OrderPatch
Data Protection Terms
Current policy information · Version 2026-09-21
Operator: DDANZG
Address: 東京都杉並区今川2丁目14-21 コスモハイツ201
Privacy/security contact: ddanzg@gmail.com
Parties, status and instructions
These data protection terms are between the merchant using OrderPatch and DDANZG, 東京都杉並区今川2丁目14-21 コスモハイツ201. Privacy and security inquiries: ddanzg@gmail.com. Processing is limited to documented merchant/customer instructions for order editing, authentication, security and privacy support. The service lasts while the app is installed, followed only by an approved limited deletion/backup period. Merchant agreement acceptance must be recorded through an appropriate contractual process; no signature or acceptance is inferred merely from visiting this page.
Scope and responsibilities
Data subjects are the merchant's customers and authorized merchant/staff users. Data categories and purposes are described in the Privacy Policy. The merchant supplies appropriate customer notices, determines the lawful basis and authorizes staff access and order changes. DDANZG will process data only for those instructions, restrict operator access to authorized people, maintain confidentiality obligations and assist the merchant with privacy requests. Merchant and operator agreement acceptance should be retained with the applicable merchant record.
Service providers and international processing
Fly.io provides application hosting, storage and infrastructure diagnostics; Shopify provides the commerce platform and its APIs. The merchant authorizes use of the necessary providers when these terms are agreed. DDANZG must maintain records of appropriate provider contracts, subprocessors and any legally required international transfer mechanism. These terms do not claim a specific transfer clause or certification. Material provider changes must be communicated through the agreed merchant contact channel.
Security, incidents and assistance
DDANZG will maintain documented safeguards, review access and respond to suspected security incidents. Confirmed or reasonably suspected exposure of merchant data must be escalated without undue delay under the incident procedure, with notice to affected merchants and Shopify through verified channels. Any statutory timing must be assessed for the incident and jurisdiction; these terms do not replace that assessment. Notices should describe known impact, containment and next updates without exposing other merchants' information.
Return, deletion and accountability
The retention schedule and its implementation status are described in the linked retention policy. Privacy requests must be tracked to actual delivery or a documented valid exception; webhook receipt is not closure. Termination/redaction covers application records and must also account for limited-lived backups and restore procedures. Legally required preservation, if any, must be specific, access-restricted and reviewed, not an unlimited exception. DDANZG should retain evidence of controls and agreed terms and make appropriate evidence available to the merchant on a verified request.