Privacy Policy
Last updated: August 26, 2026
1. Introduction & Who We Are
My Tokyo Treasure ("we," "us," or "our") operates mytokyotreasure.com (the "Site") from Japan. We are the data controller responsible for the personal information described in this Privacy Policy. Our processing of personal information is governed primarily by Japan's Act on the Protection of Personal Information (APPI), and — where applicable to you — the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
This policy explains what we collect, why, who we share it with, how long we keep it, and the rights you have. By using the Site you acknowledge the practices described here. If you do not agree, please discontinue use of the Site.
2. Information We Collect
Information you provide directly:
- Account data — name, email address, and password (stored only as a secure hash) when you register.
- Two-factor and passkey data — if you choose to turn them on: an authenticator-app secret, and for a passkey, a credential identifier and public key. A passkey's private key never leaves your device, and we never receive your fingerprint, face, or device PIN.
- Order data — recipient name, shipping address, phone number where required by the carrier or destination country, box contents, and order history.
- Payment data — your card details are collected and processed directly by Stripe, Inc. and never touch or reside on our servers. We receive only a payment confirmation token, the card brand, and the last four digits of the card number.
- Communications — messages, claims, photos, and attachments you send via our contact form or email, including damage-claim evidence.
- Reviews — review text and any name or photo you choose to submit.
Information collected automatically:
- IP address, device and browser type, operating system, referring URL, and pages viewed.
- Approximate location — a city and country estimated from your IP address. This is derived, not precise: we do not collect GPS or device location, and we never ask your browser for it.
- Sign-in records — the date, IP address, approximate location, browser, and device for each successful sign-in, the method used (password, authenticator code, or passkey), and failed sign-in attempts on your account. You can see this list yourself under Security on your account page.
- Session cookies strictly necessary for login state and cart persistence (see Section 6).
- Server logs used for security monitoring and fraud prevention, including counts of requests by IP address used to rate-limit sign-in, password reset, and other sensitive actions.
Information from third parties:
- Payment outcome, risk, and dispute signals from Stripe (e.g. fraud scores, chargeback notices).
- Delivery status and tracking events from shipping carriers.
3. How We Use Your Information & Legal Bases
We process personal information for the following purposes:
- Fulfilling your order — processing payment, packing, shipping, customs declarations, and delivery notifications. Legal basis: performance of a contract.
- Account management — authentication, password reset, and order history. Legal basis: performance of a contract.
- Customer support — responding to enquiries and processing claims. Legal basis: performance of a contract; legitimate interests.
- Transactional email — order confirmations, shipping notifications, and account emails, currently sent via Amazon SES (see Section 4). Legal basis: performance of a contract.
- Account security — keeping a record of sign-ins so you can review them, emailing you when your account is signed into from a device we have not seen before, offering two-factor sign-in and passkeys, and rate-limiting sensitive actions to slow down automated attacks. Legal basis: legitimate interests; performance of a contract.
- Fraud prevention & security — detecting fraudulent orders, bad-faith chargebacks, promotion abuse, and attacks on the Site; maintaining internal records of disputed orders and claims. Legal basis: legitimate interests.
- Defending legal claims — retaining order records, correspondence, tracking data, and claim evidence to establish, exercise, or defend legal claims, including payment disputes. Legal basis: legitimate interests; legal obligation.
- Legal compliance — tax, accounting, customs, and consumer-law obligations. Legal basis: legal obligation.
- Marketing — only with your explicit consent, which you may withdraw at any time via the unsubscribe link in any marketing email. Legal basis: consent.
- Site improvement — aggregate, non-identifying analysis of how the Site is used. Legal basis: legitimate interests.
We do not use your personal information for automated decision-making that produces legal effects, and we do not sell personal information.
4. How We Share Your Information
We do not sell, rent, or trade your personal information. We share it only as follows:
- Stripe, Inc. — payment processing, fraud screening, and dispute handling. Where a chargeback is filed, we share relevant order evidence (address, tracking, correspondence) with Stripe and the card networks to contest the dispute.
- Amazon Web Services — cloud hosting, database (DynamoDB), file storage (S3), account sign-in (Cognito), and email delivery (SES), primarily in the Asia Pacific (Tokyo) region.
- Email delivery — Amazon SES and Resend. We use two transactional email providers and can switch between them; both receive your email address and the contents of the message being sent. Mail is currently delivered by Amazon SES, with Resend configured as the alternative. Both are listed because mail already sent through one remains processed by that provider after a switch. Neither is used for marketing, and neither receives your payment details.
- Cloudflare, Inc. — we use Cloudflare Turnstile, a bot check shown after repeated failed sign-in attempts. Cloudflare receives your IP address and browser signals in order to tell a person from a script. Turnstile is designed not to profile or track users across sites, and we receive only a pass/fail result.
- Google LLC — Google Analytics, used to count visits and understand how people find the Site. This runs only if you agree to it in the cookie banner; if you decline, or simply never answer, nothing is loaded and Google receives nothing. Where it does run, Google receives your IP address, the pages you view, and general device and referral information, and may process it in the United States. We use it for aggregate statistics only, never for advertising.
- Shipping carriers and postal services — recipient name, address, phone number (where required), and customs declaration data (contents description and value), as legally required for international shipping.
