Third-Party Services

Full transparency on every external service we use and why.

Effective: March 27, 2026

Stripe — Payment processing

Handles all payment transactions on the platform.

  • Data shared: payment card details, billing address, transaction amounts
  • Stripe is both data processor and controller (for fraud prevention)
  • Your full card number is never stored on our servers
  • PCI DSS compliant

Authentication

Handles account creation and single sign-on.

  • Data shared: email, name, authentication tokens
  • Used for account management and SSO
  • Neon Auth for identity management

Google reCAPTCHA — Bot protection

Protects the platform from automated abuse.

  • Data collected: IP address, browser characteristics, mouse movement patterns
  • Used during login, signup, and sensitive actions
  • Google acts as data controller for this data

Klipy — GIF content

Powers GIF search and embedding in communities.

  • Data shared: search queries
  • Highest content safety filter applied
  • No personal data transmitted

Vercel & Neon — Infrastructure

Our hosting and database providers.

  • Vercel: application hosting, edge network, serverless functions
  • Neon: PostgreSQL database with connection pooling
  • All data encrypted in transit and at rest
  • Both providers are SOC 2 compliant

Your rights

You can exercise your data rights directly with third-party controllers (like Stripe or Google) or through us for data we process on their behalf. Contact privacy@tokyofishmarket.com for assistance.

Contact

privacy@tokyofishmarket.com