レコットの紹介にもどる
レコット
プライバシーポリシー
Burst株式会社(以下「当社」)は、商品診断サービス「レコット」(管理画面、Shopify アプリ、ストアに設置される診断を含み、以下「本サービス」)において取り扱う情報について、個人情報の保護に関する法律その他の法令を遵守し、以下のとおり取り扱います。本サービスを導入する事業者を「利用者」、診断を利用するお客さまを「エンドユーザー」といいます。日本語版と英語版に相違がある場合は、日本語版が優先します。
1. 事業者情報
事業者名:Burst株式会社
所在地:〒220-0072 神奈川県横浜市西区浅間町1-4-3 ウィザードビル402
代表者:久野 隆二
所在地:〒220-0072 神奈川県横浜市西区浅間町1-4-3 ウィザードビル402
代表者:久野 隆二
2. 利用者について取得する情報
・Shopify ストアの情報:ストアのドメイン、ストア名、Shopify が発行するアクセストークン(暗号化して保管します)、許可された権限の範囲、インストール・アンインストールの日時
・商品情報:商品名、価格、通貨、商品画像、商品ページの URL、商品タグ、商品タイプ、ベンダー、販売可否。商品の説明文や在庫数は取得しません
・会社情報:利用者が保存した法人名、所在地、電話番号、ご担当者名、連絡先メールアドレス、ロゴ画像。Shopify のストア情報(ストア名、住所、メールアドレス)は入力欄の初期値としてのみ表示し、利用者が保存するまで記録しません
・契約・請求の情報:プラン、契約状態、期間、Shopify または Stripe の課金・決済 ID、追加枠のご購入記録、当社が発行する適格請求書。カード情報は当社では保持しません
・同意・操作の記録:利用規約への同意、追加枠の購入、自動追加への同意を行った方のメールアドレス(Shopify アプリからの利用規約への同意では、ストアのメールアドレス)
・管理画面から直接ご利用の場合:ログイン用のメールアドレス、表示名、ならびにパスワード(ハッシュ化して保管)または Google/Apple のアカウント識別子、最終ログイン日時。管理画面は、ログイン状態の維持と不正防止のため Cookie を使用します
・お問い合わせや商談を通じていただいた、ご担当者名、連絡先、対応の記録
・商品情報:商品名、価格、通貨、商品画像、商品ページの URL、商品タグ、商品タイプ、ベンダー、販売可否。商品の説明文や在庫数は取得しません
・会社情報:利用者が保存した法人名、所在地、電話番号、ご担当者名、連絡先メールアドレス、ロゴ画像。Shopify のストア情報(ストア名、住所、メールアドレス)は入力欄の初期値としてのみ表示し、利用者が保存するまで記録しません
・契約・請求の情報:プラン、契約状態、期間、Shopify または Stripe の課金・決済 ID、追加枠のご購入記録、当社が発行する適格請求書。カード情報は当社では保持しません
・同意・操作の記録:利用規約への同意、追加枠の購入、自動追加への同意を行った方のメールアドレス(Shopify アプリからの利用規約への同意では、ストアのメールアドレス)
・管理画面から直接ご利用の場合:ログイン用のメールアドレス、表示名、ならびにパスワード(ハッシュ化して保管)または Google/Apple のアカウント識別子、最終ログイン日時。管理画面は、ログイン状態の維持と不正防止のため Cookie を使用します
・お問い合わせや商談を通じていただいた、ご担当者名、連絡先、対応の記録
3. エンドユーザーについて取得する情報
・診断の回答:選んだ選択肢またはスライダーの値と、表示した結果。自由記述欄はなく、氏名・メールアドレス・電話番号等は取得しません
・診断の利用状況:質問の表示、診断の開始と完了、選択肢の選択、結果の表示、商品ページのクリック。いずれも、ページを開くたびに新しく作られる無作為な ID(セッション ID)に結び付けて記録します。本サービスの診断画面は Cookie を使用しません。商品画像は、Shopify その他の利用者の画像配信元からエンドユーザーのブラウザに直接読み込まれます
・購入の記録(Shopify アプリのみ):第5項の Web ピクセルにより、診断の結果を表示したセッションからの購入について、購入金額、通貨、購入日(日単位)を記録します。注文番号、顧客 ID、氏名、メールアドレス、住所は記録しません
・通信の記録:サーバーは、不正利用の防止と障害の調査のため、アクセス元 IP アドレス、アクセス先の URL、日時等をホスティング事業者のログに記録します。IP アドレスはデータベースには保存しません
・診断の利用状況:質問の表示、診断の開始と完了、選択肢の選択、結果の表示、商品ページのクリック。いずれも、ページを開くたびに新しく作られる無作為な ID(セッション ID)に結び付けて記録します。本サービスの診断画面は Cookie を使用しません。商品画像は、Shopify その他の利用者の画像配信元からエンドユーザーのブラウザに直接読み込まれます
・購入の記録(Shopify アプリのみ):第5項の Web ピクセルにより、診断の結果を表示したセッションからの購入について、購入金額、通貨、購入日(日単位)を記録します。注文番号、顧客 ID、氏名、メールアドレス、住所は記録しません
・通信の記録:サーバーは、不正利用の防止と障害の調査のため、アクセス元 IP アドレス、アクセス先の URL、日時等をホスティング事業者のログに記録します。IP アドレスはデータベースには保存しません
4. 回答からの推定(年代・性別の傾向)
利用者が選択肢に年代や性別の傾向を設定した場合、当社は回答から年代・性別の傾向を集計し、利用者のレポートに表示します。推定はレポートの表示時に集計として行い、エンドユーザーごとの推定結果は保存しません。20セッション未満の集計は表示しません。推定は参考情報であり、エンドユーザーの実際の年代・性別を示すものではありません。
5. Web ピクセルとブラウザへの保存(Shopify アプリ)
