1. Who we are
This policy applies to theryokanguide.com and the services made available through it (the Site). The Site is operated by Vent Neuf Ltd, trading as The Ryokan Guide. For applicable data-protection law, the operator is the controller of the personal data described here.
Postal address: 62 Athinas, Athina Court, 1st Floor, Office 103, 8010 Paphos, Cyprus · Registration number: HE 492024
Privacy contact: our contact form
2. Data we handle and why
We collect the minimum data reasonably needed to deliver the Site, send communications you request, understand performance with your consent, protect the service, and meet legal obligations. We do not use special-category or sensitive personal data and ask you not to send it to us.
| Activity | Data | Purpose and legal basis | Recipients |
|---|---|---|---|
| Reader account, private profile, and saved ryokans | Email address, Cognito account identifier, authentication and security records, ryokan slugs you save, and optional planning preferences such as travel party, season, regions, prefectures, itinerary stops, editorial price tier, bathing, setting, room, dining, and the TRG qualities you select | Create and secure your requested account, remember your private shortlist and preferences, and produce transparent editorial recommendations. Performance of the account service you request and legitimate interests in protecting and improving it. | Amazon Web Services, including Cognito for authentication and DynamoDB for private profile and favorites storage (eu-west-1). Editorial ryokan data remains in Directus; account preferences are not stored there. |
| Private recommendations and Ryokan Edit | The bounded profile choices above, saved ryokan slugs, the current Edit step, and coarse interaction counts. Anonymous in-progress Edit and pending-save state may remain only in that browser tab. | Create a finite, explainable shortlist and resume an action you requested. Performance of the requested account or discovery service. Optional analytics events are sent only after analytics consent and exclude the profile choices themselves. | The Site application and Amazon Web Services for signed-in persistence. Google Analytics receives only bounded, non-identifying event names and counts when you have consented. |
| Consent-based analytics | Pages and events viewed, approximate location, referrer, device/browser information, cookie identifiers, and booking-link clicks | Measure and improve the Site. Consent. Google Analytics is not loaded until you choose Allow. | Google Analytics. |
| Site delivery and security | IP address, request date/time, requested URL, user agent, and security/error records | Deliver, troubleshoot, and protect the Site. Legitimate interests in operating a reliable and secure publication; legal obligations where applicable. | Amazon Web Services (site hosting, eu-west-1), Cloudflare (DNS and edge network), and the Directus host where it serves content or assets. |
| Messages and rights requests | Contact details, message contents, evidence you provide, and verification information where reasonably necessary | Respond to you and comply with legal obligations. Legitimate interests, steps at your request, and legal obligations. | Relevant staff, service providers, and professional advisers when necessary. |
| Affiliate referrals, when marked | Destination URL and identifiers embedded in a paid link; a partner may later report conversion, booking value, or commission information | Attribute eligible referrals and operate the reader-supported business. Legitimate interests or consent where applicable tracking law requires it. | The booking service, affiliate network, and their technology providers identified by the destination link. |
We receive information directly from you, automatically from your browser and hosting infrastructure and, only for marked paid links, from the relevant affiliate or booking service. We do not receive your full payment-card details from an ordinary outbound booking link.
6. International transfers
The Site is available internationally and its providers may process data in countries other than the one where you live. Privacy protections can differ between countries. Where applicable law requires a transfer mechanism, we use contractual or other lawful safeguards offered by the relevant provider and assess supplementary protections where necessary. You may contact us for information about safeguards relevant to your data.
7. How long we keep data
Production retention settings and deletion routines follow these configured periods:
- Account, profile, and saved-ryokan data: while the account remains open, then deleted or de-identified after a valid account-deletion request, subject to security records, legal obligations, and backup rotation.
- Raw form submissions: 90 days, then deletion unless a longer period is required by law.
- Google Analytics user and event data: 14 months.
- Hosting and security logs: Up to 30 days, subject to the hosting provider’s security requirements.
We may retain a limited record longer when reasonably necessary to honour an opt-out, establish or defend legal claims, investigate abuse, or meet a legal obligation. Copies in secured backups age out under their normal rotation and are not restored for ordinary business use after a valid deletion request.
8. Your privacy rights
Depending on where you live and which law applies, you may have rights to ask for access to or a copy of your personal data; correction; deletion; restriction; portability; objection to certain processing; and withdrawal of consent. You may always object to direct marketing. You may also have the right to complain to your local data-protection authority.
Send a request using our contact form and state the right you want to exercise. We may ask for proportionate information to verify identity and prevent unauthorised disclosure. We respond within the period required by applicable law and do not discriminate against anyone for exercising a privacy right. You can use the same channel to request deletion of your reader account, private profile, and saved ryokans.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising as those terms are used in California privacy law. If those practices change, this policy and the Site's controls will be updated before the change takes effect.
9. Children and security
The Site is a general-audience travel publication and is not directed to children under 13. Children under 13 should not create an account or submit an email address. If you believe a child has sent us personal data, contact us so we can investigate and delete it where required.
We use proportionate organisational and technical safeguards designed to protect data, including access controls and encrypted transport. No internet service is completely secure. We maintain a response process for suspected incidents and will notify affected people and regulators when applicable law requires it.
10. Changes and contact
We may update this policy when the Site, providers, or applicable requirements change. We will post the revised effective date here and provide a more prominent notice before a material change where appropriate. We will request new consent before using previously collected data for a materially different purpose when the law requires it.
Questions, requests, or complaints may be sent using our contact form or by post to Vent Neuf Ltd, 62 Athinas, Athina Court, 1st Floor, Office 103, 8010 Paphos, Cyprus.