Privacy Policy

Operator: Marco Glorie, a sole proprietorship (個人事業主) Business address: We'll tell you without delay if you ask — just contact us at info@oni-style.com Effective: Sep 20, 2026 · Last updated: Sep 20, 2026

We run onistyle (oni-style.jp and oni-style.com), a Japanese/English site covering hardstyle, hardcore, rawstyle and related dance music in Japan. This policy explains what we know about you, why, and what you can ask us to do about it.

We follow Japan's Act on the Protection of Personal Information (the "APPI"). If the EU or UK GDPR applies to you, §11 covers the extra rights you get.

1. The short version

You don't need an account to use most of onistyle. If you never sign in, never message us and never post a comment, we hold nothing that identifies you personally.

That said, we're not going to claim we know nothing about you. Like any website, we record technical access data, and we run usage analytics on every visit — including anonymous ones. §2(c) and §2(e) say exactly what that means. Everything else we hold, you create by doing something: signing in, sending us a message, or commenting on an event.

2. What we collect

(a) When you sign in. Signing in is optional. We only ask when you do something that needs an account — following an artist or venue, or commenting on an event. There are two ways in:

  • Google or LINE. We receive your display name, an account ID from that provider, and your email address if the provider shares it. LINE sign-in needs an email address to work. If LINE doesn't share one — including if you decline to share it — sign-in through LINE won't complete; use Google instead.

We never see your password for any of these. From LINE we don't receive your friend list, groups, talk contents or contacts.

Worth being direct about what this means: creating an account is the act that causes us to hold your name, and that name becomes public the moment you opt in to an event's attendee list, or the moment you post a comment. If you'd rather we held nothing, use onistyle without an account.

(b) When you contact us. We have two contact forms — general support, and partnership or advertising. We get the name and email you enter, plus your message. If you're signed in, the form pre-fills your name and email, and you can edit both before sending.

Your message reaches us by email and stays only in our email system — it never goes into onistyle's database. Separately we keep a short record of the submission: who sent it, when, which form, whether you were signed in, and your IP address and browser user-agent. We keep those last two to protect the forms from spam and abuse. That record doesn't contain what you wrote.

(c) What gets recorded automatically. Like any website, our hosting and infrastructure providers keep server and security logs — IP address, browser user-agent, pages requested, timestamps. We use them for security, abuse prevention and fixing faults.

(d) What you post, and who's going. If you comment on an event, what you send — and the display name attached — is meant to be public. Comments post immediately, without review. Don't put anything in a public post you don't want public.

Event pages have a "who's going" attendee list, and it's opt-in for each event separately — you choose per event whether to appear on it. Nothing else you do publishes your attendance, and opting in to one event never opts you in to another. You can remove yourself at any time.

(e) Cookies and analytics. We use cookies and browser storage to keep you signed in, remember whether you want Japanese or English, and for security.

We also use PostHog to understand how onistyle gets used. It records pages viewed, clicks and other interactions with things on the page, scroll and click positions (heatmaps), approximate location from your IP address, and it stores an identifier in your browser. It's set up not to build a persistent profile of anonymous visitors, and it masks whatever you type into form fields. We use Sentry to catch technical errors, which can include your IP address, browser and the page you were on.

We don't use advertising networks, and we don't sell or share your information for advertising or cross-site tracking. If that changes we'll update this policy first, and ask your consent where it's required.

(f) What we don't collect.

  • Biometric data, including facial-feature data
  • Personal information from children, knowingly
  • Special-care-required personal information (要配慮個人情報) or GDPR special-category data

Ticket links. You don't buy tickets on onistyle. Our links to ticket sellers may carry a referral tag so they know the visit came from us. We don't get your name, payment details or what you bought. Once you follow the link, that seller's privacy policy applies.

2A. Information your browser sends to other companies

Separately from what we collect ourselves, some pages make your browser or device send information directly to other companies. Japan's Telecommunications Business Act requires us to list each one, what gets sent, and why — so here they are.

