Privacy Policy
v1.0.0Effective Date: January 4, 2026
This Privacy Policy describes how G Y UNIT LIMITED LIABILITY COMPANY ("we", "us", or "our"), a company located in Tokyo, Japan, collects, uses, and shares your personal information when you use the Unit Oncall service (the "Service").
1. INFORMATION WE COLLECT
We collect only the minimum information necessary to provide the Service:
Account Information
Email address and display name.
Technical Identifiers
Device tokens (for push notifications) and IP addresses.
Alert Data
Information contained in alerts sent from your integrated monitoring tools.
Audit and Security Records
We create records of security- and configuration-relevant events so that activity on the Service can be reviewed after the fact. These records are of two kinds:
- Organization audit records — actions taken within an Organization, such as changes to its members, Teams, Schedules, integrations, and settings. Each record includes the event and the time it occurred, the user who performed it and the user it affected (where applicable), the source IP address, the user agent of the browser or client used, a request identifier, and metadata describing the event. These records are created only for Organizations on a plan that includes audit logging; on plans that do not include the feature, the corresponding records are not created.
- Account-level security records — events that belong to a Unit Oncall account rather than to any single Organization, such as signing in, signing out, failed sign-in attempts, and attempts to enter an Organization of which the account is not a member. Each record includes the event and the time it occurred, the account concerned where it can be determined, the source IP address, the user agent, a request identifier, and metadata describing the event. We do not store the email address submitted in a failed sign-in attempt.
For the categories of personal information that we disclose to California consumers under the CCPA/CPRA, the information contained in these records falls under the "Identifiers" category (including the source IP address and the account to which the record relates) and the "Internet or other electronic network activity information" category. See §6 (Data Retention) for how long these records are kept and for how they are treated when you delete your account.
NO PHONE NUMBERS
We do not collect or store your physical phone numbers. VoIP communications are handled via data-based protocols (WebSocket/Push).
Social Login Information (OAuth)
When you choose to sign in using Google or GitHub, we receive:
- Your email address
- Your display name
- Your profile picture URL
We do not receive or store your Google or GitHub password. Your social login credentials are handled entirely by Google or GitHub.
2. HOW WE USE YOUR INFORMATION
We use your information to:
- Provide and maintain the Service.
- Process transactions and fulfill orders through our third-party processors.
- Detect, prevent, and address fraud, unauthorized access, or security issues.
- Comply with legal and regulatory obligations.
- Create and manage your account.
- Deliver notifications to your devices via VoIP and push notifications.
- AI Summarization: Utilize Google Cloud Vertex AI to summarize and reformat alert data to provide more understandable notifications.
- Analyze and improve the performance and security of the Service.
We do not process your personal information for purposes that are incompatible with the original purpose of collection without providing you with direct notice and obtaining your consent.
3. DATA PROCESSING AND AI SAFETY
We utilize enterprise-grade AI infrastructure to ensure your data is handled securely:
Vertex AI Processing
We use Google Cloud Vertex AI to process alert data.
No Training
In accordance with Google Cloud's data governance policies, your data is NOT used to train Google's foundational AI models. Your information remains your own.
AI Responsibility
While AI helps clarify alerts, it may occasionally generate inaccurate information. You are responsible for verifying the original alert data before taking any action.
4. DATA STORAGE AND CROSS-BORDER TRANSFER
Storage Location
Your personal data is stored and processed in the United States using Google Cloud Platform infrastructure.
Transfer to Japan
As we are a Japanese company, your data may be accessed by our personnel in Japan solely for maintenance and support purposes.
Consent
By using the Service, you expressly consent to the transfer and processing of your personal data in the United States and Japan.
For Residents of Canada: Your personal information may be subject to the laws of the United States, and may be subject to disclosure to the governments, courts, or law enforcement or regulatory agencies of the United States, pursuant to its laws.
5. REGIONAL RESTRICTIONS (GDPR)
The Service is intended for residents of the United States, Canada, and Japan. It is NOT intended for residents of the European Union (EU) or the European Economic Area (EEA).
6. DATA RETENTION
We retain your personal data for as long as your account is active or as needed to provide you with the Service. Upon account deletion, your personal data will be removed within 30 days, except (i) where retention is required by applicable law, and (ii) as otherwise provided in the subsections below for operational audit logs.
Operational Audit Logs
We retain the audit and security records described in §1 in order to support security monitoring, incident response, abuse prevention, and compliance with applicable laws and with our legal and contractual security obligations. We do not use these records for other purposes.
Organization audit records. Where audit logging is included in your Organization's plan, these records are retained for up to five (5) years from the date the record is created. Your Organization may choose a shorter retention period in its settings, in which case the shorter period applies; a period longer than the maximum permitted by your plan is limited to that maximum. Enterprise plans may provide for a longer period, including retention without a fixed end date. Audit logging is not available on plans that do not include the feature, and on those plans the corresponding records are not created; records created while the feature was included in the plan are retained for up to five (5) years from the date the record is created, regardless of the period that applied when they were created, and are no longer viewable in the Service once the plan no longer includes the feature.
Account-level security records. These records are created for every account, irrespective of plan, because the events they describe occur before any Organization or plan has been determined — a failed sign-in, for example, happens before an Organization is chosen. These records are retained for up to five (5) years from the date the record is created. In setting that period we took into account the time required to detect and investigate abuse that develops over an extended period (such as credential-stuffing and account-enumeration attempts), the period within which a security incident is likely to come to light, and the periods for which we may need to establish, exercise, or defend legal claims.
For both kinds of record, deletion is carried out by a scheduled process that runs periodically rather than continuously. A record may therefore remain for a short additional period after its retention period has elapsed, until the next scheduled run.
Any copies of these records retained in backup or archival systems are purged in the ordinary course of our backup rotation schedule and are accessed only for disaster recovery or for the purposes described in this subsection. Records may be retained for a longer period only where required by applicable law (for example, in response to a legal hold).
Anonymization of Audit Records
The retention periods above apply to the records themselves, not to the personal data they contain about you. When you delete your account, or when we act on a verifiable request from you to delete your personal information, we do not delete these records; we anonymize them. For account deletion, anonymization is carried out as part of the deletion process, within the 30-day period stated at the beginning of this section.
Anonymization consists of the following:
- Every reference to you in a record — the user who performed the action, the user affected by it, and, where the subject of the record is a user account, the subject of the record — is replaced with a surrogate reference. The surrogate reference is generated at random; it is not derived from your account identifier, your email address, or any other information about you.
- We create no mapping between a surrogate reference and an account. No mapping table, key, or equivalent record is created or kept in the systems that hold these records. Copies of a record made before it was anonymized may remain in backup and archival systems until they are purged on the schedule described above; we do not use those copies to resolve a surrogate reference, and they are accessed only for the purposes stated in that paragraph.
- The source IP address and user agent recorded for actions you performed are overwritten, the request identifier is removed, and the event metadata is reduced to a fixed list of fields that do not identify an individual; anything outside that list is discarded.
- The record is marked as anonymized, together with the time of anonymization.
- These changes are applied to every category of audit record in a single database transaction, so that a record is either anonymized in full or left unchanged.
The purpose of the surrogate reference is to preserve the continuity of the audit trail: actions carried out by the same person remain recognizable as a single sequence for the purpose of a security investigation, without identifying the person. This is how we are able to act on your deletion request while keeping an intact record of what happened.
We will not attempt to re-identify anonymized audit records. We maintain and use these records only in anonymized form. We will not build or use any capability to link a surrogate reference to an account, and we will not correlate anonymized records with account data, with other records or logs, or with information obtained from any third party, for the purpose of determining whom a record concerns.
One limitation applies. Account-level security records that are not associated with any account — a failed sign-in attempt using an email address that does not correspond to an account, for example — contain no account reference and therefore cannot be located in response to a request concerning a particular individual. For those records, the retention criteria described above are the only applicable control. As stated in §1, we do not store the email address submitted in such an attempt.
7. YOUR RIGHTS
7-1. General Rights Regarding Your Personal Data
Depending on your location, you may have certain rights regarding your personal data:
- Right to Know and Access: You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months, including the categories of information collected, the sources, and the third parties with whom we share it.
- Right to Delete: You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. For operational audit records, we respond by anonymizing the records rather than deleting them, as described in §6 (Data Retention).
- Right to Correct: You have the right to request the correction of any inaccurate personal information that we maintain about you.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of your sensitive personal information to only those services necessary to perform our business.
7-2. Privacy Notice for California Residents
This section applies solely to residents of the State of California ("consumers" or "you"). We adopt this notice to comply with the California Consumer Privacy Act of 2018 ("CCPA") and the California Privacy Rights Act of 2020 ("CPRA").
The CCPA/CPRA provides California residents with specific rights:
-
Right to Opt-Out of Sale or Sharing: You have the right to direct us to not "sell" your personal information for monetary value or "share" your personal information for cross-context behavioral advertising. (Note: We do not currently sell or share personal information as defined by these laws.)
-
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
-
Authorized Agent: Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information for California residents.
7-3. Exercising Your Rights
To exercise the rights described above, please submit a verifiable consumer request to us by:
- Contact Form: https://unit-oncall.com/contact/
- Email: legal@unit-oncall.com
We will verify your identity before responding to your request.
