Privacy Policy
Optional Google Analytics
Japan Private Car Service uses Google Analytics 4, provided by Google, to understand website visits and the booking process. Analytics is optional: we load its browser tracking only after you choose “Allow analytics”. Declining does not prevent you from booking.
With your permission, analytics cookies and similar identifiers identify your browser and session. Google receives usage events, a simplified page address without query parameters, and recognised referring website origins. Google may also process technical information, including browser, device and network information, under its own policies. We do not send contact details, flight details, pickup addresses, booking access tokens or URL query parameters to Google Analytics.
When analytics identifiers are available and you have agreed, we associate them with your saved booking to measure quotes, bookings, checkout, completed payments and confirmed refunds. Payment and refund events come from our server and may include a transaction reference, currency and amount; refund amounts come from confirmed refund records, and these events do not include your payment card information. This helps us measure visits through to completed bookings. Advertising personalisation and Google signals are disabled in this integration.
You can decline or withdraw permission using “Analytics settings” on public pages. Withdrawal stops further browser collection and removes analytics attribution from saved bookings accessible through this browser's booking session. It does not undo events already sent to Google, or automatically identify bookings from other browsers or deleted sessions. If saving your withdrawal fails, we display a retry message. For an earlier booking or a data request, contact booking@japanprivatecarservice.com.
We store your analytics preference in this browser for up to 180 days. Necessary booking and security storage remains separate. Google may process analytics information outside your country, including outside Japan. Read how Google uses information from sites that use its services and Google’s Privacy Policy.
Japan Private Car Service in ChatGPT
When you use our ChatGPT App, we process the trip information you choose to provide, such as pickup and destination, travel dates and times, passenger and luggage counts, selected vehicles and stops, flight information, and the contact or invoice details needed for your booking. We use this information to answer your request, produce a quote, prepare your booking, arrange checkout and provide your booking and payment status.
Our customer login uses Auth0, with the identity service hosted in its United States region. Your authenticated identity is linked to your customer account so that you can access your own quotes and bookings. This does not grant access to our administration systems or another customer's information.
When you request a quote, booking or status in ChatGPT, the App returns the customer-facing information needed for that request to ChatGPT/OpenAI. Internal supplier prices, costs, margins and pricing rules are not included. Google services may help resolve a place you select. Checkout is handled through our official payment flow and Stripe; do not enter payment-card details in the ChatGPT conversation.
Disconnecting the App stops your future use of that connection. It is not a request to cancel a journey or erase booking, payment or other records covered by our existing retention policy. To ask about access, correction or deletion, contact booking@japanprivatecarservice.com. The retention and deletion provisions in this privacy policy continue to apply.
Japan Private Car Service values the personal information and privacy of its customers. This Privacy Policy explains how we collect, use, store, share, and protect personal information when customers browse our website, submit inquiries, create orders, complete payments, use airport transfers, city-to-city transfers, hourly car rentals, day tours, and other related services. This policy applies to customers, passengers, inquirers, and other relevant personnel who engage in business with Japan Private Car Service through our official website or channels recognized by our company. We process personal information only within the scope necessary for providing services, processing orders, completing payments, customer support, security management, dispute resolution, fulfilling legal obligations, and other lawful purposes. By using this website, submitting an order, or providing personal information to our company, customers agree that they have read this policy. For personal information processing that requires customer consent under applicable law, our company will obtain the appropriate consent in accordance with Japanese law.
Personal Information We Collect
1.1 In order to provide private transfers, airport transfers, intercity transfers, hourly car rentals, day tours, and other related services, the company may collect necessary personal information based on the specific circumstances of the customer's use of the service.
1.2 The basic identity and contact information we may collect includes but is not limited to:
(1) Name; (2) Phone number; (3) Email address; (4) WhatsApp or other instant messaging contact information; (5) Country or region information; (6) Other contact information voluntarily provided by the customer.
1.3 Information related to orders and transportation services may include but is not limited to:
(1) Service Date; (2) Pickup Time; (3) Pickup Location; (4) Destination; (5) Hotel Name and Address; (6) Private Residence, Guesthouse, or Other Pickup Address; (7) Number of Passengers; (8) Number of Children and Necessary Information Related to Safety Seat Arrangements; (9) Number, Size, and Special Luggage Circumstances of Luggage; (10) Booked Vehicle Type; (11) Service Duration; (12) Route; (13) Stopover Locations; (14) Order Notes and Other Service Requirements Requested by the Customer.
1.4 For airport transfer services, we may collect information related to flights, including but not limited to:
(1) Airline name; (2) Flight number; (3) Departure airport; (4) Arrival airport; (5) Flight date; (6) Estimated arrival or departure time; (7) Publicly available flight status information; (8) Other necessary information directly related to pickup or drop-off arrangements.
1.5 For train stations, Shinkansen stations, cruise terminals, or other transportation transfer services, we may collect information about trains, cruises, terminals, arrival times, and other details related to pickup arrangements that customers voluntarily provide.
1.6 If customers contact us for inquiries, complaints, order modifications, refund applications, or other customer service matters, we may retain relevant communication content, including but not limited to emails, WhatsApp messages, website inquiry records, phone contact records, and other communications directly related to the service.
1.7 If a customer creates a personal account, we may collect and retain information related to the account, including account identification information, login records, order history, frequently used contact information, and other account information voluntarily saved by the customer.
1.8 If customers pay via credit card, debit card, or other third-party payment methods, the company may receive necessary transaction information related to the payment, such as payment status, transaction number, payment amount, currency, payment time, bank card type, or limited identification information provided by the payment service provider.
1.9 Unless otherwise explicitly stated by the company, the company will generally not retain full credit card numbers, security codes (CVV), or other sensitive payment credentials that do not need to be directly held by the company. Relevant payment information is typically handled by professional third-party payment service providers used by the company in accordance with their security standards.
1.10 To ensure order execution, resolve disputes, prevent fraud, and enhance service security, the company may retain operational records related to order fulfillment within the limits allowed by law, including driver arrival times, vehicle dispatch records, service start and end times, pickup status, and other reasonable and necessary information.
1.11 In applicable and lawful circumstances, the vehicle or scheduling system may generate vehicle location, GPS, or operational information related to order fulfillment. The company shall only use such information within the scope of order execution, safety, dispute resolution, legal obligations, or other lawful necessary purposes.
1.12 Our company will not continuously track customers' personal locations for purposes unrelated to services. Information related to vehicle locations is generally used for vehicle dispatch, pickup coordination, service proof, safety management, and dispute resolution.
1.13 When customers visit this website, the website server, analytics tools, or necessary technical services may automatically collect certain technical information, including but not limited to:
(1) IP address; (2) Browser type; (3) Device type; (4) Operating system; (5) Access time; (6) Accessed page; (7) Referring page; (8) Necessary identification information generated by Cookies or similar technologies; (9) Website operation and security logs.
1.14 The technical information mentioned above is mainly used to ensure the normal operation of the website, network security, troubleshooting, statistical analysis, improving user experience, and preventing fraud or malicious attacks.
1.15 If this website uses Cookies, analytics tools, advertising tools, or similar technologies, the company will handle the relevant information in accordance with Japanese applicable laws and the provisions of this policy regarding Cookies and website technologies.
1.16 Customers may choose not to provide certain non-essential information to the company. However, if certain information is necessary for verifying identity, contacting passengers, arranging vehicles, completing payments, or legally providing transportation services, refusal to provide such information may result in the company being unable to complete the relevant order or service.
1.17 The company will not actively request customers to provide personal information that is unrelated to transportation services and has no legitimate purpose for processing.
1.18 If a customer voluntarily provides information to the company regarding their health condition, disability, special care needs, or other relatively sensitive information, the company shall only process such information to the extent reasonably necessary for arranging accessible services, assistive devices, safe transportation, or other services explicitly requested by the customer, and shall take appropriate protective measures in accordance with applicable laws.
1.19 Customers should not provide highly sensitive information unrelated to the service through order notes, chat, or other channels, including full bank card passwords, online banking passwords, other account passwords, or other information that the company does not have a reasonable necessity to collect.
1.20 If a client representative books on behalf of accompanying passengers or other personnel, and provides the company with the names, contact information, flight details, accommodation, or other personal information of the relevant individuals, the client should ensure that they have a legal basis for providing such information, and should reasonably inform the relevant individuals that this information will be used to complete the transportation service.
1.21 For information regarding minors, our company will generally only process necessary information within the scope of completing family or group transportation, child safety seat arrangements, and other legally necessary services.
1.22 The company will not actively request customers to provide detailed sensitive personal information about children for commercial purposes unrelated to the order.
1.23 If a customer submits passports, identification documents, or other proof of identity for handling specific matters, the company should only use them within the scope of identity verification, fraud prevention, legal obligations, or other legitimate necessity, and should control the scope and duration of storage according to actual necessity.
1.24 The company may obtain information related to order execution from legal sources other than the customer themselves, such as travel agencies, corporate customers, hotels, partner platforms, co-bookers, or other sources authorized by the customer or having a legitimate basis.
1.25 If the order is booked by a travel agency, company, family member, friend, or other representative, the company may obtain the actual passenger's name, contact information, flight, hotel, and other information necessary to complete the service from the person making the booking.
1.26 The company may also obtain necessary information directly related to the execution of the service from airlines, airports, map services, payment service providers, or other legitimate third-party sources, such as public flight status, address location, payment status, or other technical information.
1.27 The company will not collect personal information without purpose or limit merely because it is technically possible to obtain it. The scope of personal information collection should be appropriate to clear, reasonable, and lawful processing purposes.
1.28 If our company adds new services, payment methods, account functions, or technical features in the future, and therefore needs to collect new categories of personal information, our company will update this policy in accordance with applicable laws or otherwise reasonably inform customers of the relevant processing matters.
1.29 Customers may, within the scope permitted by applicable laws, make requests such as inquiries, corrections, or other legally entitled requests regarding personal information held by the company, as stipulated in subsequent sections of this policy.
1.30 The provisions in this section regarding the scope and methods of collecting personal information are implemented only within the limits permitted by Japanese applicable law. The company will handle customer personal information in accordance with Japanese applicable laws on the protection of personal information and other regulations that are legally enforceable.
Purpose of Use of Personal Information
2.1 This company uses the collected personal information only within a clear, reasonable, and legal scope, and appropriately manages personal information in accordance with applicable Japanese laws. In principle, this company will not use personal information for purposes clearly unrelated to the original collection purpose, unless permitted by law or another legitimate basis.
2.2 The company may use customers' and passengers' personal information for accepting, confirming, and managing service bookings, including but not limited to confirming service dates, pickup times, pickup and drop-off locations, destinations, vehicle types, number of passengers, number of children, number of luggage items, flight information, service duration, and other order details.
2.3 The company may use relevant personal information to determine whether the vehicle is suitable for the number of passengers, amount of luggage, and special transportation needs of the customer, and accordingly arrange appropriate vehicles, drivers, and other service resources.
2.4 The company may provide the customer's name, contact phone number, WhatsApp contact information, pickup location, destination, flight information, number of passengers, luggage information, and other information necessary to complete the order to the actual driver, dispatcher, or personnel legally involved in the service execution.
2.5 The information mentioned above should only be provided to the extent reasonably necessary to complete a specific order. In principle, the company will not provide customer personal information to drivers or other service personnel that is clearly unrelated to completing the order.
2.6 For airport pickup and drop-off services, the company may use information provided by the customer, such as the airline, flight number, estimated arrival or departure time, to check or confirm the flight status, in order to reasonably arrange the vehicle, driver's arrival time, and pickup service.
2.7 If the customer's flight is advanced, delayed, canceled, rescheduled, or otherwise changed, the company may adjust the vehicle and driver arrangements based on the relevant flight information, and handle the related services in accordance with the order conditions, the 'Terms and Conditions of Service,' and the 'Cancellation, Waiting, and No-Show Policy.'
2.8 For pick-up and drop-off services at hotels, train stations, Shinkansen stations, cruise ports, ports, guesthouses, private residences, and other locations, the company may use the location, accommodation, train, cruise, or other relevant information provided by the customer to confirm the pick-up location and reasonably arrange the service.
