1. Scope, service boundaries and privacy law
This policy applies to the Gomanen software services when you browse our public pages, create or use a portal account, submit an application or payment through the portal, contact us through the services, or use Gomanen Shirube before, during or after a challenge.
It explains how those software services handle personal information. It does not set the commercial, participation, conduct, itinerary or operational conditions of a Gomanen Challenge. Those matters are governed by the separate Challenge Terms and Conditions and any challenge-specific notices provided to you.
Gomanen is established and administered in South Australia, Australia, while Gomanen Challenges take place across Japan and Shirube is principally used there during tours. We manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. This policy describes our obligations and practices under Australian privacy law.
You can browse public challenge information without identifying yourself. We need accurate identifying information when it is not practical to provide an account, booking, payment, safety or tour service anonymously.
2. Information we collect
The information we collect depends on how you interact with us. It may include:
Account and contact details
Your name, title, gender, email address, password hash, profile image, phone number, address, country, state, time zone, verification status and account preferences.
Tour, driver and safety details
Challenge applications, interests, team and vehicle assignments, driving preferences, date of birth, emergency contacts, dietary or lifestyle preferences, clothing size, medical conditions you disclose, and other information needed to plan and safely deliver a tour. Health information is sensitive information; we collect it with your consent where it is reasonably necessary for safety, accessibility or service delivery.
Payments and business records
Booking prices, deposits, balances, discounts, payment status, currency, transaction references, card type and last four digits, Stripe customer and payment identifiers, Wise transfer details, receipts, refunds, invoices and remittance records. We do not receive or store your full card number from Stripe Checkout.
Documents and communications
Documents you upload or sign, inspection records and signatures, support enquiries, emails, portal messages, notification delivery records, communication attachments, survey or feedback responses, and records of your agreement to challenge terms or safety notices.
Technical, security and activity data
IP address, browser and user-agent data, session identifiers, cookie data, access times, page and feature activity, device information, API and audit activity, and error or security diagnostics. We also collect the Shirube information described below.
How we collect information
We collect information directly from you, automatically when you use our services, from another participant when they nominate you as a teammate or emergency contact, and from providers involved in a transaction or service, such as Stripe, Wise or Google Maps. If you give us information about another person, please tell them and make sure you are authorised to do so.
3. Why we collect and use it
We collect, hold, use and disclose personal information where reasonably necessary to:
- create, secure and support accounts, authenticate users, and prevent fraud or misuse;
- assess applications, organise teams, vehicles, routes, accommodation and tour logistics;
- process deposits, payments, transfers, refunds, invoices and payment reconciliation;
- provide challenge information, documents, customer support, service messages and notifications;
- support participant welfare, emergency coordination, incident response and tour safety;
- operate Shirube’s location, messaging, media, moderation and notification features;
- use content uploaded to Shirube for Gomanen Challenge marketing and promotion as described below;
- maintain, troubleshoot, secure and improve our services and understand feature performance;
- keep appropriate business, tax, insurance, safety, audit and dispute records; and
- comply with law, court orders and lawful requests, or protect a person from a serious threat to life, health or safety.
We may use de-identified or aggregated information for reporting, planning and service improvement where it is no longer reasonably capable of identifying you.
4. Gomanen Shirube mobile app
Shirube is optional. You do not have to install or use it to participate in a tour. We strongly encourage it because it improves safety coordination, communication, group bonding and the overall challenge experience. If you do not use it, some live coordination and social features will be unavailable and we may use other practical communication arrangements.
You sign in to Shirube with the same verified account used for this portal. Depending on the features you enable, the app collects and shares the following information:
GPS location
When you actively start location sharing and grant operating-system permission, we receive latitude, longitude, accuracy, direction, speed and capture time. The app is designed for one active sharing device per team. Current team position is made available to authorised Gomanen staff and participants in the relevant challenge coordination group for navigation, regrouping, welfare checks and emergency assistance.
Device and app data
We collect an app installation identifier, device platform and label, app version, last-seen time, notification preferences and, if enabled, a push-notification token. Authentication tokens connect the app securely to your portal account.
Chat, safety and social activity
Messages, safety status updates (including “Need help”), typing activity, reactions, read status, mute and block choices, reports, and related timestamps are visible or used within the relevant tour audience. Gomanen staff can access messages and reports where needed for support, safety and moderation.
Uploaded media
Photos, videos, audio, captions and file metadata you choose to upload are stored and shared with the selected challenge audience. Content you upload may also be used by Gomanen Challenge for marketing and promotional purposes, including on our websites, social media, email, printed materials and advertising.
By uploading content to Shirube, you acknowledge and consent to this marketing and promotional use, confirm that you own the content or have all permissions needed to share and license it, including permission relating to identifiable people, and grant Gomanen Challenge a non-exclusive, worldwide, royalty-free licence to use, reproduce, edit, adapt, publish, communicate and display that content for those purposes. You retain ownership of your content.
You may contact us to ask that we stop new uses of your content. We may not be able to withdraw material that has already been published or distributed, and other participants may save content they can view.
Your location choices
Location sharing does not begin merely because you sign in. You can stop an active sharing session in Shirube and can withdraw location permission in your device settings. The active session also expires automatically and cannot continue beyond the applicable tour coordination window. Stopping location sharing does not remove location already received, which is retained only as described below.
Shirube supports safety communication but is not an emergency service and should not be relied on as the only way to obtain help. In an emergency, contact emergency services on 000 when it is safe and possible to do so.
