Spider Labs, Inc., a corporation organized under the laws of Japan, on behalf of its subsidiaries and divisions (collectively, "Spider Labs," "us," "we," or "our") has prepared this Privacy Policy ("Policy") to describe how Spider Labs collects, uses, discloses and otherwise processes personal information when Spider Labs acts as a controller or business with respect to visitors to its websites, users of its applications, customer and prospective-customer contacts, job applicants, and other individuals who interact with Spider Labs. This Policy applies to the website located at https://spideraf.com/ and other websites operated by Spider Labs (each, a “Site”), and mobile applications provided by or on behalf of Spider Labs (each, an “Application,” and together with the Sites, the “Platform”). It also describes certain processing performed through Spider AF services when Spider Labs determines the purposes and means of that processing. Where Spider Labs processes personal information solely on behalf of a customer, the customer’s privacy notice and the applicable customer agreement govern that processing. Capitalized terms not defined in this Policy, shall have the meanings given in the Spider Labs Terms of Service, located at https://spideraf.com/terms-of-service. Spider Labs reserves the right, at any time, to modify this Policy. If we make revisions that materially change the way we collect, use, or share personal information, we will post those changes in this Policy and provide any additional notice required by applicable law. You should review this Privacy Policy periodically so that you keep up to date on our most current policies and practices. We will note the effective date of the latest version of our Policy at the end of this Policy. Changes apply from the stated effective date and do not affect the lawfulness of processing that occurred before that date.
The following are categories (with non-exhaustive examples) of personal information we may collect about you:
| Category | Examples |
|---|---|
| A. Individual Identifiers and Contact Information | A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, telephone number, or other similar identifiers. |
| B. Geolocation Data | Approximate location inferred from an IP address or device information, and precise location only where specifically disclosed and enabled by you. |
| C. Commercial and Account Information | Records of services you have purchased, company information, communications, marketing preferences, or other consuming preferences or tendencies. Account name and password, payment information provided for billing or processed by a payment service provider, billing address, order details, and other account or order-related history or information. |
| D. Internet or Other Electronic Network Activity | Browsing history, search history, information on an individual's interaction with a website, application, or advertisement, device and browser information, clickstream data, and fraud or security signals. |
We obtain the categories of personal information listed above on or through our Platform from the following categories of sources:
Personal Information necessary for business activities will be acquired by us directly from Users and other parties, from the browser or mobile application environment, or via our partners. Additionally, when we acquire Personal Information, we will let you know or publicly announce the purpose of use thereof in advance (hereinafter referred to as "Public Announcement, etc.") except in the following circumstances:
Spider Labs's primary purpose in collecting personal information is to provide the Services and Content that you request on the Platform. Spider Labs may also use personal information for various purposes, including without limitation to:
Spider Labs may also use Personal Information pertaining to contact persons, etc., of our client corporations and self-employed business owners as follows:
We may use Personal Information pertaining to individuals who desire to join Spider Labs and apply for job openings for the following purposes:
In addition to the specific situations discussed elsewhere in this Policy, Spider Labs may share your personal information in the following circumstances:
We may share your personal information with companies that are affiliated with us (that is, that control, are controlled by, or are under common control with us). In addition, if we sell all or part of its business or make a sale or transfer of assets or are otherwise involved in a merger or business transfer, we may transfer your personal information to a third party as part of that transaction, including at the negotiation stage.
We may ask if you would like us to share your personal information with other unaffiliated third parties who are not described elsewhere in this policy, and we may do so with your consent.
We may disclose personal information in response to subpoenas, warrants, or court orders, in connection with any legal process, or to comply with relevant laws. We may also share your personal information in order to establish or exercise our rights; to defend against a legal claim; to investigate, prevent, or take action regarding possible illegal activities or fraud; to protect the safety and security of other Users; or to prevent a violation of our Terms of Service.
We may share your personal information with third parties who perform services on our behalf that are necessary for the orderly operation of the Platform. Among other things service providers may help us perform website hosting, app design, maintenance services, database management, web analytics, app analytics, billing, payment processing, fraud protection, credit risk reduction, marketing, or any other use set out in this Policy. Access to your personal information by these service providers is limited to the information reasonably necessary for the service provider to perform the services for which it was engaged. We require our service providers to keep the personal information that they are provided with confidential, to use it only for the contracted purposes, to implement appropriate safeguards, and to comply with all applicable laws. Some third parties may act as independent controllers for limited activities, in which case their own privacy notices also apply.
