Privacy
cizucu Inc. (株式会社cizucu) (“we,” “us,” or “our”) respects the privacy of everyone who uses the event platform “hauss” that we provide (the “Service”), and handles personal information and other information about users appropriately.
This Privacy Policy (the “Policy”) sets out the information we collect, the purposes for which we use it, disclosure to hosts and other third parties, our use of external services, how we manage information, and the rights users may exercise.
Please review this Policy when you use the Service.
1. Scope of this Policy
This Policy applies to our handling of information in connection with the Service’s websites, applications, events, ticket sales, messaging, email delivery, magazines, inquiries, and other related activities.
Information that a host who holds an event through the Service collects or uses on their own may be subject to that host’s privacy policy or other terms.
Information handled on external websites or services linked from the Service is subject to the privacy policies of the providers of those services.
2. Compliance with laws
We comply with Japan’s Act on the Protection of Personal Information, the Telecommunications Business Act, and other applicable Japanese laws and guidelines.
Depending on where we provide the Service and where users are located, we also comply with applicable data protection laws, including the following:
- the EU General Data Protection Regulation (GDPR)
- UK GDPR and the UK Data Protection Act
- the California Consumer Privacy Act (CCPA/CPRA)
- other privacy and electronic communications laws of relevant countries and regions
If this Policy conflicts with mandatory applicable law, that law prevails.
3. Definitions of information under this Policy
“Personal information” under this Policy means information that can identify a specific individual—such as a name, email address, or phone number—or information that includes a personal identifier code.
Even where information is not personal information, we treat cookies, IP addresses, device information, browsing history, event registration and attendance history, and other information collected in relation to users as “user information,” and handle it appropriately under this Policy.
4. Information we collect
4.1 Account information
In connection with registering and managing accounts, we may collect the following information:
- Name, display name, and username
- Email address and phone number
- Profile image
- Bio, SNS, and other external links
- Country of residence, region, language, and time zone
- Date of birth or information needed for age verification
- Account identifiers
- Login methods and authentication-related information
- Notification, visibility, and other settings
- Organizations you belong to, roles, and permissions
The Service may offer magic links, Google, and other authentication methods we designate.
4.2 Event registration and attendance information
In connection with registering for an event, purchasing tickets, or attending an event, we may collect the following information:
- Events and tickets you registered for
- Ticket type, quantity, and status
- Registration time, purchase time, and check-in time
- Order numbers, ticket numbers, QR codes, and other identifiers
- Participant name, email address, and phone number
- Information about companions
- Responses to registration forms set by the host
- Surveys, guestbook entries, comments, and feedback
- Cancellation, refund, and inquiry history
- Past attendance history and relationship to series
- Coupons, invite codes, and referral information
For free-admission events, if a user asks to receive notices about future events or coupons, we may collect an email address, phone number, LINE identifiers, or other contact details needed—even if the user has not created an account.
4.3 Host and organization information
From hosts who create events, sell tickets, or receive payouts, we may collect the following information:
- Individual name, company name, trade name, and representative name
- Address, phone number, and email address
- Host profile and activities
- Organization members, roles, and permissions
- Information about the seller or service provider for the event
- Tax information and qualified invoice issuer registration numbers
- Stripe connected account identifiers and status
- Sales, refunds, chargebacks, and payout information
- Status of identity and business verification
- Inquiries to hosts and related support history
For identity documents, bank account details, and other information Stripe collects directly, we may not retain or be able to view all of that information.
4.4 Payment and transaction information
In connection with paid tickets and other transactions, we may collect the following information:
- Purchase amount, currency, taxes, and fees
- Payment time and payment status
- Type of payment method
- Card brand and last digits of the card number
- Stripe Customer ID, Payment Intent ID, and other payment identifiers
- Refunds, cancellations, chargebacks, and disputed charges
- Receipt and billing information
Full credit card numbers and security codes are, in principle, handled directly by Stripe and are not retained by us.
