TOP SERVICES

Social × Video Marketing

Social Media Management POV Studio Influencer PR Social Ads Management Inbound Tourism Marketing Full-Funnel Marketing Recruitment Marketing

Product × Travel

Travi Travel App

AI × R&D

AllRev AI Marketing Tool UGC Lab WORKS COLUMNS TEAM CONTACT

Privacy Policy

Privacy Policy

This is a reference translation. The Japanese version is the authoritative text; in the event of any discrepancy, the Japanese version prevails.

TripClear Inc. ("the Company") recognises the importance of protecting personal information. The Company complies with Japan's Act on the Protection of Personal Information ("the APPI") and endeavours to handle and protect personal information appropriately in accordance with the privacy policy set out below ("this Privacy Policy"). Unless otherwise stated herein, terms used in this Privacy Policy have the meanings given to them in the APPI.

1. Definition of personal information

In this Privacy Policy, "personal information" means information relating to a living individual that falls under either of the following items.

  1. (1) Information that can identify a specific individual by means of a name, date of birth or other description contained in it (meaning any matter written or recorded in a document, drawing or electromagnetic record, or expressed by voice, movement or any other method), including information that can be readily collated with other information and thereby identify a specific individual.
  2. (2) Information containing an individual identification code.

2. Purposes of use

The Company uses personal information for the following purposes.

  1. (1) To provide the hotel video discovery service, hotel video booking service and other services offered by the Company ("the Services").
  2. (2) To provide information about the Services and to respond to enquiries.
  3. (3) To provide information about the Company's products and services.
  4. (4) To respond to conduct that breaches the Company's terms, policies and similar documents relating to the Services ("the Terms").
  5. (5) To give notice of changes to the Terms relating to the Services.
  6. (6) To improve the Company's services and develop new ones.
  7. (7) For employment administration and internal procedures (in respect of personal information of officers and employees), and for selection and communication in recruitment (in respect of personal information of applicants).
  8. (8) For shareholder administration and procedures required under the Companies Act and other laws (in respect of personal information of shareholders, holders of share options and the like).
  9. (9) To analyse information on service usage and produce statistical data, processed into a form that cannot identify an individual, in connection with the Company's services.
  10. (10) For other purposes incidental to those above.

3. Changes to the purposes of use

The Company may change the purposes of use of personal information within a scope reasonably deemed to have relevance to the original purposes. Where it does so, it will notify the individual to whom the personal information relates ("the Individual") or make a public announcement.

4. Restrictions on use

4.1 Except where permitted by the APPI or other laws, the Company will not handle personal information beyond the scope necessary to achieve the purposes of use without the Individual's consent. This does not apply in the following cases.

  1. (1) Where required by law.
  2. (2) Where necessary to protect the life, body or property of a person and it is difficult to obtain the Individual's consent.
  3. (3) Where specially necessary to improve public health or promote the sound development of children and it is difficult to obtain the Individual's consent.
  4. (4) Where it is necessary to cooperate with a national organ, a local government or a party entrusted by either in performing duties prescribed by law, and obtaining the Individual's consent is likely to impede the performance of those duties.
  5. (5) Where personal data is provided to an academic research institution and that institution needs to handle it for academic research purposes (including where only part of the purpose is academic research, but excluding cases where there is a risk of unjustly infringing an individual's rights and interests).

4.2 The Company will not use personal information in a manner that may encourage or induce unlawful or improper conduct.

5. Proper acquisition of personal information

5.1 The Company acquires personal information properly and will not do so by deception or other improper means.

5.2 Except in the following cases, the Company will not acquire special care-required personal information (as defined in Article 2, paragraph 3 of the APPI) without the Individual's prior consent.

  1. (1) Where any of items (1) to (4) of Section 4.1 applies.
  2. (2) Where such information is acquired from an academic research institution and needs to be acquired for academic research purposes (including where only part of the purpose is academic research, but excluding cases where there is a risk of unjustly infringing an individual's rights and interests), limited to cases where the business operator and the institution conduct the academic research jointly.
  3. (3) Where such information has been made public by the Individual, a national organ, a local government, an academic research institution, a party listed in the items of Article 57, paragraph 1 of the APPI, or another party prescribed by the rules of the Personal Information Protection Commission.
  4. (4) Where such information that is externally apparent is acquired by observing or photographing the Individual.
  5. (5) Where such information is received from a third party and that provision falls under any item of Section 8.1.

5.3 When receiving personal information from a third party, the Company will confirm the following matters in accordance with the rules of the Personal Information Protection Commission, except where the provision falls under any item of Section 4.1 or any item of Section 8.1.

  1. (1) The third party's name and address, and, in the case of a corporation, the name of its representative (or, in the case of an unincorporated association with a designated representative or administrator, that person's name).
  2. (2) The circumstances in which the third party acquired the personal information.

6. Security management

To guard against the risks of loss, destruction, alteration and leakage, the Company exercises necessary and appropriate supervision over its employees to ensure the security of personal information. Where it entrusts all or part of the handling of personal information to a third party, it exercises necessary and appropriate supervision over that party as well. The specific security measures applying to the Company's retained personal data are as follows.

