Privacy Policy

Last update 03/13/2024

1. About This Privacy Policy

We believe that everyone using FamilyAlbum should be confident in the security of their data. We wrote this Privacy Policy to explain to our users what data we collect, how it’s used, disclosed, and why.

This Privacy Policy also provides information based on laws related to the processing of your personal data. Further, this Privacy Policy sets out the basis by which we will process any personal data that you provide to us or that we obtain from other sources.

Thank you for taking the time to read through this Privacy Policy. If you have any questions, please do not hesitate to contact us.

2. Information About Us

For the purpose of data protection law, MIXI, Inc. ("we", "us", and "our") is the data controller with respect to your personal data.

  1. Our main office address:
    Shibuya Scramble Square 36F, 2-24-12 Shibuya, Shibuya-ku, Tokyo 150-6136, Japan
  2. Our email address:
    support@family-album.com
  3. You can also contact us by tapping “Support” in the Settings tab of the FamilyAlbum app.

3. Definitions

In this Privacy Policy:

  1. Your “personal data” means any data which relates to you and from which you can be identified. It may include contact details, other personal information as defined under applicable data protection laws, photographs, and videos.
  2. Processing” means any activity or operation that is carried out in respect of your personal data, including collecting, storing, using, transferring, and deleting.
  3. App” refers to the family photograph/video-sharing mobile and web applications collectively named “FamilyAlbum”.
  4. Child” means any individual under the age of 13 registered as a “child” in the FamilyAlbum app.

4. How We Collect Your Personal Data and What Personal Data We Collect

  1. Information you provide while using the app. This may include your nickname, email address, relationship to the child, payment information (including credit card details and shipping information) and usage history of the app, as well as the child’s nickname, age, and birthdate. Other personal data may also be contained in photographs and video clips you upload to the app, users’ comments on them, titles of photo albums, photobooks and DVDs, passwords set by users for URLs making it possible for other users to view albums, etc.

    In order to use the app, you are required to provide nicknames for yourself and the child, as well as your relationship to the child. Other personal data is not required. Any additional personal data will only be obtained if and when you choose to provide it to us.
  2. Information we collect. This may include your device information (such as operating system/version, hardware model, browser type/version), IP address, FamilyAlbum login information, usage log for the app, device IDs (such as Apple IDFA or Google AAID), and cookies and similar technologies.

    For more information regarding cookies and similar technologies, please see “9. Information on the use of cookies and similar technologies” below.
  3. Information we collect from other sources. This may include:
    • Information about ad clicks and app installs from marketing platforms
    • Purchase information/history from Apple, Google, and other payment platforms for products and services ordered through the app
    • FamilyAlbum usage activity from analytics platforms
    • Shipping information provided by other app users when ordering DVDs, photobooks, and/or other products and services purchased through the app as a gift
    • Perceptual hashes of photographs and video clips, feature vectors of users’ faces, the estimated gender and age of each user’s face, results of classifications of facial images of each user (used for album function for each user), results of automatic suggestions for creating and purchasing photobooks and other products and/or services, tag information on photographs and video clips, etc. generated via Google Cloud Platform.
    • When uploading to FamilyAlbum via Google Photos: Photos/videos selected for upload and profile information registered to Google Photos (If you choose to use this feature, your name, email address, and profile picture are accessed to display in the app while using the feature. This information is not saved to our servers.)

5. Purpose and Legal Basis of Processing Personal Data

We may use your personal data for the following purposes based on your consent (where required under applicable data protection laws) or our legitimate interests (or an equivalent basis under the laws of your jurisdiction), or in order to perform contracts with you or comply with our legal obligations:

  • To provide you with our services. Our services include the app, customized content (such as 1s Movies, auto-generated photobooks, DVDs, and other content), payment processing for products and services purchased within the app, and improvements to the app.
  • To provide user support. This includes handling inquiries and complaints, troubleshooting and solving technical issues, and making necessary changes to our services.
  • For marketing analytics. This includes collecting and analyzing data to research usage of the app.
  • To protect against cyberattacks. This includes maintaining the privacy of our users and investigating and deterring unauthorized or illegal activity.
  • For marketing. This includes operating promotional campaigns, measuring the performance of these campaigns, and sending information about our services, products, and features. We do not sell your data to any third parties. We also do not share your data to any third parties for advertising purposes.
  • Other. As otherwise permitted or required by applicable laws.

