UreyukiBox Privacy Policy
Last updated: 2026-08-28
Mai Sato ("we") sets out below how we handle the personal information of users of the Shopify app "UreyukiBox" (the "Service") and of their end customers (the customers of the Shopify store).
1. Information we collect
1.1 Information from your Shopify store
The Service retrieves the following through the Shopify Admin API.
- Store details (store name, domain, email address, address, currency setting)
- Product data (product name, SKU, price, stock quantity, per-location inventory levels)
- Order data (order number, order date and time, products, quantities, tax) — used as sales history for demand forecasting
- Supplier data (standard Shopify fields and data migrated from Stocky)
- Store owner details (information provided by Shopify during OAuth)
1.2 Stocky migration data (optional feature)
Stocky API copy
If you use the API copy in the Stocky migration wizard, we retrieve the following through the Stocky API.
- Suppliers
- Purchase orders
- Stock adjustments
- Purchase tax types (excluding rows explicitly marked
purpose=salesby Stocky)
Your Stocky API key is used only to perform the migration and is not stored on our servers. It is discarded once the migration finishes.
The “UreyukiBox Stocky Migration” Chrome extension
The extension's single purpose is to read migration data from the Stocky account you are signed in to and copy it to the same store in UreyukiBox. Until you review the specific disclosure in UreyukiBox, select the consent checkbox and press the button to start the Stocky copy, the extension does not read, store or transmit the Stocky URL, store identity, page content or CSV content. After that explicit action, it opens the Stocky dashboard and transiently processes the current path within Stocky and visible store identity on the device to check connectivity and sign-in status. It returns the matching source-store domain to the UreyukiBox interface, but this connectivity check does not store or transmit migration page or CSV content to the UreyukiBox server.
After you start a copy, the extension makes only read-only GET requests to Stocky pages and CSV files within https://stocky.shopifyapps.com/, using an allowlist fixed in the extension. It does not monitor or collect your general browsing history or any other website.
It collects the following information needed to migrate Stocky data to UreyukiBox.
- Source-store identity (the
myshopify.comdomain) and the Stocky source path, collection conditions, page title, headings, tables, permitted settings and links, CSV files, checksums and collection results - Supplier and vendor master data, contacts, supplier account numbers, online-order usernames (but not passwords), addresses, telephone numbers, payment terms, notes, lead times and product relationships
- Products, variants, SKUs, costs, reorder points, forecasting settings, days of cover, minimum order quantities (MOQ) and purchase tax types
- Stocktakes, purchase orders and lines, stock adjustments and lines (including the name of the person who made an adjustment), and their CSV files
- Reports including ABC analysis, best sellers, Low Stock, products, orders, sale items, SKUs, Statistics, Stock on hand and its history and average costs, stock adjustments and profit, plus evidence that Transfers cannot be retrieved from Stocky
This data may include personal information such as supplier contacts' names, email addresses, postal addresses, telephone numbers and online-order usernames, and the names of people who made stock adjustments; user-generated information or business communications such as supplier notes and purchase-order comments; and business or financial information about purchasing, sales, costs, taxes and profit.
The extension does not read, copy or transmit your Stocky login password, the value of any authentication cookie, or a Stocky API key. Chrome uses your signed-in session for same-origin GET requests, but the extension never reads the cookie value. Password fields and fields indicating authentication, session, API-key or similar secret values are excluded from collection. It does not monitor clicks, keystrokes or general browsing behaviour.
1.3 On-device extension data, transmissions and logs
- To prevent duplicates on retry and resume safely,
chrome.storage.localstores the job ID, source-store domain, start time, execution generation, profile, completed and current tasks, collection checkpoint, error code and Stocky collector tab ID. It does not store the contents of Stocky pages or CSV files in this area. - The one-use connection code, which is valid for 60 seconds, is not persisted on the device. An authorization token that permits writes only to its bound job is held only in
chrome.storage.sessionfor trusted extension contexts. Each token expires after 20 minutes and can be renewed while the job runs, but no token can be used after the 24-hour hard limit from job creation. - Collected page and CSV data is processed in memory and sent over HTTPS, with checksum verification, only to the fixed destination
https://api.ureyukibox.app/. The request sends no browser cookie and no referrer. - When the extension connects to the UreyukiBox API, we and our infrastructure providers may receive the IP address, timestamp, fixed API path requested, response status, browser and extension version, job and task IDs and error codes in access or operation logs used for security, abuse prevention, troubleshooting and reliability. We do not use those logs to record the contents of Stocky pages or CSV files, passwords, cookies, API keys or the value of a short-lived authorization token.
