include the following, from technical and organizational perspectives.
Encryption of communications: communications between a user's device and the Company's services are encrypted using TLS (Transport Layer Security) to prevent interception and tampering in transit.
Encryption at rest: confidential information (sensitive information such as two-factor authentication secrets) is encrypted and managed at rest.
Access restrictions on identification document images: access to images of official identification documents uploaded for identity verification is limited to the administrators in charge of review, with access controls applied.
Randomization of file names: uploaded images are stored with randomly assigned file names that are difficult to guess, to prevent unauthorized guessing or acquisition by third parties.
Two-factor authentication (optional): to strengthen the protection of their account, users may optionally enable two-factor authentication using a one-time password (TOTP) from an authentication app and backup codes. In addition, login sessions expire after a certain period (one week by default), and the retention period when the option to stay logged in is selected is also limited (two weeks by default).
Supervision of entrusted parties: where the handling of personal information is entrusted externally (payment, image storage, email delivery, and the like), we select operators that implement sufficient security measures and exercise appropriate supervision through contracts and the like.
The Company continuously reviews these measures and endeavors to improve them. However, with respect to the transmission of information over the internet and its electronic storage, complete security cannot be guaranteed. Please understand in advance that, although the Company implements a reasonable level of security measures, it cannot completely eliminate the possibility of any unauthorized access or information leakage.
14. Notification in the Event of a Breach
Notification to supervisory authorities If the Company becomes aware that a leakage, loss, damage, or other security incident (a "breach") has occurred, or is likely to have occurred, with respect to the personal information or personal data it handles, the Company will, in accordance with the applicable laws of each country, notify the prescribed supervisory authority without delay.
For matters to which Article 33 of the GDPR applies, we will notify the competent supervisory authority, in principle, within 72 hours of becoming aware of the breach. However, this does not apply where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where notification cannot be made within 72 hours, the notification will be accompanied by the reasons for the delay.
For matters to which Japan's APPI applies, where the breach constitutes a reportable event prescribed by that Act and related cabinet and ministerial ordinances and rules, such as a breach involving special care-required personal information or a breach that is likely to have been carried out for an improper purpose, we will report a preliminary report and a definitive report to the Personal Information Protection Commission (PPC) within the prescribed deadlines.
Notification to affected users Where a breach is likely to significantly harm the rights and interests of users (including where it results in a high risk within the meaning of Article 34 of the GDPR), the Company will, in accordance with applicable laws, endeavor to notify the affected users themselves, by written notice, email, or other appropriate means, without undue delay, of the fact of the breach and of information on the measures users can take.
The Company will examine and implement the facts of the breach and measures to prevent recurrence, and will publicly announce an overview thereof as necessary.
15. Users' Rights and How to Exercise Them
Users have the following rights with respect to their personal information and personal data, to the extent provided by applicable laws. The Company responds in good faith to the exercise of these rights.
Rights under Japan's APPI Users to whom that Act applies, including users located in Japan, may make the following requests with respect to the Company's retained personal data (the "requests for disclosure and the like"). - Requests for notification of the purpose of use - Requests for disclosure of retained personal data (including disclosure by a method involving the provision of an electromagnetic record) - Requests for correction, addition, or deletion where the content is not factual - Requests for cessation of use or erasure - Requests for cessation of provision to third parties
Rights under the GDPR (EEA, UK, etc.) Users to whom the GDPR or the UK GDPR applies have the following rights. - The right to access (disclosure of) the personal data being processed - The right to rectification of inaccurate personal data - The right to erasure of personal data (the so-called "right to be forgotten") - The right to restriction of processing - Data portability (the right to receive the data one has provided in a structured, commonly used, and machine-readable format, or to have it transmitted to another controller) - The right to object to processing - The right to withdraw consent at any time with respect to processing based on consent (this does not affect the lawfulness of processing prior to withdrawal)
Rights under the CCPA/CPRA (California, etc.) Users to whom the law of the state of California, USA or similar laws apply have the following rights. - The right to know and access the categories and specific contents of personal information that the Company acquires, uses, and discloses - The right to request deletion of personal information - The right to request correction of inaccurate personal information - The right to opt out of the "sale" or "sharing" of personal information - The right not to be subjected to unlawful discrimination for having exercised these rights - The right to exercise rights through an authorized agent
How to exercise rights If you wish to exercise the above rights, please contact us via the email address stated at the end of this Policy (contact[@]meetmeetnow[.]com) or via the Company's inquiry form (/contact_us). To prevent impersonation and to protect the rights of the individual, the Company verifies, to the extent necessary, that the request is from the individual (or a lawful agent). For requests by an agent, we may ask for documents evidencing the agent's authority.
After receiving a request, the Company responds within the period prescribed by applicable laws (for the GDPR, in principle within one month; where the matter is complex or the like, this may be extended within the scope of the law, in which case we will notify you with the reasons; for the CCPA/CPRA, in principle within 45 days, which may be extended within the scope of that law). Where a statutory requirement or exception applies, we may be unable to respond to all or part of a request, in which case we will notify you of the reasons.
