プライバシーポリシー
最終更新日: 2026-10-09
「受注チェッカー」(以下「本アプリ」)は、株式会社AmpTechが提供するShopifyアプリです。本ポリシーは、本アプリが取得する情報とその取り扱いを説明します。
本アプリは、お客様(ストアの購入者)の個人情報を当社のサーバーに保存しません。
発送前チェックの表示に必要な氏名・住所・電話番号・注文内容は、画面を開いたときにShopifyから直接取得して表示するのみで、当社側には保存しません。
取得する情報
- ストア情報: ストアのドメイン、プラン、主要言語、タイムゾーン
- 接続情報と受信記録: Shopifyが本アプリに発行したアクセストークン(ストアのデータへアクセスするための鍵)と認証セッションの情報、および受信したWebhookの配信ID・種別・受信日時(同じ通知を二重に処理しないための記録で、30日で削除します)。ストア情報に記録するアクセストークンは、アプリ側でも暗号化して保存します。購入者の情報は含みません
- チェックルールの設定内容: マーチャントが本アプリ上で設定した判定条件
- チェック結果の記録: Shopifyの注文識別子(注文ID)、注文番号、注文日時、合計金額と通貨、入金状態・発送状態、適用したルール、判定結果、確認状態(未確認/確認済み)、確認したスタッフの識別子、確認日時
- 担当者名簿: マーチャントが本アプリに登録した担当者の表示名と、任意で紐付けたShopifyスタッフの識別子(マーチャントの従業員情報であり、購入者の情報ではありません)
- 確認コメント: 担当者が注文ごとに入力する自由記述のメモ。自由記述であるため個人情報が混入する可能性があります。入力欄には注意書きを常時表示し、チェック結果より短い保持期間で自動削除します
- アクセス記録: 注文の詳細を表示した日時、表示したスタッフの識別子、その画面で表示した項目の種別(氏名・住所・電話番号などの区分名のみで、値は含みません)。一覧画面の閲覧は記録しません(一覧には顧客個人情報を表示しないため)
- 出荷保留の記録: 保留をかけた注文の識別子とフルフィルメントの識別子、Shopifyが発行した保留の識別子、保留の種類(入金・住所・配送日時など)、保留した日時と解除した日時。購入者を特定する情報は含みません
- 配送希望日などの取得元の設定: 注文のどの項目から配送希望日や時間帯を読み取るかの設定と、自動検出で見つかった項目名・書式の種別。項目名と書式だけで、入力された値そのものは保存しません
- ご利用量の記録: 月ごとにチェックした注文の件数(プランの上限判定に使います)
- 注文内容の要約値: 同じ内容の注文を繰り返し判定しないための、注文内容から計算した不可逆な要約値(ハッシュ)。元の内容を復元することはできません
- 顧客データ開示要請の受付記録: Shopifyから届いた開示要請の識別子(要請ID。届かない場合は配信ID)、受付日時、対応期限、対象となった注文の識別子と、提供対象の規模を示す件数(対象注文数・チェック結果・検出理由・確認履歴・出荷保留・確認コメントの各件数)、対応済みかどうか・対応日時・対応したスタッフの識別子。購入者を特定する情報(氏名・メールアドレス・電話番号・購入者の識別子)は一切含みません
チェック結果の記録に含まれる注文情報は識別子と非個人情報の項目(注文番号・金額・入金状態など)のみで、氏名・住所・電話番号・メールアドレス・注文明細は含まれません。
取得するが保存しない情報
本アプリは、発送前チェックの実行と画面表示のために、Shopify Admin APIを通じて以下の情報にアクセスします。いずれも処理・表示のために一時的に扱うのみで、当社のデータベースには保存しません。
- 注文の配送先情報(氏名・会社名・住所・電話番号)
- 注文の請求先住所(配送先の氏名と一致するかの判定にのみ使用し、画面には表示しません)
- 注文の備考欄・カスタム属性(配送希望日、熨斗の指定など)
- 注文のタグとメタフィールド(配送希望日などが入っている場合に読み取ります)、および商品のタグ(冷凍・冷蔵などの判定に使用します)
- 注文の支払い状況・取引履歴・明細と、Shopifyが付与する不正リスク評価
取得しない情報
- ストアフロント(購入者が閲覧するページ)に一切関与しないため、閲覧者の行動履歴・Cookie・IPアドレス等を取得しません(取得する仕組みを持ちません)
- 決済情報(クレジットカード番号等)
利用目的とアクセス権限
本アプリが使用するアクセス権限(スコープ)は次のとおりです。いずれも「発送前に確認が必要な注文を検出し、確認業務を記録する」という本アプリの機能提供のためにのみ使用します。目的外の利用、第三者への提供、広告・分析目的での利用は一切行いません。
read_orders / write_orders: 注文の入金状態・配送先・請求先住所・備考・明細を読み取って判定するため、およびマーチャントが操作したときにのみ「配送先住所の修正」と「入金済みとしてマーク」を行うため。書き込みはこの2つだけで、本アプリが自動で注文を書き換えることはありません
