Stopita

Privacy Policy

How Stopita handles store information and buyer data.

Last updated: August 26, 2026

1. Operator

コマース編集室(運営者:八木 俊輔)

2. Information we handle

  • Store domain, app authentication information, and information included in administrator sessions.
  • Information about products, variants, collections, and tags configured as lock targets.
  • Inventory-reservation sessions, cart identifiers, customer IDs, quantities, expiration times, statuses, and Draft Order and order identifiers.
  • Hashed IP addresses used to deter misuse, and records of errors, operations, and webhook processing.
  • Matching IDs and processing status for privacy requests received from Shopify.
  • The language code (ja or en) when a buyer selects Stopita's display language. It is stored as stopitaBuyerLocale in browser localStorage and a URL parameter of the same name. The URL selection also works when browser storage is unavailable. It does not change the store-wide language or cart identifier.
  • The language code when an administrator selects a display language. It is stored in the browser's stopita_admin_locale cookie and shop-specific stopitaAdminLocale localStorage, and an explicit selection through the stopitaLocale URL parameter is used for that display.

In the buyer's browser, we use sessionStorage to retain the inventory-reservation state and raw token in the same tab. We do not use them for advertising, behavioral analytics, or cross-site tracking.

We do not collect payment information such as credit-card numbers; payment is processed through Shopify checkout.

The inventory-reservation feature does not request or store a buyer's name, address, email address, or telephone number.

3. Purposes of use

  • Authenticate store administrators and provide inventory-lock settings.
  • Temporarily reserve inventory immediately before checkout, create Draft Orders, and release expired reservations.
  • Record completed payments, recover from failures, and prevent duplicate processing and misuse.
  • Respond to inquiries and legal or Shopify privacy requests.
  • Maintain service security and availability.

We do not use collected information for advertising or sell personal data.

4. Retention periods

  • Inventory locks and processed webhooks that are completed, expired, released, or failed: generally 30 days.
  • Expired online administrator sessions: generally 7 days.
  • Operational logs not tied to a session: generally 90 days.
  • Incomplete inventory locks, unprocessed webhooks, and offline authentication information required to operate the app: until processing is complete or the contract ends.

We may retain information longer where necessary for legal retention duties, disaster-recovery backups, or unresolved processing.

5. Service providers and international processing

This service uses Shopify's API and checkout features, and Railway's hosting and database infrastructure. Information may be processed or stored in infrastructure outside Japan.

6. Access, correction, deletion, and restriction

We respond to required privacy webhooks received from Shopify. Buyers should contact the store where they made their purchase; store administrators should contact us below. After verifying identity and matching the relevant data, we respond to requests for access, correction, deletion, or restriction in accordance with applicable law and Shopify procedures.

7. Contact

Operator: コマース編集室(運営者:八木 俊輔)

Email: contact@marketer-room.com