Privacy Policy

Last updated: 2026-07-24 · Operated by Meliorra Inc.

1. Controller

This Privacy Policy describes how Meliorra Inc. (“we”) handles personal and other user information in the “Tieron” service. We are the business operator handling personal information under Japan’s APPI.

2. Information we collect

(1) Account: email address, authentication data (passwords are managed encrypted by the authentication platform; we never hold them in plain text), language preference. (2) Company profile: company name, employee count, industry, business description, and the terms-consent record (timestamp and version). (3) Third-party details you enter: supplier contacts’ names and email addresses for SAQ invitations, and contact details contained in uploaded lists. (4) SAQ responses, which may contain personal information such as site details or contact names. (5) Usage logs: anonymous-ID-based event logs and access timestamps.

3. Purposes

Authentication, providing / maintaining / improving the Service, sending SAQ invitations and important notices, support, preventing abuse and securing the Service, anonymized usage statistics, and legal compliance. We do not use the data for other purposes.

4. Uploaded lists and spend data

Scoring runs in your browser. Saved lists are stored under your account and readable only by you. Spend figures are private tenant data — never displayed publicly, shared with other users, or provided to third parties. For sanctions screening, only supplier names and countries (never spend) are sent to our matching service, processed in memory, and not stored.

5. Processors and cross-border transfer

We entrust processing to: Google Cloud Platform / Firebase (hosting, authentication, database; primarily US regions) and Resend (email delivery; US). These processors are located outside Japan (primarily the US). We verify their security posture and bind them contractually to appropriate handling. Information about the data-protection regimes of the processors’ countries is available on request.

6. Third-party provision

We do not provide personal information to third parties without consent, except as required by law, and we never sell it. Company-level information a supplier chooses to disclose (name, country, risk values) may be shown to buyers in a trading relationship as a function of the Service, subject to the supplier’s disclosure settings, including masking.

7. Security

TLS encryption in transit, owner-only access control enforced by Firestore security rules, credential management by the authentication platform, and least-privilege operations. In the event of a breach we will notify affected individuals and the Personal Information Protection Commission as required by law.

8. Retention and deletion

We retain user information for as long as needed for the purposes above. Upon an account deletion request, we delete User Data and personal information within a reasonable period, except where retention is legally required.

9. Your rights

You may request notification of purposes, disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of third-party provision of your personal information via the contact below. We will verify your identity and respond without undue delay as required by law.

10. Cookies and local storage

We use browser local storage for session, language, and draft-saving purposes. Usage is measured with first-party, anonymous-ID event logs; we do not use third-party advertising cookies.

11. Changes

Changes to this Policy are announced in the Service; material changes are additionally notified by appropriate means such as email.

12. Contact

Meliorra Inc., y.hagiwara@meliorra.co. See also the Terms of Service.

Back to Tieron