Shopify アプリは、ストアに Web ピクセルを追加します。Web ピクセルは、ページの閲覧とチェックアウトの完了を検知し、Shopify のプライバシー設定で分析とマーケティングの両方が許可されている場合に限り動作します(ストアの地域の設定によっては、同意の表示がなく許可として扱われる場合があります)。診断から商品ページに進んだ際の URL に含まれるセッション ID をブラウザ(localStorage)に保存し、購入が完了すると、セッション ID、購入金額、通貨を当社に送信して、保存した ID を消去します。保存から30日を過ぎた ID は送信に使用しません。許可が取り消された場合は、ストアのページを開いた時点で保存した ID を消去します。
6. 利用目的
本サービスの提供(診断の表示、商品との対応づけ、レポートの作成)、Shopify ストアとの商品の同期、料金の請求と適格請求書の発行、利用規約の改定等のご通知、お問い合わせへの対応、営業および顧客管理、不正利用の防止、障害の調査、ならびに本サービスの保守および品質の向上のために利用します。ある利用者の情報を、他の利用者の診断やレポートのために利用しません。ただし、個人および利用者を識別できない統計情報を作成し、利用または公表することがあります(レコット利用規約 第8条)。
7. 第三者提供
エンドユーザーの情報は、その診断を設置した利用者に対してのみ、レポート等の形で提供します。法令に基づく場合を除き、ご本人の同意なくその他の第三者へ提供することはありません。
8. 業務委託・外国にある第三者への提供
当社は、利用目的の達成に必要な範囲で、以下の外部サービスに情報の取り扱いを委託し、委託先には必要かつ適切な監督を行います。
・データの保管:Supabase(データベース/日本・東京リージョン)
・サーバーの運用:Vercel(日本・東京リージョンで処理。通信の記録を含みます)
・メールの送信:Resend(米国)。利用者へのご請求書、ご通知、メールアドレスの確認・パスワード再設定のメール、ならびに第10項のご報告の送信に使用します
・決済:Stripe(米国)。管理画面から直接ご利用の場合の料金のお支払いに使用し、利用者のメールアドレスを送信します
Resend および Stripe は米国に所在するため、これらに送信する情報を外国にある第三者へ提供することになります。当該国の個人情報の保護に関する制度については、個人情報保護委員会のウェブサイトで公表されている情報をご参照ください。委託先との契約に基づき、適切な安全管理措置を講じます。
Shopify アプリからご利用の場合、ストアの情報、商品情報、課金の記録は Shopify(Shopify Inc.)から当社が取得し、料金は Shopify の課金を通じてお支払いいただきます。Google/Apple でログインした場合は、各社からメールアドレスと表示名を取得します。
・データの保管:Supabase(データベース/日本・東京リージョン)
・サーバーの運用:Vercel(日本・東京リージョンで処理。通信の記録を含みます)
・メールの送信:Resend(米国)。利用者へのご請求書、ご通知、メールアドレスの確認・パスワード再設定のメール、ならびに第10項のご報告の送信に使用します
・決済:Stripe(米国)。管理画面から直接ご利用の場合の料金のお支払いに使用し、利用者のメールアドレスを送信します
Resend および Stripe は米国に所在するため、これらに送信する情報を外国にある第三者へ提供することになります。当該国の個人情報の保護に関する制度については、個人情報保護委員会のウェブサイトで公表されている情報をご参照ください。委託先との契約に基づき、適切な安全管理措置を講じます。
Shopify アプリからご利用の場合、ストアの情報、商品情報、課金の記録は Shopify(Shopify Inc.)から当社が取得し、料金は Shopify の課金を通じてお支払いいただきます。Google/Apple でログインした場合は、各社からメールアドレスと表示名を取得します。
9. 保有期間と削除
・診断の回答と利用状況の記録:記録から400日を経過したものを、毎日自動で削除します
・通信の記録:ホスティング事業者のログに最長30日間保存され、その後自動で消去されます
・Shopify のアクセストークン:アプリのアンインストール時に直ちに削除します
・ご契約の終了後:解約された場合、または Shopify アプリのアンインストール後にお支払い済みの期間が終了した場合は、その90日後に、商品情報(商品画像を含む)、診断の内容と表示設定、回答、利用状況の記録を削除します。お支払いがなく利用停止となった場合は、停止から90日後の契約終了のご通知から30日後に削除します。お支払い済みの期間のない場合(ローンチパートナー等)は、info@burst-tech.com へのご依頼により削除します
・Shopify からストアのデータ削除の要求(shop/redact)を受けた場合は、認証情報を削除します。その他の情報は、上記の期間に従い、またはご依頼により削除します
・適格請求書とその明細:法令に基づき7年間保存します
・ログイン用アカウント、会社情報・ロゴ、ストアの登録記録、契約・請求の記録、同意の記録:上記の削除の対象外とし、請求および法令への対応に必要な期間保存します。ご依頼により、法令上の保存義務のないものを削除します
・通信の記録:ホスティング事業者のログに最長30日間保存され、その後自動で消去されます
・Shopify のアクセストークン:アプリのアンインストール時に直ちに削除します
・ご契約の終了後:解約された場合、または Shopify アプリのアンインストール後にお支払い済みの期間が終了した場合は、その90日後に、商品情報(商品画像を含む)、診断の内容と表示設定、回答、利用状況の記録を削除します。お支払いがなく利用停止となった場合は、停止から90日後の契約終了のご通知から30日後に削除します。お支払い済みの期間のない場合(ローンチパートナー等)は、info@burst-tech.com へのご依頼により削除します
・Shopify からストアのデータ削除の要求(shop/redact)を受けた場合は、認証情報を削除します。その他の情報は、上記の期間に従い、またはご依頼により削除します
・適格請求書とその明細:法令に基づき7年間保存します
