Legal

Privacy Policy

Effective March 1, 2026 · Last updated March 9, 2026

Overview

This Privacy Policy explains how SOWAKA LLC (“SOWAKA,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you visit sowaka.life (the “Site”), use our applications, interact with our blockchain-based services (including NFTs and tokenized assets), or communicate with us.

We are committed to protecting your privacy in compliance with applicable global data protection laws, including but not limited to the EU General Data Protection Regulation (GDPR), the UK GDPR, Japan’s Act on Protection of Personal Information (APPI), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Brazil’s Lei Geral de Proteção de Dados (LGPD), China’s Personal Information Protection Law (PIPL), South Africa’s Protection of Personal Information Act (POPIA), South Korea’s Personal Information Protection Act (PIPA), and other applicable regional and national privacy laws.

Who We Are

The data controller responsible for your personal information is:

SOWAKA LLC

2-4-8-8F Ebisunishi, Shibuya-ku, Tokyo, JAPAN 〒150-0021

Data Protection Contact: info@sowaka.life

Information We Collect

Information You Provide

  • Account Information: name, email address, phone number, password, and profile preferences.
  • Transaction Information: billing and shipping addresses, payment details (credit card, PayPal, Apple Pay, Google Pay), and order history.
  • Communication Data: messages, inquiries, feedback, and customer support correspondence.
  • Identity Verification: government-issued ID or documentation when required for high-value transactions or regulatory compliance.

Information Collected Automatically

  • Device Data: IP address, browser type and version, operating system, device identifiers, screen resolution, and language preferences.
  • Usage Data: pages viewed, products browsed, search queries, click patterns, referral URLs, session duration, and interaction timestamps.
  • Location Data: approximate geographic location derived from your IP address.
  • Cookies & Tracking: see the “Cookies & Tracking Technologies” section below.

Information from Third Parties

  • Payment Processors: transaction confirmation and fraud prevention data from Shopify, Stripe, or other providers.
  • Social Login: basic profile information when you sign in via Google or other OAuth providers.
  • Blockchain Networks: publicly available on-chain data such as wallet addresses and transaction records.
  • Analytics Providers: aggregated usage insights from services such as Google Analytics.

How We Use Your Information

We process your personal information for the following purposes and on the following legal bases:

PurposeLegal Basis (GDPR)
Processing orders, payments, and shippingContract performance
Creating and managing your accountContract performance
Customer support and communicationContract performance / Legitimate interest
Sending marketing communications (with consent)Consent
Personalizing your experienceLegitimate interest
Fraud prevention and securityLegitimate interest / Legal obligation
Compliance with legal and regulatory requirementsLegal obligation
NFT minting, transfer, and provenance trackingContract performance / Consent
Analytics and service improvementLegitimate interest

Sharing Your Information

We do not sell your personal information. We may share your data with:

  • Service Providers: hosting (Vercel), e-commerce platform (Shopify), payment processing (Stripe), email delivery, analytics (Google Analytics), and customer support tools — all under data processing agreements.
  • Blockchain Networks: wallet addresses and transaction data are recorded on public blockchains and cannot be erased. See “Web3 & Blockchain” below.
  • Authentication Providers: Supabase (for account management) and Web3Auth (for wallet generation), both operating under data protection agreements.
  • Legal Authorities: when required by law, court order, or to protect our rights, safety, or property.
  • Corporate Transactions: in connection with a merger, acquisition, or sale of assets, with prior notice.

Web3 & Blockchain Data

SOWAKA offers blockchain-based features including NFTs and tokenized real-world assets (RWAs). Please note the following unique aspects:

Immutability of Blockchain Data

Transactions recorded on a blockchain (e.g., Ethereum, Polygon) are public and permanent. Your wallet address and transaction history are visible on the public ledger. We cannot modify, delete, or restrict access to this data once recorded.

Wallet & Authentication

We use Web3Auth for wallet generation and authentication. This utilizes Multi-Party Computation (MPC) technology, ensuring a non-custodial experience where we do not have access to your private keys. We do not store your private keys, seed phrases, or full wallet credentials.

Data Storage

Your profile information (email, display name) is stored in Supabase, separate from your on-chain assets. Off-chain metadata may be stored on IPFS or centralized servers.

NFT & RWA Compliance

NFTs and tokenized assets offered by SOWAKA are digital certificates of authenticity, provenance, or membership — they are not offered as financial investments. We comply with applicable regulations in each jurisdiction where we operate, including but not limited to the EU Markets in Crypto-Assets Regulation (MiCA), Japan’s Payment Services Act and Financial Instruments & Exchange Act (FIEA), Singapore’s Payment Services Act, and applicable U.S. federal and state laws. We may be required to collect additional identity information for NFT/RWA transactions to comply with Anti-Money Laundering (AML) and Know Your Customer (KYC) requirements.

International Data Transfers

SOWAKA is headquartered in Japan with customers worldwide. Your personal information may be transferred to and processed in countries other than your country of residence, including Japan, the United States, and the European Union/EEA.

