Travel smarter. Experience more Japan.

Tokyo Tickets

Privacy Policy

Last updated: February 2026

1. Who we are

Tokyo Tickets (the operator identified in the Help centre) is the controller of the personal data processed through this website. This policy explains what we collect, why, and the rights you have — in line with GDPR and LGPD principles.

2. Data we collect

Account data: name, email address, password (stored only as a salted hash), phone, country and language preference. Booking data: chosen experiences, dates, time slots, ticket types and quantities. Payment data: payment details are processed by secure payment providers and shared with our operations channel only to fulfil your order; full card numbers are never stored on our servers. Technical data: IP address, browser and device information, kept for security, fraud prevention and auditing.

3. How we use your data

We use your data to create and manage your account, process bookings, issue and deliver digital vouchers, send transactional emails (confirmation, vouchers, changes), provide support, prevent fraud and abuse, and comply with legal obligations. We do not sell personal data and do not use it for advertising without consent.

4. Operational notifications

To operate the service, booking and payment information is forwarded to our internal operations channel (a private team workspace). Access to that channel is restricted to the staff who fulfil orders. Full card numbers are never stored on our systems.

5. Sharing and processors

We share data only with processors that help us run the service: hosting infrastructure, the database provider, email delivery, and the venues that honour your vouchers (name and voucher code, where required). Processors act under contract and may only use the data to provide their service.

6. Retention

Account data is kept while the account is active. Orders, vouchers and audit logs are kept for the period required by tax and consumer law (typically 5 years), then deleted or anonymised. Session cookies expire automatically.

7. Security

Passwords are hashed with a modern key-derivation function. Traffic is encrypted in transit (HTTPS), the site is protected by a web application firewall, and access to internal tools is logged and audited. No security measure is absolute; report suspected incidents to our support address.

8. Your rights

You can access, correct, export or delete your data, and object to or restrict processing, by contacting our support address. You can also delete your account from the profile page. If you believe your rights were infringed, you may complain to your local data protection authority.

9. Cookies

We use strictly necessary cookies (session and language preference) and, if you consent, no third-party tracking cookies are set. You can manage consent from the banner shown on first visit.

10. Contact

For any privacy question or request, write to the support address in the Help centre. We respond in English and Japanese.