Privacy Policy

森合同会社 (Mori Co., LLC)
Travel Service Arrangement Business (旅行サービス手配業)

Tokyo Metropolitan Governor Registration No. 20869


Effective Date: 16 November 2025
Last Updated: 24 May 2025

 

1. Introduction

 

森合同会社 (Mori Co., LLC) (“Mori Co.”, “we,” “us,” or “our”) is a Japan-based Travel Service Arrangement Business(旅行サービス手配業)registered with Tokyo Metropolitan Governor. We provide Japan-side land-service arrangement, supplier coordination and operational support to overseas travel agencies, tour operators, wholesalers and specialist travel advisers on a B2B basis.

 

This Privacy Policy explains how we collect, use, disclose, transfer, store, retain and protect personal information when you visit our website, contact us, submit a B2B enquiry, subscribe to our trade updates, engage with us through LinkedIn or other professional channels, or work with us as a business partner.

 

We are based in Japan. Our handling of personal information is primarily governed by Japan’s Act on the Protection of Personal Information (“APPI”). Where applicable, or as a matter of good practice when working with travel-trade partners in English-speaking markets, we also take account of relevant privacy, direct-marketing and consumer-protection expectations, including, for Australian travel-trade partners, the Australian Privacy Act 1988, the Australian Privacy Principles (“APPs”), the Spam Act 2003 and the Do Not Call Register Act 2006.


This Privacy Policy is intended for business partners, trade contacts, website visitors and relevant operational contacts. It is not a consumer retail booking policy.


2. Our B2B role

 

Mori Co. does not use this website to sell Japan travel packages directly to consumers. Our services are provided to travel-trade partners, including travel agencies, tour operators, wholesalers, specialist advisers and other professional travel businesses.


Where an overseas travel agency, tour operator, wholesaler or specialist adviser works with us, that partner is generally responsible for its own traveller-facing sales, consumer disclosures, privacy notices, retail pricing, package terms, traveller consents and compliance with consumer-facing obligations in its own market.


We handle personal information only to the extent reasonably required for B2B communication, enquiry qualification, quoting, supplier coordination, operational delivery, record keeping, legal compliance and agreed business purposes.


3. Personal information we collect

 

The personal information we collect depends on your relationship with us and the way you interact with us.


3.1 Business contact information


We may collect:

  • your name;
  • company name;
  • business address;
  • business email address;
  • telephone number;
  • job title;
  • department or business function;
  • country or market;
  • professional profile information, where provided by you or publicly available on business platforms such as LinkedIn;
  • business registration, licence, accreditation or trade-identification details where relevant to B2B due diligence.

3.2 B2B enquiry and communication information


We may collect:

  • information submitted through our website contact form, B2B enquiry form or trade-document request form;
  • details of your Japan programme interests, requested services, destination preferences, proposed travel dates, budget range and operating requirements;
  • correspondence by email, LinkedIn, telephone, video call, messaging platform or other business channels;
  • notes from meetings, calls and trade discussions;
  • proposal, quotation, invoice and payment-administration information;
  • records of consent, opt-in, opt-out, unsubscribe and marketing-preference settings.

3.3 Traveller operational information


Where a B2B partner asks us to arrange Japan-side services, we may receive limited traveller information necessary for quoting, booking, supplier coordination or service delivery. This may include:

  • traveller names;
  • group size and basic itinerary details;
  • rooming or passenger lists;
  • dietary requirements;
  • accessibility or mobility requirements;
  • age range or date-of-birth information where operationally necessary;
  • emergency-contact information;
  • passport or identity information only where strictly required by a supplier, transport provider, accommodation provider, event organiser, regulator or other service process;
  • other information that the B2B partner provides to enable Japan-side service delivery.

We ask B2B partners not to send sensitive, special-category or otherwise particularly confidential traveller information unless it is necessary for the agreed service, the traveller has been appropriately informed, and the partner has the required authority, consent or other lawful basis to disclose it to us and relevant Japan-side recipients.


