Privacy Policy
Privacy Policy
Who we are
This Privacy Policy is issued by Wayfarer K.K. (WAYFARER株式会社), a company registered in Japan, with its registered office at 1-17-1 Toranomon Hills Tower, Minato, Tokyo 105-6415.
EU representative (Article 27 GDPR): Europe Services, SE, Na Cecelicce 425/4, Smíchov, 150 00 Praha 5, Czech Republic. Data subjects may contact our EU representative at info@gdprrepresentative.com regarding the processing of their personal data.
This Privacy Policy describes how your personal information is collected, used, and shared when you use the Kabin Crew app, visit the Kabin website, check in using the Kabin Pad tablet at our reception, or stay at one of our properties, including what our staff record about you as a guest during your stay. It is organized into three parts: our mobile app, our website, and how we collect, use, and share your data more broadly across your stay with us. Where a section applies to more than one part, it appears once, in the part it applies to most directly.
Wayfarer built the Kabin app as a free app, provided at no cost and intended for use as is. This page is used to inform visitors and users regarding our policies on the collection, use, and disclosure of personal information.
The personal information we collect is used for providing and improving our service. We will not use or share your information with anyone except as described in this Privacy Policy.
The terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, unless otherwise defined here.
Part 1: The Kabin App
Information Collection and Use
For a better experience while using our app, we may require you to provide us with certain personally identifiable information. Part 3 below lists everything we may collect across our app, website, the Kabin Pad, and your stay, and explains why.
The app uses third-party services that may collect information used to identify you.
Link to the privacy policy of third-party service providers used by the app:
Log Data
Whenever you use our app, in the case of an error we collect data and information (through third-party products) on your phone called Log Data. This may include your device's Internet Protocol (“IP”) address, device name, operating system version, the app's configuration when using our service, the time and date of your use of the service, and other statistics.
App Cookies
Cookies are files with a small amount of data that are commonly used as anonymous unique identifiers. The app does not use these “cookies” explicitly. However, the app may use third-party code and libraries that use cookies to collect information and improve their services. You may accept or refuse these cookies. If you refuse them, you may not be able to use some portions of the app.
Part 2: The Kabin Website
This part applies to your use of the Kabin website. When you visit our website, we ask for your consent before any non-essential cookie or tracking tool is activated. A banner appears on your first visit, letting you choose which categories of cookies to allow. Only cookies strictly necessary for the site to function are active before you make a choice.
Cookie Categories
We group our website cookies into three categories:
- Functional (always on). These are required for the site to work properly and cannot be turned off. This includes Sentry, which helps us detect and fix technical errors, Stripe for payments and personal information collection, and a dedicated consent cookie described below.
- Analytics. These help us understand how visitors use our site. Currently this covers our analytics platform, Mixpanel, Google Analytics, and Stape (which forwards website events to our analytics and marketing tools).
- Marketing. These are used for advertising and promotional communications. Currently this covers Meta (Facebook) Pixel, Customer.io, RightMessage, Triptease and Google Ads.
Your Choices
You can accept all, reject all (except Functional), or choose categories individually. If your browser sends a Global Privacy Control (GPC) signal, we treat this as a request to opt out of Analytics and Marketing automatically, without needing to ask you again.
Link to the privacy policy of third-party service providers used by the website
You can change your choice at any time using the “Cookie Settings” link in the footer of our site. When you make a choice, we record the time it was made and what you chose, so we can honor it going forward. This record does not expire automatically, and it stays in effect until you change it yourself.
To remember your choice, we store it in a dedicated first-party cookie tied to a randomly generated, anonymous identifier. This cookie is used only to remember your privacy preferences — never for tracking, analytics, or marketing — which is why it falls under the Functional category and does not require its own opt-in. We also keep a matching record on our servers, so that we can demonstrate what was consented to and when, if ever required to do so.
Website Service Providers
Some tools listed above act on our behalf under the categories described. For example, Customer.io is used only to send marketing emails; transactional messages, such as booking confirmations, are sent through a separate provider (SendGrid) and are not affected by your cookie choices.
Regulatory Compliance
This list reflects our current practices and may be updated as regulations change or as our compliance program evolves.
We design our website's cookie and consent practices to meet the requirements of the following regulations: the EU General Data Protection Regulation (GDPR) and ePrivacy Directive, the UK GDPR and Privacy and Electronic Communications Regulations (PECR), Japan's Act on the Protection of Personal Information (APPI), U.S. state privacy laws (including honoring the Global Privacy Control signal where required), Canada's PIPEDA and Quebec's Law 25, Australia's Privacy Act 1988, Singapore's Personal Data Protection Act (PDPA), New Zealand's Privacy Act 2020, Israel's Privacy Protection Law (including Amendment 13), Hong Kong's Personal Data (Privacy) Ordinance (PDPO), and Taiwan's Personal Data Protection Act (PDPA).
Part 3: How We Collect, Use, and Share Your Data
This part applies across our app, our website, the Kabin Pad, and your stay with us as a guest.
What We Collect
- Account (website and app): first and last name, email, username, password, country, profile photo (app), and your marketing email choice. If you sign in with Apple or Google, we receive your name and email from them.
- Booking: name, email, and your newsletter choice. Stripe collects your card details directly; we never see your card number. Apple Pay and Google Pay may share your billing address and phone number with us.
- Booking sites: if you book through a third-party booking site, we receive your booking and contact details from that site through our hotel management system, Mews.
- Pre-check-in and check-in (website, app, and the Kabin Pad): name, home address, email, phone number, occupation, where you're arriving from and where you're going next, your signature, and your agreement to our house rules. For each companion travelling with you: name, country of residence, and age group.
