Privacy Policy
CropWatch, LLC (the “Company”) establishes this Privacy Policy (the “Policy”) as follows regarding the handling of personal information of persons who use the Company’s services (“Users”). The Company promotes the protection of personal information by establishing a system for protecting personal information, ensuring that all employees understand the importance of protecting personal information, and requiring them to follow the Company’s personal information protection practices.
Article 1 (Personal Information)
“Personal Information” means “personal information” as defined in Japan’s Act on the Protection of Personal Information (Act No. 57 of 2003; the “APPI”), namely information relating to a living individual that can identify a specific individual by a name, date of birth, or other description contained in that information, or information that contains an individual identification code.
Article 2 (Purposes of Use of Personal Information)
The Company acquires and uses Users’ Personal Information to the extent necessary for the purposes listed below. If the Company uses Personal Information beyond the scope of these purposes, it will obtain the User’s consent in advance by an appropriate method.
- (1) To provide the Company’s services (the “Services”)
- (2) To improve or refine the Services, or to develop new services
- (3) To provide information about new features, updates, campaigns, and similar matters relating to the Services, and about other services provided by the Company, including by email, flyers, and other direct mail
- (4) To contact Users as necessary regarding maintenance, important notices, and similar matters
- (5) To respond to feedback, inquiries, and similar communications from Users regarding the Services, including verifying the User’s identity
- (6) To report to Users on their use of the Services
- (7) To ask Users to cooperate with surveys, interviews, and similar activities relating to the Services, to request their participation in events, or to report the results of those activities and events
- (8) To investigate and analyze Service usage histories and similar information, and to use the results to improve and develop the Services and deliver advertisements
- (9) To provide Personal Information to companies and other organizations participating in events hosted by the Company, based on a User’s consent or application
- (10) To identify Users who have violated the terms of use or who attempt to use the Services for fraudulent or improper purposes, and to deny their use of the Services
Article 3 (Use of Cookies, etc.)
The Company uses technologies such as cookies, information collection modules, and similar technologies (collectively, “Cookies, etc.”) to obtain information about Users’ access to and browsing of the Services. For details about the Cookies, etc. used by the Services, please review the Cookie Policy separately established by the Company.
Article 4 (Management and Protection of Personal Information)
Personal Information will be managed strictly and, except in the circumstances listed below, will not be disclosed or provided to any third party without the User’s consent. The Company also takes preventive and corrective measures against risks such as unauthorized access to, loss, destruction, alteration, or leakage of Personal Information, with due regard for security.
- (1) When it is necessary to protect a person’s life, body, or property and it is difficult to obtain the User’s consent.
- (2) When it is especially necessary to improve public health or promote the sound growth of children and it is difficult to obtain the User’s consent.
- (3) When it is necessary to cooperate with a national government body, local government, or a person entrusted by either of them in performing duties prescribed by laws and regulations, and obtaining the User’s consent is likely to impede the performance of those duties.
- (4) When otherwise permitted by laws and regulations.
Article 5 (Outsourcing the Handling of Personal Information)
The Company may outsource all or part of the handling of Personal Information to the extent necessary to achieve the purposes of use. In that case, the Company will carefully assess the service provider’s qualifications, include confidentiality and other relevant provisions in the agreement, and exercise necessary and appropriate supervision over the service provider.
Article 6 (Disclosure of Personal Information)
A User may request that the Company disclose Personal Information it holds. When the Company receives such a request from a User, it will disclose the information to the User without delay. However, the Company may withhold all or part of the information if disclosure would result in any of the following circumstances. If the Company decides not to disclose the information, it will notify the User of that decision without delay.
- (1) There is a risk of harming the life, body, property, or other rights or interests of the User or a third party
- (2) There is a risk of materially interfering with the proper conduct of the Company’s business
- (3) Disclosure would otherwise violate a law or regulation
Article 7 (Correction, etc. of Personal Information)
- 1. If Personal Information held by the Company is incorrect, the User may request that the Company correct, add to, or delete that Personal Information (collectively, “Correction, etc.”).
- 2. Upon receiving a request under the preceding paragraph, the Company will conduct the necessary investigation without delay. If it determines that the request has grounds, it will make the Correction, etc. without delay.
- 3. When the Company decides whether to make a Correction, etc. under the preceding paragraph, it will contact the User without delay.
Article 8 (Cessation of Use, etc. of Personal Information)
- 1. The User may request that the Company cease using, erase, or cease providing to third parties the Personal Information it holds (collectively, “Cessation of Use, etc.”).
- 2. Upon receiving a request under the preceding paragraph, the Company will conduct the necessary investigation. If it determines that the request has grounds, it will carry out the Cessation of Use, etc. However, if the Cessation of Use, etc. would involve substantial cost or is otherwise difficult, and the Company can take an alternative measure necessary to protect the User’s rights and interests, it will take that alternative measure.
- 3. When the Company decides whether to carry out the Cessation of Use, etc. under the preceding paragraph, it will contact the User.
Article 9 (Procedure for Amending the Privacy Policy)
The Company will review the Policy from time to time and work to improve it. Except as otherwise provided by laws and regulations or this Policy, the Company may amend this Policy. The amended Privacy Policy will take effect when the Company notifies Users by a method specified by the Company or posts it on the Company’s website.
Article 10 (Compliance with Laws, Regulations, and Standards)
The Company will comply with Japanese laws, regulations, and other standards applicable to the Personal Information it holds.
