Privacy Policy

Effective date: August 1, 2026
Last revised: August 28, 2026

Data controller

In this Policy, the “Platform” means SlotVail operated by the provider below. This matches the Legal Notice and Terms of Use operator section.

  • Provider: SlotVail Operations Office
  • Responsible person: Shohei Sano
  • Address: 3-12-15 Toyonaka-cho, Izumiotsu-shi, Osaka 595-0023, Japan
  • Email: support@slotvail.com
  • Contact form: contact.html

Section 1: Automated Verification and Data Collection

1. When participants buy chat coins or register a card for auction authorization, payment runs through Stripe’s security review. Card authentication also completes practical identity and credit checks in the system.

2. To run those reviews and operate the Service, the Platform collects and manages email, user ID, profile photo (including single-initial avatars), country of residence (GeoIP from IP address), coin purchase history, and bid history.

Section 2: Complete Credit Card Data Protection

As a hard security rule, the Platform does not store raw credit card numbers, expiry dates, CVV codes, or identity-document images on its own servers. All payment data is sent directly to Stripe’s encrypted PCI-DSS compliant systems.

Section 3: Purposes of Information Use

Personal data is used only for the automated systems and service delivery below. It is not sold or reused for unrelated purposes.

1. Fully automatic display of language (selected locales) and currency based on the user’s location (IP).

2. Instant settlement of Uniform Price and Second-Chance Raffle outcomes on secure backend servers (Firebase) when an auction ends.

3. Fast delivery of win/draw notification emails via Resend within seconds after auction end or raffle completion.

4. Creating and publishing success stories (case-study pages) after auction end, when a host submits and the Platform approves. Details follow Section 7 of the Terms of Use and Section 6 of this Policy.

Section 4: Safe Third-Party Integration

Minimum necessary data is shared with carefully selected providers to keep the Service secure and automated. Credentials are kept in backend environment variables.

  • Stripe / Stripe Connect: Card payments, identity checks, and automatic split of settled amounts (after platform fee) to charities and hosts without the Platform holding funds beyond its fee.
  • Resend: Automatic delivery of win/draw emails worldwide (including QQ Mail, Gmail, etc.) from a test address (onboarding@resend.dev) and, later, a custom domain.

Section 5: Contact and privacy requests

1. Questions about this Policy, success-story content, and requests for access, correction, restriction, or deletion of personal data may be sent to the email above or via the contact form.

2. We may ask you to verify your identity (for example, by writing from your registered email) before processing a request.

Section 6: Success Story Data

1. To generate drafts and review publication, the Platform processes auction information (title, description, images, winning amount, charity settings, etc.), host profile data, and chat statistics.

2. Information that may be published on the internet as a success story is limited to what the host edits and selects, typically including:

  • Host display name and profile image (if set)
  • Auction title, description, images, winning amount, charity name, and partial or full donation setting
  • Chat counts/statistics and comment excerpts selected by the host (anonymized or shown by nickname)

3. Winners’, bidders’, and viewers’ real names, email addresses, home addresses, and payment details are generally not published in success stories. Comment excerpts are processed so individuals cannot be identified.

4. Publication requires host submission and Platform approval. Hosts may review and edit content before submission. Drafts are not generally public before approval.

5. Published success stories can be viewed by the general public on the Platform website. They may also be quoted or republished on social media, press releases, or advertising for case-study and marketing purposes.

6. Users who post chat comments are informed, by using the Service (and agreeing to the Terms and this Policy), that their comments may be quoted in a success story. By posting, users consent to the Platform quoting comments after anonymization or similar processing under this Policy.

7. Hosts or comment authors may request correction, deletion, or unpublishing of success-story content about them through the contacts in Section 5. Removal of third-party republication is not guaranteed.

Section 7: Global data management and deletion rights

Data is stored on Firebase (Google Cloud) distributed infrastructure and operated in the spirit of the EU GDPR and California CCPA. Users may request access, correction, or full account deletion (permanent erasure) of registered email and account data (including chat history) at any time, as described in Section 5.