Who it goes toWhat gets sentWhy
VercelIP address, browser user-agent, the page you requested, the timeServing the site; security and fault diagnosis
CloudflareIP address, browser user-agent, the media file you requestedDelivering images and media; protection against attacks and abuse
SupabaseWhat you submit, and what you do while signed inStoring and retrieving your account data and comments
GoogleInformation needed to complete sign-in — only if you choose GoogleSigning you in
LINEInformation needed to complete sign-in — only if you choose LINESigning you in
PostHogIP address, browser user-agent, pages viewed, clicks and interactions with things on the page, scroll and click positionsUnderstanding how onistyle is used
SentryIP address, browser user-agent, the page URL, technical details of the errorSpotting and diagnosing faults
YouTube (Google)Your IP address; once the video loads, YouTube/Google may set its own cookies in your browserPlaying a video you clicked play on

Video playback. Where an event or article embeds a YouTube video, we don't load anything from YouTube until you click play — until then you're looking at a still image we host ourselves. When you do click, we use youtube-nocookie.com, the version of YouTube's embed built to limit what it stores before you've actually chosen to interact with the player, rather than the standard youtube.com embed. Clicking the separate "watch on YouTube" link takes you to YouTube itself, where their own privacy policy applies.

Nothing goes to an advertising network. If that changes we'll update this list before it starts.

3. What we use it for

  1. Running onistyle — signing you in, running your account, and showing the comments you post.
  2. Delivering the notifications you asked for about artists or venues you follow. §4 sets out what those emails have to contain under Japan's Act on Regulation of Transmission of Specified Electronic Mail (特定電子メール法).
  3. Answering your enquiries and keeping an accurate record of them, including requests under §7.
  4. Keeping onistyle secure — spotting and stopping spam, fraud, unauthorised access and abuse.
  5. Meeting legal obligations and responding to lawful requests from authorities.
  6. Producing aggregate statistics that don't identify anyone.
  7. Moderating reported comments and removing content that breaches the Terms of Use.

We won't use your information for something materially different without telling you or asking first, as the APPI requires.

4. Notification emails

We send notification emails because you asked for them. Following an artist or venue is what starts them, and that's your opt-in for that particular stream. Every one identifies Marco Glorie as the sender, gives you a contact channel, and carries an unsubscribe link that works without signing in. We'll add our postal address to these emails once we have a business address to publish — until then, ask via the contact channel and we'll tell you without delay. Unsubscribing is free and takes effect without delay.

We don't send marketing email to a general audience. If we start, we'll ask for your separate, explicit consent then — following an artist today isn't consent to that.

5. When the GDPR applies — our legal basis

  • Contract (GDPR Art. 6(1)(b)) — running your account and delivering the follow notifications you asked for.
  • Legitimate interests (GDPR Art. 6(1)(f)) — security, spam and abuse prevention, keeping a record of enquiries, replying to you, diagnosing errors, and understanding how onistyle is used. The data is limited and the processing is what you'd expect from a site like this.
  • Consent (GDPR Art. 6(1)(a)) — marketing email, if we ever send it. §4 says we'd ask separately first, and you could withdraw any time. We don't currently rely on consent for anything else, because we don't yet have a way for you to give or withdraw it. That's why analytics sits under legitimate interests above, and it's the same open question §11 describes: if analytics turns out to need consent, we'll build the mechanism before relying on it.
  • Legal obligation (GDPR Art. 6(1)(c)) — where the law makes us keep or hand over information.

6. Who else handles your information

We don't sell your information, and we don't hand it to anyone to use for their own purposes, except:

  • when you tell us to;
  • when the law or a lawful request from an authority requires it, including a court order or a valid disclosure request about allegedly infringing content;
  • to protect someone's life, body or property when getting consent isn't practical;
  • if the business transfers to someone else, in which case they're bound by this policy or one at least as protective.

We do use service providers who handle personal information for us, on our instructions. Under the APPI that's entrustment (委託), not third-party provision — but most of them operate outside Japan, so here they are:

ProviderWhat they doWhere
SupabaseDatabase and sign-in/identity — accounts and user emails, follows, comments, contact submission recordsJapan (Tokyo)
VercelHosting and deliveryUnited States, delivered from edge locations worldwide
Cloudflare (R2 / CDN)Media storage and deliveryAsia-Pacific storage, worldwide delivery
GoogleSign-in, if you choose itUnited States
LINESign-in, if you choose itJapan and other countries where they operate
PostHogUsage analyticsEuropean Union (Frankfurt)
SentryError reportingUnited States
ResendSending email — contact-form forwarding, notificationsUnited States

Sending information outside Japan (APPI Art. 28). Supabase holds our data in Japan, so nothing leaves the country there. PostHog is in the EU, which Japan recognises as offering equivalent protection. For the rest — Vercel, Cloudflare, Google, Sentry, Resend — we rely on data-processing agreements meeting the standard in 施行規則第16条, we take the steps needed to make sure those providers keep meeting it, and we'll give you information about those steps if you ask via §12.