・ログイン用アカウント、会社情報・ロゴ、ストアの登録記録、契約・請求の記録、同意の記録:上記の削除の対象外とし、請求および法令への対応に必要な期間保存します。ご依頼により、法令上の保存義務のないものを削除します
10. エンドユーザーからの開示・削除のご請求
Shopify ストアで購入したエンドユーザーからのご請求は、Shopify を通じて当社に届きます(customers/data_request、customers/redact)。当社は、ご請求の対象となった注文の情報(訪問時の URL、金額、日時等)を Shopify から読み取って当該エンドユーザーの診断セッションを特定し、開示のご請求には記録の内容を注文番号とともにストアのメールアドレス宛てにお送りし、削除のご請求には該当する回答と利用状況の記録を削除します。読み取った注文の情報は保存しません。ご請求の処理の記録として、Shopify の顧客 ID がホスティング事業者のログに残ります。診断を利用したものの購入していない場合、当社はエンドユーザーを特定できる情報を保有していないため、記録を特定できません。
11. 安全管理措置
Shopify のアクセストークンは AES-256-GCM で暗号化して保管します。通信は暗号化(HTTPS)し、データベースおよび社内の管理画面へのアクセスは当社の担当者に限定し、アクセス権限を管理します。その他、漏えい・滅失・毀損の防止のため、組織的・人的・物理的・技術的措置を講じます。
12. お問い合わせ窓口
本ポリシーに関するお問い合わせ、ならびに利用者からの開示・訂正・削除・利用停止等のご請求は info@burst-tech.com で承ります。ご本人またはストアの確認をさせていただく場合があります。手数料はいただきません。
Privacy Policy (English)
Burst Inc. ("we") handles information in Rekotto, a product-finder quiz service (the dashboard, the Shopify app and the quiz placed on a store, together "the Service"), as described below and in accordance with Japan's Act on the Protection of Personal Information. A business that installs the Service is a "merchant"; a person who takes a quiz is a "shopper". The Japanese text governs if the two versions differ.
1. Operator
Burst Inc. (Burst株式会社)
Wizard Bldg. 402, 1-4-3 Sengencho, Nishi-ku, Yokohama, Kanagawa 220-0072, Japan
Representative Director: Ryuji Hisano
Wizard Bldg. 402, 1-4-3 Sengencho, Nishi-ku, Yokohama, Kanagawa 220-0072, Japan
Representative Director: Ryuji Hisano
2. Information about merchants
· Shopify store: store domain, store name, the access token Shopify issues (stored encrypted), granted scopes, install and uninstall dates
· Products: title, price, currency, images, product page URL, tags, product type, vendor and availability. We do not read product descriptions or inventory counts
· Company details the merchant saves: legal name, address, phone, contact name, contact email and logo. Store name, address and email from Shopify only pre-fill the form and are not recorded until the merchant saves
· Plan and billing: plan, status, period, Shopify or Stripe charge and payment IDs, pack purchases and the qualified invoices we issue. We do not hold card details
· Records of agreement and actions: the email of whoever agrees to the Terms, buys a pack or authorises automatic packs (for Terms agreed in the Shopify app, the store's email)
· For direct dashboard use: login email, display name, and a password (stored hashed) or a Google/Apple account identifier, and last login time. The dashboard uses cookies to keep you signed in and to prevent abuse
· Contact names, contact details and correspondence records from enquiries and sales conversations