Lodging a complaint with a supervisory authority Where a user is dissatisfied with the Company's response or where otherwise necessary, the user has the right to lodge a complaint with the supervisory authority of their country of residence or the place where the infringement occurred. In Japan, this is the Personal Information Protection Commission (PPC); in the UK, the Information Commissioner's Office (ICO); and in the EEA, the competent supervisory authority of the user's place of habitual residence, place of work, or place where the infringement occurred. Lodging such a complaint does not preclude contacting the Company.
16. Cessation of Sale and Sharing (Opt-Out)
The Company does not sell or "share" personal information The Company does not "sell" users' personal information to third parties in exchange for money or other consideration. Nor does the Company disclose personal information to third parties for the purpose of "sharing" within the meaning of the California Privacy Rights Act (CPRA), that is, cross-context behavioral advertising (advertising that tracks behavioral history across the services a user uses).
The Company has external operators handle personal data only within the scope of the outsourcing necessary to provide our service, as described in "9. Provision to Third Parties (Service Providers)" of this Policy, such as payment, tax records, translation, email delivery, image storage, real-time communications, location determination, and exchange-rate acquisition, and these do not constitute "sale" or "sharing."
Honoring Global Privacy Control (GPC) signals Where the Company receives a Global Privacy Control (GPC) or other valid opt-out signal sent by a user's browser or the like, the Company honors it as an expression of an opt-out intent under applicable laws. However, as stated above, because the Company does not sell or share personal information in the first place, there is no substantive change to the processing the Company carries out.
How to opt out and make inquiries Residents of California and other users with rights under applicable laws, including those who wish to request cessation of sale or sharing, may contact us via the email address stated at the end of this Policy (contact[@]meetmeetnow[.]com) or via the inquiry form (/contact_us). The Company does not refuse to provide the service, discriminate in fees or conditions, or otherwise treat you disadvantageously on the grounds of your exercise of such rights.
17. Cookies, Sessions, and Tracking
Cookies used by the Company The Company uses the following essential cookies and similar technologies only to the extent necessary to provide the Service. These are indispensable for maintaining a user's login state, retaining the display language, and providing other basic features of the Service, and they do not track users' behavior for advertising purposes. - Session cookies: used to identify a logged-in user and maintain the authentication state. The validity period is up to one week. - Stay-logged-in cookies: used to skip login on a return visit where the user has selected "stay logged in." The validity period is up to two weeks. - Language preference cookies: used to remember the display language selected by the user and to display in the same language thereafter. The Service supports 59 languages.
No third-party advertising tracking The Company does not place on the Service any trackers for behavioral targeting advertising by third-party advertising networks, or any third-party cookies for the purpose of cross-context behavioral advertising. The Company's cookies are all used for the essential features described above.
How to control cookies Users can, through their browser settings, choose whether to accept cookies, or delete stored cookies. However, if you disable or delete essential cookies, you may be unable to use some or all of the Service normally, such as being unable to maintain your login state or having your language settings not saved.
18. Children and Minors
The Service is intended only for persons aged 18 or older. Regardless of whether a parent or other legal guardian has given consent, persons under the age of 18 may not use the Service. The Company verifies a user's age in the course of identity verification using an image of an official identification document (passport, driver's license, national ID card, and the like).
The Company does not knowingly acquire personal information from persons under the age of 18. If, in the course of identity verification or otherwise, it comes to light that a user is under the age of 18, the Company will terminate that user's account and promptly delete the personal information acquired, except for the minimal records whose retention is required by law.
If you believe that the personal information of a person under the age of 18 may have been provided to the Company (for example, where a guardian becomes aware of registration by a child), please promptly contact the Company via the email address stated at the end of this Policy (contact[@]meetmeetnow[.]com) or via the inquiry form (/contact_us). After confirmation, the Company will take the necessary deletion and other measures.
19. Changes to This Policy
The Company may revise this Privacy Policy from time to time in response to amendments to laws, changes in the guidelines of supervisory authorities, changes in the content or operation of the Service, or the Company's operational needs.
When changing this Policy, the Company will post the revised content on the Service. Where we make a change that materially affects the rights and obligations of users, we will endeavor to give prior notice with a reasonable notice period, by posting on the Service, by email, or by other appropriate means.
The Company will at all times post the latest version of this Policy on the Service, together with its effective date (the date of last revision). This Policy is provided in 59 languages, but where there is a difference in meaning among the language versions, the Japanese version shall be the authoritative text and its interpretation shall prevail. Please review the latest version from time to time. If you continue to use the Service on or after the effective date of a change, you will be deemed to have consented to the revised Policy.
20. Contact Us
For inquiries, comments, and complaints regarding this Privacy Policy or the Company's handling of personal information, and for requests to exercise the rights described above, please contact the point of contact below.
Business operator handling personal information Trade name: MeetMeetNow, Inc. Corporate number: 2011001170861 Head office address: Shibuya Dogenzaka Tokyu Building 2F-C, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo 150-0043 Representative: Kazuki Nishijima
The Company will respond to inquiries and requests it receives faithfully and appropriately in accordance with applicable laws. For identity verification, we may separately ask you to provide necessary information.