Privacy Policy
Ikkatsu Tracking for Shopify
Effective: August 11, 2026 / Last updated: October 2, 2026
1. Operator
MAKES LLC (Office Developers Division)
3-7-1 Minatomirai, Nishi-ku, Yokohama, Kanagawa 220-0012, Japan
Contact: support@gyomu.org
2. Data we handle
The app handles the Shopify store identifier, order ID, order display number, fulfillment ID, carrier, tracking number, shipment status, shipment events, app subscription status, and usage counts.
The app does not store customer names, addresses, phone numbers, email addresses, or payment information in its database.
3. Purposes of use
- Retrieve shipment status and reflect it in Shopify
- Display shipment history to the merchant and authenticated customer
- Stop monitoring after delivery is completed
- Measure usage and manage subscriptions through Shopify App Pricing
- Investigate incidents, prevent abuse, and provide support
4. Security
Tracking numbers are encrypted at rest using AES-256-GCM. A separate-key HMAC is used for searching and duplicate detection. Communications use TLS. Secret keys, Shopify access tokens, and Ikkatsu Tracking API keys are kept server-side and are not sent to the browser.
Production database files, including SQLite journal files, are stored on a LUKS2-encrypted data volume. Operational backup files are OpenPGP encrypted before storage.
Ordinary merchant lists display masked tracking numbers. A full tracking number is shown only in the authenticated customer's order-status history provided through Shopify's authenticated Customer Account API, and in an authenticated merchant's customer-data export when required to respond to a data request. Customer-facing pages access only orders for which Shopify has authenticated the customer.
5. Service providers and disclosure
To retrieve shipment status, the app sends the tracking number and carrier identifier to the Ikkatsu Tracking Common API. Shopify, hosting providers, and other infrastructure providers are also used as service providers where necessary to deliver the service. Operational backups are encrypted before being stored in the hosting environment.
We do not sell handled data to third parties for advertising purposes, except where disclosure is required by law.
6. Retention and deletion
- Shipment history for delivered, cancelled, or replaced shipments with monitoring stopped: 180 days after the last update
- Webhook processing records: 30 days after receipt
- Data request processing records: 180 days after completion
- Subscription and usage records: 730 days after the applicable period
Data is deleted automatically after the applicable retention period. On receipt of Shopify's customers/redact webhook, tracking data for the relevant orders is deleted. On receipt of shop/redact, saved data and sessions for the relevant store are deleted. Other shipment records are deleted when they are covered by these Shopify redaction processes.
These automatic retention periods apply to the live application database. Encrypted backups are managed separately, and a scheduled process removes encrypted backup files and their associated metadata after the file age exceeds 30 days. Before any backup can be restored for application use, the restore-compliance gate applies recorded redactions and current database retention cleanup.
7. Access and deletion requests
When Shopify sends a customers/data_request webhook, the merchant can review saved data for the relevant orders as JSON in the app admin. Contact support@gyomu.org with questions.
8. Changes to this policy
We may revise this policy in response to changes in law, Shopify requirements, or the service. Material changes will be announced on this page or in the app.