2.9 The company may use customer contact information to communicate with customers regarding matters directly related to the order before, during, or after the service.
2.10 Contact as described above may include but is not limited to:
(1) Send order confirmation; (2) Confirm payment status; (3) Confirm pickup time and location; (4) Confirm flight or transportation information; (5) Send driver or vehicle-related information; (6) Coordinate between driver and passenger; (7) Notify when the vehicle arrives; (8) Handle cases where the customer is late or the driver cannot contact the customer; (9) Handle changes in the itinerary; (10) Handle lost items; (11) Handle complaints, refunds, or other after-sales matters; (12) Handle other matters directly related to the fulfillment of the order.
2.11 The company may contact you via email, phone, SMS, WhatsApp, or other reasonable communication methods that the customer actively uses for the contact mentioned above.
2.12 The company may use order and customer information for internal dispatching, including vehicle arrangements, driver scheduling, service area confirmation, time management, route planning, and operational coordination.
2.13 To ensure the safety of passengers, drivers, and vehicles, the company may use information related to order execution for safety management, accident handling, emergency contact, and risk control within the limits allowed by law.
2.14 If a traffic accident, vehicle breakdown, passenger injury, property damage, or other safety incident occurs, the company may use relevant order, passenger, driver, vehicle, communication, and operational information within a reasonable and necessary scope to verify facts and handle the incident.
2.15 In the circumstances mentioned above, the company may provide necessary information to the police, fire department, medical institutions, insurance companies, lawyers, road management authorities, or other relevant institutions with a legal basis for handling the incident, as legally required or reasonably necessary for accident handling.
2.16 The company may use personal information to process customer requests for order modifications, date changes, time adjustments, route adjustments, vehicle type adjustments, changes in the number of passengers, and other service change requests.
2.17 The company may use order and payment information to confirm whether the customer has completed the payment, whether there are outstanding payments, duplicate payments, refunds, partial refunds, or other payment anomalies.
2.18 If a customer submits a cancellation or refund request, the company may use the order confirmation time, service start time, cancellation request time, payment records, driver scheduling status, vehicle arrangement status, and related communication records to determine whether the customer meets the refund conditions.
2.19 If the customer is determined to possibly have a No-show, be late, or exceed the free waiting time, the company may use driver arrival records, customer communication records, flight information, vehicle operation records, and other reasonable and necessary information to verify the actual situation.
2.20 The company may use relevant personal information to handle customer complaints, service quality issues, fee disputes, payment disputes, Chargeback, refund disputes, and other disputes related to orders.
2.21 To resolve the disputes mentioned above, the company may retain and use order records, payment records, driver scheduling records, vehicle operation data, GPS records (if applicable), emails, WhatsApp communication records, and other relevant evidence within the scope permitted by law and necessary for dispute resolution.
2.22 If a customer raises a payment dispute or chargeback with a bank, credit card company, payment service provider, or other institution, the company may use and provide the relevant institution with necessary information related to the transaction, within the scope reasonably necessary to handle the dispute.
2.23 The company may use personal information to identify, prevent, and investigate suspected fraud, unauthorized transactions, identity theft, malicious orders, duplicate refunds, abuse of discounts, false chargebacks, and other actions that may harm the interests of customers, the company, or third parties.
2.24 If the company has reasonable grounds to suspect that a transaction involves illegal activities, payment fraud, or other security risks, it may take necessary verification, security control, and investigation measures within the scope permitted by Japanese law.
2.25 The company may use customer information to fulfill accounting, tax, financial, audit, insurance, company management, and other record-keeping obligations required by law.
2.26 The company may use or provide relevant personal information within the necessary scope in accordance with Japanese law, court orders, requests from administrative agencies, police, or other legally authorized authorities.
2.27 The company may use order and service data for internal business statistics, service quality analysis, vehicle demand analysis, service area analysis, customer demand analysis, and operational improvements.
2.28 Where it is reasonably feasible to achieve the purpose of analysis, the company will use aggregated, de-identified, or other data that does not directly identify specific individuals as much as possible for statistical and analytical purposes.
2.29 The company may use information generated from website access data, device information, browser information, Cookies, and similar technologies to maintain normal website operations, enhance website security, analyze website usage, identify system errors, and improve user experience.
2.30 The company may use relevant technical information to identify malicious access, abnormal requests, network attacks, automated abuse, payment fraud, or other actions that may endanger the security of the website and system.
2.31 If a customer creates a personal account, the company may use the relevant personal information to provide account login, identity verification, order inquiry, viewing of historical orders, order management, and other account functions.
2.32 The company may use your historical orders and communication records to identify relevant orders, improve customer service efficiency, and avoid you from having to provide the same information repeatedly when you contact us again.
2.33 If a customer requests voluntarily to issue a receipt, invoice, payment proof or other business documents, the company may use the customer's provided name, company name, order information, payment information and other necessary data to prepare and provide the relevant documents.
2.34 If a customer reports a lost item, the company may use the order, vehicle, driver, pickup time, route, and contact information to assist in locating, confirming, and returning the relevant item.
2.35 If returning lost items requires courier, mailing, delivery, or other third-party services, the company may provide the necessary information to the relevant service provider to complete the return, provided it has a legal basis for handling such information.
2.36 If a customer requests special vehicle arrangements, accessibility services, child safety seats, or other special transportation needs, the company may use the information voluntarily provided by the customer to determine whether it is possible to safely and legally provide the requested service.
2.37 For information relating to health, disability, or other more sensitive matters, the company will only use such information within the scope where the customer voluntarily provides it, processing the relevant service is indeed necessary, and there is an appropriate legal basis, and appropriate protective measures will be taken.
2.38 If a customer subscribes to our company's promotions, events, news, or other marketing information, our company may use the customer's contact information to send relevant information within the scope of consent or other legal basis required by Japanese applicable laws.
2.39 For marketing communications that require customer consent under applicable law, the company shall obtain the necessary consent in accordance with the relevant legal requirements. Customers may unsubscribe or request to stop receiving such communications using the methods provided in the relevant communications.
2.40 If a customer refuses or cancels the receipt of marketing messages, it will not affect the company's ability to send necessary order confirmations, driver contact information, service change notifications, safety alerts, payment notifications, or other transactional information required to fulfill already established orders.
2.41 Except as required by applicable Japanese law, necessary for contract performance, agreed to by the customer in accordance with the law, or otherwise legally permissible, the company will not, in principle, sell customer personal information to third parties.
2.42 The company will not sell the customer's name, phone number, email address, WhatsApp contact information, or other information that can directly identify the customer's identity to data brokers or other unrelated third parties solely for the purpose of obtaining commercial benefits unrelated to transportation services.
2.43 If our company entrusts cloud servers, website hosting, email, customer communication, payment processing, data analysis, IT maintenance, accounting, or other service providers to process certain personal information, our company shall only allow them to process the information to the extent necessary to achieve the relevant business purposes.
2.44 The company will take reasonable and necessary measures to select, manage, and ensure the security of service providers handling personal information, in accordance with the nature of the service and applicable laws.
2.45 If personal information is processed or transferred across borders due to the use of cloud services, payment services, communication services, or other international technical services, the company will manage it in accordance with applicable Japanese laws and the provisions of this policy regarding third-party provision and cross-border processing.
2.46 The company may not use personal information for new purposes that are clearly unrelated to customers' reasonable expectations, based solely on general terms such as 'business needs' or 'improving services' in this policy.
2.47 If the Company intends to use the personal information it has already collected for a new purpose that is significantly different from the original processing purpose, the Company will determine whether it is necessary to notify the customer, amend this policy, obtain the customer's consent, or take other necessary measures in accordance with applicable Japanese law.
2.48 This company only retains personal information for a period that is reasonably necessary to achieve the relevant processing purposes; the specific retention period will be determined based on order fulfillment, accounting and tax requirements, payment disputes, insurance, complaint handling, security management, legal obligations, and other actual needs.
2.49 When personal information no longer has a reasonable need for retention, the company will, in accordance with applicable laws, business nature, and technical conditions, take measures such as deletion, anonymization, de-identification, or other appropriate handling, except where laws require continued retention.
2.50 The purposes and processing methods of personal information listed in this section are carried out only within the scope permitted by Japanese applicable laws. The company will not use this policy to exclude or limit customers' legally entitled rights to personal information protection.
Sharing, Entrusting Processing, and Providing Personal Information to Third Parties
3.1 In principle, the company will not sell, rent, exchange, or disclose customer personal information to third parties without reasonable grounds. Personal information will only be shared, entrusted for processing, or provided to third parties within the necessary scope when providing services, performing contracts, processing payments, ensuring security, resolving disputes, fulfilling legal obligations, or having other legitimate grounds.
3.2 To fulfill the transportation service for customer bookings, the company may provide necessary order information to drivers, dispatchers, vehicle operators, and other service personnel who are actually involved in the execution of the order, within a reasonable and necessary scope.
3.3 The information that may be provided includes but is not limited to:
(1) Customer or main passenger name; (2) Contact phone number; (3) WhatsApp or other necessary contact information; (4) Service date and time; (5) Pick-up location; (6) Destination; (7) Flight number and flight time; (8) Hotel, station, airport, or cruise terminal information; (9) Number of passengers; (10) Number of children and child safety seat requirements; (11) Number of luggage and special luggage information; (12) Service route and stopover locations; (13) Other information reasonably necessary to complete this order.
3.4 When the company provides personal information to drivers or other actual service personnel, the scope of the information should be limited to a reasonable and necessary extent for completing the relevant order, and customer information unrelated to the execution of the order should not be provided without a reasonable purpose.
3.5 Drivers and other personnel actually providing the service should only use the customer's personal information obtained for completing relevant orders, safety management, customer communication, and other legitimate purposes directly related to the service. They must not use such information for private marketing, resale, harassing customers, or any other purposes unrelated to the order.
3.6 If due to vehicle scheduling, regional operations, vehicle type demand, vehicle malfunction, driver adjustments, or other reasonable operational reasons, it is necessary for our company's legally authorized cooperative transportation service providers to participate in executing orders, our company may provide them with relevant order information within the scope necessary to complete the service.
3.7 The company shall take reasonable and necessary management measures for partners handling customer personal information, in accordance with the nature of the partnership and applicable Japanese laws, and require them to process the relevant information only within the agreed and lawful purposes.
3.8 The company may entrust third-party service providers to assist with website operations, process orders, send emails, provide customer communication tools, maintain servers, store data, process payments, perform system maintenance, provide cybersecurity services, or carry out other necessary business functions.
3.9 The third-party service providers mentioned above may include but are not limited to:
(1) Website server and cloud computing service providers; (2) Website hosting and database service providers; (3) Email sending and email system service providers; (4) Customer relationship management and customer communication service providers; (5) Instant messaging and communication service providers; (6) Payment processing and credit card payment service providers; (7) Banks and financial institutions; (8) Accounting, tax, and audit service providers; (9) IT development, maintenance, and cybersecurity service providers; (10) Data backup and disaster recovery service providers; (11) Map, address positioning, and route planning service providers; (12) Website analytics and performance monitoring service providers; (13) Other necessary service providers required to participate in business operations in accordance with the law.
3.10 When providing personal information to entrusted service providers, the company shall only provide information that is reasonably necessary to complete the entrusted business, and shall implement reasonable and necessary supervisory and security measures in accordance with the nature of the service, contractual relationship, technical conditions, and applicable laws.
3.11 The entrusted service provider shall not use the customer's personal information for purposes unrelated to the entrusted business merely because it has technical access to the company's data, except in cases where it legally processes the relevant information based on an independent legal relationship between the service provider and the customer.
3.12 When customers pay using credit cards, debit cards, e-wallets, or other online payment methods, the payment transaction may be processed by professional payment service providers, acquirers, card networks, issuing banks, or other financial institutions.
3.13 To complete payment, confirm transactions, prevent fraud, process refunds, and handle payment disputes such as chargebacks, the company and related payment institutions may process order numbers, transaction amounts, currency, payment status, transaction numbers, and other necessary payment-related information within the necessary scope.
