プライバシーポリシー
Privacy Policy
制定日 / Effective date: 2026-07-17 ・ 最終改定 / Last updated: 2026-09-22
Meliorra(以下「当社」)は、AI アシスタント経由の宿泊予約サービス「Meliorra」(MCP サーバー https://mcp.meliorra.co/mcp および関連ウェブサイトを含み、以下「本サービス」)における利用者の情報の取り扱いについて、以下のとおり定めます。
This policy describes how Meliorra ("we") handles your information in the Meliorra service — an AI-native hotel booking network available through the MCP server at https://mcp.meliorra.co/mcp and related websites (the "Service").
1. 収集する情報 Information we collect
- メールアドレス(AI アシスタント接続時の OAuth ログイン、および宿泊施設アカウントの登録時) — Email address (OAuth sign-in from your AI assistant; property account registration)
- 予約リクエストの内容(施設・日程・人数・プラン・特別リクエスト・任意で入力された氏名/連絡先) — Booking request details (property, dates, guests, plan, special requests, and any name/contact details you choose to provide)
- 表示言語の設定(ja/en/ko/zh/fr) — Language preference
- 電話予約案内(AI 音声アシスタント)をご利用の場合: 通話の音声、その文字起こし、発信者番号。通話の冒頭で記録する旨をお伝えします。 — If you call the phone concierge (AI voice assistant): the call audio, its transcript, and your caller number. The assistant states at the start of the call that it is being recorded.
- 宿泊施設アカウントの場合: 担当者名、施設情報、Google マップから取り込んだ施設の公開情報(評価・クチコミの抜粋) — For property accounts: contact name, property details, and public listing data imported from Google Maps (rating and review excerpts).
- AI 可視性診断をご利用の場合: 入力された URL と、その公開ページの内容 — If you use the AI visibility diagnosis: the URL you enter and the content of its public pages. 診断結果のページで任意にメールアドレスを登録された場合は、そのアドレスと同意の日時(結果の送付と、改善のご案内を 1 回お送りするために使います。メール内のリンクからいつでも配信を停止できます)。 — If you choose to register an email address on the diagnosis result page: that address and the time of your consent, used to send the result and one follow-up message. Every message has an unsubscribe link.
- 宿泊施設がスタッフ用のアカウントを発行した場合: スタッフの氏名・メールアドレス・権限。2 段階認証を設定した場合は、認証アプリ用の秘密鍵(暗号化して保管)と復旧コード(ハッシュ化して保管)。 — If a property issues staff accounts: the staff member's name, email address and role. If two-factor authentication is enabled: the authenticator secret (encrypted at rest) and recovery codes (stored hashed).
- 宿泊施設ごとの需要の件数(検索結果に表示された回数・空室を問い合わせられた回数などを、日ごとの件数としてのみ記録します。検索した方を特定する情報や検索の文面は含みません)。まだ提携していない宿泊施設を、その公式サイトで公開されている情報にもとづいて「未提携」と明示して紹介することがあります。 — Per-property demand counts (how often a property appeared in results or was asked about, stored only as daily totals with no searcher identifiers or query text). We may list properties that are not yet partners, clearly marked as such, based on information published on their official websites.
- 未提携として紹介している宿泊施設について: 公式サイトで公開されている施設の情報(所在地・電話・客室・料金の目安など)と、公式サイトで公表されている問い合わせ用のメールアドレス。このアドレスは、掲載したこと・内容の確認や取り下げの方法・AI アシスタント経由でどれだけ探されたかをお知らせするためにだけ使います(「営業メールお断り」等の記載がある施設には送りません。すべてのお知らせに、1 クリックの配信停止と、掲載の取り下げの方法を記載します)。掲載内容の確認・修正・取り下げは、宿ごとの掲載ページからいつでも行えます。 — For properties listed as non-partners: information published on the property's official website (address, phone, rooms, indicative rates, etc.) and the enquiry email address published there. We use that address only to tell the property that it has been listed, how to review, correct or remove the listing, and how often it has been searched for via AI assistants. We do not send notices to properties whose site says unsolicited sales email is not accepted; every notice carries a one-click unsubscribe and instructions for removing the listing. Listings can be reviewed, corrected or removed at any time from the property's listing page.
