What information IceShore collects
"User Personal Information" is any information about one of our Users which could, alone or together with other information, personally identify them or otherwise be reasonably linked or connected with them. Information such as a username and password, an email address, a real name, an Internet protocol (IP) address, and a photograph are examples of “User Personal Information.”
User Personal Information does not include aggregated, non-personally identifying information that does not identify a User or cannot otherwise be reasonably linked or connected with them. We may use such aggregated, non-personally identifying information for research purposes and to operate, analyze, improve, and optimize our Website and Service.
Information users provide directly to IceShore
We require some basic information at the time of account creation. When you create your own username and password, we ask you for a valid email address.
If you sign on to a paid Account with us or buy anything on our service, we collect your full name and address. Payment is processed by Stripe (Stripe, Inc.), and IceShore does not store your credit card or other payment method information.
You may choose to add a profile image (avatar) and a biography to your Account profile. This information may include User Personal Information. Please note that your profile information may be visible to other Users of our Service.
Information IceShore automatically collects from your use of the Service
If you're accessing our Service or Website, we automatically collect the same basic information that most services collect. This includes information about how you use the Service, such as the pages you view, the referring site, your IP address and session information, and the date and time of each request. This is information we collect from every visitor to the Website, whether they have an Account or not. This information may include User Personal information.
As further described below, we automatically collect information from cookies and similar technologies (such as cookie ID and settings) to keep you logged in, to remember your preferences, and to identify you and your device.
We may collect certain information about your device, such as its IP address, browser or client application information, language preference, operating system and application version, device type and ID, and device model and manufacturer. This information may include User Personal information.
Information we collect from third parties
IceShore may collect User Personal Information from third parties. For example, this may happen if you sign up for training or to receive information about IceShore from one of our vendors, partners, or affiliates. IceShore does not purchase User Personal Information from third-party data brokers.
What information IceShore does not collect
We do not intentionally collect “Sensitive Personal Information”, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. If you choose to store any Sensitive Personal Information on our servers, you are responsible for complying with any regulatory controls regarding that data.
If you are a child under the age of 13, you may not have an Account on IceShore. IceShore does not knowingly collect information from or direct any of our content specifically to children under 13. If we learn or have reason to suspect that you are a User who is under the age of 13, we will close your Account. Please see our Terms of Service for information about Account termination. Different countries may have different minimum age limits, and if you are below the minimum age for providing consent for data collection in your country, you may not have an Account on IceShore.
We do not intentionally collect User Personal Information that is stored in your contents or other free-form content inputs. Any personal information within a user's content is the responsibility of the content owner.
How IceShore uses your information
We use your information for the following purposes:
We use your Registration Information to create your account, and to provide you the Service.
We use your Payment Information to provide you with the Paid Account service or any other IceShore paid service you request.
We use your User Personal Information, specifically your username and profile image, to help us or other users identify you on IceShore. Its purposes include other users inviting you to an architecture or a workspace, and displaying your role in that architecture or workspace.
We use your Profile Information to fill out your Account profile and to share that profile with other users.
We use your email address to communicate with you.
We use User Personal Information to respond to support requests.
We may use User Personal Information to invite you to take part in surveys, beta programs, or other research projects.
We use Usage Information and Device Information to better understand how our Users use IceShore and to improve our Website and Service.
We may use your User Personal Information if it is necessary for security purposes or to investigate possible fraud or attempts to harm IceShore or our Users.
We may use your User Personal Information to comply with our legal obligations, protect our intellectual property, and enforce our Terms of Service.
We limit our use of your User Personal Information to the purposes listed in this Privacy Statement. If we need to use your User Personal Information for other purposes, we will ask your permission first.
Our legal bases for processing information
To the extent that foreign laws such as the GDPR apply to our processing of User Personal Information, we process it on the following legal bases:
Contract Performance:
When you create an IceShore Account, you provide your Registration Information. We require this information for you to enter into the Terms of Service agreement with us, and we process that information on the basis of performing that contract. We also process your username and email address on other legal bases, as described below.
If you have a paid Account with us, we collect and process additional Payment Information on the basis of performing that contract.
