Omake プライバシーポリシー / Privacy Policy
English version follows the Japanese text. / 英語版は日本語の後に続きます。
Omake プライバシーポリシー
株式会社Craftify(以下「当社」)は、Shopifyアプリ「Omake」(以下「本アプリ」)における個人情報および利用者情報の取り扱いについて、以下のとおり定めます。
1. 取得する情報
本アプリは、インストールしたストアについて以下の情報のみを取得・保存します。
- ストアのドメイン(例: example.myshopify.com)
- Shopifyが発行するアクセストークン
- 付与された権限(スコープ)およびその有効期限
2. 取得しない情報
本アプリは、以下の情報を取得も保存もしません。
- 買い物客の氏名、住所、メールアドレス、電話番号などの個人情報
- 注文の内容、決済情報
- ストアの顧客リスト
- ストアのスタッフの氏名、メールアドレス
本アプリが要求する権限は、商品・ディスカウント・チェックアウト検証の操作、ストアの言語設定の読み取り、商品の公開情報の読み取りに限られます。顧客情報および注文情報を読み取る権限は要求しません。
3. 利用目的
取得した情報は、本アプリがShopifyのAPIを通じて以下を行うためにのみ利用します。
- ノベルティ設定の保存および読み出し
- 条件を満たしたカートへのノベルティの追加
- チェックアウト時の検証
4. 保管場所と期間
情報は日本国内(東京リージョン)のサーバーに保管します。
- アプリケーション: Fly.io(東京)
- データベース: Supabase(東京)
保存した情報は、本アプリがストアからアンインストールされた時点で削除します。ShopifyのWebhook(app/uninstalled、shop/redact)を受信して削除処理を行います。
5. 第三者への提供
取得した情報を第三者に販売、貸与、提供することはありません。上記の保管および処理のために、以下の事業者のサービスを利用します。
- Shopify Inc.(アプリの実行基盤)
- Fly.io, Inc.(アプリケーションの実行環境)
- Supabase, Inc.(データベース)
6. お問い合わせで受け取る情報
本アプリに関するお問い合わせをメールでいただいた場合、送信者の氏名、メールアドレス、ストア名およびお問い合わせの内容を受け取ります。これらはお問い合わせへの回答と本アプリのサポートのためにのみ利用し、第三者に提供しません。
これらの情報の開示、訂正、利用停止または削除を希望される場合は、下記のお問い合わせ先までご連絡ください。ご本人であることを確認のうえ、法令に従って対応します。
7. 安全管理措置
当社は、取得した情報の漏えい、滅失または毀損を防ぐため、以下の措置を講じます。
- 本アプリとの通信はすべて暗号化(HTTPS)する
- データベースにアクセスできる者を、当社の担当者と本アプリに限定する
- アクセストークンを本アプリの動作以外の目的に使用しない
8. 買い物客からの請求について
本アプリは買い物客の個人情報を保持していないため、Shopifyからデータ開示請求(customers/data_request)または削除請求(customers/redact)を受信した場合、開示または削除すべきデータが存在しない旨を記録します。
9. お問い合わせ
本ポリシーおよび個人情報の取り扱いに関するお問い合わせ先
株式会社Craftify
メール: support@crafti-fy.jp
10. 改定
本ポリシーの内容は、必要に応じて改定することがあります。重要な変更を行う場合は、本ページで告知します。
制定日: 2026年9月9日
最終更新日: 2026年9月12日
Omake Privacy Policy
This policy describes how Craftify Inc. (“we”) handles information in the Shopify app “Omake” (“the App”).
1. Information we collect
For each store that installs the App, we collect and store only:
- The store domain (e.g. example.myshopify.com)
- The access token issued by Shopify
- The granted scopes and their expiry
2. Information we do not collect
The App does not collect or store:
- Shoppers’ names, addresses, email addresses, or phone numbers
- Order contents or payment information
- The store’s customer list
- Names or email addresses of store staff
The App requests permissions only to manage products, discounts, and checkout validation, to read the store’s language settings, and to read public product listings. It does not request permission to read customer or order data.
3. How we use it
The stored information is used solely to let the App call Shopify’s APIs in order to:
- Save and read the gift settings
- Add the gift to carts that meet the configured conditions
- Validate the cart at checkout
4. Where and how long we store it
Data is stored on servers in Japan (Tokyo region).
- Application: Fly.io (Tokyo)
- Database: Supabase (Tokyo)
Stored data is deleted when the App is uninstalled from the store. Deletion is triggered by Shopify’s app/uninstalled and shop/redact webhooks.
5. Third parties
We do not sell, rent, or otherwise provide the collected information to third parties. We use the following service providers for hosting and processing:
- Shopify Inc. (app platform)
- Fly.io, Inc. (application hosting)
- Supabase, Inc. (database)
6. Information from support inquiries
When you contact us by email about the App, we receive your name, email address, store name, and the content of your inquiry. We use this information only to respond to you and to support the App, and we do not provide it to third parties.
If you wish to request disclosure, correction, suspension of use, or deletion of this information, please contact us at the address below. We will verify your identity and respond in accordance with applicable law.
7. Security
We take the following measures to prevent leakage, loss, or damage of the information:
- All communication with the App is encrypted (HTTPS)
- Access to the database is limited to our authorized staff and the App itself
- Access tokens are used only for the App’s operation
8. Requests about shoppers
The App holds no shopper personal data. When Shopify sends a data request (customers/data_request) or an erasure request (customers/redact), we record the request and confirm that no such data exists.
9. Contact
Craftify Inc.
Email: support@crafti-fy.jp
10. Changes
We may revise this policy. Material changes will be announced on this page.
Effective date: September 9, 2026
Last updated: September 12, 2026