All legal pages

Privacy Policy

How WeLive collects, uses, shares, protects and retains personal information, and the rights you have over it.

Operator
ONE WAVE合同会社
Service
WeLive
Privacy and contact email
contact@welive.world
Version
2026-08-12-draft-1 · 2026-08-12

Initial draft template dated 12 August 2026. It describes how WeLive intends to handle personal information and is written to be honest about what is not yet decided. It is not legal advice.

A signed downloadable PDF will be added once the final text is approved.

ONE WAVE合同会社 (“we”, “us”, “the operator”) operates the WeLive residence and the WeLive website. This Privacy Policy explains what personal information we handle, why we handle it, who we share it with, how long we keep it and what you can ask us to do with it.

If anything here is unclear, or you want to exercise a right described below, write to contact@welive.world.

1. Controller and scope

ONE WAVE合同会社 operates WeLive and is the party responsible for the personal information described here. Where the GDPR or UK GDPR applies, ONE WAVE合同会社 acts as the controller; under Japan's Act on the Protection of Personal Information (APPI), it acts as the business handling personal information.

This policy covers the WeLive website, guest and resident accounts, bookings and applications, stays in the residence, identity verification, online agreements, payments, optional add-on services, minibar and equipment orders, concierge and support conversations, and the public contact form.

2. Information we collect

We collect only what a given interaction actually requires. Depending on what you do, that may include:

  • Account and profile data: your name, email address, phone number, preferred language, and the authentication and account identifiers created when you sign in.
  • Booking, application and stay data: requested dates, the room you are interested in, guest or occupant counts, occupant details, your current city and country, occupation or source-of-funds information where a longer stay requires it, your reason for staying, an emergency contact, and the messages and contract records generated around your stay.
  • Identity and compliance data: document type, a masked document number, images or PDFs of the document you upload, expiry date, verification status and the audit trail of the review. Identity documents are stored privately and are never displayed publicly.
  • Payment data: the payment provider used, the external transaction or reference identifier, amount, currency, status, and invoice or receipt records. WeLive does not store full card numbers. Stripe, Square or PayPal processes payment credentials directly under its own terms.
  • Optional service data: cleaning preferences, meal preferences, dietary, allergen or accessibility information (collected only with your explicit consent where the information is sensitive), transport itineraries, interpretation needs, minibar and equipment orders, and condition or damage records for rented items.
  • Support and contact data: the messages you send us, support-assistant transcripts where you have consented to their retention, tickets, and escalation records.
  • Technical data: IP address, device and browser information, timestamps, security and activity logs, and strictly necessary cookies. Analytics or marketing cookies are set only after you have made the choice required in your jurisdiction.

We do not collect race or ethnicity for the purpose of deciding admission, and we do not use nationality or national origin as an automatic rejection criterion. Any information you volunteer that we do not need is deleted rather than kept.

3. Purposes and legal grounds

We process personal information only as far as necessary to:

  • respond to your enquiries before any contract is formed, and manage accounts, applications, bookings, agreements, your stay and the services you request;
  • verify identity, prevent fraud, protect guests, residents and the property, enforce the house rules and comply with legal obligations;
  • process payments and refunds and maintain the accounting records the law requires;
  • send you operational messages about your booking, stay or order and provide support;
  • keep the service secure, troubleshoot faults and maintain audit records;
  • improve the service, using aggregated or anonymised information wherever that is sufficient;
  • send marketing messages, and only where you have given separate opt-in consent that you can withdraw at any time.

If you are in the EU, EEA or United Kingdom, the legal basis depends on the purpose. Managing your account, application, booking, agreement and stay rests on the performance of a contract or steps taken at your request before entering one. Tax, accounting, safety and record-keeping duties rest on legal obligation. Fraud prevention, physical and information security, audit trails and the defence of legal claims rest on our legitimate interests, which we have balanced against your rights and which you may object to. Genuine emergencies affecting someone's life or health rest on vital interests. Sensitive information such as dietary, allergen, health or accessibility details, and any marketing, rest on your explicit and separately obtained consent.

We never bundle marketing consent into the terms you must accept to use the service, and refusing marketing has no effect on your booking or stay.