3.14 Complete credit card numbers, security codes (CVV), credit card passwords, or other highly sensitive payment credentials should, in principle, be handled by payment service providers that comply with relevant security standards. In principle, the company does not actively retain complete sensitive payment credentials that are not necessary for completing the business.
3.15 Payment service providers, banks, credit card organizations, and other financial institutions may independently process certain personal information based on their own legal obligations, privacy policies, anti-fraud rules, and financial regulatory requirements. The relevant institutions shall bear the corresponding legal responsibilities for their independent processing actions.
3.16 If a customer makes a booking through a travel agency, OTA, agent, corporate client, hotel, travel platform, or other third-party channel, the company may receive necessary customer and passenger information from the relevant third party to complete the transportation service.
3.17 In the aforementioned circumstances, the company may provide the original booking channel with necessary information related to order confirmation, service execution, modification, cancellation, refund, complaint handling, or dispute resolution.
3.18 Third-party travel agencies, OTA platforms, agents, or other booking platforms may independently process customers' personal information according to their own privacy policies and legal relationships with customers. The company does not control the independent processing of personal information by such third parties, but the company remains responsible for its own legal obligations regarding the processing of personal information.
3.19 If the customer books through a third-party platform themselves, it is recommended that the customer also read the relevant privacy policy of that third-party platform to understand how the platform handles the customer's personal information.
3.20 If a traffic accident, passenger injury, vehicle damage, property loss, insurance claim, or other event requiring insurance handling occurs, the company may provide necessary information to insurance companies, insurance agencies, accident investigation agencies, or other relevant institutions within the scope reasonably necessary for handling the accident and insurance matters.
3.21 If an emergency medical assistance situation occurs, to protect the life and physical safety of the customer, passengers, drivers, or other individuals, the company may provide necessary information to fire services, ambulance services, medical institutions, police, or other emergency service agencies within the scope permitted by Japanese applicable law.
3.22 If this company receives a lawful request from a court, police, tax authority, administrative agency, regulatory body, or other public authority legally authorized to do so, the company may provide the relevant personal information within the necessary scope as required by applicable Japanese law.
3.23 When this company receives a request for information from a government agency or other public institution, it will verify the legality, authority, and necessary scope of the request to the extent reasonably feasible, and will not unconditionally disclose all customer information solely because a third party has made a request.
3.24 If necessary for the company to establish, exercise, or protect its legitimate rights, to handle contract disputes, traffic accidents, payment disputes, chargebacks, fraud investigations, litigation, arbitration, or other legal proceedings, the company may provide necessary information to lawyers, judicial scrivener, accountants, insurance companies, payment institutions, courts, or other professional institutions legally involved in the relevant matters.
3.25 In the aforementioned circumstances, the company shall limit the information provided to the scope reasonably necessary for handling the specific dispute or legal matter.
3.26 If a customer raises a Chargeback or other payment dispute with the credit card company, bank, payment service provider, or other institution, the company may submit to the relevant institution the information necessary to prove the transaction and service circumstances in accordance with applicable laws.
3.27 The aforementioned data may include order confirmation information, payment records, order terms accepted by the customer, cancellation time, driver scheduling records, driver arrival records, waiting time, vehicle operation records, GPS data (if applicable), emails, WhatsApp or other communication records directly related to the dispute, and service completion status.
3.28 The company shall not provide excessive personal information that is clearly unrelated to the specific dispute to banks or payment institutions for the purpose of handling payment disputes.
3.29 If a customer requests the company to assist in locating or retrieving lost items, the company may provide necessary information to drivers, hotels, transportation companies, courier companies, postal service providers, or other relevant parties involved in the handling of the lost items, as needed.
3.30 If a customer requests that lost items be mailed or delivered to a specified address, the company may provide the recipient's name, address, phone number, and any other information necessary to complete the delivery to the postal, courier, or delivery service provider responsible for the transportation.
3.31 The company may use cloud services, email services, payment services, communication tools, data analysis services, or other technical services located outside Japan or operated in multiple countries and regions.
3.32 By using the aforementioned services, customer personal information may be stored, accessed, processed, or transmitted to servers, data centers, or countries or regions where relevant service providers are located outside of Japan.
3.33 If personal information involves providing it to a third party outside Japan or processing it across borders, the company will handle it appropriately in accordance with Japan's applicable personal information protection laws, including the service providers, recipients, systems of the country or region where they are located, and applicable protective measures.
3.34 When applicable laws in Japan require obtaining customer consent, providing relevant information, confirming the recipient's protective measures, or performing other procedures, the company will take necessary measures in accordance with the law.
3.35 The company shall not unlimitedly transfer customer personal information to any country, region, or third party solely on the grounds of 'using international services'.
3.36 The company may use map, navigation, address search, or route planning services to confirm pickup locations, dispatch vehicles, and arrange routes. When using these services, location information necessary to complete address queries or route planning may be processed by the relevant technical service providers.
3.37 The company should make every effort to avoid sending customer identity information to map, navigation, or other technical service providers when such information is not necessary for the completion of relevant functions.
3.38 If this website uses visitor analytics, website performance analytics, error monitoring, or similar services, the relevant service providers may process IP addresses, device information, browser information, cookie identifiers, access times, and website usage information based on technical requirements.
3.39 The primary purposes for which this company uses related analytical services include understanding website operations, identifying technical issues, enhancing security, analyzing page usage, and improving customer experience.
3.40 If customer consent is required by law for any Cookies, advertising technologies, or analytical technologies, the company will implement necessary consent management measures in accordance with applicable laws.
3.41 Without a legitimate basis, the company will not, in principle, sell customer names, phone numbers, email addresses, WhatsApp contact information, trip information, or other information that can directly identify individuals to third parties unrelated to the company's transportation services, website operations, payment processing, customer support, or legal obligations.
3.42 The company will not sell customer ride records, flight information, hotel information, route information, or contact information as a commercial list, even if a third party is willing to pay a fee.
3.43 If this company undergoes a merger, corporate split, business transfer, organizational restructuring, or other legally permitted business transaction in the future, personal information related to the affected business may be inherited or transferred along with the relevant business within the scope permitted by Japanese applicable law.
3.44 The business transactions mentioned above do not automatically permit the use of personal information for purposes entirely unrelated to the original collection purpose. The party inheriting the relevant personal information remains subject to the corresponding protection obligations under applicable laws and in accordance with the relevant processing purposes.
3.45 If a customer books on behalf of other passengers, the company may provide necessary service information to accompanying passengers, primary contact persons, or other relevant parties of the order within the scope necessary to complete the order, but care should be taken to avoid disclosing unnecessary personal information to unauthorized persons.
3.46 If a third party inquires with the company about whether a customer has an order, hotel stay, travel route, contact information, or other personal information, the company will generally not disclose such information solely based on the inquiry.
3.47 For the aforementioned inquiries, the company may request reasonable verification of identity or authorization based on specific circumstances; if it is not possible to reasonably verify the identity, authorization, or other legal basis of the inquirer, the company may refuse to provide the relevant personal information.
3.48 Staff, drivers, partners, and entrusted service providers of our company should be granted information access permissions according to their actual work needs when handling customer personal information, to prevent unauthorized access by individuals without business-related requirements.
3.49 If the Company discovers that entrusted service providers, partners, or other information recipients may be using, disclosing, or otherwise improperly handling personal information without authorization, the Company will take investigative, access restriction, suspension of provision, remediation requirements, or other necessary measures within the scope that is reasonably feasible and required by law.
3.50 If there is a breach, loss, damage, or unauthorized access to personal information that may affect the rights and interests of customers, the company will take necessary measures in accordance with applicable Japanese laws, including investigation, risk control, reporting, and notification.
3.51 Customers may make corresponding requests regarding personal information held by the company, as well as records provided by third parties that may be legally requested for disclosure, in accordance with subsequent sections of this Privacy Policy and applicable Japanese laws.
3.52 The company may legally retain necessary records related to the sharing of personal information, entrusted processing, or information provided by third parties, in order to fulfill legal obligations, resolve disputes, ensure security management, and demonstrate the legitimacy of related processing.
3.53 The terms 'sharing', 'entrusted processing', 'third-party provision', and 'cross-border processing' mentioned in this section shall be determined in accordance with the actual processing relationship and applicable Japanese law, and shall not be altered in terms of legal liability or obligations merely due to the use of a general term in this policy.
3.54 The company may not avoid the requirements of Japanese applicable law regarding the provision of personal information to third parties, cross-border provision, consent of the individual, security management, or supervisory obligations by referring to personal information processing activities as 'entrustment,' 'collaboration,' or other terms.
3.55 Nothing in this section shall be interpreted as granting the company unlimited rights to disclose customer personal information. The sharing, outsourcing, provision to third parties, and cross-border processing of all personal information shall have reasonable purposes and appropriate legal basis, and shall be limited to the extent necessary to achieve the relevant purposes.
3.56 The provisions in this section shall be implemented only within the scope permitted by Japanese law. If mandatory Japanese laws regarding the protection of personal information impose stricter requirements on personal consent, third-party provision, cross-border provision, record-keeping, security management, or other matters, the relevant legal provisions shall be followed.
