Privacy Policy
Last updated: September 26, 2026
日本語はこちら
This policy explains how Great Bright Science and Technology Inc. (偉輝科技株式会社, “GBST”, “we”) handles personal data through FirstPass: the website firstpass.cloud, the customer dashboard, the hosted identity verification page and the API at api.firstpass.cloud.
1. Who we are
- Operator: Great Bright Science and Technology Inc. (偉輝科技株式会社)
- Representative Director: TAN PEK AUN
- Address: 402, 1-51-3 Chuo, Nakano-ku, Tokyo 164-0011, Japan
- Contact: hello@firstpass.cloud
2. Two roles: customers and applicants
Customers are the businesses that create a FirstPass workspace and send identity checks to us. For customer account data we decide how the data is used.
Applicants are the customer's own end users whose face and identity document are checked. We process applicant data on behalf of the customer, to run the checks the customer requests. The customer decides to verify its users with FirstPass and is responsible for telling its applicants about it, for having a lawful basis, and for obtaining any consent that applicable law requires (including consent to process biometric data and to store it as described below) before sending their data to FirstPass. If you are an applicant, please contact the service that asked you to verify first; we will also help with requests sent to us (section 9).
3. What we collect
Customer account and billing data
- Company or workspace name, email address, and a password (stored only as a salted hash).
- API keys (stored only as a hash plus a short hint; the full key is shown once).
- Credit balance and top-up history: Stripe checkout session and payment identifiers, or USDT transaction hash, network and amount. We do not receive or store card numbers; card payments are entered on Stripe.
- Usage logs: which API endpoint was called, when, whether it was billable, and the result verdict.
- The IP address of sign-up attempts, used for abuse limits.
- Monthly usage reports we email to the workspace address.
Applicant data (KYC checks)
- Identity data sent by the customer or entered on the verification page: name, email, phone number, and for Level B also date of birth, nationality, address, occupation, whether the person is a politically exposed person, source of funds and annual income (self-declared, not verified by us).
- Face images: the selfie and, on the hosted verification page, the live-scan evidence (challenge frames, screen-flash frames and a short scan video).
- Identity document images and the fields read from them (document type, document number, name, date of birth, expiry). For images classified as Japanese My Number cards, the document-number field is cleared and sensitive-number filtering is applied to OCR text. Misclassification remains possible; submit the photo side and mask sensitive numbers before upload.
- For Level B: proof-of-residence and source-of-funds documents and the fields read from them.
- Results: face match score and verdict, a face fingerprint (a 128-number face embedding derived from the images, which is biometric data), document and liveness checks, and the overall outcome.
- The customer's own reference for the applicant, if the customer provides one.
Website visitors
- Free demo: the email address you enter and your IP address. Your selfie and ID photo (and, for Level B, your residence and funds documents) are processed to show the result and to email you a report, but the images are not stored. We keep the email address, IP address, chosen level, face match verdict and similarity score, document type, and whether your browser reported a live scan (a self-reported flag we do not verify). The name and phone check on the website keeps only the email address and IP address.
- Support chat: the messages you type and the replies, linked to a random session id, and your IP address for rate limiting.
- Analytics and advertising data described in section 7.
4. KYC records are retained
These paid checks are each stored as a record: Level A and Level B (hosted verification sessions and the direct /v1/kyc/a and /v1/kyc/b calls), face compare (/v1/face/compare) and ID document reading (/v1/document/ocr). A record contains the identity data and results that check produced and downscaled selfie and/or document images. Hosted sessions also store the live-scan frames, screen-flash frames, scan video and face fingerprint; if the applicant retries on the same link, the new attempt replaces the previous attempt's record. Direct Level A and B calls do not store the face fingerprint they return. An ID image that shows no face (for example the back of a card) is not stored; only the fields read from it are. For Level B, the proof-of-residence and source-of-funds images are stored encrypted, separately from the record, and inaccessible 90 days after upload, then overwritten at startup or by the next expiry job; the fields read from them stay with the record. Only authorised FirstPass staff reviewing records can view these two images through the staff page (not the customer's dashboard, exports or API), and staff-page access is logged with the staff account and time (admin-token access is logged as a shared admin identity). This access does not assign applicant review to FirstPass. The service requesting verification handles review and any follow-up; if it needs original proofs, it must arrange collection with the applicant. The face fingerprint endpoint (/v1/face/embed), the name, email and phone check (/v1/identity/basic) and proof-of-residence reading (/v1/document/por) are billed but create no record. Standalone proof-of-residence reading refunds unreadable or unrecognized documents and reader outages; Level B retains its overall 2-credit charge for unreadable proofs. Storage is not optional for customers and cannot be switched off.
