ROKKODE Inc. (the "Company") establishes this Privacy Policy (this "Policy") for the handling of User information in connection with the eSIM data communication service provided under the name Stork Mobile and related websites, applications, support, and all other related services (collectively, the "Service").
Stork Mobile Privacy Policy
1. Scope
This Policy applies to personal information, personal data, information relating to communications usage, Cookies, and other information relating to Users that the Company obtains in connection with the Service.
Information independently obtained by payment service providers, authentication providers, analytics service providers, or other third parties in connection with the Service may be subject to the privacy policies and other terms established by those third parties.
2. Controller
The Company is the entity responsible for handling personal information and personal data obtained by the Company in connection with the Service.
The Company's name is ROKKODE Inc. The Company's contact point for privacy inquiries is set out in Article 17.
3. Information We Collect
The Company may collect the following information when providing the Service. The items below are examples of the main categories of information collected, and the specific items may vary depending on how the User uses the Service, the device used, the plan purchased, the payment method, the inquiry content, and other circumstances.
Account information
Name, email address, language setting, country or region, Account ID, registration date and time, authentication tokens, email verification information, login status, email unsubscribe information, push notification settings, and other information necessary to create, authenticate, and manage Accounts.
External authentication information
If a User uses Sign in with Apple, Sign in with Google, or another external authentication service, the Company may collect User identifiers, email addresses, names, authentication results, authentication tokens, and other information necessary for external authentication. External authentication providers may collect, use, or store information relating to Users for authentication, prevention of unauthorized use, security, and other purposes determined by those providers. The handling of information by Apple or Google is subject to Sign in with Apple & Privacy, Apple Privacy Policy, Sign in with Google, Google Privacy Policy, and other terms established by those companies.
eSIM and plan information
ICCID, IMSI, MSISDN, eSIM issuance, installation, deletion, suspension, expiration, and other status information, eSIM setup information, plan purchase details, data allowance, usage period, remaining balance, purchase history, additional data history, covered countries or regions, and other information necessary to provide the Service.
Communications usage records
Data usage, remaining data, connection date and time, last usage date, country or region of use, connected Compatible Network, communication status, usage status obtained from Telecommunications Providers or partners, and other information necessary to provide, display, and determine the status of communication services. The Company does not collect communication content, URLs visited, or the content of communications themselves.
Device and usage environment information
Device type, device model, OS, application version, browser, IP address, access date and time, request logs, error logs, authentication Cookies, device settings, eSIM installation or deletion status, and other information relating to the usage environment of the Service.
Payment and billing information
Purchased items, purchase amount, currency, payment result, transaction identifiers, payment method type, card brand, partial card number, payment errors, chargebacks, refund history, name, address, email address, and other information necessary for payment, billing, refunds, and accounting.
Inquiry and support information
Name, email address, inquiry subject, inquiry content, relevant eSIM or Account, device information, support history, communications from the Company, and other information necessary for inquiry handling.
Reviews, surveys, and other information submitted by Users
User name, review content, ratings, country or region of use, posting date and time, and other information submitted by Users in connection with the Service. Reviews, ratings, and other content posted or submitted by Users may be published on websites, applications, advertisements, landing pages, or other media managed or used by the Company.
Cookies, analytics, and fraud prevention information
Cookies, local storage, browsing history obtained through analytics services, page transitions, operation history, event information, purchase events, reCAPTCHA tokens, Firebase App Check tokens, Firebase Analytics, Sentry, and other information necessary for analytics, prevention of unauthorized use, and troubleshooting.
4. Purposes of Use
The Company uses the collected information for the following purposes.
To provide the Service, create Accounts, verify identity, authenticate logins, and manage Users.
To issue eSIMs, support installation, provide communication services, grant plans, provide additional data, display remaining balances, display usage history, determine last usage dates, and determine eSIM expiration.
To charge fees, process payments, provide refunds, issue receipts, perform accounting and tax processing, and respond to unauthorized payments and chargebacks.
To respond to User inquiries, provide support, investigate failures, verify identity, and respond to important communications.
To analyze use of the Service, improve quality and features, develop new features, and optimize displayed content.
To send information about the Service, important notices, support communications, campaigns, and other marketing communications by email, push notification, in-app notification, or other methods.
To detect, prevent, investigate, and respond to unauthorized access, unauthorized use, unauthorized payments, nuisance conduct, violations of terms, and security issues.
To coordinate with payment service providers, authentication providers, analytics service providers, cloud service providers, and other external services necessary to provide the Service.