We've also looked into the personal-information rules of each country above, so we understand the environment our providers operate in.

If the GDPR applies to you: personal data reaching Japan from the EEA is handled under the PPC's Supplementary Rules, which the European Commission's adequacy decision for Japan makes applicable. Where a provider handles data outside both the EEA and Japan, we rely on Standard Contractual Clauses or another Art. 46 mechanism they offer.

7. Your rights, and how to use them

Under the APPI you can ask us to:

  • show you the personal data we hold about you, and records of any third-party provision — electronically if you'd like;
  • correct, add to or delete anything factually wrong;
  • stop using or erase your data, or stop providing it to third parties, where the APPI's grounds apply;
  • tell you what we use it for.

How. Contact us at info@oni-style.com. No particular form is needed — just tell us what you want and which account or email address it concerns. We'll check it's really you first, usually by confirming you control that email address or account. We reply without undue delay. There's no fee. If we ever introduce one we'll publish the amount here first.

If you ask us to delete an enquiry you sent, we act on both the email and the matching submission record.

Complaints. If our answer doesn't satisfy you, you can complain to Japan's Personal Information Protection Commission (個人情報保護委員会, https://www.ppc.go.jp/).

8. How long we keep things

Anything tied to your account — your profile, follows, notification settings and comments — we keep for as long as your account exists. There's no fixed expiry date, because you're the one who decides: you can delete your account yourself at any time, and doing so deletes or anonymises this data. We may keep something only where the law requires it or an unresolved dispute makes it necessary. Deleting your account deletes your comments too; you can also delete an individual comment yourself at any time without deleting your account — see the Terms of Use.

Everything else has no self-service delete button, so we put it on a fixed period instead. You can still ask us to delete it — see §7.

  • Contact emails and submission records — 12 months, on a rolling basis. We're continuously deleting the oldest, not clearing everything out once a year.
  • Server and security logs — these sit with our hosting and infrastructure providers, not in our own database. We set their retention to 12 months or less wherever the provider lets us configure it.
  • Analytics (PostHog) — 1 year.
  • Error reports (Sentry) — 30 days.

9. Keeping it safe

We take reasonable organisational, technical and physical measures against loss, misuse and unauthorised access — access control on our database, encryption in transit, and limited administrator access.

If a breach hits the APPI's reporting thresholds we report it to the Personal Information Protection Commission and tell the people affected. Where the GDPR applies we notify the relevant supervisory authority within 72 hours if the breach is likely to put anyone's rights and freedoms at risk.

10. Children

onistyle isn't aimed at children, and we don't knowingly collect personal information from anyone under 16. If we find out we have, we delete it.

11. If you're in the EEA or the UK

We're based in Japan and run a Japan-focused service. We don't market onistyle to people in the EEA or the UK.

We'll be straight with you about the harder question. GDPR Art. 3(2)(b) also catches monitoring people's behaviour in the EEA, and the analytics described in §2(e) — clicks, heatmaps, approximate location — run on every visitor, wherever they are. We don't build persistent profiles of anonymous visitors, and we don't analyse individual behaviour or make decisions about people from it, which is why we don't think this amounts to the kind of monitoring that brings us fully within the GDPR. But it's a genuine question rather than an obvious no, and we'd rather say so than pretend otherwise. If it resolves the other way, we'll add a consent mechanism and update this policy.

Where the GDPR or UK GDPR does apply to you, you also have the rights of access, rectification, erasure, restriction, portability and objection (GDPR Arts. 15–22), and you can complain to your local supervisory authority. We don't make automated decisions that produce legal or similarly significant effects.

We haven't appointed a representative under GDPR Art. 27 or its UK equivalent, since we don't currently consider ourselves within Art. 3(2). If that changes we'll appoint one and update this policy.

12. Contact

Questions, or requests under §7:

Marco Glorie (onistyle) — info@oni-style.com Ask via the same channel and we'll give you our business address without delay.

13. Which language governs

This policy exists in Japanese and English. The Japanese text governs; the English is a reference translation.

14. Changes

We may update this policy. We'll announce material changes on the site before they take effect, and the "last updated" date at the top tells you when it last changed. Where the law requires your consent to a change, we'll ask.