Privacy
Privacy Statement
ON THE LISTS (the “Service”) provides online ticketing and table reservation systems for venues. The Service complies with Japan’s Act on the Protection of Personal Information (APPI) and Singapore’s Personal Data Protection Act (PDPA), together with the related guidelines issued under each, and provides the same level of protection to all customers regardless of nationality or of the venue they visit. This statement explains how the Service handles your personal information. If you enter personal information on behalf of another person, please do so only with their consent and share this statement with them.
1Information We Collect
The information you are asked to enter depends on how you use the Service.
(a) When you purchase a ticket or reserve a table:
- Name
- Email address
- Phone number
- (For table reservations only) an optional free-text request field
(b) When you register from an invitation link (guest list):
- Name
- Gender (male or female)
- Either your age group (20s, 30s, 40s, or 50s and above) or your date of birth, depending on the registration form used by the venue
- Email address (optional)
- Phone number (optional)
If you are attending with companions, the representative enters the same items for each companion. Please do so only with their consent.
(c) When you contact us by email from the ON THE LISTS website (onthelists.com):
The website does not have an inquiry form. The “request a demo” links open your own email application with a suggested message, which you are free to edit before sending. We therefore receive whatever you choose to write, together with the email address you send from. The suggested message asks for:
- Venue name
- Your name
- City or location
- Estimated guests per night
- Your preferred way to be contacted (email, phone, or WhatsApp)
- Anything else you would like to add, such as preferred dates for a demo
In either case, the Service does not collect your address, and does not collect sensitive personal information without your prior consent except as required by law. Please do not enter personal information of others in the request field.
2Purpose of Use
The information collected is used only for the following purposes:
- Receiving and confirming your purchase, reservation, or guest list registration, and providing it to the venue you selected
- Issuing electronic tickets (QR codes), sending confirmation notices, and verifying entry on the day of the event
- Confirming that you meet the venue’s minimum age requirement for entry
- Handling refunds, cancellations, and other matters related to your transaction
- Compiling attendance statistics for the venue (such as totals by gender and age group) to help the venue plan its events
- Customer relationship management by the venue, including assistance on your future visits
- Sending you information about upcoming events at the venue, where you have provided your email address or phone number
- Responding to inquiries you send us from our website
- Preventing fraudulent use and maintaining security
3Role of the Service
The Service acts in two different roles depending on how your information reached us.
(1) Information you provided to a venue (sections 1(a) and 1(b) above). The Service stores and processes it on behalf of the venue as a contracted data processor (a “data intermediary” under Singapore’s PDPA). The party that determines the purpose of use — the data controller under the APPI, and the organisation responsible under the PDPA — is the venue at which you made your purchase or reservation, or for which you registered on the guest list. Where you registered from an invitation link, the venue that issued that link is that party.
For information in this category, data in the Service is technically separated and managed per venue; information provided to one venue is never visible to another venue. The Service’s operators do not access the content of your personal information except to the extent necessary for system maintenance and operation. Venues may export their own guest information into their own systems. Please refer to each venue’s privacy policy for how exported data is handled.
(2) Information you provided to us through our website (section 1(c) above). ON THE LISTS itself determines the purpose of use and is responsible for it.
4Retention Period
For purchases and reservations (section 1(a)), the Service retains your email address, phone number, and the request field for the period necessary to handle refunds, chargebacks, and other transaction-related matters after the event, and thereafter deletes them or processes them into a form that can no longer identify individuals, except where retention is required by law.
Guest list registrations (section 1(b)). 26 months after your visit, the Service deletes or anonymizes your name, email address, phone number, and date of birth. Your gender, age group, visit dates, entry category, and the host through whom you registered are retained after that point in a form that can no longer identify you, for the purpose of compiling attendance statistics for the venue. Records of past events therefore remain complete as counts, while the individuals recorded in them can no longer be identified.
Purchases and reservations (section 1(a)), including table reservations. Your name and the record of what you purchased or reserved are retained for the venue’s customer relationship management for as long as the venue uses the Service, so that the venue can recognise you and serve you on your next visit.
Inquiries sent to us from our website (section 1(c)) are retained for as long as necessary to handle the inquiry and for business records.
Where retention is required by law, the Service retains the relevant information for the period required.
5Credit Card and Payment Information
The Service never collects or stores credit card information. All payment processing is performed by PCI DSS-compliant payment processors contracted by each venue, and card information is transmitted directly from your device to the payment processor. Payments are made by you directly to the venue; the Service does not receive or hold your funds. The Service receives only the result of the payment and a reference identifier (token) for the transaction, and has no means of obtaining the card number itself.
For the handling of card information by the payment processor, please refer to that company’s privacy policy.
6Provision to Third Parties
The Service does not provide your personal information to any third party other than the venue you selected and, to the extent necessary for payment processing, the payment processor contracted by that venue, except as required by law.
7Data Storage Location and Security Measures
The Service is cloud-based. Your personal information is stored primarily on cloud infrastructure located in Japan. Some processing and storage — such as email delivery, inquiries you send us by email, and website analytics — takes place on services located outside Japan, including in the United States and the EU. The Service understands the personal information protection systems of the countries where data is stored, and implements security measures including encryption of communications and stored data, per-venue access control (row-level security), authentication management, and log monitoring. Where the transfer of personal data to a third party in a foreign country applies — including, for customers of a venue outside Japan, the storage of your data in Japan — the Service takes the measures required by law, including the requirements for overseas transfer under the APPI and the Transfer Limitation Obligation under the PDPA.
8In the Event of a Data Breach
In the event of a leak, loss, or damage of personal data that is likely to harm the rights and interests of individuals, the Service will promptly notify the venue as the entrusting party and, in cooperation with the venue, report to the competent authority (the Personal Information Protection Commission in Japan, and the Personal Data Protection Commission (PDPC) in Singapore) and notify the affected individuals in accordance with the applicable law, or support the venue in doing so. The Service will also investigate the cause and formulate and publish measures to prevent recurrence.
9Requests for Disclosure, Correction, and Suspension of Use
You may request disclosure, correction, addition, deletion, suspension of use, erasure, or suspension of third-party provision of your personal information. In Singapore, these correspond to your right of access and right of correction under the PDPA.
Where your information was provided to a venue (sections 1(a) and 1(b)), the Service acts as a contracted processor, so please direct requests in principle to that venue. If you contact the Service’s contact point, we will respond in cooperation with the venue. Where your information was provided through our website (section 1(c)), please direct requests to the Service’s contact point below. In either case, we may ask you to submit documents to verify your identity.
ON THE LISTS Personal Information Contact: privacy@onthelists.com
10Cookies and Access Analytics
The Service uses cookies only to keep you signed in to the administration screens and to remember the display language of those screens. Guests who register from an invitation link are not asked to sign in. The Service does not use cookies for advertising. Where the venue’s registration form offers to remember your details for your next visit, that information is stored only on your own device and is not sent anywhere until you submit a registration; you can erase it at any time with the Clear button on the form.
The ON THE LISTS website (onthelists.com) uses a privacy-focused analytics tool (Plausible Analytics) to understand how the site is used. It does not set cookies, does not create persistent identifiers, and does not track you across other websites. The data it collects is processed and stored on infrastructure located within the EU. Because the tool does not identify individual visitors, we are not able to offer an individual opt-out. You can block it using your browser’s settings or an extension.
11Revisions to This Statement
The Service may revise this statement in response to amendments to laws and regulations, updates to the guidelines of the Personal Information Protection Commission and the Personal Data Protection Commission (PDPC), and changes to the Service. Material changes will be announced on the Service.
Last updated · 21 August 2026