TERMS OF USE SHIMANO SERVICE PORTAL

Last Updated: January 2026

Acceptance of Terms. The use of SHIMANO Service Portal is subject to the following Terms of Use. Shimano reserves the right to modify, replace or update these Terms of Use at any time for reasonable grounds with or without notice. By continuing to use the Portal, User agrees to the latest version of the Terms of Use and to be bound by them.

IF YOU DO NOT AGREE TO THESE TERMS IN THEIR ENTIRETY YOU SHOULD NOT ACCESS

OR USE THE PORTAL OR ANY PART THEREOF.

Shimano Portal Data Protection Notice for Users on the USA and Canada Market

Introduction and Scope

Thank you for taking the time to review Shimano's Data Privacy Notice, applicable to User of the Shimano Portal. Shimano supplies high quality products and components for bike and fishing tackle. As manufacturer and global sales organization, we like to provide services to our business to business customers via the Shimano Service Portal. This Portal provides information on products, order information and warranty cases, accessible at all times for our Dealers and Distributors. This Data Protection Notice (the "Notice") describes the data processing activities in connection with the use of the Portal website offered by Shimano. Next to this specific Data Protection Notice for the online Portal Shimano has a general Privacy Policy which is published online  click here (https://www.shimano.com/en/privacypolicy.html)  that is applicable to data we collect from website visitors and offline sales activities. This notice includes the following information:

The categories of personal data we process;

The purposes for processing personal data;

How you can exercise your rights under applicable laws;

The categories of personal data we share with third parties; and

The categories of third parties with whom we share personal data.

For optimal readability, this document is laid out as follows:

  • Introduction and scope
  • Who we are
  • What the Portal is designed for
  • Categories of data subjects and Personal data that the Portal processes
  • Why are we entitled to process this data (legal basis)
  • No automated decision-making
  • How long do we retain your personal data
  • How do we secure your personal data
  • With whom do we share your data
  • What are your rights to access, modify, correct or delete data
  • Data-Protection officer
  • Supervision
  • Terms of Use
  • Disclaimer
  • Copyright
  • Cookie and other tracking tools
  • Privacy Policy version 1.0
  • Attachment list of Distributors per Country

This document uses the definitions as set out in the Terms of Use that are applicable to the Portal.

Who we are

Shimano is the worldwide renowned supplier of bike components and fishing tackle. Manufacturer of Shimano Products is:

Shimano Inc. ("SIC", "Shimano")

 

3-77 Oimatsu-cho, Sakai-ku, Sakai City
Osaka 590-8577, Japan

 

For all sales activities on USA territory the USA Headquarters is responsible: SHIMANO NORTH AMERICA HOLDING, INC. dba SHIMANO NORTH AMERICA BICYCLE, INC.

("SNAH")

One Holland, Irvine, California 92618 

 

For all sales activities on Canada territory; the Canada Headquarters is responsible:

SHIMANO CANADA LTD., (“SCL”)

427 Pido Road, Peterborough, Ontario K9J 6X7

 

Depending on your country of residence you will do business with a local Shimano Sales Office or with one of the contracted Shimano Distributors that operate under their own name.

 

SIC and SNAH/SCL together are the entities responsible for the processing of your Personal Data in relation to the Portal as joint controllers (referred to hereinafter as "we", "our" or "us").

 

Next to that the Portal facilitates a closed environment for Distributors. Each Distributor is a joint controller with SNAH/SCL for their own Distributor Portal environment.

 

You can contact each Shimano joint controller by postal mail at the addresses above. Distributors contact details are published in the attached list.

What the Portal is designed for

The Portal operates on the basis of the business profile as administrated in Shimano CRM system. Each Dealer respectively Distributor appoints Users (with a minimum of one main User per Dealer /Distributor). The Portal is used to communicate regarding Shimano Products, regular case and warranty handling. The Portal offers services and featuresto both Dealers and Distributors.

 

To limit the access to Portal services; only to accredited Dealers and contracted Distributors will be invited to create a User Account. To monitor correct access and usage of the Portal each User will be required to file personal data as well as business data upon creation of the account. A User Account grants continuous secure access to the Portal and enable User to act on behalf of the Dealer or Distributor that User is working for. Terms of Use are applicable to every User Account.

Future

Shimano launched the Portal in 2026 with Product Information and warranty case handling. Future development of the Portal may include communication on business transactions, operations, sales rep visits, logistics and financial handling of orders, as well as direct access to Shimano Order intake tools via Single Sign on, dealer locator tools and additional marketing purposes such as product launch events and online evaluations.
 

