1. What we collect
When you book a reservation or submit a form, we collect: name, email, phone number, party size, date, time, dietary preferences, and any notes you add. For private-event inquiries, we may additionally collect company name, budget range, and event details. We never collect payment card numbers directly — all transactions run through PCI-compliant partners (Stripe for gift cards, Tock/OpenTable-equivalent for deposits).
2. Why we collect it
- To fulfill the reservation or inquiry. Without contact info, we can't confirm your seat.
- To communicate about your booking. Changes, cancellations, weather advisories.
- With your explicit consent, to send the Priority List or Journal subscribers a seasonal note — typically 2–4 times a year.
- To improve the experience. Aggregate, anonymized analytics on which pages guests use and which CTAs they act on.
3. What we do NOT do
- We do not sell your information to third parties. Ever.
- We do not share your information with advertisers or data brokers.
- We do not run behavioral retargeting ads based on your visit.
- We do not place marketing cookies without your consent (EU/UK only via a cookie banner; US guests are not targeted with non-essential cookies by default).
4. How long we keep it
Reservation data is retained for 24 months after your last visit, then deleted or anonymized. Private-event contracts are retained for 7 years per business-record requirements. Email subscriber lists are retained until you unsubscribe. Gift-card purchase records are retained for the longer of the card's validity period or 3 years.
5. Who sees it
Access to guest data is limited to the reservations, events, and management teams (approximately 8 people). Our technology providers (reservations platform, email sender, payment processor) see only the data required to perform their function and operate under written data-processing agreements.
6. Analytics & cookies
We use a privacy-first analytics tool that does not track you across sites or build a profile. Events (page views, CTA clicks, form submissions) are recorded in aggregate and stripped of personal identifiers in the tracking layer before they leave your browser. No third-party advertising cookies are placed.
7. Your rights
Regardless of where you live, you can:
- Request a copy of the data we hold about you.
- Request correction or deletion of that data.
- Unsubscribe from any email communication with one click.
- Opt out of non-essential cookies and analytics.
Write to privacy@kurohanahouse.com. We respond within 30 days; EU/UK requests within 7 days per GDPR.
8. Children
Our services are not intended for children under 16. We do not knowingly collect information from anyone under 16. If you believe a child has submitted information to us, contact us and we'll delete it.
9. Security
Data is stored in encrypted form (at rest and in transit). Our reservations platform and payment processors meet or exceed SOC 2 / PCI DSS compliance requirements. In the unlikely event of a breach affecting your data, we will notify affected guests within 72 hours.
10. Changes to this policy
If we change this policy, we'll update the "Updated" date at the top of this page. Material changes will be announced on the homepage and to any subscribers at least 14 days in advance.
Contact the privacy team: privacy@kurohanahouse.com