Privacy Policy
Last updated: April 17, 2026
This Privacy Policy explains how Capylytics collects, uses, discloses, and otherwise processes personal data in connection with our website, applications, dashboards, integrations, and related services. It also explains the choices and rights available to you regarding your personal data.
1. General Information
Here you can find general information about us, our Services, and how this Privacy Policy applies.
1.1. About this Privacy Policy
This Privacy Policy applies to the personal data we process through capylytics.com and the Capylytics applications, dashboards, integrations, and related services (collectively, the "Services").
Capylytics is part of a suite of tools operated under the name Capylabz, designed for e-commerce agencies and stores. This Privacy Policy applies specifically to Capylytics unless otherwise stated.
This Privacy Policy does not apply to third-party websites, applications, platforms, or services that integrate with Capylytics or that you access through the Services. Those third parties process data under their own terms and privacy policies.
1.2. Data controller
The Services are owned and operated by HappyWeb株式会社, located at 1-11-5, Kita Saiwai, Nishi-ku, 6/9F, Sotetsu KS Building, Yokohama, Kanagawa-Ken, 220-0004, Japan ("we," "us," and "our").
1.3. Children
The Services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
1.4. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, legal obligations, or data practices. When we do, we will post the updated version on this page and update the "Last updated" date above. Where required by law, we will also provide notice or seek consent.
2. Our Role: Controller and Processor
Here we explain when we process personal data for our own business purposes and when we process it on behalf of our customers.
2.1. When we act as a controller
We act as a data controller for personal data we collect and use for our own business purposes, such as:
- account registration and administration;
- billing and subscription management;
- responding to enquiries and support requests;
- sending service-related communications;
- security, fraud prevention, and abuse detection;
- improving, maintaining, and supporting the Services; and
- complying with legal obligations.
2.2. When we act as a processor
Capylytics is an e-commerce reporting platform. Our customers may connect third-party services such as e-commerce, marketing, advertising, analytics, and messaging platforms to Capylytics in order to generate reports, dashboards, and insights.
When we process personal data contained in data imported from or made available through those connected services ("Service Data"), we generally act as a data processor or similar service provider on behalf of our customer. In those cases:
- our customer is responsible for deciding what data is collected and connected to Capylytics;
- our customer is responsible for having a valid legal basis to share that data with us; and
- we process that data only to provide, secure, support, and improve the Services, and as otherwise instructed by the customer or required by law.
If you are an end customer, subscriber, or shopper whose data has been uploaded to or synced with Capylytics by one of our customers, you should direct privacy requests to that customer first.
3. What Data We Collect
Here we describe the categories of personal data we may collect through Capylytics.
3.1. Data you provide directly
We may collect the following personal data directly from you:
- name;
- email address;
- company name;
- billing address;
- country;
- account credentials or authentication-related information;
- subscription plan information; and
- communications you send to us when requesting a demo, support, or sales information.
3.2. Account and workspace data
When you create or use a Capylytics account, we may collect:
- account identifiers;
- workspace or lab identifiers;
- user role and permission information;
- connected store or integration identifiers;
- installation and onboarding metadata;
- subscription status; and
- audit and access history related to use of the Services.
3.3. Billing and payment data
If you purchase a paid plan, payments are processed by third-party payment providers such as Stripe or Shopify. We may receive billing and transaction information such as:
- billing name;
- billing email;
- billing address;
- plan and subscription details;
- invoice and payment status;
- limited payment method metadata; and
- transaction identifiers.
We do not store full payment card numbers or CVV codes on our own systems.
3.4. Data from connected platforms
If you or your organization connect third-party services to Capylytics, we may receive and process data made available by those services. Depending on the integrations you enable, this may include:
- store, order, product, and customer data from e-commerce platforms;
- marketing and advertising data such as campaign, spend, impressions, clicks, and conversion metrics;
- email and messaging performance data;
- analytics and reporting data;
- store and account metadata; and
- aggregated business performance data and operational metrics.
Some of this data may include personal data, such as customer names, email addresses, order history, or geographic information, depending on what your organization chooses to connect and sync.
3.5. Support and communications data
If you contact us, we may collect:
- your name;
- email address;
- company name;
- the content of your request;
- attachments or information you provide voluntarily; and
- records of our communications with you.
3.6. Usage, log, and device data
When you use the Services, we may automatically collect technical and usage data such as:
- IP address;
- browser type and version;
- device type;
- operating system;
- referring URLs;
- pages or screens viewed;
- timestamps of access and activity;
- login events;
- error logs;
- performance and diagnostic data; and
- sync, import, and job status data.
3.7. Cookies and similar technologies
We may use cookies and similar technologies on our website and in our Services. Our use of cookies and similar technologies is described separately in our Cookie Policy.
