プライバシーポリシー
1. 適用範囲
本ポリシーは、オフィス長谷川が提供する次のShopifyアプリ(総称して「本アプリ」)に適用されます: Inventory Audit、Metafield Editor、Inventory Adjuster、Fraud Detecto、Product Validator、Returns Manager。本アプリはShopifyを利用する事業者(「マーチャント」)向けです。各アプリが取り扱うデータは異なります。下記のアプリ別説明を確認してください。
2. 運営者と役割
オフィス長谷川は、本アプリの認証、機能提供、設定・操作の保存、セキュリティ、サポートのために情報を処理します。マーチャントのShopifyストアや購入者に関する情報について、通常、マーチャントが利用目的と取扱いを決定し、オフィス長谷川は本アプリを提供するためにその指示に従って処理します。購入者の情報に関する問い合わせは、まず購入先のマーチャントへご連絡ください。
3. 共通して取り扱う情報
- ストアと認証: Shopifyストアの識別子・ドメイン、インストール状態、許可scope、Shopify認証sessionおよびShopify発行のaccess/refresh token。sessionにShopify Admin利用者のID、氏名、メールアドレス、locale、役割情報が含まれる場合があります。
- 設定と操作: アプリごとの設定、保存ビュー、操作結果、リクエスト日時、エラー分類、Shopify webhookの処理情報。
- 問い合わせ: マーチャントがメール等で送る連絡先、問い合わせ内容、サポート対応履歴。
- 運用ログ: 障害・不正利用の調査に必要なストア識別子、イベント種別、内部ID、件数、エラー分類など。ログの保存期間・アクセス条件はCloudflareのサービスとアカウント設定に従います。
4. アプリごとの情報と保持
各アプリの個別リンクは、このポリシー内の該当行に移動します。
| アプリ | 機能に使う情報 | 保存と削除 |
|---|---|---|
| Inventory Audit | Shopifyから都度取得する在庫調整日時・数量・商品/variant・SKU・location・理由・在庫状態・担当スタッフID/氏名・参照文書ID/URI。参照先は注文等を示すことがあります。本アプリは顧客profileや注文objectを直接照会しません。 | 在庫履歴の行やCSV内容はアプリのD1へ保存しません。ストア設定と保存filterはマーチャントが削除するか、アンインストール処理で削除されます。アンインストール後のストア識別markerはShopifyのshop/redact処理まで残る場合があります。 |
| Metafield Editor | 編集対象として選んだ商品のvariant、metafield定義・値、SKU、商品・variant名。顧客profileや注文を直接照会しません。Customer reference型のmetafieldが選ばれた場合、Customer IDを一時処理する可能性があります。 | metafield値や編集中の値をアプリD1へ恒久保存しません。保存ビューはブラウザーのlocal storageに残り、期限はありません。Shopifyのアンインストールやwebhookでは消えないため、利用者がブラウザーのサイトデータを削除してください。Shopify sessionはアンインストール時に削除します。 |
| Inventory Adjuster | 商品・variant・SKU・名称、在庫item・location、変更前/差分/変更後数量、マーチャントが入力した理由や参照値、更新結果。 | 調整receiptと再試行に必要なpayloadは作成から90日後の削除対象です。削除処理は定期実行として実装されていますが、実行失敗や処理量により遅れる場合があります。最小限のrequest IDは重複適用防止のためインストール中保持され、アンインストール時に削除されます。 |
| Fraud Detecto | 注文ID・表示番号・日時・金額・通貨・Shopifyのrisk情報、Customer ID、IP、配送先住所の一部を注文間の共通パターン検出に使います。氏名・メール・電話番号は照会しません。Customer ID、IP、住所はストア別HMAC値に変換して分析に使います。 | 生のIP、住所、Customer IDは分析用D1へ保存しません。注文要約・HMAC signal等は原則として注文作成から90日以内に削除する設計です。削除schedulerの失敗時は遅れることがあります。Shopifyの顧客データ要求に対するreportはマーチャントが取得し、購入者へ提供します。自動で注文を拒否・取消ししません。 |
| Product Validator | scan対象の商品・variant ID/名称、SKU、barcode値と種類、scan状態・検出結果。顧客、注文、在庫情報を照会しません。 | scan snapshotは最大7日、アプリ全体の日次quota counterは10日保存し、その後削除する実装です。定期cleanupが遅れた場合は削除が遅れることがあります。顧客データをアプリ機能情報として保存しません。 |
| Returns Manager | Customer Accountにログインした購入者本人の注文、返品対象line item、返品理由、任意メモ。管理画面ではマーチャントが返品詳細を確認し、Shopify上で処理します。氏名・メール・電話・住所を直接照会しません。 | 返品申請のメモはShopifyへ送信しますが、アプリD1へ保存しません。返品一覧の識別情報は申請中/処理中に保持され、CANCELED/CLOSED/DECLINED状態になった後、最終更新から365日で削除対象です。履行済みprivacy request記録は30日後に削除対象です。quota操作の詳細データは90日後に削除対象ですが、最小限の再送防止記録はインストール中保持されます。未処理privacy requestと再投入防止tombstoneは必要な間保持します。定期cleanupが遅れる場合があります。 |
