Privacy Policy
Last updated: 2026-07-24 · Operated by Meliorra Inc.
1. Controller
This Privacy Policy describes how Meliorra Inc. (“we”) handles personal and other user information in the “Tieron” service. We are the business operator handling personal information under Japan’s APPI.
2. Information we collect
(1) Account: email address, authentication data (passwords are managed encrypted by the authentication platform; we never hold them in plain text), language preference. (2) Company profile: company name, employee count, industry, business description, and the terms-consent record (timestamp and version). (3) Third-party details you enter: supplier contacts’ names and email addresses for SAQ invitations, and contact details contained in uploaded lists. (4) SAQ responses, which may contain personal information such as site details or contact names. (5) Usage logs: anonymous-ID-based event logs and access timestamps.
3. Purposes
Authentication, providing / maintaining / improving the Service, sending SAQ invitations and important notices, support, preventing abuse and securing the Service, anonymized usage statistics, and legal compliance. We do not use the data for other purposes.
4. Uploaded lists and spend data
Scoring runs in your browser. Saved lists are stored under your account and readable only by you. Spend figures are private tenant data — never displayed publicly, shared with other users, or provided to third parties. For sanctions screening, only supplier names and countries (never spend) are sent to our matching service, processed in memory, and not stored.
5. Processors and cross-border transfer
We entrust processing to: Google Cloud Platform / Firebase (hosting, authentication, database; primarily US regions) and Resend (email delivery; US). These processors are located outside Japan (primarily the US). We verify their security posture and bind them contractually to appropriate handling. Information about the data-protection regimes of the processors’ countries is available on request.
6. Third-party provision
We do not provide personal information to third parties without consent, except as required by law, and we never sell it. Company-level information a supplier chooses to disclose (name, country, risk values) may be shown to buyers in a trading relationship as a function of the Service, subject to the supplier’s disclosure settings, including masking.
7. Security
TLS encryption in transit, owner-only access control enforced by Firestore security rules, credential management by the authentication platform, and least-privilege operations. In the event of a breach we will notify affected individuals and the Personal Information Protection Commission as required by law.
8. Retention and deletion
We retain user information for as long as needed for the purposes above. Upon an account deletion request, we delete User Data and personal information within a reasonable period, except where retention is legally required.
9. Your rights
You may request notification of purposes, disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of third-party provision of your personal information via the contact below. We will verify your identity and respond without undue delay as required by law.
10. Cookies and local storage
We use browser local storage for session, language, and draft-saving purposes. Usage is measured with first-party, anonymous-ID event logs; we do not use third-party advertising cookies.
11. Changes
Changes to this Policy are announced in the Service; material changes are additionally notified by appropriate means such as email.
12. Contact
Meliorra Inc., y.hagiwara@meliorra.co. See also the Terms of Service.