We safeguard international transfers using appropriate mechanisms, including:

  • Adequacy decisions by relevant authorities (e.g., EU adequacy decisions for Japan)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (BCRs) where applicable
  • Consent, where other mechanisms are unavailable and permitted by law

For EEA/UK residents: your data may be processed outside the EEA/UK. We rely on EU-approved SCCs and adequacy decisions. For Brazilian residents: transfers comply with LGPD requirements including ANPD-approved SCCs. For Chinese residents: cross-border transfers comply with PIPL requirements including security assessments where mandated. For Japanese residents: transfers follow the APPI framework and guidelines issued by the PPC.

Cookies & Tracking Technologies

We use cookies and similar technologies to enhance your experience. Categories include:

Strictly Necessary Cookies

Essential for site operation: session management, shopping cart, checkout, security, and authentication. These cannot be disabled.

Analytics & Performance Cookies

Help us understand usage patterns and improve site performance. We use Google Analytics with IP anonymization enabled. You can opt out at tools.google.com/dlpage/gaoptout.

Marketing & Advertising Cookies

Used to deliver relevant advertisements. These are only set with your consent. You may opt out via:

You can manage cookie preferences through your browser settings or our cookie consent banner. We honor Global Privacy Control (GPC) and “Do Not Track” signals where required by law.

Data Retention

We retain personal information only as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Typical retention periods:

  • Account data: for the duration of your account plus 3 years after deletion request.
  • Transaction data: 7 years (for tax and legal compliance).
  • Marketing data: until you withdraw consent or opt out.
  • Blockchain data: permanently, as blockchain records cannot be deleted.
  • Log & analytics data: up to 26 months.

Your Rights

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal information:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure (“Right to Be Forgotten”): request deletion of your data, subject to legal obligations and blockchain immutability.
  • Restriction: limit processing of your data in certain circumstances.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests or for direct marketing.
  • Withdraw Consent: where processing is based on consent, withdraw at any time without affecting prior processing.
  • Non-Discrimination: exercise your rights without receiving discriminatory treatment.
  • Automated Decision-Making: opt out of solely automated decisions that produce legal or significant effects.

To exercise your rights, contact us at info@sowaka.life. We will respond within the timeframes required by applicable law (typically 30 days under GDPR, 45 days under CCPA/CPRA).

Regional Disclosures

European Economic Area, UK & Switzerland (GDPR / UK GDPR)

If you are located in the EEA, UK, or Switzerland, you have the rights described above. You also have the right to lodge a complaint with your local supervisory authority. For a list of authorities, visit edpb.europa.eu.

United States (CCPA/CPRA, State Privacy Laws)

California residents: we do not “sell” or “share” your personal information as defined by the CCPA/CPRA. You have the right to know, delete, correct, and opt out. We do not use sensitive personal information for purposes beyond those permitted by law. Residents of other U.S. states with privacy legislation (Virginia, Colorado, Connecticut, Texas, Oregon, etc.) have similar rights under their respective laws.

Japan (APPI)

We handle your personal information in accordance with Japan’s Act on the Protection of Personal Information. We will indicate the purpose of use, manage data securely, and provide access and correction upon request. We provide notice before transferring data to third parties, and cross-border transfers are governed by PPC guidelines.

Brazil (LGPD)

Brazilian residents have rights under the LGPD including access, correction, anonymization, portability, and deletion. Our Data Protection Officer can be contacted at info@sowaka.life. International transfers comply with ANPD-approved Standard Contractual Clauses.

China (PIPL)

For individuals in China, we process data in accordance with the Personal Information Protection Law. We obtain separate consent for cross-border transfers and sensitive data processing. You have the right to access, correct, delete, and restrict processing of your data.

South Korea (PIPA)

We comply with South Korea’s Personal Information Protection Act, including notice, consent, and data minimization requirements for Korean data subjects.

South Africa (POPIA)

South African residents benefit from the protections under POPIA, including the right to access, correction, and objection to processing. Cross-border transfers are subject to adequate safeguards.

Singapore (PDPA)

We comply with the Personal Data Protection Act, including consent, purpose limitation, and data protection obligations for Singapore residents.

Children & Minors

Our Site and services are not directed to individuals under the age of 16 (or the applicable age of digital consent in your jurisdiction — 13 in the U.S., 16 in the EU, 20 in Japan for certain services). We do not knowingly collect personal information from minors. If you believe a minor has provided us with data, please contact us at info@sowaka.life and we will promptly delete it.

Automated Decision-Making

We may use automated systems for fraud prevention and order risk assessment. These systems may temporarily deny transactions from IP addresses or payment methods associated with suspicious activity. You have the right to request human review of any automated decision that significantly affects you.

Security

We implement industry-standard technical and organizational measures to protect your data, including TLS encryption in transit, encryption at rest, access controls, regular security audits, and incident response procedures. Despite these measures, no system is completely secure — we cannot guarantee absolute security.

Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated through email notification, a banner on our Site, or other appropriate means. We encourage you to review this policy regularly. The “Last Updated” date at the top indicates the most recent revision.

Contact Us

For questions, requests, or complaints regarding this Privacy Policy or your personal data:

SOWAKA LLC

2-4-8-8F Ebisunishi, Shibuya-ku, Tokyo, JAPAN 〒150-0021

If you are unsatisfied with our response, you may lodge a complaint with your local data protection authority. EEA residents may contact their national supervisory authority; UK residents may reach the Information Commissioner’s Office (ICO); Japanese residents may contact the Personal Information Protection Commission (PPC).