AIO Struct Check プライバシーポリシー
事業者情報
収集するデータと目的
本アプリは、Shopifyストアへのインストールおよびサービス提供に必要な範囲で、以下のデータを収集・処理します。
収集するデータ
ショップ情報
- ショップドメイン、アクセストークン(暗号化保存)、インストール日時、アンインストール日時
- 目的: アプリの認証・動作・課金管理
スキャン・診断データ
- ストアの公開ページURL、HTTPステータス、HTMLコンテンツ(スキャン処理後に短期保存)
- 構造化データ(JSON-LD等)の検出結果、チェック項目の判定結果
- AIOスコア、カテゴリ別スコア、スキャン履歴
- 目的: 内部構造化の診断・スコアリング・課題リストの生成
実装・設定データ
- 有効化したスキーマ種別、設定内容(config_json)
- llms.txt の生成内容、AIクローラー設定
- AI生成FAQの下書き・承認状態(faq_drafts)
- 目的: JSON-LD等の自動実装・管理
課金・プランデータ
- 利用プラン、課金レコード(charge_id)、スキャンページ数・AIクレジット使用量
- 目的: Shopify Billing APIを通じた課金管理・使用量制限の適用
操作ログ
- 実装のON/OFF等の操作履歴(audit_logs)
- 目的: 不正利用の防止・障害調査
AIO診断データ(Premiumプラン・追加パック利用時)
- 登録キーワード、AI回答での表示率・順位・引用ドメイン等の診断結果
- 目的: AI検索エンジンにおける自ストアの表示状況の統計的計測
競合ベンチマークデータ(AdvancedプランおよびPremiumプラン利用時)
- マーチャントが手動登録した競合サイトのURL、当該URLのトップページに対するチェック結果
- 目的: 自ストアと競合サイトのスコア比較
収集しないデータ
本アプリは、ストアの顧客(エンドユーザー)の個人情報を収集しない設計です。氏名・メールアドレス・購買履歴等の顧客データは取得しません。
データの保管と安全管理
保管場所
- データはGoogle Cloud Platform(リージョン: asia-northeast1 / 東京)上のCloud SQL(PostgreSQL 15)に保存します。
- レポートファイル(CSV・PDF)およびHTMLスナップショットはCloud Storageに保存します。HTMLスナップショットは短期保存です。
保存期間
- アンインストール後30日以内に、当該ショップに関するデータを完全削除します。
- その他の保存期間については[要記入]。
安全管理措置
- Shopify OAuthアクセストークンはCloud KMSで暗号化して保存します。
- Webhookの受信時はHMAC署名を検証します。
- 管理画面へのアクセスはShopify App Bridge(セッショントークン)で認証します。
- コンテンツセキュリティポリシー(CSP)を設定しています。
- システムの稼働状況はCloud Monitoring・Error Reporting・Uptime Checkで監視しています。
- 競合URLの取得処理では、プライベートIPアドレス・クラウドメタデータIPアドレス・内部ホスト等へのアクセスを拒否するSSRF対策を実装しています。
第三者提供(Shopify APIを含む)
本アプリは、サービス提供のために以下の第三者サービスを利用します。これらのサービスに対し、処理に必要な範囲でデータが送信されます。
| サービス |
用途 |
提供するデータの範囲 |
| Shopify(Admin GraphQL API / Billing API / Webhook) |
ストア情報取得・課金処理・イベント受信 |
ショップドメイン・アクセストークン・課金情報 |
| Google Cloud Platform(Cloud Run・Cloud SQL・Cloud Tasks・Cloud Storage・Cloud Scheduler・Secret Manager・KMS) |
アプリのホスティング・データ保存・ジョブ処理 |
上記「収集するデータ」全般 |
| Vertex AI(Gemini 2.5 Flash) |
AI FAQ下書き生成・改善提案文生成 |
商品説明・メタフィールド等のストアコンテンツ |
| OpenAI(Responses API) |
AIO診断(ChatGPT照会) |
登録キーワード |
| SerpApi |
AIO診断(Google AI Overviews取得) |
登録キーワード |
上記以外の第三者にデータを販売・提供することはありません。各サービスのプライバシーポリシーは各社のウェブサイトをご参照ください。
ユーザーの権利(開示・削除請求)
Shopifyマーチャント(ショップオーナー)は、本アプリが保有するショップに関するデータについて、以下の権利を行使できます。
- データの開示請求: 保有データの内容の確認を求めることができます。
- データの削除請求: 保有データの削除を求めることができます。
また、本アプリはShopifyのGDPR必須Webhookに対応しています。
customers/data_request: 顧客データの開示要求
customers/redact: 顧客データの削除要求
shop/redact: ショップデータの削除要求
app/uninstalled: アンインストール時のデータ削除キュー投入
請求・お問い合わせは、下記「お問い合わせ」欄のメールアドレスまでご連絡ください。
改定
本プライバシーポリシーは、法令の改正・サービス内容の変更等に応じて改定することがあります。重要な変更を行う場合は、アプリ内またはメール等の適切な方法でお知らせします。改定後のポリシーは、掲載した時点から効力を生じます。
お問い合わせ
プライバシーポリシーに関するご質問・データの開示・削除請求は、以下までご連絡ください。
AIO Struct Check — Privacy Policy
Business Information
Data We Collect and Why
We collect and process data only to the extent necessary to install the app and provide its services.
