Privacy Policy
Date of Establishment: August 7, 2026
Notice regarding this English translation: This document is an English translation of the Privacy Policy (プライバシーポリシー) of Wonder Ventures K.K. (ワンダーベンチャー株式会社). It has been prepared solely for reference purposes. The official Privacy Policy of the Company is the Japanese-language version. In the event of any discrepancy or inconsistency between the Japanese original and the following English translation, the Japanese original shall prevail in all respects.
Wonder Ventures K.K. (hereinafter the “Company”) sets forth in this Privacy Policy (hereinafter this “Policy”) for what purposes and in what manner the Company handles the personal information of users in connection with their use of the services operated by the Company (hereinafter the “Company Services”).
The Company complies with the Act on the Protection of Personal Information (Act No. 57 of 2003, including subsequent amendments; hereinafter the “APPI”), the Installment Sales Act, the Act on Prevention of Transfer of Criminal Proceeds and other relevant laws and regulations of Japan, and handles personal information appropriately. In addition, as a business operator that concludes contracts for the handling of credit card numbers, etc. under the Installment Sales Act, the Company handles personal information appropriately in accordance with the Guidelines for the Protection of Personal Information in the Credit Field.
This Policy explains the categories of personal information that the Company acquires, the purposes of use thereof, provision to third parties, methods of managing personal information, and the rights of the individual with respect to personal information. This Policy applies to visitors to the Company’s website, persons considering the use of the Company Services, merchants, and the representatives, officers, beneficial owners, employees and other related parties of merchants, as well as cardmembers and persons making inquiries to the Company. Even where the Company Services are not provided directly on the Company’s website, this Policy applies to personal information that the Company acquires and handles in connection with such services.
In this Policy, “User” means an individual or corporation (including merchants) that uses or is considering the use of the Company Services, the representatives, officers, beneficial owners, employees and other related parties thereof, cardmembers, visitors to the Company’s website, and persons making inquiries to the Company. Provisions concerning Users that are corporations also apply to the personal information of related parties of such corporations that the Company acquires.
1. Personal Information Handling Business Operator
Wonder Ventures K.K. is the business operator that acquires and handles the personal information of Users in connection with the services used by Users. For the Company’s representative, address and contact point for inquiries regarding personal information, please refer to Article 11.
2. Personal Information Acquired by the Company
The Company acquires the following personal information to the extent necessary to achieve the purposes of use set forth in Article 4 of this Policy.
(1) Identification information: name, date of birth, gender, nationality, address; for Users that are corporations, the corporate name, address and corporate number, as well as the names and dates of birth of their representatives, officers and beneficial owners, etc.
(2) Contact information: address or location, telephone number, e-mail address, place of employment or trade name, and other information relating to contact details
(3) Identity verification information: matters stated in, and images of, identity verification documents (driver’s license, residence card, passport, the front side of the Individual Number Card (My Number Card), etc.); facial images captured in the course of identity verification (eKYC); the purpose of the transaction; occupation or nature of business; information relating to beneficial owners; information as to whether the person falls under a person who holds an important public position in a foreign government, etc.
(4) Financial and transaction information: bank account information; details of settlements and transactions (date and time, amount, currency, merchant name, etc.); credit card numbers, etc. (card number, expiration date, etc.); the handling and usage status of cards; information relating to merchant agreements (application date, contract date, contract termination date, etc.); information relating to sales, receipts and billing; and financial information relating to screening (financial statements, tax payment certificates, matters stated in certificates of registered matters, etc.)
(5) Account and technical information: account ID, login history, IP address, device identifiers, information relating to browsers and operating systems, cookies and other identifiers, and usage history and operation logs of the Company Services
(6) Information relating to inquiries and applications: the content of inquiries or complaints and the history of responses thereto
Non-acquisition of Individual Numbers (My Numbers)
Because the Company is not in a position to process personal-number-related affairs prescribed in the Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures (hereinafter the “My Number Act”), the Company does not acquire, use or store Users’ Individual Numbers (My Numbers). Where an Individual Number Card (My Number Card) is used as an identity verification document, the Company acquires only the matters stated on the front side of the card and does not acquire the Individual Number. Where the Company receives a copy of a certificate of residence or any other document on which an Individual Number is stated, the Company will store such document after deleting the portion containing the Individual Number by a method that renders it unrecoverable. The corporate numbers of Users that are corporations constitute neither personal information nor specific personal information, and the foregoing restrictions do not apply thereto.
