Privacy Policy
This Privacy Policy is established by Pepin (a sole proprietor; “we,” “us,” or the “Company”) to help users use our various services safely. It applies to services we provide, including websites, applications, and any other services we provide (collectively, the “Services”).
Article 1 (Personal Information)
“Personal Information” means information about a living individual as defined under the Act on the Protection of Personal Information of Japan, including information that can identify a specific individual (e.g., name, date of birth, address, phone number, contact details) and “personal identification codes.”
Article 2 (How We Collect Information)
We may ask users for information such as name, date of birth, address, phone number, email address, bank account number, and credit card number when registering or using the Services. We may also collect transaction records and payment-related information that includes personal information from our partners (information providers, advertisers, ad delivery partners, etc.).
Article 3 (Purposes of Use)
We use personal information for the following purposes:
- To provide and operate our services
- To respond to inquiries (including identity verification)
- To send emails about new features, updates, campaigns, and other services we offer
- To contact users as needed for maintenance or important notices
- To ask about service usage, experience, and satisfaction and improve the Services
- To ask users to submit a neutral review of the Services
- To create and publish a case study after obtaining separate prior consent from the user
- To identify and refuse users who violate terms or attempt to use services for improper purposes
- Purposes incidental to the above
Article 4 (Surveys, Review Requests, and Case Studies)
For users who have asked to receive these communications from us, we may send a survey or review request to their registered contact details at an appropriate time after they begin using the Services, taking their actual usage into account.
We do not specify the content or rating of a review, and we do not offer money, discounts, or any other benefit in exchange for posting, editing, or deleting a review.
Users may stop future survey or review requests by following the instructions in the email or contacting us under Article 12. Choosing to stop these requests will not adversely affect the terms on which they may use the Services.
Before publishing a store name, logo, or comments as part of a case study, we will identify the proposed content and publication channels and obtain the user’s separate prior consent. We will not publish this information as a case study without that consent.
Article 5 (Changes to Purposes)
We may change the purposes of use only when reasonably related to the purposes before the change. When we change the purposes, we will notify users or publish the updated purposes in a manner we prescribe.
Article 6 (Provision to Third Parties)
We will not provide personal information to third parties without users’ prior consent, except in the following cases (and where permitted by applicable laws):
- Where necessary to protect life, body, or property and obtaining consent is difficult
- Where necessary for improving public health or promoting the sound growth of children and obtaining consent is difficult
- Where cooperation with governmental bodies is necessary and consent may impede such operations
Article 7 (Cookies and Analytics)
We may use technologies such as cookies, device identifiers, and access logs to provide, maintain, improve the Services, prevent misuse, and understand usage. We may also use third-party analytics tools. In such cases, those third parties may collect user information using cookies or similar technologies.
Details about what is collected, how it is handled, and opt-out methods are governed by each provider’s policies. Users may disable cookies via browser settings; however, some parts of the Services may become unavailable.
Article 8 (Outsourcing / Joint Use)
We may outsource all or part of the handling of personal information to third parties within the scope necessary to achieve the purposes of use. In such cases, we will appropriately supervise contractors.
If we conduct joint use, we will separately publish the items of personal information jointly used, the scope of joint users, purposes of use, and the party responsible for management.
Article 9 (Security Measures and Disclaimer)
We take reasonable and appropriate measures to prevent leakage, loss, or damage of personal information and to manage security. However, even if we take such measures, if leakage occurs due to unauthorized access, failures of communication lines/devices, failures of external services, users’ device environments/settings, third-party misconduct, or other causes beyond our reasonable control, we are not liable to the extent permitted by law.
Where we are liable, we are not liable for indirect, special, incidental, consequential damages or lost profits, to the extent permitted by law.
Article 10 (Retention Period)
We retain personal information for the period necessary to achieve the purposes of use, for periods required by law, or for a period we reasonably deem necessary. When it is no longer needed, we will delete or dispose of it in an appropriate manner.
Article 11 (Special Provisions for Shopify Apps)
This Article applies to information processed through Shopify apps provided by us. If this Article conflicts with another provision of this Policy, this Article prevails to the extent of that conflict for Shopify apps.
By installing and beginning to use any of our Shopify apps, the Merchant agrees to this Policy and these Special Provisions.
1. General Terms for Shopify Apps
- Sources and data minimization: We receive or collect merchant, store, product, variant, order, customer, payment, usage-event, and other data disclosed for each app through Shopify APIs, webhooks, and Web Pixels only when needed to provide the relevant app. We process only the minimum personal data necessary to provide that app’s functionality.
- Purpose limitation and privacy choices: We use the data only for the purposes stated in the app-specific handling table, App Store listing, app admin, or related documentation, and not for unrelated advertising, sale, or other purposes. Where consent applies, we respect customers’ consent and opt-out choices and the Merchant’s privacy settings. Measurement through Web Pixels and similar tools follows consent signals supplied by Shopify.
- Security: Personal data is encrypted at rest and in transit. We also apply reasonable safeguards such as access controls, permission management, and logging. Backups containing personal data receive equivalent protection.
- Service providers: We may engage service providers for cloud hosting, databases, monitoring, email delivery, customer support, and similar functions where necessary. We require appropriate safeguards by contract or other means and supervise their handling of personal data.
- Access, correction, restriction, and deletion requests: Merchants may submit a request through the contact in Article 12. A request from a store customer should generally be made to the relevant Merchant. We reasonably assist the Merchant and respond to Shopify’s mandatory compliance webhooks, including
customers/data_requestandcustomers/redact. - Uninstallation: When an app is uninstalled, we follow Shopify’s required process, including
shop/redact, and generally delete or de-identify Merchant Data and customer personal data associated with that store within 30 days after uninstallation, except where retention is required by law. Data retained under a legal obligation is used only for that purpose and deleted when the retention period ends. - Data protection roles: The Merchant is the controller of customer personal data for its store and is responsible for establishing a lawful basis, providing required notices and consent mechanisms, and responding to customer requests. We are a processor acting on the Merchant’s instructions when processing that data to provide an app. We act as an independent controller for information for which we determine the purposes and means of processing, such as contract administration, billing, support, security, and legal compliance. Different roles apply where required by applicable law or an individual agreement.
2. App-specific Data Handling Table
| App | Data Collected and Processed | Purposes | Retention Period |
|---|---|---|---|
| Marutto Search | Order ID, line item ID, product and variant IDs, amounts, discounts and refunds, currency, order date and time, search terms, clicks, session identifiers, etc. We do not collect or store names, addresses, telephone numbers, email addresses, bank account numbers, or credit card numbers. | Search analytics, measurement of search-attributed revenue, search quality improvement, and improvement recommendations | Search, click, order-attribution, and other measurement data is retained for 90 days. |
Article 12 (Contact)
For inquiries about this Policy, please contact us at:
Address: 8F Wind Ebisu Building, 2-4-8 Ebisu-nishi, Shibuya-ku, Tokyo 150-0021, Japan
Business Name: Pepin (start date: Jan 5, 2026)
Email: support@pepin.studio
Established: December 8, 2025
Revised: July 16, 2026
Revised: July 21, 2026