4. Sharing and service providers

We do not sell personal information. We share it only where a specific purpose requires it, and only to the extent necessary, with:

  • cloud, database, storage and hosting providers that run the platform;
  • the authentication provider that manages sign-in;
  • the email delivery provider used for operational messages, once one is configured;
  • payment processors (Stripe, Square or PayPal) for the transaction you authorise;
  • an identity-verification provider, if and when one is configured — none is active today, and this policy will be updated before one is used;
  • contracted housekeeping, meal preparation, transport and interpretation providers, limited to what they need to deliver the service you ordered;
  • professional advisers such as lawyers and accountants, and insurers, where necessary to establish, exercise or defend legal claims;
  • public authorities, courts and law-enforcement bodies where we are legally required to disclose information.

Every provider receives the minimum information needed, is bound by a written contract restricting their use of it, and may not use it for their own purposes.

5. International transfers

WeLive operates in Japan, but the systems and providers we rely on may store or process personal information in other countries, including outside your own.

Where we transfer personal information across borders, we apply the safeguards required of us: under APPI, we take the steps required before transferring information to a third party in a foreign country, including obtaining consent where that is the applicable route or ensuring the recipient maintains equivalent standards. Where the GDPR or UK GDPR applies, we rely on an adequacy decision or on appropriate contractual safeguards such as standard contractual clauses, together with any supplementary measures a transfer requires.

Japan benefits from an EU adequacy framework, but we do not claim that every provider or processing location we use is automatically covered by it. Each transfer is assessed on its own facts. You may ask us at contact@welive.world which safeguard applies to a particular transfer.

6. Retention

We keep personal information only as long as the purpose it was collected for requires:

  • Active account and stay data is kept while your account or stay is active and while it remains necessary to provide the service and to establish or defend legal claims.
  • Payment, accounting, contract and guest records are kept for the statutory periods that apply to them in Japan and any other applicable jurisdiction.
  • Rejected or withdrawn applications and the identity materials submitted with them are kept only as long as necessary to complete the review, prevent repeat fraudulent applications, resolve disputes and satisfy legal duties.
  • Support and security logs are kept for a limited, documented period defined in our internal retention schedule.
  • Sensitive optional-service information, such as dietary, allergen or accessibility details, is deleted or anonymised once it is no longer needed to deliver the service.

The exact periods live in an internal retention schedule that the operator maintains and can adjust, together with a deletion queue that carries out scheduled deletions. That schedule is being finalised and will be summarised here before publication. A legal hold — for example an ongoing dispute, investigation or regulatory request — may extend retention until the hold is lifted.

7. Security

We apply reasonable organisational and technical safeguards: role-based access control so staff only reach what their role requires, private storage buckets for documents, time-limited signed access links, encryption of data in transit, managed secret storage for credentials, activity and audit logging, least-privilege database policies, backups, and a defined incident-response procedure.

No system can be guaranteed completely secure, and we do not promise absolute security. If a breach occurs that is likely to affect your rights, we will notify you and the competent authorities as the law requires.

8. Your rights

You can make any request described here by writing to contact@welive.world. We will ask you to verify your identity before we act, so that we do not disclose someone's information to the wrong person.

Under APPI you may ask us to disclose the personal information we hold about you, to correct, add to or delete inaccurate information, to cease using or to erase information handled improperly, to cease providing it to third parties, and to tell you about records of third-party transfers.

Where the GDPR or UK GDPR applies, you also have the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, objection to direct marketing at any time, and withdrawal of any consent you have given — withdrawal does not affect processing carried out before it. These rights are subject to the exceptions the law provides, for example where we must keep records to comply with a legal duty or to defend a legal claim.

If you are not satisfied with our response, you may complain to Japan's Personal Information Protection Commission and, where applicable, to the supervisory authority in your country or region.

9. Automated support and decisions

The WeLive Concierge is an automated assistant. It can answer questions, explain services and create support requests on your behalf.

It does not make final decisions about identity verification, bookings, admission, refunds or anything else with legal or similarly significant effect. Those decisions are made by a person. You can ask for human review of any answer or outcome at any time.

10. Children

Accounts and bookings made by or for a minor require a parent or legal guardian where the applicable law requires it, and the responsible adult must provide the required information.

We do not knowingly allow minors to order alcohol. Alcohol ordering remains disabled across the platform until the operator has completed the applicable compliance review and age-verification approval.

11. Updates and contact

We may update this policy as the service, our providers or the law changes. Every version carries a version label and a date, and previous versions are retained so that you can see what applied when. Where a change materially affects you, we will give notice by email or through the site before it takes effect, and we will ask for fresh consent where consent is the basis for the change.

For any question about this policy or about your personal information, contact contact@welive.world.