Now Serving Our Story Menu Gallery Footprint Book Us Contact Us 日本語
← Nyanmeshi JAPAN

1. What We Access

Our tools connect to third-party platforms (TikTok, and Meta, which operates Instagram and Facebook) using OAuth 2.0 to publish content on behalf of our own business accounts. The data we handle is limited to: (a) OAuth access/refresh tokens and our own business-account identifiers; (b) standard web server logs generated by our hosting provider (GitHub Pages), which may include visitor IP addresses and user-agent strings; and (c) any information you voluntarily send us by email. We treat all such information as personal data where it relates to an identifiable individual. We do not access or collect the personal data of other platform users or of third-party accounts.

2. Purpose and Legal Basis

We process the limited data described above solely to authenticate with, and publish our own content to, our business accounts on TikTok, Instagram and Facebook, and to respond to enquiries. We rely on the consent of our authorised personnel and, where applicable, the "business contact information" and "legitimate interests" bases under the PDPA. We do not use this data for any other purpose without further notice and, where required, consent.

3. What We Do Not Do

4. Website Analytics

This website uses Google Analytics 4 (GA4) to understand aggregate visitor traffic: pages viewed, approximate geographic region (country/city level), referral source, and marketing-campaign attribution via UTM link parameters. This data is aggregated and is not used to identify individual visitors. We do not enable Google Signals, advertising personalization, or cross-site retargeting, and we do not combine analytics data with any other dataset we hold. Analytics only runs once we have configured a GA4 property; until then, no analytics script loads and no visitor data is collected by this mechanism. You can prevent GA4 from collecting your visit using a browser extension such as the Google Analytics Opt-out Browser Add-on, or by using an ad/tracker-blocking browser extension. Google's own handling of this data is governed by the Google Privacy Policy.

5. Data Storage and Retention

OAuth access tokens and API credentials are held in a private, access-controlled environment with reasonable security arrangements, and are transmitted only to the authorised platform APIs as required to operate the integration. We do not sell or disclose them to third parties. Tokens are retained only for as long as the integration is active. Upon revocation or disconnection, all associated tokens are deleted.

6. Data Deletion

The only data we store that is associated with platform accounts is OAuth tokens and our own account identifiers. You can trigger deletion of this data at any time by revoking our application's access through the platform's own settings:

Revocation immediately invalidates the affected tokens, which are then deleted from our environment. To request deletion directly, or to obtain confirmation of deletion, email emi.maekawa@nyanmeshi.com with the subject "Data Deletion Request." We will action and confirm such requests within 30 days. This page also serves as our Data Deletion Instructions URL for the purpose of Meta Platform requirements.

7. Data Breach Notification

We maintain reasonable security arrangements to protect data in our possession or control. In the event of a data breach that is assessed to be notifiable under the PDPA, we will notify the Personal Data Protection Commission as soon as practicable and in any case within 3 calendar days of making that assessment, and will notify affected individuals where the breach is likely to result in significant harm to them.

8. Third-Party Platforms

Our integrations operate under the respective privacy policies and developer terms of connected platforms. Our use of these APIs is also governed by the Meta Platform Terms and Developer Policies, and by the TikTok Developer Terms of Service and Content Sharing Guidelines. Please refer to:

9. Your Rights

Singapore residents may refer to the Personal Data Protection Act 2012 (PDPA) for rights regarding personal data. If you believe we hold any personal data about you, you may contact us at any time to: access or obtain a copy of your data; request correction of inaccurate data; withdraw consent to our continued use of your data (we will inform you of the likely consequences); or, where applicable under the PDPA, request portability of data you have provided.

We will respond to such requests as soon as reasonably possible, and in any event within 30 days of receiving a request and any information we reasonably require to process it. If we cannot respond within 30 days, we will inform you of the time by which we will respond.

If you are not satisfied with how we have handled your personal data, you may lodge a complaint with the Personal Data Protection Commission of Singapore (www.pdpc.gov.sg).

10. Data Protection Officer

Nyanmeshi JAPAN PTE. LTD. (UEN: 202536798D), registered at 175 Bukit Batok West Avenue 8, #06-273, Singapore 650175, has designated a Data Protection Officer responsible for ensuring compliance with the PDPA. The DPO may be contacted at: emi.maekawa@nyanmeshi.com, Attn: Data Protection Officer.

11. Governing Law

This Privacy Policy is governed by the laws of Singapore, including the Personal Data Protection Act 2012 (PDPA). The Personal Data Protection Commission (PDPC) is the relevant supervisory authority.

12. Changes

We may update this policy from time to time. The date at the top of this page reflects the most recent revision.

13. Contact

Questions? Email us at emi.maekawa@nyanmeshi.com.