上記の定期削除期間はアプリの実装方針です。ジョブ失敗、復旧用backup、ShopifyまたはCloudflareの運用ログにより、完全削除の時点が遅れることがあります。バックアップ等は各提供者の仕組みに従います。
5. 利用目的
情報は、Shopify認証、本アプリの機能提供、マーチャントが依頼したShopifyデータの読み取り・更新、設定・操作結果の保存、重複実行防止、Shopify privacy requestへの対応、サポート、セキュリティ維持、障害調査に利用します。購入者データを広告に使ったり、販売したり、無関係な横断プロファイリングに利用したりしません。Fraud Detectoの結果は調査支援であり、注文を自動拒否・取消しする判断には使いません。
6. Shopify、Cloudflareその他の処理先
本アプリはShopify Admin APIまたはCustomer Account APIを利用し、Cloudflare Workersで実行します。永続データは主にCloudflare D1に保存し、Fraud DetectoとReturns ManagerはCloudflare Queuesも使用します。これらの提供者は本アプリを運用するために情報を処理します。確認したアプリコードには、別の広告・分析・AI事業者へ情報を送る連携はありません。
ShopifyとCloudflareは日本国外で情報を処理する場合があります。特定の国だけで処理・保存することは保証しません。Cloudflare D1は保存時暗号化とWorker-D1間のTLSを提供するとCloudflareが説明していますが、これはすべてのアカウント設定、バックアップ、アクセス履歴を個別に監査したという意味ではありません。D1のtoken等にアプリケーション層の列暗号化は実装していません。
7. データの共有とマーチャントの管理
本アプリはデータをマーチャントのShopifyストアで認可された利用者に表示します。CSVを含むexportを誰と共有するかはマーチャントが管理します。端末へダウンロードされたCSVや、ブラウザー内に保存された設定・コピーは、オフィス長谷川が遠隔で削除できない場合があります。Shopifyや法令に基づく場合を除き、データを第三者へ開示しません。
8. 保持、アンインストール、プライバシー要求
Shopify sessionとtokenは認証に必要な間保持し、アンインストールやShopifyのshop/redact webhookに応じて削除します。期限切れsessionの自動削除はすべてのアプリで実装されているわけではないため、削除イベントまで一部session記録が残ることがあります。保存設定、履歴、削除対象はアプリごとに上表のとおり異なります。
Shopifyからのcustomers/data_request、customers/redact、shop/redact webhookを受信し、署名を検証してアプリに保存された該当情報を処理します。Fraud DetectoとReturns Managerでは購入者に関するrequest reportをマーチャントが取得し、購入者への提供をマーチャントが行います。オフィス長谷川から購入者へ自動送信されるものではありません。購入者は、購入したストアのマーチャントへも問い合わせてください。
アプリ利用や保存情報に関する問い合わせ・削除依頼は、下記の連絡先へ送ってください。依頼者と対象ストアを確認した上で、適用される法令およびShopifyの要件に従って対応します。
9. セキュリティ
本アプリはShopify認証、shop単位のデータ分離、必要なAPI権限、Webhook署名検証を使用し、Shopify tokenを通常のブラウザー画面へ渡さない設計です。Cloudflare D1のprovider encryption/TLS以外に、保存値へのアプリ層暗号化を実装していないものがあります。アカウント権限、ログ保持、backup、MFAなどの設定は提供者・運営アカウントに依存します。完全な安全を保証するものではありません。
10. 子ども
本アプリは事業者のShopifyストア運営者向けであり、子どもを対象とするサービスではありません。
11. 改定
本アプリのデータ処理、提供者、保持期間または連絡先が変わった場合、本ポリシーを改定し、発効日を更新します。
12. 運営者・お問い合わせ
オフィス長谷川 / Office Hasegawa〒150-0043 東京都渋谷区道玄坂1丁目10番8号 渋谷道玄坂東急ビル2F-C
電話: +81 80-5724-2942
メール: info@officehasegawa.com
Privacy Policy
1. Scope
This Policy applies to the following Shopify apps provided by Office Hasegawa (collectively, the “Apps”): Inventory Audit, Metafield Editor, Inventory Adjuster, Fraud Detecto, Product Validator, and Returns Manager. The Apps are for Shopify merchants. Each App processes different information; see the app-specific descriptions below.
