プライバシーポリシー — Popup Banner|ABテスト・分析・CVR改善
1. 事業者情報
- アプリ名: Popup Banner|ABテスト・分析・CVR改善
- 事業者名: [要記入]
- 所在地: [要記入]
- 代表者: [要記入]
2. 収集するデータと目的
本アプリが収集・処理するデータは以下のとおりです。
ショップ・セッション情報
- 収集内容: Shopify が発行するセッション情報(ショップドメイン、アクセストークン等)
- 目的: アプリの認証およびShopify Admin APIへのアクセス
ポップアップ設定データ
- 収集内容: マーチャントが作成したポップアップの設定情報(画像URL、リンク先、表示条件、スケジュール等)
- 目的: ストアフロントへのポップアップ配信および管理画面での設定管理
パフォーマンス統計データ
- 収集内容: ポップアップごとの日次集計データ(インプレッション数、クリック数、クローズ数、A/Bバリアント)
- 目的: 管理画面でのCTR・パフォーマンス表示
- 備考: 統計データはポップアップ単位・日次で集計されます。エンドユーザー(ストア訪問者)を個人として識別する情報は収集・保存しません。
ブラウザ側のローカルストレージ(ストア訪問者のブラウザ)
- 収集内容: ポップアップの表示済みフラグ、表示回数カウント、A/Bバリアント割り当て(各ブラウザのlocalStorage / sessionStorage に保存)
- 目的: 頻度上限・再表示制御・A/Bバリアントの固定
- 備考: これらのデータはサーバーに送信・保存されません。ストア訪問者の個人情報(氏名、メールアドレス等)はサーバー側で収集・保存しません。
プラン・課金情報
- 収集内容: 現在の利用プラン(Free / Basic / Pro)
- 目的: プランに応じた機能制限の適用およびポップアップ配信
- 備考: 課金処理はShopify Billing APIを通じてShopifyが行います。クレジットカード情報等の決済情報は本アプリでは収集・保存しません。
アプリ設定
- 収集内容: 管理画面の表示設定(App Embed 案内バナーの非表示フラグ等)
- 目的: 管理画面のUI状態管理
3. データの保管と安全管理
保管場所
本アプリのサーバーサイドデータは、Google Cloud Platform(GCP)上のCloud SQL(PostgreSQL)に保管されます。サーバーはGCP asia-northeast1リージョン(東京)で運用されています。
保管期間
- セッション情報・ポップアップ設定・統計データ・プラン情報・アプリ設定は、マーチャントがアプリをアンインストールした時点で削除されます。
- その他の保管期間については [要記入] です。
安全管理措置
- サーバーとの通信はHTTPS(TLS)で暗号化されます。
- データベースへのアクセスはCloud SQL認証を通じて制限されています。
- APIシークレット等の機密情報はGCP Secret Managerで管理されています。
- 上記以外の具体的な安全管理措置の詳細については [要記入] です。
4. 第三者提供(Shopify APIを含む)
本アプリは以下の第三者サービスを利用します。
Shopify
- 利用内容: アプリの認証(Shopify OAuth)、画像ファイルの保管(Shopify Files API)、課金処理(Shopify Billing API)、ストアフロントへのポップアップ配信(App Proxy / Theme App Extension)
- 取得スコープ:
write_files(ファイルの書き込み)、read_products(商品情報の読み取り)
- Shopifyのプライバシーポリシー: https://www.shopify.com/legal/privacy
Google Cloud Platform(GCP)
その他の第三者への提供
上記以外の第三者に対して、マーチャントまたはストア訪問者のデータを販売・提供することはありません。法令に基づく開示要求がある場合を除きます。
5. ユーザーの権利(開示・削除請求)
マーチャント(アプリ利用者)
マーチャントは、本アプリが保有するショップに関するデータの開示・訂正・削除を請求することができます。削除請求については、アプリをアンインストールすることで、セッション情報・ポップアップ設定・統計データ・プラン情報・アプリ設定がサーバーから削除されます。
ストア訪問者(エンドユーザー)
本アプリはストア訪問者の個人情報をサーバー側で収集・保存しません。ブラウザのlocalStorage / sessionStorageに保存されたデータは、ブラウザの設定からいつでも削除できます。
GDPRコンプライアンス
本アプリはShopifyのGDPRコンプライアンスWebhook(customers/data_request、customers/redact、shop/redact)に対応しています。ストア訪問者の個人情報はサーバーに保存していないため、データリクエストおよびデータ削除リクエストに対しては確認応答のみを返します。ショップデータの削除リクエスト(shop/redact)に対しては、該当ショップの全データを削除します。
請求・お問い合わせは、本ポリシー末尾のお問い合わせ先までご連絡ください。
6. 改定
本プライバシーポリシーは、法令の改正やアプリの機能変更等に伴い、予告なく改定する場合があります。改定後のポリシーは本ページに掲載した時点で効力を生じます。重要な変更がある場合は、管理画面またはその他の方法でお知らせするよう努めます。
7. お問い合わせ
本プライバシーポリシーに関するお問い合わせは、以下までご連絡ください。
- 事業者名: [要記入]
- メールアドレス: [要記入]
- その他の連絡先: [要記入]
Privacy Policy — Popup Banner & A/B Testing
1. Business Information
- App Name: Popup Banner & A/B Testing
- Operator: [To be completed]
- Address: [To be completed]
- Representative: [To be completed]
2. Data We Collect and Why
The following data is collected and processed by this app.
