kumiki-reorder-reminder / Privacy Policy
Kumiki Reorder Reminder プライバシーポリシー
- 施行日 / Effective
- 最終更新日 / Updated
日本語
Kumiki Reorder Reminder(以下「本アプリ」)は、BLANKS WORK(https://blanks.work)が運営する Shopify アプリです。このポリシーでは、本アプリが収集・処理する情報の内容、目的、保持期間、提供先を説明します。対象は、本アプリをインストールしたマーチャント(以下「マーチャント」)と、そのストアのアカウント画面で本アプリのブロックを見る購入者(以下「購入者」)です。
1. 本アプリの機能
本アプリは、ストアのアカウント画面(プロフィール、注文、注文状況)にブロックを表示します。ブロックには、ログイン中の購入者が以前に購入し、そろそろ必要になりそうな商品が並びます。ボタンを押すと、同じバリアントと数量がカートに入ります。マーチャントには、そのボタンを経由した注文の数を表示します。
2. 収集・処理する情報
2.1 マーチャントとストアの情報(保存します)
マーチャントが本アプリをインストールして利用すると、次の情報を保存します。
- ストアの myshopify.com ドメインと Shopify のストア ID
- ストアのタイムゾーンと通貨
- インストール日時とアンインストール日時
- Shopify から取得した本アプリの契約状態(有効か無効か、プラン名など)
- マーチャントが保存した設定(既定の補充サイクル、何日早めに表示するか、最大表示数、在庫切れの扱い)と、導入チェックリストの状態
- ストアの Shopify API のアクセストークンと更新トークン(AES-256-GCM で暗号化して保存します)
マーチャントのスタッフの氏名、メールアドレスなどの個人情報は保存しません。本アプリが使うのは、ストア単位のアクセス(オフライン)だけです。
2.2 注文の情報(一時的に処理し、保存しません)
ボタンの効果をマーチャントに示すため、サーバーが Shopify Admin API で過去 30 日の注文を読みます。読むのは注文ごとに次の項目だけです。
- 注文の作成日時とキャンセル日時
- 明細ごとの、本アプリの非表示の目印の有無、現在の数量、割引前の単価
この情報は、日別の合計を計算するためだけに使います。保存するのは日別の合計(日付、ボタン経由の注文数、商品金額の合計、通貨)だけです。注文 ID、明細、購入者の情報は保存しません。
購入者の氏名、メールアドレス、電話番号、住所は読みません。
2.3 アカウント画面での購入者の情報(購入者のブラウザー内だけで処理します)
ログイン中の購入者がアカウント画面を開くと、本アプリのブロックが購入者のブラウザー内で動きます。ブロックは Shopify から次の情報を読みます。
- 購入者本人の最近の注文(過去 60 日、最大 20 件の商品、バリアント、数量、注文日)
- 商品の現在の情報(在庫、価格、画像、マーチャントが設定した補充サイクル)
これらは、ブロックに表示する商品を決めるためだけに使います。この情報は当方のサーバーに送らず、保存もしません。 購入者の氏名、メールアドレス、電話番号、住所は読みません。
2.4 カートの非表示の目印
購入者がボタンを使うと、本アプリはカートの明細に非表示のプロパティ _reorder_reminder(値は 1)を付けます。購入者が注文すると、このプロパティはマーチャントの Shopify ストアの注文データの一部になります。個人情報は含みません。ボタン経由の注文を数えるために使います。
2.5 技術的なログ
ホスティング事業者(Google Cloud)は、本アプリのサーバーへのリクエストを自動で記録します。対象は、マーチャントが Shopify 管理画面で本アプリを使う時のブラウザーからのリクエストや、Shopify からの Webhook などです。記録には、IP アドレス、ブラウザーのユーザーエージェント、日時、URL が含まれることがあります。
本アプリ自身のログには、運用上の出来事(ストアのドメイン、エラー、処理時間など)を記録します。アクセストークンなどの秘密情報と、購入者の個人情報は記録しない設計にしています。
3. 利用目的
上記の情報は、次の目的にだけ使います。
- マーチャントとその購入者に、本アプリの機能を提供する
- Shopify を通じて、マーチャントの契約を確認する
- ボタンの効果を集計して表示する
- 本アプリの安全確保、保守、障害対応、サポートへの対応
情報の販売、広告やプロファイリングへの利用はしません。法的な効果やそれに準じる重大な影響を及ぼす自動的な意思決定もしません。
4. 保持期間と削除
- 日別の合計: 直近 30 日分だけを保持します。集計のたびに置き換えます。
- アクセストークン: マーチャントがアンインストールした時点で削除します。
- ストアの全データ: Shopify から
shop/redactを受け取った時点で削除します。Shopify はアンインストールの約 48 時間後にこれを送ります。 - 購入者のデータの請求: 購入者個人に結び付く情報は保存していません。Shopify から
customers/data_requestまたはcustomers/redactを受け取った場合は、受け取ったことを記録し、該当する情報がないことを確認します。 - ログ: 30 日間保持し、その後自動で削除します。
- 注文の一時的な処理(2.2): 注文のファイルは読みながら処理し、保存しません。
5. 委託先(サブプロセッサー)
本アプリの運営に、次の事業者を利用します。各事業者は当方の委託を受けた範囲でだけ情報を処理します。
| 事業者 | 用途 | 所在地 |
|---|---|---|
| Google Cloud(Cloud Run、Secret Manager、Cloud Logging) | 本アプリのサーバーの運用、暗号鍵と秘密情報の保管、ログ | 米国(us-central1、アイオワ州) |
| Neon(PostgreSQL のデータベース。Amazon Web Services 上で運用) | 第 2 章のストアの情報と日別の合計の保存 | 米国(AWS us-east-2、オハイオ州) |
| Shopify | 本アプリが動くプラットフォーム、本アプリの料金の請求 | Shopify のプライバシーポリシーのとおり |
情報は米国に移転され、米国で処理されます。法令が求める場合は、各事業者のデータ処理条件や標準契約条項など、適切な保護措置に基づいて移転します。{{TRANSFER_MECHANISM_CONFIRMED}}
法令に基づく場合を除き、上記以外の第三者に情報を提供しません。
6. 安全管理
- すべての通信を TLS で暗号化します。
- データベースは、データベース事業者が保存時に暗号化します。
- Shopify のアクセストークンは、本アプリでさらに暗号化します(AES-256-GCM)。
- 秘密情報は Google Cloud Secret Manager に保管します。
- 本番環境へのアクセスは、権限のある担当者に限定します。
7. Cookie
本アプリは Shopify 管理画面の中で動き、Shopify のセッショントークンを使います。広告や追跡のための Cookie は使いません。アカウント画面のブロックも Cookie を設定しません。
8. 利用者の権利
マーチャントは、ストアについて当方が保持する情報の開示、訂正、削除を {{CONTACT_EMAIL}} に請求できます。購入者は、購入したストアにご連絡ください。購入者からのプライバシーに関する請求は Shopify から当方に届き、第 4 章のとおり対応します。請求には 30 日以内に対応します。
お住まいの地域(欧州経済領域、英国、カリフォルニア州、日本など)の法令により、処理への異議や監督機関への申し立てなど、追加の権利が認められる場合があります。
9. 子ども
本アプリは事業者向けです。子どもの情報を意図して収集することはありません。
10. このポリシーの変更
このポリシーを変更した場合は、冒頭の「Last updated」の日付を更新します。重要な変更の場合は、本アプリ内またはメールでマーチャントにお知らせします。たとえば、将来データベースを Neon から Google Cloud SQL(米国、us-central1)に移す予定があり、その時に第 5 章を更新します。
11. お問い合わせ先
- BLANKS WORK
- https://blanks.work
- お問い合わせ先: https://blanks.work/contact/
English
Kumiki Reorder Reminder (“the App”, “we”, “us”) is a Shopify app operated by BLANKS WORK (https://blanks.work). This policy explains what information the App collects and processes, why, how long it is kept, and who it is shared with. It applies to merchants who install the App (“Merchants”) and to customers of those stores who see the App’s block in their customer account (“Customers”).
1. What the App does
The App shows a block in a store’s customer account pages (profile, orders, and order status). The block lists products that a signed-in Customer bought before and may need again soon, with a button that adds the same product variant and quantity to the cart. The App also shows Merchants how many orders were placed through that button.
2. Information we collect and process
2.1 Merchant and store information (stored)
When a Merchant installs and uses the App, we store:
- The store’s myshopify.com domain and Shopify store ID
- The store’s time zone and currency
- Installation and uninstallation dates
- Subscription status for the App (for example, active or inactive, and the plan name), as reported by Shopify
- App settings the Merchant saves (default reorder cycle, how many days early to show reminders, maximum number of items, out-of-stock behavior) and onboarding checklist status
- Shopify API access tokens and refresh tokens for the store. These are encrypted with AES-256-GCM before they are stored.
We do not store the names, email addresses, or other personal information of the Merchant’s staff. The App uses store-level (“offline”) access only.
