プライバシーポリシー
最終更新: 2026年9月1日 / Last updated: September 1, 2026
Raiten は、Shopify ストアで来店・イベントの予約を受け付けるアプリです。予約枠を 商品のバリアントとして販売し、注文が入ったら予約として記録します。このページは、 アプリが保存する情報のすべてを説明します。
保存する情報
ストアから
- ストアのドメイン(例:
example.myshopify.com)。 - インストール時に Shopify が発行するアクセストークン。ストアの商品と注文を アプリが読み書きするためだけに使います。
- 管理画面を開いたスタッフの氏名・メールアドレス・言語設定。Shopify が発行する セッションに含まれるもので、認証のためだけに保持します。
- 店が入力した設定。予約メニューの名称・説明・所要時間・定員・営業時間・休業日・ 受付期間、リマインダーメールの文面・送信者名・返信先アドレス。
予約した方(購入者)から
予約は Shopify の通常のチェックアウトで成立します。注文が作成されると Shopify から アプリに通知(orders/create Webhook)が届き、次の項目を保存します。
- 氏名、メールアドレス、電話番号、Shopify の顧客 ID。
- 注文の識別子と注文番号(例: #1001)、予約した明細の識別子。
- 予約した枠の日時と人数、予約の状態(確定・キャンセルなど)。
- 予約の変更・キャンセル用のトークン。アプリが生成する値で、予約 1 件に 1 つ 対応します。
- リマインダーメールを送信した日時。
Raiten は配送先住所・支払い情報・予約枠以外の注文内容を保存しません。 アプリにも、テーマに表示される予約カレンダーにも、解析・追跡・広告のコードは 入っていません。
利用する目的
- 予約を確定し、枠の定員を管理するため。
- 店の管理画面に予約一覧を表示し、CSV として書き出せるようにするため。
- 店が有効にした場合に限り、来店の前日にリマインダーメールを送るため。既定では 送信しません。
- 予約した方が自分で日時の変更・キャンセルをできるようにするため(上記の トークンで本人の予約を特定します)。
第三者への提供
Raiten はこれらの情報を販売・貸与しません。処理を委託しているのは次の 2 社です。
- Cloudflare(Workers・D1)— アプリの実行と情報の保存。
- Resend — リマインダーメールの配信。宛先のメールアドレスと本文を 渡します。本文には店名・予約日時・氏名が含まれることがあります。店がリマインダーを 有効にしていない場合、Resend には何も渡しません。
保管期間と削除
- 予約日時から 12 か月を過ぎた予約は、氏名・メールアドレス・ 電話番号・顧客 ID・変更用トークンを自動的に削除します。日時・人数・状態は 店の業務記録として残りますが、個人を特定できる情報は残りません。
- アプリがアンインストールされると、Shopify の
shop/redactが 48 時間後に 届き、そのストアのデータ(設定・予約・枠・セッション)をすべて削除します。 - セッション(アクセストークンを含む)はアンインストールの通知を受けた時点で 削除します。
Shopify が定める個人データ関連の通知には次のとおり対応します。
- 顧客データの開示請求(
customers/data_request)— 該当する 予約を特定し、ストアの運営者を通じて 30 日以内に開示します。 - 顧客データの削除要求(
customers/redact)— 該当する予約から 氏名・メールアドレス・電話番号・顧客 ID・変更用トークンを削除します。 - ストアデータの削除要求(
shop/redact)— そのストアのデータを すべて削除します。
安全管理
- 通信はすべて HTTPS です。保存された情報は Cloudflare D1 上で保管時に暗号化されます。
- 個人情報を含む画面(予約一覧と顧客用の予約ページ)へのアクセスを記録しています。 CSV の書き出しは予約一覧に表示された内容から作られるため、その読み出しが記録に 残ります。記録には氏名やメールアドレスそのものは含めません。
- 個人データの漏えいなどが発生した場合、影響を受けるストアの運営者に速やかに 連絡し、事実と対応を伝えます。
予約した方へ
ご自身の予約に関する情報の開示・削除は、予約したストアへお申し出ください。ストアから Shopify を通じて要求が届いた時点で、Raiten は上記のとおり対応します。
お問い合わせ
このポリシーに関するお問い合わせ: support@weshipd.com
変更
このポリシーを変更した場合、ページ上部の最終更新日を合わせて更新します。
Privacy policy (English)
Raiten is a Shopify app that lets a merchant sell appointment and event slots as product variants and records the resulting orders as bookings. This section describes everything the app stores. The Japanese text above is the original.
What Raiten stores — from the store
- The store domain (for example
example.myshopify.com). - The access token Shopify issues at install, used only to read and write the store's own products and orders.
- The name, email address, and locale of staff who open the admin pages. These come from the Shopify session and are kept only for authentication.
- Settings the merchant enters: menu name, description, duration, capacity, business hours, closed dates, booking window, and the reminder email's subject, body, sender name, and reply-to address.
What Raiten stores — from buyers
Bookings are made through Shopify's normal checkout. When an order is created, Shopify sends the app an orders/create webhook and the app stores:
- Name, email address, phone number, and Shopify customer ID.
- The order and line item identifiers, and the order name (for example #1001).
- The date and time of the booked slot, the number of people, and its status.
- A cancellation token generated by the app — one per booking, used to let the buyer reach their own booking.
- When a reminder email was sent.
Raiten does not store shipping addresses, payment details, or any part of an order other than the booked slot. Neither the app nor the calendar shown in the storefront contains analytics, tracking, or advertising code.
Why it is stored
- To confirm bookings and keep each slot within its capacity.
- To show the merchant a list of bookings and let them export it as CSV.
- To send a reminder email the day before, only when the merchant has turned reminders on. They are off by default.
- To let buyers reschedule or cancel their own booking, identified by the token above.
Sharing
Raiten does not sell or rent this data. Two processors act on our behalf:
- Cloudflare (Workers and D1) — running the app and storing the data.
- Resend — delivering reminder emails. The recipient address and the message body are passed to it; the body may contain the store name, the booking time, and the buyer's name. Nothing is passed when reminders are off.
Retention and deletion
- Twelve months after the booked date, the name, email address, phone number, customer ID, and cancellation token are deleted automatically. The booking row itself (time, quantity, status) remains as the merchant's business record and no longer identifies anyone.
- When the app is uninstalled, Shopify sends
shop/redact48 hours later and every piece of that store's data (settings, bookings, slots, sessions) is deleted. - Sessions, including the access token, are deleted as soon as the uninstall webhook arrives.
Raiten handles Shopify's mandatory privacy webhooks:
- Customer data request — the matching bookings are identified so the merchant can pass them on within 30 days.
- Customer redact — name, email, phone, customer ID, and token are removed from the matching bookings.
- Shop redact — all of that store's data is deleted.
Security
- All traffic uses HTTPS, and stored data is encrypted at rest by Cloudflare D1.
- Access to screens containing personal data (the booking list and the buyer's own booking page) is logged. The CSV export is built from what the booking list has already loaded, so that read is what appears in the log. The logs never contain names or email addresses themselves.
- If personal data is exposed, we notify the affected merchants promptly with what happened and what we did about it.
If you made a booking
To see or delete the information held about your booking, contact the store you booked with. Raiten acts as described above once the request reaches us through Shopify.
Contact
Questions about this policy: support@weshipd.com