· Products: title, price, currency, images, product page URL, tags, product type, vendor and availability. We do not read product descriptions or inventory counts
· Company details the merchant saves: legal name, address, phone, contact name, contact email and logo. Store name, address and email from Shopify only pre-fill the form and are not recorded until the merchant saves
· Plan and billing: plan, status, period, Shopify or Stripe charge and payment IDs, pack purchases and the qualified invoices we issue. We do not hold card details
· Records of agreement and actions: the email of whoever agrees to the Terms, buys a pack or authorises automatic packs (for Terms agreed in the Shopify app, the store's email)
· For direct dashboard use: login email, display name, and a password (stored hashed) or a Google/Apple account identifier, and last login time. The dashboard uses cookies to keep you signed in and to prevent abuse
· Contact names, contact details and correspondence records from enquiries and sales conversations
3. Information about shoppers
· Quiz answers: the options or slider values chosen and the results shown. There are no free-text fields; we do not collect names, emails or phone numbers
· Quiz usage: question views, quiz start and completion, option selections, result views and product clicks, each tied to a random ID created fresh on every page load (session ID). The quiz page sets no cookies. Product images load in the shopper's browser directly from Shopify or the merchant's image host
· Purchases (Shopify app only): through the Web Pixel in section 5, for sessions that were shown a quiz result, we record the order value, currency and date (to the day). We do not record order numbers, customer IDs, names, emails or addresses
· Request logs: to prevent abuse and investigate faults, our servers record the requesting IP address, the URL requested and the time in the hosting provider's logs. IP addresses are not stored in our database
· Quiz usage: question views, quiz start and completion, option selections, result views and product clicks, each tied to a random ID created fresh on every page load (session ID). The quiz page sets no cookies. Product images load in the shopper's browser directly from Shopify or the merchant's image host
· Purchases (Shopify app only): through the Web Pixel in section 5, for sessions that were shown a quiz result, we record the order value, currency and date (to the day). We do not record order numbers, customer IDs, names, emails or addresses
· Request logs: to prevent abuse and investigate faults, our servers record the requesting IP address, the URL requested and the time in the hosting provider's logs. IP addresses are not stored in our database