2.2 Order information (processed temporarily, not stored)
To show Merchants the results of the reorder button, our server reads the store’s orders from the last 30 days through the Shopify Admin API. For each order, it reads only:
- The order’s creation date and cancellation date
- For each line item: whether it carries the App’s hidden marker, its current quantity, and its original unit price
We use this information only to calculate daily totals. We store only those daily totals: the date, the number of orders placed through the reorder button, the total item amount, and the currency. We do not store order IDs, line items, or any information about Customers.
We do not read Customers’ names, email addresses, phone numbers, or addresses.
2.3 Customer information in the customer account (processed in the Customer’s browser only)
When a signed-in Customer opens their customer account, the App’s block runs in the Customer’s browser. It reads that Customer’s own recent orders (up to 20 orders from the last 60 days: products, variants, quantities, and order dates) and current product information (availability, price, image, and the reorder cycle set by the Merchant) from Shopify.
This information is used only to decide which products to show in the block. It is not sent to our servers, and we do not store it. The block does not read the Customer’s name, email address, phone number, or address.
2.4 Hidden cart marker
When a Customer uses the reorder button, the App adds a hidden line item property, _reorder_reminder with the value 1, to the cart. If the Customer places the order, this property becomes part of the order in the Merchant’s Shopify store. It contains no personal information. It lets the Merchant and the App count orders placed through the button.
2.5 Technical logs
Our hosting provider (Google Cloud) automatically records request logs when the App’s server receives requests, for example from a Merchant’s browser while they use the App in the Shopify admin, or from Shopify webhooks. These logs can include the IP address, browser user agent, request time, and requested URL. Our own application logs record operational events (for example, the store’s domain, errors, and processing times). We designed them to exclude access tokens and other secrets, as well as Customer personal information.
3. How we use information
We use the information above only to:
- Provide the App’s features to the Merchant and to the Merchant’s Customers
- Confirm the Merchant’s subscription to the App through Shopify
- Calculate and display the results of the reorder button
- Secure, maintain, and troubleshoot the App, and respond to support requests
We do not sell information, and we do not use it for advertising or profiling. We do not make automated decisions that have legal or similarly significant effects on anyone.
4. Retention and deletion
- Daily totals: only the most recent 30 days are kept. Each recalculation replaces the previous totals.
- Access tokens: deleted when the Merchant uninstalls the App.
- All store data: deleted when we receive Shopify’s
shop/redactrequest, which Shopify sends about 48 hours after the App is uninstalled. - Customer data requests: we do not store information linked to individual Customers. When Shopify sends a
customers/data_requestorcustomers/redactrequest, we record that we received it and confirm that we hold no matching data. - Logs: kept for 30 days, then deleted automatically.
- Temporary order processing (section 2.2): the order file is processed as it is read and is not saved.
5. Service providers (subprocessors)
We use the following providers to run the App. They process information only on our behalf.
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud (Cloud Run, Secret Manager, Cloud Logging) | Hosting the App’s server, storing encryption keys and secrets, logs | United States (us-central1, Iowa) |
| Neon (PostgreSQL database, hosted on Amazon Web Services) | Storing the store information and daily totals described in section 2 | United States (AWS us-east-2, Ohio) |
| Shopify | The platform the App runs on, and subscription billing for the App | As described in Shopify’s privacy policy |
Information is transferred to and processed in the United States. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the providers’ data processing terms and Standard Contractual Clauses. {{TRANSFER_MECHANISM_CONFIRMED}}
We do not share information with any other third party, except where the law requires it.
6. Security
- All connections use TLS encryption.
- The database is encrypted at rest by our database provider.
- Shopify access tokens are additionally encrypted by the App (AES-256-GCM).
- Secrets are stored in Google Cloud Secret Manager.
- Access to production systems is limited to authorized personnel.
7. Cookies
The App runs inside the Shopify admin and uses Shopify session tokens. It does not set advertising or tracking cookies. The customer account block does not set cookies.
8. Your rights
Merchants can ask us to access, correct, or delete the information we hold about their store by contacting us at {{CONTACT_EMAIL}}. Customers should contact the store they purchased from; Shopify forwards Customer privacy requests to us, and we respond to them as described in section 4. We respond to requests within 30 days.
Depending on where you live (for example, in the European Economic Area, the United Kingdom, California, or Japan), you may have additional rights under local law, such as the right to object to processing or to complain to a data protection authority.
9. Children
The App is intended for businesses. We do not knowingly collect information from children.
10. Changes to this policy
If we change this policy, we will update the “Last updated” date above. If the change is significant, we will also notify Merchants in the App or by email. For example, we plan to move the database from Neon to Google Cloud SQL (United States, us-central1) in the future. We will update section 5 when that happens.
11. Contact
- BLANKS WORK
- https://blanks.work
- Contact form: https://blanks.work/contact/