read_merchant_managed_fulfillment_orders / write_merchant_managed_fulfillment_orders: 要確認と判定された注文の出荷を保留し、確認後に解除するため
read_assigned_fulfillment_orders: 外部倉庫に割り当てられた出荷単位の状態を確認するため
read_products: 商品の温度帯(冷凍・冷蔵)などを判定するため
read_locales: ストアの主要言語に合わせて管理画面の表示言語を初期設定するため
顧客一覧(read_customers)および60日より前の注文(read_all_orders)へのアクセス権限は要求しません。メールアドレスは保護対象顧客データの申請対象に含めていません。
第三者サービス
本アプリは Fly.io(ホスティング)、Supabase(データベース)、Sentry(エラー監視)を利用します。いずれもサービス提供のためにのみ利用します。Sentryへエラー情報を送信する前に、リクエストの本文、URLのクエリ文字列、Cookie、認証情報を含むリクエストヘッダ(ブラウザの種類など一部を除きます)、利用者の識別情報を取り除きます。上記「取得するが保存しない情報」をエラーメッセージに含めない方針で実装していますが、エラーメッセージの本文は原因の調査のために送信するため、そこに情報が含まれる可能性を完全には排除できません。
データの保存場所と処理場所
本アプリを提供する株式会社AmpTechは日本の法人であり、欧州(欧州経済領域・英国・スイス)に拠点を持ちません。本アプリが扱う情報の保存場所と処理場所は次のとおりです。
- アプリサーバー(Fly.io): 東京リージョン(日本)で稼働します。注文のチェックと、画面表示のためにShopifyから情報を取得する処理は、このサーバー上で行います
- データベース(Supabase): 上記「取得する情報」は、東京リージョン(日本)のデータベースに保存します
- エラー監視(Sentry): エラー情報は米国で処理・保存します
本アプリの画面との通信は、Fly.ioのネットワークを経由します。Fly.ioは、接続元に近いFly.ioの拠点で暗号化通信(TLS)を終端し、東京のサーバーへ転送します。そのため、日本国外から本アプリの画面を開いた場合、画面に表示する情報はその地域のFly.ioの拠点を経由します。
したがって、欧州のストアについても、上記「取得する情報」は欧州域外である日本のデータベースに保存します。購入者に関する情報(上記「取得するが保存しない情報」)は保存せず、日本のサーバー上で処理するだけです。エラー情報は米国で処理・保存します。ただし、欧州から本アプリの画面を開いた場合の通信は、上記のとおり欧州にあるFly.ioの拠点を経由します。
データの保持と削除
- チェック結果と確認履歴は、対応完了から既定24か月で自動削除します。マーチャントは本アプリの「全般設定」で12・24・36・60か月から選べます
- 確認コメントは、個人情報が混入する可能性があるため既定12か月と短く設定しています(3・6・12・24か月から選択可)。期限を過ぎたコメントは本文のみを削除し、「いつ・誰が・何をしたか」の記録は残します
- アプリをアンインストールすると、再インストールの猶予として24時間おいたうえで、当該ストアのデータを全テーブルから物理削除します
- Shopifyからの削除要請(shop/redact)を受けた場合は、猶予を待たず直ちに削除します
- 上記の削除とは別に、処理を順番に実行するためのジョブ管理記録(ストアのドメインと注文の識別子を含みます。購入者を特定する情報は含みません)は、各処理が終わってから24時間後に保管用の領域へ移し、その24時間後に削除します。そのため、ストアのデータを削除したあとも、この記録は最長で約48時間残ります
- お客様個人の削除要請(customers/redact)を受けた場合、当社は氏名・住所・電話番号・メールアドレスを保存していないため削除すべき項目は原則ありません。ただし該当注文に確認コメントが残っている場合は、その本文を削除します
- 顧客データ開示要請の受付記録は、対応済みにしたものだけをチェック結果と同じ保持期間(既定24か月・対応日から起算)で自動削除します。未対応のものは、対応期限の管理に必要なため対応が完了するまで削除しません
お問い合わせ
dev@amptech.co.jp(日本語・英語対応)
利用規約
本アプリの利用条件はアプリ利用規約をご覧ください。
Privacy Policy
Last updated: 2026-10-09
"Order Checker" ("the App") is a Shopify app provided by AmpTech Inc. This policy explains what information the App collects and how it is handled.
