Legal

Data Processing and Security Policy

How data is processed, secured, and retained across our website, orders, and client engagements.

Last updated: August 19, 2026

This policy describes how Autonomax processes and secures data in connection with the https://www.autonomax.site website, orders, and client engagements. It supplements our Privacy Policy with more detail for clients providing project data.

1. Categories of Data Processed

  • Website enquiry data.
  • Customer, order, and invoice data.
  • Traffic videos.
  • Vehicle, sensor, GPS, or other mobility data.
  • Personal data, including video content that may incidentally include faces or vehicle number plates.
  • Payment metadata from Stripe and PayPal — order totals, payment status, and transaction references. Full card numbers and PayPal account credentials are handled by Stripe and PayPal directly and are never received or stored by us.

2. Client Responsibility for Lawful Authority

Clients are responsible for having the appropriate legal authority, notices, consents, and permissions in place before providing video, sensor, vehicle, GPS, or personal data to us — including where footage or data may incidentally include identifiable individuals or vehicles.

3. Purpose and Retention

We use client-provided project data only for the agreed service or project, and retain it only as reasonably necessary for delivery of that engagement, legal obligations, security, and dispute resolution. We do not claim a specific retention period.

4. Access Controls

Access to data is limited to authorised personnel and the service providers who process it on our behalf. Server-side credentials for our systems are stored as environment variables and are never exposed in client-side code, source control, or logs.

5. International Data Transfers

Stripe, PayPal, and our hosting providers may process data outside Japan as part of providing their services to us.

6. Security Measures

  • Payment card and PayPal account data is handled directly by Stripe and PayPal, not by our own systems.
  • Server-side secrets are kept in environment variables and are never sent to the browser or committed to source control.
  • Server-side validation is used for order pricing, so browser-submitted values are never trusted for payment amounts.
  • Access to our database uses role-scoped credentials rather than broad, shared access.

We do not claim a specific encryption standard, anonymisation process, or security certification. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Sub-processors

We use the following service providers to deliver our website and services: Vercel (hosting), Supabase (database), Stripe (payments, including card and Google Pay processing), and PayPal (payments, once enabled). Google Pay is a payment method available through Stripe and is not an independent data processor for us.

8. Contact for Data Requests

For questions about this policy or to make a data request, contact info@autonomax.site.