4.5 Posted and public information
We collect the following information that users post or register on the Service:
- Event, series, and host pages
- Magazines, articles, text, and comments
- Photos, videos, audio, and other content
- Guestbook entries, participant voices, and event reports
- Follows, reactions, and shares
- Public profiles and attendance or hosting history
- Content visibility and display settings
Information set to public may be viewable by other users, the general public on the internet, or search engines.
4.6 Communications and inquiry information
In connection with communications with us, hosts, or other users, we may collect the following information:
- Message and email content
- Inquiries, reports, and appeals for reconsideration
- Email send, delivery, open, click, and error information
- Reply tokens and other communication identifiers
- Customer support contact history
- Survey and interview responses
4.7 Device and usage information
When you use the Service, we may automatically collect the following information:
- IP address
- Cookies and similar identifiers
- Device, OS, browser, and app information
- Language, time zone, and approximate region
- Pages viewed, referrers, searches, clicks, and interaction history
- Event view, save, registration, and purchase history
- Session times and time spent
- Crashes, errors, response times, and diagnostic information
- Information related to abuse or security
If we collect precise device location, we will explain that before collection and ask for permission on the device.
4.8 Information from external services
If you choose to connect an external service, we collect information from that service within the scope you authorize.
- Google account name, email address, and profile image
- LINE user identifiers, display name, and profile information
- Information authorized from calendars and other connected services
- Payment, identity verification, and connected account information provided by Stripe
- Attendance information provided by hosts, co-hosts, or event operators
Disconnecting an external service may stop future collection of information from that service.
4.9 Publicly available information
To enrich event information, verify hosts, or introduce events, we may collect event names, host names, event details, public profiles, and other information from websites, SNS, and other publicly available sources.
If you want listed content corrected or removed, you may request it by contacting us.
4.10 Sensitive information
Depending on the nature of an event, we may collect sensitive information such as food allergies, disability accommodations, health conditions, religious accommodations, and similar details.
We and hosts collect such information only when needed for safe event operations or other necessary purposes, and handle it based on explicit consent or another lawful basis under applicable law.
5. Purposes of use
We use collected information for the following purposes:
- Account registration, authentication, and management
- Creating, publishing, searching for, and recommending events
- Event registration, ticket issuance, and check-in
- Ticket payment, sales management, refunds, and payouts to hosts
- Communication among hosts, participants, and operations staff
- Holding, changing, or canceling events, and emergency contact
- Notifications by email, push notification, LINE, and other channels
- Providing coupon, invite, and referral features
- Providing magazines, guestbook entries, reports, and other content
- Recommending events based on interests, region, attendance history, and similar factors
- Measuring, analyzing, and improving use of the Service
- Announcing new features, campaigns, and other information
- Handling inquiries, reports, disputes, and rights infringements
- Preventing fraudulent payments, spam, fraud, and other abuse
- Maintaining security, investigating outages, and monitoring errors
- Enforcing the Terms of Use and Community Guidelines
- Complying with laws and orders of courts or government authorities
- Creating statistics and analysis that cannot identify individuals
- Reviewing and improving our business, the Service, and marketing initiatives
We distinguish notifications needed for event operations from advertising or marketing communications.
If we use information for a purpose that is not reasonably related to the purpose stated at collection, we will notify users in advance and obtain any consent required by law.
6. AI-powered features
We may use generative AI or machine learning for event descriptions, magazines, event reports, summaries, translation, recommendations, and other features.
AI-powered features may process text, images, form responses, event information, and other information needed for generation on our systems or those of AI service providers.
We use AI under the following principles:
- We do not send personal information beyond what is needed for processing
- We do not send payment card information or identity documents to AI services
- If we use sensitive information, we provide required explanations and obtain consent
- We indicate AI-generated output when appropriate
- We do not make decisions with significant effects on users based solely on AI
- We appropriately manage AI services and the information we send to them
Where AI features are optional, users may choose not to use them.
7. Disclosure to hosts
To the extent needed for event registration and operations, we provide participant information to the host of that event and to members with the necessary operations permissions.
