Privacy & Cookie Policy

How The Ryokan Guide collects, uses, shares, retains, and protects personal data, including account services, forms, analytics, cookies, and affiliate links.

Effective 1 September 2026

1. Who we are

This policy applies to theryokanguide.com and the services made available through it (the Site). The Site is operated by Vent Neuf Ltd, trading as The Ryokan Guide. For applicable data-protection law, the operator is the controller of the personal data described here.

Postal address: 62 Athinas, Athina Court, 1st Floor, Office 103, 8010 Paphos, Cyprus · Registration number: HE 492024
Privacy contact: our contact form

2. Data we handle and why

We collect the minimum data reasonably needed to deliver the Site, send communications you request, understand performance with your consent, protect the service, and meet legal obligations. We do not use special-category or sensitive personal data and ask you not to send it to us.

Personal-data activities
ActivityDataPurpose and legal basisRecipients
Reader account, private profile, and saved ryokansEmail address, Cognito account identifier, authentication and security records, ryokan slugs you save, and optional planning preferences such as travel party, season, regions, prefectures, itinerary stops, editorial price tier, bathing, setting, room, dining, and the TRG qualities you selectCreate and secure your requested account, remember your private shortlist and preferences, and produce transparent editorial recommendations. Performance of the account service you request and legitimate interests in protecting and improving it.Amazon Web Services, including Cognito for authentication and DynamoDB for private profile and favorites storage (eu-west-1). Editorial ryokan data remains in Directus; account preferences are not stored there.
Private recommendations and Ryokan EditThe bounded profile choices above, saved ryokan slugs, the current Edit step, and coarse interaction counts. Anonymous in-progress Edit and pending-save state may remain only in that browser tab.Create a finite, explainable shortlist and resume an action you requested. Performance of the requested account or discovery service. Optional analytics events are sent only after analytics consent and exclude the profile choices themselves.The Site application and Amazon Web Services for signed-in persistence. Google Analytics receives only bounded, non-identifying event names and counts when you have consented.
Consent-based analyticsPages and events viewed, approximate location, referrer, device/browser information, cookie identifiers, and booking-link clicksMeasure and improve the Site. Consent. Google Analytics is not loaded until you choose Allow.Google Analytics.
Site delivery and securityIP address, request date/time, requested URL, user agent, and security/error recordsDeliver, troubleshoot, and protect the Site. Legitimate interests in operating a reliable and secure publication; legal obligations where applicable.Amazon Web Services (site hosting, eu-west-1), Cloudflare (DNS and edge network), and the Directus host where it serves content or assets.
Messages and rights requestsContact details, message contents, evidence you provide, and verification information where reasonably necessaryRespond to you and comply with legal obligations. Legitimate interests, steps at your request, and legal obligations.Relevant staff, service providers, and professional advisers when necessary.
Affiliate referrals, when markedDestination URL and identifiers embedded in a paid link; a partner may later report conversion, booking value, or commission informationAttribute eligible referrals and operate the reader-supported business. Legitimate interests or consent where applicable tracking law requires it.The booking service, affiliate network, and their technology providers identified by the destination link.

We receive information directly from you, automatically from your browser and hosting infrastructure and, only for marked paid links, from the relevant affiliate or booking service. We do not receive your full payment-card details from an ordinary outbound booking link.

3. Cookies, local storage, and analytics

The Site uses a first-party local-storage record to remember your analytics choice. It is necessary to respect that choice and does not itself measure your browsing. If you choose Allow, the Site loads Google Analytics and Google may set first-party analytics cookies. On an initial or saved Reject choice, Google Analytics is not loaded and analytics events are not sent by the Site. If you withdraw after previously allowing it, collection is disabled immediately; code already loaded in that page remains until the page is closed or reloaded.