Consent:
We rely on your consent to use your User Personal Information under the following circumstances: when you fill out the information in your user profile; when you decide to participate in a training, research project, beta program, or survey; and for marketing purposes, where applicable. All of this User Personal Information is entirely optional, and you have the ability to access, modify, and delete it at any time. At the time of account registration, we obtain your explicit consent (via checkbox) to the Terms of Service and this Privacy Statement, and we record the version consented to and the timestamp. Whether to receive marketing emails is an optional choice that you may make and withdraw at any time.
Legitimate Interests:
Generally, the remainder of the processing of User Personal Information we perform is necessary for the purposes of our legitimate interest, for example, for legal compliance purposes, security purposes, or to maintain ongoing confidentiality, integrity, availability, and resilience of IceShore’s systems, Website, and Service.
If you would like to request deletion of data we process on the basis of consent or if you object to our processing of personal information, please email to legal@iceshore.ai.
How we share the information we collect
We may share your User Personal Information with third parties under one of the following circumstances:
With your consent
We share your User Personal Information, if you consent, after letting you know what information will be shared, with whom, and why. Additionally, you may direct us through your actions on IceShore to share your User Personal Information.
With service providers
We entrust the handling of User Personal Information to the following providers. We have contracts with each of them to protect personal information (data processing terms).
- Amazon Web Services (Amazon Web Services, Inc.): operating the Service and storing data (Japan, Tokyo region); receiving, storing and replying to inquiry emails (United States); delivering the Service (edge locations in various countries); storing access logs (United States; kept for 90 days)
- SendGrid (Twilio Inc.): sending notification emails (United States)
- Google Workspace (Google LLC): receiving and storing inquiry emails (United States and other countries)
- Stripe (Stripe, Inc.): payment processing (United States and other countries)
- Google Analytics 4 (Google LLC): website analytics (United States and other countries)
- Claude (Anthropic, PBC): reviewing and summarizing inquiry emails and drafting replies; operating the Service and responding to outages (United States)
The Sub-processors for data stored in your Workspace, or processed by us through the use of your Workspace (Customer Data), are listed in Annex 3 of the Data Processing Agreement.
For security purposes
If you are a member of a Workspace (the unit of work within our Service, as defined in the Terms of Service), IceShore may share your username, Usage Information, and Device Information associated with that Workspace with an owner and/or administrator of the Workspace, to the extent that such information is provided only to investigate or respond to a security incident that affects or compromises the security of that particular Workspace.
For legal disclosure
IceShore strives for transparency in complying with legal process and legal obligations. Unless prevented from doing so by law or court order, or in rare, exigent circumstances, we make a reasonable effort to notify users of any legally compelled or required disclosure of their information. IceShore may disclose User Personal Information or other information we collect about you to law enforcement if required in response to a valid subpoena, court order, search warrant, a similar government order, or when we believe in good faith that disclosure is necessary to comply with our legal obligations, to protect our property or rights, or those of third parties or the public at large.
Change in control or sale
We may share User Personal Information if we are involved in a merger, sale, or acquisition of corporate entities or business units. If any such change of ownership happens, we will ensure that it is under terms that preserve the confidentiality of User Personal Information, and we will notify you on our Website or by email before any transfer of your User Personal Information. The organization receiving any User Personal Information will have to honor any promises we made in our Privacy Statement or Terms of Service.
Aggregate, non-personally identifying information
We share certain aggregated, non-personally identifying information with others about how our users, collectively, use IceShore, or how our users respond to our other offerings, such as our conferences or events.
Contents
Access to private contents
If your content is private, you control who can access it. Our personnel view private content only in the following cases:
When necessary to respond to a support request from you.
When necessary to maintain the security and integrity of IceShore, or to respond to outages or misuse.
When necessary to comply with the law.
When you have consented.
We automatically scan content by machine to mask credentials and to detect improper content. No person views the content during this scanning. The handling of Workspace data is set out in the
Data Processing Agreement.
