Privacy Policy
COMSEE Privacy Policy
Established September 26, 2026
AI Hikari, Inc. ("we") handles personal information in COMSEE (the "Service"), our TikTok Shop operations service, in accordance with this policy. Our other businesses follow our company privacy policy (ai-hikari.com). This English version is a translation for reference. If there is any discrepancy, the Japanese version prevails.
1. Information we collect
- Account information: name, email address, organization, role and profile image. Passwords are kept by our contractor (Amazon Cognito); we do not hold them.
- Sign-in with external accounts: when you sign in with Google or LINE, we receive from that provider, with your consent, your email address, whether it is verified, your name (display name) and your identifier in that service.
- Applications to use the Service: the applicant's name, email address, organization name, shop name, operating status and requests.
- Information entered into the Service: business partners' contact names, contact details and notes, and cases, tasks, photos and other information users register.
- Information from External Services: based on the user's authorization, product, order, return, sales and performance information from TikTok Shop, and aggregated ad performance and audience attributes from TikTok for Business. Order information may include information about buyers, but the Service does not display buyers' names, addresses or contact details, nor use them to contact buyers.
- Usage records: the type of device used to sign in (browser information), the date, result and IP address of sign-in attempts, and records of operations.
- Inquiries: company name, name, email address and the content of the inquiry.
2. Purposes of use
- Providing the Service (creating accounts and verifying identity, matching existing accounts, inviting members to organizations, connecting External Services, displaying screens, analysis and forecasting, AI suggestions and drafts)
- Reviewing applications and contacting users (procedures, notices and important changes)
- Responding to inquiries and support
- Preventing unauthorized access and use, and ensuring security
- Investigating failures and improving the Service (using statistical information that does not identify individuals)
- Complying with laws
3. Information received from External Services
Information received from TikTok Shop and TikTok for Business is used only for the Customer that authorized it; it is not shown to other Customers or provided to third parties. We comply with TikTok's developer terms and data rules.
The email address and name received from Google or LINE are used only to match or create your account and to send notices from the Service.
4. AI processing
To create suggestions, drafts and summaries, we pass the user's question and the necessary part of the organization's data to an AI model. The AI model runs on Amazon Bedrock (regions in Japan), and the data passed is not used to train the model. Buyers' personal information is not passed to the AI model.
5. Provision to third parties
We do not provide personal information to third parties without prior consent, except:
- when required by law;
- when necessary to protect a person's life, body or property and it is difficult to obtain consent;
- when necessary to cooperate with national or local government bodies performing duties prescribed by law; or
- when provided along with the succession of business due to a merger or other reasons.
6. Contractors and storage location
We entrust the handling of personal information to contractors to the extent necessary to provide the Service. Our main contractor is Amazon Web Services (servers, databases, file storage, sign-in, email delivery and AI processing). Data is stored in the Tokyo region (Japan), and AI processing takes place in regions in Japan.
To deliver screens faster we use a content delivery network (Amazon CloudFront), and communications may pass through locations outside Japan.
We set safety management in contracts with contractors and supervise them appropriately.
7. Security measures
- Encryption in transit (TLS) and at rest. Authorization credentials for External Services are further encrypted with a separate key.
- Data is separated by organization, and row-level controls in the database prevent other organizations from reading it.
- Role-based permissions and limits on the number of sign-in attempts.
- Passwords are left to a dedicated service (Amazon Cognito) and are not kept in our database.
- Keeping records of operations and failures, and training employees.
- Understanding the external environment: personal data is stored in Japan (AWS Tokyo region). We take safety management measures after understanding the personal information protection systems of the countries where our contractors are located.
8. Cookies
The Service uses cookies and browser storage to keep your sign-in, display language, selected shop and display settings (such as the sidebar width). We do not use cookies for advertising or behavioral tracking, nor external analytics tools.
9. Retention period
We keep personal information for as long as necessary for the purposes of use. After use of the Service ends, User Data is deleted after the period we set. Operational logs are deleted automatically after 30 days and database backups after 14 days. Information that the law requires us to keep is kept for that period.
10. Requests for disclosure, correction, deletion, etc.
When you request notification of the purposes of use, disclosure, correction, addition or deletion, suspension of use or erasure, suspension of provision to third parties, or disclosure of records of provision to third parties for retained personal data, we respond without delay in accordance with the law after verifying your identity. Please contact the address below.
We do not charge a fee for these requests.
You can revoke connections with External Services at any time on the External Service. Disconnection on the Service side can also be requested at the address below.
11. Changes
When we change this policy, we announce the changed content and its effective date on the Service or our website. We notify users of important changes by email or other means.
12. Business operator and contact
AI Hikari, Inc. (株式会社AI光)
1-2 Kaigan, Minato-ku, Tokyo 105-0022, Japan
Representative Director: QI ZHIJIE
Privacy inquiries: privacy@ai-hikari.com