- Records are encrypted (Fernet, AES-based) before being written to our database.
- Each record is visible only in the dashboard of the customer that ran the check, and to our authorised operations staff (Level B proof-of-residence and source-of-funds images: our authorised staff only, through logged staff-page access). Faces are never matched across customers; FirstPass is not a shared face database and runs no face search.
- Records have no automatic deletion period. They are kept while the customer uses the service and afterwards until erased. Our operations staff erase a record on request (section 8).
5. Why we use the data
- To run the identity checks customers request and return and store the results for their audit trail.
- To operate customer accounts, sign-in, billing and credits, and to send service emails (API key, monthly reports).
- To prevent abuse (rate limits on sign-up, demo and chat) and keep the service secure.
- To answer questions through the support chat and by email, and to follow up on sales enquiries.
- To understand how the website is used and measure our advertising (section 7).
We do not sell personal data, and we do not use applicant data for our own marketing or to train AI models.
6. Service providers and where data goes
| Provider | What for | Data | Location |
|---|---|---|---|
| Vultr (The Constant Company, LLC) | API servers, database and backups | All service data, KYC records encrypted | Servers in Tokyo, Japan; provider in the United States |
| Google LLC (Google Drive) | Off-site backup copy of the database | Database copy, KYC records encrypted | United States / global |
| Vercel Inc. | Hosting the website and verification page | Page requests, IP address | United States / global edge |
| Anthropic, PBC | Reading identity, residence and funds documents; the AI support chat | Document images; chat messages | United States |
| Stripe, Inc. | Card payments for credit top-ups | Payment details entered on Stripe; workspace id | United States / global |
| Resend, Inc. | Sending emails (API key, demo report, monthly report, internal notifications) | Email address and message content | United States |
| Zoho Corporation | Our mailbox hello@firstpass.cloud | Emails you send us, internal notifications | See Zoho's policy |
| Google LLC (Analytics, Ads) | Website analytics and ad measurement | See section 7 | United States |
| X Corp. | Ad measurement | See section 7 | United States |
Face matching and the face fingerprint are computed on our own servers, not by a third party. USDT top-ups are detected by our own payment gateway on the same servers; blockchain transactions are public by nature. Email addresses may be checked with a DNS lookup of the domain's mail server.
7. Analytics and advertising on the website
The public pages of firstpass.cloud use these tags. They are not loaded on the identity verification page, the customer dashboard or the API.
- Google Analytics 4 and Google Ads (Google LLC, United States): pages viewed, cookie identifiers, device and browser information, and events such as form submissions, to understand site use and measure ad performance. Opt out with Google's add-on https://tools.google.com/dlpage/gaoptout or at https://adssettings.google.com.
- X Pixel (X Corp., United States): pages viewed, whether a workspace sign-up was completed (a conversion), cookie identifiers, IP address, and device and browser information. The company name, email address and password you enter are not sent. Managed under X's privacy policy (https://x.com/en/privacy); you can turn off ad personalization in X's “Personalization and data” settings: https://x.com/settings/account/personalization.
8. How long we keep data
- KYC records: no automatic deletion period (section 4). Erasure on request: we overwrite the record so the images, face fingerprint, name and email are removed, and keep an erasure marker plus record metadata such as id, workspace, level and timestamps. Linked sessions retain operational metadata, including return_url; avoid putting personal data in that URL. Record erasure does not also erase demo/signup logs or separate website sales chats; requests covering these require a separate operational assessment.
