FormSync Customer Forms プライバシーポリシー
1. 事業者情報
- アプリ名: FormSync Customer Forms
- 開発者・運営者: [要記入]
- 所在地: [要記入]
- 連絡先: [要記入]
2. 収集するデータと目的
本アプリは、Shopifyストアのマーチャントおよびそのストアの顧客から、以下のデータを収集・処理します。
マーチャント(ストア運営者)から収集するデータ
| データ種別 |
収集目的 |
| ショップドメイン・ショップ識別情報 |
アプリの動作・テナント管理 |
| プラン・課金情報(Shopify Billing API経由) |
サブスクリプション管理・従量課金処理 |
| フォーム定義・フィールド設定 |
フォームの構築・表示 |
| 許可リスト(メールアドレス・電話番号・氏名・任意コード) |
照合処理 |
| タグルール・設定情報 |
顧客セグメント管理 |
| アップロードされたロゴ画像(Shopify Files経由で保管) |
ゲートページの表示 |
顧客(エンドユーザー)から収集するデータ
| データ種別 |
収集目的 |
| フォーム回答内容(氏名・電話番号・メールアドレス・任意入力値等) |
顧客メタフィールド・標準フィールドへの書き込み |
| メール/SMS購読同意(同意日時・取得元を含む) |
マーケティング同意の記録・Shopifyへの反映 |
| ログイン前ゲートでの入力内容(一時保存) |
ログイン後の顧客レコードへの書き込み |
| フォーム送信履歴(送信日時・配置面・照合結果) |
送信履歴の管理・表示 |
| IPアドレス(ショップIDで加塩したハッシュ値のみ保存) |
レート制限・不正アクセス防止 |
| 照合入力値(ハッシュ値のみ保存、原文は保存しない) |
許可リスト照合ログの管理 |
本アプリは、収集したデータを上記目的の範囲内でのみ使用します。
3. データの保管と安全管理
保管場所・環境
- アプリのデータベースはMySQL(Google Cloud Run / asia-northeast1リージョン)上で動作します。
- ロゴ画像はアプリサーバーには保存されず、Shopify Filesに保管されます。
保存期間
| データ種別 |
保存期間 |
| ログイン前ゲートの一時保存データ(PendingSubmission) |
最大7日間(期限切れ後に自動削除) |
| 照合ログ(MatchLog) |
最大90日間(自動削除) |
| 許可リスト(削除予定日が設定された場合) |
設定された削除予定日まで |
| その他の顧客データ・送信履歴 |
[要記入] |
安全管理措置
- 許可リストへの照合入力値は原文を保存せず、SHA-256ハッシュ値のみを記録します。
- IPアドレスはショップIDで加塩したハッシュ値のみを記録します。
- ゲートトークンはHMAC-SHA256で生成し、データベースにはハッシュ値のみを保存します。
- Cookieは HttpOnly・Secure・SameSite=Lax の属性を付与して発行します。
- レート制限(60秒間に20回)および照合失敗ロック(5回失敗で900秒ロック)を実装しています。
- 管理画面上の照合ログUIでは、ハッシュ値の先頭4文字・末尾2文字のみを表示します。
- 照合拒否の理由(未登録・期限切れ・利用回数超過等)は顧客には開示しません。
- その他の技術的・組織的安全管理措置については[要記入]。
4. 第三者提供(Shopify APIを含む)
本アプリは、以下の第三者サービスとデータをやり取りします。
Shopify
本アプリはShopify APIを使用して動作します。アプリが利用するShopify APIのスコープは以下のとおりです。
read_customers・write_customers:顧客の標準フィールド・メタフィールド・同意情報・タグの読み書き
read_files・write_files:ゲートページ用ロゴのShopify Filesへの保存
read_themes:テーマのOS 2.0対応状況・App Embed有効状態の診断
Shopifyのプライバシーポリシーについては、Shopify Inc.の定めるポリシーをご参照ください。
Shopify Flow
マーチャントがShopify Flowとの連携を設定した場合、フォーム送信時および照合拒否時にトリガーイベントが送信されます。
Google Cloud
アプリのサーバーはGoogle Cloud Run(asia-northeast1リージョン)上で動作しています。
その他の第三者提供
上記以外の第三者へ顧客データを提供することは、法令に基づく場合を除き行いません。
5. ユーザーの権利(開示・削除請求)
顧客(エンドユーザー)の権利
本アプリはShopifyのGDPR要件に基づく以下のWebhookを実装しています。
- customers/data_request:顧客データの開示請求に対応します。
- customers/redact:顧客データの削除請求に対応します。対象データには、送信履歴・ログイン前一時保存データ・同意ログが含まれます。
- shop/redact:ストアのアンインストールから48時間経過後、ストアに紐づく全データを削除します。
アンインストール直後はデータを即時削除せず、再インストール時のデータ継続性のために保持します。shop/redactウェブフック受信後に削除処理を実行します。
データの開示・削除請求の方法
データの開示・削除をご希望の場合は、下記お問い合わせ先までご連絡ください。
6. 改定
本プライバシーポリシーは、法令の改正・アプリの機能変更等に伴い、予告なく改定する場合があります。改定後のポリシーは本ページに掲載した時点で効力を生じます。重要な変更がある場合の通知方法については[要記入]。
7. お問い合わせ
プライバシーポリシーに関するお問い合わせは、以下までご連絡ください。
- 担当窓口: [要記入]
- メールアドレス: [要記入]
- その他連絡先: [要記入]
FormSync Customer Forms Privacy Policy
1. Business Information
- App name: FormSync Customer Forms
- Developer / Operator: [To be completed]
- Address: [To be completed]
- Contact: [To be completed]
2. Data Collected and Purposes
This app collects and processes data from Shopify merchants and their store customers as described below.