Retention Period, Deletion, and Anonymization of Personal Information
4.1 Our company will only retain customer personal information for a reasonable period necessary to achieve the purposes of personal information processing described in this Privacy Policy, fulfill transportation services, handle customer inquiries and complaints, perform contracts, process payments and refunds, resolve disputes, comply with tax and accounting requirements, fulfill legal obligations, and protect the legitimate rights and interests of our company. 4.2 Our company will not indefinitely retain customer personal information without a reasonable business purpose or legal basis. The specific retention period will be determined based on the type of personal information, purpose of use, order status, legal requirements, dispute risks, and the reasonable business needs of our company. 4.3 Information related to customer orders and transportation services, including but not limited to customer name, contact information, service date, pickup location, destination, number of passengers, luggage information, flight information, vehicle arrangements, driver arrangements, order amount, payment status, and service completion records, may be retained by our company for a reasonable period after the service is completed. 4.4 The purposes for retaining the order information mentioned in the previous paragraph include but are not limited to: (1) Handling customer after-sales inquiries; (2) Processing order modifications, cancellations, and refunds; (3) Handling customer complaints; (4) Confirming actual service conditions; (5) Handling lost items; (6) Handling traffic accidents and insurance matters; (7) Handling payment disputes and chargebacks; (8) Preventing fraud or duplicate disputes; (9) Fulfilling accounting, tax, and auditing obligations; (10) Establishing, exercising, or protecting the legitimate rights of our company; (11) Fulfilling applicable legal requirements in Japan. 4.5 Records related to payments, refunds, transactions, and finances may be retained by our company for the statutory or reasonably necessary period in accordance with applicable Japanese accounting, tax, corporate management, and other legal requirements. 4.6 Even if a customer has canceled an order, completed an order, or stopped using our company's services, if relevant transaction information must be retained by law, our company may continue to retain the relevant information within the legally prescribed or reasonably necessary period. 4.7 In principle, our company will not proactively retain complete bank card numbers, bank card security codes (CVV), bank card passwords, or other highly sensitive payment credentials that are not necessary to complete the transaction for the purpose of business record retention. 4.8 If a customer completes payment through a third-party payment service provider, some payment information may be retained by the relevant payment service provider in accordance with its own legal obligations, data retention policies, and security rules. Our company cannot directly control the data retained independently by third-party payment service providers in accordance with the law. 4.9 Our company may retain emails, WhatsApp messages, website inquiry records, order messages, and other necessary communication records related to customer services. 4.10 The communication records mentioned in the previous paragraph may be used to confirm customer requests, prove order modifications or cancellations, resolve complaints, process refunds, confirm pickup times and locations, handle no-show disputes, manage chargebacks, and resolve other service-related disputes. 4.11 Communication records related to specific orders may be retained together with the relevant order information as needed. 4.12 For communication information that is clearly temporary, unrelated to order execution or legal obligations, and has lost business necessity, our company may regularly delete or clean it according to internal management rules. 4.13 Personal information related to traffic accidents, vehicle damage, passenger injuries, insurance claims, police investigations, litigation, arbitration, payment disputes, or other legal disputes may be retained by our company until the relevant matters are finally resolved and the applicable statutory rights exercise period expires. 4.14 If our company reasonably foresees that a particular order may lead to litigation, chargebacks, insurance claims, complaints, investigations, or other disputes, even if the relevant information could normally be deleted according to internal retention rules, our company may still suspend the deletion of the relevant information for the period reasonably necessary to handle the matter. 4.15 The aforementioned suspension of deletion should only apply to information reasonably related to specific disputes or legal matters and should not serve as a basis for indefinitely retaining all customer information. 4.16 If a court, police, tax authority, administrative agency, regulatory agency, or other legally authorized agency requests our company to retain relevant information, our company may extend the retention period of the relevant information in accordance with applicable laws and legal requirements. 4.17 For customer account information, if this website provides customer account functionality, our company may retain the necessary information to maintain the account and provide related functions during the account's existence. 4.18 After a customer cancels their account, our company will delete, anonymize, or otherwise appropriately handle information that is no longer needed based on the nature of the information and applicable laws; however, this does not apply to information that must be retained by law or is necessary for processing existing orders, disputes, payments, taxes, and other legal matters. 4.19 Customers have the right to request the deletion, cessation of use, cessation of third-party provision, or other legally permitted requests regarding the relevant personal information held by our company in accordance with applicable personal information protection laws in Japan. 4.20 When a customer requests the deletion of personal information, our company may require the customer to provide reasonable and necessary information to confirm the identity of the requester and whether they have the right to make the relevant request. 4.21 After reasonably completing identity verification, if the relevant personal information is no longer necessary for continued processing or retention, and there are no legal requirements or other lawful bases for retention, our company will take deletion, cessation of use, anonymization, or other appropriate measures in accordance with applicable laws in Japan. 4.22 A customer's request for deletion does not automatically mean that our company must immediately delete all information related to that customer. 4.23 In the following circumstances, our company may be legally unable to immediately delete all or part of the personal information: (1) Japanese law requires continued retention; (2) Accounting, tax, or audit records must be retained by law; (3) The order has not been completed; (4) Refunds have not been completed; (5) Payment disputes or chargebacks have not been resolved; (6) Traffic accidents or insurance claims have not been resolved; (7) Customer complaints or other disputes have not been resolved; (8) There are ongoing or reasonably anticipated litigation, arbitration, investigations, or other legal proceedings; (9) It is necessary to retain information within the legal limits to prevent fraud, duplicate refunds, or abuse of services; (10) It is necessary to establish, exercise, or protect legal rights; (11) Other situations permitted or required by applicable Japanese laws to continue retention. 4.24 If a customer requests deletion but some information must continue to be retained by law or based on other legal grounds, our company may delete the parts that do not need to be retained and restrict the use of the parts that must continue to be retained. 4.25 For information retained for legal, tax, accounting, dispute resolution, or other legitimate reasons, our company will not, in principle, use it for marketing or other unnecessary purposes unrelated to the retention purpose. 4.26 Our company may regularly review personal information that has exceeded the reasonable retention period, lost its purpose of use, and lacks legal grounds for continued retention, and take deletion, destruction, de-identification, anonymization, or other appropriate measures based on actual circumstances. 4.27 When deleting electronic data, our company will take appropriate measures based on system structure, data type, technical conditions, and reasonable security standards to ensure that the relevant data can no longer be used through normal business systems. 4.28 When destroying paper documents containing personal information, our company may take shredding, secure destruction, or other reasonable methods based on the sensitivity of the materials to reduce the risk of unauthorized recovery or use of personal information. 4.29 Due to database backups, server backups, disaster recovery systems, security logs, or other technical reasons, deleted information may continue to exist in the backup system for a certain period. 4.30 For the backup data mentioned in the previous paragraph, our company may not be able to immediately delete a specific customer's information from each historical backup after a deletion request is made by the customer. 4.31 Our company shall take reasonable access restrictions and security management measures for backup data. Relevant backups exceeding the established retention period shall be processed according to our company's backup rotation, overwriting, deletion, or destruction mechanisms. 4.32 If historical backups containing previously deleted or restricted information are reloaded due to system recovery, our company will take necessary measures within reasonable feasibility to prevent the relevant information from re-entering unnecessary daily processing workflows. 4.33 Our company may, in legally and reasonably necessary cases, de-identify, aggregate, or anonymize some data for business analysis, service improvement, operational statistics, demand forecasting, security analysis, and other legitimate purposes. 4.34 If the relevant data has been processed to the extent that specific individuals can no longer be reasonably identified, our company may manage and use it in accordance with applicable Japanese laws as anonymous processed information, statistical information, or other corresponding legal categories. 4.35 Our company shall not consider data that can still easily identify specific customers through phone numbers, emails, order numbers, precise itineraries, or other information as sufficiently anonymized merely by deleting customer names. 4.36 When conducting anonymization or de-identification processing, our company shall take reasonable and necessary measures based on the nature of the data, re-identification risks, processing purposes, and applicable laws. 4.37 In principle, our company will not unreasonably re-match anonymized data that has been processed in accordance with the law and should not be re-identified with other information, unless permitted or required by applicable Japanese laws. 4.38 Our company may retain access logs, security logs, login records, IP addresses, device information, error logs, and other technical data generated by the operation of the website and system to ensure the security of the website and system, prevent unauthorized access, investigate system failures, and prevent fraud. 4.39 The technical information mentioned in the previous paragraph shall have a reasonable retention period determined based on its security purpose, risk level, and legal requirements, and shall be deleted, overwritten, anonymized, or otherwise appropriately processed when it no longer has reasonable security or business necessity. 4.40 If our company discovers that personal information has become inaccurate due to errors, duplicate records, or other reasons, our company may make corrections, updates, merges, deletions, or other necessary processing based on actual circumstances. 4.41 Customers may also request our company to correct, supplement, or delete personal information that should be corrected in accordance with this Privacy Policy and applicable Japanese laws. 4.42 If a customer only requests to modify their phone number, email, pickup address, flight number, or other order information, whether this request constitutes a correction of personal information and whether it simultaneously constitutes an order modification shall be handled separately based on the specific circumstances. 4.43 Customers may not request our company to destroy accounting records, transaction records, accident materials, litigation evidence, or other information that must be retained by law through personal information deletion requests. 4.44 Similarly, our company shall not indefinitely refuse customer requests for deletion, cessation of use, or other personal information rights requests based solely on "internal records," "company policy," or "system needs" without reasonable purpose or legal basis. 4.45 If a customer requests deletion, cessation of use, or other related requests for personal information, our company will review and process the requests based on the request content, information nature, and applicable Japanese laws after completing the necessary identity verification. 4.46 If our company legally decides that it cannot fully meet the customer's request, it will explain to the customer the reasons or relevant basis for not being able to fully process the request in accordance with applicable legal requirements. 4.47 If personal information has been lawfully provided to a third party, when a customer requests deletion or cessation of provision to the third party, our company will determine whether to take necessary measures such as ceasing provision, notifying relevant parties, or other necessary actions based on applicable Japanese laws and the actual processing relationship. 4.48 For information controlled and processed by third parties based on their own independent legal relationships, such as banks, credit card companies, payment service providers, OTAs, or other independent data processors, customers may need to make corresponding requests directly to the relevant third parties. 4.49 The measures taken by our company regarding the retention, deletion, destruction, anonymization, and backup management of personal information shall be commensurate with the sensitivity of the information, the scale of processing, technical feasibility, potential risks, and the nature of our company's business. 4.50 Our company will conduct necessary reviews and adjustments of personal information retention and deletion rules based on changes in business systems, legal regulations, security risks, and actual operating conditions. 4.51 The retention periods specified in this chapter do not imply that all categories of personal information will adopt the same retention period. Different materials may apply different retention periods based on legal obligations, business purposes, and risk situations. 4.52 If applicable Japanese laws specify clear minimum or maximum retention periods for specific personal information, transaction data, accounting data, tax data, accident data, or other records, our company will prioritize compliance with relevant mandatory legal provisions. 4.53 Our company shall not use this chapter as a basis to evade the personal information rights that customers enjoy under applicable Japanese laws. 4.54 All provisions in this chapter shall be executed only within the scope permitted by applicable Japanese laws. In case of conflict between this chapter and mandatory legal provisions related to personal information protection in Japan, the relevant mandatory legal provisions shall prevail.
Measures for the Secure Management of Personal Information
5.1 To prevent the leakage, loss, damage, alteration, unauthorized access, improper use, or other security incidents involving customer personal information, the company will implement reasonable and necessary organizational, personnel, physical, and technical security management measures based on the nature, quantity, usage purpose, storage method, and related risks of the personal information being processed.
5.2 Our company will establish reasonable security management systems for personal information in accordance with Japan's Personal Information Protection Act and other applicable laws and regulations. We will conduct necessary inspections, maintenance, and improvements to relevant security measures based on business content, technical environment, and changes in risks.
5.3 The company will make reasonable efforts to ensure that only directors, employees, drivers, dispatchers, customer service personnel, financial personnel, system administrators, and authorized personnel who have a legitimate need to access personal information for the performance of their duties may access such information within the scope necessary for their roles.
5.4 The company may set different access permissions for internal systems, order backend systems, customer management systems, email, cloud services, servers, file storage systems, and other systems involving personal information, based on actual business needs.
5.5 In principle, our company assigns access rights to personal information based on the principles of 'business necessity' and 'minimum necessary authority,' ensuring that individuals without business-related needs do not come into contact with customer personal information unrelated to their responsibilities.
5.6 For personnel who have resigned, been transferred, no longer participate in related business, or no longer require access to personal information for other reasons, the company will promptly revoke, suspend, or adjust their access rights to related systems and data within a reasonable and feasible scope.
5.7 The company may implement password protection, identity verification, multi-factor authentication, access restrictions, login management, or other appropriate identity authentication measures for accounts involving personal information, based on the importance of the system and technical conditions.
5.8 Personnel who obtain access to our company's systems must not provide, share, sell, rent, or disclose their accounts, passwords, verification codes, authentication information, or other access credentials to others without authorization.
5.9 If an account, password, device, or other access credentials are suspected to have been compromised, leaked, or used without authorization, the relevant parties should promptly report this to the company. The company may take necessary security measures such as changing passwords, freezing accounts, terminating sessions, revoking permissions, or other actions based on the actual situation.
5.10 The company may retain necessary login records, operation records, access logs, abnormal access records, or other security logs based on the system's nature and technical feasibility, for system maintenance, security investigations, fraud prevention, and handling of personal information security incidents.
5.11 Regarding customer order information, contact details, itinerary information, driver arrangements, payment status, and other business data, the company will set appropriate access permissions based on actual business needs and will make every effort to prevent irrelevant personnel from obtaining unnecessary information.
5.12 When providing customer information to drivers, our company will, in principle, only provide information that is reasonably necessary to complete the relevant transportation service, including but not limited to passenger names, contact numbers, WhatsApp or other necessary contact information, pickup time, pickup location, destination, flight information, number of passengers, luggage information, and special requirements directly related to the service.
5.13 Drivers, guides, cooperating transportation personnel, and other individuals who receive customer information to complete specific orders must not use the relevant personal information for private purposes, marketing purposes, or other unauthorized purposes outside of executing the order.
5.14 The company may require employees, drivers, contractors, collaborators, and other personnel who have the opportunity to come into contact with personal information to comply with confidentiality obligations, internal management rules, and personal information security requirements.
5.15 Without our company's authorization, relevant personnel must not take unauthorized photographs, copy, download, export, print, forward, disclose, or disseminate customer personal information through private social media, except in cases where it is reasonably necessary to complete the service.
5.16 For customer information processed via email, WhatsApp, phone, SMS, or other instant messaging tools, the company will implement reasonable management measures based on actual business needs and require relevant personnel to avoid sending customer information to individuals unrelated to the order.
5.17 In cases where it is necessary to establish communication groups among customers, drivers, dispatchers, or other service personnel, the company shall limit the use of personal information within the group to the extent necessary to complete the relevant order and essential post-sale processing.