We participate in behavioral-based advertising. This means that a third party may use technology (e.g., a cookie) to collect information about your use of our Platform so that we can provide advertising about products and services tailored to your interest. That advertising may appear either on our Platform, or on other websites.
We may jointly offer events, promotions, or any other product or service offerings with third party partners or our clients, which may be your employer. The personal information that you submit through an event, promotion, or other product or service offering may be combined and transmitted with the Registration Information related to your Account. Third party partners or clients may collect information directly from you, which may be combined with personal information disclosed by us. If you decide to request, enter into, or participate in an event, promotion, or other product or service offering that is offered by us and identified as a joint effort with a third-party partner or client, the information that you provide may be shared with us and with that identified third party.
The Platform may offer you the ability to share your personal information through a social networking website (e.g., Facebook, X (formerly Twitter)), using such site's integrated tools (e.g., the Facebook "Like" button or the X "Post" (formerly "Tweet") button). The use of such integrated tools enables you to share personal information about yourself with other individuals or the public, depending on the settings that you have established with such social networking site. For more information about the purpose and scope of data collection and use in connection with such social networking site or a site's integrated tools, please visit the privacy policies of the entities that provide these social networking sites.
The Platform may provide you with the opportunity to post comments, messages, or reviews in a public forum. If you decide to submit personal information at these locations, that information will be available to other Users of the Platform.
Users may recommend other Users to join the Platform by providing their contact information or selecting friends from a social networking site. Users may also provide information about other Users of the Platform such as reviews of the services or products that he or she received, booking or scheduling information, or reference information.
We maintain reasonable administrative, technical and organizational safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal information. These safeguards may include encryption in transit, access controls, monitoring, and procedures appropriate to the nature of the information and the risks of processing. No method of transmission over the Internet, or method of electronic storage, is fully secure. While we use reasonable efforts to protect your personal information from the risks presented by unauthorized access or acquisition, we cannot guarantee the security of your personal information. In the event that we are required by law to inform you of any unauthorized access or acquisition of your personal information we may notify you electronically, in writing, or by telephone, if permitted to do so by law.
You can make the following choices regarding your personal information:
You may request access to your personal information by contacting us as described below. We will grant you reasonable access to the data that we have about you as required by law.
We rely on you to update and correct the personal information contained in your Account. Note that we may keep historical information in our backup files as permitted by law. If our Platform does not permit you to update or correct certain personal information, please contact us as described below.
Typically, we retain your personal information for the period necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. You may, however, request that we delete your personal information by contacting us as described below. We will grant a request to delete information as required by law, but you should note that in many situations we must keep your personal information to comply with our legal obligations, resolve disputes, enforce our agreements, or for another one of our business purposes. Except as provided above, we will delete, aggregate, or de-identify all of your personal information as described in this subsection within the timeframes required by law.
The provision of your Personal Information is at your own discretion. However, if you do not agree to provide your Personal Information, there may be a case where you are unable to use all or part of our services or our partners' services.
You can make the following choices to opt out of certain activities regarding your personal information:
You may choose to provide us with your e-mail address for the purpose of allowing us to send newsletters, surveys, offers, and other promotional materials related to our Platform, as well as targeted offers from third parties. You can stop receiving promotional e-mails by clicking the "unsubscribe" links in the e-mails or by contacting us as described below. If you decide not to receive promotional e-mails, we may still send you service-related communications, such as those about your Account, to fulfill orders for products and service you have requested or deliver notifications directly to you through the Platform.
We participate in behavioral-based advertising. This means that a third party may use technology (e.g., a cookie) to collect information about your use of our Platform so that we can provide advertising about products and services tailored to your interest. That advertising may appear either on our Platform, or on other websites. If you wish to limit third parties' collection of information about your use of our Platform, you can opt-out of such at the Digital Advertising Alliance (http://optout.aboutads.info/) in the US, the Digital Advertising Alliance of Canada (https://youradchoices.ca/choices/) in Canada, or the European Digital Advertising Alliance (http://www.youronlinechoices.eu/) in Europe. PLEASE NOTE THAT OPTING-OUT OF BEHAVIORAL ADVERTISING DOES NOT MEAN THAT YOU WILL NOT RECEIVE ADVERTISING WHILE USING THE PLATFORM. IT WILL, HOWEVER, EXCLUDE YOU FROM INTEREST-BASED ADVERTISING CONDUCTED THROUGH PARTICIPATING NETWORKS, AS PROVIDED BY THEIR POLICIES AND CHOICE MECHANISMS.