Sensitive Information
The Company does not acquire, use or provide to third parties any sensitive information as defined in the Guidelines for the Protection of Personal Information in the Credit Field (namely, special care-required personal information (race, creed, social status, medical history, the fact of having a disability, criminal record, the fact of having suffered damage caused by a crime, the fact that procedures relating to a criminal case such as arrest, detention or institution of prosecution have been carried out against the person, etc.), as well as information relating to labor union membership, family origin, registered domicile, health care and sex life), except in the cases listed in the said Guidelines. The principal cases in which the Company may fall within such exceptions are as follows:
- Where based on laws and regulations, etc. (verification at the time of transaction, preparation and retention of verification records and transaction records, etc., and filing of suspicious transaction reports under the Act on Prevention of Transfer of Criminal Proceeds; investigations relating to merchants under the Installment Sales Act, etc.)
- Where necessary for the protection of the life, body or property of a person
- Where it is necessary to cooperate with a national government organ, a local government or a person entrusted thereby in performing affairs prescribed by laws and regulations
- Where, out of the necessity to ensure the appropriate operation of the business, such information is handled, based on the consent of the individual, to the extent necessary for the performance of business
Merchant Screening Using Publicly Available Sources
As part of merchant screening (screening at the time of affiliation and ongoing screening thereafter) and the exclusion of anti-social forces, the Company may conduct investigations using reports by news organizations, the Official Gazette and other publicly available information sources with respect to Users that are merchants and their representatives, officers, beneficial owners and others.
Where, in the course of such investigations, the Company acquires a criminal record, the fact that procedures relating to a criminal case have been carried out or other special care-required personal information (including sensitive information), the Company will acquire and use such information only where the prior consent of the individual has been obtained or where based on laws and regulations, etc., and only to the extent necessary for the performance of the business of merchant screening and the exclusion of anti-social forces. Such consent shall be obtained by the methods prescribed in the merchant terms and conditions and the merchant application form. With respect to the representatives, officers, beneficial owners and others of Users that are merchants, except where the Company obtains consent directly from each such person, it is presumed that the User that is a merchant has obtained the prior consent of each such person.
Investigations concerning information that does not constitute special care-required personal information, such as whether a person falls under an organized crime group member, etc., may be conducted regardless of whether the above consent has been obtained.
3. Acquisition of Personal Information
The Company acquires personal information by the following methods:
- By receiving personal information directly from Users (such as upon account registration, merchant application, card application, the conduct of identity verification (eKYC), use of settlement services, inquiries to support, and registration for marketing communications)
- By automatically recording personal information through cookies and other similar technologies when Users use the Company’s website or applications (please refer to Article 7)
- By receiving Users’ personal information indirectly from third parties (payment networks (Visa, Mastercard, etc.), acquirers, payment service providers, identity verification service providers, credit information agencies, group companies, etc., limited to the extent permitted by laws and regulations)
- By acquiring information from registries and other publicly available information sources
The Company does not acquire personal information by deception or other wrongful means.
4. Purposes of Use of Personal Information
The Company uses personal information only to the extent necessary to achieve the purposes of use that have been notified to Users or publicly announced in advance. The principal purposes of use are as follows:
(1) Account management and provision of services: opening and management of accounts; conclusion and management of merchant agreements; issuance and management of cards; processing of settlements, refunds and chargebacks; settlement of payments to merchants; and provision of customer support
(2) Compliance with laws and regulations, etc. and response to legal obligations: compliance with the laws and regulations, etc. of Japan and response to requests from administrative authorities (the Ministry of Economy, Trade and Industry, the Financial Services Agency, the police, the Personal Information Protection Commission, etc.), including the following:
- Verification at the time of transaction, preparation and retention of verification records and transaction records, and filing of suspicious transaction reports under the Act on Prevention of Transfer of Criminal Proceeds
- Appropriate management of credit card numbers, etc., investigations relating to merchants (screening at the time of affiliation and ongoing screening thereafter), and preparation and retention of investigation records under the Installment Sales Act
- Screening based on lists of persons subject to economic sanctions and other sanctions lists (including responses to measures such as asset freezes under the Foreign Exchange and Foreign Trade Act and responses to requests under the rules of international card scheme operators)
(3) Risk management and countermeasures against fraudulent use: detection, investigation and prevention of fraud, fraudulent transactions, impersonation, unauthorized use of credit card numbers, etc. and other illegal or inappropriate acts; response to chargebacks and other disputes; credit management; and ensuring the security of systems
(4) Improvement and analysis of services: improvement of the Company Services based on the results of analysis of usage status, development of new functions and services, and enhancement of the user experience
(5) Marketing: provision of information relating to the Company’s products, services or campaigns; provided, however, that this applies only where the prior consent (opt-in) of the User has been obtained. Users may withdraw such consent at any time.
(6) Business succession: in connection with a merger, acquisition or business transfer, personal information may be provided to the successor, on the condition that an equivalent level of protection is ensured.
5. Provision of Personal Information to Third Parties
The Company does not sell or lend Users’ personal data. The Company may provide personal data in accordance with each of the following paragraphs. In addition to the cases set forth below, the Company may provide personal data to third parties where based on laws and regulations (including responding to police investigations, court orders and requests from administrative authorities) or where the separate consent of the User has been obtained after specifying the recipient, the information to be provided and the purpose of use.
With respect to the provision set forth in paragraphs (1) and (2) below, the Company obtains in advance the consent of the User under Article 27, Paragraph 1 of the APPI, as part of the User’s consent to the cardmember terms and conditions or the merchant terms and conditions at the time of application for a card or a merchant agreement.
(1) Provision in connection with the processing of card transactions
- Cases of provision: where a User uses a card issued by the Company, or where the Company processes card transactions in relation to its settlement services for merchants
- Purpose of provision: authorization of card transactions, processing of clearing and settlement, handling of refunds, chargebacks and other disputes, and detection and prevention of fraudulent use
- Recipients: the Company handles personal data solely within a cloud environment located in Japan, does not handle personal data in foreign countries, and does not provide personal data to third parties located in foreign countries.
- Items of personal data to be provided: card numbers and other card identification information, names, transaction details (date and time, amount, currency, merchant name, etc.), and information necessary for authentication and fraud detection
(2) Provision to payment service providers, etc.
- Cases of provision: where a User uses the Company’s settlement services for merchants
- Purpose of provision: screening relating to merchants (screening at the time of affiliation and ongoing screening thereafter), performance of operations under merchant agreements, appropriate management of credit card numbers, etc. and prevention of the unauthorized use thereof, prevention of duplicate affiliation and other fraudulent acts, and communications with and provision of information to Users incidental thereto
- Recipients: international card scheme operators, acquirers, payment service providers and other settlement service providers with which the Company is affiliated or has a business alliance
- Items of personal data to be provided: the User’s name or corporate name, address or location, date of birth, information relating to the representative, information relating to the merchant agreement (application date, contract date, contract termination date, etc.), information relating to the handling and usage status of credit cards, etc., matters stated in official documents (certified copies of registries, etc.), and other information necessary to achieve the above purposes of provision
(3) Joint use under the Merchant Information Exchange System
Pursuant to the Merchant Information Exchange System operated by the Japan Consumer Credit Association, a certified installment sales association prescribed in the Installment Sales Act, the Company jointly uses the personal data of Users that are merchants (including Users that wish to conclude a merchant agreement) as follows:
- Purpose of joint use: for the sound development of credit transactions and the protection of consumers, through the improvement of the accuracy of screening by member companies of the Merchant Information Exchange System (hereinafter “JDM Members”) at the time of conclusion of merchant agreements and during the term thereof, the exclusion of merchants that engage in acts lacking in the protection of users, etc., and the appropriate management of credit card numbers, etc. and the prevention of the unauthorized use thereof
- Items of personal data to be jointly used: information relating to acts lacking in the protection of users, etc. (including acts suspected of being such acts and acts for which such determination is difficult); information relating to acts that impede the appropriate management, etc. of credit card numbers, etc.; the fact of, and grounds for, investigations under the Installment Sales Act; the fact of, and grounds for, measures taken based on such investigations (including termination of agreements); information relating to complaints filed by users, etc. and investigations thereof; information collected in relation to the facts of dispositions published by administrative organs; and the name, address, telephone number and date of birth of the merchant relating to the foregoing (in the case of a corporation, the corporate name, address, telephone number, corporate number, and the name and date of birth of the representative)
- Period of registration: a period not exceeding five years from the date of registration (for information relating to investigations, from the date of registration of the completion of the corresponding measures or of the termination of the agreement)
- Scope of joint users: comprehensive credit purchase intermediaries, individual credit purchase intermediaries and business operators that conclude contracts for the handling of credit card numbers, etc., which are members of the Japan Consumer Credit Association and are JDM Members, as well as the Merchant Information Exchange Center of the said Association (hereinafter the “JDM Center”)
- Party responsible for management: Japan Consumer Credit Association, Merchant Information Exchange Center (Address: 14-1 Nihonbashi-Koamicho, Chuo-ku, Tokyo; Representative: Tetsuo Matsui; Telephone: 03-5643-0011)
6. Retention Periods
The Company retains personal data only for the period necessary to achieve the purposes of use, and when it is no longer necessary to retain such data, the Company securely disposes of or anonymizes it in accordance with the Company’s data retention and disposal policy.