2. Roles
Office Hasegawa processes information to authenticate stores, provide app features, retain settings and operation results, secure the Apps, and provide support. For information about a merchant’s Shopify store or its buyers, the merchant generally determines the purposes and means of processing, and Office Hasegawa processes that information as needed to provide the Apps and follow the merchant’s instructions. Buyers should first contact the merchant from whom they purchased.
3. Information processed across the Apps
- Store and authentication data: Shopify store identifier/domain, installation status, granted scopes, Shopify authentication sessions, and Shopify-issued access or refresh tokens. A session may contain the Shopify Admin user’s ID, name, email address, locale, and role information.
- Settings and operations: app-specific settings, saved views, operation results, request times, error categories, and Shopify webhook processing information.
- Support: contact details, messages, and support history sent by merchants.
- Operational logs: information needed to diagnose failures or abuse, such as store identifiers, event types, internal IDs, counts, and error categories. Log retention and access depend on Cloudflare services and account settings.
4. App-specific data and retention
Each app-specific link takes you to its entry in this Policy.
| App | Information used | Storage and deletion |
|---|---|---|
| Inventory Audit | Inventory adjustment dates, quantities, products/variants, SKUs, locations, reasons, inventory states, staff IDs/names, and reference document IDs/URIs retrieved from Shopify when requested. A reference may point to an order or another record. The App does not directly query customer profiles or Order objects. | Adjustment-history rows and CSV contents are not stored in the App’s D1 database. Store settings and saved filters are deleted by the merchant or during uninstall cleanup. An uninstall marker containing store identification may remain until Shopify’s shop/redact process. |
| Metafield Editor | Selected products and variants, metafield definitions/values, SKUs, and product/variant names. It does not directly query customer profiles or orders. If a customer-reference metafield is selected, a Customer ID may be processed temporarily. | Metafield values and edits are not permanently stored in the App’s D1 database. Saved views remain in browser local storage without an expiry. Shopify webhooks cannot remove them; the user must clear the browser’s site data. Server-side Shopify sessions are deleted on uninstall. |
| Inventory Adjuster | Products, variants, SKUs, names, inventory items, locations, before/delta/after quantities, merchant-entered reasons or references, and update results. | Adjustment receipts and retry payloads are scheduled for deletion 90 days after creation. Cleanup is implemented as a scheduled task, but may be delayed if the task fails or exceeds its processing capacity. Minimal request IDs are retained while installed to prevent duplicate application and deleted on uninstall. |
| Fraud Detecto | Order IDs/display numbers, dates, amounts, currencies, Shopify risk information, Customer IDs, IP addresses, and some shipping-address fields for cross-order pattern detection. Customer names, emails, and phone numbers are not queried. Customer IDs, IP addresses, and addresses are converted to shop-specific HMAC values for analysis. | Raw IP addresses, addresses, and Customer IDs are not stored in the analysis D1 tables. Order summaries and HMAC signals are designed to be deleted within 90 days after order creation; deletion may be delayed if scheduled cleanup fails. For Shopify customer-data requests, the merchant retrieves the report and provides it to the buyer. The App does not automatically reject or cancel orders. |
| Product Validator | Product/variant IDs and names, SKUs, barcode values and types, scan status, and detected issues. It does not query customer, order, or inventory information. | Scan snapshots are retained for up to seven days and the app-wide daily quota counter for ten days, after which cleanup is scheduled. Deletion may be delayed if cleanup does not run. The App does not store customer data as functional app data. |
| Returns Manager | Orders, returnable line items, return reasons, and optional notes submitted by the buyer logged into their Customer Account. Merchants review return details in Shopify Admin and process them through Shopify. The App does not directly query customer names, emails, phone numbers, or addresses. | Return notes are sent to Shopify but are not stored in the App’s D1 database. Return-index identifiers are kept while a return is pending/in progress; records in CANCELED, CLOSED, or DECLINED status are scheduled for deletion 365 days after their last update. Fulfilled privacy-request records are scheduled for deletion after 30 days. Detailed quota operation data is scheduled for deletion after 90 days, while minimal anti-replay records remain while installed. Pending privacy requests and redaction tombstones are retained as needed. Scheduled cleanup may be delayed. |
The periods above describe the Apps’ implemented retention policy. Failed cleanup jobs, recovery backups, and provider or platform logs may delay complete deletion. Backups are subject to the relevant provider’s systems.