Some browsers and devices offer “Do Not Track” signals. Because no uniform legal or industry standard currently governs how websites must respond to Do Not Track signals, we do not respond to those signals unless applicable law requires otherwise. We do, however, process legally recognized opt-out preference signals, including Global Privacy Control, as a request to opt out of the sale or sharing of personal information for the browser or device that sends the signal. Where required, we will apply the signal without requiring you to take additional action. You may also exercise your choices through the “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” link on our Sites.
We do not intend to acquire Personal Information through any means that does not involve the verification of your identity. In the event that we acquire Personal Information through such means, we will notify you to that effect and acquire such Personal Information upon obtaining your consent.
9.1 When a User uses our service or views our website, we may automatically acquire the User's cookie, IP address, IDFA, AAID and other information from the User's browser. We may use such information for the purpose of identifying the User, delivering optimal advertisement, analyzing for delivery of optimal advertisement, developing a new service, and optimizing our services for Users.
9.2 The cookies and similar technologies identified by our cookie management platform as currently used on our Sites are shown in the cookie table displayed in this section. The table is generated by our cookie management platform (CookieYes) and is updated automatically based on periodic scans of our Sites, and is intended to reflect the cookies detected during the most recent scan. For each cookie, the table shows its name, provider, purpose and retention period, organized by category (Necessary, Functional, Analytics, Performance and Advertisement). You can review and change your consent preferences for each category at any time via the consent settings described in Section 9.3. The table does not limit the disclosures elsewhere in this Policy. Because the table is based on periodic automated scans, a recently deployed technology may appear after the next scan. We will update the table within a reasonable period after deployment and will not rely on this timing statement to place or access non-essential technologies before obtaining consent where consent is required. We may also use browser-storage and similar technologies that do not appear in the cookie table, including identifiers stored in localStorage or comparable browser storage. We use these technologies to recognize devices or browsers, detect device spoofing and other fraudulent activity, generate fraud signals and scores, and support the shared fraud-detection activities described in Section 11. These identifiers may be combined with information collected through other customer websites, applications or services. Information regarding their purpose, provider and retention period will be made available through our consent-management interface or another notice presented when the technology is used.
9.3 You can accept, decline, or change your cookie preferences for non-essential cookies and similar technologies, including browser-storage identifiers, at any time by clicking the "Cookie Settings" button available on our website. Withdrawing your consent is as easy as giving it. Where applicable law requires consent before a non-essential cookie or similar technology is stored or accessed, we will seek that consent through our consent-management tool. You may also control cookies and certain browser-storage technologies through your browser or device settings as described below.
9.4 The User may elect to allow the use of cookies and other information. If the User elects to not allow the use of such information, there may be a case where the User is unable to use all or part of our services or activate certain advertisement settings which require cookies and other information, and the User may experience a problem in using our services.
9.5 Also when you would like to request notification or disclosure of the purpose of use of the aforementioned information, correction, addition or deletion of a portion thereof, suspension of the use thereof, deletion thereof, or suspension of provision to a third party, we will accommodate your request through the procedures set forth in this Privacy Policy.
9.6 Additionally, for the steps to activate or inactivate cookies, IDFA, AAID, or other information or to delete such information, please see the manuals or Help pages for your OS or browser (with regard to advertising identifiers of third parties such as Google and Apple, please see the privacy policies of such parties).
9.7 For any question regarding the identification document, fees, and other specific procedures, please also make an inquiry to our contact indicated below.