Shop and Session Information
- Data: Session information issued by Shopify (shop domain, access token, etc.)
- Purpose: App authentication and access to the Shopify Admin API
Popup Configuration Data
- Data: Popup settings created by merchants (image URL, link destination, display conditions, schedule, etc.)
- Purpose: Delivering popups to the storefront and managing settings in the admin panel
Performance Statistics
- Data: Daily aggregated data per popup (impressions, clicks, closes, A/B variant)
- Purpose: Displaying CTR and performance metrics in the admin panel
- Note: Statistics are aggregated at the popup level on a daily basis. No information that identifies individual end users (storefront visitors) is collected or stored on the server.
Browser-Side Local Storage (Storefront Visitors' Browsers)
- Data: Popup dismissed flags, display frequency counts, and A/B variant assignments (stored in each browser's localStorage / sessionStorage)
- Purpose: Frequency capping, redisplay control, and A/B variant assignment
- Note: This data is not transmitted to or stored on the server. Personal information of storefront visitors (name, email address, etc.) is not collected or stored server-side.
Plan and Billing Information
- Data: Current subscription plan (Free / Basic / Pro)
- Purpose: Applying plan-based feature restrictions and popup delivery
- Note: Payment processing is handled by Shopify via the Shopify Billing API. Payment details such as credit card information are not collected or stored by this app.
App Settings
- Data: Admin UI state (e.g., App Embed guide banner dismissed flag)
- Purpose: Managing UI state in the admin panel
3. Data Storage and Security
Storage Location
Server-side data for this app is stored in Cloud SQL (PostgreSQL) on Google Cloud Platform (GCP). The server operates in the GCP asia-northeast1 region (Tokyo, Japan).
Retention Period
- Session information, popup configurations, statistics, plan information, and app settings are deleted when a merchant uninstalls the app.
- Retention periods for other data: [To be completed]
Security Measures
- All communication with the server is encrypted via HTTPS (TLS).
- Database access is restricted through Cloud SQL authentication.
- Sensitive information such as API secrets is managed using GCP Secret Manager.
- Details of additional security measures beyond the above: [To be completed]
4. Third-Party Disclosure (Including Shopify APIs)
This app uses the following third-party services.
Shopify
- Usage: App authentication (Shopify OAuth), image file storage (Shopify Files API), billing (Shopify Billing API), storefront popup delivery (App Proxy / Theme App Extension)
- Scopes Requested:
write_files (write files), read_products (read product information)
- Shopify Privacy Policy: https://www.shopify.com/legal/privacy
Google Cloud Platform (GCP)
Other Third Parties
We do not sell or disclose merchant or storefront visitor data to any third parties other than those listed above, except where required by applicable law.
5. User Rights (Access and Deletion Requests)
Merchants (App Users)
Merchants may request access to, correction of, or deletion of data held by this app relating to their shop. For deletion requests, uninstalling the app will cause session information, popup configurations, statistics, plan information, and app settings to be removed from the server.
Storefront Visitors (End Users)
This app does not collect or store personal information of storefront visitors on the server. Data stored in the browser's localStorage / sessionStorage can be deleted at any time through the browser's settings.
GDPR Compliance
This app supports Shopify's GDPR compliance webhooks (customers/data_request, customers/redact, shop/redact). Because no personal information of storefront visitors is stored on the server, data requests and data erasure requests receive an acknowledgment-only response. Shop data deletion requests (shop/redact) result in the deletion of all data associated with the relevant shop.
To submit a request, please contact us using the contact information at the end of this policy.
6. Changes to This Policy
This Privacy Policy may be updated without prior notice due to changes in applicable laws or app functionality. Any revised policy takes effect upon publication on this page. We will endeavor to notify merchants of significant changes through the admin panel or other means.
7. Contact
For inquiries regarding this Privacy Policy, please contact us at:
- Operator: [To be completed]
- Email: [To be completed]
- Other Contact: [To be completed]