MyInbox SG ← トップページへ戻る

プライバシーポリシー

MyInbox SG — Operated by UNIVERSAL SCENT TECHNOLOGY PTE. LTD. (UEN 202420710N)

本書の正文は英語版です。日本語版は参考訳であり、両者に齟齬がある場合は英語版が優先します。
The English version below is the governing text; the Japanese text is a courtesy translation.

MyInbox SG プライバシーポリシー

最終更新日: 2026年8月22日

本プライバシーポリシー(以下「本ポリシー」)は、UNIVERSAL SCENT TECHNOLOGY PTE. LTD.(UEN 202420710N、登記住所: 137 Telok Ayer Street #05-07, Singapore 068602。以下「当社」)が、MyInbox SG サービス(以下「本サービス」)に関連して、シンガポール個人情報保護法(Personal Data Protection Act 2012。以下「PDPA」)に従い、個人データをどのように収集・利用・開示・保護するかを説明するものです。

本サービスはお客様の物理的な郵便物を取り扱うため、封筒の画像や、お客様の指示に基づく郵便物の内容物など、一般的なオンラインサービスよりも機微性の高いデータを処理します。本ポリシーはその取扱いを詳細に説明します。

第1条(データ保護責任者)

当社はデータ保護責任者(Data Protection Officer。以下「DPO」)を選任しています。連絡先: dpo@myinbox.sg または登記住所宛の郵便(「Data Protection Officer」宛と明記)。

第2条(収集する個人データ)

(a) アカウントデータ — 氏名、メールアドレス、電話番号、Box番号、プラン・各種設定、登録された追加受取人名義。

(b) 本人確認(KYC)データ — パスポートまたは公的IDの情報・画像、住所証明、関連する確認記録。

(c) 郵便メタデータ・外観画像 — 封筒外観の写真・スキャン(銀行名など差出人が判別できる場合があります)、到着日、取扱い履歴。

(d) 郵便内容データ(内容スキャン)お客様が開封スキャンを指示した場合に限り作成されます。内容スキャンには、銀行・カード明細、政府機関からの通知、医療・保険関連の書面など、極めて機微な情報が含まれ得ます。当社は、スキャンの実施・品質確認・お客様への提供に必要な場合を除き、内容を閲読・分析・利用しません。

(e) 決済データ — Stripeが処理します。当社は限定的な請求情報(カードブランド、下4桁、決済ステータス等)を受領しますが、カード番号全体は保存しません。

(f) 技術・利用データ — ログイン記録(マジックリンク認証)、IPアドレス、デバイス・ブラウザ情報、ダッシュボード操作、すべての郵便取扱い操作の監査ログ。

(g) コミュニケーション — サポートとのやり取り、通知メールの配信記録(メール配信事業者 Resend 経由)。

第3条(収集・利用・開示の目的)

当社は以下の目的で個人データを収集・利用・開示します:

  1. 本サービスの提供: 郵便物の受領・保管・到着通知・(指示に基づく)スキャン・廃棄、ダッシュボードの運営、サービス通知の送信。本サービスには郵便物の転送は含まれず、転送目的での個人データの処理は行いません。
  2. 本人確認および郵便受領権限の確認、詐欺・不正利用・違法利用の防止。
  3. Stripeによるサブスクリプション管理を含む請求・決済処理。
  4. カスタマーサポートおよびサービスに関する連絡。
  5. セキュリティの維持、監査ログおよび取扱い記録の管理。
  6. 法令上の義務、裁判所の命令、当局の適法な要請への対応。
  7. 集計化・非識別化データによるサービス改善(郵便物の内容を分析・広告・モデル学習に利用することは一切ありません)。
  8. お客様の明示的なオプトイン同意がある場合に限り、本サービスに関するマーケティング情報の送付。

当社は、PDPAに基づき、お客様の同意(登録時および指示時)、サービス履行に必要な処理についての契約上の必要性によるみなし同意、およびPDPAが許容する範囲での正当な利益(詐欺防止・セキュリティ等)を処理の根拠とします。