To respond to requests based on laws, regulations, administrative agencies, courts, Telecommunications Providers, payment service providers, or other legitimate authority or necessity.
To give notices necessary for operation of the Service, including changes to the Terms of Use or other Company terms, changes to the Service, and suspension or termination of the Service.
For purposes incidental or related to the purposes above.
Users may unsubscribe from, or change settings for, marketing emails, push notifications, and other marketing communications by the method specified by the Company. However, the Company may continue to send important notices concerning the provision of the Service, purchases, payments, security, changes to the Terms of Use or this Policy, suspension or termination of the Service, and other operationally important matters even after a User unsubscribes from marketing communications.
5. Legal Bases for Processing
Depending on your country or region, the Company may be required to identify a legal basis for processing personal data. The Company's processing is generally based on one or more of the following grounds.
Performance of a contract or steps prior to entering into a contract, including providing the Service, creating and managing Accounts, issuing eSIMs, granting Data Plans, processing payments, and providing support.
Compliance with legal obligations, including accounting, tax, telecommunications, consumer protection, fraud prevention, security, and lawful requests from public authorities.
Legitimate interests of the Company or third parties, including improving and securing the Service, preventing unauthorized use, troubleshooting, analyzing usage, and communicating important operational information, provided that those interests are not overridden by applicable rights and interests of Users.
Consent, where required by applicable law, including certain marketing communications, Cookies or similar technologies, or other processing for which consent is required.
Where processing is based on consent, a User may withdraw consent by the method specified by the Company or by contacting the Company. Withdrawal of consent does not affect processing carried out before the withdrawal.
6. Payment Information
Payment processing for the Service may be performed through payment service providers or other third-party services used by the Company. The Company currently uses Stripe as its main payment service provider.
The Company may obtain or store payment results, transaction identifiers, card brands, partial card numbers, and other information necessary for payment management from payment service providers, but the Company does not store complete card numbers or security codes in its systems.
Stripe may collect, use, store, or disclose payment-related information and other personal data of Users for payment processing, fraud prevention, identity verification, dispute handling, and other purposes determined by Stripe. Stripe's handling of information is subject to the Stripe Privacy Policy and other terms established by Stripe.
7. Third-Party Disclosure and No Sale or Sharing of Personal Data
The Company does not sell, share, or provide Users' personal data to third parties in the ordinary operation of the Service. In particular, the Company does not sell personal data or share personal data for cross-context behavioral advertising.
However, the Company may provide Users' personal data to third parties in the following cases.
The User has consented.
The provision is based on laws or regulations.
The provision is necessary to protect the life, body, or property of a person and it is difficult to obtain the User's consent.
The provision is particularly necessary to improve public health or promote the sound development of children and it is difficult to obtain the User's consent.
The Company needs to cooperate with a national government agency, local government, or a person entrusted by them in performing affairs prescribed by law, and obtaining the User's consent may interfere with the performance of those affairs.
The provision is necessary in connection with a merger, company split, business transfer, or other business succession.
The Service may use external services necessary for its operation, including payment, authentication, cloud hosting, analytics, prevention of unauthorized use, email delivery, and support. These are generally treated as outsourcing to service providers or processors, or as external services directly used by Users.
If the Company outsources the handling of personal information to an external service provider, the Company will exercise necessary and appropriate supervision over that provider. If a User directly uses a payment service, external authentication service, or other external service, the provider of that external service may collect, use, or store the User's information in accordance with its own terms, privacy policy, and other conditions.
If coordination with an external service constitutes a third-party disclosure of personal data, the Company will provide personal data to the third party only if one of the cases listed in this Article applies.
8. International Transfers
Except where required by law, the Company does not plan, as part of its ordinary operations, to provide Users' personal data to foreign Telecommunications Providers, eSIM profile providers, or roaming networks.
However, because the Service uses payment service providers, authentication providers, cloud service providers, analytics service providers, and other external services, User information may be handled by businesses located outside Japan or stored on servers located outside Japan. Such handling or storage does not automatically mean that the Company has disclosed personal data to a third party. Whether it constitutes a transfer of personal data to a foreign third party depends on the contractual structure, storage location, access rights, actual handling, and other circumstances.
If the handling of personal data constitutes a transfer to a foreign third party, the Company will take measures required by applicable law, such as obtaining necessary consent, providing information about the recipient, confirming the recipient's personal information protection measures, and implementing contractual safeguards, except where permitted by law.
9. Service Providers and Processors
The Company may outsource all or part of the handling of personal information to external service providers or processors to the extent necessary to achieve the purposes of use. In that case, the Company will exercise necessary and appropriate supervision over those service providers or processors.