However, in the following cases, the Company retains personal data beyond such period to the extent necessary. The principal retention periods are as follows:
(1) Records relating to investigations concerning merchant agreements:
- Records of investigations at the time of the merchant agreement (basic matters concerning the applicant merchant, the products handled, measures relating to the appropriate management of card numbers, etc.), periodic investigations, and those ad hoc investigations relating to changes in notified matters: until the preparation of the records relating to the investigation conducted next after such investigation is completed. Where the merchant agreement with the relevant merchant has terminated, for five years from the date of termination
- The date of conclusion of the merchant agreement: for five years from the date on which the merchant agreement with the relevant merchant terminated
- Records of ad hoc investigations relating to acts falling under any item of Article 35-3-7 of the Installment Sales Act, complaints relating to acts lacking in the protection of the interests of users, etc., or leakage or other incidents or fraudulent use: for five years after preparation
- Among the matters investigated at the time of the merchant agreement, those overlapping with the matters investigated in the ad hoc investigations described above (the presence and content of prohibited acts, the systems necessary to prevent them, and the status of development of the complaint handling system): for five years from the investigation at the time of the relevant merchant agreement
(2) Information registered with the Merchant Information Exchange Center (JDM Center) operated by the Japan Consumer Credit Association: a period not exceeding five years from the date of registration (the period prescribed in the Operational Rules of the Merchant Information Exchange System established by the said Association). However, with respect to the fact of, and grounds for, merchant investigations and information relating to acts that impede the appropriate management, etc. of credit card numbers, etc., such period is counted from the date of registration of the completion of the corresponding measures or of the termination of the merchant agreement.
(3) Records relating to measures for the dissolution of relationships with anti-social forces: for five years from the time of dissolution of the relationship
(4) Records relating to internal and external audits: for seven years with respect to the date and time of the audit, the department conducting it, the person conducting it, the content of the audit, the results of the audit and the improvement report. Where an external audit is used, for seven years with respect to documents relating to the audit agreement, audit methods, the status of the audit, the audit results and the internal responses to matters pointed out in the audit
(5) Records of the implementation of education and training: for seven years
(6) Access logs of systems that handle personal data: for at least six months (in order to periodically check for anomalous activity)
(7) Where the retention of records, books and documents, etc. is required by laws and regulations: where accounting books, vouchers or other books and documents contain personal data, the Company retains such personal data during the retention period prescribed by laws and regulations for such books and documents. The principal examples are accounting books and important materials relating to the business thereof under the Companies Act (for ten years from the closing of the accounting books), financial statements and the supplementary schedules thereto (for ten years from preparation), books and documents, etc. under the Corporation Tax Act and other tax laws (in principle, for seven years; for ten years in the case of those relating to a business year for which the carryover deduction of losses applies), and books and qualified invoices, etc. under the Consumption Tax Act (for seven years).
7. Use of Cookies, etc.
The Company uses cookies and similar technologies for the provision of the basic functions of the Company Services, access analysis, and (where the consent of the User has been obtained) marketing and targeting. Cookie settings may be managed through browser settings.
8. Security Control Measures
In order to prevent the leakage, loss or damage of the personal data it handles and otherwise to ensure the security control of personal data, the Company takes necessary and appropriate measures as follows:
- Development of basic policies and internal rules: formulation of basic policies and handling rules for the proper handling of personal data
- Organizational security control measures: appointment of a person responsible for the handling of personal data, establishment of a system for inspecting and auditing the status of handling, and establishment of a system for responding to incidents such as leakage
- Human security control measures: implementation of periodic education and training for employees on the proper handling of personal data, and inclusion of matters relating to confidentiality in internal rules, etc.
- Physical security control measures: control of entry to and exit from areas where personal data is handled, and measures to prevent the theft or loss of devices and electronic media, etc.
- Technical security control measures: limitation of the persons in charge and the scope of personal data handled through access control, encryption of data, implementation of mechanisms to protect against unauthorized access, etc., and implementation of periodic audits
- Management of credit card numbers, etc.: in accordance with the Installment Sales Act, the Company takes the measures necessary to prevent the leakage, loss or damage of credit card numbers, etc.