第4条(郵便物の内容 — 特別な保護措置)

  1. 指示なき開封の禁止。 お客様の明示的な指示、法令上の要求、または差し迫った危険の防止に合理的に必要な場合を除き、当社は郵便物を開封しません(利用規約第2条2項参照)。
  2. アクセス制限。 郵便物の取扱いおよび業務上の内容スキャンへのアクセスは、守秘義務を負う訓練済みの権限者に限定されます。
  3. 監査ログ。 すべての取扱い操作(受領・撮影・開封・スキャン・廃棄)および内容スキャンへのスタッフのアクセスは記録されます。
  4. 二次利用の禁止。 郵便物の内容は、マーケティング、プロファイリング、分析、広告、AI学習に利用されず、第5条に定める場合を除き第三者に開示されません。
  5. 暗号化。 内容スキャンおよび外観画像は、通信時(TLS)・保存時ともに暗号化されます。

第5条(第三者への開示)

当社は個人データを販売しません。開示先は以下に限られます:

本サービスは郵便物の転送を提供しないため、onward delivery(転送)のために運送事業者・郵便事業者へお客様の個人データを開示することはありません。

当社のデータ仲介者は、当社の指示に基づいてのみ個人データを処理し、PDPA水準で保護する契約上の義務を負います。

第6条(国外移転)

一部のサービス提供者(クラウドホスティング、Stripe、Resend等)は、シンガポール国外でデータを保存・処理することがあります。個人データを国外へ移転する場合、当社はPDPAの移転制限義務(Transfer Limitation Obligation)に従い、移転先がPDPAと同等の保護水準を提供することを、契約上の保護措置を含めて確保します。

第7条(保存期間・削除)

当社は、上記目的に必要な期間または法令上必要な期間に限り個人データを保存し、その後は安全に削除または匿名化します。現行スケジュール:

データ 保存期間
外観画像 当該郵便物の最終処理から90日後に削除
内容スキャン プラン/保存設定による。デフォルトは作成から1年、その後削除。アカウント解約後は一律30日で削除
アカウントデータ アカウント存続期間+1年
KYCデータ アカウント存続期間+解約後5年(詐欺防止・法的請求対応)
請求記録 5年(税務・会計要件)
監査ログ 3年

削除予定前に必要な内容スキャンをダウンロードすることはお客様の責任です。物理郵便物の保管・廃棄(スキャン後30日での廃棄デフォルトおよび180日での最終処理ルールを含む)は利用規約によります。

第8条(お客様の権利)

PDPAに基づき、お客様は以下を行うことができます:

当社の回答にご満足いただけない場合は、シンガポール個人情報保護委員会(PDPC、www.pdpc.gov.sg)に申立てを行うことができます。

第9条(セキュリティ)

当社は、データの機微性に応じた管理的・技術的・物理的保護措置を実施します: 保存・通信の暗号化、記録を伴うneed-to-knowベースのアクセス、物理郵便物のための安全な施設、スタッフの守秘義務誓約と訓練、安全な廃棄(クロスカットシュレッダー、デジタルデータの暗号学的消去)。PDPA上通知義務のあるデータ侵害(重大な害または相当規模)が発生した場合、法令に従いPDPCおよび影響を受ける本人に通知します。

第10条(Cookie・トラッキング)

app.myinbox.sg は必須Cookie(セッション・認証)のみを使用します。第三者広告Cookieおよびアクセス解析ツールは使用しません。Cookieはブラウザ設定で制御できますが、必須Cookieを無効化するとログインできなくなることがあります。

第11条(マーケティング・Do Not Call)

当社は本サービスの一部としてサービス通知・取引通知を送信します。マーケティングメッセージはオプトイン同意がある場合に限り送信し、常に配信停止手段を含めます。当社は Spam Control Act 2007 および、シンガポールの電話番号についてはPDPAのDo Not Call条項を遵守します。

第12条(未成年者)

本サービスは18歳未満の方を対象としておらず、顧客として未成年者のデータを故意に収集しません。登録受取人宛の郵便物に第三者の個人データが付随的に含まれることがありますが、当社は本サービスの提供に必要な範囲でのみ処理します。

