プライバシーポリシー

Privacy Policy

最終更新日:

Last updated:

本ポリシーは、ブランドone-coin.appのウェブサイト、アカウント、および提供する各アプリ(Web・デスクトップ等)に共通して適用されます。アプリ固有の扱いがある場合は、各アプリのページでも案内します。内容は必要に応じて見直し、重要な変更はサイト上でお知らせします。本ポリシーおよび関連文書は日本語版を正とします。英語その他の言語の表示は参考訳です。

1. 事業者

事業者名:北海道オンライン 清水嘉一(屋号「北海道オンライン」)。所在地・電話番号は運営者情報(特定商取引法に基づく表記)に記載します。個人情報に関するお問い合わせ・開示等のご請求、およびセキュリティ上の問題の報告はサポートのお問い合わせフォームからお願いします(人による返信は support@one-coin.app 等で行うことがあります。セキュリティ報告の場合は、件名等にその旨を記載してください)。

2. 収集する情報

利用状況に応じて、次の情報を取得することがあります。

  • アカウント情報:Google ログインに伴う識別子(Googlesub)、メールアドレス、表示名、プロフィール画像 URL など、認証に必要な範囲
  • 課金関連情報:プラン・契約状態、顧客 ID、決済イベントのメタデータなど。カード番号などの決済手段の詳細は決済事業者(Stripe)が保持し、運営者は原則として保持しません
  • デバイス連携情報:デスクトップアプリと Web アカウントを紐づけるためのワンタイムコード、端末トークン、確認日時など
  • サポート情報:問い合わせフォームやメールで送られた氏名・連絡先・内容・添付ファイル、対象アプリ名・バージョンなど。フォーム送信時はボット対策のため Cloudflare Turnstile の検証トークンも処理します
  • 電話・録音:特商法・サポート用の 050 番号への着信に伴う通話関連情報(発信者番号、通話イベント、用件の録音データ)。録音は折り返し対応のために取得し、通知メール等で担当者へ伝えます
  • メール配信の同意情報:コインくんメルマガの配信可否(有料契約開始時に配信対象となり、メール内の配信停止リンクで停止した状態を含みます)。オンボーディング等の使い方メールの配信停止状態
  • 更新確認に伴う技術情報:デスクトップアプリが更新の有無を確認する際に送受信し得るアプリ名・バージョン・OS 等の技術情報(撮影画像や端末内の文書内容は含みません)
  • 利用・運用ログ:アクセス日時、IP、User-Agent、エラー情報、セキュリティ調査に必要なイベントなど(画像や文書の中身、認証トークン、カード情報は通常ログに残しません)

3. デスクトップ/端末内データ

各アプリが端末上で扱うデータ(例: 撮影・録画画像、ホットキーに割り当てた定型文、メモ、設定ファイル)は、原則として利用者の端末内にあります。運営者は、利用者の明示的な操作なく、その内容を外部へ送信しません。クラウド同期や共有機能を追加する場合は、送信前の確認、保存期間、削除方法をアプリ側で明示します。

4. 利用目的

  • サービスの提供、認証、セッション管理、デバイス連携
  • 有料機能の課金・自動更新の停止・領収関連の処理
  • 不具合対応、サポート(フォーム・メール・電話の折り返し)、セキュリティ監視
  • サービス運営に必要なトランザクションメール(課金・セキュリティ・重要なお知らせ等)の送信
  • 利用ユーザー(有料契約の有効期間が開始した利用者)へのコインくんメルマガの配信。配信停止は各メール内の配信停止リンクからのみ行えます(有料契約の終了だけでは自動停止しません)
  • Google アカウントの新規登録時に開始する使い方メール(オンボーディング)の配信。停止は各メール内のリンクから行えます(コインくんメルマガとは別)
  • デスクトップアプリの更新確認および更新配信
  • サービス改善のための集計・分析(個人を特定しない形を優先)
  • 利用規約違反への対応、法令に基づく対応

メールの開封・クリック等の計測は、現状行いません。将来実施する場合は、本ポリシーを更新したうえで案内します。

5. 第三者提供・委託

運営者は、次の場合を除き、個人情報を第三者に販売・貸与しません。サービス提供のために次の事業者を利用します(各社のプライバシー方針が適用されます)。

  • Google: ログイン認証。人によるサポート返信には Google Workspace を用いることがあります
  • Stripe: 決済・顧客ポータル
  • Cloudflare: ホスティング、CDN、ボット対策(Turnstile)、データベース(D1)、オブジェクトストレージ(R2)等
  • Resend: トランザクションメール・メルマガ配信
  • Vonage: 050 番号、IVR、用件録音

