DRAFT — DO NOT PUBLISH UNTIL THE ITEMS MARKED “TO CONFIRM” HAVE BEEN COMPLETED AND NIOTA LLC’S ACTUAL PRACTICES HAVE BEEN VERIFIED.
Privacy Policy
Last updated: 7 September 2026
NIOTA LLC, trading as Roam Defender (“Roam Defender”, “we”, “us”, or “our”), handles personal information in accordance with applicable Japanese law, including the Act on the Protection of Personal Information (“APPI”). This Policy explains our handling of personal information in connection with our website, LINE Official Account, vehicle rental, booking, payment, trip-planning, and customer-support services.
1. Business Operator
Operator: NIOTA LLC (Roam Defender)
Registered address: [TO CONFIRM — insert NIOTA LLC’s complete registered address]
Representative: [TO CONFIRM — insert the name of NIOTA LLC’s representative]
Privacy contact: admin@roam-defender.com
2. Personal Information We Handle
Depending on the service you use, we may handle:
- Identity and contact data: name, nickname, email address, telephone number, address, LINE display name, LINE user identifier, language, and contact preferences.
- Booking and trip data: requested rental dates and times, vehicle, number of travellers, pickup and return details, itinerary and campsite preferences, add-ons, promotions, and booking status.
- Driver-verification data: driver names and, only where reasonably necessary for rental eligibility, insurance, or legal obligations, passport and domestic or international driving-licence details or copies.
- Transaction data: quotations, invoices, payment status, refunds, deposits, toll charges, insurance selections, and transaction references. Full payment-card data is normally collected directly by the payment provider, not by us.
- Communications: messages, images, files, call notes, support history, feedback, and reviews sent through LINE, email, telephone, our website, or other channels.
- Website and device data: IP address, browser and device information, cookies, logs, website interactions, and referral source.
Please provide only information that is necessary. Do not send passwords or complete payment-card details. Do not send passport or driving-licence images through ordinary chat unless we specifically request them and identify an approved submission method.
3. How We Collect Information
We collect information directly from you; through our website, booking forms, and LINE Official Account; from payment, booking, insurance, or service providers involved in your request; and automatically through cookies and similar technologies. Where Japanese law requires us to state a purpose at the point of collection, we will do so on the relevant form or screen.
4. Purposes of Use
We use personal information, to the extent necessary, for the following specified purposes:
- to respond to enquiries, check availability, prepare quotations, and create, administer, change, or cancel reservations;
- to process payments, deposits, refunds, invoices, toll charges, and related accounting and tax records;
- to verify driver eligibility and meet rental, insurance, safety, fraud-prevention, and legal requirements;
- to arrange pickup, return, vehicle delivery, roadside assistance, campsites, and other requested trip services;
- to provide customer support and communicate before, during, and after a rental, including urgent safety communications;
- to investigate accidents, damage, misuse, complaints, disputes, security incidents, and legal claims;
- to maintain and improve our website, operations, customer journey, pricing rules, and service quality using appropriately limited data;
- to send promotions or service news where permitted by law or with consent, and to manage opt-out requests; and
- to comply with law, respond to lawful requests, and establish, exercise, or defend legal rights.
If we materially change a purpose beyond what a customer could reasonably expect, we will provide notice and obtain consent where required.
5. LINE Official Account and Automated/AI Assistance
When you communicate with our LINE Official Account, LY Corporation and its group or service entities may process account, device, message, and interaction information under their own terms and privacy notices. LINE may provide us with information such as your LINE user identifier, display name, messages, and interaction events.
We may use rules-based automation and, after the relevant system and vendor safeguards have been approved, AI-assisted tools to classify requests, collect booking details, check availability against our booking records, calculate draft quotations using approved pricing rules, summarise conversations, draft replies, and route cases to staff. We will not rely solely on automated output for final confirmation of availability, special pricing, driver eligibility, booking changes, refunds, or other decisions with material effects. Staff may review and correct outputs.
Passport, driving-licence, full payment-card, and other high-risk identity information must not be intentionally submitted to a generative-AI provider unless NIOTA LLC has first approved the provider, necessity, data location, contractual safeguards, access controls, and any consent or notice required by law. [TO CONFIRM before launch: AI provider(s), processing country/countries, retention, training settings, and human-review workflow.]
6. Entrusted Service Providers and Third-Party Provision
We may entrust processing to service providers acting on our instructions, such as website hosting, WordPress-related services, booking and customer-management systems, email, security, analytics, cloud services, communications platforms, and payment processors. We select and supervise contractors as required by applicable law.
We may also provide the minimum necessary information to independent recipients—including insurers, roadside-assistance providers, vehicle-delivery personnel, campsites or other suppliers requested by you, professional advisers, and competent authorities—where you have consented, provision is necessary to perform your requested arrangements and is lawful, or another legal basis applies. We do not sell personal data.
Square processes payment information under its own privacy notice. LINE and other third-party services may also handle information under their own privacy terms. A privacy notice does not by itself replace consent where APPI requires prior consent for third-party provision.
7. Processing or Transfer Outside Japan
Some approved service providers may process personal data outside Japan. Before a transfer that is subject to APPI’s rules for foreign third parties, we will use an available lawful mechanism. Depending on the recipient and country, this may include: (a) prior consent after providing the information required by law about the destination country and recipient’s safeguards; (b) a recipient in a jurisdiction recognised under Japanese law as having an equivalent system; or (c) contractual or other arrangements that require continuous implementation of measures equivalent to those required by APPI, together with the required oversight and information.
[TO CONFIRM before publication and before enabling AI/webhook processing: identify each overseas recipient, destination country or region, applicable transfer mechanism, and how customers can obtain information about safeguards.]
8. Retention and Identity Documents
We retain personal information only for periods reasonably necessary for the purposes above, taking account of the booking lifecycle, safety, claims, limitation periods, and legal, accounting, tax, and insurance obligations. We then delete, securely dispose of, or anonymise it, unless continued retention is required or permitted by law.
Passport and driving-licence copies must be collected only where necessary, access-restricted, and deleted or securely disposed of promptly when the verification, rental, insurance, claim, or legally required retention purpose no longer applies. [TO CONFIRM operationally: set and implement documented retention periods for enquiries, LINE messages, unsuccessful quotations, bookings, transaction records, identity documents, accident/insurance files, website logs, and backups.]
9. Security Control Measures
We maintain measures appropriate to our size, systems, risks, and the information handled. These include defining responsibility and handling rules; limiting staff and contractor access by role; staff confidentiality and training; protecting devices, records, and work areas against loss or unauthorised viewing; account authentication, access controls, software updates, malware and unauthorised-access protections; secure deletion and disposal; incident escalation; oversight of contractors; and, when data is handled overseas, understanding the relevant external legal environment. We review these measures and will provide further information where required by law, except where disclosure could undermine security.
10. Cookies and Analytics
Our website may use cookies and similar technologies that are strictly necessary for website, booking, security, and payment functions. Optional analytics or advertising technologies will be described through the relevant notice or consent control where required. You can manage cookies through your browser and any cookie controls displayed on our website; disabling necessary cookies may affect functionality.
[TO CONFIRM before publication: list the analytics, advertising, embedded-content, and cookie providers actually active on the website, their purposes, retention, and opt-out or consent controls.]
11. Requests Concerning Retained Personal Data
Subject to APPI and other applicable law, you may request notification of purpose of use; disclosure of retained personal data or third-party provision records; correction, addition, or deletion of inaccurate data; and suspension of use, deletion, or suspension of third-party provision where the legal conditions are met.
Send requests to admin@roam-defender.com with your name, contact details, the right requested, and enough information to identify the relevant record. We may request reasonable identity or authority verification. We will explain any applicable procedure or fee before processing and respond without undue delay. We may refuse all or part of a request where permitted by law and, where required, explain the reason.
12. Marketing Choices
You may opt out of marketing messages at any time by using the method shown in the message or contacting us. This does not stop communications necessary for an active booking, safety, payment, or legal matter.
13. Children
Vehicle-rental contracts are intended for adults legally able to enter into the agreement. If limited information about a child is needed for a booking, such as a child-seat request, a parent or legal guardian should provide it. Where valid consent cannot be given by the child, we will seek consent from the appropriate representative when required.
14. Personal Data Breaches
We investigate suspected loss, unauthorised access, disclosure, or other security incidents and take containment and remediation steps. Where APPI or another applicable law requires notice to the Personal Information Protection Commission or affected individuals, we will provide it within the required manner and timing.
15. Changes to This Policy
We may update this Policy to reflect changes in services, systems, vendors, or law. The latest version will be posted on this page with the updated date. If a change requires consent, we will seek it separately.
16. Contact and Complaints
NIOTA LLC (Roam Defender)
Registered address: [TO CONFIRM]
Representative: [TO CONFIRM]
Email: admin@roam-defender.com
Website: https://roam-defender.com/
Please use the contact above for privacy enquiries, requests, or complaints. [TO CONFIRM: whether NIOTA LLC belongs to a certified personal information protection organisation; if so, add its name and complaint contact.]
Internal legal-review note: this corrected draft is not ready for publication until all “TO CONFIRM” items match NIOTA LLC’s actual systems and operations. A Japanese-qualified lawyer should review the completed version and the associated booking forms, consent language, vendor contracts, and internal procedures.