6. Disclosure of Personal Data to Recipients

Your personal data may be shared with the following recipients in the situations described below and as otherwise permitted or required by applicable laws:

  • Authorized employees or affiliates. When necessary, these authorized employees and affiliates will access the minimum amount of data required to provide customer support, operate our system and services, or investigate fraud or security issues.
  • Manufacturers and service/shipping providers of products/services ordered through the app (including photobooks, DVDs, and other products/services). We provide only the minimum amount of information necessary for them to carry out the specific services listed in our contract with them. Further, the information is only used for the exact purposes specified in the contract and all information is deleted after the required task has been completed.
  • Payment service providers. Payments for products/services ordered through the app are processed by secure and trusted payment processors, such as Apple, Google, Stripe, and GMO. We do not store payment information.
  • Infrastructure vendors and other service providers. We store all data on servers provided by secure infrastructure services. We also provide data to service providers who support our business, such as by analyzing how our app is used, providing customer service, conducting surveys, measuring promotional campaigns, and/or sending emails and push notifications to users, for the purpose of processing the data described in the above.
  • Law enforcement bodies. In response to legal requests, we will share the minimum amount of data necessary with law enforcement bodies.
  • Other users invited to your album by you or your partner. The only information accessible by other album members is information that you have provided when using the app.

In order to process personal data as described in “5. Purpose and Legal Basis of Processing Personal Data” above, we retain third-party service providers including the following:

  • Amazon Web Services, Google Cloud Platform (to store data, provide our service, etc.)
  • Google Firebase (for analytics, to send push notifications, etc.)
  • Apple App Store, Google Play Store, Stripe, GMO-PG (to process and confirm payments)
  • Zendesk (to provide customer support)
  • AppsFlyer (for marketing analytics)
  • Meta, X (formerly Twitter) (for advertising and analytics)
  • NewRelic (to monitor our service)
  • SendGrid (to send emails)
  • SurveyMonkey (to conduct user surveys)

In all cases, we apply strict measures to keep your data safe and your privacy protected. We share your personal data only for the purposes described in “5. Purpose and Legal Basis of Processing Personal Data” above and in accordance with applicable laws. We do not sell your personal data to any third parties, even in the form of anonymized statistical data.

7. Cross-Border Transfer of Personal Data

Whenever we transfer, store, or process your personal data, we take reasonable steps to safeguard the privacy of your data. When using or disclosing personal data transferred from your jurisdiction, we take the measures required by applicable data protection laws. For further details, please refer to the country-specific section below that is applicable to you.

8. Storage Limit of Personal Data

We retain your personal data only to the extent and for the period of time (which shall not exceed any of the periods listed below) necessary to achieve the purposes for which the personal information is collected, except when required by law to retain it for a longer period of time. In that case, we retain your data for the period required by law.

  • We retain your personal data until we receive a request from you to delete your account.
  • Photos and videos deleted from the app are removed from our servers automatically within 30 days.
  • Your personal data will be deleted from our servers within 30 days of receiving a request to delete your account.

9. Information on the Use of Cookies and Similar Technologies

We utilize cookies and similar technologies within the app in order to collect certain information, including the following:

  • Tracking IDs. Tracking IDs are used by various third-party service providers to associate multiple sessions (and any activity within those sessions) with a unique ID. Your device sends this unique ID with related engagement data, allowing third-party service providers to attribute all relevant activities to one user.
  • Cookies. Cookies are small text files stored on your device by your web browser. We use first-party cookies and we allow our third-party service providers to use cookies for their services. These cookies store your login details, preferences, or other information in order to provide a more efficient and personalized experience. You can learn more about cookies here.
  • IP addresses. We and our third-party service providers collect IP addresses in services relating to the app.

We use the following first-party cookies based on your consent or without your consent only where permitted by applicable laws.

CookieExpiration Time
web_session
To keep you logged in while using the FamilyAlbum Premium Computer Upload Site
10 minutes from last access
invitation
To connect you to the right album after clicking an invitation link
14 days from last access
follower_access_token
To keep you logged in while using the browser version of the app
14 days from last access

We may change the expiration time frames listed above in order to optimize the app’s usability.

