Privacy Policy
Last updated: July 28, 2026
This English translation is provided for convenience. In the event of any discrepancy between this translation and the Japanese version, the Japanese version shall prevail.
AltPilot (the "Company") is committed to protecting privacy in the web analytics service "RevenueScope" (the "Service"). This policy explains what information we collect, how we use it, and how we protect it.
1. Information We Collect
1-1. Information about service users (site operators)
- Account information: email address and name (used for account management, providing the Service, and communication)
- Payment information: credit card details are processed directly by our payment processor (Stripe, Inc.); the Company does not store them
- Usage logs: access timestamps and features used (used for service improvement)
- Ad spend data: ad spend by platform and month, as registered by the service user from the settings screen (entered in a form or uploaded as CSV; used to calculate ROAS and analyze budget allocation)
1-2. Information about website visitors (via the tracking script)
Through the tracking script installed on a user's website, we collect the following information. This information is processed under an entrustment of the user's analytics operations (Article 27, Paragraph 5, Item 1 of the Act on the Protection of Personal Information of Japan).
| Category | Items collected |
|---|---|
| Identifiers | Visitor ID (rs_visitor_id), session ID (rs_session_id) ※ Random UUIDs assigned via cookies. We do not collect information that directly identifies individuals, such as names or email addresses |
| Browsing information | Page URL, referrer URL, session duration, page view count |
| Traffic source information | UTM parameters (source, medium, campaign, term, content), ad click IDs (gclid, fbclid, yclid, ttclid, ldtag_cl) |
| Device information | Device category (mobile/desktop/tablet), browser name, OS name |
| Geographic information | Country, region, city (estimated from IP address; the IP address itself is not stored) |
| Revenue information | Transaction ID, amount, currency (automatically captured from the website's dataLayer purchase events) |
1-3. Data from external service integrations (Google Search Console)
Only when a service user connects their own external service account from the settings screen, we retrieve the following data via OAuth authorization. Connecting is optional and is not required to use the Service's core features.
- Google Search Console: We retrieve search performance data (search queries, clicks, impressions, average position, and page URLs) for the property the user selects, on a read-only basis (webmasters.readonly). This data is used solely to provide the user with reports that analyze their own search keywords against their revenue. We do not share it with third parties, use it for advertising purposes, or allow humans to read it except where necessary for support, security, or legal compliance.
RevenueScope's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. OAuth tokens are stored encrypted; disconnecting from the settings screen or revoking access from your Google account settings invalidates the token and stops any further data retrieval. You can request deletion of already-retrieved data via the procedure in Section 7.1.
1-4. Information obtained from public sources for sales outreach
For the purpose of introducing the Service, the Company may obtain contact information of personnel at businesses operating their own e-commerce sites and at e-commerce support companies (company name, department, name, email address, phone number, etc.) from publicly available sources such as company websites (including published contact points), publicly posted company email addresses, and public business directories.
This information is used solely for introducing and proposing the Service and for related communications. We do not provide or sell it to third parties. We retain it only for as long as necessary for these purposes and delete it without undue delay once no longer needed.
If you do not wish to receive sales communications from the Company, or would like the information obtained about you to be deleted, please let us know via the method described in the email you received or by contacting support@revenuescope.jp. We will stop further communications and promptly delete the information upon request. Disclosure and correction requests are accepted at the same contact point.
The information described in this section is obtained solely from public sources, entirely independently of the website visitor information described in Section 1-2. The Company never uses service users' website visitor information for its own sales or marketing purposes (see Section 4).
2. Use of Cookies
The Service's tracking script uses the following first-party cookies.
| Cookie name | Purpose | Duration |
|---|---|---|
| rs_visitor_id | Visitor identification (new/returning determination, linking sessions) | 1 year |
| rs_session_id | Session identification (measuring a sequence of browsing activity as one session) | 30 minutes (extended on each interaction) |
These are first-party cookies set on the user's website domain. We do not use third-party cookies.
3. Disclosures under the External Transmission Rules
Pursuant to the amended Telecommunications Business Act of Japan (Act No. 70 of 2022), we disclose the following.
| Item | Details |
|---|---|
| Recipient | AltPilot (RevenueScope) |
| Information transmitted | URLs of pages viewed, referrer, device and browser information, geographic information (country, region, city), cookie identifiers (rs_visitor_id, rs_session_id), revenue information (via dataLayer) |
| Purposes of use | Providing site operators (service users) with traffic analysis, revenue attribution analysis, and per-channel performance measurement; and producing statistical data anonymized and aggregated so that individual users and visitors cannot be identified (used for service improvement, improvement of analytical models through statistical learning and analysis, and provision of additional features) |
| Opt-out | You can stop further data collection by deleting or blocking rs_visitor_id and rs_session_id in your browser's cookie settings |
4. Purposes of Use
Information about service users (site operators)
- Account management and authentication
- Providing the Service and managing usage
- Communications about the Service (usage notifications, notices of changes to terms, etc.)
- Providing customer support
- Improving the Service and developing new features
Information about website visitors
- Providing service users with traffic analysis and revenue attribution analysis
- Per-channel performance measurement and conversion analysis
- Displaying real-time visitor information
The Company does not use website visitor information for its own purposes (such as the Company's marketing, advertising, or profiling). However, the Company may use statistical data anonymized and aggregated so that individual users and visitors cannot be identified for improving the Service, improving analytical models through statistical learning and analysis, and providing additional features (such as industry-average comparison features). See Section 9 of the Terms of Service for details.
Information obtained from public sources for sales outreach (Section 1-4)
- Introducing and proposing the Service
- Responding to opt-out and deletion requests
5. Third-Party Provision and Sharing
The Company does not sell collected information to third parties. We do not provide information to third parties except in the following cases.
- Service providers necessary for operating the Service: We entrust data processing to cloud service providers in the following categories to the extent necessary to operate our infrastructure. These include providers located in the United States.
- Database and authentication infrastructure
- Payment processing (Stripe, Inc.)
- Website hosting
- As required by law: where disclosure is legitimately requested by government authorities in accordance with applicable law
- Protection of life or property: where necessary to protect a person's life, body, or property
6. Data Security Measures
We take the following measures to protect collected data.
- Encryption in transit: HTTPS (TLS) for all data communication
- Access control: only authenticated users can access their own data
- Data separation: data is logically separated per user
- Backups: regular backups to prevent data loss
- Infrastructure: reliable cloud service providers
7. Your Rights
Service users (site operators) have the following rights.
- Access: access to your account information and collected data
- Correction: correction of account information
- Deletion: requesting deletion of your account and erasure of data
- Data retrieval: viewing analytics data through the dashboard
You can exercise these rights via the settings screen or by contacting support@revenuescope.jp.
Requests from website visitors for disclosure, deletion, or similar are the responsibility of the service user (site operator) as the data controller. The Company will cooperate to a reasonable extent.
7.1 Data deletion procedure
If you wish to delete your account and all collected analytics data, you can request deletion by any of the following methods.
- Delete from the settings screen (immediate): Log in at https://app.revenuescope.jp/settings and delete the target site from the "Danger Zone" using the "Delete site" button. All related data, including events and sessions tied to the site, is deleted immediately. To delete your entire account, delete all sites and then contact the email address below.
- Request by email: Email support@revenuescope.jp from your registered email address with "Data deletion request" in the subject line. After identity verification, we will delete the relevant data within 7 days in principle and notify you by email upon completion.
- Deleting data from external service integrations (Google Search Console): Disconnect the "Search Console integration" in the settings screen. The OAuth tokens stored on the RevenueScope side will be deleted. Deletion of already-retrieved search performance data is handled via (1) site deletion or (2) email request above. To fully revoke the app's permissions on Google's side, revoke access to this app from your Google Account's "Third-party apps & services" page. Ad spend data you registered from the settings screen involves no OAuth integration, and is deleted via (1) site deletion or (2) email request above.
In all cases, all data on our servers (including backups) is completely deleted within 30 days after account closure.
8. Data Retention
- Account information: retained for as long as the account exists; deleted within 30 days after account closure.
- Analytics data: retained for the period of your plan (Free and Starter: 14 months; Growth: 24 months; Scale: 36 months). Data beyond the retention period is deleted automatically.
- Information obtained from public sources for sales outreach: retained only for as long as necessary for the purposes above; deleted promptly upon an opt-out or deletion request.
9. Use by Minors
The Service is intended for businesses and is not directed at persons under 18 years of age.
10. Changes to This Policy
If the Company changes this policy, it will provide notice of the changes on the Service. For material changes, notice will be given at least 30 days in advance.
11. Contact
For inquiries about this policy, please contact:
- Business name: AltPilot
- Personal information protection manager: Toshihiro Shishido
- Email: support@revenuescope.jp