9. Requests for Disclosure, etc. of Retained Personal Data
In accordance with the provisions of the APPI, Users may make the following requests to the Company with respect to retained personal data by which the User is identified (hereinafter “Requests for Disclosure, etc.”):
- Request for notification of the purpose of use: Users may request notification of the purpose of use of the User’s data held by the Company.
- Request for disclosure: Users may request the disclosure of the User’s retained personal data held by the Company and of the records of provision to third parties under the APPI. In making a request for disclosure, the User may designate the method of disclosure, such as provision by electromagnetic record or another method.
- Request for correction, addition or deletion of content: Where the content of retained personal data is not factual, the User may request the correction, addition or deletion thereof.
- Request for cessation of use, erasure, or cessation of provision to third parties: Users may make such requests in the following cases:
- Where the data is handled for a purpose other than the purpose of use notified in advance, or is handled beyond the scope necessary to achieve the purpose of use
- Where the data is used in a manner that may encourage or induce an illegal or unjust act
- Where the data was acquired by deception or other wrongful means
- Where the data has been provided to a third party (including a third party located in a foreign country) in violation of the provisions of the APPI
- Where the Company no longer needs to use the relevant retained personal data
- Where an incident concerning the leakage, loss or damage of, or otherwise concerning the security of, the relevant retained personal data has occurred
- Where, as a result of such handling, the rights or legitimate interests of the User are harmed or may be harmed
Requests for Disclosure, etc. shall be made to the contact point set forth in Article 11 by the method prescribed by the Company. The Company will respond within a reasonable period (normally within two weeks) in accordance with the provisions of the APPI. In order to prevent improper requests through impersonation or otherwise, the Company will verify the identity of the requester by reasonable methods, such as by requesting the submission of identity verification documents.
Please note that, pursuant to the APPI or other laws and regulations, the Company may be unable to comply with all or part of a Request for Disclosure, etc. In particular, the Company may decline to disclose all or part of the retained personal data where (i) there is a risk of harm to the life, body, property or other rights or interests of the individual or a third party, (ii) there is a risk of a significant impediment to the proper implementation of the Company’s business (including information relating to the filing of suspicious transaction reports under the Act on Prevention of Transfer of Criminal Proceeds), or (iii) disclosure would violate other laws or regulations. Where the Company decides not to comply with a Request for Disclosure, etc., it will notify the User to that effect without delay.
Requests for Disclosure, etc. may be made not only by the individual but also by the statutory representative of a minor or an adult ward, or by an agent appointed by the individual. In the case of a request made by an agent, the Company will request the submission of the agent’s own identity verification documents and documents evidencing the authority of representation.
10. Handling of Personally Referable Information
The Company may receive from third parties “personally referable information,” such as cookie IDs and device identifiers, which alone cannot identify a specific individual. Where the Company acquires such personally referable information as personal data by linking it with a User’s personal information, the Company will do so after obtaining the User’s prior consent where required by laws and regulations, and, after acquisition, will handle such information as personal information under the APPI in accordance with this Policy.
11. The Company’s Representative and Address, and Contact Point for Inquiries Regarding Personal Information
The Company’s name, address and the name of its representative are as follows:
- Name: Wonder Ventures K.K. (ワンダーベンチャー株式会社)
- Address: 13F Pacific Century Place Marunouchi, 1-11-1 Marunouchi, Chiyoda-ku, Tokyo
- Representative: Ngan Lam Yan (ンガン・ラム・ヤン)
For questions regarding this Policy or the Company’s handling of personal information, Requests for Disclosure, etc., and the filing of complaints, please contact the following:
- E-mail address: japan.support@wonder.app
- Mailing address: Wonder Ventures K.K., Support Desk, at the address set forth above
The Company will respond promptly and in good faith to requests from Users.
The Company is a covered business operator of the Japan Consumer Credit Association, an accredited personal information protection organization under the APPI. Complaints regarding the Company’s handling of personal information may be filed not only with the Company’s contact point but also with the following contact point of the said Association:
Japan Consumer Credit Association, Consultation Office (Consultation Desk for the Handling of Personal Information)
- Address: 6F Jusei Nihonbashi Koamicho Building, 14-1 Nihonbashi-Koamicho, Chuo-ku, Tokyo
- Telephone: 03-5645-3360
- Hours: Monday through Friday (excluding public holidays and the year-end and New Year period), 9:30–12:00 / 13:00–17:30
12. Changes to This Policy
The Company may change this Policy from time to time. Where a material change is made, the Company will notify Users by means of the Company’s website, e-mail, in-app notification or other methods. The revised Policy shall apply from the revised “Date of Establishment” stated at the beginning hereof.