Last updated: 2026-04-25
Tankotastic (“we”, “us”, “I”) operates tankotastic.com (the “Site”) and the e-commerce service described on it. This policy explains what personal data we collect, why, how we use it, and your rights.
Contact for all privacy matters: hello@tankotastic.com
1. Who we are
Tankotastic is operated by Said Tijani Ben, an individual trader based in Itabashi-ku, Tokyo, Japan. Tijaniben Said is the data controller for personal data collected through this Site.
For data-protection correspondence, please email hello@tankotastic.com. Full business address disclosed without delay on request.
2. What we collect
We collect only what’s needed to fulfill your order and run the Site.
When you place an order:
- Name
- Shipping address
- Billing address (if different)
- Email address
- Phone number (for EMS shipping label — required by Japan Post)
- Payment details (processed and stored by Stripe — we never see or store your card number)
- Order history on our store
When you browse the Site:
- IP address (used to auto-detect country for currency display, then discarded)
- Device / browser type
- Pages visited, referral source
- Cookies (see Section 7)
When you subscribe to the newsletter:
- Email address only
When you email us:
- Email address and the content of your message
3. Why we use it
- Fulfill your order — process payment, print the shipping label, deliver the package
- Customer service — respond to your emails, handle refunds, track packages
- Legal compliance — tax records, customs declarations, Japanese accounting law
- Service improvement — anonymized analytics to understand what’s popular
- Marketing (only if you opt in) — send you occasional emails about new snacks and promotions
We do not sell your personal data. Ever.
4. Who we share it with
Only with service providers strictly needed to run the store:
| Provider | What they receive | Why |
|---|---|---|
| Stripe | Payment info | Process your payment |
| Japan Post (EMS) | Name, address, phone | Ship your order |
| Our hosting provider | Everything you submit to the Site | Store the data on their servers |
| Email provider (e.g. Mailchimp / ConvertKit) | Email address only, if subscribed | Send newsletter |
| Google Analytics (if enabled) | Anonymized browsing data | Understand site traffic |
Each of these has its own privacy policy. We use reputable providers with appropriate data-protection standards.
We may also disclose data if legally required (court order, tax audit, customs investigation).
5. International transfers
Because we ship worldwide, your data may be transferred outside Japan — for example, to Stripe’s servers (US / EU) or to postal networks in your country. We only use providers that comply with recognized data-protection frameworks.
6. How long we keep it
- Order records: 7 years (required by Japanese tax law — 法人税法 / 所得税法)
- Email correspondence: 2 years, then deleted
- Newsletter subscription: until you unsubscribe
- Analytics cookies: up to 2 years, anonymized
7. Cookies
We use a minimum set of cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| tk_country | Remember your country for currency display | 7 days |
| tk_currency_seen | Don’t re-show the currency banner | 30 days |
| WooCommerce cart cookies | Keep your cart contents between pages | Session |
| Google Analytics (_ga, _gid) | Anonymous traffic analytics (if enabled) | 2 years |
You can disable cookies in your browser, but the cart won’t work if you block WooCommerce cookies.
8. Your rights
Depending on where you live, you may have rights to:
- Access the personal data we hold on you
- Correct data that’s wrong
- Delete your data (subject to legal retention limits — tax records we must keep)
- Export your data in a portable format
- Withdraw consent for marketing emails (unsubscribe link in every email, or email us)
- Object to processing
- Lodge a complaint with your local data-protection authority
To exercise any of these, email hello@tankotastic.com. We respond within 30 days.
If you’re in the EU / UK (GDPR)
Our legal bases for processing are: contract performance (fulfilling your order), legal obligation (tax, customs), consent (newsletter), and legitimate interest (basic analytics, fraud prevention).
If you’re in California (CCPA/CPRA)
You have the right to know what we collect, request deletion, and opt out of “sale” (we don’t sell data). Email us to exercise these rights.
If you’re in Japan (APPI — 個人情報保護法)
We comply with the Act on the Protection of Personal Information. Requests for disclosure / correction / deletion can be sent to hello@tankotastic.com.
9. Security
- All Site traffic is encrypted with HTTPS (TLS 1.2+)
- Payment is handled by Stripe — PCI DSS Level 1 certified
- We don’t store card numbers, CVV, or full payment details
- Passwords (if you create an account) are hashed, never stored in plain text
No system is 100% secure. If a breach affects your data, we’ll notify you and relevant authorities as required by law.
10. Children
Tankotastic is not directed at children under 13. We do not knowingly collect data from children. If you believe a child has submitted data, email us and we’ll delete it.
11. Changes to this policy
We may update this policy when the law or our practices change. Material changes will be announced on the Site. The “last updated” date at the top will always be current.
Questions? hello@tankotastic.com