Article 11 (Handling Complaints and Consultations)
The Company accepts complaints and consultations from Users regarding the handling of Personal Information and responds to them appropriately and promptly. The Company also responds promptly and appropriately to Users’ requests concerning the disclosure, correction, addition, or deletion of Personal Information, or the refusal of its use or provision, and similar matters.
Article 12 (Security Control Measures)
The Company implements organizational, physical, personnel, and technical measures to prevent unauthorized access to, loss, destruction, alteration, leakage, and similar incidents involving Personal Information provided by Users. These measures include restricting access to personal information files, recording access logs, and implementing security measures to prevent unauthorized external access. If an incident such as the leakage of a User’s Personal Information occurs, the Company will promptly report it to the relevant supervisory authority in accordance with the APPI and related guidelines. Following the authority’s instructions, the Company will also take necessary action, including measures to prevent similar incidents and recurrence. For details, please see the attached “Security Control Measures for Personal Information.”
Article 13 (Company Address, Representative, and Personal Information Protection Manager)
The Company’s address and the names of its representative and Personal Information Protection
Manager are as follows:
Address: 88 Saint Laurent Street, Epping NH 03042 USA
Representative: Kevin Cantrell
Article 14 (Contact)
For inquiries regarding the Company’s handling of Personal Information, please contact:
CropWatch, LLC
806-5 Minamikata, Saito City, Miyazaki Prefecture 881-0027, Japan
TEL: 080-4284-3390
Email: sayaka@cropwatch.io
Article 15 (CropWatch Android App and Home-Screen Widget)
1. Scope
This section applies to the CropWatch Android app and home-screen widget, package name io.cropwatch.widget. The app signs users into an existing CropWatch account and displays information from their CropWatch devices. The app does not provide an account-creation function.
2. Information sent to CropWatch
When a user signs in, the app sends the email address and password entered by the user to https://api.cropwatch.io over HTTPS. The CropWatch API returns an access token, which the app uses to request the user’s device and gateway information.
If the API rejects an access token, the app may send the saved email address and password again to obtain a new access token and continue refreshing the widget.
The app downloads device names, device identifiers, CropWatch location and group names, current sensor readings, measurement units, last-update times, online and alert status, gateway status, and fleet totals. If the user selects a location or group filter, that selection is included in later API requests. The Android app downloads sensor readings but does not upload sensor readings.
CropWatch location names refer to locations assigned to monitoring equipment. The app does not request or access the Android device’s GPS location.
3. Information stored on the Android device
The app stores the account email address, reusable password, and access token in encrypted app storage. The encryption key is managed by Android Keystore.
The app also stores selected filters and the latest widget display data in Android’s private app storage. This data can include device names and identifiers, CropWatch location or group names, current readings, status and alert information, gateway totals, device-page links, and the last successful update time. The widget cache is separate from the encrypted credential store. The app does not keep a local history of sensor readings.
The saved email address and password allow the widget to refresh in the background when the current access token is no longer accepted.
4. Local retention and deletion
The app does not use a time-based local deletion schedule while the user remains signed in. A successful sign-out deletes the saved credentials, filters, and widget cache. Removing the final CropWatch widget calls the same local deletion process. Clearing the app’s storage or uninstalling the app also removes its private local data.
The app is configured to exclude its data from Android cloud backup and device-to-device transfer.
Signing out, removing the widget, or uninstalling the app deletes local Android data only. These actions do not delete the user’s CropWatch account or information stored on CropWatch servers.
5. Home-screen display, Autofill, and browser links
Device information is displayed on the Android home screen. Anyone who can view the device’s home screen may be able to see the widget’s contents. The Android launcher receives the widget data needed to display it.
The sign-in fields support Android Autofill. If the user enables an Autofill or password-manager service, that service handles the entered information under its own privacy terms.
Account, privacy, gateway, and device links open CropWatch pages in the user’s external browser. Device-page links contain the related CropWatch location and device identifiers. The app does not place the user’s password or access token in those browser links. Browser and website activity is governed by the applicable CropWatch website privacy and cookie policies.
6. Advertising, analytics, and other recipients
The Android app contains no advertising, analytics, or third-party crash-reporting SDK. The native app sends authentication and fleet requests directly to CropWatch services.
CropWatch uses [INSERT THE CONFIRMED CATEGORIES OF SERVICE PROVIDERS THAT PROCESS API OR ACCOUNT DATA, SUCH AS CLOUD HOSTING OR CUSTOMER SUPPORT PROVIDERS]. Information about those providers and any other disclosure or sharing is governed by Articles 4 and 5 of this Policy.
[IF TRUE, ADD: CropWatch does not sell personal or sensitive information and does not share it for third-party advertising.]
7. Server retention and deletion
Information stored by CropWatch servers is retained [INSERT THE ACTUAL RETENTION PERIOD OR RULE FOR ACCOUNTS, SENSOR DATA, SECURITY LOGS, AND BACKUPS].
A user may request access to, correction of, or deletion of server-held personal information as described in Articles 6 through 8 by contacting sayaka@cropwatch.io. [INSERT THE NORMAL COMPLETION TIME AND IDENTIFY ANY INFORMATION THAT MUST BE RETAINED FOR LEGAL, SECURITY, CONTRACTUAL, OR BACKUP PURPOSES.]
8. Security
The Android app restricts its API traffic to HTTPS and rejects cleartext HTTP. Authentication information is encrypted locally using a key managed by Android Keystore. Cached widget information and filters are kept in Android’s private app storage. App data is excluded from Android cloud backup and device-to-device transfer.