- サービス運用ログ(アクセス日時、API 呼び出しの成否など) — Operational logs (timestamps, API call outcomes)
本サービスは、ツールの実行に必要な範囲を超えて AI アシスタントの会話内容・履歴・メモリを収集しません。決済情報(クレジットカード番号等)は収集しません。
We do not collect conversation history or memory from your AI assistant beyond what is needed to execute the requested tool, and we do not collect payment card details.
2. 利用目的 How we use it
- 宿泊施設の検索・空室確認・予約リクエストの仲介と、その進捗通知(メール送信を含む)
- 本人確認(メール到達確認コードの送信)と不正利用の防止
- 成果報酬の算定根拠となる予約履歴(監査用の追記型台帳)の維持
- 宿泊施設への、AI 経由の需要のご報告とサービスのご案内(宿泊施設アカウント、および診断でメールアドレスを登録された方。配信はいつでも停止できます)
- サービスの品質改善・障害対応
We use your information to search properties, check availability, deliver booking requests to hotels and notify you of their status (including by email); to verify your email address and prevent abuse; to maintain an append-only booking ledger used for success-fee accounting and audits; and to operate and improve the Service.
3. 第三者への提供・外部サービスの利用 Sharing and processors
- 予約リクエストの内容(氏名・連絡先・ご要望を含む)は、予約先の宿泊施設に提供されます。 — Booking request details (including your name, contact details and requests) are shared with the hotel you request.
- メール送信は Resend, Inc.(米国)を利用します。宛先のメールアドレスと本文が同社へ送信されます。 — Emails are delivered via Resend, Inc. (United States); the recipient address and message body are sent to it.
- 電話予約案内の音声応対と文字起こしは OpenAI, L.L.C.(米国)の API で処理されます。通話の音声が同社へ送信されます。 — The phone concierge's voice handling and transcription are processed by the API of OpenAI, L.L.C. (United States); call audio is sent to it.
- サイトへのログインに Google アカウントを使う場合、認証は Google LLC(米国)が行います。施設情報の取り込みには Google Places API を、書体の配信には Google Fonts を利用します。 — If you sign in to the website with a Google account, authentication is performed by Google LLC (United States). We use the Google Places API to import property listings and Google Fonts to serve typefaces.
- 宿泊施設がサイトコントローラー(例: Beds24)を接続している場合、在庫確認・予約確定のために予約情報が当該システムへ送信されます。 — If the hotel uses a connected channel manager (e.g. Beds24), booking data is sent to that system to confirm inventory.
- 検索クエリ、および宿泊施設が入力した施設情報・取り込んだクチコミの抜粋は、推薦・プロフィール生成・翻訳のため Anthropic, PBC(米国)の API で処理されることがあります。 — Search queries, and property details entered by hotels including imported review excerpts, may be processed by the API of Anthropic, PBC (United States) for ranking, profile generation and translation.
- 本サービスは Google Cloud(東京リージョン asia-northeast1)でホストされます。 — The Service is hosted on Google Cloud (asia-northeast1, Tokyo).
外国にある事業者への提供について。上記のうち Resend・OpenAI・Anthropic・Google はいずれも米国に所在する事業者で、サービスの提供に必要な範囲で情報が米国へ送信されます。宿泊施設が接続したサイトコントローラーの事業者が日本国外に所在する場合は、その所在国へも予約情報が送信されます。各事業者における情報の取り扱い、および所在国の個人情報保護制度についてのお問い合わせは、下記の連絡先で承ります。
Transfers outside Japan. Resend, OpenAI, Anthropic and Google are located in the United States, and information is sent there to the extent needed to provide the Service. If the channel manager connected by a hotel is operated outside Japan, booking data is also sent to that operator's country. Contact us below for details on how these providers handle information and on the relevant data-protection regimes.