7-4. Record Keeping and Retention
To ensure compliance with legal requirements, the Company maintains a record of all consumer requests and our responses thereto. We will retain these records for a minimum of 24 months, as required by CCPA/CPRA.
7-5. Children’s Privacy and Sale of Minors’ Personal Information
The Service is not intended for use by anyone under the age of 16. We do not knowingly collect or maintain personal information from individuals under the age of 16. Furthermore, the Company does not have actual knowledge that it sells or shares the personal information of consumers under 16 years of age.
8. SECURITY
We implement industry-standard security measures to protect your personal data, including encryption in transit (TLS) and at rest. However, no method of transmission over the Internet is 100% secure.
9. THIRD-PARTY SERVICES
The Service integrates with third-party services:
- Google Cloud Platform: For hosting, AI processing, and infrastructure. Google Privacy Policy
- Google reCAPTCHA: To protect our contact form from spam and automated abuse. When you use our contact form, reCAPTCHA collects hardware and software information (such as device and application data) and sends it to Google for analysis. We act as the data controller for this information. Google Privacy Policy
- Google OAuth: For optional social login authentication. Google's privacy policy applies to data processed by Google. Google Privacy Policy
- GitHub OAuth: For optional social login authentication. GitHub's privacy policy applies to data processed by GitHub. GitHub Privacy Statement
- Stripe Managed Payments (Stripe, Inc.): Acts as our Merchant of Record (MoR) in the jurisdictions where Stripe Managed Payments is offered, handling payment processing, invoicing, chargeback handling, and tax compliance—calculating, collecting, and remitting applicable sales taxes, VAT, and GST (Stripe Tax provides the underlying calculation engine). Stripe Privacy Center
- Postmark (ActiveCampaign, LLC): For transactional email delivery (e.g., password resets, email verification, system alerts). Postmark Privacy Policy
- Apple Push Notification Service (APNs): For iOS push notifications. Apple Privacy Policy
- Firebase Cloud Messaging (FCM): For Android push notifications. Google Privacy Policy
Each third-party service has its own privacy policy governing the use of your data.
10. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar technologies on unit-oncall.com to operate our service and understand usage patterns. You can manage your preferences via the Cookie Banner displayed on first visit, or by clearing your browser storage for unit-oncall.com to reset your choices.
10-1. Categories
| Category | Purpose | Cookies | Local Storage | Opt-out |
|---|---|---|---|---|
| Necessary | Essential for site operation (security, session) | — | unit-oncall-cookie-consent (records your cookie preferences; technically a Local Storage item, not a cookie) | Cannot be disabled |
| Analytics | Anonymous usage measurement to improve our product | Firebase Analytics (GA4) _ga, _ga_* | — | Toggle "Analytics" off in the Cookie Banner |
| Marketing | Currently not used (toggle reserved for future advertising features) | — | — | Toggle "Marketing" off in the Cookie Banner |
10-2. Consent Mode v2
We implement Google Consent Mode v2. When you visit unit-oncall.com for the first time, the following Consent Mode categories are set to denied by default: analytics_storage, ad_storage, ad_user_data, and ad_personalization. Other Consent Mode categories not used by this site (such as functionality_storage and security_storage) remain at their browser defaults. Analytics scripts (GA4) only fire after you explicitly grant consent via the Cookie Banner. This ensures no analytics or advertising cookies are placed on your device without your explicit opt-in.
10-3. Withdrawing Consent
You can change your cookie preferences at any time by clearing your browser storage for unit-oncall.com. The Cookie Banner will reappear on your next visit, allowing you to make a new selection.
10-4. Third-Party Sub-Processors
Firebase Analytics is provided by Google LLC. Their data handling is governed by Google's Privacy Policy and the Google Analytics Data Processing Terms. See §9 (Third-Party Services) for the full list of sub-processors.
11. GOVERNING LAW AND JURISDICTION
This Privacy Policy shall be governed by the laws of Japan. Any disputes shall be subject to the exclusive jurisdiction of the Tokyo District Court.
12. CONTROLLING LANGUAGE
This Privacy Policy is drafted in English. In the event of any discrepancy between the English version and any translation, the English version shall prevail.
13. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Effective Date" above.
14. CONTACT US
If you have any questions about this Privacy Policy, please contact us at:
Contact Form: https://unit-oncall.com/contact/
Email: legal@unit-oncall.com
Address:
G Y UNIT LIMITED LIABILITY COMPANY
N&E BLD. 6F., 1-12-4, GINZA, CHUO-KU, TOKYO, JAPAN
Questions about this policy? Contact us