法令に基づく開示請求、人命・財産の保護のために必要な場合など、正当な理由があるときは開示することがあります。

6. 国外での取扱い

上記「5. 第三者提供・委託」に掲げる事業者の一部は、日本国外(主に米国その他の国・地域)に所在し、または国外のサーバ・ネットワーク上で個人情報を取り扱うことがあります。本サービスの性質上、認証・決済・ホスティング・メール・電話の各処理において、国外での取扱いが発生し得ます。

運営者は、これらの事業者への委託等にあたり、各社の契約上の保護措置およびプライバシー方針を確認し、個人情報保護法その他の法令で求められる範囲で適切に取り扱います。取扱いの詳細は各社の方針をご確認ください(GoogleStripeCloudflareResendVonage)。事業者が所在する国における個人情報の保護に関する制度については、個人情報保護委員会が公表する情報(例:米国)もご参照ください。

7. 保存期間

次を目安とします(法令・紛争対応で必要な記録は、必要な期間延長することがあります)。

  • アカウント・セッション・デバイス連携:利用継続中は保持。有料契約の終了後もアカウントが残る場合があります。アカウント削除または個人データの削除のご請求後、業務上・法令上必要な記録を除き、原則 30 日以内に削除または匿名化します
  • 課金・契約記録:会計・税法上等で求められる期間(目安として最大約 7 年)保持することがあります
  • サポート問い合わせ・添付:対応および再発防止のため、目安として最大 1 年保持したうえで削除または匿名化します
  • 通話録音・発信者番号:折り返し対応に必要な期間(目安として最大 90 日)。Vonage 側の保持期間は同社の仕様に従います
  • 運用ログ:セキュリティ調査のため、目安として最大 180 日保持したうえで削除または匿名化します(運用コスト等により見直すことがあります)

8. 安全管理

アクセス制御、通信の暗号化(HTTPS)、秘密情報の環境分離、入力検証、レート制限など、合理的な安全管理措置を講じます。詳細方針は社内のセキュリティ方針に従います。

9. 利用者の選択

  • ログイン状態の確認・ログアウト(Web のログイン関連画面。アカウント詳細の自己編集画面は順次整備します)
  • 課金の確認・自動更新の停止(各アプリの料金ページおよび Stripe 顧客ポータル)
  • コインくんメルマガの配信停止(各メルマガ内の配信停止リンクのみ)。ログイン画面やサポートフォームからは停止できません。課金・セキュリティ・重要なお知らせ等のトランザクションメール、およびオンボーディングの使い方メールは、メルマガの配信停止の対象外です
  • アカウント情報または個人データの削除のご請求(サポートのお問い合わせフォーム)。有料契約の有効期間が終了しただけではアカウントは自動削除されません。開示・訂正・利用停止等は次項によります

10. 開示・訂正・利用停止等のご請求

運営者は、個人情報保護法その他の法令に基づき、ご本人から保有個人データの開示、訂正、追加、削除、利用停止、消去、第三者提供の停止、第三者提供記録の開示等を求められたときは、法令で定められた範囲内で、合理的な期間内に対応します。

  • 請求方法:サポートのお問い合わせフォームから、「個人情報に関するご請求」である旨、請求の種類、対象となる情報の特定に必要な事項を記載してご連絡ください。人による返信は support@one-coin.app 等で行うことがあります
  • 本人確認:ご請求がご本人または正当な代理人によるものであることを確認するため、登録メールアドレスとの照合や、追加の確認へのご協力をお願いすることがあります。代理人の場合は、代理権を示す資料の提出をお願いすることがあります
  • 手数料:原則として無料です。開示等に著しく費用を要する場合は、法令の範囲で実費相当額をご負担いただくことがあり、その場合は事前にお知らせします
  • 応じられない場合:法令に定める事由に該当する場合など、ご請求の全部または一部に応じられないときは、その旨と理由をお知らせします

11. Cookie・ローカル保存等

次の目的で Cookie や類似技術を使用します。

  • セッション: ログイン状態の維持(必須に近い)
  • セキュリティ:Cloudflare Turnstile 等のボット対策(サポートフォーム等)
  • サイトの安定運用: 配信・障害調査に必要な範囲