4. Inference from answers (age and gender tendency)
Where a merchant tags answer options with an age or gender tendency, we aggregate answers into an estimated age and gender mix shown in the merchant's report. The estimate is computed as an aggregate when the report is viewed; no per-shopper estimate is stored. Groups of fewer than 20 sessions are not shown. The estimate is indicative only and does not state any shopper's actual age or gender.
5. Web Pixel and browser storage (Shopify app)
The Shopify app adds a Web Pixel to the store. It detects page views and completed checkouts, and runs only when analytics and marketing are both permitted in Shopify's privacy settings (depending on the store's regional settings, this may be permitted without a consent banner). It saves the session ID from the URL the shopper reached from the quiz in the browser (localStorage); when a checkout completes it sends the session ID, order value and currency to us and deletes the saved ID. An ID saved more than 30 days earlier is not sent. If permission is withdrawn, the saved ID is deleted the next time a store page is open.
6. Purposes
Providing the Service (showing quizzes, matching products, building reports), syncing products with the Shopify store, billing and issuing qualified invoices, notices such as changes to the Terms, answering enquiries, sales and customer management, preventing abuse, investigating faults, and maintaining and improving the Service. We do not use one merchant's information for another merchant's quizzes or reports. We may, however, create, use or publish statistics that identify no individual and no merchant (Rekotto Terms, Article 8).
7. Disclosure to third parties
Shopper information is provided only to the merchant whose store ran the quiz, as reports and similar. Except as required by law, we do not provide it to any other third party without consent.
8. Service providers and transfers outside Japan
We use the following providers, under appropriate supervision, as needed for the purposes above:
· Database: Supabase (Tokyo, Japan region)
· Hosting: Vercel (processing in the Tokyo, Japan region, including request logs)
· Email: Resend (United States), for invoices and notices to merchants, email verification and password reset, and the reports in section 10
· Payments: Stripe (United States), for fees paid by merchants using the dashboard directly; the merchant's email is sent to it
As Resend and Stripe are in the United States, information sent to them is provided to third parties outside Japan. For the United States' data protection regime, see the information published by Japan's Personal Information Protection Commission. Appropriate safeguards are required by contract.