3.8. Sensitive data
We do not intentionally require or seek special categories of personal data or other sensitive data through the Services. Please do not provide sensitive personal data unless it is strictly necessary and you have an appropriate legal basis to do so.
4. Sources of Personal Data
Here we explain where personal data may come from.
We collect personal data from the following sources:
- directly from you;
- from your use of the Services;
- from your employer or organization;
- from connected third-party platforms that you or your organization authorize;
- from payment providers such as Stripe or Shopify; and
- from service providers and contractors acting on our behalf.
5. How We Use Personal Data
Here we explain the purposes for which we use personal data.
We use personal data for the following purposes:
- to provide and operate the Services;
- to create and manage accounts, labs, workspaces, and clientspaces;
- to authenticate users and manage access;
- to import, organize, analyze, and display connected platform data;
- to provide dashboards, reports, and related reporting features;
- to process subscriptions, invoices, and payments;
- to provide customer support;
- to monitor, secure, and maintain the Services;
- to detect, investigate, and prevent fraud, abuse, and unauthorized access;
- to improve and develop our Services;
- to send service-related notices and transactional messages;
- to communicate about demos, sales, and account matters; and
- to comply with legal obligations and enforce our terms.
6. Legal Bases for Processing
Where required by applicable law, we rely on the following legal bases.
- Performance of a contract, when processing is necessary to provide the Services you requested;
- Legitimate interests, such as operating, securing, supporting, and improving the Services;
- Consent, where required by law, such as for certain optional communications or cookies; and
- Legal obligation, where processing is necessary to comply with applicable law.
7. How Long We Keep Data
Here we explain how long we retain personal data.
7.1. General retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
7.2. Account and billing data
We retain account, subscription, and billing records for as long as needed to maintain your account and as required for tax, accounting, and legal compliance.
7.3. Service Data
We retain Service Data for as long as necessary to provide the Services to our customer, subject to the customer's instructions, contractual terms, and applicable law.
7.4. Logs and diagnostics
We retain logs, diagnostics, and technical records for as long as reasonably necessary for security, troubleshooting, abuse prevention, and service improvement.
7.5. Deletion
When personal data is no longer needed, we will delete it or anonymize it, unless we are legally required or otherwise permitted to keep it.
8. How We Share Personal Data
Here we explain when personal data may be shared with third parties.
8.1. Service providers and subprocessors
We may share personal data with service providers and subprocessors that help us operate the Services, such as providers of:
- hosting and infrastructure;
- cloud storage and databases;
- payment processing;
- transactional email delivery;
- customer support tooling;
- analytics, monitoring, and security tooling; and
- professional services, contractors, and advisers.
These parties may access personal data only as needed to perform services for us and subject to appropriate confidentiality and data protection obligations.
8.2. Payment providers
If you make a purchase, your payment information will be processed by Stripe or Shopify, as applicable, under their own privacy policies and contractual terms.
8.3. Business transfers
We may disclose personal data in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction.
8.4. Legal and compliance disclosures
We may disclose personal data where necessary to:
- comply with applicable law, regulation, legal process, or lawful requests from public authorities;
- protect our rights, property, or safety;
- protect the rights, property, or safety of our users or others; or
- investigate fraud, abuse, security incidents, or violations of our terms.
8.5. No sale of personal data
We do not sell personal data.
9. International Transfers
Here we explain that data may be processed in countries other than your own.
We and our service providers may process personal data in countries other than the country where you reside, including Japan and other jurisdictions where our providers operate.
Where required by applicable law, we use appropriate safeguards for international transfers, such as contractual protections and other lawful transfer mechanisms.
10. Security
Here we explain how we protect personal data.
We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, authentication safeguards, encryption in transit where appropriate, network protections, monitoring, and vendor due diligence.
No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security.
11. Your Rights
Depending on your location and applicable law, you may have certain privacy rights.
You may have the right to:
- access personal data we hold about you;
- request correction of inaccurate personal data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing;
- request portability of personal data;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent supervisory authority.
To exercise your rights, contact us using the details below. We may need to verify your identity before fulfilling your request.
If we process your personal data on behalf of one of our customers, we may direct your request to that customer, since they are usually the party responsible for responding to such requests.
12. Communications
Here we explain the messages we may send you.
12.1. Service communications
We may send you service-related and transactional messages, such as:
- account notices;
- onboarding messages;
- subscription updates;
- invoices and receipts;
- technical or administrative notices; and
- security alerts.
You cannot opt out of essential service communications.
12.2. Marketing communications
If permitted by law, we may send you information about product updates, new features, or offers. You can unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting us.
13. Contact
If you have any questions about this Privacy Policy or our data protection practices, please contact us using the following details:
Email address: support@capylabz.com
Mail address: HappyWeb株式会社, 1-11-5, Kita Saiwai, Nishi-ku, 6/9F, Sotetsu KS Building, Yokohama, Kanagawa-Ken, 220-0004, Japan