Certain Spider AF features connect to a customer’s Google Ads account through Google APIs. Information received from Google APIs will be used and transferred in accordance with the Google API Services User Data Policy, including the Limited Use requirements. • We do not request or receive your Google Ads username or password. You authorize access through Google’s authorization process and may revoke that access through your Google account settings. • We access and retain the account, campaign, placement, performance, cost, configuration and audience-list metadata reasonably necessary to provide the enabled fraud-detection, reporting, tracking-template and exclusion features. The precise fields depend on the features you enable and Google’s API functionality. • Through this integration, we do not access the individual members or underlying end-user identifiers contained in Customer Match or similar audience lists, and we do not upload email addresses, telephone numbers or other end-user identifiers to Google Ads for Customer Match or similar audience creation. • We do not sell Google Ads account data. We use it only to provide, secure, support and improve the enabled integration, comply with law, and as otherwise permitted by the applicable customer agreement and Google’s policies. • At the customer’s direction or as authorized through the enabled configuration, Spider AF may set or update tracking templates and transmit or apply fraud-related configuration, including IP, placement or audience-related exclusions. Customers should review enabled permissions and configuration settings before authorizing the integration.
Spider Labs offers optional integrations with advertising, analytics and other third-party platforms. Our Platform Integrations Privacy Notice, available through the applicable integration setup and authorization pages, describes the information accessed, received, stored or transmitted through each integration, the purposes of processing, retention practices, available controls, revocation and data-deletion procedures. That notice supplements this Privacy Policy. If a platform-specific disclosure directly conflicts with a general statement in this Privacy Policy, the more specific platform-integration disclosure will control for that integration.
We provide anti ad fraud tools to our partners. Our partners and their partners that adopt our anti ad fraud tools may place a JavaScript tag (or any similar technological measure) in a server, website or application which is part of the advertising network, and when an end user uses the server, website or application containing a JavaScript tag, the IP address, User Agent, IDFA, AAID, referrer, URL, time stamp, browser information, browser-storage identifiers, including identifiers stored in localStorage or comparable technologies, user interaction data (such as clicks, cursor location and movement, touches and scrolls), and other behavioral history information are acquired from such end user (the information so acquired shall be referred to collectively as the "Behavioral History Information"). Depending on the relevant processing activity, Spider Labs may process Behavioral History Information on behalf of a customer under the applicable customer agreement, or may process it as a controller for purposes disclosed in this Policy, including protecting, securing, maintaining and improving our fraud-detection services. We use such Behavioral History Information for the purpose of taking anti ad fraud measures through bot detection and other monitoring of unauthorized use, optimizing anti ad fraud measures, conducting analysis to optimize our anti ad fraud measures, and developing new services. Browser-storage identifiers may be used to recognize or correlate a device or browser across customer properties and may contribute to the shared fraud-detection databases, scores, classifications, block lists and other outputs described in this Section. Where consent is required for storing or accessing such identifiers, we will obtain consent before doing so. Spider Labs may combine Behavioral History Information and other fraud-related information obtained from or generated in connection with multiple customers, services and other sources to create, maintain and operate shared fraud-detection, security, risk-scoring and verification databases and systems. As part of Spider AF and other current or future fraud-prevention, security, risk-scoring, verification and related services, Spider Labs may provide customers and other authorized recipients with database-derived results, including fraud scores, classifications, alerts, block lists, exclusion feeds and fraud-related identifiers such as IP addresses, domains, URLs and comparable technical identifiers. For this processing, Spider Labs acts as a controller or business, as applicable. Spider Labs limits such disclosures to information reasonably necessary for the applicable purpose and does not identify the customer from which particular fraud-related information originated unless authorized by that customer or required by applicable law. Where we rely on aggregated or de-identified information for service improvement or development, we take reasonable measures designed to prevent that information from identifying an individual. Also when you would like to request notification or disclosure of the purpose of use of your Behavioral History Information, correction, addition or deletion of a portion thereof, suspension of the use thereof, deletion thereof, or suspension of provision to a third party, we will accommodate your request through the procedures set forth in this Privacy Policy subject to applicable law and verification requirements. Additionally, for the steps to activate or inactivate IDFA, AAID, or other information or to delete such information, please see "9. Cookies and Similar Technologies". In addition, we may use order information obtained through the Anti-Resale Service (which may include names, addresses and contact details) to detect and prevent fraudulent resale activities in our services and to improve the accuracy of such detection (including updating detection databases) as permitted by the applicable customer agreement and applicable law. To the extent Spider Labs uses such information for a purpose that it independently determines, Spider Labs acts as a controller for that processing and applies the safeguards and rights described in this Policy. For details of the information collected and analyzed through each Spider AF service (Anti-Ad Fraud, Anti-Resale, Fake Lead Protection, and SiteScan), please refer to the Spider AF Terms of Service and the applicable order forms and service specifications. Where Spider Labs processes personal data on behalf of its customers in the course of providing these services, such processing is governed by the agreement with the customer, including the Data Protection Agreement set out in Annex I of the Terms of Service.
The following applies to individuals in the European Economic Area (EEA).
Spider Labs is required to inform you of the lawful bases of our processing of your personal information, which are described below. If you have questions about the lawful basis of how we process your personal information, contact us at the address listed in the section titled "CONTACTING US" below. We process personal information on one or more of the following bases, depending on the purpose and context:
Spider Labs retains your personal information:
European data protection laws give you certain rights regarding your personal information. You may ask us to take the following actions in relation to your personal information that we hold:
This Section applies to California residents and supplements the other provisions of this Privacy Policy. It describes our practices when Spider Labs acts as a “business” under the California Consumer Privacy Act, as amended, including by the California Privacy Rights Act (collectively, the “CCPA”). “Personal information,” “sensitive personal information,” “sell,” “share,” and other terms defined by the CCPA have the meanings given by the CCPA. This Section does not apply to information exempt from the CCPA or to processing that Spider Labs performs solely as a service provider or contractor on behalf of a customer.
The table below describes the categories of personal information that we may collect, the purposes for which we collect and use them, the categories of sources, the categories of recipients to which we disclose them for business purposes, whether we sold or shared them during the preceding twelve months, and our retention criteria. “Shared” refers to disclosure for cross-context behavioral advertising. We do not sell personal information for money. Certain advertising disclosures may constitute a sale or sharing under the CCPA even when no money is exchanged.
| Category | Sources & Purposes | Business-Purpose Recipients | Sold | Shared | Retention |
|---|---|---|---|---|---|
| Identifiers and contact information (name, alias, postal address, email, phone, IP address, account identifiers, similar identifiers) | You, your device or browser, customers, business partners, advertising and analytics providers, public sources. Used to provide and secure services, manage accounts and transactions, communicate, market, measure campaigns, detect fraud and comply with law. | Affiliates, hosting and infrastructure providers, customer-support providers, payment and billing providers, professional advisers, security and fraud-prevention providers, and government authorities where required. | No, unless a later notice states otherwise. | Yes — identifiers such as online identifiers, IP addresses and hashed contact information may be shared with advertising partners for cross-context behavioral advertising, subject to your opt-out rights. | Account and contact identifiers are retained for the duration of the relevant relationship and thereafter as necessary for legal, security, compliance and dispute-resolution purposes. IP addresses and similar event-level identifiers processed through Spider AF are generally retained 90 days operationally, ~6 months in backups, and up to 2 years in restricted archival storage for fraud-model development, backtesting, research, investigations and compliance. |
| Geolocation data (generally approximate location inferred from IP address or device data) | Your device or browser and service providers. Used for security, fraud detection, localization, analytics and advertising measurement. | Hosting, analytics, security, fraud-prevention and advertising providers. | No. | May be shared if transmitted through advertising technologies. | Approximate location associated with Spider AF event data follows the same 90 days / ~6 months / 2 years schedule described above. Other geolocation data is retained as long as reasonably necessary for the purpose collected. |
| Commercial and account information (service, order, transaction, billing, account, communication and preference information) | You, customers, transaction and payment providers, and business partners. Used to provide services, process transactions, support accounts, prevent fraud, communicate and market. | Affiliates, payment and billing providers, customer-support providers, hosting providers, professional advisers, fraud-prevention providers and government authorities where required. | No. | May be shared when conversion or campaign events contain commercial information. | Retained for the duration of the customer or account relationship and thereafter as reasonably necessary for billing, support, fraud prevention, legal compliance, dispute resolution and enforcement of agreements. Event-level data processed through Spider AF may follow the operational/backup/archival periods above. |
| Internet or other electronic network activity (browsing, search, device, browser, clickstream, interaction, advertisement, fraud/security data) | Automatically from your browser, device and interactions, and from customers, advertising, analytics and security partners. Used to operate, secure, analyze and improve the Platform, detect fraud, measure campaigns and provide advertising. | Hosting, analytics, advertising, security, fraud-prevention and technical-service providers. | No. | Yes, when disclosed to advertising partners for cross-context behavioral advertising. | Spider AF event data: 90 days operational, ~6 months backups, up to 2 years restricted archival storage for fraud-model development, backtesting, research, investigations and compliance. Other network-activity information is retained as long as reasonably necessary. |
| Professional or employment-related information (employer, title, business contact details, job-application information) | You, recruiters, references, customers, business partners and public professional sources. Used for B2B relationship management, recruiting, communications, compliance and security. | Affiliates, recruiting and HR providers, customer-relationship providers, professional advisers and government authorities where required. | No. | No, unless included in an advertising identifier or audience event, in which case the relevant identifier may be shared. | Retained for the duration of the relevant business, employment or recruitment relationship and thereafter as reasonably necessary for legal, compliance, recordkeeping and dispute-resolution purposes. |
| Inferences (interests, preferences, fraud indicators, risk scores, likely engagement) | Generated from information collected from you, devices, customers and service providers. Used for fraud detection, security, service improvement, analytics and marketing. | Fraud-prevention, security, analytics, advertising and technical-service providers. | No. | May be shared when used for cross-context behavioral advertising. | Fraud indicators, risk scores and related inferences tied to Spider AF event data follow the 90-day / ~6-month / 2-year schedule above. Other inferences are retained as long as reasonably necessary. |
| Sensitive personal information (e.g., account credentials and any other CCPA-sensitive information collected in a relevant context) | You, customers, devices and service providers. Used for authentication, security, fraud prevention, service delivery and legal compliance. | Security, authentication, hosting, fraud-prevention and other providers necessary for the permitted purpose. | No. | No. | Retained only as long as reasonably necessary for authentication, security, fraud prevention, service delivery or legal compliance. Spider Labs does not intentionally retain account credentials or other sensitive personal information in the raw-event archive unless necessary for a documented purpose and subject to appropriate access restrictions and safeguards. |
Spider Labs does not use or disclose sensitive personal information for purposes that are subject to the CCPA right to limit. We will update this notice and provide the required method to exercise the right to limit if our practices change.
Subject to applicable exceptions, California residents may have the right to: (a) know the categories of personal information we collected, the categories of sources, our purposes, the categories of third parties to whom we disclosed, sold or shared personal information, and the categories of personal information disclosed, sold or shared; (b) access specific pieces of personal information; (c) delete personal information; (d) correct inaccurate personal information; (e) opt out of the sale or sharing of personal information; (f) limit the use and disclosure of sensitive personal information when the right applies; and (g) receive equal service and price and not be retaliated against for exercising CCPA rights.
You may opt out by selecting the “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” link on our Sites and adjusting the applicable settings. We also process legally recognized opt-out preference signals, including Global Privacy Control, as described in Section 7.3. Your opt-out applies to the browser or device from which you submit the request unless you are logged in and we are able and required to associate the request with your account. We will not ask you to opt back in for at least twelve months after your opt-out unless permitted by law.
You may submit a request by emailing dpo@spideraf.com, with info@spideraf.com available as a general alternative, or through any additional request method identified on our Site. If Spider Labs operates exclusively online and has a direct relationship with you, an email address may be the only required submission method. Otherwise, we will provide the request methods required by applicable law. Describe the right you wish to exercise and provide information reasonably necessary to identify the relevant records.
We will verify requests using information reasonably related to the request and the sensitivity of the information. We may request additional information where necessary to protect against fraud or unauthorized disclosure. You may designate an authorized agent. We may require proof that the agent is authorized and may ask you to verify your identity or confirm the authorization directly, except where the agent has a valid power of attorney under applicable law.
We will confirm receipt and respond within the periods required by the CCPA. We may extend the response period when reasonably necessary and permitted by law, and will notify you of the extension. We generally do not charge a fee, but may charge a reasonable fee or deny a request that is manifestly unfounded or excessive where permitted by law. If we deny a request, we will explain the basis for the denial and any available appeal or complaint process required by applicable law.
We will not discriminate against you for exercising a CCPA right. We may offer a financial incentive or a price or service difference that is reasonably related to the value of personal information only after providing any notice and consent required by law.
California Civil Code section 1798.83 permits certain California residents to request information regarding disclosure of personal information to third parties for their own direct-marketing purposes. You may submit such a request using the contact information in Section 15.
We will review and update this Section at least annually and when our practices materially change. The effective date appears at the end of this Privacy Policy.
When exercising the rights or options described in this Privacy Policy, the following guidelines apply:
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee or decline to comply with your request if your request is clearly unfounded, repetitive, or excessive.
When exercising your rights or otherwise assisting you, we may need to request specific information from you to help us confirm your identity. This is a security measure to ensure we do not disclose personal information to any person who is not entitled to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to all legitimate requests within 30 days of your request. Occasionally it may take us longer than 30 days to respond, for instance if your request is particularly complex or you have made a number of requests. In this case, we will notify you of the delay, and may continue to update you regarding the progress of our response.
You will not be subject to discrimination as a result of exercising the rights described herein. In some cases, when you exercise one of your rights, we will be unable to comply with the request due to legal obligations or otherwise, or we will be unable to provide you certain products or services. These responses are not discrimination and our reasons for declining your request or ceasing services will be provided at that time.
When you would like to request notification or disclosure of the purpose of use of Personal Information, correction, addition or deletion of a portion thereof, suspension of the use thereof, deletion thereof, or suspension of provision to a third party, please make a request to our contact indicated below. We will accommodate such requests in an appropriate manner and to a reasonable extent pursuant to the law. For such purpose, we will verify your identity with the identification document designated by us and confirm the specifics of your request, and we will also ask you to submit a copy of the relevant documents. For any question regarding the identification document, fees, and other specific procedures, please also make an inquiry to our contact indicated below. For any inquiry concerning the handling of Personal Information or if you have any questions or concerns about our Privacy Policy or any other privacy or security issue, please contact us at:
Spider Labs, Inc.For individuals residing in the European Economic Area ("EEA"), Spider Labs, Inc. has adopted the following additional provisions for the processing ('processing' means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction) of personal information and other information provided by individuals residing in EEA based on the General Data Protection Regulation ("GDPR").These additional provisions shall prevail to the extent it conflicts with any provision in the main body of the Privacy Policy.
We process the Information based on your consent in principle. The processing of the Information in the absence of your consent shall be based on
We store the Information primarily in Japan. In addition, we may transfer the Information to business partners of ours located in countries outside of the EEA. When we transfer personal data from the EEA to Japan, we rely on the European Commission’s applicable adequacy decision to the extent the transfer is within its scope. For transfers to another country or recipient not covered by an adequacy decision, we use an applicable safeguard under Chapter V of the GDPR, such as the European Commission’s standard contractual clauses, binding corporate rules, or another lawful mechanism. Where required, we assess the laws and practices of the destination country and implement supplementary measures. You may contact us to request information about the applicable transfer mechanism and, where available, a copy of the relevant safeguards.
You have the following rights with respect to us based on laws and regulations and you may exercise these rights by contacting our DPO. In the event that you exercise these rights, we will respond in good faith, barring statutory exceptions, after confirming that the requesting person is the person in question. The right of access: The right to obtain confirmation as to whether or not the Information concerning you is being processed, and where that is the case, (the right to) access to the Information and the accompanying information. The right to rectification: The right to obtain the rectification of inaccurate Information concerning you. The right to erasure: The right to obtain the erasure of personal information concerning you in certain cases. The right to restriction of the processing: The right to obtain restriction of the processing in certain cases. The right to object to the processing: The right to object to the processing of Information based on the purposes of the legitimate interests pursued by us or third parties. The right to data portability: The right to receive the Information concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from us.
You can withdraw consent on the processing of information at any time. Withdrawing consent does not affect the lawfulness of the processing based on consent before the withdrawal. You can withdraw consent by contacting our DPO.
You have the right to lodge a complaint on the processing of Information with the protection authority having jurisdiction over your residence.
We do not make decisions based solely on automated processing, including profiling.
We handle the Information with appropriate security and confidentiality measures.
(1) DPO
Data Protection Officer: Eurico Doirado(2) EU Representative
Eurico DoiradoLast Revised: September 1, 2026