3.4 Website, analytics and technical information


When you use our website, we may collect:

  • IP address;
  • browser type and version;
  • device information;
  • operating system;
  • pages visited;
  • referring pages or campaign sources;
  • time and date of access;
  • approximate location derived from technical data;
  • cookies, analytics identifiers and similar tracking data.

3.5 Marketing and trade-update information


If you subscribe to, request or consent to B2B trade updates, we may collect:

  • name;
  • business email address;
  • company and role;
  • areas of professional interest;
  • subscription source;
  • consent date, method and wording;
  • engagement with our emails, website or LinkedIn content;
  • unsubscribe or preference-management records.

4. How we collect personal information

 

We may collect personal information:

  • directly from you when you contact us, submit a form, request information, subscribe to updates or communicate with us;
  • from your company, employer or authorised representative;
  • from an overseas travel agency, tour operator, wholesaler or specialist adviser working with us;
  • from publicly available professional sources, including company websites, trade directories, event delegate materials and LinkedIn, where lawful and appropriate;
  • from suppliers and operational partners involved in Japan-side service delivery;
  • from website analytics, cookies and similar technologies;
  • from CRM, email, cloud, website, analytics, accounting and business-administration systems we use to manage our operations.

We do not intentionally collect personal information by deception, unlawful scraping, address harvesting or unlawful automated extraction.


5. Why we use personal information

 

We use personal information for the purposes set out below.


5.1 B2B service delivery and supplier arrangement


We may use personal information to:

  • respond to B2B enquiries;
  • assess whether a proposed Japan programme is within our registered scope and operational capacity;
  • prepare proposals, quotations, service sheets and itineraries for trade partners;
  • coordinate accommodation, transport, guiding, dining, admissions, activities and other Japan-side land services;
  • communicate with Japanese suppliers, facilities and service providers;
  • manage amendments, cancellations, disruptions, incidents and emergency support;
  • provide pre-trip, in-trip and post-trip B2B operational support.

5.2 Business administration


We may use personal information to:

  • maintain partner records;
  • conduct B2B onboarding and due diligence;
  • manage quotations, invoices, payments and accounting records;
  • maintain internal records of authority, scope, supplier commitments and operational decisions;
  • improve our services, workflow, documentation, website and trade communications;
  • manage disputes, complaints, insurance matters or legal claims.

5.3 Trade marketing and professional communication


We may use personal information to:

  • send B2B trade updates, destination insights, service news or quiet-wellness programme commentary where we have consent or another lawful basis;
  • manage subscriptions, preferences, suppression records and unsubscribe requests;
  • invite relevant trade contacts to meetings, briefings or professional discussions;
  • measure the performance of our website, LinkedIn content, email campaigns and B2B communications.

We do not use traveller operational information for general marketing unless we have a clear lawful basis and the relevant consent or authority.


5.4 Legal, regulatory and safety purposes


We may use personal information to:

  • comply with applicable laws, regulations, accounting obligations and official requests;
  • protect our legal rights and legitimate business interests;
  • prevent fraud, misuse, cyber incidents or unauthorised access;
  • respond to data-security incidents;
  • protect the safety, health or wellbeing of travellers, staff, suppliers or others where necessary.

6. Direct marketing and trade updates

 

We send B2B marketing communications, trade updates or professional briefings only where lawful and appropriate.


For Australian trade contacts, our preferred practice is to use inbound marketing and express consent. For example, you may choose to subscribe through a website form, LinkedIn lead form or other opt-in mechanism. Where we request consent, we aim to use an active, unticked and unbundled consent box.


Each marketing email or direct electronic marketing communication will aim to:

  • clearly identify 森合同会社 (Mori Co., LLC) as the sender;
  • include accurate contact details;
  • be relevant to a professional B2B travel-trade context;
  • provide a simple and free unsubscribe or opt-out method;
  • honour unsubscribe requests promptly.