Data Collected
Shop Information
- Shop domain, access token (stored encrypted), installation date, uninstallation date
- Purpose: Authentication, app operation, and billing management
Scan and Diagnostic Data
- Public page URLs, HTTP status codes, and HTML content of the store (retained for a short period after scan processing)
- Detected structured data (JSON-LD, etc.) and check-item results
- AIO scores, category scores, and scan history
- Purpose: Diagnosing internal structure, scoring, and generating issue lists
Implementation and Configuration Data
- Enabled schema types and configuration settings (config_json)
- Generated llms.txt content and AI crawler settings
- AI-generated FAQ drafts and approval status (faq_drafts)
- Purpose: Auto-injection and management of JSON-LD and related structured data
Billing and Plan Data
- Subscription plan, billing records (charge_id), scanned page count, and AI credit usage
- Purpose: Billing management via Shopify Billing API and usage-limit enforcement
Audit Logs
- Operation history such as enabling/disabling implementations (audit_logs)
- Purpose: Fraud prevention and incident investigation
AIO Diagnostic Data (Premium plan and add-on credit packs)
- Registered keywords, and diagnostic results including appearance rate, ranking, and cited domains in AI responses
- Purpose: Statistical measurement of how often the store appears in AI search engines
Competitor Benchmark Data (Advanced and Premium plans)
- Competitor site URLs manually registered by the merchant, and check results for those URLs' top pages
- Purpose: Comparing the merchant's store score against competitor sites
Data We Do Not Collect
This app is designed not to collect personal information of the store's end customers. We do not access customer names, email addresses, purchase history, or similar customer data.
Data Storage and Security
Storage Location
- Data is stored in Cloud SQL (PostgreSQL 15) on Google Cloud Platform (region: asia-northeast1 / Tokyo).
- Report files (CSV and PDF) and HTML snapshots are stored in Cloud Storage. HTML snapshots are retained for a short period only.
Retention Period
- All data associated with a shop is permanently deleted within 30 days of uninstallation.
- Retention periods for other data: [To be completed]
Security Measures
- Shopify OAuth access tokens are encrypted at rest using Cloud KMS.
- Incoming webhooks are verified using HMAC signatures.
- Access to the admin interface is authenticated via Shopify App Bridge (session tokens).
- A Content Security Policy (CSP) is applied.
- System health is monitored via Cloud Monitoring, Error Reporting, and Uptime Check.
- Competitor URL fetching includes SSRF protections that reject requests to private IP addresses, cloud metadata IP addresses, and internal hostnames.
Third-Party Services (Including Shopify API)
To provide its services, the app uses the following third-party services. Data is shared with these services only to the extent required for processing.
| Service |
Purpose |
Data Shared |
| Shopify (Admin GraphQL API / Billing API / Webhooks) |
Retrieving store information, processing billing, receiving events |
Shop domain, access token, billing information |
| Google Cloud Platform (Cloud Run, Cloud SQL, Cloud Tasks, Cloud Storage, Cloud Scheduler, Secret Manager, KMS) |
App hosting, data storage, job processing |
All data described in the "Data We Collect" section |
| Vertex AI (Gemini 2.5 Flash) |
Generating AI FAQ drafts and improvement suggestions |
Store content such as product descriptions and metafields |
| OpenAI (Responses API) |
AIO diagnostics (ChatGPT queries) |
Registered keywords |
| SerpApi |
AIO diagnostics (Google AI Overviews retrieval) |
Registered keywords |
We do not sell or share data with any third parties beyond those listed above. Please refer to each provider's own privacy policy for details.
User Rights (Access and Deletion Requests)
Shopify merchants (shop owners) may exercise the following rights regarding data held by this app:
- Right of Access: You may request confirmation of what data we hold about your shop.
- Right to Deletion: You may request that we delete data we hold about your shop.
The app also supports Shopify's mandatory GDPR webhooks:
customers/data_request: Customer data access requests
customers/redact: Customer data deletion requests
shop/redact: Shop data deletion requests
app/uninstalled: Queuing data deletion upon uninstallation
To submit a request, please contact us at the email address listed in the "Contact" section below.
Revisions
This Privacy Policy may be updated in response to changes in applicable laws or the services we provide. When material changes are made, we will notify you through the app or by other appropriate means such as email. Revised policies take effect upon publication.
Contact
For questions about this Privacy Policy or to submit a data access or deletion request, please contact us at: