Privacy Policy
AI Optimizer
本アプリが扱うデータについて
本アプリはShopifyマーチャント向けの業務用アプリです。扱うデータは次の2種類に分かれます。
- マーチャント情報: アプリを導入したストア運営者に関する情報(ストアドメイン、アプリの利用状況)
- ストア内のデータ: マーチャントが保有する商品データと、注文の流入元のみ。購入者の氏名・住所・電話番号・メールアドレスは取得しません。
Go Studio(以下「当方」)は、AI Optimizer(以下「本アプリ」)における個人情報の取扱いについて、以下のとおり定めます。
本ポリシーは日本語を正本とします。右上の切替から表示できる英語版は参考のための自動翻訳であり、相違がある場合は本ページの日本語版が優先します。
0. 当方の立場
本アプリが扱うデータは、次の2つに分かれ、それぞれ当方の立場が異なります。
- マーチャントのストア内のデータ(商品データ等)について、当方はマーチャントの委託を受けてこれを取り扱います。当方は、本ポリシー第2項に定める目的の範囲を超えて、これらのデータを利用しません。データの内容について決定する権限はマーチャントにあります。
- マーチャント自身に関する情報(ストアドメイン、ストア担当者の氏名・メールアドレス、アプリの利用状況、サポートのやり取り)について、当方は自ら取扱いの目的を定める事業者として、本ポリシーに従って取り扱います。
委託を受けた取扱いの詳細(目的限定、再委託先、安全管理措置、保存期間、漏えい時の通知、マーチャントへの情報提供)は、利用規約第5項に定めます。
1. 取得する情報
1-1. マーチャントに関する情報
本アプリのインストール時に、Shopifyから以下を取得します。
- ストアのドメイン、ストア名、アプリの認証情報(アクセストークン)
- ストアオーナーの氏名・メールアドレス(Shopifyがアプリに提供する範囲)
1-2. ストア内の商品データ
診断と修正提案のために、以下を取得します。
- 商品名、説明文、商品画像の代替テキスト、カテゴリ、タグ、ブランド、メタフィールド、SEO情報
- バリアントの価格、SKU、バーコード、在庫数
1-3. 注文の流入元に関する情報
AI経由の売上を計測するために、注文に紐づく以下の情報のみを取得します。
- 参照元URL、流入元の名称、流入区分、発生日時
当方は、購入者の氏名・住所・電話番号・メールアドレスを取得しません。また、これらを取得するための権限(保護顧客データ Level 2)を Shopify に申請していません。
※ 本項の機能は、Shopifyの保護顧客データアクセスの承認を得たうえで順次提供します。
1-4. 保存する内容
当方のデータベースに保存するのは、次のものに限られます。
- セッション情報 — ストアのドメイン、Shopifyのアクセストークン、および Shopify がアプリに提供するストア担当者のアカウント情報(氏名、メールアドレス、ロケール、アカウント種別)。アプリの認証を維持するために必要なものです
- 商品ごとの診断結果とスコアの履歴 — 商品ID、商品名、スコア、未達となった診断項目
- AI修正機能の利用量 — ストア単位・月単位の処理件数のみ
- 日付×流入チャネル単位に集計した、注文件数と売上金額
個々の注文の識別子および購入者を識別しうる情報は、一切保存しません。
2. 利用目的
取得した情報は、次の目的にのみ利用します。
- 商品データがAIエージェント経由で発見されうる状態かを診断し、スコアと課題を提示するため
- 商品説明・代替テキスト等の改善案を生成し、マーチャントの承認を経て反映するため
- AI経由の流入と売上の推移をマーチャントに提示するため
- 不具合の調査と本アプリの品質改善のため
- マーチャントからの問い合わせに対応するため
上記以外の目的には利用しません。
3. 第三者提供
当方は、次の場合を除き、取得した情報を第三者に提供しません。
- ご本人またはマーチャントの同意がある場合
- 法令に基づく場合
- 第4項に定める外部サービスに、利用目的の達成に必要な範囲で取扱いを委託する場合
当方は、取得した情報を販売しません。
4. 外部サービスの利用
本アプリは、機能の提供のために次の外部サービスを利用します。
| 事業者 | 提供先へ渡る情報 | 取扱いを行う国 | 目的 |
|---|---|---|---|
| Anthropic(Claude API) | 商品データのテキスト(商品名・説明文・カテゴリ・代替テキスト等) | 米国 | 商品説明等の改善案の生成 |
| Shopify | — | — | 認証、課金、アプリの配信 |
| Render | 上記1-4の保存内容 | 米国 | アプリの稼働 |
| Neon(PostgreSQL) | 上記1-4の保存内容 | 米国 | データの保存 |
| Sentry | エラー発生時の技術情報 | 米国 | 不具合の検知 |
Anthropic に送信されるのは商品データであり、購入者の個人情報は含まれません。また、当方は API 経由で送信したデータがモデルの学習に利用されない条件で利用しています。
上記のうち、日本国外で取扱いが行われるものについては、当方は、個人情報の保護に関する法律第28条および同法施行規則第16条に基づき、委託先との契約により、日本の個人情報保護法が求める措置に相当する措置を継続的に講じさせ、その実施状況を定期的に確認しています。
移転先の外国の名称、当該外国における個人情報の保護に関する制度、および委託先が講じている相当措置の概要については、お問い合わせ窓口までご請求いただければ、遅滞なくご提供します。
5. 安全管理措置
- 通信はすべて暗号化(HTTPS)します
- 保存されるデータは暗号化された環境で保持します(Neonの既定の暗号化)
- アクセストークン等の認証情報は環境変数として管理し、ソースコードには含めません
- 本番環境のデータにアクセスできるのは、本アプリを運営する担当者のみに限定します
- 取得する情報を、機能の提供に必要な最小限に留めます。 具体的には、注文データを取得する権限は直近60日分の範囲に限定し、それ以上の期間を取得する権限(
read_all_orders)は申請しません
6. 保存期間と削除
- スコアの履歴(スコア、商品数、未達件数などの要約)は、記録した日から24か月間保存し、経過したものから順に削除します。あわせて、1ストアあたりの保存件数を直近1,000件に制限しており、これを超える古い記録は24か月の経過前でも古いものから削除します
- 商品ごとの診断結果の内訳(商品ID、商品名、商品別のスコア、未達となった診断項目)は、直近10回分のスキャンについてのみ保存し、それより古い内訳は削除します
- AI修正機能の利用量の記録は、対象月の末日から24か月間保存します
- セッション情報は、アプリが導入されている間、および認証の有効期間中のみ保持します
- エラー調査のための技術情報(Sentry)は、Sentryの保持設定に従い、最長90日で削除されます
- 本アプリをアンインストールした場合、Shopifyはその約48時間後に削除要求(
shop/redact)を送信します。当方はこれを受信した時点で、当該ストアに関して保存しているすべてのデータを直ちに削除します - 購入者に関する削除要求(