表示言語の選択、利用規約等への同意バージョン、デバイス連携に関する状態などは、ブラウザまたはアプリの localStorage/端末内ストレージに保存することがあります。必須でない追跡広告 Cookie を主目的としては使いません。

12. 子どもの利用

当サービスは、一般の業務・個人利用を想定しています。16 歳未満の方から、保護者の同意なく意図的に個人情報を収集しません。該当する場合はサポートまでご連絡ください。

13. 要配慮個人情報

運営者は、要配慮個人情報(病歴、障がい、信条等、個人情報保護法に定めるもの)を、サービス提供の目的で意図的に取得しません。利用者がサポート等で任意に記載した場合は、当該対応に必要な範囲でのみ取り扱います。

14. 漏えい等への対応

個人データの漏えい、滅失、毀損その他の事態が発生し、または発生したおそれがある場合、運営者は個人情報保護法その他の法令に従い、必要に応じてご本人への通知、個人情報保護委員会への報告その他の措置を講じます。

15. 改定

本ポリシーを変更する場合は、本ページを更新します。重要な変更は、可能な範囲でサイト上または登録メールでお知らせします。

16. 関連

This policy applies to theone-coin.appwebsite, accounts, and apps (web, desktop, and similar). App-specific practices, if any, are also described on each app’s pages. We may update this policy and will announce material changes on the site.The Japanese version is authoritative.English and other languages are for reference only.

1. Operator

Operator:Hokkaido Online / Yoshikazu Shimizu(trade name “Hokkaido Online”). Address and phone number are listed in theoperator info (Specified Commercial Transactions Act notice). For privacy inquiries, access/correction/deletion requests, and security reports, use thesupport form(human replies may be sent from addresses such as support@one-coin.app; for security reports, please indicate that in the subject or message).

2. Information we collect

Depending on how you use the Service, we may collect the following.

  • Account information:identifiers from Google sign-in (Googlesub), email address, display name, profile image URL, and other data needed for authentication
  • Billing information:plan and contract status, customer IDs, and payment-event metadata. Payment-method details such as card numbers are held by the payment provider (Stripe); the operator generally does not store them
  • Device-linking information:one-time codes, device tokens, and confirmation timestamps used to link a desktop app to a web account
  • Support information:name, contact details, message content, attachments, and app name/version sent via the form or email. Form submissions also process a Cloudflare Turnstile token for bot protection
  • Phone / recordings:call-related data for the 050 support number (caller number, call events, and voice messages recorded for callback). Recordings are used for follow-up and may be shared with staff via notification email
  • Email subscription status:whether the Coin-kun newsletter is on (delivery starts when a paid contract begins; includes the stopped state after using the unsubscribe link in email). Stop status for onboarding / how-to email
  • Update-check technical information:technical data such as app name, version, and OS that a desktop app may send or receive when checking for updates (does not include capture images or on-device document contents)
  • Usage and operations logs:access time, IP address, User-Agent, errors, and events needed for security investigations (we do not normally log image or document contents, auth tokens, or card data)

3. Desktop / on-device data

Data each app handles on the device (for example captures, recordings, hotkey snippets, notes, or settings files) stays on the user’s device by default. The operator does not send that content off-device without an explicit user action. If we add cloud sync or sharing, the app will state confirmation before sending, retention, and how to delete.

4. Purposes of use

  • Providing the Service, authentication, session management, and device linking
  • Billing, stopping auto-renewal, and receipts for paid features
  • Bug handling, support (form, email, phone callback), and security monitoring
  • Sending transactional email needed to operate the Service (billing, security, and other important notices)
  • Sending the Coin-kun newsletter to Account Users (users whose paid-contract term has started). Unsubscribing is only via the unsubscribe link in each newsletter message (ending a paid contract does not by itself stop the newsletter)
  • How-to / onboarding email that starts when a Google account is newly registered. You can stop it from the link in each message (separate from the Coin-kun newsletter)
  • Desktop app update checks and update delivery
  • Aggregated analysis to improve the Service (preferring non-identifying forms)
  • Responding to terms violations and legal requirements

We do not currently measure email opens or clicks. If we do so in the future, we will update this policy and announce it.

5. Third parties and processors

The operator does not sell or rent personal information except as described here. We use the following providers to run the Service (each provider’s privacy policy also applies).

  • Google: sign-in; human support replies may use Google Workspace
  • Stripe: payments and customer portal
  • Cloudflare: hosting, CDN, bot protection (Turnstile), database (D1), object storage (R2), and related services
  • Resend: transactional email and newsletters
  • Vonage: 050 number, IVR, and voice recordings

We may disclose information when required by law, or when reasonably necessary to protect life or property.

