News
Does a Digital Scavenger Hunt Need Personal Data? Why Petanco Doesn’t Pursue Privacy Certifications
Petanco does not hold ISO/IEC 27001, a SOC 2 report, Japan’s PrivacyMark, or any other external privacy or security certification. This isn’t something we’ve put off. It’s a deliberate policy, and this article is our official explanation of why. The short version: Petanco protects personal data not by proving it with a certificate, but by designing the service so that it doesn’t hold that data in the first place.
What you’ll learn in this article
- Why Petanco doesn’t hold external certifications such as ISO/IEC 27001 or SOC 2
- Why “certified” and “won’t leak” are two different things
- How the cost of getting and keeping a certification ends up in the price you pay
- Exactly which personal data Petanco holds, and which it never collects
- What to do when you genuinely need shipping details (Google Sheets integration)
- A ready-made statement you can paste into a security review or procurement file
The bottom line: not holding data comes before protecting it
Broadly speaking, there are two ways to approach personal data protection.
| Approach | Mindset | When a breach happens |
|---|---|---|
| Collect it, then guard it closely | Collect whatever might be useful, then protect it with processes, policies and audits | Once the defenses are breached, everything you hold is exposed |
| Don’t collect it in the first place | Never collect information the service doesn’t need in order to work | Even if there’s a breach, the sensitive information simply isn’t there |
Petanco takes the second approach. The reason is simple: data you don’t have can’t leak. It’s the one safeguard that can never be broken.
And to join a digital scavenger hunt, participants don’t actually need to hand over their name, home address or phone number. The moment you hold data you don’t need, you take on a duty to protect it and a risk of leaking it. Petanco is designed so that duty and that risk never arise.
A certification doesn’t guarantee your data won’t leak
Certifications and attestations such as ISO/IEC 27001 and SOC 2 (and Japan’s PrivacyMark) check whether an organization’s structure, policies and operations meet a defined standard at the time of the audit. Meet the criteria, go through the audit, pay the fees, and you get the certificate.
In other words, what a certification proves is that “a process aligned with the standard was in place,” not that “a data breach won’t happen.” Organizations that hold these certifications, including large companies and public bodies, have still suffered major breaches, again and again. The fact that a certification can’t prevent incidents has, unfortunately, already been proven many times over.
To be clear, Petanco isn’t rejecting these frameworks. They’re a genuinely useful prompt for an organization to get its house in order. The problem is that using “certified or not” as a stand-in for “safe or not” easily leads to the wrong call.
A certification tells you how data is protected, not how much of it is held. Two companies with the same certification can be in completely different positions after a breach: one storing the names and home addresses of 100,000 people, the other holding only email addresses. What you should look at isn’t the badge. It’s what data you’re handing over, and how much of it.
There’s one more point that rarely gets said out loud: the cost of getting and keeping a certification ends up in the price of the service. Beyond audit and registration fees, it means drafting policies, training staff, running internal audits, preparing for periodic follow-up and renewal audits, and often hiring consultants. These costs keep coming long after the certificate is issued. They get built into prices, and in the end the customer pays for them. If Petanco pursued a certification, we would have no choice but to pass that cost on in our pricing.
We won’t raise your price for something that doesn’t guarantee protection against leaks. Instead of spending that money, Petanco chooses to reduce the data it holds in the first place. The less there is to protect, the less it costs to protect it. Not having certification costs built into our prices is one of the reasons Petanco can keep its pricing low (every price is published on Petanco pricing).
Petanco’s answer: never take the data that would hurt if it leaked
Petanco builds this idea into the service as three principles.
Principle 1: Don’t collect
- With the “No Login” type, participants join with no app install, no sign-up and no personal information at all
- Even with “Easy Login”, the only thing we hold is an email address. Names, home addresses and phone numbers are never collected
- Credit card details are handled by Stripe, a major payment provider, and are never stored by Petanco
- Age group and gender are asked only when the organizer turns on the Age Group / Gender survey presets (they’re off by default). Usernames and area of residence are never collected. In September 2026 we retired the participant My Page feature, cutting the data we hold even further
Principle 2: Don’t show
Email addresses registered through Easy Login can’t be viewed even by the organizer. Age group and gender collected with survey presets are visible to organizers only as aggregated statistics, and they don’t appear in the Applicant Data list (on screen or in CSV). Because participants’ contact details never reach the organizer, the organizer never has to manage a contact list in the first place.
Principle 3: Delete
Participant data (stamps, survey responses, prize entry information and so on) is automatically deleted from our servers 30 days after the campaign’s publish period ends (for campaigns created on or after October 1, 2026). If you end a campaign before its publish period is over, the 30 days still count from the end of the publish period. Extending the draft retention period doesn’t stop this deletion, because the extension only keeps your campaign settings. Aggregated figures that can’t identify anyone, such as check-in counts, aren’t deleted. Organizer account information is also deleted after a period set by us (90 days as standard) following account deletion. Even if you do nothing, the data doesn’t linger.
The complete list of what is and isn’t stored is published under Handling Personal Information on the Features page.
This is also risk design for you, the organizer
Holding participants’ personal data means taking on responsibility for managing it. The contact list stays with you after the event, along with the duty to store it, dispose of it and answer inquiries about it. If it ever leaks, it’s the organizer, not the tool vendor, who faces the fallout.
Petanco keeps personal data out of the organizer’s hands partly so that you don’t have to carry that risk. When the event ends, there’s no contact list to protect, because there never was one.
You might wonder whether you need to collect data to measure results. Movement between checkpoints, stamp collection rates and age and gender trends can all be analyzed with aggregated data that doesn’t identify individuals. Personally identifiable information is rarely needed for analysis.
When you really need shipping details: the Linked Application Form
Of course, there are times when you genuinely need names and addresses, for example to ship prizes to winners. For those cases, use the Linked Application Form as the prize’s application method.
The Linked Application Form is an entry form that includes shipping details. Whatever participants enter is written directly to your own Google Sheet and is not stored by Petanco (it doesn’t appear in the Applicant Data list in the admin dashboard either).
| Item | Details |
|---|---|
| Always collected | Name, email address |
| Optional fields | Phone number, plus a shipping address shown as one set: Address line 1, Building name, City, State/Province, Postal code (campaigns whose default language is English use the US address format; every field shown is required except Building name) |
| Where entries go | The Google Sheet you specify (appended to a dedicated entries tab) |
| Stored by Petanco | No |
| Requirement to publish | A Privacy Policy URL must be set for the campaign |
Setup is a single setting for the whole campaign: register the URL of the spreadsheet you want entries written to, then add the sharing address shown on screen as an editor. A connection test runs when you save, so a campaign can never go live with a sheet Petanco can’t write to.
We require a Privacy Policy URL before this feature can be published so that the basis for collecting participants’ shipping details is made clear to them. Until the URL is set, no entries are accepted.
The key point: you, the organizer, own the personal data collected, and managing it is your responsibility. Petanco can’t unshare the spreadsheet from its side either, so the data stays entirely under your control. “If you need personal data, keep it yourself instead of handing it to us to hold.” That is Petanco’s position.
For the setup steps, see our guide to the Linked Application Form.
What Petanco discloses instead of a badge
In place of certification, Petanco’s policy is to disclose information in a form you can verify.
- Security white paper (Japanese only): covers our location and governing law, encryption, data backup, return and deletion, development practices, incident handling, and our status against the Cloud Service Level Checklist published by Japan’s Ministry of Economy, Trade and Industry (METI). Available on request
- List of personal data we do and don’t store: published in detail, including who it concerns, what it is and how it’s handled
- Privacy Policy: sets out how we use personal data and that we don’t provide it to third parties without prior consent
- FAQ: Handling Personal Information: the questions reviewers ask most often, answered in Q&A form
From a reviewer’s point of view, a page that spells out what’s held, what isn’t and when it’s deleted should be far easier to verify in practice than a single badge. That verifiability is what Petanco wants to offer.
What we’ll be upfront about
If your procurement rules require a specific certification or attestation, such as ISO/IEC 27001 or a SOC 2 report, Petanco can’t meet that requirement. We’d rather say so plainly.
But if the purpose behind the requirement is “participants’ personal data must not leak,” then not holding the data in the first place is a more direct answer to that goal. When you raise this internally, please share this article together with the list of stored data and the security white paper (in Japanese).
For security reviewers and procurement teams
You’re welcome to quote the statement below as-is in a security review, vendor assessment or procurement document.
Petanco (provided by GOWAS LLC) does not hold external certifications or attestations such as ISO/IEC 27001, SOC 2 or Japan’s PrivacyMark. This is a deliberate policy: rather than demonstrating its controls through certification, Petanco protects personal information by design, limiting the personal information it collects to the minimum necessary.
For participants, Petanco collects only the email address used for Easy Login, age group and gender answers when the organizer enables the corresponding survey presets, and the email address entered in a prize Application Form. It does not collect names, home addresses, phone numbers or area of residence. With the “No Login” type, no personal information is collected at all.
Organizers cannot view the email addresses participants register through Easy Login. Age group and gender answers are used only for aggregated statistics and do not appear in the Applicant Data list. Credit card information is handled by Stripe and is not stored by Petanco.
