Privacy Policy
Last updated: March 7, 2026
1.Information We Collect
We collect the following categories of personal information when you use our services:
Account Information: When you create an account via Google sign-in, we receive your name and email address from your Google profile. We store a unique user identifier and your email address.
Booking Information: When you book a tour, we collect your selected tour and date, package selection (Standard or Premium), preferred meeting time, trading card game interests (e.g., Pokémon, One Piece, Gundam), product type preferences (e.g., sealed boxes, singles, graded cards), budget range, and optional grail card descriptions.
Payment Information: We collect payment details necessary to process your deposit and balance charges. All card numbers and sensitive payment data are handled directly by Stripe, our payment processor. We do not store your full card number, CVV, or expiration date on our servers. We retain Stripe customer identifiers, payment intent identifiers, and a reference to your saved payment method for the purpose of charging the remaining tour balance.
Terms Acceptance Records: We record the timestamp at which you accept our Terms and Conditions.
Automatically Collected Information: When you visit our website, our hosting provider (Vercel) may automatically collect standard server logs, including your IP address, browser type, and pages visited. We do not use analytics trackers, advertising pixels, or third-party tracking cookies.
2.How We Use Your Information
We use your personal information for the following purposes:
To provide our services: Processing and managing your tour bookings, collecting deposit and balance payments, sending booking confirmation and welcome emails, and communicating tour logistics such as meeting points and times.
To operate our business: Verifying date availability, preventing duplicate bookings, processing cancellations and refunds per our stated policy, and managing rescheduling requests.
To improve our services: Understanding customer preferences to enhance tour experiences. We do not sell, rent, or share your personal information with third parties for marketing purposes.
3.Third-Party Service Providers
We share personal information with trusted third-party service providers who process data solely on our behalf and for the purposes described in this policy:
Supabase — database hosting and user authentication. Stripe — payment processing, payment method storage, and refund management (PCI-DSS Level 1 certified). Google — account authentication via Google sign-in and embedded maps for tour meeting points. Resend — transactional email delivery (booking confirmations and welcome emails). Vercel — website hosting and server infrastructure.
Each provider is contractually obligated to protect your data and use it only for the services they provide to us. We do not sell, rent, or share your personal information with third parties for marketing or advertising purposes.
4.Cookies & Local Storage
Authentication Cookies: We use HTTP-only cookies to maintain your login session. These cookies are strictly necessary for the website to function and cannot be opted out of while using authenticated features.
Session Storage: We temporarily store your booking form data in your browser's session storage to preserve your selections during the checkout process. This data is automatically cleared when you close your browser tab.
We do not use advertising cookies, analytics cookies, or any third-party tracking cookies.
5.Data Retention
Account Data: Your account information is retained for as long as your account remains active. You may request account deletion by contacting us at the email address below.
Booking Records: Completed booking records, including payment history, are retained for a minimum of seven (7) years to comply with tax and financial record-keeping obligations.
Abandoned Bookings: Booking records for incomplete or abandoned checkouts (where payment was not completed) are automatically deleted within 24 hours.
Transactional Emails: Email delivery records are retained by our email provider (Resend) in accordance with their retention policy.
6.Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
All data is transmitted over HTTPS/TLS encryption. Payment data is handled by Stripe, a PCI-DSS Level 1 certified processor, and never touches our servers in raw form. Database access is restricted through role-based access controls and service-level authentication keys. Administrative functions require verified administrator credentials.
While we take reasonable precautions to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your information.
7.Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Access: You may request a copy of the personal data we hold about you.
Correction: You may request that we correct inaccurate personal data.
Deletion: You may request that we delete your personal data, subject to our legal retention obligations.
Data Portability: You may request a copy of your data in a structured, machine-readable format.
Withdrawal of Consent: Where processing is based on consent, you may withdraw consent at any time by contacting us.
To exercise any of these rights, please contact us at the email address listed below. We will respond to your request within thirty (30) days.
8.International Data Transfers
Kanto TCG Tours operates in Japan. Our third-party service providers may store and process data in various countries, including the United States. By using our services, you acknowledge that your data may be transferred to and processed in jurisdictions outside your country of residence, which may have different data protection standards.
9.Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will take steps to delete such information.
10.Changes to This Policy
We may update this Privacy Policy from time to time. The updated policy will be posted on this page with a revised "Last updated" date. Your continued use of our services after any changes constitutes acceptance of the updated policy. We encourage you to review this page periodically.
11.Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Email: inquiry@kantotcgtours.com
Website: https://www.kantotcgtours.com