Privacy Policy
How we collect, use, and protect your personal information at LensTokyo.
Quick summary
- We collect account, booking, vendor, premium membership, and analytics data needed to run LensTokyo.
- We use Stripe, Cloudinary, email, and analytics partners; data stays protected by contract.
- EU/UK visitors see a consent banner; everyone can control cookies and email settings.
- We store records only as long as required for law, disputes, or product support.
1. Data we collect
Users and premium members
- Account and profile: name, email, username, password hash, preferred languages, service interests, and contact details.
- Bookings: pricing snapshots, coupons, tax rate, schedule changes, deliverables, activity logs, IP address, and user agent.
- Payments: Stripe customer IDs, payment intent IDs, transfer IDs, and refund attempts tied to bookings or memberships.
- Premium usage: subscription status, plan type, lifetime payment events, paywall access flags, and upgrade prompts.
- Device and analytics: consent state, GA4 events, cookie identifiers, approximate region, performance metrics, and error logs.
Vendors
- Vendor compliance: legal name, date of birth, business registration details, invoice numbers, verification documents (encrypted, deleted after six months), and availability settings.
- Payout and tax: Stripe Connect account IDs, payout schedules, transfer attempts, tax forms, and bank-country metadata.
- Marketplace activity: booking quotes, schedule responses, deliverable uploads, coupon configuration, and audit logs.
2. How we use data
- Provide bookings, marketplace dashboards, deliverable workflows, and customer support.
- Run payments, coupons, refunds, and Stripe Connect payouts as Merchant of Record.
- Validate vendors and protect the community through audits, logging, and fraud review.
- Operate premium memberships, manage paywalls, and surface upgrade prompts.
- Send transactional emails (bookings, payouts, verification, membership) and optional marketing where permitted.
- Improve the product via consented analytics, performance monitoring, and bug diagnostics.
3. Legal bases
We rely on contract (providing services you request), legitimate interest (security, analytics, support), legal obligations (tax, accounting, consumer law), and consent (analytics cookies, optional marketing, storing sensitive vendor docs).
6. Retention
- Verification documents: deleted six months after review.
- Booking and payout snapshots: kept for the statutory period for tax and dispute resolution.
- Activity logs: retained while needed for fraud prevention and product analytics.
- Premium membership records: kept while the account stays open or until required for chargeback defense.
7. Your rights
- Access, correct, or delete your data (subject to legal limits).
- Export booking or membership histories on request.
- Withdraw consent for analytics or marketing.
- Object to processing based on legitimate interest where applicable.
- Lodge a complaint with your local regulator.
8. Security
We encrypt verification files at rest, enforce access controls, monitor suspicious activity, and limit staff access to need-to-know roles. No online system is 100% secure, so report suspected issues promptly.
9. Updates
We will revise this policy when we launch new features or legal rules change. The revision date appears at the top of the page; continued use means you accept the update.
For related terms, see our Terms of Use and Refund Policy.
Have a question or a data request? Visit our FAQ page.
Questions about your data?
Reach out for access, correction, deletion, or any other privacy request.