Skip to content
ProductsAboutLegalContact
JA
Menu
ProductsAboutLegalContact日本語法務文書
← Legal index日本語版 →A2Z

Version 1.0 / Effective 2026-08-17

Current document

A2Z Privacy Policy

Public policy version: 1.0
Effective date: 2026-08-17

1. Operator

This Policy explains how gathron, a sole proprietor established in Japan (the Operator), handles information in A2Z.

  • Operator: gathron (sole proprietor)
  • Proprietor or representative: Aki Sudo
  • Business address: info@a2z.gathron.com
  • Privacy contact: info@a2z.gathron.com

2. Information We Collect

We collect information only to the extent necessary to provide and protect the Service.

2.1 Account and Authentication

  • internal account ID, CALLSIGN, account creation time, and account status;
  • email address and identifiers for any linked authentication methods;
  • country or region of residence and birth month and year;
  • versions and language of accepted Terms, Privacy Policy, and Code of Conduct, acceptance time, region, and account status at acceptance;
  • login sessions and device identifiers, creation and last-use times, and revocation time; and
  • hashed one-time codes, authentication request times, attempt counts, expiry times, and a keyed transformation of the requesting IP address.

We do not store a fixed A2Z password, a plaintext one-time code, or a plaintext refresh token.

2.2 Gameplay and Network Data

  • faction, ROOM, SORTIE, position input, Life, loadout, tickets, HELP, SCAN, LOCK, combat results, and contribution records;
  • queues, parties, world progress, season progress, cosmetics, titles, and entitlements;
  • connection-test latency, packet loss, device clock difference, test time, and expiry; and
  • connection, disconnection, input-validation, error, and security audit logs.

2.3 Safety and Support

  • report category, target CALLSIGN, ROOM, report time, and processing status;
  • profile blocks, warnings, feature restrictions, suspensions, reasons, periods, and appeals; and
  • support requests, information submitted for identity verification, and response history.

The current Service has no free-text in-game chat or in-game voice chat.

2.4 Purchases

  • product, SKU, quantity, amount, currency, purchase provider, status, and purchase or refund time;
  • Stripe Checkout Session, PaymentIntent, webhook event, and other transaction references; and
  • purchase-confirmation version and language, confirmation time, CALLSIGN and product snapshot, versions of the terms shown, immediate-delivery and withdrawal acknowledgement, and the full confirmation notice;
  • purchase-authorization challenge hashes, attempt count, expiry, verification and consumption time, and first and last recorded use of a paid entitlement and the use type; and
  • monthly purchase limit, amount used, and the scheduled time and amount of a limit change.

The Operator does not store card numbers, card security codes, Apple ID credentials, Google account credentials, plaintext purchase codes, or plaintext purchase-authorization grants. Payment-method details are handled by the payment provider.

2.5 Device and Browser Data

  • IP address or a transformation of it, user agent, operating system, browser, app version, language, connection time, and incident information; and
  • session cookies, device identifiers, and locally stored display or control settings.

A2Z does not currently use non-essential analytics, advertising cookies, or third-party crash analytics. Before introducing any such technology, we will identify the provider, recipient, data, purpose, retention period, and consent or opt-out mechanism in this Policy and the applicable user interface.

3. Why We Use Information

We use information to:

  1. create accounts, authenticate users, manage devices, and prevent unauthorized login;
  2. provide and synchronize WORLD FRONT, ROOMs, combat, queues, parties, rewards, and game progress;
  3. verify age, region, purchase limits, and acceptance of current policies;
  4. display products, verify payments, grant and restore entitlements, process refunds, prevent duplicates, and maintain accounting records;
  5. investigate cheating, disruption, collusion, inactivity, HELP abuse, and other violations, and handle enforcement and appeals;
  6. investigate incidents, protect security, manage capacity, improve quality, and maintain compatibility;
  7. provide access, export, correction, deletion, support, and other data-rights processes;
  8. send notices about policies, material Service changes, security, purchases, and shutdown; and
  9. comply with law, resolve disputes, conduct audits, and protect rights.

We do not use this information for targeted advertising, individualized pricing based on behaviour, or the sale of combat power.

3.1 Legal Bases in the EEA, United Kingdom, and Similar Jurisdictions

Where applicable law requires us to identify a legal basis, we rely on:

  • performance of a contract or steps requested before entering a contract for account creation, authentication, gameplay, purchases, entitlement delivery, restoration, support, and account deletion;
  • legitimate interests in securing the Service, preventing fraud and abuse, maintaining reliability, enforcing rules, resolving disputes, and establishing or defending legal claims, after considering the rights and interests of users;
  • compliance with legal obligations for accounting, tax, consumer protection, regulatory requests, incident response, and legally required records; and
  • consent only for an optional purpose when the Service expressly asks for it. Consent may be withdrawn without affecting processing already carried out lawfully, and refusal does not block core Service functions unless the optional feature cannot operate without that processing.

Acceptance of this Policy acknowledges receipt of this notice; it is not treated as consent for every processing activity.

4. How We Collect Information

We obtain information that users submit, information created through use of the Service, technical information sent by a user’s device, transaction information received from providers such as Stripe, and information submitted during support interactions.

5. Processors and External Services

We use service providers only as necessary, limit the information provided to them, and review appropriate contractual and security safeguards.