The App does not store your customers' personal information on our servers.
Names, addresses, phone numbers, and order details needed for pre-shipment review are fetched directly from Shopify when you open the screen, and are not persisted on our side.
Information we collect
- Store information: store domain, plan, primary language, and timezone
- Connection and delivery records: the access token Shopify issues to the App (the key used to reach the store's data) and authentication session information, plus the delivery ID, topic and received time of each webhook we receive (kept so the same notification is not processed twice, and deleted after 30 days). The access token recorded with the store information is additionally encrypted by the App before it is stored. These records contain no shopper information
- Check rule settings: the conditions the merchant configures in the App
- Check results: Shopify order identifiers (order IDs), order number, order date, total amount and currency, payment and fulfillment status, the rules applied, the outcome, review status (pending / reviewed), the identifier of the staff member who reviewed it, and the review timestamp
- Assignee list: display names the merchant registers in the App, and optionally the linked Shopify staff identifier (this is merchant employee information, not shopper information)
- Review comments: free-text notes staff write on an order. Because they are free text, they may contain personal information. The input field carries a persistent warning, and comments are deleted automatically on a shorter retention period than check results
- Access records: when an order's detail screen was viewed, which staff member viewed it, and which categories of field were displayed (category names such as name / address / phone only — never the values). Viewing the order list is not recorded, because the list shows no customer personal information
- Fulfillment hold records: the identifiers of the order and fulfillment order we placed a hold on, the hold identifier Shopify issued, the hold category (payment, address, delivery date and so on), and when it was placed and released. These records contain nothing that identifies a shopper
- Field mapping settings: which order field the App reads the requested delivery date and time slot from, plus the field names and value formats found by automatic detection. We store the field names and formats only, never the values entered into them
- Usage records: how many orders were checked in each month, used to apply plan limits
- Order content digest: an irreversible digest (hash) computed from the order's contents so the same order is not re-evaluated unnecessarily. The original contents cannot be recovered from it
- Customer data request records: the identifier of each data request Shopify sends us (the request ID, or the webhook delivery ID when no request ID is delivered), when it was received, its response deadline, the identifiers of the orders it covers together with counts that indicate the size of the disclosure (orders covered, check results, findings, review-history entries, fulfillment holds and review comments), and whether it has been handled together with when and by which staff member. These records contain nothing that identifies a shopper — no name, email address, phone number, or shopper identifier
The order data in check result records is limited to identifiers and non-personal fields (order number, amount, payment status, and the like) — no names, addresses, phone numbers, email addresses, or line items.
Information we access but do not store
To run pre-shipment checks and render the review screen, the App accesses the following through the Shopify Admin API. All of it is handled transiently for processing and display only, and is never written to our database.
- Order shipping details (name, company, address, phone number)
- Order billing address (used only to compare the name against the shipping address; it is never shown on screen)
- Order notes and custom attributes (requested delivery date, gift wrapping instructions, etc.)
