Signals プライバシーポリシー

最終更新日: 2026-07-27 / 運営者: 株式会社ギャザリング(Gathring Inc.)
日本語English

はじめに

本プライバシーポリシー(以下「本ポリシー」)は、株式会社ギャザリング(Gathring Inc.)(以下「当社」)が提供する Shopify 埋め込みアプリ 「Signals」(アプリハンドル: ec-lens-connector、 提供 URL: https://connector.ec-lens.com。以下「本アプリ」)における、加盟店およびその ストア訪問者・顧客に関する情報の取扱いについて定めるものです。

本アプリの性質: Signals は、ストアのファーストパーティ計測データと注文データを 収集・集計し、加盟店自身が生データをエクスポート(CSV / JSON / REST API)できるようにする 分析ユーティリティです。ストアフロントの改変・チェックアウトの迂回は行わず、 AI による診断・推奨は一切提供しません(「読み取り・集計・エクスポート」のみ)。 AI 診断機能を持つ当社 SaaS「EC Lens」(ec-lens.com/privacy) とは別サービスであり、本ポリシーは Signals 専用です。

1. 収集する情報と取得方法

1-1. Web Pixel 拡張によるストアフロント・イベント

本アプリは Shopify の公式 Web Pixel 拡張を登録し (スコープ write_pixels / read_customer_events)、加盟店ストアフロント上で 発生する行動イベント(ページ閲覧、商品閲覧、カート追加・削除、検索、コレクション閲覧、 チェックアウト開始・配送先入力・決済情報入力・完了 等)を収集します。収集は Shopify の Customer Privacy(同意)状態に従い、同意がない場合は識別子を伴わない最小限の計測(cookieless)に 切り替わります。スクリプトタグ方式は使用しません。

このうち配送先入力が完了した時点では、地域別の傾向を把握する目的で 国コード・市区町村名・郵便番号の先頭 3 文字のみを取得します。 氏名・番地・電話番号・メールアドレスを Web Pixel から取得することはありません。 郵便番号は意図的に先頭 3 文字までに切り詰めており、これ単体で個人を特定することはできません。

1-2. 注文・顧客・チェックアウト情報(個人情報を含む)

本アプリは orders/create webhook(スコープ read_orders / read_customers)を通じて、確定した注文の情報を取得します。これには氏名・ メールアドレス・住所等の個人情報(PII)が含まれ得ます。当社はこれらを Shopify の保護対象顧客データ(Protected Customer Data)として取り扱います。

read_checkouts は、放棄されたカート(カゴ落ち)の情報の取得に使用しています。 これは、加盟店が当社 SaaS「EC Lens」と本アプリを連携し、カゴ落ちリマインダー機能を有効にしている 場合に限り、EC Lens が本アプリの権限を用いて行います(データの流れは §4 を参照)。

データ最小化: 取得する PII は集計・重複排除に必要な範囲に限定します。 本アプリの公開 REST API および CSV/JSON エクスポートは、加盟店自身の認証のもとで 加盟店が自らのデータにアクセスする目的にのみ用いられ、第三者向けの公開エンドポイントから 顧客 PII を返却することはありません。

1-3. 商品・在庫・分析データ

集計の文脈付けのため、商品カタログ(read_products)から、閲覧・購入された商品が 属するコレクション情報を読み取ります。これは個人を識別しないストア運営データです。

在庫(read_inventory)および Shopify Analytics / Reports (read_analytics / read_reports)については、 権限は保持していますが、現時点ではこれらを用いたデータの取得・保存を行っていません。 将来の機能で使用することがあります。いずれも個人を識別しないストア運営データです。

1-4. アクセスログ

不正利用の防止と監査のため、API・エクスポートへのアクセス日時、リクエスト種別、 対象ショップドメイン等のアクセスログを記録します。顧客 PII への読取アクセスは別途 監査ログ(PII_READ / PII_EXPORT)として記録されます。