Storage technologies used by the Site
NameProviderPurposeTypical duration
trg_sessionThe Ryokan Guide / Amazon CognitoEssential httpOnly cookie that authenticates a signed-in account. It is not available to browser scripts.Up to 24 hours; normally about 1 hour.
trg_refreshThe Ryokan Guide / Amazon CognitoEssential httpOnly cookie used by the server to keep an account signed in and revoke its session on sign-out.Up to 30 days, or earlier on sign-out, revocation, or browser deletion.
cookie-consentThe Ryokan Guide (local storage)Records Allow or Reject, the policy version, and the time of the choice.Until the policy version changes, you change the choice, or browser storage is cleared.
trg.pending-favorite.v1The Ryokan Guide (session storage)Temporarily remembers the ryokan you asked to save while the same browser tab completes sign-in or account confirmation.Up to 24 hours, until the save completes, or until that tab/session storage is cleared.
trg.public-ryokan-edit.v2The Ryokan Guide (session storage)Keeps the bounded choices and resulting finite nine-stay Ryokan Edit in the current browser tab so sign-in or an accidental navigation does not erase the planning context. A legacy v1 brief is removed after one-time migration.Until Start again is chosen, that tab is closed, or session storage is cleared.
_gaGoogle AnalyticsDistinguishes browsers for consent-based audience measurement.Up to 2 years, subject to browser and analytics configuration.
_ga_<measurement-id>Google AnalyticsMaintains session and measurement state after consent.Up to 2 years, subject to browser and analytics configuration.

Advertising storage, ad personalisation, and ad-user-data signals are disabled in the Site's Google tag configuration. We do not use the Site for cross-context behavioural advertising. Browser “Do Not Track” signals do not have a uniform technical standard; the cookie choice below is the control for this Site. Where a legally recognised signal applies to a future practice, we will honour it as required.

5. Service providers and other sharing

We disclose personal data only as needed to:

  • operate accounts, private profiles, saved ryokans, recommendations, forms, hosting, security, content delivery, and analytics you permit through contracted service providers;
  • complete a marked affiliate referral when you choose to follow the relevant link;
  • comply with law, a valid legal process, or protect users, the Site, and legal rights;
  • obtain confidential professional advice or complete a business reorganisation with appropriate safeguards.

Core providers include Amazon Web Services for site hosting, account authentication, and private profile and favorites storage; Cloudflare for DNS and edge delivery; Google Analytics when you consent; and the configured Directus infrastructure for editorial content, media, and form submissions. Each external booking provider acts under its own terms and privacy notice once you leave the Site. We will update this policy before adding a provider whose role materially changes these data uses.

6. International transfers

The Site is available internationally and its providers may process data in countries other than the one where you live. Privacy protections can differ between countries. Where applicable law requires a transfer mechanism, we use contractual or other lawful safeguards offered by the relevant provider and assess supplementary protections where necessary. You may contact us for information about safeguards relevant to your data.

7. How long we keep data

Production retention settings and deletion routines follow these configured periods:

  • Account, profile, and saved-ryokan data: while the account remains open, then deleted or de-identified after a valid account-deletion request, subject to security records, legal obligations, and backup rotation.
  • Raw form submissions: 90 days, then deletion unless a longer period is required by law.
  • Google Analytics user and event data: 14 months.
  • Hosting and security logs: Up to 30 days, subject to the hosting provider’s security requirements.

We may retain a limited record longer when reasonably necessary to honour an opt-out, establish or defend legal claims, investigate abuse, or meet a legal obligation. Copies in secured backups age out under their normal rotation and are not restored for ordinary business use after a valid deletion request.

8. Your privacy rights

Depending on where you live and which law applies, you may have rights to ask for access to or a copy of your personal data; correction; deletion; restriction; portability; objection to certain processing; and withdrawal of consent. You may always object to direct marketing. You may also have the right to complain to your local data-protection authority.

Send a request using our contact form and state the right you want to exercise. We may ask for proportionate information to verify identity and prevent unauthorised disclosure. We respond within the period required by applicable law and do not discriminate against anyone for exercising a privacy right. You can use the same channel to request deletion of your reader account, private profile, and saved ryokans.

We do not sell personal information. We do not share personal information for cross-context behavioural advertising as those terms are used in California privacy law. If those practices change, this policy and the Site's controls will be updated before the change takes effect.

9. Children and security

The Site is a general-audience travel publication and is not directed to children under 13. Children under 13 should not create an account or submit an email address. If you believe a child has sent us personal data, contact us so we can investigate and delete it where required.

We use proportionate organisational and technical safeguards designed to protect data, including access controls and encrypted transport. No internet service is completely secure. We maintain a response process for suspected incidents and will notify affected people and regulators when applicable law requires it.

10. Changes and contact

We may update this policy when the Site, providers, or applicable requirements change. We will post the revised effective date here and provide a more prominent notice before a material change where appropriate. We will request new consent before using previously collected data for a materially different purpose when the law requires it.

Questions, requests, or complaints may be sent using our contact form or by post to Vent Neuf Ltd, 62 Athinas, Athina Court, 1st Floor, Office 103, 8010 Paphos, Cyprus.