5.18 After the order is completed, if there is no further business necessity for the relevant instant messaging group or communication channel, the company may, based on actual operational circumstances, discontinue, close, exit, delete, or restrict further use of the related groups and data, except for records that must be retained in accordance with laws or for dispute resolution.
5.19 The company will take reasonable security measures to protect office computers, mobile devices, servers, databases, cloud storage, backend management systems, and other devices or systems that may store personal information, based on actual circumstances.
5.20 The aforementioned security protection measures may include but are not limited to password protection, device locking, access control, firewalls, security updates, malware protection, data backup, logging, permission management, communication encryption, and other technical measures appropriate to the level of risk.
5.21 The company will make reasonable efforts to promptly install or implement important security updates, vulnerability patches, or other necessary security measures related to the systems in use, in order to reduce the risk of known security vulnerabilities being exploited.
5.22 The company will reasonably back up important business data based on the needs of business continuity and data security, and determine the backup method, backup frequency, and retention period according to the importance of the data, system environment, and actual operational needs.
5.23 Regarding backup data, the company will implement appropriate access control and security measures based on actual technical conditions to reduce the risk of unauthorized access, copying, modification, or leakage of backup files.
5.24 The company shall make reasonable efforts to avoid storing databases, order files, or other sensitive information containing a large amount of customer personal information on unauthorized personal devices or public storage spaces for a long time without reasonable security measures.
5.25 If it is necessary for actual business purposes to use laptops, mobile phones, tablets, or other mobile devices to process customer information, the company may implement reasonable security measures such as passwords, screen locks, authentication, remote management, or other measures based on the nature of the device.
5.26 If devices used for processing personal information are lost, stolen, or at risk of unauthorized access, the company will take reasonable measures such as account freezing, password changes, remote logout, remote deletion, revocation of access rights, or other appropriate actions based on the specific circumstances.
5.27 For customer information, order information, accident information, accounting information, or other documents containing personal information that are stored in paper form, the company will implement reasonable measures for storage and access restrictions based on the nature of the documents.
5.28 For paper-based personal information that is no longer required to be retained, the company may process it in a manner appropriate to the sensitivity of the data, such as shredding, secure destruction, or other reasonable methods, to reduce the risk of unauthorized recovery or use of the information.
5.29 When transmitting personal information over the internet, the company may adopt HTTPS, TLS, or other reasonable encryption communication measures based on the technical conditions of the relevant systems and services, in order to reduce the risk of data being illegally intercepted, altered, or stolen during transmission.
5.30 For particularly important account credentials, system administrator permissions, database access permissions, and other high-risk permissions, the company may implement stricter access control and authentication measures than those for regular accounts.
5.31 In principle, the company will not request customers to send complete bank card passwords, bank card security codes (CVV), or online banking passwords through regular email, WhatsApp, SMS, or other methods unsuitable for transmitting highly sensitive payment credentials.
5.32 If a customer voluntarily sends highly sensitive information to the company through an insecure channel, the company may request the customer to stop sending it and, where reasonably feasible, delete, obscure, or otherwise appropriately handle the relevant information.
5.33 When the company processes personal information using external servers, cloud services, email services, payment services, website technical services, communication services, or other third-party systems, it will select service providers with appropriate security measures within a reasonable and feasible scope.
5.34 For third parties entrusted by the company to process personal information, the company may require them to take reasonable measures to protect personal information through contracts, service terms, confidentiality obligations, access controls, or other appropriate means, depending on the nature of the service, the category of information processed, and the associated risks.
5.35 For systems and security measures independently controlled by third-party service providers, the company cannot guarantee that any third-party system will absolutely not experience failures, cyberattacks, data breaches, or other security incidents. However, the company will fulfill reasonable selection, supervision, and other necessary obligations within the scope required by Japanese applicable laws.
5.36 The company will not exempt itself from its legal obligations to protect personal information on the grounds of 'use of third-party systems'.
5.37 If a third-party service provider experiences a security incident that may affect the personal information of our customers, we will take reasonable and necessary measures such as investigation, risk control, notification, or other appropriate actions in accordance with the nature of the incident, the scope of impact, and applicable Japanese laws after becoming aware of the relevant situation.
5.38 The company may provide education or reminders on personal information protection, security management, confidentiality obligations, phishing prevention, password security, and other necessary matters to employees and other relevant personnel as needed for business operations.
5.39 The company may conduct regular or irregular inspections of the personal information processing procedures, access permissions, security measures, and related internal systems, based on the scale of personal information processing, business risks, and actual circumstances.
5.40 If during the inspection, it is found that the management of personal information poses significant security risks, the company will take reasonable corrective actions, adjust permissions, repair systems, improve processes, or implement other necessary measures based on the level of risk and technical feasibility.
5.41 If the company discovers or reasonably suspects a personal information security incident, such as leakage, loss, damage, unauthorized access, malicious attacks, account intrusion, incorrect transmission, or other similar events, the company will conduct necessary investigations based on the nature of the incident and the level of risk.
5.42 The company may take control measures including but not limited to stopping access to related systems, modifying account passwords, revoking access permissions, isolating affected systems, saving related logs, contacting technical service providers, preventing further leaks, and other reasonable measures based on the investigation.
5.43 If a personal information security incident meets the conditions requiring reporting under applicable Japanese laws to the Personal Information Protection Commission or other relevant authorities, the company will fulfill the corresponding reporting obligations in accordance with applicable laws.
5.44 If a personal information security incident meets the conditions requiring notification to relevant customers or individuals under applicable Japanese laws, the company will notify affected individuals in a manner required by law and practically feasible.
5.45 The aforementioned notice may, depending on the actual situation, include a summary of the incident, the categories of information potentially involved, the potential impact, measures already taken or planned to be taken by the company, and reasonable protective measures that customers can take.
5.46 When handling personal information security incidents, the company may cooperate with server providers, payment service providers, cybersecurity service providers, insurance companies, lawyers, police, regulatory authorities, or other necessary third parties as needed, but only to the extent that it is legally and reasonably necessary to provide relevant information.
5.47 Customers should also take reasonable measures to protect their own account, email, mobile phone, WhatsApp, and other contact information and devices related to our company's services.
5.48 Risks arising from customers voluntarily disclosing account passwords, verification codes, order information, or other personal information to unrelated third parties, or from unauthorized access to customers' own devices, accounts, or communication tools, shall be determined based on specific facts, both parties' responsibilities, and applicable Japanese law.
5.49 The company will not rely on this provision to exempt itself from legal liability for damages to personal information caused by the company's intentional acts, gross negligence, or other actions for which exemption is legally prohibited.
5.50 If customers discover that their account, order information, contact details, or other personal information related to this company may have been used without authorization, they should notify this company as soon as possible through the contact methods published by this company, so that this company can take necessary measures based on the actual situation.
5.51 Although the company takes reasonable security measures, no internet communication, electronic storage, cloud computing, mobile communication, or information system can guarantee absolute security or completely eliminate technical failures, cyberattacks, and other risks.
5.52 The provisions mentioned above should not be interpreted as a general exemption of the company from liability for the security of personal information. The company will still assume corresponding legal liability within the scope of Japanese applicable laws, based on the cause of the incident, foreseeability, security measures taken, and the actual liability of the company.
5.53 The company will review and update its personal information security measures as necessary, based on business development, technological changes, new cybersecurity risks, the scale of personal information processing, and changes in Japanese laws and regulations.
5.54 The security measures implemented by the company should be appropriate to the nature, quantity, processing purpose, and potential risks of the personal information being handled, and should be continuously improved within a reasonable and feasible scope.
5.55 If a customer legally requests information about the security measures the company has taken regarding their personal information, the company may provide an appropriate explanation within the scope that does not affect the company's information security, does not disclose third-party secrets, does not disclose technical details that could be used to attack the system, and is permitted under applicable Japanese law.
5.56 All safety management, liability limitations, and third-party service regulations in this section shall be implemented only within the scope permitted by Japanese law, and shall not exclude or limit consumer rights, personal information rights, or the company's legally mandated responsibilities that cannot be excluded or limited under Japanese mandatory laws.
Cookies, Website Analytics, and Similar Technologies
6.1 This website may use Cookies, local storage, pixel tags, log files, website analytics tools, and other similar technologies to ensure the normal operation of the website, save necessary settings, enhance website security, analyze website usage, improve user experience, and support related business functions.
6.2 Cookies are small data files stored on the customer's device by the website, which can be used to identify the browser, save language settings, maintain login status, record user preferences, support shopping or booking processes, and complete other necessary functions.
6.3 The company may use strictly necessary Cookies to enable the basic functions of the website, including but not limited to:
(1) Maintain normal website operation; (2) Save language and region settings; (3) Maintain customer login status; (4) Support order submission and payment process; (5) Prevent malicious attacks, fraud, or abnormal access; (6) Ensure website and account security; (7) Record necessary session status; (8) Provide other basic website functions that customers actively use.
6.4 For cookies necessary to enable the basic functionality of the website, if Japanese applicable law allows their use without obtaining additional consent, the company may use them within a reasonable and necessary scope.
6.5 The company may use website analytics tools to collect access and usage information, in order to understand website page views, user navigation paths, device categories, browser types, sources of visits, page dwell time, technical errors, and other website performance information.
6.6 The main purposes of website analysis include:
(1) Understand overall website usage; (2) Identify page or system issues; (3) Improve page loading speed; (4) Optimize website structure and user experience; (5) Analyze potential issues in the order process; (6) Enhance website security; (7) Improve service content and technical performance.
6.7 Website analytics tools may process IP addresses, device information, browser information, visited pages, visit times, referring pages, cookie identifiers, and other related technical data.
6.8 Wherever possible, the company will make reasonable efforts to minimize the direct identification of specific customers and may process analytical data using aggregated, de-identified, or other appropriate methods to achieve the analytical objectives.
6.9 If this website uses third-party website analytics services, the relevant third parties may process certain website access data according to their technical and legal arrangements. The company will manage the relevant services reasonably in accordance with applicable Japanese laws and this Privacy Policy.
6.10 The company may use error monitoring, performance monitoring, and network security tools to detect website crashes, interface anomalies, server errors, malicious access, abnormal logins, network attacks, and other technical issues.
6.11 The aforementioned tools may automatically collect device information, browser information, network information, IP addresses, error logs, and other technically necessary data.
6.12 The company may use map, address search, route calculation, positioning, and navigation-related technologies to help customers input pickup locations and destinations, calculate routes, confirm service areas, and complete vehicle scheduling.
6.13 When using map or address services, location information entered by customers may be processed by the relevant map or technical service providers. The company will make every effort to avoid sending customer identification information to the relevant service providers that is unnecessary for achieving address or route functions.
6.14 This website may use third-party payment technology to help customers complete credit card, electronic wallet, or other payment methods. The payment page may use Cookies or similar technologies for security verification, risk control, payment status management, and fraud prevention.
6.15 Information generated by relevant payment technologies may be independently processed by the payment service provider in accordance with its own legal obligations, privacy policy, and security rules.
6.16 If this website provides customer account functionality, it may use Cookies or similar technologies to save login status, account sessions, and security authentication information, to avoid customers from having to log in repeatedly on each page.
6.17 The company may use language or region-related cookies to save the customer's preferred language, currency display format, or other website preferences, in order to provide a more convenient experience when the customer visits again.
6.18 The company may use functional cookies to save certain website settings chosen by customers, but will not use this as a basis to track customers' behavior on other unrelated websites indefinitely.
6.19 If our company uses advertising cookies, remarketing technologies, cross-site tracking tools, or other marketing technologies that require customer consent in accordance with applicable Japanese law in the future, our company will take necessary measures to inform and obtain consent before enabling such technologies.
6.20 For non-essential Cookies or similar technologies that require customer consent by law, customers may generally choose to accept, reject, or adjust the corresponding categories through the Cookie settings tool provided on the website.
6.21 After customers refuse non-essential Cookies, the basic booking, pickup and drop-off, and essential service functions of the website should not be unreasonably restricted; however, some personalized, analytical, or additional features may not be usable.