Establishment of a basic policy
This Privacy Policy has been established as a basic policy covering compliance with applicable laws and guidelines, and the contact point for questions and complaints, in order to ensure the proper handling of personal data.
Rules governing the handling of personal data
Handling rules have been established covering methods, responsible persons and their duties at each stage: acquisition, use, storage, provision, deletion and disposal.
Organisational security measures
1) A person responsible for the handling of personal data has been appointed; the employees who handle personal data and the scope of the data they handle are clearly defined; and a reporting line to the responsible person has been established for any fact or indication of a breach of the law or the handling rules.
2) The handling of personal data is subject to regular self-inspection, together with audits by other departments and external parties.
Personnel security measures
1) Employees receive regular training on points to observe when handling personal data.
2) Confidentiality obligations regarding personal data are set out in the work rules.
Physical security measures
1) In areas where personal data is handled, employee entry and exit is controlled, the equipment that may be brought in is restricted, and measures are taken to prevent unauthorised persons from viewing personal data.
2) Measures are taken to prevent the theft or loss of equipment, electronic media and documents that handle personal data, and when such items are carried — including within the premises — measures are taken so that the personal data cannot be readily identified.
Technical security measures
1) Access controls limit both the personnel involved and the scope of the personal information databases they handle.
2) Mechanisms are in place to protect information systems handling personal data from external unauthorised access and malicious software.
Understanding the external environment
Because the provider entrusted with storing personal data is based in the United States, the Company has informed itself of the US personal information protection regime and implements necessary and appropriate security measures accordingly. Where personal information is stored in any other country, the Company likewise informs itself of that country's personal information protection regime before implementing security measures.

7. Reporting of leakage

Where a leak, loss or damage occurs in relation to personal information handled by the Company, and the APPI requires a report to the Personal Information Protection Commission and notification to the Individual, the Company will make that report and give that notification.

8. Provision to third parties

8.1 Except where any item of Section 4.1 applies, the Company will not provide personal information to a third party without the Individual's prior consent. However, the following do not constitute provision to a third party as described above.

  1. (1) Where personal information is provided in connection with entrusting all or part of its handling within the scope necessary to achieve the purposes of use.
  2. (2) Where personal information is provided in connection with a business succession arising from a merger or other cause.
  3. (3) Where the information is used jointly in accordance with the APPI.

8.2 Notwithstanding Section 8.1, and except where any item of Section 4.1 applies, where the Company provides personal information to a third party in a foreign country (excluding countries designated by the rules of the Personal Information Protection Commission under Article 28 of the APPI) that has not established a framework meeting the standards designated by those rules, it will first obtain the Individual's consent to such provision.

8.3 When obtaining consent under Section 8.2, the Company will provide the Individual with the following information. Where item (1) cannot be identified, the Company will instead provide, in place of items (1) and (2), a statement that item (1) cannot be identified together with the reason, and any information that may serve as a useful substitute for the Individual.

  1. (1) The name of the foreign country concerned.
  2. (2) Information on that country's personal information protection regime.
  3. (3) Information on the measures the third party takes to protect personal information (or, where that information cannot be provided, a statement to that effect and the reason).

8.4 When the Company provides personal information to a third party, it prepares and retains records in accordance with Article 29 of the APPI.

8.5 When receiving personal information from a third party, the Company carries out the necessary confirmations and prepares and retains records of them in accordance with Article 30 of the APPI.

9. Disclosure of personal information

9.1 Where an Individual requests disclosure of personal information under the APPI, the Company will confirm that the request comes from the Individual themselves and will make the disclosure without delay (or notify the Individual if no such personal information exists). This does not apply where the Company is not obliged to disclose under the APPI or other laws. Please note that a fee is charged for disclosure. The Company will set that fee at a reasonable amount having regard to actual costs, and will notify the Individual of it without delay after receiving the request.

9.2 The preceding section applies mutatis mutandis to records of provision to third parties prepared under Section 8.4 and records of receipt from third parties prepared under Section 8.5, in each case relating to personal information identifying the Individual, except for the provisions concerning fees.

10. Correction of personal information

Where an Individual requests correction, addition or deletion of personal information ("correction") under the APPI on the grounds that it is not accurate, the Company will confirm that the request comes from the Individual themselves, carry out the necessary investigation without delay within the scope required to achieve the purposes of use, make the correction based on the results and notify the Individual accordingly (or notify the Individual if it decides not to make the correction). This does not apply where the Company is not obliged to make the correction under the APPI or other laws.

11. Suspension of use of personal information

Where an Individual requests, under the APPI, (i) suspension of use or erasure of their personal information ("suspension of use") on the grounds that it is being handled beyond the scope of the publicly announced purposes of use, that it is being used in a manner that may encourage or induce unlawful or improper conduct, or that it was acquired by deception or other improper means; (ii) suspension of provision of their personal information ("suspension of provision") on the grounds that it has been provided to a third party without their consent; or (iii) suspension of use or suspension of provision on the grounds that the Company no longer needs to use their personal information, that a situation prescribed in the main text of Article 26, paragraph 1 of the APPI has arisen in relation to their personal information, or that the handling of their personal information may otherwise harm their rights or legitimate interests — and where the request is found to be justified — the Company will confirm that the request comes from the Individual themselves, carry out the suspension of use or suspension of provision without delay, and notify the Individual accordingly. This does not apply where the Company is not obliged to do so under the APPI or other laws.

