Last updated: [[ PRIVACY_UPDATED_DATE ]]
When you join JapanPass, we collect your first name and email address. When you book a session or tour, we collect the information required to process payment and deliver the service. We do not collect payment card data directly. This is handled by Stripe, PayPal, or the relevant payment processor.
Your information is used to deliver the services you book, send the guides and resources you sign up for, and communicate about your membership or bookings. We do not sell your data. We do not share your data with third parties except those required to deliver the service (Stripe, Google Meet, Calendly).
We use Google Analytics to count visits and see which pages people read. It sets cookies. We do not use advertising cookies, tracking pixels, or any third-party advertising network.
If you are in the EU, the EEA, the UK or Switzerland, analytics do not load until you allow them. You will see a banner the first time you visit, and nothing that measures runs before you answer it. If we cannot tell where you are, you get the banner as well. Declining changes nothing you can see, and you are not asked again on that device.
Everywhere else, analytics load as they always have, and you can turn them off in your browser.
These are the only things we store on your device:
We also count how many times a listing page is viewed. That counter records the listing and the type of event and nothing else — no IP address, no browser string, and no identifier of any kind, so those counts cannot be traced back to a person.
When a business becomes a JapanPass partner we hold the contact details you give us, the record of what you bought, and when it renews. We do not hold your card. Payment is handled by Stripe, who are the processor; we see the last four digits and the card brand, and nothing else.
We also keep a record of our correspondence with you, so that whoever picks up your enquiry can see what was already said. That record is internal. It never appears on your public listing, and it is never sold, licensed or shared with another company.
| What | How long |
|---|---|
| Your public listing | For as long as it is on the site |
| Partner billing records | [[ BILLING_RETENTION_YEARS ]] years, because tax law requires it |
| Correspondence with a business | [[ CORRESPONDENCE_RETENTION ]] |
| Enquiries and form submissions | [[ ENQUIRY_RETENTION ]] |
| A do-not-contact request | Kept indefinitely, on purpose |
| Listing view counts | Kept indefinitely. They contain nothing about a person |
| Google Analytics | [[ ANALYTICS_RETENTION ]], set in the Google Analytics property |
Why a do-not-contact request is kept forever. If you ask us to stop contacting you, we have to remember that you asked. Deleting the request would mean that the next time your business appeared in a data import, we would have no idea you had ever said no. So we keep the request, and nothing else changes about it.
Data is stored on Supabase infrastructure. Email communications use standard email service providers.
You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Write to [[ PRIVACY_EMAIL ]] and we will reply within [[ ERASURE_RESPONSE_DAYS ]] days.
Two things we will tell you plainly rather than after the fact. A do-not-contact request stays, for the reason above. And a business listing that is a matter of public record may be re-added by a later data collection unless you also ask us not to contact you.
These rights are what we offer everyone, everywhere. We have not written a separate policy for one region and a weaker one for another.