Data Collected from Merchants (Store Operators)
| Data Type |
Purpose |
| Shop domain and shop identifier |
App operation and tenant management |
| Plan and billing information (via Shopify Billing API) |
Subscription management and usage-based billing |
| Form definitions and field settings |
Building and displaying forms |
| Allow list entries (email addresses, phone numbers, names, custom codes) |
Allow list matching |
| Tag rules and configuration settings |
Customer segmentation |
| Uploaded logo images (stored via Shopify Files) |
Displaying the gate page |
Data Collected from Customers (End Users)
| Data Type |
Purpose |
| Form responses (name, phone number, email address, custom input values, etc.) |
Writing to customer metafields and standard fields |
| Email / SMS marketing consent (including timestamp and collection source) |
Recording consent and syncing to Shopify |
| Pre-login gate input (temporarily stored) |
Writing to the customer record after login |
| Form submission history (timestamp, surface placement, match result) |
Managing and displaying submission history |
| IP address (stored only as a salted hash using the shop ID) |
Rate limiting and abuse prevention |
| Allow list input values (stored only as hash values; raw values are never stored) |
Managing allow list match logs |
This app uses collected data solely for the purposes described above.
3. Data Storage and Security
Storage Environment
- The app database runs on MySQL via Google Cloud Run (asia-northeast1 region).
- Logo images are not stored on the app server; they are stored in Shopify Files.
Retention Periods
| Data Type |
Retention Period |
| Pre-login gate temporary data (PendingSubmission) |
Up to 7 days (automatically deleted after expiry) |
| Match logs (MatchLog) |
Up to 90 days (automatically deleted) |
| Allow list entries (when a deletion date is configured) |
Until the configured deletion date |
| Other customer data and submission history |
[To be completed] |
Security Measures
- Allow list input values are never stored in plain text; only SHA-256 hash values are recorded.
- IP addresses are stored only as hash values salted with the shop ID.
- Gate tokens are generated using HMAC-SHA256; only the hash value is stored in the database.
- Cookies are issued with the HttpOnly, Secure, and SameSite=Lax attributes.
- Rate limiting (20 requests per 60 seconds) and match-failure locking (locked for 900 seconds after 5 failures) are implemented.
- The match log UI in the admin panel displays only the first 4 and last 2 characters of hash values.
- The reason for allow list rejection (not found, expired, usage limit reached, etc.) is not disclosed to customers.
- Additional technical and organizational security measures: [To be completed].
4. Third-Party Disclosure (Including Shopify API)
This app exchanges data with the following third-party services.
Shopify
This app operates using the Shopify API. The Shopify API scopes used by the app are as follows:
read_customers / write_customers: Reading and writing customer standard fields, metafields, marketing consent, and tags.
read_files / write_files: Storing gate page logos in Shopify Files.
read_themes: Diagnosing theme OS 2.0 compatibility and App Embed status.
For Shopify's privacy practices, please refer to the privacy policy published by Shopify Inc.
Shopify Flow
When a merchant configures Shopify Flow integration, trigger events are sent upon form submission and upon allow list match rejection.
Google Cloud
The app server runs on Google Cloud Run (asia-northeast1 region).
Other Third-Party Disclosure
Customer data is not disclosed to any third parties other than those listed above, except as required by applicable law.
5. User Rights (Access and Deletion Requests)
Rights of Customers (End Users)
This app implements the following webhooks in accordance with Shopify's GDPR requirements:
- customers/data_request: Handles customer data access requests.
- customers/redact: Handles customer data deletion requests. Data subject to deletion includes submission history, pre-login temporary data, and consent logs.
- shop/redact: Deletes all data associated with a store 48 hours after uninstallation.
Data is not deleted immediately upon uninstallation; it is retained to support data continuity in the event of reinstallation. Deletion is performed upon receipt of the shop/redact webhook.
How to Submit Access or Deletion Requests
To request access to or deletion of your data, please contact us using the information provided in the Contact section below.
6. Revisions
This Privacy Policy may be updated without prior notice due to changes in applicable laws or app functionality. Any revised policy takes effect upon publication on this page. The method of notification for material changes: [To be completed].
7. Contact
For inquiries regarding this Privacy Policy, please contact us at:
- Contact person / department: [To be completed]
- Email address: [To be completed]
- Other contact information: [To be completed]