Disclosed information may include the following:
- Name, display name, and contact details
- Ticket and payment status
- Registration form responses
- Check-in status
- Cancellation and refund status
- Messages with the host
- Information participants provide voluntarily
On the Service, access to participant information is limited to Host, Manager, and others with permissions needed for event operations.
Even if someone appears as a co-host or related party, we do not provide participants’ personal information to anyone without management permissions.
After a host obtains or exports participant information from the Service, that host is also responsible, as a personal information handling business operator or data controller, for their own handling of that information.
Hosts may not use participant information beyond what is needed for event operations. Adding participants to future advertising or marketing lists requires separately obtaining any consent required by law.
8. Disclosure to third parties
Except in the following cases, we do not provide personal data to third parties without the individual’s consent:
- Where required by law
- Where necessary to protect a person’s life, body, or property, and obtaining consent is difficult
- Where especially necessary to improve public health or promote the sound upbringing of children
- Where necessary to cooperate with legally required affairs of national or local government bodies
- In connection with a merger, company split, business transfer, or other business succession
- Where we entrust handling of personal information to a processor
- Where we provide information to hosts to the extent needed for event registration and operations
- Where disclosure to relevant parties is needed to address abuse, rights infringement, or safety issues
- Other cases permitted by law
9. External services and processors
In providing the Service, we may use the following providers and have them handle information to the extent necessary:
| Provider | Main purposes | Information that may be handled |
|---|---|---|
| Google LLC and affiliates | Google Cloud, Firebase, authentication, Google Analytics, AI, and data storage/processing | Account information, usage data, device information, logs, and content |
| LY Corporation and affiliates | LINE login and LINE notifications | LINE identifiers, display names, and notification information |
| Stripe, Inc., Stripe Payments Japan株式会社, and affiliates | Payments, identity verification, Stripe Connect, refunds, and fraud detection | Buyer and host information, payment/transaction information, and identity verification information |
| Resend, Inc. | Sending, receiving, and managing email delivery | Names, email addresses, email content, and delivery information |
| Functional Software, Inc. (Sentry) | Error monitoring, crash analysis, and incident response | Device information, IP addresses, account identifiers, and error/operation logs |
| OpenAI, L.L.C. and other AI service providers we use | Text generation, summarization, translation, classification, and other AI features | Information users provide to AI features, and event/content information |
| Slack Technologies, LLC | Internal communication and handling inquiries, outages, and abuse | Inquiry information, operations information, and minimum necessary error information |
| Other cloud, security, and support providers we use | Operating, maintaining, and securing the Service | Information needed for each engagement |
We review processors’ security practices and supervise them as needed through contracts and other appropriate means.
If we add or change processors in a material way, we will update this Policy or a separate processor list.
10. Google Analytics
We use Google Analytics to understand and improve how the Service is used.
Google Analytics may use cookies and similar technologies to collect pages viewed, interactions, usage times, referrers, devices, browsers, approximate region, and other usage information.
In principle, we enable analytics cookies and use Google Analytics by default. Users can turn them off (opt out) anytime from Cookie settings.
In principle, we use the following settings:
- Disable ads personalization
- Disable Google Signals
- Do not set personal information such as email addresses as the User-ID
- Do not include personal information in URLs or event parameters
- Set data retention to 14 months
- Analytics cookies are on by default; users can opt out in Cookie settings
For how Google handles information, please review the Google Privacy Policy and related materials.
11. Sentry
We use Sentry to detect errors, crashes, and performance issues and to improve the stability and security of the Service.
Information that may be sent to Sentry includes the following:
- Error details and stack traces
- Time of occurrence and user path
- Device, OS, browser, and app information
- IP address and approximate region
- User identifiers we issue
- Technical request information at the time of the error
We filter and mask data so that names, email addresses, registration form responses, payment card information, authentication tokens, and similar details are not unnecessarily sent to Sentry.
We do not use Sentry Session Replay by default. If we use it in the future, we will mask inputs and screen content, obtain any required consent, and update this Policy.
Error data on Sentry is retained for, in principle, no more than 90 days. For details, also see the Sentry Privacy Policy.
