UreyukiBox Privacy Policy
Last updated: 2026-07-06
Mai Sato ("we") sets out below how we handle the personal information of users of the Shopify app "UreyukiBox" (the "Service") and of their end customers (the customers of the Shopify store).
1. Information we collect
1.1 Information from your Shopify store
The Service retrieves the following through the Shopify Admin API.
- Store details (store name, domain, email address, address, currency setting)
- Product data (product name, SKU, price, stock quantity, per-location inventory levels)
- Order data (order number, order date and time, products, quantities, tax) — used as sales history for demand forecasting
- Supplier data (standard Shopify fields and data migrated from Stocky)
- Store owner details (information provided by Shopify during OAuth)
1.2 Stocky migration data (optional feature)
If you use the Stocky migration wizard, we retrieve the following through the Stocky API.
- Suppliers
- Purchase orders
- Stock adjustments
- Tax types
Your Stocky API key is used only to perform the migration and is not stored on our servers. It is discarded once the migration finishes.
1.3 Information you enter
- Email address for alert notifications
- Slack webhook URL
- LINE user ID (obtained when you link our LINE official account, if you use LINE notifications)
- Business details (contact email address)
1.4 Information collected automatically
- IP address, browser information, timestamps and operation logs while using the Service
- Session information using cookies and similar technologies
- Aggregated data from Cloudflare Web Analytics (in a form that does not identify individuals)
2. How we use it
We use the information we collect for the following purposes.
- Providing, operating and improving the Service
- Persisting your Stocky data in our own database (so it survives Stocky's shutdown)
- Generating and delivering demand forecasts and stock alerts (email / Slack / LINE)
- Responding to your enquiries
- Preventing misuse
- Statistical analysis of how the Service is used (in a form that does not identify individuals)
- Other work necessary to operate the Service
3. Disclosure to third parties
We do not provide your personal information to third parties except in the following cases.
- Where you have consented
- Where required by law
- Where necessary to protect a person's life, body or property
- Where we provide information to subcontractors — cloud providers such as Cloudflare (Pages, DNS), Fly.io (backend API), Resend (email delivery) and Google (Gemini API: suggesting which products respond to seasonal events) — to the extent needed to provide the Service
- Where information passes to a successor in connection with a business transfer
3.1 What we send to the AI (Gemini API)
Only when you actively ask for suggestions on the "Seasonality by product" screen, we send product names, product categories and vendor names (the Shopify vendor field) to Google's Gemini API. We send catalogue information only: no personal information about end customers, no order data, no stock quantities and no prices are sent.
This runs only when you explicitly trigger it, and the suggestions do not affect any order quantity until you approve them. If you do not use the feature, nothing is sent to the Gemini API.
4. Where data is stored
The backend of the Service is hosted on Fly.io in the Tokyo region (nrt). The database is PostgreSQL (Tokyo region) and is stored encrypted.
The frontend and marketing site are served from Cloudflare's global edge network, but persistent storage of user data is limited to the Tokyo region.
5. How long we keep data
- Sales history used for demand forecasting is retained for the past 24 months.
- Stocky migration data (suppliers, purchase orders, stock adjustments, tax types) is retained for as long as you use the Service.
- If you stop using the Service, we provide a CSV export within 30 days of cancellation and then delete the data completely.
- Pre-launch waitlist registrations from the marketing site are deleted 12 months after the launch announcement is sent, or 30 days after you unsubscribe, whichever comes first.
- Where a retention period is prescribed by law, that period applies.
6. Security measures
We take the following measures to prevent leakage, loss or damage of personal information and otherwise manage it securely.
- Encryption at rest and TLS 1.3 encryption in transit
- Least-privilege access control and secure storage of credentials
- Authentication via Shopify App Bridge session tokens (JWT)
- Operation logging and periodic audits
- Ongoing remediation of vulnerabilities
7. Your rights
You may make the following requests regarding your own personal information that we hold.
- Notification of the purpose of use
- Disclosure, correction, addition or deletion of the information
- Suspension of use, erasure, or suspension of provision to third parties
Send requests to [email protected]. We will verify your identity and respond within a reasonable period.
You can stop waitlist emails immediately using the "unsubscribe" link at the end of each message. We also handle unsubscribe requests sent through our contact form.
8. Cookies
The Service uses cookies for authentication, session management and usage analysis. You can disable cookies in your browser, but some features of the Service may then stop working.
9. Contact
Please direct enquiries about this policy to:
Mai Sato (trading as Mumu Labo)
Email: [email protected]
Address: MIEUX Shibuya Building 8F, 5-3 Maruyamacho, Shibuya-ku, Tokyo 150-0044, Japan
10. Changes to this policy
We may revise this policy in response to changes in law or to the Service. If a change is significant, we will notify you within the Service or by email.
Mai Sato
Established: 2026-07-06