Also, the Portal is intended to be used to share product manuals, specified maintenance instructions for Shimano accredited Dealer, Distributors and Users. information on events, product launches and commercial activities.

Distributors’ Portal access

Distributors that have entered into a Distributor contract with Shimano have their own Dealer base. To provide warranty service to that Dealer base, each Distributor has its own segregated environment within the Portal. Dealers connected to Distributors are invited to this specific part of the Portal where Shimano has no direct access to. The Distributor will be responsible for maintaining the Dealer base in their own environment. Only to verify the reimbursement process, pseudonymized warranty case data will be shared with Shimano via the Portal of the Distributors Dealers. These Dealers have similar functionalities and news updates on the Portal, only their communication line is directly and only with the Distributor.

To be able to maintain the platform and continuously improve functionality of the platform Shimano will use anonymized data for the maintenance and future development of the Portal.

In case Shimano wants to perform an audit or evaluation on specific Dealer accounts, Users will be requested to sign up for these audits.

Categories of data subjects and Personal data that the Portal processes

The Portal processes Personal Data of the following categories of data subjects collectively referred to as "Users"):
 

  • Dealer information (if the dealer is a single person company)
  • Contact data of Dealer Users which can include both business owners as employees of dealers
  • Contact data of Distributor Users which include mainly employees of Distributors
     

As a User you provide personal data to Shimano, this data comprises:
 

  • Dealer Name*: being the legal entity name of the business
  • optionally Dealer alias for quick search reference
  • Dealer address and Ship to address*
  • Usernames of all Users that are connected to a Dealer
  • User Email address
  • Business Phone number
  • Bank account number for reimbursement purposes

 

*When a User is connected to Distributor instead of a Dealer Business name and address of the Distributor is collected.

 

When a Dealer is connected to a Distributor environment Shimano will process pseudonymized data, therefore only the following data will be visible to Shimano:
 

  • Distributor or Shimano Sales Officer that the dealer is connected to
  • Timezone
  • Preferred language (English by default)

 

When using our Portal we automatically collect Personal Data:When using our Portal we automatically collect Personal Data:

 

  • Dealer number will be provided by the system
  • Device information: IP address, unique device ID (such as Instance ID, IDFV, Firebase ID); and
  • internet activity information: such as IP address (or proxy server}, geolocation, language, browser type, operating system type and version, date and time stamps associated with your login as mentioned in the cookie and tracking tools below. Any User can choose to minimize tracking cookies via the browser settings;
  • Portal usage log information: Log (information about your interactions with the Portal, including access, error logs and crash recovery logs, date/time stamps and clickstream data)

 

The Portal does not intend to process any special categories or sensitive data. The Portal is designed as a business tool and therefore collects business information. No data of minors/juveniles is allowed in the Portal. All Users must be 18 years or older to use the Portal.

Why we are entitled to process this data (legal basis)

Shimano Portal processes personal data on the legal bases of contract in accordance with the applicable US and Canada and federal law including, without limitation, the  California Consumer Privacy Act (CCPA) California Privacy Rights Act (CPRA),Virginia Consumer Data Protection Act (VCDPA) and Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) as applicable.

 

When creating a User Account a party enters into a User Agreement. Only with a User Account Dealers have the option to enjoy our content and Services via the Portal. If a Dealer decides not to agree on the User Agreement, services will be provided via direct contact with the sales representatives and customer service of either the Shimano Sales Office or the Distributor.

 

Users can delete their User Account at any given moment in time via the account of the User that is the main Dealer Contact, as long as a minimum of one User will remain connected to a Dealer.

Quality improvement

Shimano may also process Personal Data for quality and Service improvement purposes, e.g., to detect, to revalidate User access on regular base and analyze problems in the Portal as well as in our products or Services, to carry out predictive maintenance and calculate the necessary product replacement timing, to introduce new products or service and test their compatibility. This data processing is allowed on the legal basis of legitimate interests to improve the quality of our products and services.

No Automated decision making

The Portal is not designed for automated decision making that impacts Users or Dealers. All requests, orders and warranties will be handled by people. If you have doubts about the outcome of a warranty request, please upload your comments under the case number for additional revision.