It is possible to disable cookies and other tracking IDs on your device. To learn more, visit the appropriate link below:

10. Your Rights

We acknowledge that, depending on where you are located, you may have certain rights, such as the right to access and correct your personal data, discontinue our usage of your personal data, and other rights stipulated in each applicable jurisdictional law. To exercise any of these rights, please contact us using the information provided in either the country-specific section applicable to you or “16. Contact” below. You also have the right to lodge a complaint with a data protection authority in the jurisdiction where you reside, where you work, or where the alleged infringement of your rights took place. We will comply with any such request in full accordance with the applicable laws and regulations.

11. Required Personal Data

The following personal data is required to use the app:

  • For users who are creating an album: Your nickname, the child’s nickname, and your relationship to the child
  • For users who are invited to an album created by another user: Your nickname and your relationship to the child

Please note that you cannot use the app if we cannot obtain the personal data listed above.

12. Privacy of Children

We do not knowingly collect or solicit information from anyone under the age of 13 without parental consent. The app is not directed at children under the age of 13 who register themselves without parental consent, and we do not knowingly allow such persons to register. In the event that we learn that we have collected personal data from a child under age 13 without parental consent, we will delete that information as quickly as possible. If you believe that we might have obtained any information from a child under 13 without parental consent, please contact us.

13. California Privacy Laws

The California Consumer Privacy Act (“CCPA”) requires us to provide additional privacy-related information to California residents. If you are a California resident, please see this section.

For the purpose of this section, “personal information” refers to information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. To the extent this section applies to you, the provisions of this section prevail over any conflicting provisions in other sections of this Privacy Policy.

  1. CCPA Disclosures
    Section 4 lists personal information that we may collect and have collected within the preceding 12 months from you and the categories of sources from which we may collect, and have collected within the preceding 12 months, your personal information. Such personal information is classified into the following categories of personal information as set forth in the CCPA.
    • Identifiers, including your nickname, email address, payment information (including credit card details and shipping information), the child’s nickname, and IP address;
    • Other personal information, including relationship to the child and tag information on photographs and video clips;
    • Characteristics of protected classifications, including the child’s age and birthdates;
    • Commercial information, including usage history of the app, purchase information/history from Apple, Google, and other payment platforms for products and services ordered through the app;
    • Audio, electric, visual and similar information, including photographs and video clips you upload to our website;
    • Internet or other electronic network activity information, including your device information (such as operating system/version, hardware model, browser type/version), FamilyAlbum login information, usage log for the app, device IDs (such as Apple IDFA or Google AAID), cookies and similar technologies, information about ad clicks and app installs from marketing platforms, and FamilyAlbum usage activity from analytics platforms;
    • Inference, including results of automatic suggestions for creating and purchasing photobooks and other products and/or services; and
    • Sensitive personal information, including perceptual hashes of photographs and video clips, feature vectors of users’ faces, the estimated gender and age of each user’s face, results of classifications of facial images of each user (used for album function for each user).
    Section 5 lists the business or commercial purposes for which we may collect, use or disclose, and have collected, used, or disclosed within the preceding 12 months, your personal information.

    We do not sell, and in the preceding 12 months we have not sold, any of your personal information for monetary or other valuable consideration, nor do we share, and in the preceding 12 months we have not shared, any of your personal information for "cross context behavioral advertising purposes", including personal information of minors under the age of 16 years.

    We retain each category of your personal information as described in Section 8.

    The following list describes: (i) the categories of personal information that we have disclosed for our business purposes within the preceding 12 months; and (ii) the categories of third parties to whom we have disclosed such personal information for our business purposes within the preceding 12 months.
    • Identifiers
      • - Authorized employees or affiliates
      • - Manufacturers and service/shipping providers of products/services ordered through the app (including photobooks, DVDs, and other products/services)
      • - Payment service providers
      • - Infrastructure vendors and other service providers
      • - Law enforcement bodies
      • - Other users invited to your album by you or your partner
    • Other personal information
      • - Authorized employees or affiliates
      • - Manufacturers and service/shipping providers of products/services ordered through the app (including photobooks, DVDs, and other products/services)
      • - Infrastructure vendors and other service providers
      • - Law enforcement bodies
      • - Other users invited to your album by you or your partner
    • Characteristics of protected classifications
      • - Authorized employees or affiliates
      • - Manufacturers and service/shipping providers of products/services ordered through the app (including photobooks, DVDs, and other products/services)
      • - Infrastructure vendors and other service providers
      • - Law enforcement bodies
      • - Other users invited to your album by you or your partner
    • Commercial information
      • - Authorized employees or affiliates
      • - Manufacturers and service/shipping providers of products/services ordered through the app (including photobooks, DVDs, and other products/services)
      • - Infrastructure vendors and other service providers
      • - Law enforcement bodies
    • Audio, electric, visual and similar information
      • - Authorized employees or affiliates
      • - Manufacturers and service/shipping providers of products/services ordered through the app (including photobooks, DVDs, and other products/services)
      • - Infrastructure vendors and other service providers
      • - Law enforcement bodies
      • - Other users invited to your album by you or your partner
    • Internet or other electronic network activity information
      • - Authorized employees or affiliates
      • - Infrastructure vendors and other service providers
      • - Law enforcement bodies
    • Inference
      • - Authorized employees or affiliates
      • - Manufacturers and service/shipping providers of products/services ordered through the app (including photobooks, DVDs, and other products/services)
      • - Infrastructure vendors and other service providers
      • - Law enforcement bodies
      • - Other users invited to your album by you or your partner
    • Sensitive personal information
      • - Authorized employees or affiliates
      • - Manufacturers and service/shipping providers of products/services ordered through the app (including photobooks, DVDs, and other products/services)
      • - Infrastructure vendors and other service providers
      • - Law enforcement bodies
      • - Other users invited to your album by you or your partner
  2. Rights of California Residents
    Under the CCPA, you are entitled to the following rights:
    • Right to know. You have the right to request what personal information we have collected, used, and disclosed about you within the preceding 12 months. You may only make a request for access twice within a 12-month period.
    • Right to delete.You have the right to request the deletion of your personal information that we collect or maintain, subject to certain exceptions.
    • Right to correct.You have the right to request the correction of inaccurate personal information that we collect or maintain about you.

    To exercise your right to know, delete, or correct your personal information, you may submit a request via email at support@family-album.com

    For your requests, you must provide us with sufficient information that allows us to reasonably verify you are the person about whom we collected the personal information and describe your request with sufficient detail to allow us to properly evaluate and respond to it. If we are not able to verify your identity for your requests to know, delete, or correct, with the information provided, we may ask you for additional pieces of information.

    Only you, or a person that you authorize to act on your behalf, may make a request related to your personal information. If you are an authorized agent making a request on behalf of another individual, you must provide us with signed documentation that you are authorized to act on behalf of that individual.

    Additionally, you have the right to not to receive discriminatory treatment if and when you exercise your rights conferred by applicable law.

    Please note, we do not process sensitive personal information for the purposes that, under applicable law, require us to support the right to limit the use or disclosure of sensitive personal information.
  3. California Do Not Track
    Cal. Bus. & Prof. Code § 22575(b) provides that California residents are entitled to know how we respond to “Do Not Track” browser settings. We do not currently take actions to respond to Do Not Track signals because a uniform technological standard has not yet been developed.
  4. California Shine the Light
    Within the meaning of California’s “Shine the Light” law (Cal. Civ. Code § 1798.83), we do not disclose personal information to third parties for their own direct marketing purposes.

14. EU/UK Privacy Laws

In addition to the other sections of this Privacy Policy, this section applies if we process any personal data within the scope of, the EU General Data Protection Regulation and/or the UK General Data Protection Regulation (collectively, the “GDPR”). If you are an EU or UK user, please read this section.

  1. Purpose and Legal Basis of Processing Personal Data
    We use your personal data for the following purposes based on the following legal basis:
    • To provide you with our services. Our services include the app, customized content (such as 1s Movies, auto-generated photobooks, DVDs, and other content), payment processing for products and services purchased within the app, and improvements to the app (Performing contracts or legitimate interests).
    • To provide user support. This includes handling inquiries and complaints, troubleshooting and solving technical issues, and making necessary changes to our services (Legitimate interests).
    • For marketing analytics. This includes collecting and analyzing data to research usage of the app (Consent or legitimate interests).
    • To protect against cyberattacks. This includes maintaining the privacy of our users and investigating and deterring unauthorized or illegal activity (Legitimate interests).
    • For marketing. This includes operating promotional campaigns, measuring the performance of these campaigns, and sending information about our services, products, and features. (Consent or legitimate interests).
    • Other. As otherwise permitted or required by applicable laws. (Performing legal obligations or legitimate interests).
  2. [When we process special categories of personal data; in particular, biometric data for the purpose of uniquely identifying a natural person, we will obtain your explicit consent as the legal basis for processing this data.]

    When we process your personal data based on your consent, you may withdraw your consent at any time by contacting us using the information provided in “d. EU/UK Representative” or “16. Contact” below. The withdrawal of your consent shall not affect the lawfulness of processing performed based on your consent before its withdrawal.

  3. Cross-border Transfer of Personal Data
    Whenever we transfer, store, or process your personal data, we take reasonable steps to safeguard the privacy of your data. When using or disclosing personal data transferred from the European Economic Area and/or the UK, we adhere to the standard contractual clauses approved by the European Commission and/or the Government of the UK, adopt other means under European Union law and/or UK law to ensure adequate safeguards, or obtain your consent. You can obtain more details about the protection given to your personal data when it is transferred outside the EEA and/or the UK (including a copy of the standard contractual clauses which we have entered into with recipients of your personal data) by contacting us using the information provided in “d. EU/UK Representative” or “16. Contact” below.
  4. Your Rights
    Under the GDPR, you have the following rights:
    • The right to obtain information regarding the processing of your personal data and access to the personal data which we hold about you.
    • The right to request that we rectify your personal data if it is inaccurate or incomplete.
    • The right to request that we erase your personal data in certain circumstances. This may include (but is not limited to) circumstances in which:
      • - it is no longer necessary for us to retain your personal data for the purposes for which we collected it;
      • - we are only entitled to process your personal data with your consent, and you withdraw your consent; or
      • - you object to our processing of your personal data for our legitimate interests, and our legitimate interests do not override your own interests, rights and freedoms.
    • The right to request that we restrict our processing of your personal data in certain circumstances. This may include (but is not limited to) circumstances in which:
      • - you dispute the accuracy of your personal data (but only for the period of time necessary for us to verify its accuracy);
      • - we no longer need to use the personal data except for the establishment, exercise or defence of legal claims; or
      • - you object to our processing your personal data for our legitimate interests (but only for the period of time necessary for us to assess whether our legitimate interests override your own interests, rights and freedoms).
    • The right to object to us about our processing of your personal data.
    • The right to receive any personal data which we process about you on the basis of your consent or on a contract (as opposed to any other legal ground) and where the processing is carried out by automated means in a structured, commonly used and machine-readable format and/or request that we transmit that data to a recipient where this is technically feasible. Please note that this right only applies to personal data which you have provided to us.
    To exercise any of these rights, please contact us using the information provided in “d. EU/UK Representative” or “16. Contact” below.
  5. EU/UK Representative
    You can contact our EU/UK representative using the contact information below.
    • EU representative: DP-Dock GmbH (Address: Ballindamm 39, 20095, Hamburg, Germany; Email: mixi@gdpr-rep.com)
    • UK representative: DP Data Protection Services UK Ltd. (Address:16 Great Queen Street, Covent Garden, London, WC2B 5AH, UK; Email: mixi@gdpr-rep.com)

15. Changes to This Privacy Policy

We may occasionally update this Privacy Policy in order to better meet our obligations under data protection laws. Significant changes may be accompanied by a notification and/or request for consent, as required by law.

16. Contact

Should you have any questions or concerns regarding this Privacy Policy, please do not hesitate to contact us.

FamilyAlbum at MIXI, Inc.
Shibuya Scramble Square 36F, 2-24-12 Shibuya, Shibuya-ku, Tokyo 150-6136, Japan
support@family-album.com

You can also contact us by tapping “Support” in the Settings tab of the FamilyAlbum app.

You can contact our Data Protection Officer (DPO) by email at dpo@mixi.co.jp.

Start your FREE album with FamilyAlbum now!