プライバシーポリシー
最終更新: 2026年9月1日 / Last updated: September 1, 2026
tamaru は、Shopify ストアでロイヤルティプログラム(ポイント)を運用するアプリです。ポイントの残高そのものは Shopify の store credit に預けており、tamaru は残高を 自前で保持しません。このページは、アプリが保存する情報のすべてを説明します。
保存する情報
- ストアのドメインと設定 — 付与率、据置日数、対象の販売チャネル、 VIP ランクの定義、有効期限、表示の色と文言。
- ポイントの付与・取り消しの履歴 — 顧客の識別子(Shopify の顧客 ID)、 金額、通貨、対象の注文 ID、発生時刻、適用した付与率とランク。金額の根拠を後から説明できるようにするために記録します。
- 紹介の関係 — 紹介コードと、誰が誰を紹介したかの対応。
- Shopify の認証情報 — API アクセストークン。
保存しない情報
顧客の氏名・メールアドレス・電話番号・住所を保存しません。要求もしていません。Shopify の「保護された顧客データ」の設定でも、これらの任意フィールドを選択していません。 ポイントの計算に必要なのは顧客の識別子と注文金額だけです。
クレジットカード情報・決済情報を扱いません。ポイントの引き当ては Shopify の checkout が処理します。
第三者への提供
情報を販売しません。第三者に提供しません。広告・分析のための外部サービスを組み込んでいません。データは Cloudflare (アプリの実行基盤・データベース)と Shopify の中だけにあります。
保管と削除
- 顧客が Shopify 側で個人データの削除を要求したとき(
customers/redact)— 付与・取り消しの履歴から顧客の識別子を不可逆な代替 ID に差し替えます。以後その記録から個人には辿れません。金額・通貨・時刻は残します。これは個人データ ではなく取引の記録であり、ストアの会計記録でもあるためです。紹介の関係と ランクの記録は削除します。 - ストアがアプリを削除したとき — 48 時間後に Shopify から届く
shop/redactで、そのストアのデータをすべて削除します。tamaru は商品・顧客・注文に metafield を書き込まないため、アプリ側の削除で 本当に何も残りません。
要求するアクセス権限
注文の読み取り、顧客の読み取り、store credit の読み取りと入出金の 4 つだけです。テーマへの書き込み権限を要求しません。ストアフロントの表示は theme app extension で行い、テーマのコードを書き換えません。
問い合わせ
Privacy policy (English)
tamaru runs a loyalty points program for Shopify stores. Point balances live in Shopify store credit; tamaru does not hold balances itself.
What we store
- Store domain and settings — earn rate, holding period, eligible sales channels, VIP tier definitions, expiry, display color and wording.
- Point award and reversal history — customer identifier (Shopify customer ID), amount, currency, order ID, timestamp, and the rate and tier applied. We keep this so every amount can be explained afterwards.
- Referral relationships — referral codes and who referred whom.
- Shopify authentication — API access token.
What we do not store
We do not store customer names, email addresses, phone numbers, or addresses, and we do not request them. None of the optional protected customer fields are selected. Point calculation only needs a customer identifier and an order amount. We never handle payment details; redemption is processed by Shopify checkout.
Third parties
We do not sell or share your data. No advertising or analytics SDKs are embedded. Data lives only in Cloudflare (hosting and database) and Shopify.
Retention and deletion
- On
customers/redact, we replace the customer identifier with an irreversible surrogate ID in the award history. Amounts, currency and timestamps remain: these are transaction records and part of the store’s financial records, not personal data. Referral relationships and tier records are deleted. - On
shop/redact(48 hours after uninstall), all data for that store is deleted. tamaru writes no metafields to products, customers or orders, so nothing is left behind.
Scopes we request
Read orders, read customers, read store credit accounts, and write store credit account transactions. We do not request theme write access — the storefront UI is a theme app extension and never edits theme code.