How Long do we retain your data

We will not process your Personal Data longer than necessary for the purpose for which it was originally collected unless applicable law requires a longer retention period. For specific retention periods by data category, please contact us as provided in this Notice Subject to statutory retention periods, we will delete your Personal Data:

  • 1 year after you have deleted your user account

How do we secure your data

We have implemented standard industry practices internally and with our service providers to maintain the security of Users Personal Data depending on its sensitivity and to avoid disclosure of such Personal Data unpermitted under this Notice. We do this by taking technical and organizational measures, which are periodically checked and adjusted. The IT people associated with Shimano and our service provider are constantly monitoring whether they can ensure better technical security by default. In the event of a data breach, we will notify affected individuals and relevant authorities as required by applicable laws

 

For example, Shimano uses a strict separation of our systems and databases. Download rights are set to a minimum. We also use encryption methods and secure connections and multi factor authentication.

Data in the Distributor environment is not accessible to people of SIC or Shimano Sales Offices. The Dealer account information and uploaded case information provided in warranty cases is called your input data. We save this input data in Distributors environment where dealer name and User contact details are only visible to the Distributor Users. For Shimano warranty case information is disclosed under a unique ID number. This is called pseudonymization of the Distributor Dealer data.

 

There is a division of roles within our business processes. We have made arrangements when and under what conditions access to the Dealer database is possible. The technical and organizational security measures are regularly reviewed, expanded and adapted. We document these measures in the internal Shimano impact assessment.

What can you do to contribute to the security of your personal data?

If you have the impression that your data is not properly secured or if there are indications of misuse, please report this immediately using the contact form on your User dashboard.

 

Your own behavior can prevent abuse. Do not forward emails you receive from the Portal, as they may contain personal data about you as the recipient. Always use a strong password of at least 10 characters and do not leave your account logged in unnecessarily. Never share your User account with other people. The Dealer User with the primary contact can create new Users for the Dealer access via the Portal.

With whom do we share your data?

Shimano does not sell your data to third parties.

 

Shimano uses third-party software, e.g., for the Portal, consumer webshops, sending newsletters, invoices etc. To this end, your data will be provided to third parties in as limited a manner as possible.

With all Service providers acting on our behalf we enter into a business contract. These service providers are legally and contractually required to respect and comply with applicable data protection legislation and this Data Privacy Notice.

Our service providers for the Portal include:

 

  • Salesforce, Nissey Marunouchi Garden Tower 1-1-3, Marunouchi, Chiyoda-ku, Tokyo 100-0005, Japan (data processor for Cloud service and user management)
  • Accenture Japan Ltd., Akasaka Intercity AIR (Reception: 8F) 1-8-1Akasaka, Minato-ku, Tokyo 107-8672, Japan (data processor; system maintenance provider) and Accenture Inc. (7th Floor, Robinsons Cybergate 1, Pioneer St., Mandaluyong City, Philippines) as sub-processor of Accenture Japan
  • KPMG Netherlands, Laan van Langerhuize 1, 1186 DS Amstelveen (data processor; system maintenance provider)

 

As a global company Shimano allows International data transfers from USA and Canada to Japan.

 

Data collected via the Portal of USA or Canada Users will be stored centrally on servers located in the USA or Canada and will be accessible for SNAH/SCL. The Portal will also be used for non USA or Canada User, whose data will be accessible by SIC. Overall logging data and general maintenance of the Portal will be executed from Japan. Accordingly, your Personal Data mainly device information, internet activity information and Portal Usage log information will be transferred to and disclosed to selected recipients located  in Japan which has been recognized by the USA and Canada as providing for an adequate level of data protection.

 

Data transfer to the sub-processor Accenture Inc. (Philippines) is covered by standard contractual clauses between Accenture Japan Ltd. and Accenture Inc. (Philippines). You can contact our data protection officer for instructions on how to obtain a copy of these.

 

Shimano may also provide data to third parties in order to comply with statutory obligations, such as recordkeeping requirements and filing tax returns. With companies that process data on our behalf, such as the email management software, our accountant, insurer and their local service providers, but also regional event organizers, we enter into an agreement and make arrangements for the security of your data. We process your data within the EU and in Japan.

 

All Dealers that have requested to be visible in the Global Shimano Dealer locator, will be published with their business contact details on Shimano websites.

 

Third-party links and websites.

 

Our Services can offer you the possibility of accessing third party content, such as Distributors websites, event apps and online services. Please note that we are not responsible for the data processing activities of these third parties. We encourage you to read the data protection notices of any third party website, app or online service you connect with.