Provider Purpose Main information Entity and processing locations
Stripe Web payment, refunds, fraud prevention internal A2Z account reference, amount, currency, product reference, and payment information entered directly into Stripe A2Z’s Stripe account country is Japan. At initial launch, A2Z intends to use one-time Stripe Checkout with cards and eligible Apple Pay and Google Pay wallets only. Stripe Japan, Inc. is the contracting entity, with Stripe Payments Europe, Limited additionally involved for Personal Data and subprocessors in Japan and other countries. The Operator verifies the actual LIVE payment-method configuration before enabling sales.
Resend / Plus Five Five, Inc. login codes and notification email email address, message content, and delivery result United States, including Resend’s authorized United States subprocessors; international processing may occur as described in Resend’s current notices
GMO Internet, Inc. / Onamae.com Rental Server static public web delivery public frontend files and server access, error, and PHP logs servers are installed in Japan; the provider states that the latest 14 days of Web-data backups are retained. The contracted control panel stores these logs in the server area; on 15 August 2026, the configured log-retention period was one week, with selectable periods up to 24 months. Logs outside the selected retention period are no longer retained by this setting.
GMO Internet, Inc. / Onamae.com VPS API, database, and deployment-time database backup server data described in this Policy servers are installed in Japan; database and deployment backups currently use the same VPS. On 15 August 2026, the operator captured one provider-level VPS snapshot after a controlled shutdown; no recurring snapshot schedule is configured. A daily production control removes database backups older than 88 complete days so that they do not reach 90 complete days.
  • Stripe Privacy Policy
  • Resend Privacy Policy
  • Resend Subprocessors
  • Onamae.com Rental Server Terms

6. Disclosure and International Processing

  1. We do not disclose personal data to a third party except with consent, where required or permitted by law, to protect life, physical safety, or property where consent is difficult to obtain, or in another case permitted by applicable law.
  2. Payment, email, hosting, and similar providers act under appropriate processor or service-provider arrangements and oversight where required.
  3. If information is handled in another country, we review that country’s legal framework, contractual protections, and ongoing security and provide information, obtain consent, or implement another lawful transfer mechanism where required.
  4. Information may be transferred as part of a merger, business transfer, or similar succession only in accordance with applicable law.

7. Information Visible to Others

CALLSIGN, faction, in-game ship display, eligible gameplay records, titles, and world-progress history may be visible to other users or on the official website. We do not publicly display email addresses, birth information, internal account IDs, device information, internal purchase references, reporter identities, or precise real-world location.

8. Retention

We retain information only for as long as necessary for the purpose described or required by law. The following periods are intended maximums and must be verified against the production deletion and anonymization jobs before publication.

Information Intended maximum retention
detailed ROOM input and combat logs 30 days
authentication and security audit logs 180 days
report evidence 180 days after the case closes
purchase, refund, and accounting records 7 years or a longer period required by applicable law
cancellation period for account deletion 30 days
deletion-eligible data in backups expired or overwritten within 90 days after final deletion
irreversibly aggregated statistics and public world, LOOP, and ending history no fixed limit

After account deletion, purchase and refund records retained for legal, accounting, or fraud-prevention purposes are separated from the game profile and use an irreversible keyed transformation of the account identifier.

9. Security

We use reasonable administrative and technical measures such as access control, separation of duties, encrypted transmission, token hashing, short-lived one-time codes, per-device session revocation, audit logging, backups, vulnerability response, and processor oversight.

Some security details cannot be published. If a data incident requires notice or reporting under applicable law, we will notify the relevant authority and affected users as required.

10. Your Rights and Choices

  1. Account Settings allows a user to request an export containing account, device, purchase, consent, progression, and safety information.
  2. Export requires an additional code sent to the registered email address. The resulting download authorization is short-lived and single-use. The generated JSON is not stored as a server file.
  3. Depending on applicable law, you may request notice of purpose, access, correction, completion, deletion, restriction, erasure, cessation of disclosure, or disclosure of third-party transfer records.
  4. Identity or authority may need to be verified. The procedure and response method will be published at info@a2z.gathron.com. If a request cannot be fulfilled in whole or part, we will explain the applicable reason where required.
  5. Account deletion may be cancelled for 30 days. After that period, personal and game data are deleted except for transaction records that must be retained.

11. Children’s Privacy

A2Z is a general-audience online game intended for users aged 13 or older and is not directed to children under 13. Registration uses birth month and year to apply the basic age gate, and an online account is not created when the submitted age is under 13. Limited authentication and security records created before the eligibility decision may be retained for the periods described above to protect the Service and establish compliance. Where regional law requires a higher age or verified parental authorization, the user must not use online combat or purchases until that condition is met; the Operator may request verification or restrict access if it becomes aware that a requirement has not been met. Contact info@a2z.gathron.com if you believe we have collected information from an underage child.

12. Cookies and Device Storage

The Web Service uses cookies or local storage required for login, secure sessions, device identification, settings, and fraud prevention. Authentication cookies use Secure, HttpOnly, and an appropriate SameSite attribute where applicable.

Before introducing non-essential analytics or advertising technology, we will add the purpose, recipient, retention period, and consent or opt-out method to this Policy and to an appropriate cookie notice.

13. Changes to This Policy

For a material change, we will communicate the effective date and substance in advance through the Service, official website, or registered email. If a change materially affects purposes, recipients, or user rights, the Service will request express acceptance of the updated Terms, Privacy Policy, and Code of Conduct before the next SORTIE or purchase. We retain the acceptance time, document versions, language, and region.

14. Contact

  • Privacy contact: info@a2z.gathron.com
  • Postal address: info@a2z.gathron.com
  • Supported contact language and hours: English and Japanese; Monday-Friday 10:00-17:00 JST, excluding Japanese public holidays
  • Personal information handling business operator: gathron, Aki Sudo; info@a2z.gathron.com

Independent software for play, analysis, and collaboration.

ProductsAboutContactLegalBlog
Designed and operated in Japan.© 2026 gathron