top of page

Privacy Policy

Last Updated : 2026-08-12   |   Effective: 2026-08-12
 

LIBERIUS TECHNOLOGIES INC., (“Liberius”) has established a privacy policy to guide the management of personal information for users who engage with the services offered on Hotelwee. This policy demonstrates our dedication to safeguarding users' personal information and maintaining responsible data handling practices within the context of our services.

 

1. Personal Information

Personal information" refers to "personal information" as defined in the Act on the Protection of Personal Information, and includes information about living individuals that can be used to identify specific individuals by name, date of birth, address, telephone number, contact information, and other descriptions, as well as data related to appearance, fingerprints, voiceprints, and health insurance card insurer numbers.  "Personal information" refers to information that can identify a specific individual by itself, such as name, date of birth, address, telephone number, contact information, or any other description.

2. Information that we collect​

When a user registers for our services, we may request personal information such as name, date of birth, address, telephone number, email address, bank account number, credit card number, and driver's license number. Additionally, transaction records and payment information, including the user's personal information, may be shared with our partners (including information providers, advertisers, and advertisement distributors, etc.) during interactions between the user and our partners.  If a User chooses to connect a Google account to the Service, we also collect and process data from that Google account through Google APIs ("Google User Data"). The categories of Google User Data, the purposes for which we use them, and the way we store, share, and delete them are described in Section 10 (Google User Data — Gmail Integration) below.

3. How we use your information

The purposes for collecting and using personal information are as follows:

1) To provide and operate our services.

2) To respond to user inquiries (including verification of identity).

3) To send email notifications about new features, updates, campaigns, and other relevant information related to the services users are utilizing, as well as information on other services provided by the Liberius.

4) To contact users when necessary for maintenance, important notices, and other essential communications.

5) To address instances where users have violated the Terms of Service.

6) To identify users who have breached the Terms of Use or are attempting to use the Service for illegal or unjust purposes, and to deny their access to the Service.

7) To enable users to view, modify, or delete their own registration information, or to review their service usage status.

8) To process payments for paid services.

9) To provide the Gmail integration features described in Section 10, including displaying, organizing, searching, summarizing, drafting, and sending email from a Google account that the User has connected to the Service.

10) For any purposes incidental to the above-mentioned uses.

 

4. Change of purpose of use

1) We will only change the purpose of using personal information when it is reasonably acknowledged that the new purpose is related to the original purpose of use prior to the change.

2) In the event of a change in the purpose of use, we will inform the user of the updated purpose by following our prescribed methods or by making an announcement on this website (Hotelwee).

 

5. How we share your information with third-parties

We will not provide personal information to a third party without the prior consent of the user, except in the following cases. This exclusion applies to cases permitted under the Personal Information Protection Law and other relevant regulations:

 

1) When it is necessary to protect a person's life, body, or property, and obtaining the individual's consent is difficult.

2) In cases where providing personal information is particularly necessary for improving public health or promoting the sound growth of children, and obtaining the individual's consent is difficult.

3) When it is necessary to cooperate with a state organ, a local government, or an individual or entity entrusted by either of the former two in executing affairs prescribed by law, and obtaining the individual's consent is likely to impede the execution of the affairs in question.

4) When we have notified or announced the following matters in advance, and when we have notified the Personal Information Protection Committee:

  • The purpose of use includes providing information to a third party.

  • The specific data items to be provided to the third party.

  • The means or method of providing information to the third party.

  • The provision of personal information to a third party will be discontinued at the request of the individual concerned.

  • The method of accepting the individual's request.

Google User Data is subject to additional and stricter sharing restrictions. Notwithstanding anything to the contrary in this Section 5, we share Google User Data only as described in Section 10.6, and we never sell it, transfer it to data brokers or information resellers, or use it for advertising.

6. Disclosure of personal information

1) When an individual requests the disclosure of their personal information, we will promptly provide the information to them. However, we may decide not to disclose all or part of the personal information if any of the following cases apply. A fee of 1,000 yen will be charged for each instance of personal information disclosure:

  • When there is a risk of harm to the life, body, property, or other rights or interests of the individual or a third party.

  • If there is a risk of significant hindrance to the proper conduct of our business.

  • In the event of any other violation of laws and regulations.

2) Despite the previous paragraph, as a general rule, the Liberius will not disclose non-personal information, such as historical data and characteristic information.

7.  Correction and deletion of personal information

​1) If a user's personal information held by the Liberius is incorrect, the user may request the Liberius to correct, add, or delete their personal information following the procedures prescribed by the Liberius.

2) If we determine that it is necessary to address a user's request as described in the previous paragraph, we will promptly make the necessary corrections or adjustments to the relevant personal information.

3) Upon making a correction or adjustment based on the previous paragraph, or when deciding not to make any changes, we will promptly notify the user of our decision.

8.  Suspension of use of personal information

1) An individual requests us to cease the use or delete their personal information (hereinafter referred to as "Cease of Use") on the grounds that it has been handled beyond the scope of the purpose of use or obtained through wrongful means, we will promptly conduct the necessary investigation.

2) Based on the results of the investigation mentioned in the previous paragraph, we will take appropriate action without delay.

3) In cases where we implement a cessation of use, etc. based on the previous paragraph, or when we decide not to cease the use, etc., we will promptly notify the user of our decision.

4) Despite the preceding two paragraphs, if the cessation of use involves a significant amount of cost or is otherwise difficult to implement, and if alternative measures can be taken to protect the rights and interests of the user, we will implement such alternative measures.

9.  Revision of this policy

1) The contents of this Privacy Policy may be changed without prior notice to the user, except as otherwise required by law or other regulations.

2) Unless otherwise specified by the Liberius, the revised Privacy Policy shall take effect from the moment it is published on this website.

​3) Notwithstanding the preceding paragraphs, if we intend to make a change that materially expands how we access, use, store, or share Google User Data, we will notify affected Users by email or in-product notice at least 14 days before the change takes effect, and where required we will obtain renewed consent.

10. Google User Data (Gmail Integration)

**10.1 Overview and optional nature**
Users who operate accommodation businesses may choose to connect a Google account (Gmail) to the Service so that Hotelwee can help them read, organize, draft, and send guest correspondence from their own mailbox. This connection is entirely optional; the remainder of the Service functions without it.

 

**10.2 Permissions (OAuth scopes) we request and why**
 

​​​​​​​​​​

 

 

 

 

 



 

 

 

 

 

 

Gmail scopes that permit reading, creating, or modifying message content, metadata, or headers are classified by Google as **restricted scopes**, and are therefore subject to the additional requirements described in Sections 10.5 through 10.8.
The connection is established only when an authorized representative of the User completes Google's OAuth consent screen and grants the permissions listed in Section 10.2. We do not access any Google account data before that consent is given, and we do not access any Google account other than the one the User connects.
In this Privacy Policy, "**Google User Data**" means data that we obtain from a connected Google account through Google APIs, including raw data and any data aggregated, anonymized, or derived from it.

 

**10.3 Google User Data we access and store**
When a Google account is connected, we may access and store:
1) Message content of email in the connected mailbox, including subject lines, message bodies, and attachments;
2) Message metadata, including sender and recipient addresses, timestamps, message and thread identifiers, headers, and labels;
3) Drafts created by or through the Service, and records of messages sent through the Service;
4) The email address, account identifier, and basic profile information of the connected Google account; and
5) OAuth access tokens and refresh tokens issued by Google.
If Hotelwee limits synchronization — for example, only messages in specific labels, only messages newer than a given date, or only messages matching guest-correspondence rules — state that limit here. Google expects data minimization, and a narrower statement is both more accurate and easier to approve.

**10.4 How we use Google User Data**
We use Google User Data only to provide and improve the user-facing Gmail integration features that are visible and prominent in the Hotelwee interface, namely:
1) Displaying guest email in a unified inbox and organizing it by conversation, property, and reservation;
2) Matching messages to reservation and guest records held in the Service;
3) Searching, filtering, labelling, and tracking the status of guest correspondence;
4) Generating AI-assisted summaries and suggested reply drafts that are presented to the User for review inside the Service;
5) Sending, replying to, and forwarding email at the User's instruction or with the User's approval; and
6) Detecting and preventing abuse, spam, and security incidents affecting the Service.

