Back to Holding Home
Institutional Governance

Privacy Policy

Last Updated: March 2026 • Effective Immediately across all Twiros Platforms

01. Scope & Organization

Twiros operates as an independent technology holding collective. This Privacy Policy governs all software platforms, vertical micro-SaaS applications, developer tools, and centralized infrastructure operated under the Twiros corporate umbrella (collectively, "Portfolio Ventures").

When you interact with any Twiros subsidiary or software ecosystem (including XoomCare, Storecraft Studio, Nihongo Renshuu, and Kostokom Commerce), your data is safeguarded under the standardized privacy architectures set forth in this document.

02. Information Collection & Purpose

We collect only the minimal data required to deliver high-performance software services:

  • Account & Identity Data: Name, work email address, and authenticated identity credentials when you provision a tenancy or enterprise account.
  • Operational Telemetry: Aggregated system performance, API latency, error diagnostics, and feature utilization telemetry to maintain 99.99% system availability.
  • Transactional Data: Order tokens, transaction identifiers, and currency exchange records required for accounting, tax compliance, and automated receipt dispatch.

03. Payment Processing & Financial Security

Twiros maintains a zero-retention policy for sensitive payment credentials. We do not store raw credit card numbers, CVVs, or mobile financial PINs on any server.

All payment transactions are tokenized and processed through PCI-DSS Level 1 compliant international gateways (such as Lemon Squeezy and Stripe) or bank-regulated local payment routers. All checkout endpoints enforce strict 256-bit TLS/SSL transport encryption.

04. Zero Third-Party Monetization

We do not sell, rent, or lease personal or enterprise data to advertising brokers, data syndicates, or commercial brokers. Our business model is strictly derived from high-value software subscriptions and specialized enterprise licensing.

05. Data Sovereignty & User Rights

You retain complete ownership over your proprietary business data. Depending on your jurisdiction (including GDPR, CCPA, and relevant national frameworks), you have the right to request data export in standard JSON/CSV formats, rectification of inaccurate records, or complete account purge ("Right to be Forgotten").

Compliance & DPO Inquiries

To exercise your rights or request an enterprise Data Processing Agreement (DPA), contact our governance desk directly at inquiries@twiros.com. All formal compliance requests receive verified confirmation within 48 business hours.