- ID documents: a photo of each foreign guest's passport or ID, and the details we read from it — document type, number, name, date of birth, sex, nationality, issuing country, and issue and expiry dates. Guests who live in Japan are not asked for this, except at our Minpaku properties. If the back of a My Number card is scanned by mistake, we delete the image and never retain the number itself.
- During your stay: your door codes, and any messages you send to our chat assistant or to our staff.
- Extras you book:
- Restaurant and food experiences (through ByFood): name, email, phone, gender, party size, and any note you add.
- Hotel experiences: whatever information that specific experience asks for, such as your name or height.
- eSIM: only your order details. No personal information is shared with the eSIM provider.
- Contact form and newsletter: name, email, your reservation number and message, or, for the newsletter alone, just your email address.
- What our staff record: ID-check decisions, task notes, and billing notes, which may include the last four digits of a card.
- Collected automatically: cookies on our website (see Part 2); how you use our app and website — including, on the website, session recordings — through Mixpanel; error reports through Sentry; your app version and language; and your IP address and browser details. If you enable Face ID or fingerprint login, only a device-level key reaches us; we never receive your fingerprint or facial data itself.
Why We Use It (Legal Basis)
- Booking, your stay, payments, door access, chat, your account, and extras (ByFood, hotel experiences, eSIM): to provide the service you booked (performance of a contract).
- Guest register and passport copy: required by Japanese hotel law, and necessary for us to be able to host you — our legitimate interest in complying with the Japanese law under which we operate, together with the necessity of this data to provide your stay.
- Keeping payment and accounting records: our legitimate interest in complying with Japanese tax and company law.
- Marketing emails, analytics cookies, and marketing cookies: your consent, which you may withdraw at any time.
- Keeping stay details for 5 years to recognize returning guests: our legitimate interest in welcoming back repeat guests.
- Error monitoring and security: our legitimate interest in keeping our service working and secure.
ID Requirement at Check-In
Japanese law requires all foreign guests to present a valid passport at check-in. We are unable to check you in without it.
Who We Share It With
- Hotel operations: Mews (our hotel management system, which holds reservations and guest profiles); AWS (hosting and file storage, including passport photos, and app sign-in).
- ID documents: Anthropic, United States (reads passport and ID photos taken at the Kabin Pad, and companion photos uploaded through the app or website); Stripe Identity (verifies passports within the app, without a selfie).
- Payments: Stripe.
- Messages: Twilio, United States (text messages, including door codes); SendGrid, United States (emails); OpenAI, United States (your chat assistant's responses).
- Booking partners: ByFood (restaurant and food bookings, as described above); Yumeyakata (kimono experience bookings: names, email, each participant's kimono type and height, and stay dates).
- Sign-in: Apple and Google, when you use their sign-in option.
- Analytics and marketing: Mixpanel, Meta, Google (Tag Manager and Analytics), Triptease, RightMessage, Customer.io, and Stape.
- Monitoring: Sentry and New Relic.
- Internal tools: Google Sheets (internal reports containing guest names and emails) and Slack (door codes by room number, for staff use).
International Data Transfers
Some of our providers are outside Japan and the EU: in the United States (AWS, Anthropic, OpenAI, Stripe, Twilio, SendGrid, Mixpanel, Meta, Google, Customer.io, Sentry, New Relic, Slack, Stape, RightMessage), and in the United Kingdom (Triptease). When we send your data to these providers, we rely on the EU-U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. The United Kingdom is covered by a European Commission adequacy decision. Japan has also been recognized by the European Commission as providing an adequate level of data protection since 2019. Mews, our hotel management system, is based in the Netherlands (EU) and is not included in this list.
How Long We Keep Your Data
- Guest register and passport copies: 3 years from the date the register entry is made, as required by the enforcement rules of the Japanese Ryokan Business Act.
- Payment and accounting records, including the reservations and invoices they relate to: 10 years, under Japanese tax and company law
- Analytics data (Mixpanel): 5 years, after which Mixpanel deletes it automatically; website session recordings are kept for 30 days.
- Error reports (Sentry): 90 days, deleted automatically.
- ID photos submitted for reading (Anthropic): deleted within 30 days.
- Chat assistant messages (OpenAI): retained by OpenAI for up to 30 days.
- Stripe Identity verification data: retained by Stripe for up to 7 years under its own policies.
- Account information: until you delete your account.
- Marketing emails: until you unsubscribe.
- Door codes: a new code is generated for each stay and stops working at checkout.
- Other stay details (chat messages, and check-in details that are not part of the guest register): 5 years after your last stay, so that we can recognize you as a returning guest.
Your Rights
Subject to applicable law, you can:
- see your data and get a copy of it
- receive your data in a format you can transfer to another company (data portability)
- correct it
- delete it
- restrict or object to how we use it
- withdraw your consent at any time
You can exercise any of these rights by submitting a request through this link.
We will respond within one month. You also have the right to lodge a complaint with the data protection authority in your country of residence.
part 4: Applies to Both the App and the Website
Security
We value your trust in providing us your personal information, and we strive to use commercially acceptable means of protecting it. However, no method of transmission over the internet, or method of electronic storage, is 100% secure, and we cannot guarantee its absolute security.
Links to Other Sites
Our app and website may contain links to other sites. If you click a third-party link, you will be directed to that site, which we do not operate. We strongly advise you to review the privacy policy of any external site; we have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We advise you to review this page periodically for changes. We will notify you of any changes by posting the new Privacy Policy on this page.
This Privacy Policy was last updated on Sep 30, 2026.
Contact Us
You can reach us at our registered address above, or by submitting a request through this link.