CITY PASSPORT
CITY PASSPORT / LEGAL

Privacy policy

Last updated: 1 October 2026

01 Operator and scope

This policy explains how 株式会社悠遊 handles personal information when providing City Passport.

City Passport is operated by 株式会社悠遊(ユウユウ), represented by 代表取締役 松本波涛. Address: 〒111-0031 東京都台東区千束2丁目4−3, Japan. Corporate number: 2011101075028. Contact: [email protected] or 03-6802-8000.

02 Information and purposes

For authentication and account management, we handle email addresses, login identifiers, display names, usernames, avatars and settings, including optional profile information such as birthdays.

For passport and social features, we handle visits and stamp history, memory text and photos, saved places, friendships, event registrations and attendance, and gift receipt, transfer and use history.

For merchant applications and operations, we handle store and contact details, application documents, events and stamp settings. We handle orders, payment status and credit records to process and reconcile purchases, and enquiry details to respond to enquiries.

Access, scan and processing records are used to prevent abuse, resolve faults and operate the service safely.

03 Location

If you allow location access, it is used to show your position and nearby stores on the map. Store and venue addresses and coordinates are used to display those places.

You can change location permission in your device settings.

04 Sharing and external services

Profiles, memories and events you publish or share are visible to others within the visibility settings of the relevant feature. We do not sell personal information.

We use Supabase for authentication, databases and file storage; MapTiler for maps; the Geospatial Information Authority of Japan (国土地理院) for address search, to which the typed address string is sent; Open-Meteo for event weather, to which only venue coordinates are sent; Resend for email delivery; and Stripe for payments, as needed to provide the service. Stripe handles card details; they do not pass through our servers.

When Apple / Google sign-in is used, the relevant authentication service handles information needed for login. External services also apply their own policies. We may disclose information to the extent required by law.

05 AI features and international transfers

Some app features (reflections, annual reviews, questions about your passport, merchant AI assistance and store-seal generation) send input through HelixToken (Singapore AI Evolution Pte. Ltd., Singapore) to the model provider (Google LLC, United States) to obtain generated results. Submitted content is not used to train AI models and is retained temporarily only for the period necessary to generate responses and detect abuse.

06 Retention and account closure

At account closure, display names, birthdays and locale settings are de-identified. Closed accounts cannot be reopened, and their usernames and City Passport IDs cannot be reused.

Following a 30-day grace period after closure or the applicable deletion, memory text, drafts, saved places and applicable merchant notes are deleted or irreversibly de-identified. Photo database records are deleted only after removal of the stored images is confirmed. Authentication identities become eligible for removal after the 30-day closure grace period. Cleanup runs periodically.

Stamps, passports, gifts and their history, events and participation history, and store relationships are retained indefinitely as de-identified provenance records to preserve historical and transaction integrity. Records needed to reference replies and pages remain after memory text is removed.

Scan logs, notification delivery records and completed processing records generally have a 30-day retention period; notifications have a 90-day period. In-progress records, referenced records and records needed for the latest operational checks may be excluded until processing and integrity checks allow removal. Business-licence images submitted with merchant applications become eligible for deletion 90 days after a decision or withdrawal.

07 Security and your requests

We take necessary security measures, including access restrictions, to prevent leakage, loss and damage to personal information.

To request access, correction, deletion or restriction of use of your personal information, or to ask about this policy, contact [email protected]. We verify your identity and respond in accordance with applicable law. Please also see the retention section for information retained as historical records.

08 Age eligibility

The Service is intended for people aged 13 and over.

09 Policy changes

Updates are published on this page. Where the law requires notice or consent, we follow those requirements.