Information Security Policy
Information Security Policy
At Marvelous Co., Ltd. (hereinafter "the Company") operates first-party e-commerce brands (Zutty, Belle Cie, At Marvelous) on its own shops and marketplaces. This Information Security Policy describes the security and data-protection practices the Company applies to its internal systems, integrations, and the limited customer data the Company handles on its own behalf. The Company does not provide software or services to third-party merchants; all integrations are for first-party self-use only.
1. Scope and Purpose
This Policy applies to all employees, contractors, devices, applications, cloud services, and data assets used by the Company in the course of operating its own e-commerce business. The purpose of this Policy is to protect the confidentiality, integrity, and availability of customer data, business records, and operational systems.
2. Organizational Security
Information security is the responsibility of the Company's representative director, who acts as the single accountable owner for security decisions, incident response, and data-protection requests. Security responsibilities are reviewed at least annually.
3. Access Control
Access to internal systems, cloud accounts (Google Workspace, AWS, Firebase, Cloudflare), and e-commerce platform accounts is granted on a least-privilege basis. Each authorized person uses an individual account with a strong unique password and multi-factor authentication (MFA) where supported. Shared credentials are avoided; when unavoidable for legacy platforms, they are restricted to a minimum number of staff and rotated upon role change.
4. Data Classification and Encryption
The Company classifies data into the following categories and applies controls accordingly:
- Customer personal data (name, address, phone number, order history) — handled exclusively through established e-commerce platforms (Rakuten, Amazon, Yahoo, Shopify, SHOPLIST, etc.) and never copied to uncontrolled local files. Internal references retain only minimum identifiers (order ID, SKU).
- Business operational data (inventory, pricing, SKU master) — stored on Google Drive / Google Sheets and AWS S3 with access controls.
- Public data (product catalog, public website content) — published openly with no confidentiality requirement.
All data in transit is encrypted using HTTPS/TLS. Data at rest is stored in Google Cloud (Firebase / Google Drive) and AWS S3, which apply provider-managed encryption-at-rest by default. Credentials and API secrets are stored in restricted environment files and never committed to source control.
5. Endpoint Security
All company-managed devices run Microsoft Windows with Windows Defender (built-in antivirus and real-time protection) enabled. Automatic operating-system and application updates are enabled. Screen lock with short timeout, complex password policy, clear-desk practice, and multi-factor authentication for cloud services are enforced as daily operational practice.
6. Network and Infrastructure Security
The Company relies on managed cloud infrastructure (Google Cloud, AWS, Cloudflare) that provides built-in DDoS protection, network monitoring, and threat detection. The Company does not host production services on self-managed servers. Public web properties are served via Cloudflare Workers / Cloudflare CDN with TLS, HSTS, and security headers applied.
7. Vulnerability Management
The Company monitors vendor advisories for the cloud services and libraries it depends on. Operating systems and managed services apply security updates automatically. Application dependencies are reviewed and updated when security advisories are issued. The single accountable owner reviews the security posture of all integrations at least every six months and after any significant change to systems or business processes.
8. Incident Response
In the event of a suspected or confirmed security incident or data breach, the Company follows the response process below:
- The person who discovers the incident reports it immediately to the representative director (the single accountable owner).
- The scope and impact are assessed; affected accounts or systems are isolated and credentials rotated as needed.
- Affected customers, partners, and platform providers (including TikTok Shop where applicable) are notified without undue delay once material impact is confirmed.
- Reports to regulatory authorities are made when required by applicable law (including the Japanese Personal Information Protection Act).
- A post-incident review is conducted, and preventive measures are applied. The incident record is retained for future reference.
9. Data Subject Rights and Deletion
The Company supports user requests to access, correct, update, export, or delete personal data as set out in its Privacy Policy. Requests received through the contact form are handled without undue delay after verification of the requestor's identity. Where the Company integrates with platform partners (e.g. TikTok Shop) on a first-party self-use basis, the Company will assist the platform in fulfilling lawful user requests, including update or deletion of user data, and will delete user data obtained through such integrations after the cooperation ends or upon platform request.
10. Third-Party and Sub-Processor Management
The Company uses a limited set of established third-party providers (Google Workspace / Cloud, AWS, Cloudflare, e-commerce platforms, payment processors). Personal data is processed only through providers that publish their own security and privacy standards. The Company does not transfer personal data to third parties outside the scope of its Privacy Policy and applicable law.
11. Compliance and Review
This Policy is reviewed at least annually and updated whenever material changes occur in systems, regulations, or business processes. The Company complies with the Japanese Personal Information Protection Act and applicable contractual obligations with platform partners. While the Company does not currently hold ISO 27001, ISO 27701, or SOC 2 Type II certification, it applies equivalent practical controls scaled to the size and risk profile of a small first-party e-commerce operator.
12. Contact
For security inquiries, vulnerability reports, or data-protection requests, please use the contact form. All notifications received through this channel are routed to the single accountable owner for prompt response.
Effective: 2026-06-17
At Marvelous Co., Ltd.