You may unsubscribe from our B2B trade updates at any time by using the unsubscribe link in our emails, replying with an opt-out request, or contacting us at info@journeysen.com.


We do not knowingly use harvested-address lists or send marketing communications to people who have opted out.


7. Cookies and analytics

 

Our website may use cookies and similar technologies to support website functionality, improve performance, protect security and understand how visitors use our site.


Cookies may include the following categories.


7.1 Essential cookies

These are required for website functionality, security, fraud prevention, traffic management and basic operation.


7.2 Analytics cookies

These help us understand website traffic, visitor behaviour, page performance and referral sources. Our website may use Google Analytics or similar analytics tools for these purposes. Google Analytics may collect information such as pages visited, approximate location, device and browser information, referral sources and interactions with our website through cookies or similar technologies.


7.3 Marketing or campaign cookies

These may help us understand the effectiveness of B2B campaigns, including LinkedIn or other professional marketing activity.


You can manage cookies through your browser settings. Disabling some cookies may affect website functionality. Where required, we will seek consent or provide cookie-management options in accordance with applicable law.


8. When we disclose personal information

 

We do not sell personal information.


We may disclose personal information to the following categories of recipients where necessary for the purposes described in this Privacy Policy.


8.1 Japan-side suppliers and service providers


Where required for B2B service delivery, we may disclose relevant traveller or operational information to:

  • accommodation providers;
  • transport providers;
  • guides, interpreters and local coordinators;
  • restaurants, activity providers, cultural venues and attractions;
  • museums, event venues and admission providers;
  • emergency or disruption-support contacts;
  • other Japan-side suppliers needed to deliver confirmed arrangements.

We disclose only the information reasonably necessary for the relevant supplier or service provider to perform its role.


8.2 B2B travel-trade partners


We may disclose information to the travel agency, tour operator, wholesaler or specialist adviser with whom we are working, including information relating to quotes, supplier confirmations, traveller data, incidents, service updates, cancellations, amendments and post-trip review.


8.3 Professional and operational service providers


We may disclose personal information to service providers that support our business, including:

  • website hosting, domain, security, content-delivery, analytics and optimisation providers;
  • cloud hosting and storage providers;
  • email, calendar and communication tools;
  • CRM, partner-record and marketing-preference platforms;
  • accounting, invoicing and payment-administration providers;
  • IT, cyber-security and data-backup service providers;
  • legal, accounting, insurance and professional advisers.

We use reputable third-party platforms and service providers to support our business operations, communications, marketing compliance and website performance. These may include website hosting, domain, security, content-delivery, CRM, email, calendar, cloud storage, document-management, analytics, accounting and business-administration providers. These providers may process, store or access personal information in countries outside Japan, depending on their systems, hosting arrangements and support operations. We may change or add service providers from time to time, but we will continue to apply appropriate confidentiality, access-control, data-minimisation and security measures.


8.4 Legal, regulatory and safety disclosure


We may disclose personal information where required or authorised by law, court order, regulator, government authority or law-enforcement body, or where reasonably necessary to protect safety, prevent fraud, respond to a serious incident, manage a claim or protect our legal rights.


8.5 Business transfer


If we restructure, merge, transfer or sell all or part of our business, we may disclose relevant personal information to professional advisers, counterparties or successor entities, subject to appropriate confidentiality and data-protection controls.


9. Cross-border processing and disclosure

 

Mori Co. is located in Japan. If you contact us from Australia, New Zealand, Europe, the United Kingdom, Canada, the United States or another jurisdiction, your personal information may be transferred to, stored in or accessed from Japan.


We may also use service providers located in, or operating from, other countries. These may include website hosting, security, CRM, cloud, email, analytics, payment, accounting, document-management and business-administration providers.


Where personal information is transferred, disclosed or made accessible across borders, we take reasonable steps to use appropriate safeguards. These may include:

  • contractual confidentiality and data-protection terms;
  • limiting data shared to what is necessary;
  • restricting access to authorised persons;
  • using reputable service providers with recognised security and privacy controls;
  • applying access, retention and deletion controls;
  • using standard contractual clauses or equivalent transfer mechanisms where required;
  • reviewing supplier and platform settings where practicable;
  • maintaining records of key service providers and data flows where appropriate;
  • providing information about foreign third-party disclosure, or obtaining consent, where required by applicable law.