Public contents
If your content is public, anyone may view it. If you include User Personal Information, Sensitive Personal Information, or confidential information, such as email addresses or passwords, in your public content, that information may be indexed by search engines or used by third parties.
Other important information
Public information on IceShore
Many of IceShore services and features are public-facing. If your content is public-facing, third parties may access and use it in compliance with our Terms of Service, such as by viewing your profile or contents or pulling data via our API. Some third parties, such as data brokers, are known to scrape IceShore and use the data.
Your User personal information contained in your content may be gathered by third parties. If you do not want your User Personal Information to appear in third parties, please do not include your personal information in the content.
If you would like to use IceShore data, you must comply with our Terms of Service regarding information usage and privacy, and you may only use any public-facing User Personal Information you gather for the purpose for which our user authorized it. For example, where an IceShore user has made an email address public-facing for the purpose of identification and attribution, do not use that email address for the purposes of sending unsolicited emails to users or selling User Personal Information, such as to recruiters, headhunters, and job boards, or for commercial advertising. We expect you to reasonably secure any User Personal Information you have gathered from IceShore, and to respond promptly to complaints, removal requests, and "do not contact" requests from IceShore or IceShore users.
Similarly, contents on IceShore may include publicly available User Personal Information collected as part of the collaborative process.
Retention and deletion
We keep User Personal Information only for as long as we need it for the purposes described in this statement. In practice:
- Account information (user name, email address, profile, language preference): until you close your account. When you close it, we replace the user name and email address in your account registration with non-identifying values. We also erase your profile image and biography, and delete your verification code records and the consent and connection records described below. User names and email addresses in records of Workspace activity (audit logs), invitations and join requests are Workspace data and are handled under the Data Processing Agreement. Email addresses in database operation records are kept for security purposes after you close your account, for the period set out under "Access and security records" below.
- Consent and connection (OAuth / MCP) records (consent viewed, approved, renewed or revoked, referring origin, campaign information identifying how you arrived, anonymous session identifier): 12 months from the date of the record. Anything older is removed by an automated daily job. These records do not include IP addresses.
- Architectures you create and their version history: until we erase it upon request. We keep the most recent 50 versions per architecture and delete older ones beyond that. When you delete an architecture or a workspace in the Service, it is no longer visible to users, but it is not erased from our storage. Closing your account does not erase your architectures from our storage either. The owner of the Workspace (on a Paid Plan, the Customer) may request erasure from our storage by contacting legal@iceshore.ai. The owner may make this request even after closing their own account, by including information that identifies the Workspace, such as its name. Erasure is handled as set out in Section 11 of the Data Processing Agreement. If you are a member of a Workspace, please contact its owner.
- Email you send us: kept as a record of our correspondence (no fixed retention period). Contact legal@iceshore.ai if you want it deleted.
- Payment records: held by Stripe (Stripe, Inc.), which processes payments for us. We also keep transaction records for as long as tax and corporate law require us to.
- Access and security records: kept to keep the Service secure and to investigate misuse and outages. Delivery access logs (IP address, request URL, browser information and referrer) are kept for 90 days, service processing logs (IP address and request details) for 365 days, and database operation records (including the email address of the account that performed the operation) for up to 7 years. They are kept after you close your account until the relevant period has passed.
- Backups: up to 7 days.
We may keep information longer where the law requires it, where we need it to investigate a dispute or abuse, or where it cannot be removed immediately from backups. In those cases we use it only for that purpose.
To ask us to disclose, correct, stop using or delete your User Personal Information, contact legal@iceshore.ai. We will verify that the request comes from you before acting on it. Requests about data stored in a Workspace will be referred to the owner of that Workspace (on a Paid Plan, the Customer), as set out in Section 7 of the Data Processing Agreement. If you live in the European Economic Area (EEA) or the UK, you may also lodge a complaint with the data protection supervisory authority in your country. If you only want to stop marketing email, you can do so immediately from the unsubscribe link in any such message.