customers/redact)については、当方が購入者の個人情報を保存していないため、削除対象が存在しません
7. 開示・訂正・削除・利用停止
個人情報の保護に関する法律(個人情報保護法)に基づき、ご本人からの開示・訂正・追加・削除・利用停止のご請求に対応します。下記お問い合わせ窓口までご連絡ください。ご本人であることを確認のうえ、合理的な期間内に対応します。
8. 子どものプライバシー
本アプリはEC事業者向けの業務用ツールであり、子どもによる利用を想定していません。子どもから意図的に個人情報を取得することはありません。
9. 本ポリシーの改定
当方は、法令の改正や本アプリの機能変更に応じて本ポリシーを改定することがあります。改定を行う場合、当方は、改定後の内容および効力発生時期を定め、効力発生時期が到来するまでに、本ページへの掲載および本アプリ内の表示により周知します。マーチャントの権利義務に影響を与える改定については、効力発生の30日前までに周知します。
お問い合わせ・事業者情報
- 事業者:
- Go Studio(個人事業)
- 代表者:
- 樋口 一裕
- 所在国:
- 日本
本ポリシーに関するお問い合わせ、個人情報の開示等のご請求、および委託先における個人データの取扱いに関するご照会は、お問い合わせページよりご連絡ください。
当方の住所は、ご請求に応じて遅滞なくご回答します。
About the data this App handles
This App is a business tool for Shopify merchants. The data we handle falls into two categories.
- Merchant information: information about the store operator who installed the App (store domain, app usage).
- Data within the store: only product data held by the merchant and the source of orders. We do not collect shoppers' names, addresses, phone numbers, or email addresses.
Go Studio ("we") sets forth the following policy regarding the handling of personal information in AI Optimizer (the "App").
The Japanese version of this policy is authoritative. This English version, available via the toggle above, is an automated translation provided for reference. In the event of any discrepancy, the Japanese version on this page shall prevail.
0. Our Role
The data handled by the App falls into two categories, in which our role differs:
- Data inside the merchant's store (such as product data) is handled by us as an entity entrusted by the merchant. We do not use that data beyond the purposes set out in Section 2 of this policy. The merchant retains authority over the content of that data.
- Information about the merchant itself (store domain, store staff name and email address, app usage, and support correspondence) is handled by us as the party that determines the purposes of such handling, in accordance with this policy.
The detailed terms governing entrusted handling — purpose limitation, sub-contractors, security measures, retention periods, incident notification, and provision of information to merchants — are set out in Section 5 of our Terms of Service.
1. Information We Collect
1-1. Merchant Information
Upon installation, we receive the following from Shopify.
- Store domain, store name, and app credentials (access token)
- The store owner's name and email address, to the extent provided by Shopify to the App
1-2. Product Data in the Store
For diagnosis and generating improvement suggestions, we collect the following.
- Product titles, descriptions, image alt text, categories, tags, vendor, metafields, and SEO information
- Variant price, SKU, barcode, and inventory count
1-3. Order Source Information
To measure AI-driven revenue, we collect only the following information associated with an order.
- Referring URL, source name, source type, and timestamp
We do not collect shoppers' names, addresses, phone numbers, or email addresses. We have also not requested the Shopify permission (Level 2 protected customer data) that would allow us to do so.