5. Purposes
We use information for Shopify authentication; providing app features; reading or updating Shopify data at the merchant’s request; saving settings and operation results; preventing duplicate operations; responding to Shopify privacy requests; support; security; and troubleshooting. We do not use buyer data for advertising, sell it, or use it for unrelated cross-store profiling. Fraud Detecto provides investigation signals and does not automatically reject or cancel orders.
6. Shopify, Cloudflare, and other processing providers
The Apps use the Shopify Admin API or Customer Account API and run on Cloudflare Workers. Persistent data is stored primarily in Cloudflare D1; Fraud Detecto and Returns Manager also use Cloudflare Queues. These providers process information as needed to operate the Apps. The reviewed app code does not integrate with a separate advertising, analytics, or AI provider.
Shopify and Cloudflare may process information outside Japan. We do not guarantee that processing or storage occurs only in a particular country. Cloudflare describes encryption at rest for D1 and TLS between Workers and D1. This does not mean every account setting, backup, or access log has been individually audited. Application-layer encryption for D1 tokens and other stored values is not implemented.
7. Sharing and merchant control
The Apps display information to users authorized in the merchant’s Shopify store. The merchant controls who receives exports, including CSV files. Office Hasegawa may not be able to remotely delete files downloaded to a device or settings/copies stored in a browser. We do not disclose information to third parties except to Shopify, providers needed to operate the Apps, or when legally required.
8. Retention, uninstall, and privacy requests
Shopify sessions and tokens are retained as needed for authentication and are deleted in response to uninstall or Shopify shop/redact events. Automatic cleanup of expired sessions is not implemented uniformly across all Apps, so some session records may remain until a deletion event. Settings, histories, and deletion behavior differ by App as described above.
The Apps receive Shopify customers/data_request, customers/redact, and shop/redact webhooks, verify their signatures, and process the relevant information held by the App. For Fraud Detecto and Returns Manager, the merchant retrieves reports relating to buyer requests and provides them to the buyer. Office Hasegawa does not automatically send those reports to buyers. Buyers may also contact the merchant whose store they used.
For questions or deletion requests about an App or information it stores, contact us below. We will verify the requester and relevant store and respond under applicable law and Shopify requirements.
9. Security
The Apps use Shopify authentication, shop-scoped data access, necessary API permissions, and webhook signature verification. Shopify tokens are not intentionally exposed to ordinary browser UI data. Some values in D1 do not have application-layer encryption beyond provider-level encryption/TLS. Account permissions, log retention, backups, and multi-factor authentication depend on provider and operator-account settings. No method of transmission or storage is completely secure.
10. Children
The Apps are business services for Shopify merchants and are not directed to children.
11. Changes
We may update this Policy when app data practices, providers, retention periods, or contact details change. We will update the effective date.
12. Operator and contact
Office Hasegawa / オフィス長谷川2F-C Shibuya Dogenzaka Tokyu Building, 1-10-8 Dogenzaka, Shibuya-ku, Tokyo 150-0043, Japan
Phone: +81 80-5724-2942
Email: info@officehasegawa.com