12. Provision of personal-related information to third parties

12.1 Where it is anticipated that a third party will acquire personal-related information (as defined in Article 2, paragraph 7 of the APPI, limited to information constituting a personal-related information database as defined in Article 16, paragraph 7 of that Act; the same applies below) as personal data, the Company will not provide that information to the third party without first confirming the following matters in accordance with the rules of the Personal Information Protection Commission, except where any item of Section 4.1 applies.

  1. (1) That the Individual's consent has been obtained to the third party receiving the personal-related information from the Company and acquiring it as personal data identifying the Individual.
  2. (2) In the case of provision to a third party in a foreign country, that before seeking the consent referred to in the preceding item, the Individual has been provided, in accordance with the rules of the Personal Information Protection Commission, with information on that country's personal information protection regime, the measures the third party takes to protect personal information, and any other information useful to the Individual.

12.2 When the Company provides personal-related information to a third party, it prepares and retains records in accordance with Article 31 of the APPI.

12.3 When receiving personal-related information from a third party, the Company carries out the necessary confirmations and prepares and retains records of them in accordance with Article 31 of the APPI.

13. Handling of pseudonymously processed information

13.1 When creating pseudonymously processed information (as defined in Article 2, paragraph 5 of the APPI, limited to information constituting a pseudonymously processed information database as defined in Article 16, paragraph 5 of that Act; the same applies below), the Company processes personal information in accordance with the standards prescribed by the rules of the Personal Information Protection Commission. Where it has created such information or acquired deleted information (as defined in Article 41, paragraph 2 of the APPI; the same applies below), it implements measures for the security of that deleted information in accordance with those standards.

13.2 The Company complies with the following in respect of pseudonymously processed information.

  1. (1) Notwithstanding Section 4.1, and except where required by law, the Company will not handle pseudonymously processed information (limited to information that constitutes personal information) beyond the scope necessary to achieve the purposes of use.
  2. (2) In applying Section 3 to pseudonymously processed information (limited to information that constitutes personal information), "change within a scope reasonably deemed to have relevance" is read as "change", and "notify or make a public announcement" is read as "make a public announcement".
  3. (3) Except where required by law, the Company will not provide pseudonymously processed information (whether or not it constitutes personal information) to a third party. However, the cases listed in the items of Section 8.1 do not constitute provision to a third party as described above.

14. Handling of anonymously processed information

14.1 When creating anonymously processed information (as defined in Article 2, paragraph 6 of the APPI, limited to information constituting an anonymously processed information database as defined in Article 16, paragraph 6 of that Act; the same applies below), the Company processes personal information in accordance with the standards prescribed by the rules of the Personal Information Protection Commission.

14.2 Having created anonymously processed information, the Company implements security measures in accordance with the standards prescribed by the rules of the Personal Information Protection Commission.

14.3 Having created anonymously processed information, the Company publishes the categories of information relating to individuals contained in it, in accordance with the rules of the Personal Information Protection Commission.

14.4 When providing anonymously processed information (including information the Company has created and information received from third parties; the same applies below unless otherwise stated) to a third party, the Company first publishes, in accordance with the rules of the Personal Information Protection Commission, the categories of information relating to individuals contained in it and the method of provision, and expressly informs the third party that the information provided is anonymously processed information.

14.5 In handling anonymously processed information, the Company will not, for the purpose of identifying the individual to whom the personal information used to create it relates, (1) collate the anonymously processed information with other information, or (2) acquire the descriptions or individual identification codes deleted from that personal information, or information on the processing method applied under Article 43, paragraph 1 of the APPI (item (2) applying only to anonymously processed information received from a third party).

14.6 The Company endeavours to implement, on its own initiative, the measures necessary and appropriate for the security of anonymously processed information, for handling complaints about its creation and other handling, and otherwise for ensuring its proper handling, and to publish the content of those measures.

15. Use of cookies and similar technologies

The Company's services may use cookies and similar technologies. These help the Company understand how its services are used and contribute to improving them. Users who wish to disable cookies can do so by changing their web browser settings. Note that disabling cookies may make some features of the Company's services unavailable.

16. Contact

Requests for disclosure, comments, questions, complaints and any other enquiries regarding the handling of personal information should be directed to the contact below.

est Largo SHIBUYA 102, 1-18-2 Higashi, Shibuya-ku, Tokyo 150-0011, Japan

TripClear Inc. (CEO: Takumi Nagata)

E-mail: info@tripclear-inc.com

(Enquiries are handled on weekdays between 10:00 and 18:00 JST.)

17. Continuous improvement

The Company reviews its practices regarding the handling of personal information as appropriate, endeavours to improve them continuously, and may amend this Privacy Policy where necessary.

[Established 28 February 2025]

[Last amended 1 March 2025]