上記のほか、法令に基づく場合を除き、本人の同意なく第三者に個人情報を提供しません。個人情報を広告目的で販売・共有することはありません。
We do not sell your personal information or share it for advertising. Beyond the processors above, we disclose personal information only with your consent or as required by law.
4. 保存期間 Retention
- 予約に含まれる旅行者の情報(氏名・メールアドレス・電話番号・ご要望): 完了・キャンセル・否認・期限切れとなった予約について、チェックアウト予定日から 1 年が経過した時点で自動的に消去(匿名化)します。 — Traveler details in a booking (name, email, phone, requests): automatically erased (anonymized) one year after the scheduled check-out date for bookings that are completed, cancelled, declined or expired.
- 予約の日程・金額・ステータス、および監査用台帳: 成果報酬の算定・税務・紛争対応のため、個人を特定しない形で法令上必要な期間保存します。 — Booking dates, amounts, status and the audit ledger: retained in non-identifying form as long as needed for fee accounting, tax and dispute resolution.
- 通話の文字起こしと発信者番号: 通話から 90 日で自動的に消去します(通話件数などの統計のみ残します)。通話の音声そのものは当社では保存しません。 — Call transcripts and caller numbers: automatically erased 90 days after the call (only statistics such as call counts remain). We do not store the call audio itself.
- メール確認コードは 10 分、OAuth の認可コードは 5 分、リフレッシュトークンは 30 日、宿泊施設向け承認リンクは 72 時間で失効します。 — Verification codes expire in 10 minutes, authorization codes in 5 minutes, refresh tokens in 30 days, and hotel approval links in 72 hours.
保存期間の経過前であっても、アカウントおよび関連データの開示・訂正・利用停止・削除を下記の連絡先までご請求いただけます。ご本人であることをメールアドレスへの到達確認により確かめたうえで、法令上保存が必要な記録を除き、合理的な期間内に対応します。手数料はいただきません。
You may request access to, correction, suspension of use, or deletion of your account and associated data at any time via the contact below. After confirming your identity by verifying your email address, we will respond within a reasonable period, except for records we are legally required to keep. There is no fee.
5. 安全管理 Security
通信はすべて HTTPS で暗号化されます。パスワードと認証トークンはハッシュ化して保存し、外部システムの資格情報と通知先(Webhook)の URL・署名鍵は AES-256-GCM で暗号化して保管します。秘密情報は Google Cloud Secret Manager で管理します。
All traffic is encrypted over HTTPS. Tokens are stored hashed; third-party credentials are encrypted at rest with AES-256-GCM; secrets are managed in Google Cloud Secret Manager.
6. Cookie Cookies
本サービスのウェブサイトが使用する Cookie は、ログイン状態を保持するためのセッション Cookie(meliorra_session、最長 7 日)のみです。広告・行動分析のための Cookie や外部のアクセス解析は使用していません。Google アカウントでログインする場合は、Google のログイン機能がその Cookie を使用します。紹介リンクから宿泊施設向けページを開いた場合は、登録時に紹介元を引き継ぐため、紹介コードをお使いのブラウザ内(localStorage)に保存します。
The website uses a single session cookie (meliorra_session, up to 7 days) to keep you signed in. We do not use advertising or behavioural-analytics cookies or third-party analytics. If you sign in with Google, Google's sign-in component uses its own cookies. If you open the property page from a referral link, the referral code is kept in your browser's localStorage so it can be applied when you register.
7. ポリシーの変更 Changes
本ポリシーを変更する場合は、本ページで告知します。重要な変更は施行前に告知します。
Changes to this policy will be posted on this page; material changes will be announced before they take effect.
8. お問い合わせ Contact
support@meliorra.co