**10.5 Limited Use commitment**
Hotelwee's use and transfer of information received from Google APIs, including Google Workspace scopes, to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements(https://developers.google.com/terms/api-services-user-data-policy#additional_requirements_for_specific_api_scopes).
In particular, we do **not**:
1) Sell Google User Data, or transfer it to advertising platforms, data brokers, or information resellers;
2) Use Google User Data to serve advertising, including retargeting, personalized, or interest-based advertising;
3) Use Google User Data to determine credit-worthiness or for lending purposes;
4) Use Google User Data to create, train, or improve any generalized machine learning or artificial intelligence model. Google User Data is used with AI models only to generate output for that same User's appropriate use case and user-facing features within the Service, and our AI service providers are contractually prohibited from using it for model training; or
5. Build databases of, scrape, or create permanent copies of Google User Data beyond what is necessary to provide the features described in Section 10.4.

**10.6 Sharing with service providers**
We do not share Google User Data with third parties except as follows:
1) With service providers that process Google User Data on our behalf and under contract solely to provide or improve the features described in Section 10.4, namely cloud hosting provider, e.g. Amazon Web Services / Google Cloud for hosting and storage and AI model provider(s), e.g. OpenAI / Anthropic / Google for the AI-assisted summary and drafting features. These providers are bound by confidentiality and data protection obligations at least as protective as this Privacy Policy, are prohibited from using Google User Data for their own purposes including model training, and retain the data only as long as necessary to return the output to us;
2) Where necessary for security purposes, such as investigating abuse or a security incident;
3) Where required to comply with applicable laws or regulations; or
4) As part of a merger, acquisition, or sale of assets, and only after obtaining the User's explicit prior consent.

**10.7 Human access to Google User Data**
We do not permit our personnel to read Google User Data, except:
1) Where we have obtained and documented the User's explicit consent or affirmative agreement to view specific messages or data, for example when the User asks us to investigate a problem with a particular message;
2) Where the data, including any derivation of it, has been aggregated and anonymized and is used for internal operations in accordance with applicable law;
3) Where necessary for security purposes, such as investigating a bug or abuse; or
4) Where necessary to comply with applicable laws or regulations.

**10.8 Security**
We treat Google User Data as confidential and protect it in transit and at rest. Our measures include:
1) Encryption of Google User Data at rest using an industry-accepted encryption standard, and transmission over secure modern protocols (TLS/HTTPS);
2) Encryption at rest of OAuth access tokens and refresh tokens, with key material held in a hardware security module or an equivalent-strength key management system;
3) Role-based access controls, least-privilege administrative access, and logging of access to production systems;
4) Protections against prompt injection and other attacks on the AI-assisted features; and
5) Completion of the Cloud Application Security Assessment (CASA) required by Google for applications using restricted scopes, and such periodic third-party security assessments as Google requires.

**10.9 Retention, disconnection, and deletion**
A User may disconnect a Google account at any time, either from within the Service at Settings → Integrations → Google or from the Google account permissions page at https://myaccount.google.com/permissions.
When a User disconnects, or when the Service Use Contract terminates:
1) We revoke and delete the associated OAuth access and refresh tokens without delay; and
2) We delete Google User Data stored by the Service within 30 days, except where retention for a longer period is required by law, and except for backup copies, which are deleted on our ordinary backup rotation of no more than 90 days.
A User may also request deletion of Google User Data without disconnecting the account by contacting us at the address in Section 11. Help documentation explaining how to manage and delete this data is available at https://www.hotelwee.com/.

**10.10 The User's own responsibilities**
A connected mailbox usually contains personal information about hotel guests and other third parties. As between Hotelwee and the User, the User is responsible for determining the purposes of that processing, for having the authority to connect the mailbox, and for giving any notice and obtaining any consent required from guests and mailbox account holders under applicable law. Hotelwee processes that information as the User's entrusted service provider and in accordance with the User's instructions and this Privacy Policy.

 

11.  Contact for Inquiries

For all inquiries regarding this policy, including requests relating to Google User Data, please contact us at:

Personal Information Inquiries Desk, Hotelwee.

hotelwee@liberius.co.jp

Scope
What it permits
Why Hotelwee needs it
Read messages, attachments, headers, labels
Display guest email in the Hotelwee inbox, match messages to reservations, generate summaries and suggested replies shown in the Hotelwee interface
Read and write messages, labels, drafts, and read/archive status
Save Hotelwee-generated drafts into the mailbox, apply and sync labels, mark messages read or archived when the User acts in Hotelwee
Send mail as the connected account
Send replies and guest messages that the User composes or approves in Hotelwee, from the hotel's own address
The email address and account identifier of the connected account
Identify which mailbox is connected and link it to the correct Hotelwee account
bottom of page