- Level B proof-of-residence and source-of-funds images: inaccessible 90 days after upload, then overwritten at startup or by the next expiry job (the image is overwritten; the record and the fields read from the documents are kept). An image that may show a 12-digit My Number (個人番号), or that our reader could not check, is not stored at all; only the fields read from it are kept.
- Customer account, billing and usage records: while the workspace exists and afterwards as needed for accounting and legal obligations.
- Demo leads, support chat messages and abuse-limit logs: no fixed deletion period at present. Contact hello@firstpass.cloud about erasure; these logs need separate handling from KYC record erasure, with no completion time guaranteed.
- Database backups: rolling local copies (about 7 days) and off-site copies that are replaced over time, so erased or deleted data may remain in backups for a limited period.
9. Your rights
Depending on where you live (for example under Japan's Act on the Protection of Personal Information or the EU/UK GDPR), you may ask us to tell you what data we hold about you, give you a copy, correct it, stop using it, or erase it. Applicants should normally contact the service they verified with, which controls their record; you can also write to us and we will work with that customer. Customers can request erasure of an applicant record on the applicant's behalf. Email hello@firstpass.cloud; we may need to confirm your identity. You may also complain to your data protection authority (in Japan, the Personal Information Protection Commission).
10. Transfers outside your country
Our servers are in Japan, but several providers above are based in the United States and may process data there or elsewhere. Data protection rules in those countries may differ from those in your country. We use providers that commit to protecting the data under their terms, and we send them only what their task needs.
11. Security
Connections use HTTPS. KYC records are encrypted in the database, API keys and passwords are stored only as hashes, dashboard sessions use signed cookies, and access to the servers and operations tools is limited to authorised staff. No system is perfectly secure; we will notify affected customers and authorities of a breach as required by law.
12. Changes