2. 利用目的

表示される数値はすべて加盟店自身のデータの事実集計であり、捏造値や AI 生成の推計値は含みません。

3. AI の不使用・AI ベンダーへの非送信

本アプリ(Signals)は AI を一切使用しません。 本アプリが、収集した加盟店データ・ 顧客 PII を、Anthropic・OpenAI その他いかなる外部 AI / LLM ベンダーへ送信することはありません。 AI による診断・推奨・自動生成テキストは本アプリの機能に含まれません。 (加盟店が当社 SaaS「EC Lens」ec-lens.com と本アプリを 連携した場合に限り、§4 に記載の日次集計値が EC Lens 側の AI 分析に用いられます。その場合は 当該サービスのポリシーが適用されます。)

4. 第三者提供・委託

当社は、以下を除き、取得した情報を第三者に提供しません。

4-1. 当社 SaaS「EC Lens」との内部連携

加盟店が自ら EC Lens アカウントと本アプリを連携した場合に限り、EC Lens は当社内部の 連携経路(同一サーバー内・署名付き)を通じて、直近 90 日分の行動イベントおよび注文データを 取得します。このとき注文データから顧客の個人情報(メールアドレス・顧客レコード)は 除外されます。EC Lens 側に保存されるのは日次の集計値のみ (日別・イベント種別ごとの件数、注文件数と売上合計、ファネル各段階の訪問者数)で、行動イベントの 生データは保存されません。この集計値は EC Lens の AI 分析に用いられます。また、カゴ落ち リマインダー機能を有効にした場合、EC Lens は本アプリの権限(read_checkouts)を用いて 放棄されたカートの情報を取得します(§1-2 参照)。

EC Lens は当社が同一法人として運営する別サービスであり、日本法上の「第三者提供」には該当しませんが、 データの流れを明確にするため本項に記載しています。連携後の当該データの取扱いには EC Lens のプライバシーポリシー(AI による分析を含む)が 適用されます。連携していない加盟店のデータが EC Lens へ渡ることはありません。

上記を除き、本アプリから AI / LLM ベンダーへデータを提供・送信することはありません。

5. 安全管理措置

6. 保持期間と自動削除

7. アンインストール時およびデータ削除請求

加盟店が本アプリをアンインストールすると、app/uninstalled webhook により当社は アンインストールを記録します。当該ショップに関する保存データ(注文・イベント・セッション等)の 実際の削除は、Shopify が定める shop/redact コンプライアンス webhook(通常 アンインストールから最大 48 時間後に送信)を契機に実行します。加えて、当社は Shopify の GDPR コンプライアンス webhook 3 種を実装しています。

webhook トピック当社の対応
customers/data_request加盟店経由で受領した顧客のデータ提供請求に対応します。
customers/redact対象顧客に関する保存データを削除(マスキング)します。
shop/redactアンインストール後、対象ショップに関する保存データを削除します。

これらのエンドポイント(/webhooks/gdpr)は HMAC 署名を検証し、不正な署名には 401 を返します。

8. データの所有権と加盟店の権利

本アプリが収集するデータは加盟店に帰属します。加盟店は、本アプリの管理画面から 自らのデータを CSV / JSON でエクスポートでき、また発行されるショップ単位の Bearer トークンを用いて REST API 経由で取得できます。データの開示・訂正・削除の ご請求は、下記の問い合わせ先までご連絡ください。

9. お問い合わせ・運営者情報

運営者: 株式会社ギャザリング(Gathring Inc.)
所在地: 東京都中央区銀座1丁目22番11号
お問い合わせ: customer@ec-lens.com

10. 本ポリシーの変更

当社は、法令の変更やサービス内容の変更に応じて本ポリシーを改定することがあります。重要な変更が ある場合は、本ページ上で告知します。最終更新日は冒頭に記載しています。


Signals — Privacy Policy (English)

Last updated: 2026-07-27 · Operator: 株式会社ギャザリング(Gathring Inc.)

This Privacy Policy describes how 株式会社ギャザリング(Gathring Inc.) ("we") handles information in connection with the Shopify embedded app "Signals" (app handle ec-lens-connector, served at https://connector.ec-lens.com).

Nature of the app: Signals is an analytics utility that collects first-party storefront and order data, aggregates it for the merchant, and lets the merchant export the underlying raw data (CSV / JSON / REST API). It does not modify the storefront, does not bypass checkout, and provides no AI diagnosis or recommendations. It is read / observe / export only. This policy is specific to Signals and is separate from our SaaS product "EC Lens" (ec-lens.com/privacy), which does include AI analysis.

1. Information we collect

1-1. Storefront events via Web Pixel extension. Using Shopify's official Web Pixel extension (scopes write_pixels / read_customer_events), we collect storefront behavioural events (page views, product views, add-to-cart and remove-from-cart, search, collection views, checkout started / shipping address submitted / payment info submitted / completed, etc.), honouring the visitor's Shopify Customer Privacy consent state (a cookieless, identifier-free minimal mode is used when consent is absent). No script-tag injection is used.

When a shipping address is submitted at checkout, we additionally collect only the country code, the city name and the first three characters of the postal code, for regional trend analysis. The Web Pixel never collects names, street addresses, phone numbers or email addresses. The postal code is deliberately truncated to its first three characters and cannot identify an individual on its own.

1-2. Orders and customers (may include PII). Through the orders/create webhook (scopes read_orders / read_customers) we ingest completed order records, which may include personal data such as name, email and address. We treat these as Shopify Protected Customer Data. Data minimisation: PII is limited to what is needed for de-duplicated aggregation, and the app's public REST API never returns customer PII to third parties — exports/API are for the merchant accessing their own data under their own authentication.

1-2b. Abandoned checkouts. read_checkouts is in active use, to retrieve abandoned checkout (abandoned cart) records. This happens only where the merchant has linked our SaaS "EC Lens" to this app and enabled the cart-abandonment reminder feature; EC Lens then performs that retrieval using this app's permission (see section 2a for the data flow).

1-3. Catalog. We read from the product catalog (read_products) the collections a viewed or purchased product belongs to, in order to contextualise aggregates. This is store operations data and does not identify individuals. Inventory (read_inventory) and Shopify Analytics / Reports (read_analytics, read_reports): we hold these permissions but do not currently use them — no data is read or stored through them at present. They may be used by future features. All of these are store operations data that does not identify individuals.

1-4. Access logs. We log access date/time, request type and target shop domain; reads/exports of customer PII are recorded in a dedicated audit log.

2. No AI / no transmission to AI vendors

Signals does not use AI. Signals does not send any collected merchant data or customer PII to Anthropic, OpenAI, or any other external AI/LLM vendor. Only where the merchant has linked our SaaS "EC Lens" to this app are the daily aggregates described in section 2a used by EC Lens's own AI analysis, under that product's own policy.

2a. Internal data sharing with our SaaS "EC Lens"

Only where the merchant has themselves linked their EC Lens account to this app, EC Lens retrieves the last 90 days of behavioural events and order records over our internal, signed, same-server channel. Customer personal data (email address and customer record) is excluded from the order data. What EC Lens stores is daily aggregates only (per-day event counts by type, order counts and revenue totals, and per-stage unique visitor counts); raw behavioural event data is not stored there. Those aggregates are used by EC Lens's AI analysis. In addition, where the cart-abandonment reminder feature is enabled, EC Lens uses this app's permission (read_checkouts) to retrieve abandoned checkout records (see section 1-2b).

EC Lens is a separate service operated by the same company, so this is not a "provision to a third party" under Japanese law; we describe it here to make the data flow explicit. Once linked, EC Lens's own privacy policy (which includes AI-based analysis) applies to that data. No data from merchants who have not linked EC Lens is passed to it.

3. Security, retention and deletion

4. Data ownership and your rights

Collected data belongs to the merchant. Merchants can export their data as CSV / JSON from within the app and retrieve it via the REST API using a per-shop bearer token. To request disclosure, correction or deletion, contact us below.

5. Contact

Operator: 株式会社ギャザリング(Gathring Inc.)
Address: 東京都中央区銀座1丁目22番11号
Email: customer@ec-lens.com