OrderPatch

Privacy Policy

Current policy information · Version 2026-09-21

Operator: DDANZG
Address: 東京都杉並区今川2丁目14-21 コスモハイツ201
Privacy/security contact: ddanzg@gmail.com

Who handles your data

OrderPatch processes store data to provide order editing. The merchant determines the purpose and lawful basis for processing customer data; DDANZG processes it on the merchant's instructions. Operator: DDANZG, 東京都杉並区今川2丁目14-21 コスモハイツ201. Privacy and security inquiries: ddanzg@gmail.com.

Data and purposes

Order IDs, order names, items, quantities, prices, payment/fulfillment/cancellation status and delivery addresses support displaying and editing orders. Recipient first and last names and postal addresses submitted by customers support shipping-address corrections. Authenticated customer IDs establish order ownership. Product and variant details support product selection. The order-editing flow does not request customer email or phone fields. Shopify compliance webhook payloads can contain email and phone; the app does not copy these fields into its database.

What is stored

Orders and addresses are processed during a request and in the user's browser, and are not copied into an application order database. Changes are saved in Shopify. The session database stores shop identifiers, access/refresh tokens, expiry and scope information, and can hold merchant/staff account metadata such as name, email and user ID through Shopify's session adapter. AuditLog stores the shop, event, outcome, timestamp and keyed hashes of customer/order IDs, not their names or addresses. These hashes are pseudonymous, not anonymous. The data-request tracker stores hashed request/customer/order references and case status/deadlines.

Limited use and recipients

This code uses the data for requested order editing, authentication, security auditing and privacy-request handling. It does not implement advertising, customer profiling, sale of customer data, or model training. Hosting and persistent storage are provided by Fly.io; store APIs and customer account authentication are provided by Shopify. The configured app region is Tokyo (nrt); this is not a guarantee that all provider processing or support access stays in Japan. Applicable cross-border processing terms and provider agreements govern the relevant service relationships.

Retention and deletion

Current production has no scheduled age-based removal of audit rows or manual backups. Authenticated Shopify redaction webhooks remove matching active-database records; they do not individually erase backup snapshots. Proposed limits are 90 days for access audit rows, 90 days after completion for privacy cases, 7 days for manual recovery backups and delivered export working files, and 30 days for diagnostic logs. Fly's current volume snapshot setting is 5 days. A manual backup can remain inside a snapshot for up to a further 5 days. The proposed limits are not yet enforced; they must be approved and verified before being presented as active guarantees. Pending privacy cases remain tracked until resolved and overdue cases must be escalated. Shopify-held orders follow the merchant's separate retention policy.

Security and customer rights

Existing controls include HTTPS, Shopify authentication and webhook signature validation, customer-order ownership checks, HMAC access logs and an encrypted production volume. These controls do not constitute a security certification. Customers should direct access, correction and deletion requests to the merchant from whom they ordered. Merchants can use Shopify's customer privacy request tools. A verified merchant contact and delivery channel must be established by the operator; an HTTP webhook acknowledgement alone does not fulfill a request. No customer data should be sent through public issues or code repositories.