6. Handling outside Japan

Some of the providers listed in section 5 are located outside Japan (mainly in the United States and other countries or regions), or may process personal information on servers or networks outside Japan. Given the nature of the Service, processing for authentication, payments, hosting, email, and phone may involve handling outside Japan.

When entrusting or otherwise providing information to these providers, the operator reviews each provider’s contractual safeguards and privacy policy, and handles personal information as required by the Act on the Protection of Personal Information and other applicable laws. For details of each provider’s practices, see their policies (Google,Stripe,Cloudflare,Resend,Vonage). For information on personal-data protection regimes in the countries where providers are located, see materials published by Japan’s Personal Information Protection Commission (for example, theUnited States).

7. Retention

We use the following as a guide (records needed for law or disputes may be kept longer).

  • Accounts, sessions, device linking:kept while you use the Service; an account may remain after a paid contract ends. After an account-deletion or personal-data deletion request, we delete or anonymize within about 30 days, except records we must keep
  • Billing / contract records:may be kept for periods required by accounting or tax rules (about up to 7 years as a guide)
  • Support messages / attachments:kept up to about 1 year for handling and prevention, then deleted or anonymized
  • Call recordings / caller numbers:kept for the period needed for callback (about up to 90 days). Vonage retention also follows Vonage’s terms
  • Operations logs:kept up to about 180 days for security investigations, then deleted or anonymized (may be revised with operating cost)

8. Security

We take reasonable measures such as access control, HTTPS, isolating secrets, input validation, and rate limiting. Details follow our internal security policy.

9. Your choices

  • Review sign-in state and sign out (web login-related screens; a full self-service account page is being prepared)
  • Review billing or stop auto-renewal (each app’s pricing page and the Stripe customer portal)
  • Unsubscribe from the Coin-kun newsletter (only via the unsubscribe link in each newsletter). You cannot stop it from the sign-in screen or the support form. Transactional email (billing, security, and other important notices) and onboarding how-to email are not covered by newsletter unsubscribe
  • Requests to delete account information or personal data (via thesupport form). Ending a paid contract’s active term does not by itself delete the account. Access, correction, suspension of use, and similar requests follow the next section

10. Requests for disclosure, correction, suspension of use, etc.

When the data subject requests disclosure, correction, addition, deletion, suspension of use, erasure, suspension of third-party provision, or disclosure of records of third-party provision of retained personal data, the operator will respond within a reasonable period and within the scope required by the Act on the Protection of Personal Information and other applicable laws.

  • How to request:Use thesupport form, state that the message is a personal-data request, and include the type of request and enough detail to identify the data concerned. Human replies may be sent from addresses such as support@one-coin.app
  • Identity verification:To confirm the request is from the data subject or a duly authorized agent, we may match the registered email address or ask for further confirmation. Agents may be asked to submit proof of authority
  • Fees:Requests are free in principle. If disclosure or similar handling would incur substantial cost, we may ask you to bear actual expenses within the scope of law, and we will tell you in advance
  • When we cannot comply:If we cannot grant all or part of a request for a reason provided by law, we will inform you of that fact and the reason

11. Cookies and local storage

We use cookies and similar technologies for:

  • Session: keeping you signed in (near-essential)
  • Security:bot protection such as Cloudflare Turnstile (e.g. support form)
  • Stable operation: delivery and incident investigation as needed

Language preference, the version of terms/privacy accepted, and device-linking state may be stored in browser or app localStorage / on-device storage. We do not use non-essential tracking-ad cookies as a primary purpose.

12. Children

The Service is intended for general business and personal use. We do not knowingly collect personal information from personsunder 16without a parent or guardian’s consent. Please contact support if this applies.

13. Sensitive personal information

The operator does not intentionally collect sensitive personal information (as defined under Japanese law, such as medical history, disability, or beliefs) for providing the Service. If a user voluntarily includes such information in support contacts, we handle it only as needed for that response.

14. Data breaches

If a leak, loss, or damage of personal data occurs or is likely to occur, the operator will take measures required by the Act on the Protection of Personal Information and other applicable laws, including notifying affected individuals and reporting to the Personal Information Protection Commission where required.

15. Changes

When we change this policy, we update this page. For material changes, we will notify on the site or by registered email where practical.

16. Related