6.22 Customers can delete, restrict, or block Cookies through their browser settings. Settings may vary depending on the browser and device used, and customers can manage Cookies based on the functionality of their browser.
6.23 If the customer completely blocks all Cookies, including those necessary for the operation of the website, some website functions, login functions, order functions, language settings, or payment processes may not operate properly.
6.24 After customers delete Cookies, previously saved language settings, account sessions, preferences, or other website settings may need to be reselected or relogged in.
6.25 The company will not refuse to provide customers with primary transportation services that can be completed through other normal means, solely because the customer refuses analysis or marketing cookies that the company is legally allowed to refuse.
6.26 The company may adjust the Cookies or similar technologies used based on changes to website functionality, technological updates, changes in service providers, or legal requirements.
6.27 If any changes significantly affect the way the Company processes customers' personal information, the Company will update this Policy, Cookie notices, or take other necessary measures in accordance with applicable Japanese law.
6.28 The company shall not collect personal information that is clearly unrelated to website operations, service improvement, security, or customer legal consent, under the names of 'Cookie' or 'Website Analysis', without limit.
6.29 If third-party websites, social media, map services, payment services, or other external platforms appear on this website via links, embedded components, or other means, and customers access or use the relevant third-party services, the relevant third parties may process information according to their own privacy policies and cookie rules.
6.30 This company does not control how independent third-party websites handle their own Cookies and personal information. However, the company will fulfill its legal management responsibilities under applicable Japanese law for third-party services that the company actively selects and embeds on its website.
6.31 If a customer accesses this website through a search engine, social media, an advertising platform, or another external website, the relevant external service may have already processed the customer's visit or related advertising information according to its own policies. The independent processing actions by the relevant third parties are not directly controlled by the company.
6.32 The company may use aggregated statistical data to understand the general situation of customers visiting this website in different countries or regions, the main pages visited, and the performance of the order process, in order to support business operations and service improvement.
6.33 When conducting relevant statistics, the company should, to the extent reasonably practicable, avoid using precise identifying information that is unnecessary for the statistical purpose.
6.34 The company may retain necessary website access logs for system security, troubleshooting, preventing unauthorized access, investigating malicious activities, and fulfilling legal obligations.
6.35 The retention period for access logs will be determined based on security requirements, technical environment, potential disputes, and applicable Japanese laws, and will not be retained indefinitely without a reasonable purpose.
6.36 For Cookies and related data that are no longer needed for website operation, security, analysis, or legal obligations, the company will delete, expire, anonymize, or otherwise appropriately process them in accordance with technical conditions, service provider settings, and applicable law.
6.37 When this company uses third-party analytics, payment, map, cloud services, or other technical services, related data may be processed outside Japan. This is governed by the section of this policy regarding cross-border data transfers and overseas service providers.
6.38 If customers have any questions about the use of Cookies, analytics tools, or similar technologies on this website, they may contact us using the contact information listed in this Privacy Policy.
6.39 The company will review the use of Cookies and similar technologies in accordance with applicable Japanese laws, technological developments, and actual business needs, and will continuously improve transparency and management measures within a reasonable scope.
6.40 All provisions regarding Cookies, website analytics, similar technologies, and third-party tools in this section shall be implemented only within the scope permitted by Japanese law, without excluding or limiting the customer's legally entitled rights to personal information protection.
Cross-border Transmission and Overseas Service Providers
7.1 In the course of providing website, booking, payment, customer communication, cloud storage, email, map, data analysis, network security, and other related services, the company may use third-party service providers that have servers, data centers, affiliated offices, or business operation locations outside of Japan.
7.2 Customer personal information may be stored, accessed, transmitted, or processed outside of Japan due to the use of the services mentioned above.
7.3 When the company processes personal information involving areas outside of Japan, it will take necessary and appropriate management measures for such processing in accordance with Japan's Personal Information Protection Act and other applicable laws.
7.4 The company will not transmit customer personal information to overseas locations without reasonable business purpose or appropriate protective measures, solely because a particular overseas technical service is more convenient or less costly.
7.5 Types of services that may involve processing outside the country include but are not limited to:
(1) Website and server hosting services; (2) Cloud computing and cloud storage services; (3) Database and data backup services; (4) Email services; (5) Customer communication and instant messaging services; (6) Credit card and other payment processing services; (7) Bank card organizations and financial institutions; (8) Map, address search, and route planning services; (9) Website access analysis services; (10) Network security and error monitoring services; (11) Customer relationship management systems; (12) IT development, maintenance, and technical support services; (13) Other technical or professional services reasonably necessary for the operation of our business.
7.6 When the company transmits or allows overseas service providers to process personal information, it will limit the information provided to the extent reasonably necessary to achieve the specific service purpose as much as possible.
7.7 For example, to process online payments, payment service providers may need to process customer names, order numbers, transaction amounts, currency, payment status, relevant bank card information, and anti-fraud information.
7.8 To provide email or customer communication services, the relevant service provider may process customer email addresses, phone numbers, communication content, order numbers, and other information necessary to complete the communication function.
7.9 To provide map, address lookup, or route planning functions, relevant service providers may process customer input pickup locations, destinations, or other location information.
7.10 The company shall make reasonable efforts to avoid sending customer personal information to map, analysis, or other technical service providers when such information is not necessary for the realization of relevant functions.
7.11 To provide website analytics, security monitoring, or error diagnostic functions, relevant service providers may process IP addresses, device information, browser information, cookie identifiers, access times, page visit records, error logs, and other technical information.
7.12 If a third-party service provider processes personal information based on its own legal relationship with the customer, legal obligations, or independent business purposes, the third party may bear the corresponding legal responsibilities as an independent information processor.
7.13 The Company will not be exempt from its obligations under Japanese applicable law to protect personal information, merely because a third party is an overseas entity or an independent processing entity.
7.14 When selecting overseas service providers that may process customers' personal information, the company will consider their security measures, privacy protection mechanisms, service terms, and other relevant factors within a reasonable and feasible scope, based on the nature of the service, category of personal information, scale of processing, and level of risk.
7.15 The company may manage overseas service providers entrusted with processing personal information through contract terms, data processing agreements, service terms, access permissions, security settings, technical measures, or other appropriate means.
7.16 If applicable Japanese laws require the Company to confirm the personal information protection measures taken by overseas recipients, the Company will conduct the necessary confirmation in accordance with legal requirements.
7.17 If applicable Japanese laws require the Company to continuously monitor the implementation of personal information protection measures by overseas recipients, the Company will take corresponding measures within a reasonable and necessary scope.
7.18 If the Company finds that an overseas service provider is unable to continue taking the necessary protective measures required by Japanese applicable laws, the Company will take measures such as requiring rectification, restricting data provision, changing service settings, suspending relevant processing, replacing the service provider, or other reasonable and necessary measures depending on the specific circumstances.
7.19 If it is legally required to obtain the customer's consent to provide personal information to a third party outside Japan, the company will obtain the necessary consent in accordance with applicable laws before providing it.
7.20 When obtaining the customer's consent for services provided by overseas third parties in accordance with the law, the company will provide the customer with relevant information necessary to make a judgment within the scope required by Japanese applicable law.
7.21 The aforementioned relevant information may include, according to applicable laws and actual circumstances, the country or region where the overseas recipient is located, information about the personal information protection system in that country or region, the personal information protection measures taken by the recipient, or other matters that need to be explained in accordance with the law.
7.22 If applicable Japanese laws permit processing or providing information abroad under specific conditions without requiring further consent, the company may do so provided the relevant legal conditions are met and necessary measures are taken.
7.23 The provisions in this policy regarding cross-border processing do not imply that customer personal information will necessarily be transmitted to all the listed countries, regions, or service providers. The actual processing location depends on the services actually used by the company, system configuration, and the infrastructure of the relevant service providers.
7.24 The company may not automatically satisfy all requirements for obtaining individual consent from cross-border third parties by making general statements in this Privacy Policy.
7.25 For matters requiring separate consent as required by law, the company will take necessary consent procedures separately based on the actual processing situation.
7.26 If an overseas service provider acts solely as a third party entrusted by the company to process personal information, its legal nature and applicable requirements shall be determined based on Japanese applicable law and the actual processing relationship, and shall not be automatically changed merely because it is located outside Japan.
7.27 Likewise, the company may not avoid the requirements of Japanese applicable law regarding the provision of personal information by a third party or a third party outside Japan by formally referring to such provision as a "commission," when in fact the personal information is provided for the independent use of a third party.
7.28 When customers pay using credit cards, debit cards, electronic wallets, or other international payment methods, transaction information may be processed by payment service providers, acquirers, card networks, issuing banks, anti-fraud systems, or other financial institutions inside or outside Japan.
7.29 The financial institutions mentioned above may independently process relevant personal information in accordance with financial regulation, anti-money laundering, fraud prevention, bank card rules, transaction security, and their own privacy policies.
7.30 In principle, the company cannot control the processing of personal information by banks, credit card organizations, and other independent financial institutions in accordance with their own legal obligations. However, the company will still legally assume corresponding responsibility for providing personal information to relevant institutions.
7.31 When customers communicate with us via WhatsApp, email, or other international communication services, the content of the communication may be transmitted or stored via infrastructure located outside of Japan by the relevant service provider.
7.32 When customers use related third-party communication services, the service provider may also independently process certain information according to its own service terms and privacy policy.
7.33 Our company recommends that customers should not send complete bank card passwords, security codes (CVV), online banking passwords, or other highly sensitive credentials unrelated to transportation services through regular email, instant messaging software, or other channels unsuitable for transmitting highly sensitive information.
7.34 If the Company uses servers, databases, or backup systems located outside of Japan, the Company will implement reasonable access controls, identity authentication, backup management, and other security measures based on the nature and risk of the personal information being processed.
7.35 The use of overseas servers or cloud services does not imply that the relevant service providers are free to use the personal information of our company's customers. Service providers entrusted by our company shall process the relevant data in accordance with the corresponding contractual relationships, service terms, and applicable laws.
7.36 If personal information is backed up, copied, or recovered from a disaster across data centers in multiple countries or regions, the company will take reasonable and necessary management measures in accordance with the technical structure of the relevant services and applicable Japanese law.
7.37 If it is necessary to restore data through overseas infrastructure due to a major system failure, cyber attack, disaster, or other emergency situation, the company may take appropriate measures within the scope that is reasonably necessary to ensure business continuity and data security.
7.38 If a data breach, unauthorized access, cyberattack, or other incident that may affect the security of customer personal information occurs with an overseas service provider, the company will take reasonable and necessary measures in response, based on the nature of the incident and the company's legally mandated responsibilities, upon becoming aware of it.
7.39 The aforementioned measures may include confirming the situation with the service provider, restricting access, modifying permissions, protecting the account, preserving necessary evidence, assessing the scope of affected data, and taking other risk control measures.
7.40 If any incident meets the reporting criteria under applicable Japanese laws, the company will fulfill the necessary reporting obligations to the Japanese Personal Information Protection Commission or other competent authorities in accordance with the law.
7.41 If any event meets the legal requirements for notifying affected individuals, the company will fulfill the necessary obligation to notify individuals in accordance with applicable Japanese law.
7.42 If a customer makes a booking through a travel agency, OTA, corporate client, agent, or other third-party channel, that third party may transfer the customer's information from another country or region to the company on its own initiative.
7.43 For independent collection and cross-border processing of personal information conducted by a third party prior to providing it to the company, the third party shall bear corresponding responsibility in accordance with its own applicable laws and legal relationships with the client.
7.44 After obtaining customer personal information legally from third parties, the company will process the relevant personal information under its control in accordance with this Privacy Policy and applicable Japanese laws.
7.45 If our company changes servers, payment service providers, cloud services, communication systems, or other technology suppliers in the future, resulting in significant changes to the cross-border processing of personal information, our company will determine based on applicable Japanese law whether it is necessary to update this policy, provide additional information to customers, or obtain the necessary consent.
7.46 Customers may make reasonable inquiries regarding the overseas processing of their personal information by the company, using the contact methods specified in this Privacy Policy.
7.47 For information related to overseas third parties required by applicable Japanese laws to be provided to the individual, the company will process it upon completing reasonable identity verification and meeting the relevant legal conditions.
7.48 The company may legally protect cybersecurity information, trade secrets, the legitimate rights and interests of third parties, and other information that should not be disclosed in accordance with the law when responding to relevant inquiries.
7.49 This section shall not be interpreted as the company being entitled to rely solely on the customer's use of this website or completion of an order as implying the customer's unlimited consent to the cross-border provision of all current or future personal information.
7.50 For cross-border third-party providers that require explicit consent under applicable law, the company shall still fulfill the corresponding obligations in accordance with the actual situation and Japanese applicable law.
7.51 The company will conduct necessary reviews of cross-border personal information processing arrangements based on business development, changes in service providers used, changes in laws and regulations in Japan and related countries or regions, and changes in personal information protection risks.
7.52 The provisions in this section regarding overseas processing, overseas third-party provision, entrusted processing, personal consent, and security management shall be determined based on the actual data processing relationship to establish their legal nature, and shall not be altered by the use of any particular name in this policy, thereby changing the obligations under Japanese applicable laws.
7.53 If any provision in this section conflicts with mandatory legal requirements in Japan regarding the protection of personal information, the mandatory legal requirements shall prevail.
7.54 The provisions of this section shall be implemented only within the scope permitted by Japanese law, and shall not exclude or limit the customer's legally entitled rights to personal information protection or the company's legally required obligations regarding personal information protection.
Customer's Personal Information Rights
8.1 This company respects the right of customers to protect their personal information in accordance with the law, and handles customer requests regarding their personal information within a reasonable scope in accordance with Japan's Personal Information Protection Act and other applicable laws.
8.2 Customers may, in accordance with applicable Japanese law, and after meeting the relevant conditions and completing the necessary identity verification, request to inquire, confirm, correct, add, delete, cease use, stop third-party provision, or otherwise legally request information related to their personal data held by the company.
8.3 When customers make requests related to personal information, they should, in principle, do so through the official contact methods published by our company, including but not limited to email, website inquiry channels, or other methods designated by our company.
8.4 To protect the security of customer personal information and prevent unauthorized individuals from accessing, modifying, or deleting others' information, the company may request customers to provide reasonable and necessary identity verification documents before processing related requests.
8.5 Identity verification methods may include but are not limited to:
(1) Order number; (2) Name used during booking; (3) Email address used during booking; (4) Phone number used during booking; (5) Payment-related information; (6) Service date and location; (7) Other information that can reasonably verify the requester's identity.
8.6 The company will not request customers to provide information that is clearly beyond what is necessary for identity verification and processing requests.
8.7 If the Company is unable to reasonably verify the identity of the requester, or has reasonable grounds to suspect that the request may involve unauthorized access, fraud, identity theft, or harm to the rights of others, the Company may delay processing or refuse the relevant request.
8.8 Customers have the right, within the scope of applicable Japanese laws, to request confirmation as to whether the company holds personal information relating to themselves.
8.9 If a customer legally requests the disclosure of personal information, the company will process the information that can be legally disclosed, provided that the necessary identity verification is completed and the conditions of applicable Japanese laws are met.
8.10 When disclosing personal information, the company may omit information related to third-party privacy, trade secrets, security management, or other information that is legally prohibited from disclosure according to laws and regulations.
8.11 If the information requested by the customer involves personal information of fellow passengers, family members, friends, company employees, tour group members, or other third parties, the company will not provide such third-party information to the customer without the legal authorization of the relevant party.
8.12 If a customer finds that the personal information stored by the company is incorrect, incomplete, outdated, or otherwise inaccurate, the customer may legally request correction, supplementation, or updates to the relevant information.
8.13 After receiving a reasonable request for correction, the company will verify the relevant information based on the actual situation, and make reasonable corrections when it is confirmed that there are indeed errors and legally required to be corrected.
8.14 Whether information voluntarily provided by the customer during the order execution process, such as flight numbers, hotel addresses, pickup locations, number of passengers, and number of luggage items, constitutes a correction of personal information should be determined based on specific circumstances; some items may also fall under order modifications.
8.15 If a customer requests to modify an order that has already been confirmed, the company will handle it in accordance with the order modification rules outlined in the 'Service Terms and Conditions' and the 'Cancellation, Waiting, and No-Show Policy'.
8.16 Customers may request the deletion of their personal information within the scope permitted by applicable Japanese laws.
8.17 After receiving a deletion request, the company will determine whether personal information still needs to be retained, whether there is a legal obligation to retain it, whether there are outstanding orders, payment disputes, refund matters, complaints, insurance matters, or other legitimate grounds for retention.
8.18 If there is no further need to retain the relevant personal information, and there is no legal requirement or other legitimate reason, the company will take measures such as deletion, anonymization, de-identification, or other appropriate handling.
8.19 If certain personal information must be retained in accordance with the law, the company may delete only the parts that do not need to be retained further and limit the scope of use of the information that continues to be retained.
8.20 A customer's request to delete data does not mean that the company is required to delete all data related to that customer.
8.21 In the following circumstances, the company may be legally unable to immediately delete all or part of the personal information:
(1) Legal requirements require continued retention; (2) Tax, accounting, or audit requirements require retention; (3) The order has not been completed; (4) Payment has not been settled; (5) Refund has not been completed; (6) Customer complaints have not been resolved; (7) There is a payment dispute or chargeback; (8) There is a traffic accident or insurance processing; (9) There is litigation, arbitration, or other legal proceedings; (10) Retention is indeed necessary to prevent fraud or protect legitimate rights.
8.22 Customers may request, in accordance with applicable Japanese law and under qualifying circumstances, to cease the use of their personal information.
8.23 If a customer believes that the Company's use of their personal information exceeds a reasonable purpose, violates laws and regulations, or lacks a legal basis, they may request the Company to stop using their personal information.
8.24 After receiving a request to stop using the service, the company will investigate the relevant processing purposes, legal basis, necessity of use, and other related factors based on the actual situation.
8.25 If it is confirmed that there is a legally required situation to cease use, the company will stop the use of the relevant personal information within a reasonable scope.
8.26 If the information requested by the customer to stop processing is information necessary for completing an already confirmed order, the company may not be able to immediately stop all processing, as this could result in the inability to complete the transportation service the customer has already purchased.
8.27 In such cases, the company will endeavor to limit the scope of information usage, solely for fulfilling orders, legal obligations, or other necessary purposes.
8.28 Customers may request, within the scope permitted by applicable Japanese laws, to stop the provision of their personal information to third parties.
8.29 After receiving a request to stop third-party provision, the company will determine based on whether the personal information has already been provided to a third party, the basis for the provision, legal requirements, and the actual handling situation.
8.30 If any third party provides information that falls within the scope required by Japanese applicable law to be discontinued, the company will take necessary measures.
8.31 For information that must be provided to a third party in accordance with the law, such as courts, police, administrative agencies, tax authorities, insurance institutions, payment institutions, or other legally authorized institutions, the company is unable to stop providing the information solely based on the customer's request.
8.32 For information that the customer has already provided directly to a third party through a travel agency, OTA, agent, payment service provider, or other third party, the customer may need to make requests such as deletion, cessation of use, or other actions directly to the relevant third party.
8.33 Customers may withdraw certain consents previously given to the company for the processing of their personal information within the limits permitted by applicable laws.
8.34 However, withdrawing consent will not affect the validity of processing carried out based on a previous lawful consent.
8.35 If the processing of personal information is not only based on the customer's consent, but also on other lawful grounds such as the performance of a contract, legal obligations, protection of life safety, or the establishment or maintenance of legitimate rights, the withdrawal of consent does not automatically require the company to cease all related processing.
8.36 For example, if a customer withdraws their consent to receive marketing emails, it does not affect the company's ability to continue sending order confirmations, driver contact information, payment notifications, service change notices, safety alerts, or other information necessary for fulfilling the contract.
8.37 If a customer does not wish to receive marketing promotional information, they may unsubscribe according to the method provided in the marketing message or request to stop receiving it from our company.
8.38 If a customer requests to stop receiving marketing information, it does not affect the company's continued retention of transaction records, payment records, service records, or information required by law to be retained for completed orders.
8.39 The company may charge reasonable fees for personal information requests made by customers, in accordance with applicable Japanese law, such as copying costs, postage costs, or administrative processing fees permitted by law.
8.40 If applicable Japanese laws prohibit charging fees, or if the customer requests matters that are legally required to be handled free of charge, the company will not charge unreasonable fees.
8.41 The company will process the relevant request within the time period stipulated by applicable Japanese laws or a reasonable time after receiving the customer's complete request and completing the necessary identity verification.
8.42 If it is not possible to complete the request in a timely manner due to the complexity of the requested content, the need to investigate third-party information, the need to confirm legal obligations, the need to process a large amount of data, or other reasonable reasons, the company will inform the customer of the processing status within the limits allowed by applicable law.
8.43 If the company legally decides to refuse, limit, or is unable to fully meet a customer's request, the company will explain the relevant reasons within the scope required by applicable laws.
8.44 If customers have any questions regarding how the company handles personal information, they may first consult or file a complaint through the company's contact information.
8.45 The company will reasonably take into account customer opinions and, based on actual circumstances, review the relevant personal information processing procedures, security measures, and business operations.
8.46 Customers are also entitled by law to seek further consultation or remedies from the Japanese Personal Information Protection Commission, consumer protection agencies, judicial authorities, or other legally authorized institutions.
8.47 The company will not refuse to provide transportation services that the customer has legally purchased and meets the conditions, simply because the customer legally exercises their personal information rights.
8.48 The company will not discriminate against, retaliate against, reduce the quality of service, or take any other unreasonable adverse measures against customers for making reasonable requests regarding their personal information.
8.49 However, if the customer refuses to provide the necessary information required to complete the order, resulting in the company being unable to safely, legally, or effectively provide transportation services, the company may be unable to accept or continue providing the relevant services depending on the specific circumstances.
8.50 The company may retain records of customers' requests regarding personal information, including the request time, content of the request, identity verification status, processing results, and related communication records, to demonstrate that the company fulfills its legal obligations for the protection of personal information.
8.51 The records themselves may contain personal information, which the company will manage in accordance with this privacy policy and applicable Japanese law.
8.52 The rights of customers regarding their personal information should be determined comprehensively based on applicable Japanese laws, the actual relationship between the customer and the company, the purpose of information processing, and specific circumstances.
8.53 This section shall not be interpreted as limiting the customer's legally entitled rights to protect personal information, nor shall it be interpreted as allowing the company to refuse legally mandated requests through internal rules.
8.54 At the same time, this section does not impose an obligation on the company to disclose information that is not required by law, significantly affects the rights of third parties, discloses trade secrets, or endangers system security.
8.55 All provisions in this chapter regarding inquiries, corrections, deletions, suspensions of use, suspensions of third-party provision, and other personal information rights shall be executed only within the scope permitted by applicable Japanese laws.
8.56 If Japanese mandatory laws regarding the protection of personal information provide different provisions concerning customer rights, processing deadlines, disclosure obligations, or other matters, the relevant legal provisions shall prevail.
Protection of Personal Information of Minors
9.1 Our company values the protection of children's and minors' personal information and will take reasonable protective measures for minors' personal information within the scope required by Japanese applicable laws.
9.2 Our private transportation service may involve family travelers, child passengers, and minors traveling together, such as airport transfers, family private car services, theme park transfers, day tours, intercity travel, and other tourism transportation services.
9.3 In order to complete the transportation service, ensure passenger safety, and meet the service needs requested by customers, the company may need to collect necessary information related to minor passengers.
9.4 Information that may be collected includes but is not limited to:
(1) Number of traveling children; (2) Age range of children; (3) Child safety seat requirements; (4) Relevant information about travel arrangements; (5) Special transportation needs; (6) Other information necessary to complete the service.
9.5 In principle, the company will not actively collect detailed personal information of minors that is unrelated to transportation services in order to provide general private transportation services.
9.6 The company will not request customers to provide sensitive detailed information such as passport numbers, school information, health records, medical records, or other information not directly necessary for general transportation services for minors.