7. Overseas processing and disclosure
We administer the software services from Australia and they are used in Japan during Gomanen Challenges. Personal information may be collected while you are in Japan, transferred to or stored in systems serving the Australian business, and accessed in Japan by authorised personnel or participants where a Shirube feature permits that access.
Some providers and their subprocessors operate globally. Personal information or technical request data may therefore be stored in or accessible from Australia, Japan, the United States and other countries in which the providers listed above operate. The exact countries can vary with provider infrastructure, support and the storage region configured for a service. Because global content-delivery and security networks may route requests dynamically, it is not practicable to identify every country in advance.
Where the Australian Privacy Principles apply to a cross-border disclosure, we take reasonable steps required by APP 8 before disclosing personal information. Overseas privacy protections may differ from those in Australia. Direct requests from your browser or device to Google, Cloudflare, OpenStreetMap, Bunny Fonts, social platforms or app-platform services are also governed by your relationship with those providers.
8. Retention and security
We keep personal information only for as long as it is reasonably needed for the purpose collected, to deliver an active or upcoming service, or to meet legal, tax, accounting, insurance, safety, fraud-prevention and dispute obligations. Retention varies by record type:
- Shirube location points and live snapshots are deleted when the relevant challenge coordination window closes.
- Shirube messages and reports about those messages are ordinarily deleted after 90 days, including where a report has not yet been actioned.
- Validated Shirube photos, videos and audio are retained privately on an ongoing basis for the marketing and promotional purposes described in this policy. Incomplete, rejected or failed uploads expire sooner.
- Shirube mobile access tokens ordinarily expire after 90 days and can be revoked sooner by signing out or deleting an account.
- Session, diagnostic and security records are kept for operationally appropriate periods.
- Booking, transaction, tax, insurance, incident, consent and legal records are kept for the applicable statutory period or while a claim or dispute may reasonably arise.
Media removed from a chat through moderation is quarantined from the marketing library and retained in private storage as evidence. It remains accessible only to authorised staff for moderation, safety, complaint or legal purposes. Residual copies may remain temporarily in protected backups until those backups are overwritten through their normal cycle.
How we protect information
We use safeguards appropriate to the nature of the information, including password hashing, encrypted connections, authentication and access controls, private storage for sensitive files, audit and security logging, monitoring, provider due diligence, and restricting staff access to a business need. No internet or storage system is completely secure, so we cannot guarantee absolute security.
If a data breach is likely to cause serious harm and the Notifiable Data Breaches scheme applies, we will notify affected people and the Office of the Australian Information Commissioner as required by law.
9. Account deletion
You may request account deletion through your portal settings, through Shirube where that option is available, or by contacting us.
Paid challenge restriction. We will not complete account deletion in the operational lead-up to, or during, a challenge for which you are a paying customer. We need the account and associated records to administer your booking, payments, safety, access and communications. If this applies, we will tell you when the hold can end and action the request after the challenge and immediate operational follow-up are complete.
While a deletion request is on hold, you can still stop Shirube location sharing, withdraw optional device permissions and ask us to restrict optional communications. Obligatory booking, safety and service communications may continue.
When deletion can proceed, we deactivate or soft-delete the account, revoke access tokens, remove information that is no longer needed, and delete or de-identify data where reasonably practicable. Deletion is not necessarily erasure of every business record.
Validated Shirube media remains privately retained after account deletion. We remove its database links to your account and the expired chat message, but we do not alter the media itself; a photo, video, audio recording or caption may still identify you or another person from its content.
If you have used our business services, we retain limited internal records needed for record keeping. These may include your identity and contact details, application and participation history, team or vehicle assignments, transaction, invoice, refund and payment references, agreements and consents, safety or incident records, complaints, audit history, and records needed for tax, insurance, fraud prevention, disputes or legal compliance. Retained records are not used to reactivate your account or for unrelated marketing, and access is restricted to authorised personnel.
10. Your rights and choices
Access and correction
You can review and update many details in the portal. You may also ask us for access to personal information we hold about you or ask us to correct inaccurate, out-of-date, incomplete, irrelevant or misleading information. We may verify your identity and may refuse or limit access where an exception under law applies; if so, we will explain the reason where permitted.
Permissions and participation
You can choose not to provide optional information, but this may limit a feature or our ability to provide a safe or tailored service. You can stop Shirube location sharing, change operating-system permissions, mute notifications, block a participant, report content, or stop using the app.
Marketing
We may send challenge news or offers where you have consented or where otherwise permitted. You can use the unsubscribe facility in a marketing message or contact us. Unsubscribing does not stop account, payment, safety, booking or other non-marketing service messages.
We do not charge to make an access or correction request. If fulfilling an access request would involve substantial cost, we will discuss any lawful and reasonable charge with you first.
11. Privacy complaints and contact
For an access, correction or deletion request, a privacy question, or a complaint, contact Gomanen through our support and contact page. Use “Privacy” in the subject and describe what happened and the outcome you are seeking. Do not send passwords, access tokens or unnecessary sensitive information.
We will acknowledge the matter, investigate it fairly, and aim to provide a substantive response within 30 days where practicable. If we need more time, we will explain why. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner.
You may ask us for this policy in another reasonably accessible format. We may update it when our services, providers or legal obligations change. The current version will remain available at this URL, and we will give additional notice where a change materially affects how we handle personal information.