- Order tags and order metafields (read where they hold values such as a requested delivery date), and product tags (used to determine attributes such as frozen / chilled)
- Order payment status, transactions, line items, and the fraud risk assessment Shopify assigns
Information we do not collect
- The App has no storefront component, so it does not collect visitor behavior, cookies, or IP addresses (no mechanism exists to do so)
- Payment information (credit card numbers, etc.)
Purpose and access scopes
The App uses the following access scopes, solely to detect orders that require review before shipment and to record the review workflow. We do not use them for any other purpose, share them with third parties, or use them for advertising or analytics.
read_orders / write_orders: to read payment status, shipping and billing addresses, notes, and line items for evaluation, and — only when the merchant performs the action — to correct a shipping address or mark an order as paid. Those two writes are the only ones the App makes; it never rewrites an order on its own
read_merchant_managed_fulfillment_orders / write_merchant_managed_fulfillment_orders: to place a fulfillment hold on flagged orders and release it after review
read_assigned_fulfillment_orders: to read the status of fulfillment orders assigned to third-party warehouses
read_products: to determine product attributes such as temperature band (frozen / chilled)
read_locales: to initialise the admin UI language from the store's primary locale
We do not request access to the customer list (read_customers) or to orders older than 60 days (read_all_orders), and we do not request email as a protected customer data field.
Third-party services
The App uses Fly.io (hosting), Supabase (database), and Sentry (error monitoring), solely to provide the service. Before an error report is sent to Sentry, we remove the request body, URL query strings, cookies, request headers that carry authentication details (a few, such as the browser type, are kept), and user identifiers. We build the App so that the data listed under "Information we access but do not store" is not placed in error messages; however, the text of an error message is sent so that we can diagnose the problem, and we cannot entirely rule out that it contains such data.
Where data is stored and processed
AmpTech Inc., which provides the App, is a company established in Japan and has no establishment in Europe (the European Economic Area, the United Kingdom, or Switzerland). Information handled by the App is stored and processed as follows.
- Application servers (Fly.io): run in the Tokyo region (Japan). Order checks, and fetching information from Shopify to render the App's screens, take place on these servers
- Database (Supabase): the information listed under "Information we collect" is stored in a database in the Tokyo region (Japan)
- Error monitoring (Sentry): error reports are processed and stored in the United States
Connections to the App's screens pass through Fly.io's network. Fly.io terminates the encrypted connection (TLS) at a Fly.io location close to where the connection originates, and forwards it to our servers in Tokyo. When the App is opened from outside Japan, the information shown on screen therefore passes through a Fly.io location in that region.
Accordingly, for stores in Europe as well, the information listed under "Information we collect" is stored in a database outside Europe, in Japan. Information about customers (listed under "Information we access but do not store") is not stored; it is only processed on our servers in Japan. Error reports are processed and stored in the United States. The exception is that, when the App is opened from Europe, the connection passes through a Fly.io location in Europe as described above.
Data retention and deletion
- Check results and review history are deleted automatically 24 months after the order is resolved by default. Merchants can choose 12, 24, 36, or 60 months in the App's General settings
- Review comments use a shorter default of 12 months because they may contain personal information (3, 6, 12, or 24 months selectable). When a comment expires we delete its text and keep only the who / when / what record
- After uninstalling, we wait 24 hours as a reinstall grace period and then physically delete the store's data from every table
- We delete data immediately upon a shop/redact request from Shopify, without waiting for that grace period
- Separately from the deletion above, job management records used to run processing in order (they contain the store domain and order identifiers, and nothing that identifies a shopper) are moved to an archive 24 hours after each job finishes and deleted 24 hours after that. These records therefore remain for up to about 48 hours after the store's data has been deleted
- For customers/redact requests, we store no names, addresses, phone numbers, or email addresses, so there is normally nothing to delete. If a review comment exists on the affected order, we delete its text
- Customer data request records are deleted automatically only once they have been marked as handled, on the same retention period as check results (24 months by default, counted from the date they were handled). Records that are still outstanding are kept until they are handled, because we need them to track the response deadline
Contact
dev@amptech.co.jp (Japanese and English)
Terms of Service
Your use of the App is governed by our Terms of Service.