We will update this page when our practices change and change the date above. Material changes that affect customers will also be announced to workspace email addresses.
プライバシーポリシー
最終更新日:2026年9月26日
偉輝科技株式会社(以下「当社」)は、FirstPass(ウェブサイト firstpass.cloud、お客様ダッシュボード、本人確認ページ、api.firstpass.cloud の API)における個人情報を以下のとおり取り扱います。英語版と日本語版の内容に相違がある場合は、hello@firstpass.cloud までお問い合わせください。
1. 事業者
- 名称:偉輝科技株式会社(Great Bright Science and Technology Inc.)
- 代表取締役:TAN PEK AUN
- 所在地:〒164-0011 東京都中野区中央1-51-3 402
- お問い合わせ:hello@firstpass.cloud
2. お客様と申請者
お客様は FirstPass のワークスペースを作成し、本人確認を当社に依頼する事業者です。申請者はお客様のサービスの利用者で、顔と本人確認書類の確認を受ける方です。申請者の情報は、お客様の依頼に基づき確認を行うために取り扱います。申請者への説明、適法な根拠の確保、および法令上必要な同意(生体情報の取扱い、下記の保存についての同意を含む)の取得は、申請者の情報を FirstPass に送る前にお客様の責任で行っていただきます。
3. 取得する情報
- お客様の情報:会社名・ワークスペース名、メールアドレス、パスワード(ハッシュ化して保存)、API キー(ハッシュ化して保存)、クレジット残高とチャージ履歴(Stripe の決済 ID、または USDT の取引ハッシュ・ネットワーク・金額。カード番号は当社では受け取りません)、API の利用記録(エンドポイント・日時・課金有無・判定)、登録時の IP アドレス。
- 申請者の情報:氏名、メールアドレス、電話番号、(レベル B)生年月日、国籍、住所、職業、PEP 該当の有無、資金源・年収(自己申告、当社では検証しません)。顔画像(自撮り、本人確認ページでは動作確認の画像・画面発光時の画像・短いスキャン動画)、本人確認書類の画像と読み取った項目(書類の種類・番号・氏名・生年月日・有効期限。マイナンバーカードと判定した画像の番号欄は空にし、読取テキストにも番号の除去処理を行いますが、誤分類の可能性はあります。顔写真の面のみを提出し、機微な番号は事前に隠してください)、(レベル B)住所確認書類・資金源書類、判定結果、顔の特徴量(128 次元の数値で、生体情報にあたります)。
- ウェブサイト訪問者:無料デモで入力したメールアドレスと IP アドレス(デモの画像は保存しません。保存するのはメールアドレス・IP アドレス・レベル・顔照合の判定と類似度・書類の種類、およびブラウザが報告したライブスキャンの有無(自己申告で当社は検証しません)です。氏名・メールアドレス・電話番号を確認するデモはメールアドレスと IP アドレスのみ保存)、サポートチャットのメッセージと IP アドレス、第7項のアクセス解析・広告計測の情報。
4. 本人確認の記録は保存されます
次の有料の確認は記録として保存されます:レベル A・B(本人確認ページ、および /v1/kyc/a・/v1/kyc/b の直接呼び出し)、顔照合(/v1/face/compare)、本人確認書類の読取(/v1/document/ocr)。記録にはその確認で得た情報と判定結果、縮小した顔画像・書類画像が含まれます。本人確認ページの場合は動作確認画像・発光時画像・スキャン動画・顔の特徴量も保存し、同じリンクで再試行した場合は前回の記録を新しい内容で置き換えます。レベル A・B の直接呼び出しでは、返却した顔の特徴量は保存しません。顔写真の写っていない書類画像(カードの裏面など)は保存せず、読み取った項目のみ保存します。レベル B の住所確認書類・資金源書類の画像は、記録とは別に暗号化して保存し、アップロードから90日後に閲覧不可となり、起動時または次の期限切れ処理で上書き消去します(読み取った項目は記録に残ります)。この2種類の画像は記録を確認する権限のある当社スタッフのみがスタッフ用ページで閲覧でき(お客様のダッシュボード・エクスポート・API には含まれません)、スタッフ用ページでの閲覧はアカウントと日時を記録します(管理トークンの場合は共通の管理者名で記録します)。これは申請者への対応を当社が引き受ける仕組みではありません。結果の確認と今後の対応は依頼元のサービスの担当です。原本が必要な場合、そのサービスが申請者から別途収集する必要があります。顔の特徴量(/v1/face/embed)、氏名・メール・電話番号の確認(/v1/identity/basic)、住所確認書類の読取(/v1/document/por)は課金されますが記録は作りません。お客様側でこの保存を無効にすることはできません。記録は暗号化してデータベースに保存し、確認を行ったお客様のダッシュボードと当社の権限あるスタッフのみが閲覧できます。お客様をまたいで顔を照合することはありません。上記の90日保存の証明画像を除き、記録に自動削除の期限はありません。削除のご依頼があれば当社の運用スタッフが第8項のとおり消去します。
5. 利用目的