12. Cookies and similar technologies
To provide the Service and to understand and improve usage, we use cookies, local storage, and other similar technologies.
Essential cookies
These cookies are needed to provide the Service, including maintaining login state, security, fraud prevention, purchase flows, and language settings.
Because they are necessary to provide the Service, they may not be disableable from Cookie settings.
Functional cookies
We use these to store language, region, display preferences, and other settings users choose.
Analytics cookies
We use Google Analytics and similar tools to measure and improve how the Service is used.
They are on by default; users can turn them off in Cookie settings. Where applicable law requires prior consent, we handle them accordingly.
Marketing cookies
We may use these to measure advertising effectiveness or show ads based on user interests.
If we introduce marketing cookies, we will update this Policy and the Cookie settings screen in advance. They are on by default; users can turn them off.
From Cookie settings (Settings → Cookies), users can turn non-essential cookies on or off. Choices are stored in this device’s browser.
We respect Global Privacy Control and other opt-out signals we can recognize, in accordance with applicable law.
13. Email and notifications
We or hosts may send notifications needed to provide the Service, such as the following:
- Event registration and purchase completion
- Tickets and how to attend
- Pre-event information
- Changes to date, time, venue, or content
- Event cancellation and refunds
- Account and security
- Changes to the Terms of Use and other important matters
These notifications may be sent regardless of marketing delivery settings.
We send marketing information about new events, magazines, coupons, campaigns, and similar topics to users who have given any consent required by law.
Users can stop marketing delivery via links in emails or notification settings. Notifications needed for event operations or contract performance may not be stoppable.
14. Visibility of information
Profiles, events, series, magazines, guestbook entries, and other information are displayed according to the visibility settings chosen by the user.
Attendance and hosting history are shown to other users only if the user chooses to make them public or sets a clear display preference.
Published information may be stored or reshared by search engines, SNS, and other external services, and we may not be able to fully remove it after publication.
15. Retention periods
We retain information only for as long as needed for the purposes of use and as required by law.
Principal retention periods are as follows:
| Information | Principal retention period |
|---|---|
| Account information | While the account exists, and within 90 days after deletion |
| Information in backups | Within 180 days after deletion |
| Ticket, payment, sales, and refund information | 7 years after the transaction is completed |
| Records relating to hosts and sellers | 7 years after the last transaction |
| Inquiry, report, and dispute-handling records | 3 years after handling is completed |
| Email delivery history | 1 year after sending |
| Security and access logs | In principle, 1 year |
| Google Analytics data | In principle, 14 months |
| Sentry error data | In principle, within 90 days |
| Marketing opt-out information | As long as needed to maintain the opt-out |
Where needed for law, accounting, fraud investigation, rights protection, or dispute handling, we may retain information beyond the periods above.
Anonymized information that cannot identify individuals may be used without a fixed period.
16. Security measures
To prevent leakage, loss, damage, unauthorized access, and other risks to personal information, we take the following security measures:
- Establishing information security and personal information handling rules
- Clarifying handling authority and management responsibility
- Access controls limited to what is needed for business
- Appropriate management of multi-factor authentication, credentials, and secrets
- Encryption of data in transit and at rest
- Managing access logs, error logs, and audit records
- Monitoring unauthorized access, vulnerabilities, and outages
- Selecting, contracting with, and supervising processors
- Training employees and requiring confidentiality
- Establishing incident response and recovery procedures
- Understanding legal systems of countries and regions where personal information is handled
Details of our security measures will be provided, after identity verification, in accordance with law.
17. International transfers
We are located in Japan. In providing the Service, personal information may be processed by processors or on servers located in Japan, the United States, or other countries and regions.
Where transfer restrictions apply, we take appropriate safeguards by one or more of the following means:
- Transfers based on an adequacy decision
- Standard Contractual Clauses (SCCs)
- the UK International Data Transfer Agreement or UK Addendum
- the individual’s explicit consent
- performance of a contract or another basis permitted by law
- contracts with processors and security measures
Information about specific safeguards may be requested by contacting us.