 

Users

 

Shimano receives contact information from Dealers about their employees, to ensure that they can create a User Account. Dealers and Distributors are responsible for offboarding User Accounts whenever a person is no longer connected to the Dealer. For the handling of Order intake and Warranty cases Shimano registers the User that creates or changes the Order or Warranty request.

What are your rights to access, modify, correct or delete data?

You have the right to access, correct or delete your personal data. You also have the right to withdraw consent for data processing or to object to the processing of your personal data by Shimano. You have the right to data portability. You have the right to opt out of the sharing of your personal data.

As a User, it is possible at any time to view your input data on the profile page of your User Account.

 

If you wish to exercise your rights in any other way, you can request access, correction, deletion or data transfer via the contact form on the website or via email.

When you send us a request via email, Shimano is entitled to ask you some questions to verify your identity. We will respond to your request as quickly as possible, and certainly within four weeks.

Data-protection officer

Supervision

General Terms of Use

Disclaimer

On our Portal website you will find information about Shimano Products including manuals. We also provide general information on developments, product launches and events of Shimano and our Distributors. We provide you with commercial product videos and success stories from our Dealers Distributors and athletes that we sponsor. The general information on the Portal or public Shimano website is of a general nature and is not intended to replace the Product Manual or as personal advice. Before a User can execute Repairs and maintenance of Shimano Products the User should finish mandatory Shimano trainings to become a certified Shimano Dealers or Shimano Service provider. You may not hold Shimano liable for the consequences of using Shimano products in a different way as shown on the product manual or maintenance performed by non-accredited mechanics.

Copyright

Cookies and other tracking 4929-3981-6841.1 

Our Portal uses cookies as described below.

 

Functionally necessary 4929-3981-6841.1 

Functionally necessary cookies support the Portal to function properly. These cookies ensure that:

 

  • The information is stored whether you are currently logged in until you are logged out.
  • The information that you enter on the various pages is remembered so that you do not have to fill in all your details again;
  • Your browser settings are stored so that you can view our websites optimally on your screen;
  • It is possible to respond to messages on our websites and apps;
  • The websites and the apps are evenly loaded, so that they remain functional and accessible;
  • It is possible to detect abuse of or potential problems on our websites, apps and services, for example by registering a number of consecutive failed log-in attempts.

List of functionally necessary cookies Shimano can use on their websites and apps are:

COOKIE NAME Provider Expiry DESCRIPTION
_Secure-has-sid First party cookie Session Detects a user's login state in LWR Experience on the client side. Set during login to LWR Experience. Never set this cookie to HttpOnly
{Userld}_spring_KmMIAnyoneDraftArticleslist First party cookie 1 day In Salesforce Classic, used to configure layout properties for the Draft Articles view in Article Management.
{Userld}_spring_KmMIArchivedArticleslist First party cookie 1 day In Salesforce Classic, used to configure layout properties for 'Archived Articles' in Article Management.
{Userld}_spring_KmMIMyDraftArticleslist First party cookie 1 day In Salesforce Classic, used to configure layout properties for 'Draft Articles' assigned to 'Me' in Article Management.
{Userld}_spring_KmMIMyDraftTranslationslist First party cookie 1 Day In Salesforce Classic, used to configure layout properties for 'Draft Translations' in Article Management.
{Userld}_spring_KmMIPublishedArticleslist First party cookie 1Day In Salesforce Classic, used to configure layout properties for 'Published Articles' in Article Management.
{Userld}_spring_KmMIPublishedTranslationslist First party cookie 1Day In Salesforce Classic, used to configure layout properties for 'Published Translations' in Article Management.
_sid First party cookie Session Identifies a Live Agent session. Stores a unique pseudonymous ID for a specific browser session over chat service.
52609e00b7ee307e First party cookie Session Browser Fingerprint cookie. Used to detect security problems
79eb100099b9a8bf First party cookie Session Browser Fingerprint trigger cookie. Used to detect session security problems.
apex_EmailAddress First party cookie 1 Year Caches contact IDs associated with email addresses.
BAYEAX_BROWSER First party cookie Expired on Creation Identify a unique browser subscribed to CometD streaming channels.
Browser Id First party cookie 1 Year Used for security protections.
Browserld_sec First party cookie 1 Year Used for security protections.
clientSrc First party cookie Session Used for security protections.
communityld First party cookie Session Cookie set to tie the ideas to a specific Experience Cloud site.
CookieConsent First party cookie 1 Year Used to apply end-user cookie consent preferences. Stores a Boolean for whether user has consented to the cookie policy options offered by the site. Without this cookie, customers would not be able collect consent from their end users.
CookieConsentPolicy First party cookie 1 Year Used to apply end-user cookie consent preferences by our client-side utility.
cookieSettingVerified First party cookie Session Used to create a popup message telling users cookies are required
cordovaVersion First party cookie Session Used for internal diagnostics with mobile applications.
csssid First party cookie Session Used to establish a request context in the correct tenant org
csssid_Client First party cookie Session Enables user switching.
devOverrideCsrfToken First party cookie Session CSRF Token.
disco First party cookie Session Tracks the last user login and active session bypassing login (For example, OAuth immediate flow).
FedAuth First party cookie Session For the SharePoint connector, used to authenticate the top-level site in SharePoint.
force-proxy-stream First party cookie 3 Hours Ensures that client requests hit the same proxy hosts and are more likely to retrieve content from cache.
force-stream First party cookie 180 Minutes Used to redirect server requests for sticky sessions.
gTalkCollapsed First party cookie 1 Year Controls whether the sidebar in Salesforce is open or not for a user.
guest_uuid_essential_<15-char SitelD> First party cookie 1 Year Provides a unique ID for guest users in Experience Cloud sites. Expires one year after the user's last visit to the site.
idccsrf First party cookie Session Tracks CrossSiteRequestForgery validation for certain SSO flows.
inst First party cookie Session Used to redirect requests to an instance when bookmarks and hardcoded URLs send requests to a different instance. This type of redirect can after an org migration, a split, or after any URL update.
language First party cookie Session Identifies the language for custom components, surveys, and flows, which support multiple Ianguages. Without this cookie, translations for custom features can appear incorrectly.
lastlist First party cookie Session Used to store the cookie name for the last Iist URL.
liveagent_sid First party cookie Session Identifies a Live Agent session. Stores a unique pseudonymous ID for a specific browser session over chat service.
lloopch_loid First party cookie 1 Year Determines whether to send the user to a specific portal login or an app login.
oid First party cookie 1 Year Stores the last logged in org for redirecting requests. Used for logging whether the cookie is present in site and community guest-user requests.
pctrk First party cookie 1 Year Used to track unique page visitors in Experiences.
Picassolanguage First party cookie Session Used to store a user's language selection fo Experience Builder site. The site doesn't load without this cookie if the user changes the site's language.
promptTestMod First party cookie 30 Days Stores whether test mode is in effect. This cookie is read-only.
renderCtx First party cookie Session Used to store site parameters in the session for reuse across requests by a single client for functionality and performance reasons. Metadata required for fetching site pages and components based on pageld, schema, viewType, brandingSet, formfactor, and audience targeting.
RRetURL First party cookie Session Used with 'Log in As' to restore the original state
RRetURL2 First party cookie Session The return URL to redirect to when logging out of a session.
RSID First party cookie Session Session ID and login-as session ID. In this case cookies are copied to the response and cause the target URL to rebuild appropriately in a proxy situation. The cookies aren't created, examined, or modified.
sfdc_lv2 First party cookie 1 Year Stores identity confirmation details (MFA).
sfdc_lv2 First party cookie 1 Year Stores identity confirmation details for Experience Cloud users. If the cookie isn't set or it expires, it must repeat the identity confirmation process the next time that they log in. Identity confirmation requires a verification method such as SMS, an authenticator app, or a security key.
sfdc-stream First party cookie 3 Hours Used to maintain a sticky (persistent) session on the http://salesforce.com domain. Makes sure that subsequent streaming requests are forwarded to the same server instance where the streaming subscription request was originally handled.
sid First party cookie Session SessionID.
sid_Client First party cookie Session Used to detect and prevent session tampering.
sidebarPinned First party cookie 10Years Controls the state of the Salesforce Classic sidebar.
ssostartpage First party cookie 1 Year Identifies the Identity Provider (ldP) location for SSO; certain service provider initiated SSO requests can fail without this cookie.
SUPRM First party cookie Session Used when the user identity that an administrator is assuming (via Log in to Experience as User) is a Customer Success Portal (CSP) user.
SUPRM First party cookie Session Used when the user identity that an administrator is assuming (via Log in to Experience as) is a Partner Relationship Management (PRM) portal user.
useStandbyUrl First party cookie Not Set Controls how quickly to set the standby URL when loading the softphone

Data Privacy Notice version 1.0

We will notify you of material changes to these Terms of Use at least 30 days in advance by posting a notice on our website or contacting you directly."

This privacy policy was last amended on January 30, 2026.

Attachment