For the Shopify app, store, product and billing information comes to us from Shopify (Shopify Inc.), and fees are paid through Shopify's billing. Signing in with Google or Apple gives us the email and display name from that provider.
· Database: Supabase (Tokyo, Japan region)
· Hosting: Vercel (processing in the Tokyo, Japan region, including request logs)
· Email: Resend (United States), for invoices and notices to merchants, email verification and password reset, and the reports in section 10
· Payments: Stripe (United States), for fees paid by merchants using the dashboard directly; the merchant's email is sent to it
As Resend and Stripe are in the United States, information sent to them is provided to third parties outside Japan. For the United States' data protection regime, see the information published by Japan's Personal Information Protection Commission. Appropriate safeguards are required by contract.
For the Shopify app, store, product and billing information comes to us from Shopify (Shopify Inc.), and fees are paid through Shopify's billing. Signing in with Google or Apple gives us the email and display name from that provider.
9. Retention and deletion
· Quiz answers and usage records: deleted automatically, daily, once 400 days old
· Request logs: kept in the hosting provider's logs for up to 30 days, then erased automatically
· Shopify access token: deleted as soon as the app is uninstalled
· After the contract ends: 90 days after a cancellation, or after the paid period ends following an uninstall of the Shopify app, we delete products (including images), quiz content and appearance settings, answers and usage records. Where a store is suspended for non-payment, deletion follows 30 days after the notice of termination, which comes 90 days after suspension. Where there is no paid period (such as launch partners), we delete on request to info@burst-tech.com
· On Shopify's shop data erasure request (shop/redact), we delete credentials. Other information is deleted on the schedule above or on request
· Qualified invoices and their lines: kept 7 years, as required by law
· Login accounts, company details and logo, the store's registration record, plan and billing records, and records of agreement: not covered by the deletions above; kept as long as needed for billing and legal obligations. On request we delete those not required by law
· Request logs: kept in the hosting provider's logs for up to 30 days, then erased automatically
· Shopify access token: deleted as soon as the app is uninstalled
· After the contract ends: 90 days after a cancellation, or after the paid period ends following an uninstall of the Shopify app, we delete products (including images), quiz content and appearance settings, answers and usage records. Where a store is suspended for non-payment, deletion follows 30 days after the notice of termination, which comes 90 days after suspension. Where there is no paid period (such as launch partners), we delete on request to info@burst-tech.com
· On Shopify's shop data erasure request (shop/redact), we delete credentials. Other information is deleted on the schedule above or on request
· Qualified invoices and their lines: kept 7 years, as required by law
· Login accounts, company details and logo, the store's registration record, plan and billing records, and records of agreement: not covered by the deletions above; kept as long as needed for billing and legal obligations. On request we delete those not required by law
10. Shopper access and deletion requests
Requests from shoppers who bought from a Shopify store reach us through Shopify (customers/data_request, customers/redact). We read the orders named in the request from Shopify (visit URLs, amount, time and similar) to identify the shopper's quiz sessions; for an access request we email the records, with the order numbers, to the store's email address, and for an erasure request we delete the matching answers and usage records. The order information we read is not stored. As a record of handling the request, the Shopify customer ID remains in the hosting provider's logs. If a shopper took a quiz but did not buy, we hold nothing that identifies them and cannot locate their records.
11. Security
Shopify access tokens are encrypted with AES-256-GCM. Traffic is encrypted (HTTPS), access to the database and our internal console is limited to our staff and access rights are managed. We take organisational, personnel, physical and technical measures against leakage, loss and damage.
12. Contact
Questions about this policy, and merchants' requests for access, correction, deletion or suspension of use: info@burst-tech.com. We may verify identity or store ownership. No fee is charged.
制定日:2026-09-28 最終更新日:2026-09-28
当社のお問い合わせフォームで取得する個人情報の取扱いは プライバシーポリシー、ご利用条件は レコット利用規約 をご覧ください。