SocialCounter
SocialCounter Privacy Policy
Privacy Policy
Last updated: August 1, 2026 / Effective: August 1, 2026
This Privacy Policy explains how SIMCODE Inc. ("SIMCODE," "we," "us," or "our") collects, uses, shares, and protects personal information in connection with SocialCounter, our real-time social media follower count display service, including the web application and any related iOS/Android applications (the "Service").
This Policy covers two groups of people: account holders (business owners and creators who register for the Service) and store visitors(customers of our account holders who scan a QR code in a store to receive a coupon, or who view a public display or coupon page). If you are a store visitor, please see Section 4 in particular.
1. Data Controller
- Company
- SIMCODE Inc.
- Address
- 1-10-8-2F-C Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
- Contact
- contact form
2. Information We Collect from Account Holders
1. Information you provide directly
- Email address (at registration and login)
- Password, if you choose email/password authentication (stored in hashed form; never stored in plain text)
- Settings and content you enter in the Service (display settings, milestone and jackpot settings, coupon campaign settings, language preferences)
2. Information from social login
- Google login: name, email address, profile image URL, Google account ID
- Facebook login: name, email address, profile image URL, Facebook user ID
3. Information from connected social media accounts
- YouTube: channel name, channel ID, subscriber count (public information)
- Instagram: username, account ID, follower count (public information)
- Facebook: page name, page ID, follower/like counts (public information)
- TikTok: username, account ID, follower count (public information)
- OAuth access tokens and refresh tokens issued by the above platforms, which we store so the Service can periodically retrieve your follower counts, together with a history of those counts over time
4. Payment and subscription information
- Subscription plan, subscription status, and billing-related identifiers generated by our payment processor Stripe (such as a Stripe customer ID)
- Your full payment card details (card number, expiry date, security code) are collected and processed directly by Stripe and are never stored on our servers
5. Information collected automatically
- Access logs (IP address, date and time of access, referrer, user agent)
- Device information (OS, browser type and version, screen resolution)
- Cookies and similar technologies (see Section 7)
- Service usage history (display mode settings, effect settings, and similar operational logs)
3. Information We Collect via Affiliate Links
When a visitor arrives at our website through an affiliate referral link, we record the referral code in a cookie (see Section 7) and log the click, including the visited path, referrer, user agent, and a truncated one-way hash of the visitor's IP address (we do not store the raw IP address in the click log). This is used to attribute referrals and prevent click fraud.
4. Information We Collect from Store Visitors
If you scan a SocialCounter QR code in a store, or open a coupon or display page operated by one of our account holders, we collect and process the following on behalf of, and in order to provide the coupon and display features to, that store:
- Session identifier: a randomly generated session ID stored in a cookie on your device (see Section 7), used to associate your visit with any coupons issued to you and to prevent duplicate issuance;
- QR scan records: the fact and time of each scan, linked to the store's account and your session ID;
- Coupon records: coupons issued to your session (coupon code, tier, platform followed, issue/expiry/redemption times);
- IP address: used for rate limiting and to enforce per-IP issuance limits that prevent coupon abuse; and
- Prize draw entries: if you participate in a jackpot/lottery feature, your session's entry and win/redemption records.
We do not ask store visitors for their name or contact details, and we do not link store visitor sessions to a visitor's identity. Store visitor records are used only to operate the coupon, display, and anti-abuse features, and are not sold or used for third-party advertising. If you have questions about a specific store's campaign, please contact the store; for questions about our processing, contact us at the address in Section 1.
5. How We Use Personal Information
- To authenticate users and manage accounts
- To retrieve and display follower counts for connected social media accounts
- To operate coupon, milestone, jackpot, and display features, including issuing and redeeming coupons for store visitors
- To send service-related notifications and transactional emails (e.g., welcome and cancellation emails)
- To process subscription payments and manage billing
- To analyze usage and improve the Service, fix defects, and develop new features (including A/B testing of our landing page)
- To attribute affiliate referrals and pay affiliate commissions
- To secure the Service, enforce rate limits, and prevent fraud and abuse (including preventing repeated free-trial signups and coupon farming)
- To respond to inquiries and enforce our Terms of Service
- To comply with legal obligations
6. How We Share Personal Information
We do not sell personal information. We share personal information only with the service providers below (acting on our behalf), with the relevant social media platforms as necessary to operate account connections, or where required by law, to protect life or safety, or in connection with a merger or business transfer.
1. Supabase Inc. (USA)
Purpose: authentication infrastructure and database hosting.
Data: email addresses, social login credentials, user settings, social media connection data (including OAuth tokens), and store visitor records.
Data is hosted in the Tokyo region (ap-northeast-1); as Supabase is a U.S. company, it may be subject to disclosure requests from U.S. authorities. Supabase holds SOC 2 Type II certification.
2. Stripe, Inc. (USA)
Purpose: subscription payment processing.
Data: email address, plan and payment amounts, billing address (where collected for tax calculation), and Stripe-generated customer IDs. Card details are handled solely by Stripe (PCI DSS Level 1 certified) and never reach our servers.
3. Google LLC (USA)
Purpose: Google social login; retrieval of YouTube subscriber counts via the YouTube Data API; website analytics via Google Tag Manager and Google Analytics 4 (see Section 7).
Data: Google authentication tokens; analytics data as described in Section 7.
4. Meta Platforms, Inc. (USA)
Purpose: Facebook social login; retrieval of follower counts via the Facebook Graph API and Instagram API.