第13条(郵便物に含まれる第三者の個人データ)

お客様が受領する郵便物には、第三者(差出人等)の個人データが含まれることがあります。当社は、お客様への本サービス提供に必要な範囲でのみこれを処理し、第4条と同じ保護措置を適用します。スキャンを指示することにより、お客様は当該郵便物を受領・処理する権限を有することを表明したものとします。

第14条(本ポリシーの変更)

当社は本ポリシーを随時更新することがあります。重大な変更は、発効の30日以上前にメールまたはダッシュボード通知でお知らせします。「最終更新日」が現行版を示します。

第15条(言語)

本ポリシーは英語で作成され、参考のため翻訳されることがあります。齟齬がある場合、英語版が優先します。

第16条(連絡先)

UNIVERSAL SCENT TECHNOLOGY PTE. LTD.(UEN 202420710N) 137 Telok Ayer Street #05-07, Singapore 068602 DPO: dpo@myinbox.sg / サポート: support@myinbox.sg

MYINBOX SG PRIVACY POLICY

Last updated: 22 August 2026

This Privacy Policy explains how UNIVERSAL SCENT TECHNOLOGY PTE. LTD. (UEN 202420710N, registered office: 137 Telok Ayer Street #05-07, Singapore 068602) ("UST", "we", "us") collects, uses, discloses, and protects personal data in connection with the MyInbox SG service (the "Service"), in accordance with the Personal Data Protection Act 2012 of Singapore (the "PDPA").

Because the Service handles your physical mail, we process categories of data that are more sensitive than a typical online service — including images of your mail and, on your instruction, the contents of your mail. This Policy describes those practices in detail.

1. Data Protection Officer

We have appointed a Data Protection Officer ("DPO"). Contact: dpo@myinbox.sg or by post to our registered office, marked "Data Protection Officer".

2. Personal Data We Collect

(a) Account data — name, email address, phone number, Box number, plan and settings, and additional recipient names you register.

(b) Identity verification (KYC) data — passport or national ID details and images, proof of address, and related verification records.

(c) Mail metadata and Exterior Images — photographs/scans of the outside of envelopes (which may reveal sender identity, e.g. a bank's name), arrival dates, and handling history.

(d) Mail content data (Content Scans) — created only when you instruct us to open and scan a mail item. Content Scans may contain highly sensitive information (bank and card statements, government correspondence, medical or insurance letters). We do not review, analyse, or use the contents except as needed to perform the scan, quality-check it, and deliver it to you.

(e) Payment data — processed by Stripe. We receive limited billing information (e.g. card brand, last four digits, billing status) but do not store full card numbers.

(f) Technical and usage data — login records (magic-link authentication), IP address, device/browser information, dashboard activity, and audit logs of all mail-handling actions.

(g) Communications — support correspondence and notification delivery records (via our email provider, Resend).

3. Purposes of Collection, Use and Disclosure

We collect, use and disclose personal data for the following purposes:

  1. Providing the Service: receiving and storing mail, notifying you of arrival, scanning (on instruction), and disposing of mail; operating the dashboard and sending service notifications. The Service does not include forwarding of mail; no personal data is processed for forwarding purposes.
  2. Verifying identity and entitlement to receive mail; preventing fraud, misuse, and unlawful use of the Service.
  3. Billing and payment processing, including subscription management via Stripe.
  4. Customer support and service communications.
  5. Maintaining security, audit logs, and records of handling actions.
  6. Complying with legal obligations, court orders, and lawful requests by authorities.
  7. Improving the Service using aggregated or de-identified data (never using mail contents for analytics, advertising, or model training).
  8. With your separate opt-in consent only: sending marketing communications about the Service.

We rely on your consent (given at sign-up and when you issue instructions), deemed consent by contractual necessity under the PDPA for processing necessary to perform the Service, and legitimate interests (e.g. fraud prevention, security) as permitted under the PDPA, where applicable.

4. Mail Content — Special Safeguards

  1. No opening without instruction. We never open mail except on your express instruction, where required by law, or where reasonably necessary to prevent immediate danger (see Terms of Service, Clause 2.2).
  2. Restricted access. Only trained, authorised staff bound by confidentiality obligations may handle mail or access Content Scans in the course of operations.
  3. Audit logging. Every handling action (receipt, imaging, opening, scanning, disposal) and every staff access to Content Scans is logged.
  4. No secondary use. Mail contents are not used for marketing, profiling, analytics, advertising, or AI training, and are not disclosed to any third party except as described in Section 5.
  5. Encryption. Content Scans and Exterior Images are encrypted in transit (TLS) and at rest.

5. Disclosure to Third Parties

We do not sell personal data. We disclose personal data only to:

Because the Service does not offer mail forwarding, we do not disclose your personal data to couriers or postal operators for onward delivery.

Our data intermediaries are bound by contract to process personal data only on our instructions and to protect it to PDPA standards.

6. International Transfers

Some service providers (e.g. cloud hosting, Stripe, Resend) may store or process data outside Singapore. Where personal data is transferred outside Singapore, we take steps required by the PDPA Transfer Limitation Obligation to ensure the recipient provides a standard of protection comparable to the PDPA, including contractual safeguards.

7. Retention and Deletion

We retain personal data only as long as necessary for the purposes above or as required by law, then securely delete or anonymise it. Current schedule:

Data Retention
Exterior Images 90 days after final handling action on the item, then deleted
Content Scans Per your plan/retention settings; default 1 year from creation, then deleted. Deleted 30 days after account termination in all cases
Account data Duration of account + 1 year
KYC data Duration of account + 5 years after termination (fraud prevention / legal claims)
Billing records 5 years (tax and accounting requirements)
Audit logs 3 years

You are responsible for downloading Content Scans you wish to keep before scheduled deletion. Physical mail storage and disposal (including the 30-day post-scan disposal default and the 180-day final handling rule) are governed by the Terms of Service.

8. Your Rights

Under the PDPA you may:

If you are dissatisfied with our response, you may complain to the Personal Data Protection Commission (PDPC), Singapore (www.pdpc.gov.sg).

9. Security

We implement administrative, technical and physical safeguards appropriate to the sensitivity of the data, including: encrypted storage and transmission; access on a need-to-know basis with logging; secure premises for physical mail; staff confidentiality undertakings and training; and secure destruction (cross-cut shredding; cryptographic erasure for digital data). In the event of a data breach that is notifiable under the PDPA (significant harm or significant scale), we will notify the PDPC and affected individuals as required.

10. Cookies and Tracking

app.myinbox.sg uses strictly necessary cookies (session/authentication) only. We do not use third-party advertising cookies or analytics tools. You can control cookies via browser settings; disabling necessary cookies may break login.

11. Marketing and Do Not Call

We send service/transactional messages as part of the Service. Marketing messages are sent only with your opt-in consent and always include an unsubscribe mechanism. We comply with the Spam Control Act 2007 and, for Singapore telephone numbers, the PDPA Do Not Call provisions.

12. Minors

The Service is not directed at persons under 18, and we do not knowingly collect their data as customers. Mail addressed to registered recipients may incidentally contain third-party personal data; we process such data solely to provide the Service.

13. Third-Party Personal Data in Your Mail

Mail you receive may contain personal data of third parties (e.g. senders). We process such data only as necessary to provide the Service to you and apply the same safeguards described in Section 4. By instructing scanning, you confirm you are entitled to receive and deal with the mail concerned.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by email or dashboard notice at least 30 days before taking effect. The "Last updated" date shows the current version.

15. Language

This Policy is prepared in English and may be translated for convenience. In case of inconsistency, the English version prevails.

16. Contact

UNIVERSAL SCENT TECHNOLOGY PTE. LTD. (UEN 202420710N) 137 Telok Ayer Street #05-07, Singapore 068602 DPO: dpo@myinbox.sg / Support: support@myinbox.sg