For international trade partners, this Privacy Policy is intended to make clear that information provided to Mori Co. may be processed in Japan and may be disclosed to relevant Japan-side suppliers and service providers where necessary for B2B service delivery.


Where a travel-trade partner discloses traveller information to Mori Co. in Japan, that partner should assess its own privacy obligations, including whether the traveller has been appropriately notified any additional steps are required before disclosing personal information to an overseas recipient.


10. Sensitive information

 

We may occasionally receive sensitive, special-category or otherwise particularly confidential information, such as dietary, allergy, health, accessibility, mobility, religious or cultural requirements, where this information is necessary to arrange appropriate travel-related services.


We ask B2B partners to:

  • provide such information only where necessary;
  • ensure the traveller has been informed;
  • obtain consent or other authority where required;
  • avoid sending excessive details;
  • use secure channels where practicable;
  • update us if the information changes or is no longer required.

We use such information only for the operational purpose for which it was provided, unless another lawful basis applies.


11. Data quality and accuracy

 

We rely on our B2B partners, website users and other information providers to give accurate, complete and up-to-date information.


If you become aware that information provided to us is inaccurate, incomplete or outdated, please contact us so that we can correct or update it where appropriate.


12. Security

 

We take reasonable technical and organisational measures to protect personal information from unauthorised access, misuse, interference, loss, disclosure, alteration or destruction.


These measures may include:

  • access controls;
  • password and account-management procedures;
  • secure cloud and email systems;
  • internal data-handling rules;
  • limited staff access based on business need;
  • supplier and service-provider controls;
  • data-backup and recovery procedures;
  • device and document-management practices;
  • incident-response procedures.

No method of transmission over the internet or electronic storage is completely secure. We therefore cannot guarantee absolute security, but we take reasonable steps to protect the information we hold.


13. Data breach and incident response

 

If we become aware of an actual or suspected data breach involving personal information, we will assess the matter and take appropriate action.


Our response may include:

  • Containment — taking steps to stop further unauthorised access, disclosure or loss.
  • Assessment — identifying what happened, what information was affected, who may be impacted and what risks may arise.
  • Notification — notifying affected parties, business partners, regulators, including the Personal Information Protection Commission where required, or other relevant persons where required or appropriate.
  • Review — identifying corrective action to reduce the risk of recurrence.

Where a breach involves information provided by a B2B partner, we will work with that partner to coordinate an appropriate response.


14. Retention of personal information

 

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including business, operational, legal, tax, accounting, audit, insurance, dispute-resolution and compliance purposes.


Indicative retention periods are:

  • business contact records: for the duration of the business relationship and a reasonable period afterwards;
  • B2B enquiry and proposal records: generally up to 3 years after the last meaningful interaction, unless a longer period is required;
  • confirmed booking, invoice, payment and supplier records: generally up to 7 years where required for tax, accounting, audit or legal purposes;
  • traveller operational records: for the period necessary to deliver services and manage post-trip matters, then deleted, de-identified or archived where appropriate;
  • marketing consent records: while you remain subscribed and for a reasonable period afterwards to evidence consent and manage suppression;
  • unsubscribe and suppression records: retained as necessary to ensure we do not send further marketing communications;
  • website analytics data: retained in accordance with the settings of the relevant analytics platform, unless deleted earlier.

We may retain de-identified or aggregated information for business analysis, service improvement, trend analysis or reporting.


15. Access, correction and other privacy requests

 

Depending on applicable law and your relationship with us, you may have rights to:

  • request access to personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion or erasure in certain circumstances;
  • object to, restrict or withdraw consent for certain processing;
  • request information about how your personal information has been used or disclosed;
  • request information relating to retained personal data or third-party provision records where applicable;
  • opt out of direct marketing;
  • make a privacy complaint.