Data: Meta authentication tokens.
5. ByteDance Ltd. / TikTok Inc.
Purpose: retrieval of follower counts via the TikTok API.
Data: TikTok authentication tokens (where applicable).
6. Resend, Inc. (USA)
Purpose: delivery of transactional emails (e.g., welcome and cancellation emails).
Data: recipient email address and email content.
7. Cookies and Analytics
We use the following cookies and similar technologies:
- Essential cookies: authentication/session cookies (required to log in and use the Service), and a maintenance-access cookie used during maintenance windows;
- Store visitor session cookie (
coupon_sid): identifies a store visitor's session for coupon issuance and duplicate prevention; retained for up to 12 months; - A/B testing cookie (
ab_hero): randomly assigns a landing page variant to measure which performs better; retained for up to 30 days; - Affiliate referral cookie (
aff_ref): records the affiliate code that referred you; retained for up to 90 days; and - Analytics: our production website uses Google Tag Manager and Google Analytics 4 to understand site usage and improve the Service. Google may set cookies and collect usage data as described in Google's privacy documentation. You can opt out of Google Analytics using Google's browser opt-out tools.
You can refuse cookies in your browser settings, but refusing essential cookies may make part or all of the Service unusable.
8. Data Retention
- We retain personal information only as long as necessary for the purposes described in this Policy.
- Account data (including authentication data, social media connection data and tokens, settings, and follower history) is retained while your account is active and deleted when you delete your account.
- After account deletion, we retain a limited record of the deletion (including the account email address) to prevent fraudulent re-use of free trials, and any records we are legally required to keep, for as long as necessary for those purposes.
- Access logs are retained for up to one year from collection.
- Store visitor records (session IDs, scan and coupon records) are retained while the relevant store's account is active and are deleted when that account is deleted.
9. Security
- All communications with the Service are encrypted using SSL/TLS.
- Passwords are stored only in hashed form.
- Database row-level security (RLS) restricts each user's access to their own data, and administrative access is limited on a need-to-know basis.
- We maintain organizational procedures for responding to data incidents.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
10. Your Rights
All users
Subject to applicable law, you may request access to, correction of, deletion of, or restriction of our processing of your personal information, and you may object to certain processing or request a copy of your data in a portable format. To exercise these rights, contact us through our contact form. We may ask you to verify your identity before responding. We aim to respond within one month. Requests are free of charge.
EEA, UK, and Switzerland (GDPR)
- Our legal bases for processing are: performance of a contract (providing the Service), consent (e.g., social login, marketing communications), legitimate interests (service improvement, security, fraud prevention), and compliance with legal obligations.
- You have the rights of access, rectification, erasure, restriction, data portability, and objection, and the right to withdraw consent at any time (without affecting prior processing).
- You have the right to lodge a complaint with your local supervisory authority.
- International transfers: Japan has received an adequacy decision from the European Commission (effective January 2019). Transfers to the United States rely on appropriate safeguards such as Standard Contractual Clauses or the EU-U.S. Data Privacy Framework, as applicable to each provider.
California (CCPA/CPRA)
- You have the right to know what personal information we collect, use, and disclose; the right to request deletion and correction; and the right not to receive discriminatory treatment for exercising your rights.
- We do not sell personal information and do not share personal information for cross-context behavioral advertising.
- You may exercise your rights, or designate an authorized agent to do so, through our contact form.
Japan (APPI)
Users in Japan may make requests regarding retained personal data (disclosure, correction, cessation of use, cessation of third-party provision) under the Act on the Protection of Personal Information, using the contact in Section 1.
11. Children
The Service is intended for users aged 16 and over. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will promptly delete it.
12. Google API Services
The Service uses Google API Services, including the YouTube Data API. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke the Service's access to your Google account at any time at https://myaccount.google.com/permissions.
13. Meta Platforms; Data Deletion Requests
The Service uses Facebook Login, the Facebook Graph API, and the Instagram API. We handle data obtained from Meta platforms in accordance with the Meta Platform Terms and Developer Policies. We do not sell data obtained from Meta platforms and do not use it for advertising without your consent.
If you remove the SocialCounter app from your Facebook settings (https://www.facebook.com/settings/?tab=applications), Meta sends us a data deletion request. We then delete the connected Facebook/Instagram account data associated with your Facebook user ID, record the request, and provide a confirmation code and a status page where you can confirm the deletion.
14. Stripe Payments
Payment processing is provided by Stripe, Inc. Card details are collected, processed, and stored directly by Stripe and never reach our servers. We share with Stripe your email address (for payment notifications and receipts), the payment amount and plan, and, for customers billed in USD, your billing address for tax calculation. For details, see Stripe's privacy policy at https://stripe.com/privacy.
15. Changes to This Policy
- We may update this Policy to reflect changes in law or in the Service.
- We will announce the updated Policy and its effective date on our website or by other appropriate means, and for material changes we will provide at least 14 days' advance notice.
- Where your consent is legally required for a change, we will obtain it.
16. Governing Law; Contact
- This Policy is governed by the laws of Japan, and the Tokyo District Court has exclusive jurisdiction as the court of first instance over disputes relating to it, except where mandatory data protection law (such as the GDPR) grants you rights or venues that prevail.
- Privacy contact
- SIMCODE Inc. Privacy Desk
- Address
- 1-10-8-2F-C Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
- Contact
- contact form
This Policy is effective as of August 1, 2026.