PAREL Subscriptions

プライバシーポリシー

最終更新日:2026年9月12日

PAREL Subscriptionsを運営するARCTERIS(以下「当社」)は、Shopifyストア運営者とその顧客に関する情報を、定期購入サービスの提供に必要な範囲で取り扱います。本ポリシーは、当社が収集する情報、その利用目的、保存と削除の方法を説明します。

1. 収集する情報

当社はカード番号、カード有効期限、セキュリティコードを取得または保存しません。配送先変更時や定期購入ギフト受取時の氏名、会社名、配送先住所、郵便番号、電話番号はShopifyで送料を再計算して契約または対象請求回を更新する間だけ処理し、アプリDB、監査ログ、メール、外部Webhookへ保存しません。ギフト受取URLの生のトークンは恒久保存せず照合用ハッシュだけを保持します。購入者がギフト案内メールを依頼した場合に限り、受取人メールと専用鍵で暗号化したトークンを送信・取消・期限切れまでOutboxで一時処理します。メール送信が外部サービスに受理された後、または案内が無効になった後、Outboxに一時保存した宛先、本文、暗号文は消去します。 Shopify Flowトリガーが受理された後も、Outboxに一時保存した顧客参照とイベント本文を消去します。 IP制限付き開発者APIの呼出元IPは許可判定中だけ処理し、DBや監査ログへ保存しません。 顧客施策の計測台帳には、ブラウザが生成した生の判断ID、ギフトURL、生のギフトトークンを保存しません。

2. 利用目的

3. 共有先・処理委託先

サービス提供に必要な範囲で、Shopify、ホスティング・データベース事業者、メール配信事業者(Resend等)へ情報を送信する場合があります。また、店舗が外部Webhookを設定した場合、その店舗が指定した送信先へ契約・決済の最小限の識別子と状態を送信します。氏名、メール、住所、電話番号は外部Webhook本文に含めません。当社は個人情報を販売せず、行動ターゲティング広告のために利用しません。為替レート事業者へ顧客情報を送信しません。

4. 保存期間と削除

情報は、サービス提供、請求、監査、法令対応に必要な期間だけ保持します。Shopifyから顧客削除またはショップ削除の正式な要求を受信した場合、対象データを削除するか、関連付けできない形へ不可逆に仮名化します。アプリのアンインストール時は認証セッションを削除し、Shopifyのショップ削除要求に従って店舗データを削除します。

5. 安全管理

通信の暗号化、アクセス制御、店舗ごとのデータ分離、秘密情報の分離、冪等処理、監査記録を用いて情報を保護します。ただし、インターネット上の通信または保存方法に絶対的な安全性を保証するものではありません。

6. データに関する請求

Shopifyストアの顧客は、購入先ストアへ開示・訂正・削除等を依頼してください。ストア運営者からShopifyの正式なプライバシー要求を通じて受領した請求には、Shopifyの手順に従って対応します。

7. お問い合わせ

本ポリシーまたはデータ取扱いについては、k.yamane@arcteris.jpまでご連絡ください。

8. 変更

法令、Shopify要件またはサービス内容の変更に応じて本ポリシーを更新し、更新日をこのページに表示します。重要な変更は、合理的な方法でストア運営者へ通知します。


Privacy Policy

Last updated: September 12, 2026

ARCTERIS, the operator of PAREL Subscriptions, processes information about Shopify merchants and their customers only as needed to provide subscription services.

Information we process

We process store and session identifiers; subscription contract, customer, order, selling plan, product and variant identifiers; contract status, schedule, quantity, price and currency; billing attempt results; refunds; audit records; incident diagnostic counts, severity, timestamps, and billing-job execution status; selected cancellation reasons, optional comments, and cancellation, pause, skip, frequency-extension, product-change, or next-cycle coupon decision history; timestamps and states for impressions, actions, primary outcomes, and successful orders for cancellation-retention, next-cycle add-on, and subscription-gift experiences, linked with a hashed journey identifier; merchant-provided referral codes and related commission and payout records; and merchant-configured outbound webhook destinations, subscribed events, and delivery or retry results; merchant-created developer API key hashes, scopes, allowed IP addresses, last-used timestamps, rate-limit counters, and usage totals; next-cycle add-on products, quantities, prices, coupon codes, cancellation-retention coupons applied only to the next billing cycle, and their processing results; box products, quantities, categories, prices, selection deadlines, and expansion status confirmed for each billing cycle; qualifying subscription sales, refunds, manual adjustments, tier balances, tiers, and discount and customer-tag synchronization status for membership programs; subscription-gift billing cycles, acceptance deadlines, acceptance, delivery and payment status, delivery option and price, and resulting order identifiers; and minimized inbound webhook identifiers. We temporarily process an email address when sending a post-purchase message, gift-recipient notice, or merchant privacy-request notice. For a requested gift notice, the gift token is stored only as ciphertext under a dedicated key until delivery, cancellation, or expiration. The recipient, message body, and ciphertext are then erased from our outbox. Customer references and event bodies are also erased after Shopify Flow accepts a trigger. For an IP-restricted developer API key, we process the caller IP only while checking the allowlist and do not store it in our database or audit logs.

We do not collect or store card numbers, expiration dates, or security codes. When a delivery address is changed or a subscription gift is accepted, we process the recipient name, company, shipping address, postal code, and phone number only while asking Shopify to recalculate delivery options and update the contract or selected billing cycle. We do not store those fields in the application database, audit log, email, or outbound webhooks. We do not retain raw gift-link tokens at rest; the gift record retains only a lookup hash, with the temporary encrypted exception described above for a buyer-requested recipient notice. The experience-measurement ledger does not retain raw browser decision IDs, gift URLs, or raw gift tokens.

How we use information

We use information to operate selling plans and subscription contracts, process and recover recurring payments, prevent duplicate charges, offer pause or skip alternatives, analyze selected cancellation reasons, measure de-duplicated experience impressions, actions, primary outcomes, and successful orders for the same billing cycle, provide notifications and support, calculate app usage fees and refund adjustments, administer agency referral commissions and manual payout records, send minimized subscription and billing events to merchant-configured systems, verify box selections before billing and prevent unapproved out-of-stock substitutions, calculate membership tiers from net subscription spend, apply the earned tier discount to the following order, synchronize the current tier to a Shopify customer tag, apply a recipient-selected delivery address and shipping price to one gifted billing cycle, investigate incidents, and comply with applicable law and Shopify requirements.

Service providers

We may share the minimum information required with Shopify, hosting and database providers, and email delivery providers such as Resend. When a merchant configures an outbound webhook, we send minimum contract and billing identifiers and status to that merchant-selected destination. We do not include customer names, email addresses, shipping addresses, or phone numbers in outbound webhook bodies. We do not sell personal information or use it for behavioral advertising. Customer information is not sent to our foreign-exchange-rate provider.

Retention, deletion, and security

We retain information only as long as needed for service delivery, billing, audit, and legal obligations. When Shopify sends a valid customer or shop redaction request, we delete the relevant data or irreversibly pseudonymize references that must remain for billing integrity. We use encrypted transport, access controls, tenant isolation, secret separation, idempotent processing, and audit records to protect data.

Requests and contact

Customers should submit access, correction, or deletion requests to the Shopify store where they made their purchase. Merchants can contact us at k.yamane@arcteris.jp. We respond to requests received through Shopify's required privacy webhooks in accordance with Shopify's procedures.

PAREL Subscriptionsへ戻る