Privacy Policy
Privacy Policy
1. Our approach to protecting personal information
CrossData Co., Ltd. ("we," "us," or "the Company") handles the personal information of users and others involved with our eSIM service "Cross eSIM" carefully and appropriately, in accordance with applicable data protection laws and guidelines. We are committed to the following.
- We comply with applicable data protection laws and regulations and follow generally accepted, fair practices for handling personal information, and we continually work to improve how we handle it.
- We set clear internal rules for handling personal information and make sure our staff understand them, and we require our business partners to handle personal information appropriately as well.
- When we collect personal information, we specify why we are collecting it, notify or publicly announce that purpose, and use the information only for that purpose.
- We generally keep personal information no longer than necessary for the purpose, and unless the law permits otherwise, we delete it promptly once that period ends or the purpose has been achieved.
- We take appropriate measures to prevent the leakage, loss, or alteration of personal information. If such an incident occurs, we report it to the relevant supervisory authority and notify the affected individuals in accordance with applicable law.
- We accept requests to access, correct, delete, or suspend the use of the personal information we hold about you, and we respond to them in good faith through our designated contact point.
2. Personal data we collect and how we use it
Personal data we collect
- Your name, email address, phone number, address, and other information you enter in our forms
- Information about your orders, payments, and eSIM use (such as order number, identifiers like the ICCID, and data usage)
- Information collected automatically when you use our website and app (such as cookies, IP address, and browser type)
- For corporate customers, the company name, department, and contact person's details
- Other details you provide when you contact us about buying or using an eSIM (for example, through inquiries or support)
Payment card details are handled directly by our payment processor (Stripe); we do not collect or store them ourselves (we keep only payment tokens, customer IDs, and similar identifiers).
How we use your information
We collect the personal information necessary to run our business and use it for the following purposes:
- Providing our products and services (*)
- Providing related after-sales support
- Billing and collecting fees, protecting our receivables, and issuing receipts and invoices (this may include outsourcing the billing and collection of fees)
- Considering and developing new products and services
- Providing information about our products and services, making proposals, and carrying out sales activities
- Training our staff to improve our sales and customer-outreach practices
- Conducting market research and other studies
- Running prize draws, campaigns, and similar promotions
- Compiling and using statistics for business analysis
- Responding to requests made under applicable data protection laws, and monitoring and auditing how personal information is handled
- Managing our contractual relationships with business partners
- Detecting and preventing fraudulent use and payments, and keeping the service secure
- For corporate customers, managing accounts, invoice-based payments, and organization users and invitations
- Other purposes reasonably necessary in connection with the above
* Our business
- Provision of eSIMs
3. Outsourcing and use of third-party services (including provision to third parties located overseas)
As necessary to fulfill the purposes above, we outsource the following operations to external providers or use services provided by third parties. We exercise appropriate supervision over these providers — including through contracts — to keep personal data secure. Where a provider is located overseas, this constitutes a "provision to a third party located in a foreign country" under the APPI.
- Payment processing (e.g., credit card payments): Stripe (located in the United States). As a provision to a third party located overseas, this is handled under a framework compliant with the APPI. The information involved includes the card and billing details needed for payment and information used to detect fraud.
- Server and storage operation and maintenance, and data hosting: handled within Japan, so this is not a provision to a third party located overseas.
- Email delivery: handled within Japan, so this is not a provision to a third party located overseas.
For details on the data protection systems in the countries mentioned above, please refer to publicly available information from the competent data protection authorities. For the measures each provider takes to protect personal information, please see that provider's privacy policy.
4. Provision to third parties
Other than the outsourcing described in this policy and in the following cases, we do not disclose or provide personal information to third parties:
- With your consent
- When the information is in a form that cannot identify you, such as statistical data
- When required or permitted by law
- When necessary to protect someone's life, body, or property and it is difficult to obtain your consent
- When cooperating with a government body or similar entity, where obtaining consent would likely impede that work
- To help prevent non-payment of fees, we may provide a defaulting customer's name, address, and similar details to other businesses in the relevant industry
- To collect arrears, we may assign the outstanding claim to a third party and provide the assignee with details such as the defaulting customer's name, address, and unpaid amount
- In connection with a merger, reorganization, or business transfer, we may provide personal information for due diligence or as otherwise necessary
5. Joint use of personal data
To conduct our business smoothly, we jointly use your name, company name, contact details, and the content of telephone conversations together with our parent company, subsidiaries, and affiliated companies. In addition to our own purposes, these companies use the information for the following businesses: the OA equipment business (selling office equipment such as copiers, multifunction devices, telephones, and PCs, as well as office supplies); the SHOP business (selling and brokering mobile phones and brokering credit cards); the insurance business; and the internet business (internet advertising, rental servers, mobile content services, and portal sites). We are responsible for managing this information.
6. Disclosure procedure
If you request disclosure of the personal data we hold about you, we will confirm your identity and then respond, in principle in writing, within a reasonable period and scope. In some cases we may be unable to comply because of legal requirements.
7. Correction and deletion
If you ask us to correct, add to, or delete the personal data we hold about you, we will confirm your identity and, where the data is inaccurate, correct, add to, or delete it within a reasonable period and scope.
8. Suspension of use and deletion
If you ask us to suspend the use of or delete the personal data we hold about you and one of the following applies, we will confirm your identity and then, in principle, suspend its use or delete it within a reasonable period and scope. Please note that if some or all of this information is suspended or deleted, we may no longer be able to provide services that meet your needs. We may also be unable to act on such requests for information we are required to retain by law.
- When we have used personal information beyond the purposes described in Section 2 without your consent
- When we obtained the personal information by unlawful or improper means
- When we have improperly disclosed personal information to a third party
9. How to contact us and submit requests
For the requests described in Sections 6, 7, and 8 above, and for any other questions about personal information, please contact us using the details below. Please note that we may be unable to act on requests that are not submitted through this procedure.
Contact
- Address
- 160-0022 8F Sumitomo Fudosan Shinjuku Gyoen Bldg.,
2-13-12 Shinjuku, Shinjuku-ku, Tokyo
CrossData Co., Ltd. - info@cross-esim.com
10. Cookies, analytics, and advertising
1. Use of cookies
Some pages on our website use cookies. A cookie is a standard browser technology that stores small pieces of information on your device — for example, to remember the contents of your cart. Cookies can identify your device, but our website does not store information that personally identifies you. If you disable cookies in your browser, some parts of the website may not work.
2. SSL/TLS encryption
Pages of our website that handle your personal information use SSL/TLS, and information such as personal data and credit card numbers is encrypted when transmitted between your device and the website. This prevents the information from being intercepted in transit.
3. Google Analytics (user attributes and interests)
To plan and improve our services, we use Google Analytics and may refer to its "Reports on user attributes and interest categories." If you would like to opt out of data collection by Google Analytics, you can do so here.
4. Advertising using Facebook Custom Audiences, LINE's audience data feature, Google Ads Customer Match, and Yahoo! Ads customer-data audience lists
We may deliver ads using Facebook "Custom Audiences," LINE's "audience data feature," Google Ads "Customer Match," and Yahoo! Ads "delivery using customer data audience lists." To do so, we may match encrypted versions of the email addresses, phone numbers, and similar data you have provided against the corresponding Facebook, LINE, Google, and Yahoo! user records, and deliver ads on that basis.
To stop the use of these services, you can opt out here.
5. LINE Advanced Matching and Google Ads enhanced conversions
We may measure ad performance using LINE's Advanced Matching (manual detailed matching) and Google Ads enhanced conversions. To do so, we may match encrypted versions of the email addresses, phone numbers, and similar data you have provided against the corresponding LINE and Google user records.
To stop the use of these features, you can opt out here.
6. Retargeting, behavioral, and affiliate advertising
We use ad delivery services provided by third parties such as Yahoo Japan Corporation, and these third parties may use cookies to collect information about your visits to and activity on our website. That information is handled under the third party's own privacy policy, and you can opt out of its use for advertising through the opt-out tools that third party provides.
11. For customers in the EU/EEA and comparable jurisdictions (GDPR)
If your habitual residence is in the European Union (EU) or European Economic Area (EEA), or in a country with national legislation comparable to the GDPR, this section takes precedence and sets out how we handle personal data under the EU General Data Protection Regulation (GDPR) or comparable legislation. The controller for this section is CrossData Co., Ltd. (contact details are given in Section 9 above).
We process personal data on the following legal bases: performance of a contract; legitimate interests (preventing fraud); legal obligations (tax and other statutory duties); and consent (marketing, ad delivery, and non-essential cookies). Non-essential cookies are used only with your prior consent (opt-in). The categories of personal data we collect and our retention periods are as set out in the main body of this policy.
Under the GDPR, you have the right to access, rectify, erase (the right to be forgotten), restrict the processing of, and port your personal data, to object to processing (including for direct marketing), and to withdraw consent, as well as the right to lodge a complaint with a supervisory authority (data protection authority) (Art. 77). To exercise your rights, please contact us using the details in Section 9 above (we respond in principle within one month of receiving your request). We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing.
Because we are based in Japan, the personal data of customers in the European Economic Area (EEA) is transferred outside the EEA. We carry out such transfers (including transfers to providers in third countries, such as the payment processor Stripe) on the basis of an adequacy decision by the European Commission, the Standard Contractual Clauses (SCCs), or other appropriate safeguards under the GDPR. You may request information about, and a copy of, the safeguards we have put in place.
12. Supplementary provisions
This policy takes effect on November 1, 2022. We may update it in line with changes to laws and guidelines, and we will announce any updates on our website.
Set up in just 3 minutes with
— ready to use in over 125 countries and regions!
Get an eSIM you can use right away, wherever you go!
Buy an eSIM


gives you dependable support, so you can enjoy your time abroad.
