プライバシーポリシー
最終更新日:2026年2月
はじめに
ViaConectaへようこそ。私たちはあなたの個人データを保護し、プライバシーを尊重することをお約束します。このプライバシーポリシーは、あなたが当社のウェブサイト (viaconecta.co) を訪問したり、モバイルアプリケーションを使用したり、eSIMサービスを購入したりする際に、私たちがどのように個人情報を収集、使用、保存、共有するかを説明します。
当社のサービスを使用することにより、あなたはこのポリシーに従って情報の収集と使用に同意したことになります。
私たちは誰か(データ管理者)
あなたの個人情報に責任を持つデータ管理者は次のとおりです:
私たちが収集する情報
私たちはサービスを提供し改善するために、さまざまな種類の情報を収集します:
A. あなたが私たちに提供する情報
- アカウント情報: メールまたはGoogle (Firebase)を使用して登録する場合、あなたの名前、メールアドレス、プロフィール写真を収集します。
- 請求情報: 私たちはサーバーにあなたのクレジットカード情報を保存しません。支払いはStripeとPayPalによって安全に処理されます。私たちは取引IDと請求履歴のみを保持します。
- 通信データ: メールまたはライブチャット(Tawk.to)を通じてサポートに連絡する際に提供される情報。
B. 自動的に収集される情報
- デバイスおよび技術データ: eSIMインストールに必要なIPアドレス、ブラウザの種類、オペレーティングシステム、およびデバイス識別子。
- 使用データ: トラフィックデータやログなど、あなたが私たちのウェブサイトやアプリをどのように使用するかに関する詳細(Google Analytics 4で分析)。
C. eSIM データ
サービスをアクティブ化するために、eSIMプロファイル(ICCID)およびその使用状況(データ消費、有効期間)に関連する技術データを処理します。
D. セキュリティモニタリング
For account security and fraud prevention, we collect:
- IP Addresses: Your real IP address (not server proxy IP) for login monitoring and error reporting
- Device Information: Device model (e.g., iPhone, iPad) and operating system version
- Login Times: Timestamp and geographic location (country) derived from IP address
- Session Data: Active device sessions for security alerts
このデータは、詐欺防止とサービス改善のための正当な利益に基づいて収集されます。
E. フライト検索データ
フライト検索ツールをご利用いただく際、お客様の検索履歴(出発地、目的地、日付など)は、外部の航空券予約提携APIへと送信されます。ただし、すべての取引は提携先企業の安全なウェブサイト上でのみ処理されるため、当社が旅行者の詳細、パスポート情報、あるいはクレジットカード等の支払いデータを閲覧・収集・保存することは一切ありません。
データの使用方法
- サービス提供: eSIM QRコードを生成して配信し、インターネット接続を確保するため。
- 支払い: 取引を処理し、StripeとPayPalを介して不正行為を防止するため。
- サポート: チャットまたはメールシステムを通じたお問い合わせに対応するため。
- 通信: 取引メール(領収書、QRコード)を送信するため、およびオプトインした場合は新しい目的地やオファーに関するニュースレターを送信するため。
- セキュリティ:ログイン監視、不正行為の検出と防止。
- 法的遵守: スペインおよび世界中の税法および電気通信規制を遵守するため。
商標・ブランド名の免責事項
ℹ️ 参考情報:このサイトに記載されている商標および製品名(Apple®など)は各所有者に帰属します。
公式としてスポンサードを受けているわけではありません。
識別目的のみで商標を使用しています。航空会社等のロゴも所有者に帰属します。
本サイトに登場する各商標はそれぞれの会社のものとなります。
支払い方法と商標
私たちは、StripeとPayPalを通じて、主要なクレジットカード、デビットカード、デジタルウォレットを使用して安全に支払いを受け付けます。
- Visa: Visa® is a registered trademark of Visa International Service Association.
- Mastercard: Mastercard® is a registered trademark of Mastercard International Incorporated.
- American Express: American Express® is a registered trademark of American Express Company.
- PayPal: PayPal® is a registered trademark of PayPal, Inc.
- Apple Pay: Apple Pay is a trademark of Apple Inc., registered in the U.S. and other countries.
- Google Pay: Google Pay is a trademark of Google LLC.