- Customs authorities — declaration data accompanying international shipments, as required by law.
- Professional advisers — lawyers, accountants, and insurers where reasonably necessary.
- Legal requirements — where disclosure is required by law, court order, or governmental authority, or is necessary to protect our rights, property, safety, or that of others, including preventing fraud.
- Business transfers — if we are involved in a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of that transaction, subject to this policy.
Service providers process data under contracts that limit their use of your data to providing services to us. For gift orders, the purchaser can see the recipient address they entered; the recipient does not gain access to the purchaser's account or payment details.
5. International Data Transfers
We operate from Japan, and your data is primarily stored in AWS data centres in the Asia Pacific (Tokyo) region. Japan has been recognised by the European Commission as providing an adequate level of data protection (adequacy decision). Where data is processed by Stripe or other providers in the United States or elsewhere, those transfers are protected by appropriate safeguards such as standard contractual clauses. By using the Site from outside Japan, you understand that your information will be transferred to and processed in Japan and in the jurisdictions of our service providers.
6. Cookies
Most of what we use is strictly necessary, and first-party: cookies that keep you signed in, renew your session, and carry a half-finished two-factor sign-in, plus browser local storage to preserve your box selections and to remember your cookie choice.
One is third-party. Cloudflare Turnstile, the bot check shown after repeated failed sign-in attempts, loads from Cloudflare and may set its own token in your browser. It is there to stop automated attacks on accounts, not to advertise or profile you, and it is designed not to track users across sites.
One is optional. Google Analytics tells us how many people visit and how they found us. It is off until you choose "Accept" in the cookie banner: decline it, or ignore the banner entirely, and the Google tag is never loaded, so no analytics cookie is set and Google receives nothing. If you do accept, it sets its own_ga cookies and Google receives your IP address and the pages you view.
You can change your mind at any time using Cookie Settings in the footer of every page. Withdrawing stops any further collection; it cannot retract information Google has already received.
We use no advertising or cross-site tracking cookies. The strictly necessary items above do not require consent under applicable law; analytics does, which is why it is off by default. You can block cookies in your browser, but sign-in and checkout will not work without them. We do not respond to "Do Not Track" browser signals, as we do not track users across third-party sites in the first place.
7. Data Retention
We keep personal information only as long as needed for the purposes above:
- Account data — for as long as your account remains active, plus a reasonable period after deletion for fraud prevention.
- Order, payment, and customs records — up to 7 years, as required by Japanese tax and commercial bookkeeping laws.
- Claim and dispute records (including photos and correspondence) — for the duration of the applicable limitation period for legal claims.
- Contact form messages — up to 3 years after the ticket is closed.
- Sign-in records (successful and failed, with IP and approximate location) — 90 days, then deleted automatically.
- Rate-limiting counters — short-lived, measured in minutes to hours, and used only to throttle repeated requests.
- Administrative action records — an internal log of changes made by our own staff through the admin panel, kept for security and accountability.
- Server and security logs — typically 12 months.
When retention is no longer required, data is deleted or irreversibly anonymised. Where you request account deletion, we honour it except for records we are legally required to keep or that are necessary to defend legal claims.
8. Your Rights
Subject to applicable law, you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted, subject to legal retention obligations.
- Restriction and objection — restrict or object to certain processing, including any direct marketing (which we will stop immediately upon request).
- Portability — receive data you provided in a structured, machine-readable format.
- Withdraw consent — at any time, without affecting prior processing.
- Complain — lodge a complaint with your local supervisory authority, or with Japan's Personal Information Protection Commission (PPC).
To exercise any right, contact us. To protect your data, we will first verify your identity — typically by confirming control of the email address on the account — and may decline requests we cannot verify. We respond within the timeframe required by applicable law (generally within one month for GDPR requests and 45 days for CCPA requests). We will not discriminate against you for exercising your rights. California residents: we do not sell or "share" personal information as defined by the CCPA/CPRA.
9. Security & Breach Notification
We apply administrative, technical, and physical safeguards proportionate to the risk: TLS encryption in transit, hashed passwords, least-privilege access to production systems, and payment handling delegated entirely to Stripe (PCI-DSS Level 1 certified).
You can strengthen your own account under Security on your account page: turn on two-factor sign-in with an authenticator app, or add a passkey and sign in with your device instead of a password. The same page lists your recent sign-ins, and we email you when your account is used from a device we have not seen before, so an unfamiliar sign-in is something you find out about rather than discover later.
No system is perfectly secure, and we cannot guarantee absolute security; you are responsible for keeping your password confidential. In the event of a data breach likely to result in a risk to your rights, we will notify affected users and the competent authorities as required by applicable law.
10. Children's Privacy
The Site is intended for adults and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it promptly.
11. Third-Party Sites & Services
The Site links to third-party services (e.g. Stripe checkout, carrier tracking pages, social media). Those services operate under their own privacy policies, which we do not control and for which we accept no responsibility. We encourage you to review them.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a revised "Last updated" date, and — where the change significantly affects how we use data you have already provided — notified to registered users by email. Your continued use of the Site after changes take effect constitutes acceptance.
13. Contact Us
For any privacy question, rights request, or complaint, please reach us via our Contact page. We take privacy concerns seriously and will respond as quickly as we reasonably can.