9.7 If the customer voluntarily provides special needs information related to minors, such as mobility assistance needs, special care needs, safety requirements, or other information, the company will only use such information to the extent reasonably necessary for arranging relevant services, safe transportation, and meeting the customer's explicit requirements.
9.8 When a booking person, guardian, or accompanying adult provides information about a minor to our company, they should ensure that they have a legal authority or reasonable basis to provide such information.
9.9 For example, when parents, legal guardians, family members, schools, tour group leaders, company representatives, or other legal representatives provide information about minors to our company for the purpose of arranging travel, they should ensure that the provision of such information complies with applicable laws and the relationship between them and the minor.
9.10 If a customer books on behalf of a minor, the company may use the booker's name, contact information, and order details as the primary contact for order confirmation, service coordination, safety communication, and after-sales processing.
9.11 In principle, the company will not directly collect unnecessary personal information from minors.
9.12 If a minor proactively sends information to the company through the website, email, social media, instant messaging tools, or other channels, the company will determine, to the extent reasonably feasible, whether to continue to retain, delete, or forward the information to their guardian for handling.
9.13 If the company discovers that a minor has provided obviously unnecessary personal information without proper authorization, the company may take appropriate measures such as deletion, restriction of use, or other actions based on the specific circumstances.
9.14 For service requirements such as child safety seats, the company may need to collect necessary information such as the number of children, age range, and number of seats, to ensure that vehicle arrangements meet customer needs.
9.15 Customers should ensure that the provided child age, quantity, height range, and other relevant information about safety seats are accurate.
9.16 If incorrect or incomplete child information provided by the customer leads to an inability to prepare suitable child safety seats, inappropriate vehicle arrangements, or services that cannot be provided as expected, the company will handle the situation based on the actual circumstances of responsibility.
9.17 The provision of child safety seats by our company is an auxiliary arrangement within transportation services and does not replace the supervisory responsibility of parents, guardians, or accompanying adults.
9.18 During transportation, the responsibility for the safety supervision of minors remains with the accompanying guardian, parents, or adults responsible for caring for the minors.
9.19 Our drivers will provide transportation services in accordance with Japanese traffic laws, safety regulations, and the content of the order confirmation. However, they are not responsible for substitute supervision, accompaniment, education, or medical care.
9.20 Customers may not request that the driver assume sole responsibility for the care of minors without adult supervision or appropriate safety arrangements.
9.21 If a customer requests that a minor travel alone, the company may determine whether to accept the service based on the minor's age, route, nature of the service, safety risks, and applicable Japanese laws.
9.22 For minors traveling alone or for special transportation needs, the company may require customers to provide additional verification documents or guardian authorization information.
9.23 If laws require guardian consent, authorization, or other procedures for the transportation of certain minors, the company has the right to request customers to complete the relevant procedures before providing services.
9.24 The company will not refuse to provide legal and reasonable transportation services based on the identity of a minor. However, in cases involving safety risks, legal restrictions, or inability to confirm guardian authorization, the company may refuse or adjust the service arrangement.
9.25 Access to information related to minors will be restricted based on business needs.
9.26 Drivers, employees, cooperating personnel, and entrusted service providers shall not use minors' personal information for purposes unrelated to the order.
9.27 Photos, videos, voices, school information, family relationships, health conditions, or other highly personalized information of minors will not be actively collected or disclosed by the company in principle.
9.28 If a customer voluntarily provides the company with photos of minors or other information, for example, to confirm the need for a child safety seat, special service arrangements, or identity verification, the company will only process such information to the extent necessary for the relevant purpose.
9.29 Without explicit customer authorization or legal permission, the company will not use minors' photos, names, travel information, or other identifiable data for promotional, advertising, social media display, or other marketing purposes.
9.30 If our company in the future conducts special activities, member services, or other business involving children, families, or minors, and needs to process additional information about minors, our company will take necessary explanatory and protective measures in accordance with applicable Japanese laws.
9.31 If the company discovers that minors' personal information may be leaked, accessed without authorization, or other security incidents occur, it will take necessary measures in accordance with the nature of the incident, applicable Japanese laws, and the provisions of this privacy policy regarding the handling of security incidents.
9.32 The company may retain order records, safety records, payment records, and other data required by law or business operations related to the transportation services for minors within a reasonable and necessary scope.
9.33 Even if the order involves minors, when the customer requests the deletion of related information, it shall still be handled in accordance with the provisions of this privacy policy regarding retention periods, legal obligations, dispute resolution, and other legitimate grounds for retention.
9.34 The company will not request minors to directly agree to the processing of marketing, advertising, or commercial information that is unrelated to general transportation services.
9.35 If obtaining guardian consent is required by law, the company will obtain the necessary consent in accordance with applicable laws before providing the relevant service or processing the relevant personal information.
9.36 The company will not intentionally collect minors' personal information beyond what is necessary for providing transportation services.
9.37 Parents, guardians, or other legal representatives who have questions about how our company handles minors' personal information may consult our company through the contact information published in this privacy policy.
9.38 The company will make necessary adjustments to the relevant protective measures based on changes in Japanese laws regarding the protection of children's and minors' personal information, changes in business operations, and technological developments.
9.39 The provisions of this section regarding the personal information of minors shall be applied together with other sections of this privacy policy.
9.40 Nothing in this section shall be interpreted as relieving the company from its legal obligation to protect the personal information of minors under applicable Japanese law.
Updates to the Privacy Policy, Applicable Law, and Contact Us
10.1 This privacy policy outlines the basic rules followed by Japan Private Car Service (Nihon Osaka Ryokaku Co., Ltd.) when providing private transportation services, operating its official website, and handling customer personal information.
10.2 The company may modify, supplement, or update this privacy policy based on the following circumstances:
(1) Changes in Japan's personal information protection laws and regulations; (2) Changes in the company's business model; (3) Changes in website functionality, booking process, or payment methods; (4) Changes in the technical services, servers, or third-party service providers used; (5) Changes in the way personal information is processed; (6) Institutional improvements to enhance customer transparency and protection measures; (7) Other reasonable and necessary operational reasons.
10.3 When the company modifies this privacy policy, it will provide customers with relevant information through website announcements, page updates, order notifications, or other appropriate methods within a reasonable scope in accordance with applicable Japanese law.
10.4 The revised privacy policy will apply to new personal information processing activities from the effective date published on the website.
10.5 For bookings completed or orders already in process before the modification, the company will generally handle related matters according to the privacy policy effective at the time the customer provided personal information, except where applicable Japanese laws allow or require the new policy to apply.
10.6 If changes to this Privacy Policy involve customers' important personal information rights, processing purposes, third-party provision, cross-border transmission, or other significant matters, the company will take necessary measures such as notification, explanation, or obtaining consent within the scope required by Japanese applicable law.
10.7 Customers continuing to visit this website, use our services, place orders, or provide personal information to our company does not represent customer consent for our company to expand the use of personal information in violation of applicable Japanese laws.
10.8 The company will not use the personal information it has already collected for new purposes that are completely unrelated to the original processing purpose and not permitted by law, merely by amending the privacy policy.
10.9 If a customer disagrees with the revised Privacy Policy, and the relevant changes involve important personal information processing matters that require the customer's consent under applicable Japanese law, the customer may choose to stop using the related service or make the corresponding request under applicable Japanese law.
10.10 This privacy policy should be read in conjunction with the following documents:
(1) Terms and Conditions; (2) Cancellation, Waiting, and No-Show Policy; (3) Specific Order Confirmation Details; (4) Payment and Refund Rules; (5) Website Usage Regulations.
10.11 If provisions regarding the processing of personal information are repeated across different documents, they should be interpreted in conjunction with the specific matters, processing purposes, and applicable Japanese laws.
10.12 While the Service Terms and Conditions mainly stipulate the rights and obligations of both parties in transportation services, and this Privacy Policy mainly stipulates the methods of handling personal information, when it comes to matters related to the protection of personal information, this Privacy Policy shall be the primary basis.
10.13 If there are specific agreements regarding the processing of personal information in specific orders, contracts, or legal documents, such agreements shall be followed within the scope permitted by Japanese law.
10.14 Nothing in this privacy policy shall be interpreted as limiting the customer's rights to protect personal information under Japan's Personal Information Protection Act and other applicable laws.
10.15 The company will not engage in unreasonable discrimination, refuse already purchased legal services, or take retaliatory measures against customers who legally request to query, disclose, correct, delete, stop using, stop third-party provision, or make other legitimate requests regarding their personal information.
10.16 However, if the customer refuses to provide information necessary for completing the transportation service, payment processing, safety management, or legal requirements, the company may be unable to provide partial or full services.
10.17 When processing personal information, the company shall comply with applicable Japanese laws, including but not limited to Japan's regulations regarding personal information protection, security management, third-party provision, cross-border transmission, and protection of the individual's rights.
10.18 If any dispute arises between the customer and the company regarding the processing of personal information, both parties should first attempt to resolve it through reasonable communication methods.
10.19 Customers can consult with the company on the following matters through the contact information published by the company:
(1) Collection and Use of Personal Information; (2) Processing of Personal Information Related to Orders; (3) Requests for Disclosure of Personal Information; (4) Requests for Correction of Personal Information; (5) Requests for Deletion of Personal Information; (6) Requests to Cease Use; (7) Requests to Cease Third-Party Provision; (8) Issues Related to the Privacy Policy; (9) Other Matters Concerning the Protection of Personal Information.
10.20 When customers make requests related to their personal information, the company should provide information that can verify their identity and the content of their request to ensure accurate processing.
10.21 The company will reasonably handle requests received from customers, based on the nature of the request, applicable Japanese laws, the status of information storage, and actual circumstances.
10.22 If a customer requests information controlled by a third party, such as banks, credit card companies, payment platforms, OTA platforms, travel agencies, communication service providers, or other independent data processing entities, the customer may need to make the request to the relevant third party simultaneously.
10.23 The company may retain records of customer privacy requests, complaints, inquiries, and processing results in accordance with applicable Japanese laws, to demonstrate the company's compliance with its obligations for the protection of personal information.
10.24 When this company retains the aforementioned records, it uses the relevant information only within the scope of handling complaints, demonstrating compliance, safety management, and legal requirements.
10.25 Contact information for our company is as follows:
Company Name: Japan Osaka Travel Corporation (Japan Osaka Travel Corporation)
Operating Brand: Japan Private Car Service
Location: Japan Osaka Prefecture
Official Website: https://japanprivatecarservice.com
Contact Information: Please contact our company via the customer service email, inquiry form, or official contact information published on the official website.
10.26 If customers wish to make formal requests regarding the processing of their personal information, they should submit them through the official contact methods provided above, so that the company can verify their identity, keep records, and proceed with subsequent handling.
10.27 The company will not request customers to submit important requests involving a large amount of personal information through unofficial personal accounts, private social media accounts, or unverified contact methods.
10.28 This privacy policy is formulated based on the Japanese legal system and is interpreted and enforced in accordance with applicable Japanese law.
10.29 If the laws of the country or region where the customer is located provide additional mandatory protections for the protection of consumer personal information, the applicable laws may continue to apply to the customer within their scope of application.
10.30 If any part of this privacy policy is determined by a court of competent jurisdiction, administrative authority, or other relevant authority to be invalid, unlawful, or unenforceable, the remaining provisions shall remain in full force and effect.
10.31 Any invalid or unenforceable part shall be interpreted in the manner that is as close as possible to the original intent and legally valid under the maximum extent permitted by Japanese law.
10.32 The company reserves the right to update this privacy policy based on changes in laws, business operations, and technological developments.
10.33 The last update time of this privacy policy will be displayed at the top of this page or another appropriate location.
10.34 By continuing to use this website, placing an order, or accepting our services, the customer is deemed to have had the opportunity to read and understand this privacy policy.
10.35 The purpose of this privacy policy is not to restrict customer rights, but to ensure that both parties can clearly understand the rules for handling personal information, based on ensuring the security and transparency of personal information processing.
10.36 This privacy policy is implemented only within the scope permitted by Japanese applicable laws, and does not exclude or limit the consumer rights, personal information protection rights of the customer, or the responsibilities that the company is legally obligated to bear.