App features
- Reduced tax rate対応
- Easy to install at $4.99/month
- Of course, supports Japanese
- Simple, no unnecessary features
- Easy to set up because there are no extra features
- Clean format supervised by a designer
※Note
Supports "new customer accounts".
Partially supports "legacy customer accounts". (Themes "Dawn/Rise/Studio" are already supported)
Inquiries about our introduction often include questions regarding security and the handling of personal information. Given that our receipt app handles personal information such as order details, customer names, and addresses, your concerns are completely understandable.
This article will clarify how SAKU Simple Receipt is designed to handle data, based on actual inquiries we've received.
To state our conclusion first, this app does not store customers' personal information on our company's servers, and receipt viewing is restricted to the individual user.
Designed not to store personal information on our company's servers
Most importantly, SAKU Simple Receipt does not save or accumulate order information or customers' personal information in our app's database.
When generating and displaying receipts, necessary data is retrieved from Shopify as needed and processed, but the data used for processing is not retained on our servers. This means that we do not "possess" or "store" personal information on our side.
As a result, customer personal information is centralized on Shopify's infrastructure. By operating on the Shopify platform, which meets global security standards, the risk of data leakage is significantly reduced compared to if we were to handle data independently.
Only the "individual" can view their receipts
We often receive questions such as, "What if someone manipulates another person's order number or URL and can see another customer's receipt?" SAKU Simple Receipt has two mechanisms to prevent this.
For displaying receipts from the order page (My Page), even if the URL is modified, viewing is controlled so that it cannot be accessed unless logged in with the account that owns the order. Since it is tied to the login status, a third party cannot view another person's receipt.
For receipts embedded in email notifications, since email by nature cannot assume a login, we have a system where the receipt is displayed only when the order ID and confirmation_number match. Unless both of these are present, a third party cannot access the receipt.
For more details on email embedding settings, please refer to this article.
https://saku-apps.com/blogs/receipt/mail-setting
About the permissions (scopes) requested by the app
SAKU Simple Receipt limits its permissions to only what is necessary for generating and displaying receipts.
The basic permissions are primarily read access. Write permissions are used only for the following two purposes:
- write_files for uploading and displaying company logos
- write_app_proxy for providing a location to display receipts
It is important to note that the app does not have write permissions for customer information or orders themselves. The app will not rewrite order or customer data, so please rest assured.
The scopes actually obtained are as follows:
| read_all_orders, read_customers, read_files, read_orders, write_app_proxy, write_files, read_draft_orders, read_locales |
Has passed Shopify App Store review
SAKU Simple Receipt has been published after passing the Shopify App Store review process. This means that it has been checked by Shopify against their security and privacy requirements. This serves as proof that the app's permissions and data handling comply with Shopify's third-party standards.
Regarding third-party certifications such as PrivacyMark and ISMS
We have not currently obtained third-party certifications such as PrivacyMark or ISMS.
This is due to operating as a small business, but more fundamentally, it is because we have adopted a design that does not hold or store personal information in our own environment, as explained above. This decision was made considering the operational costs associated with obtaining certification and the location of design-related risks.
If your internal security review requires confirmation of such certifications, we hope that the data handling structure explained in this article can serve as a basis for your assessment.
Privacy Policy
Please refer to our privacy policy below.
https://saku-apps.com/policies/privacy-policy
If you have any questions
If you need additional confirmation for security checks or internal reviews before implementation, please feel free to contact us. We will provide as much information as possible to assist your company's review and consideration.
Contact us here.
https://saku-apps.com/pages/contact