- お客様が依頼する本人確認の実施と、結果の返却・監査記録としての保存
- アカウント・ログイン・課金の管理、サービスに関するメール(API キー、月次レポート)の送信
- 不正利用の防止とセキュリティの確保
- サポートチャット・メールでのお問い合わせ対応、商談のご案内
- ウェブサイトの利用状況の把握と広告の効果測定
個人情報を販売することはなく、申請者の情報を当社のマーケティングや AI の学習に使うことはありません。
6. 委託先・外部送信先
- Vultr(The Constant Company, LLC、米国):API サーバー・データベース・バックアップ。サーバーは東京。
- Google LLC(Google ドライブ、米国):データベースの遠隔バックアップ(本人確認の記録は暗号化済み)。
- Vercel Inc.(米国):ウェブサイトと本人確認ページのホスティング。
- Anthropic, PBC(米国):本人確認書類・住所確認書類・資金源書類の読取、AI サポートチャット。
- Stripe, Inc.(米国):カードによるクレジットのチャージ。
- Resend, Inc.(米国):メール送信。
- Zoho Corporation:当社メールボックス hello@firstpass.cloud。
- Google LLC(Google アナリティクス・Google 広告、米国)、X Corp.(X Pixel、米国):第7項。
顔照合と顔の特徴量の計算は当社のサーバーで行い、第三者には送信しません。
7. 外部送信に関する公表事項(アクセス解析・広告の効果測定)
以下のタグは firstpass.cloud の公開ページでのみ動作し、本人確認ページ、お客様ダッシュボード、API では読み込みません。
- Google アナリティクス 4・Google 広告(送信先:Google LLC、米国):閲覧したページ、Cookie 等の識別子、端末・ブラウザの情報、フォーム送信等のイベント。目的はサイトの利用状況の把握と広告の効果測定です。ブラウザのアドオン(https://tools.google.com/dlpage/gaoptout)や広告設定(https://adssettings.google.com)で無効にできます。
- X Pixel(送信先:X Corp.、米国):閲覧したページ、ワークスペース登録の完了(コンバージョン)の発生、Cookie 等の識別子、IP アドレス、端末・ブラウザの情報。目的は当社の広告の効果測定です。ご入力いただいた会社名・メールアドレス・パスワードは送信しません。送信された情報は X のプライバシーポリシー(https://x.com/ja/privacy)に基づいて管理され、X の「パーソナライズとデータ」の設定(https://x.com/settings/account/personalization)から、広告のパーソナライズやデータの利用を停止できます。
8. 保存期間
- 本人確認の記録:自動削除の期限なし。削除のご依頼があれば、画像・顔の特徴量・氏名・メールアドレスを上書き消去し、消去した旨の記録に加え、記録 ID・ワークスペース・レベル・日時などのメタデータを残します。関連セッションの return_url などの運用情報も残るため、URL に個人情報を含めないでください。この処理ではデモ・登録ログ・独立した営業チャットは消去されず、これらの依頼は別途運用上の確認が必要です。
- レベル B の住所確認書類・資金源書類の画像:アップロードから90日後に閲覧不可となり、起動時または次の期限切れ処理で上書き消去(画像を上書き消去し、記録と読み取った項目は残します)。12桁の個人番号が写っている可能性がある画像、または読み取り処理で確認できなかった画像は保存せず、読み取った項目のみ残します。
- お客様のアカウント・課金・利用記録:ワークスペースの存続中、およびその後も会計・法令上必要な期間。
- デモの記録、サポートチャット、不正防止のログ:現時点で定めた削除期限はありません。削除のご依頼は hello@firstpass.cloud にお送りください。本人確認記録の消去とは別の対応が必要で、完了時期は保証していません。
- バックアップ:一定期間で入れ替わるため、消去・削除した情報がバックアップに一定期間残る場合があります。
9. 開示・訂正・利用停止・削除のご請求
個人情報の保護に関する法律に基づく開示・訂正・利用停止・削除等のご請求は hello@firstpass.cloud までご連絡ください。ご本人確認をお願いする場合があります。申請者の方は、まず本人確認を依頼したサービスにご連絡ください。当社もそのお客様と協力して対応します。
10. 外国にある第三者への提供
当社のサーバーは日本にありますが、第6項の委託先の一部は米国の事業者であり、米国その他の国で情報を取り扱う場合があります。これらの国の個人情報保護制度は日本と異なる場合があります。当社は、各事業者の規約に、情報を保護する旨が定められていることを確認し、業務に必要な範囲の情報のみを提供します。
11. 安全管理措置
通信は HTTPS で暗号化し、本人確認の記録はデータベース上で暗号化、API キーとパスワードはハッシュ化して保存し、サーバーと管理ツールへのアクセスは権限あるスタッフに限定しています。
12. 改定
取扱いを変更する場合は本ページを更新し、上記の日付を改めます。お客様に影響する重要な変更は、ワークスペースのメールアドレスにもお知らせします。