18. Users in the EEA and the United Kingdom
Where GDPR or UK GDPR applies, we process personal data on the following legal bases:
| Purpose of processing | Primary legal basis |
|---|---|
| Providing accounts, events, tickets, and payments | Performance of a contract |
| Inquiries, security, fraud prevention, and improving the Service | Our or a third party’s legitimate interests |
| Accounting, tax, identity verification, and legal compliance | Legal obligation |
| Analytics cookies and marketing delivery | Legitimate interests (opt-out available); consent where required by law |
| Handling sensitive information | Explicit consent or another basis under law |
| Use of information in emergencies | Vital interests |
| Event recommendations | Performance of a contract or legitimate interests |
Under applicable law, users may request access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent.
In principle, we do not make decisions that produce legal effects or similarly significant effects on users based solely on fully automated processing.
Users may lodge a complaint with the data protection supervisory authority that has jurisdiction over their place of residence.
19. Rights of U.S. residents
Under applicable U.S. state law, users may have the following rights:
- the right to know what personal information we collect, use, or disclose
- access to and obtaining personal information
- correction of inaccurate personal information
- deletion of personal information
- data portability
- opting out of the sale or sharing of personal information
- opting out of targeted advertising
- limiting the use of sensitive personal information
- the right not to be treated differently for exercising rights
- the right to make requests through an authorized agent
- the right to appeal our decisions
We do not sell personal information for money.
We do not share personal information for cross-context behavioral advertising.
If we begin such practices in the future, we will update this Policy in advance and provide a way to opt out of the sale or sharing of personal information.
20. Users’ rights
Under applicable law, users may make the following requests regarding their information that we hold:
- notification of purposes of use or handling status
- disclosure of personal information or records of third-party provision
- correction, addition, or update
- deletion or erasure
- suspension of use or of third-party provision
- withdrawal of consent
- obtaining or transferring data
- objection to automated processing
- stopping marketing delivery
- changing cookie consent
- making information the user published private
Requests may be made by contacting us. We respond after verifying that the requester is the individual or a duly authorized agent.
In principle, we do not charge a fee for exercising rights. However, where permitted by law, if a request is clearly unfounded or excessively repetitive, we may charge a reasonable fee or decline to respond.
Account deletion
Users may request account deletion from the Service’s settings screen or another method we designate.
Even after an account is deleted, the following information may not be deleted immediately:
- transaction and accounting records that must be retained by law
- information relating to refunds, chargebacks, and disputes
- information needed for fraud prevention and security
- information included in content created by other users
- information stored in backups
- information needed to establish, exercise, or defend our or a third party’s legitimate rights
21. Minors
If a minor uses the Service, consent of a parent or other legal guardian must be obtained in accordance with the laws of the place of residence.
The Service is not intended for children under 13 to create or use an account on their own.
In the EEA or the United Kingdom, for users of an age that requires parental approval for consent to information society services, we obtain any required consent under applicable law.
If we learn that we have collected a child’s personal information without required consent, we will delete it or take other necessary action.
22. If a personal information incident occurs
If leakage, loss, damage, or another incident involving personal information occurs, we will investigate the impact and take measures needed to contain harm, restore systems, and prevent recurrence.
Where required by law, we will report to relevant supervisory authorities and notify affected individuals.
23. Changes to this Policy
We may change this Policy in response to changes in the Service, external services we use, laws, or other circumstances.
For material changes, we will notify the changes and effective date in advance by display on the Service, email, or another appropriate method.
Where consent is required for a change, we will obtain consent again in accordance with law.
24. Language
This Policy may also be provided in languages other than Japanese.
If a translation differs from the Japanese version, the Japanese version prevails to the extent permitted by applicable law. However, if mandatory law applicable where the user is located requires different treatment, that law prevails.
25. Contact
For inquiries about personal information handling, cookies, users’ rights, or other matters under this Policy, please contact us.
Personal information handling business operator: 株式会社cizucu
For our address, representative, and other business information, see Company and Legal notice.
Last updated: July 23, 2026