データの共有(第三者)
お客様の個人データを販売することはありません。即時のeSIM接続、安全な決済、および信頼性の高いグローバルインフラストラクチャを提供するため、ViaConectaはGDPR第28条に従って信頼できるサードパーティ処理者を利用します:
| Subprocessor / Partner Category | Role & Purpose | Processing Location | Transfer Guarantee |
|---|---|---|---|
| Wholesale Mobile Connectivity & eSIM Provisioning Partners | eSIM profile generation (LPA/ICCID), data volume provisioning & local carrier network routing | EU / International | EU Standard Contractual Clauses (SCCs) |
| Cloudflare, Inc. | Global Edge CDN, DNS security, Web Application Firewall (WAF), Cloudflare Workers AI processing | Global / USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Server & Cloud Infrastructure (Hetzner Online GmbH) | Production cloud application server hosting, database backups, file storage & system logs | Germany (EU) | EU Native GDPR Compliance |
| Supabase, Inc. | Managed cloud database infrastructure (PostgreSQL), encrypted user data storage | EU / USA | EU Standard Contractual Clauses (SCCs) |
| Google Ireland Ltd / Firebase | User authentication (Google Sign-In), cloud backend hosting & Google Analytics 4 | EU / USA | EU-US Data Privacy Framework (DPF) & SCCs |
| Apple Inc. | Apple Sign-In authentication & WebAuthn Passkeys validation | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Stripe Technology Europe, Ltd | PCI-DSS compliant credit/debit card, Apple Pay & Google Pay checkout payment processing | Ireland (EU) / USA | EU-US Data Privacy Framework (DPF) & SCCs |
| PayPal (Europe) S.à r.l. | PayPal digital wallet payment processing & fraud prevention | Luxembourg (EU) | EU Native GDPR Compliance |
| Transactional Email & SMTP Infrastructure | Order confirmation receipt delivery, eSIM QR code transmission, password resets & security alerts | EU / USA | EU Standard Contractual Clauses (SCCs) |
| Tawk.to Ltd | Live customer support chat widget & support ticket resolution | UK / EU | UK/EU GDPR Adequacy Decision & SCCs |
| Microsoft Corporation (Clarity) | Aggregated user interaction heatmaps & performance optimization | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Ticketmaster / Event Partners | Global event ticket search & discovery integration | USA / EU | EU-US Data Privacy Framework (DPF) & SCCs |
| Public Transport & Transit APIs | European train & transit route schedule aggregation (DB, SBB, ResRobot) | EU | EU Native GDPR Compliance |
| Travel & Airline Affiliate Networks | Flight search result routing and referral booking redirection | EU / USA | EU Standard Contractual Clauses (SCCs) |
あなたの権利 (GDPR)
これらの権利を行使するには、[email protected] までご連絡ください。
AIトラベルアシスタント
✅ 透明性の高いAIデータ処理:AIクエリはCloudflare Workers AIを介して動的に処理され、公開モデルの学習には使用されません。
- Privacy-Focused Processing: AI queries are processed dynamically to assist with destination and eSIM selection. ViaConecta does not retain permanent chat logs in its core application database.
- Cloudflare AI Infrastructure: Processing is performed securely via Cloudflare Workers AI (utilizing open-source LLMs such as Llama). Data is handled in accordance with Cloudflare’s enterprise security policies and is not used to train public AI models.
- Transient Session Context: The assistant maintains context only during your active session to provide relevant answers. Closing the session clears local conversational context.
- No Data Monetization: We do not sell, rent, or share your AI interaction data with third-party advertisers or data brokers for marketing purposes.
AIアシスタントは、旅行の計画やeSIM情報の提供のみを目的としています。決済カードの詳細やパスワードへのアクセス権限はありません。
クッキー
私たちはあなたの体験を向上させるためにクッキーを使用します(例:ログイン状態の維持、言語の記憶)。詳細については、クッキーポリシーをご覧ください。
子供のプライバシー
当社のサービスは、16歳未満の人(「子供」)を対象としていません。私たちは、16歳未満の人から故意に個人を特定できる情報を収集することはありません。あなたが親または保護者であり、あなたの子供が私たちに個人データを提供したことに気付いた場合は、私たちに連絡してください。
データ保持
お客様のデータは、このポリシーに記載された目的のために必要な期間のみ保持します。
- Active Sessions: 30 days from last login
- Error Logs: 90 days for debugging purposes
- Account Data: Until you request deletion or close your account
- AI Chat History: Not stored (deleted immediately after session ends)
- Payment Records: As required by law for tax compliance (typically 7 years)