Participant data is automatically deleted from Petanco’s servers 30 days after the end of the campaign’s publish period (the publish period purchased by the organizer), for campaigns created on or after October 1, 2026. Extending a campaign’s draft retention period does not stop this deletion.
Where shipping details (name, address, etc.) are needed, the organizer uses the “Linked Application Form,” which writes entries directly to a Google Sheet specified by the organizer. These entries are not stored by Petanco, and the organizer is responsible for managing them. Publishing this feature requires a Privacy Policy URL to be set.
Petanco’s security measures are documented in a security white paper (in Japanese) based on the Cloud Service Level Checklist of Japan’s Ministry of Economy, Trade and Industry, available on request.
Frequently Asked Questions
Does Petanco hold ISO/IEC 27001, SOC 2 or a similar certification?
No. Rather than proving our controls through certification, we limit the personal information we collect to the minimum necessary, which shrinks the impact of any breach itself. Our security measures are documented in a security white paper (in Japanese) based on the Cloud Service Level Checklist of Japan’s Ministry of Economy, Trade and Industry.
Our security review won’t pass without a certification. What can we do?
If a certification is a hard requirement, Petanco can’t meet it. If the intent of the requirement is that participants’ personal data must not leak, please submit the list of stored personal data and the security white paper, and quote the statement in the “For security reviewers and procurement teams” section of this article.
Do participants have to enter personal information?
No. With the “No Login” type, participants join with no app install, no sign-up and no personal information. Even with “Easy Login,” the only thing we hold is an email address, and names, home addresses and phone numbers are never collected. Age group and gender are asked only when the organizer turns on the survey presets, which are off by default.
Can organizers see participants’ email addresses?
Email addresses registered through Easy Login can’t be viewed by organizers. For age group and gender collected with survey presets, organizers see aggregated statistics only. Email addresses entered in a prize Application Form are visible to organizers so they can contact winners, but Petanco never uses those addresses.
We want to ship prizes to winners. How do we collect their addresses?
Use the Linked Application Form. In addition to name and email address, you can collect a phone number and a shipping address (Address line 1, Building name, City, State/Province, Postal code). Entries are written directly to your own Google Sheet and are not stored by Petanco. You are responsible for managing the personal information you collect this way. To publish this feature, you need to set a Privacy Policy URL for the campaign.
When is the personal information you collect deleted?
Participant data (stamps, survey responses, prize entry information, etc.) is automatically deleted 30 days after the campaign’s publish period ends (for campaigns created on or after October 1, 2026). Even if you end the campaign before the publish period is over, the 30 days count from the end of the publish period. If you extend the publish period by purchasing additional days, the 30 days count from the end of the extended period. Extending the draft retention period does not stop this deletion, so please download any data you need within 30 days after the publish period ends. Campaign settings remain until the draft retention period (30 days, extendable with one click) passes. Information written to your Google Sheet through the Linked Application Form is under your control and isn’t subject to this deletion. Organizer account information is deleted after a period set by us (90 days as standard) following account deletion.
Could the personal information you collect be used for other purposes?
No. We do not provide personal information to third parties without prior consent, except where permitted or required by law. We may use statistics processed so that individuals can’t be identified to improve the service or in case studies.
Summary: don’t hold what would hurt if it leaked
- Petanco holds no external certification such as ISO/IEC 27001 or SOC 2, because a certification proves that controls met a standard, not that data won’t leak
- The cost of getting and keeping a certification ends up in the price of the service. Petanco doesn’t pass that cost on to you; it keeps data safe by holding less of it
- Instead, Petanco is designed to handle only personal information whose exposure would have limited impact. Data you don’t have can’t leak
- From participants, Petanco collects at most an email address and age group and gender answers. Names, home addresses, phone numbers and area of residence are never collected, and organizers can’t see participants’ Easy Login email addresses
- Participant data is automatically deleted 30 days after the publish period ends (extending the draft retention period doesn’t stop it)
- When shipping details are needed, the Linked Application Form writes them straight to your own Google Sheet (not stored by Petanco, and managed under your responsibility)
- Instead of a badge, Petanco publishes a security white paper and a list of the data it stores
A system that doesn’t hold anything that needs protecting is more reliable, and lighter for everyone, than a system that guards personal data heavily. That’s what Petanco believes.
→ Build a digital scavenger hunt for free with Petanco (creating an account, building and testing are all free)
- Handling Personal Information (list of stored data)
- Guide to the Linked Application Form
- Security white paper (Japanese)
- Privacy Policy
- Petanco pricing
- What is a digital scavenger hunt?
Last updated: September 2026
Author: Petanco Staff