10. Cookies, Analytics, Fraud Prevention, and Error Monitoring Tools
The Company may use Cookies, local storage, Google Analytics, Firebase Analytics, Sentry, reCAPTCHA, Firebase App Check, and other analytics, fraud prevention, or error monitoring and troubleshooting tools to provide the Service, maintain login status, improve user experience, analyze usage, measure purchase events, prevent unauthorized use, monitor errors, and investigate failures.
Information obtained through these tools may be sent to the providers of those tools. The handling of information by each provider is subject to the privacy policy and other terms established by that provider.
Users may be able to restrict or reject the use of Cookies through browser settings or methods provided by each provider. However, if Cookies or similar technologies are disabled, some parts of the Service may not be available.
The Company does not currently use advertising identifiers, retargeting, or targeted advertising technologies as part of the ordinary operation of the Service.
11. Security Measures
The Company implements necessary and appropriate security measures for collected information, including access restrictions, authentication management, communication encryption, log management, and service provider management, to prevent leakage, loss, damage, unauthorized access, unauthorized use, and other risks.
12. Retention Period
The Company retains collected information for the period necessary to achieve the purposes of use, for the period required by law or for accounting and tax purposes, and for periods necessary for dispute handling, prevention of unauthorized use, security, and other operational needs of the Service.
The retention period is determined by taking into account the type of information, purpose of use, contractual relationship with the User, period necessary to manage eSIMs and plans, inquiry handling, legal retention obligations, and other circumstances.
If a User deletes the Account, the Company will endeavor to delete or anonymize information relating to that Account, except for information that must be retained under law or for business purposes. However, the Company may retain payment records, communications usage records, logs necessary for preventing unauthorized use, inquiry history, and other information necessary for legal compliance, dispute handling, accounting, and security to the necessary extent.
13. Your Privacy Rights
Users may, under applicable laws, request notification of the purposes of use, disclosure, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, disclosure of third-party provision records, and other legally recognized actions concerning retained personal data held by the Company about the User.
Depending on your country or region, you may also have rights to access, rectify, erase, restrict processing, object to processing, receive data portability, withdraw consent, opt out of certain processing, or lodge a complaint with a supervisory authority.
To exercise these rights, please contact the inquiry contact point at the end of this Policy. The Company will verify your identity and respond within a reasonable period in accordance with applicable laws. Depending on the request, the Company may be unable to respond to the extent permitted by law.
When responding to a request for notification of purposes of use, disclosure of retained personal data, or disclosure of third-party provision records, the Company may charge a fee of JPY 1,000 per request to the extent permitted by law.
The Company generally does not charge fees for requests to correct, add, delete, suspend use, erase, or suspend third-party provision of retained personal data.
If the Company charges a fee, the Company will notify the requester of the fee amount, payment method, and other necessary matters. If bank transfer fees, postage, or other costs necessary for payment or delivery arise, the requester will bear those costs except where required by law.
14. Minors' Information
If a minor uses the Service, the minor must use the Service with the consent of a parent, guardian, or other legal representative. The Company handles information obtained from minors in accordance with this Policy.
15. Statistical, Anonymized, and Similar Information
The Company may use collected information as statistical or analytical information that cannot identify a specific individual. In that case, the Company may use that information for Service improvement, quality improvement, business analysis, and other legitimate purposes.
If the Company creates or uses anonymized information, pseudonymized information, or other information that requires special handling under applicable law, the Company will take necessary publication, management, and other measures in accordance with applicable law.
16. Automated Decision-Making
The Company does not ordinarily make decisions based solely on automated processing, including profiling, that produce legal effects concerning Users or similarly significant effects.
The Company may use automated or system-based processing for fraud prevention, security, usage measurement, failure detection, eSIM status management, and similar operational purposes, but such processing is used to provide, protect, and operate the Service.
17. Changes to This Policy
The Company may change this Policy as necessary due to changes in laws, changes to the Service, changes to the information collected or purposes of use, or other circumstances.
If the Company changes this Policy, the Company will make known the changed content and effective date by posting on the website or application, email, or any other method the Company considers appropriate.
18. Contact
For inquiries about this Policy, the handling of personal information in the Service, requests to exercise rights, or other matters, please contact the Stork Mobile contact point provided by ROKKODE Inc. Inquiries may be made by email to support@storkmobile.com or through the contact form on the Stork Mobile website or application.
Revision History
- June 9, 2026: Established and effective
