Skip to content
CraftChatCraftChat

Privacy Policy

Last updated: March 7, 2026

1. Introduction

JPSM Group ("Company," "we," "us," or "our") operates the CraftChat service ("Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at https://craftchat.net, use our WordPress plugin, or interact with our Service in any way.

We are committed to protecting your privacy and handling your data in compliance with the Act on the Protection of Personal Information (APPI) of Japan, the General Data Protection Regulation (GDPR) of the European Union, and other applicable data protection laws. Please read this Privacy Policy carefully. By using the Service, you consent to the data practices described herein.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, company name, and payment information (credit card details are processed by our payment processor and are not stored on our servers)
  • Contact Form Submissions: Name, email address, company name, inquiry type, and message content submitted through our contact form
  • Support Communications: Information provided when you contact our support team

2.2 Information Collected Automatically

  • Website Usage Data: IP address, browser type, operating system, referring URLs, pages visited, time and date of visits, and clickstream data
  • Plugin Usage Data: WordPress version, WooCommerce version, plugin configuration settings, and anonymized usage statistics
  • Chat Interaction Data: Visitor questions and AI-generated responses on your website, timestamps, and satisfaction ratings (if enabled)

2.3 Website Content Data

When you install and activate the CraftChat plugin, the Service automatically crawls and indexes the content of your website pages and WooCommerce product data. This data is stored in our vector database to enable AI-powered responses. This content data belongs to you; we process it solely to provide the Service.

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: To provide, operate, and maintain the CraftChat service, including generating AI responses to visitor inquiries
  • Account Management: To manage your account, process payments, and communicate about your subscription
  • Service Improvement: To analyze usage patterns, diagnose technical issues, and improve the Service
  • Communication: To send service-related notices, updates, security alerts, and support messages
  • Analytics: To provide you with analytics and insights about your chatbot's performance through the dashboard
  • Legal Compliance: To comply with legal obligations, respond to legal requests, and protect our rights

4. AI Data Processing and OpenAI API

CraftChat uses the OpenAI API to generate AI-powered responses to visitor questions. When processing a visitor's question:

  • Relevant portions of your indexed website content are sent to the OpenAI API along with the visitor's question
  • OpenAI processes this data to generate a response and returns it to our Service
  • According to OpenAI's API data usage policies, data submitted through the API is not used to train OpenAI's models
  • We do not send personally identifiable information of website visitors to the OpenAI API unless such information is part of the visitor's question

For more information about how OpenAI processes data, please refer to OpenAI's Privacy Policy.

5. Cookies and Tracking Technologies

5.1 Cookies We Use

  • Essential Cookies: Required for the operation of our website and dashboard (session management, authentication)
  • Analytics Cookies: Google Analytics (GA4) to understand how visitors interact with our website
  • Functional Cookies: To remember your preferences (language settings, dashboard configuration)

5.2 Chat Widget

The CraftChat widget installed on your website may use localStorage to maintain conversation context within a browser session. This data is stored locally in the visitor's browser and is not transmitted to our servers beyond the chat messages themselves.

6. Third-Party Services

We use the following third-party services that may process your data:

  • OpenAI: AI response generation (see Section 4)
  • Stripe: Payment processing (PCI DSS compliant)
  • Google Analytics: Website analytics
  • Cloud Infrastructure Provider: Data hosting and storage

Each third-party service provider has its own privacy policy governing the use of your information. We encourage you to review their respective privacy policies.

7. Data Retention

  • Account Data: Retained for the duration of your account and for up to 12 months after account termination for legal and administrative purposes
  • Chat Interaction Data: Retained for up to 24 months to provide analytics features, then automatically deleted or anonymized
  • Website Content Index: Deleted within 30 days of account termination or upon request
  • Payment Records: Retained for 7 years as required by Japanese tax law
  • Server Logs: Automatically deleted after 90 days

8. Your Rights

8.1 Under the Japanese Act on the Protection of Personal Information (APPI)

If you are a resident of Japan, you have the right to:

  • Request disclosure of the personal information we hold about you
  • Request correction, addition, or deletion of inaccurate personal information
  • Request cessation of use or deletion of your personal information if it was obtained unlawfully or is no longer necessary
  • Request cessation of provision of your personal information to third parties

8.2 Under the GDPR (EU/EEA Residents)

If you are a resident of the European Union or European Economic Area, you have the right to:

  • Access: Obtain confirmation of whether we process your personal data and request a copy of it
  • Rectification: Request correction of inaccurate or incomplete personal data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Restriction: Request restriction of processing of your personal data
  • Portability: Receive your personal data in a structured, commonly used, machine-readable format
  • Objection: Object to the processing of your personal data based on legitimate interests
  • Withdrawal of Consent: Withdraw consent at any time where processing is based on consent

You also have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

8.3 Exercising Your Rights

To exercise any of these rights, please contact us at support@craftchat.net. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Regular security assessments and vulnerability scanning
  • Access controls with role-based permissions and multi-factor authentication for administrative access
  • Secure data center facilities with physical access controls
  • Regular backups with encrypted storage

While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. When we transfer personal data outside of Japan or the EU/EEA, we ensure that appropriate safeguards are in place, such as standard contractual clauses or adequacy decisions, to protect your data in accordance with applicable data protection laws.

11. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18 without parental consent, we will take steps to delete such information promptly. If you believe we have collected information from a child under 18, please contact us at support@craftchat.net.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice on the Service at least 14 days before the changes take effect. The "Last updated" date at the top of this page indicates when this Privacy Policy was last revised. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: