← firstpass.cloud

Privacy Policy

Last updated: September 26, 2026

日本語はこちら

This policy explains how Great Bright Science and Technology Inc. (偉輝科技株式会社, “GBST”, “we”) handles personal data through FirstPass: the website firstpass.cloud, the customer dashboard, the hosted identity verification page and the API at api.firstpass.cloud.

1. Who we are

2. Two roles: customers and applicants

Customers are the businesses that create a FirstPass workspace and send identity checks to us. For customer account data we decide how the data is used.

Applicants are the customer's own end users whose face and identity document are checked. We process applicant data on behalf of the customer, to run the checks the customer requests. The customer decides to verify its users with FirstPass and is responsible for telling its applicants about it, for having a lawful basis, and for obtaining any consent that applicable law requires (including consent to process biometric data and to store it as described below) before sending their data to FirstPass. If you are an applicant, please contact the service that asked you to verify first; we will also help with requests sent to us (section 9).

3. What we collect

Customer account and billing data

Applicant data (KYC checks)

Website visitors

4. KYC records are retained

These paid checks are each stored as a record: Level A and Level B (hosted verification sessions and the direct /v1/kyc/a and /v1/kyc/b calls), face compare (/v1/face/compare) and ID document reading (/v1/document/ocr). A record contains the identity data and results that check produced and downscaled selfie and/or document images. Hosted sessions also store the live-scan frames, screen-flash frames, scan video and face fingerprint; if the applicant retries on the same link, the new attempt replaces the previous attempt's record. Direct Level A and B calls do not store the face fingerprint they return. An ID image that shows no face (for example the back of a card) is not stored; only the fields read from it are. For Level B, the proof-of-residence and source-of-funds images are stored encrypted, separately from the record, and inaccessible 90 days after upload, then overwritten at startup or by the next expiry job; the fields read from them stay with the record. Only authorised FirstPass staff reviewing records can view these two images through the staff page (not the customer's dashboard, exports or API), and staff-page access is logged with the staff account and time (admin-token access is logged as a shared admin identity). This access does not assign applicant review to FirstPass. The service requesting verification handles review and any follow-up; if it needs original proofs, it must arrange collection with the applicant. The face fingerprint endpoint (/v1/face/embed), the name, email and phone check (/v1/identity/basic) and proof-of-residence reading (/v1/document/por) are billed but create no record. Standalone proof-of-residence reading refunds unreadable or unrecognized documents and reader outages; Level B retains its overall 2-credit charge for unreadable proofs. Storage is not optional for customers and cannot be switched off.

5. Why we use the data

We do not sell personal data, and we do not use applicant data for our own marketing or to train AI models.

6. Service providers and where data goes

ProviderWhat forDataLocation
Vultr (The Constant Company, LLC)API servers, database and backupsAll service data, KYC records encryptedServers in Tokyo, Japan; provider in the United States
Google LLC (Google Drive)Off-site backup copy of the databaseDatabase copy, KYC records encryptedUnited States / global
Vercel Inc.Hosting the website and verification pagePage requests, IP addressUnited States / global edge
Anthropic, PBCReading identity, residence and funds documents; the AI support chatDocument images; chat messagesUnited States
Stripe, Inc.Card payments for credit top-upsPayment details entered on Stripe; workspace idUnited States / global
Resend, Inc.Sending emails (API key, demo report, monthly report, internal notifications)Email address and message contentUnited States
Zoho CorporationOur mailbox hello@firstpass.cloudEmails you send us, internal notificationsSee Zoho's policy
Google LLC (Analytics, Ads)Website analytics and ad measurementSee section 7United States
X Corp.Ad measurementSee section 7United States

Face matching and the face fingerprint are computed on our own servers, not by a third party. USDT top-ups are detected by our own payment gateway on the same servers; blockchain transactions are public by nature. Email addresses may be checked with a DNS lookup of the domain's mail server.

7. Analytics and advertising on the website

The public pages of firstpass.cloud use these tags. They are not loaded on the identity verification page, the customer dashboard or the API.

8. How long we keep data

9. Your rights

Depending on where you live (for example under Japan's Act on the Protection of Personal Information or the EU/UK GDPR), you may ask us to tell you what data we hold about you, give you a copy, correct it, stop using it, or erase it. Applicants should normally contact the service they verified with, which controls their record; you can also write to us and we will work with that customer. Customers can request erasure of an applicant record on the applicant's behalf. Email hello@firstpass.cloud; we may need to confirm your identity. You may also complain to your data protection authority (in Japan, the Personal Information Protection Commission).

10. Transfers outside your country

Our servers are in Japan, but several providers above are based in the United States and may process data there or elsewhere. Data protection rules in those countries may differ from those in your country. We use providers that commit to protecting the data under their terms, and we send them only what their task needs.

11. Security

Connections use HTTPS. KYC records are encrypted in the database, API keys and passwords are stored only as hashes, dashboard sessions use signed cookies, and access to the servers and operations tools is limited to authorised staff. No system is perfectly secure; we will notify affected customers and authorities of a breach as required by law.

12. Changes

We will update this page when our practices change and change the date above. Material changes that affect customers will also be announced to workspace email addresses.

プライバシーポリシー

最終更新日:2026年9月26日

偉輝科技株式会社(以下「当社」)は、FirstPass(ウェブサイト firstpass.cloud、お客様ダッシュボード、本人確認ページ、api.firstpass.cloud の API)における個人情報を以下のとおり取り扱います。英語版と日本語版の内容に相違がある場合は、hello@firstpass.cloud までお問い合わせください。

1. 事業者

2. お客様と申請者

お客様は FirstPass のワークスペースを作成し、本人確認を当社に依頼する事業者です。申請者はお客様のサービスの利用者で、顔と本人確認書類の確認を受ける方です。申請者の情報は、お客様の依頼に基づき確認を行うために取り扱います。申請者への説明、適法な根拠の確保、および法令上必要な同意(生体情報の取扱い、下記の保存についての同意を含む)の取得は、申請者の情報を FirstPass に送る前にお客様の責任で行っていただきます。

3. 取得する情報

4. 本人確認の記録は保存されます

次の有料の確認は記録として保存されます:レベル A・B(本人確認ページ、および /v1/kyc/a・/v1/kyc/b の直接呼び出し)、顔照合(/v1/face/compare)、本人確認書類の読取(/v1/document/ocr)。記録にはその確認で得た情報と判定結果、縮小した顔画像・書類画像が含まれます。本人確認ページの場合は動作確認画像・発光時画像・スキャン動画・顔の特徴量も保存し、同じリンクで再試行した場合は前回の記録を新しい内容で置き換えます。レベル A・B の直接呼び出しでは、返却した顔の特徴量は保存しません。顔写真の写っていない書類画像(カードの裏面など)は保存せず、読み取った項目のみ保存します。レベル B の住所確認書類・資金源書類の画像は、記録とは別に暗号化して保存し、アップロードから90日後に閲覧不可となり、起動時または次の期限切れ処理で上書き消去します(読み取った項目は記録に残ります)。この2種類の画像は記録を確認する権限のある当社スタッフのみがスタッフ用ページで閲覧でき(お客様のダッシュボード・エクスポート・API には含まれません)、スタッフ用ページでの閲覧はアカウントと日時を記録します(管理トークンの場合は共通の管理者名で記録します)。これは申請者への対応を当社が引き受ける仕組みではありません。結果の確認と今後の対応は依頼元のサービスの担当です。原本が必要な場合、そのサービスが申請者から別途収集する必要があります。顔の特徴量(/v1/face/embed)、氏名・メール・電話番号の確認(/v1/identity/basic)、住所確認書類の読取(/v1/document/por)は課金されますが記録は作りません。お客様側でこの保存を無効にすることはできません。記録は暗号化してデータベースに保存し、確認を行ったお客様のダッシュボードと当社の権限あるスタッフのみが閲覧できます。お客様をまたいで顔を照合することはありません。上記の90日保存の証明画像を除き、記録に自動削除の期限はありません。削除のご依頼があれば当社の運用スタッフが第8項のとおり消去します。

5. 利用目的

個人情報を販売することはなく、申請者の情報を当社のマーケティングや AI の学習に使うことはありません。

6. 委託先・外部送信先

顔照合と顔の特徴量の計算は当社のサーバーで行い、第三者には送信しません。

7. 外部送信に関する公表事項(アクセス解析・広告の効果測定)

以下のタグは firstpass.cloud の公開ページでのみ動作し、本人確認ページ、お客様ダッシュボード、API では読み込みません。

8. 保存期間

9. 開示・訂正・利用停止・削除のご請求

個人情報の保護に関する法律に基づく開示・訂正・利用停止・削除等のご請求は hello@firstpass.cloud までご連絡ください。ご本人確認をお願いする場合があります。申請者の方は、まず本人確認を依頼したサービスにご連絡ください。当社もそのお客様と協力して対応します。

10. 外国にある第三者への提供

当社のサーバーは日本にありますが、第6項の委託先の一部は米国の事業者であり、米国その他の国で情報を取り扱う場合があります。これらの国の個人情報保護制度は日本と異なる場合があります。当社は、各事業者の規約に、情報を保護する旨が定められていることを確認し、業務に必要な範囲の情報のみを提供します。

11. 安全管理措置

通信は HTTPS で暗号化し、本人確認の記録はデータベース上で暗号化、API キーとパスワードはハッシュ化して保存し、サーバーと管理ツールへのアクセスは権限あるスタッフに限定しています。

12. 改定

取扱いを変更する場合は本ページを更新し、上記の日付を改めます。お客様に影響する重要な変更は、ワークスペースのメールアドレスにもお知らせします。