To make a request, contact us at info@journeysen.com.


We may need to verify your identity and may ask for additional information to help us respond. We will respond within a reasonable period and in accordance with applicable law.


In some cases, we may not be able to provide access, deletion or correction if doing so would breach legal obligations, affect another person’s privacy, prejudice a legal claim, compromise security, or conflict with record-keeping obligations. If we refuse a request, we will explain the reason where appropriate and lawful.


16. Marketing opt-out

 

You can opt out of our B2B marketing communications at any time.


You may do so by:

  • using the unsubscribe link in our emails;
  • replying with “unsubscribe” or “no updates”;
  • contacting us at info@journeysen.com.

After you opt out, we may retain limited information necessary to record and honour your unsubscribe request. We may still send you non-marketing communications where necessary, such as messages about an active enquiry, proposal, confirmed arrangement, payment, supplier coordination, service change, operational issue or legal matter.


17. Links to third-party websites and platforms

 

Our website, emails or LinkedIn posts may contain links to third-party websites, platforms, booking tools, professional networks or supplier pages.


We are not responsible for the privacy practices, security or content of third-party websites or platforms. You should review the privacy policy of any third-party site or platform before providing personal information.


18. Children and direct consumer enquiries

 

Our website and B2B services are intended for business and travel-trade use. We do not knowingly collect personal information directly from children for marketing purposes.


If a consumer or traveller contacts us directly, we may respond to explain our B2B role and, where appropriate, refer them back to their travel agency, tour operator or professional adviser.


19. Australian travel-trade partners and traveller disclosures

 

Where a travel agency, tour operator, wholesaler or specialist adviser provides traveller information to Mori Co., that partner should ensure that:

  • the traveller has been given an appropriate privacy notice;
  • the traveller understands that their information may be disclosed to Japan-based recipients;
  • the disclosure is necessary for quoting, booking, supplier coordination, service delivery, safety, incident response or agreed travel operations;
  • sensitive information is shared only where necessary and with appropriate authority or consent;
  • the information is accurate, current and limited to what is required;
  • the partner’s traveller-facing terms, privacy policy and disclosures are consistent with the intended data flow;
  • the partner has considered whether any additional privacy, consumer-disclosure or contractual obligations apply to its own handling of traveller information.

Mori Co. will use the information for the agreed B2B operational purpose and will not use traveller information for unrelated marketing.


20. Complaints

 

If you have a concern about how we have handled personal information, please contact us first so that we can investigate and respond.


Contact: info@journeysen.com


Please include:

  • your name and contact details;
  • a clear description of your concern;
  • any relevant correspondence, dates or reference details;
  • the outcome you are seeking.

We will acknowledge and review your complaint within a reasonable period. If the matter relates to an overseas partner’s handling of traveller information, we may need to coordinate with that partner.


Depending on your location and applicable law, you may also have the right to contact a relevant privacy or data-protection authority.


21. Contact details

 

森合同会社 (Mori Co., LLC)

Registered Travel Service Arrangement Business(旅行サービス手配業)

Tokyo Metropolitan Governor Registration No. 20869


Address:

Shimofuri Building 302,

6-33-17 Komagome, Toshima-ku,

Tokyo 170-0003, Japan


Tel: +81-(0)3-5972-1285

Fax: +81-(0)3-5972-1295

Email: info@journeysen.com

Website: https://journeysen.com


22. Changes to this Privacy Policy

 

We may update this Privacy Policy from time to time to reflect changes in our business, services, technology, legal obligations, regulatory expectations or data-handling practices.


The updated version will be posted on our website with the “Last updated” date revised. Where required or appropriate, we may also notify business partners or subscribers of material changes by email or other reasonable means.


Your continued use of our website or engagement with our services after the updated Privacy Policy is posted will be treated as acknowledgement of the updated policy, to the extent permitted by applicable law and without limiting any rights you may have.