Back to NomadJapan
Privacy

What we collect, what we use it for, and who we share it with.

NomadJapan keeps personal data to a minimum and uses it only for the purpose you provided it. This policy explains what we collect and how we handle it.

Last updated:

What we collect

  • Site analytics: aggregated pageviews, dwell time, referrer, device type, and coarse geographic information. After consent, we store events such as comparison-article view, listing view, date selection, and checkout start in our own database with a one-way transformation of a random identifier that lasts only for the browser tab. This log does not contain names, emails, IP addresses, or exact stay dates. Booking-funnel data is not sent to third-party analytics by default. If explicitly enabled in future, it will be limited to coarse dimensions such as stay-length and party-size bands; exact stay dates, exact party size, and raw Stripe references will not be sent.
  • Marketing attribution:where consent is required, after you consent we keep UTM parameters; Google Ads click identifiers (such as GCLID); ValueTrack campaign, ad-group, creative, account-keyword, device and related identifiers; the first page visited; and the referring domain and path for the browser session. We exclude query strings, including search terms, from the referrer. If you submit an enquiry or booking, the same fields are stored in our own database with that record so we can measure campaign performance. We do not copy these advertising identifiers into the payment processor's metadata.
  • Enquiries: the contents of messages you send us by email or via a contact form (name, email, message, dates, party size, budget, etc.). Used solely to respond to you and propose a stay.
  • Local browser state: features such as "save for later" or "CTA dismissed" are persisted in your browser's localStorage. These never reach our servers.

How we use it

  • To improve the site, its content, and our editorial process.
  • To reply to enquiries and propose stays or quotes.
  • To detect and prevent abuse.

Sharing with third parties

We do not sell or transfer personal data to third parties without your consent, except where required by law. We do use processors for hosting, transactional email, analytics, and payments (Stripe); in each case the processor handles the minimum information needed under their own privacy terms.

Booking and payment data

When you submit a booking request we collect your name, email, phone (optional), party size, selected dates, and message in a restricted database to confirm availability and arrange your stay. Card payments are processed by Stripe, a PCI-DSS compliant payment provider; we do not receive or store full card numbers.

Identity checks and the statutory guest register

We use Stripe Identity to verify the booking representative after booking; Stripe collects and checks identity-document and facial images. For booking performance, identity checks, and the guest register required by Japanese law, we process for each guest the relevant name, age, date of birth (where available), sex, nationality, address, contact details, previous place of stay, next destination, arrival and departure time, room, and verification method. For a foreign guest without a Japanese address, we also process the passport number, original-document check result, and a reference to a passport copy in restricted storage. We do not duplicate passport or facial images into our application database; it stores only references to files held by Stripe or another access-restricted store. Unsaved entries retained while switching between guests stay only in memory within the open page and are not written to persistent browser storage.

Visitors in the EU / UK

If you are in the EU or UK, we process your personal data to respond to your enquiry and to perform a booking you request. You may ask us to access, correct, or delete it at the address below.

Cookies, tracking & consent

We use the cookies and similar technologies below. For visitors in the EU, UK, and Switzerland, non-essential cookies load only after you consent via the banner shown on your first visit. You can change or withdraw consent at any time from “Cookie Settings” in the footer.

  • Essential (no consent needed): site operation and preferences (language, consent state). Includes localStorage, which is not sent to our servers.
  • Analytics: Google Analytics (understanding and improving usage). Without consent in the EU/UK/CH, Google receives only cookieless, modelled data.
  • Advertising: Meta (Facebook) Pixel, if enabled for ad measurement. It is not loaded until you consent and is not used for the initial Google Search single-channel pilot.
  • Performance: Vercel Analytics / Speed Insights (cookieless, non-identifying).

Retention: Google Analytics data is kept up to 26 months in non-identifying form; anonymous funnel events in our own database are kept for up to 13 months; and your consent choice is stored in your browser until you change it. Marketing-attribution data stays in the current tab until the session ends; when copied to an enquiry or booking, it follows the retention period of that record. You can also disable cookies in your browser settings.

Retention and deletion

Resolved or expired enquiry messages are normally deleted after 30 days. Statutory guest-register and related identity records are retained for three years from creation; Stripe also normally retains non-biometric Identity verification data on our behalf for three years. Aggregated analytics is retained for up to 26 months in non-identifying form. You may request access, correction, or deletion by email, although we may need to retain records for a period required by law.

How to contact us

Privacy questions, data access, or deletion requests: concierge@ie-mirai.co.jp