Note: the features described in this subsection are rolled out progressively, after we obtain Shopify's approval for protected customer data access.
1-4. What We Store
Only the following is stored in our database:
- Session information — the store domain, the Shopify access token, and the store staff account details that Shopify provides to the App (name, email address, locale, and account type). These are required to maintain the App's authenticated connection to the store.
- Per-product diagnostic results and score history — product ID, product title, score, and which diagnostic checks were not met.
- AI fix usage — per-store, per-month processing counts only.
- Order counts and revenue, aggregated by date and traffic channel.
We do not store individual order identifiers or any information that could identify a shopper.
2. Purpose of Use
We use the information we collect solely for the following purposes.
- To diagnose whether product data is discoverable via AI agents, and present a score and issues
- To generate improvement suggestions for product descriptions, alt text, and similar content, applied only after merchant approval
- To show merchants trends in AI-driven traffic and revenue
- To investigate defects and improve the quality of the App
- To respond to inquiries from merchants
We do not use the information for any purpose other than the above.
3. Provision to Third Parties
We do not provide the information we collect to third parties except in the following cases.
- Where the individual or the merchant has consented
- Where required by law
- Where entrusted to the external services listed in Section 4, to the extent necessary to achieve the purposes of use
We do not sell the information we collect.
4. Use of Third-Party Services
The App uses the following external services to provide its features.
| Provider | Information Shared | Country of Processing | Purpose |
|---|---|---|---|
| Anthropic (Claude API) | Product data text (title, description, category, alt text, etc.) | United States | Generating improvement suggestions for product descriptions |
| Shopify | — | — | Authentication, billing, and app distribution |
| Render | Data described in 1-4 above | United States | Operating the App |
| Neon (PostgreSQL) | Data described in 1-4 above | United States | Storing data |
| Sentry | Technical information when an error occurs | United States | Detecting defects |
Only product data is sent to Anthropic; no shopper personal information is included. We use the API under terms where data submitted via the API is not used for model training.
Where any of the above handle data outside Japan, we ensure — under Article 28 of Japan's Act on the Protection of Personal Information and Article 16 of its Enforcement Rules — through our contracts with those providers, that they continuously implement measures equivalent to those required of us under Japanese law, and we periodically confirm their implementation.
On request to our contact point, we will provide without delay the names of the foreign countries concerned, information on their personal data protection regimes, and an outline of the equivalent measures taken by those providers.
5. Data Security Management
- All communications are encrypted (HTTPS)
- Stored data is held in an encrypted environment (Neon's default encryption)
- Credentials such as access tokens are managed as environment variables and are not included in source code
- Access to production data is limited to personnel operating the App
- We limit the information we collect to the minimum necessary to provide the App's features. Specifically, we limit our permission to access order data to the most recent 60 days, and we do not request the
read_all_orderspermission that would allow access beyond that period
6. Retention and Deletion
- Score history (the summary: score, product counts, and failure counts) is retained for 24 months from the date recorded, and is deleted on a rolling basis thereafter. We also cap storage at the most recent 1,000 scans per store; records older than that cap are deleted before the 24-month period elapses
- Per-product diagnostic detail (product ID, product title, per-product score, and which diagnostic checks were not met) is retained only for the 10 most recent scans; older detail is deleted
- AI fix usage records are retained for 24 months from the end of the month they relate to
- Session information is retained only while the App is installed and the authentication remains valid
- Technical information used for error investigation (Sentry) is deleted in accordance with Sentry's retention settings, within a maximum of 90 days
- If the App is uninstalled, Shopify sends a deletion request (
shop/redact) approximately 48 hours later. On receipt, we immediately delete all data we hold for that store - Regarding shopper deletion requests (
customers/redact), there is no data to delete because we do not store shoppers' personal information
7. Disclosure, Correction, Deletion, and Suspension of Use
In accordance with Japan's Act on the Protection of Personal Information (APPI), we respond to requests from the individual for disclosure, correction, addition, deletion, or suspension of use of their personal information. Please contact us using the details below. After verifying your identity, we will respond within a reasonable period.
8. Children's Privacy
The App is a business tool for e-commerce merchants and is not intended for use by children. We do not knowingly collect personal information from children.
9. Revision of this Policy
We may revise this policy in response to legal changes or changes to the App's features. When we do, we will set out the revised content and the date on which it takes effect, and will give notice by posting it on this page and displaying it within the App before that date arrives. For revisions that affect a merchant's rights or obligations, we will give notice at least 30 days before the effective date.
Contact and Operator Information
- Business:
- Go Studio (a sole proprietorship)
- Representative:
- Kazuhiro Higuchi
- Country of establishment:
- Japan
For inquiries about this policy, requests to disclose personal information, and questions about how our sub-contractors handle personal data, please contact us via our contact page.
We will provide our address without delay upon request.
制定日: 2026年8月13日
最終更新日(効力発生日): 2026年8月13日
Established: August 13, 2026
Last updated (effective date): August 13, 2026