How IceShore secures your information
We employ reasonable security precautions to protect personal information about you. Our services are operated from an environment with integrated security measures to help protect against the loss, misuse, and alteration of personal information provided on or through the services. These security measures include encryption of data in transit. However, no method of transmitting or storing data is completely secure. As a result, although we strive to protect personal information about you, we cannot guarantee the security of any information you transmit to us through or in connection with the services. If you have reason to believe that personal information is no longer secure, please notify us immediately by contacting us at legal@iceshore.ai. For details, see the Data & trust page of our Help Center.
Depending on your email settings, IceShore may occasionally send notification emails about new features, requests for feedback, important policy changes, or to offer customer support. We also send marketing emails, based on your choices and in accordance with applicable laws and regulations. Please note that you cannot opt out of receiving important communications from us, such as emails from our Support team or system emails. You can stop marketing emails at any time using the one-click unsubscribe link included in each email (you may also contact us at legal@iceshore.ai).
Our emails may contain a pixel tag, which is a small, clear image that can tell us whether or not you have opened an email and what your IP address is. We use this pixel tag to make our email more effective for you and to make sure we’re not sending you unwanted email.
Others
Cookies
IceShore uses cookies and similar technologies (e.g., HTML5 localStorage) to make interactions with our service easy and meaningful. Cookies are small text files that websites often store on computer hard drives or mobile devices of visitors. We use cookies and similar technologies (hereafter collectively "cookies") to provide you our services, for example, to keep you logged in, remember your preferences, identify your device for security purposes, and provide information for future development of IceShore. We also use Google Analytics 4 cookies for web analytics (except for visits from the EEA or the UK; see "Tracking and analytics"). If you disable your browser or device’s ability to accept these cookies, you will not be able to log in or use IceShore’s services.
Tracking and analytics
We use a number of third-party analytics and service providers to help us evaluate our Users' use of IceShore, use statistical reports on activity, and improve our content and Website performance. Specifically, we use Google Analytics 4 provided by Google (Google LLC). We have accepted Google's data processing terms for our use of Google Analytics 4. We do not load Google Analytics 4 for visits from the European Economic Area (EEA) or the UK (determined by the browser's time zone). For details of the information your browser sends to third parties, see Information Sent to Third Parties. In addition, we use our own internal analytics software to provide features and improve our content and performance.
External Links
Our services may contain links to various websites that we do not control. When you click on one of these links, you will no longer be transacting business through the service. Third-party websites maintain their own privacy policies, and we do not exercise any control over any of the third-party websites that may be linked to the service. If you visit a website that is linked to the service, you should consult that website’s privacy policy before providing any personal information. Please be aware that we are not responsible for the privacy practices of such other websites, and we are not liable for their misuse of personal information about you.
Cross-border data transfers
We store and process personal information mainly in Japan (AWS Tokyo region). We also transfer personal information to the providers outside Japan listed under "With service providers."
Transfers from the European Economic Area (EEA) and the UK to Japan rely on the adequacy decisions for Japan made by the European Commission and the UK. When we transfer personal information received from the EEA or the UK to a provider outside Japan, we follow the Supplementary Rules of Japan's Personal Information Protection Commission and rely on the mechanism available for that provider (such as its participation in the EU-U.S. Data Privacy Framework or standard contractual clauses included in our contract).
With providers outside Japan, we have established by contract a system that meets the standards of Article 28(1) of Japan's Act on the Protection of Personal Information, and we take the measures required by Article 28(3). We will inform you of those measures on request.
Updates to this Privacy Statement
We may change this Privacy Statement. We will announce material changes on our Website or by email. The date of the latest update is shown as the effective date at the top of this page.
Governing Language
The Japanese version of this Privacy Statement is the authoritative text. Even where a translation into English or any other language is provided, in the event of any discrepancy or inconsistency between the Japanese version and a translation, the Japanese version shall prevail.
Questions Regarding this Privacy Statement
If you have any questions or comments regarding this Privacy Statement, please send us an email at legal@iceshore.ai.
Data controller: Launchers Co., Ltd. (10F Shibadaimon Center Bldg, 1-10-11 Shibadaimon, Minato-ku, Tokyo 105-0012, Japan)
Representative: Shintaro Hara, President and Representative Director
Person responsible for personal information protection: Shintaro Hara