1.4 Information you enter
- Email address for alert notifications
- Slack webhook URL
- LINE user ID (obtained when you link our LINE official account, if you use LINE notifications)
- Business details (contact email address)
- Email address and optional Shopify store domain entered when you register for installation guidance on this website
1.5 Information collected automatically
- IP address, browser information, timestamps and operation logs while using the Service
- Session information using cookies and similar technologies
- Aggregated data from Cloudflare Web Analytics (in a form that does not identify individuals)
- Page views, clicks on installation links, referrer, and device and browser information collected by Google Analytics on this website (until you allow analytics, no cookies or other identifiers are stored and only aggregate data that does not identify you is collected)
- Page views, clicks on installation links, referrer, device and browser information, and advertising identifiers collected by the Google Ads tag if you allow advertising measurement on this website
- Referral information, registration timestamp and the version of this Privacy Policy accepted when you register for installation guidance on this website
2. How we use it
We use the information we collect for the following purposes.
- Providing, operating and improving the Service
- Persisting your Stocky data in our own database (so it survives Stocky's shutdown)
- Generating and delivering demand forecasts and stock alerts (email / Slack / LINE)
- Responding to your enquiries
- Preventing misuse
- Statistical analysis of how the Service is used and measurement of advertising performance
- Sending installation guidance and campaign terms, matching the registration when you install, and attributing referrals
- Other work necessary to operate the Service
We do not send the Stocky page or CSV originals collected by the Chrome extension to Google Analytics, Google Ads or the Gemini API. We do not sell this data; transfer it to advertising platforms, data brokers or other information resellers; or use it for personalised, retargeted or interest-based advertising, creditworthiness assessment or lending decisions.
3. Disclosure to third parties
We do not provide your personal information to third parties except in the following cases.
- Where you have consented
- Where required by law
- Where necessary to protect a person's life, body or property
- Where we provide information to subcontractors — cloud providers such as Cloudflare (Pages, DNS), Fly.io (backend API), Resend (email delivery) and Google (Gemini API: suggesting which products respond to seasonal events and generating reorder-point explanations; Google Analytics: usage analysis; Google Ads: measuring advertising performance) — to the extent needed to provide the Service
- Where information passes to a successor in connection with a business transfer
3.1 What we send to the AI (Gemini API)
Two features use the Gemini API, and each is triggered differently. In neither case do we send any personal information about end customers.
- Seasonality suggestions by product — we send product names, product categories and vendor names (the Shopify vendor field). This feature runs automatically whenever a product sync completes, including the once-daily automatic sync. It does not send anything when none of the product information above has changed since the previous send. Suggestions do not affect any order quantity until you approve them.
- Reorder point explanation ("Why this number?") — for that product we send its name, estimated daily sales, units sold in the period, stock on hand, reorder point, lead time, safety-stock days and number of days out of stock. This feature runs only when you open the explanation in the app. It is used only to write the explanation: reorder points and order quantities are calculated on our own servers, and the AI output never changes a number.
For the reorder point explanation, nothing is sent to the Gemini API unless you use the feature. The seasonality suggestions run automatically alongside product sync, as described above.
3.2 Chrome Web Store Limited Use
The “UreyukiBox Stocky Migration” Chrome extension's use of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.
- The extension limits collection and use to its disclosed single purpose of migrating Stocky data to UreyukiBox and what is necessary to provide, maintain, secure and measure the reliability of that feature.
- Transfers are limited to UreyukiBox and processors necessary to provide it. We make no other third-party transfer except to comply with law, address fraud or security, or complete a business transfer after obtaining the user's explicit prior consent.
- Personnel may read collected data only with the user's explicit consent to read specified data for support, where necessary for security, to comply with law, or as lawfully anonymised and aggregated data for internal operations.
- We do not sell collected data or use or transfer it for advertising, data brokering, creditworthiness or lending.
4. Where data is stored
The backend of the Service is hosted on Fly.io in the Tokyo region (nrt). The database is PostgreSQL (Tokyo region) and is stored encrypted.
The frontend and marketing site are served from Cloudflare's global edge network, but persistent storage of user data is limited to the Tokyo region.
5. How long we keep data
- Order history and other store data used for demand forecasting are retained while the app is in use so that the Service can provide its features.
- Stocky migration data is likewise retained while the app is in use. This can include API-copied suppliers, purchase orders and lines, stock adjustments and lines, purchase tax types and API payloads; pages, settings, CSV files, reports, collection conditions, checksums and evidence collected by the Chrome extension; files uploaded through standalone Stocky CSV import; pasted Order limits/Statistics tables; manual notes; and evidence attachments.
- The extension clears its on-device collection checkpoint when a copy completes. Minimal completed-job state remains in
chrome.storage.localuntil the next job overwrites it, and Chrome clears it when the extension is removed.chrome.storage.session, which holds the short-lived authorization token, is cleared when the extension is disabled, reloaded or updated, or when the browser restarts. - Access and operation logs for the extension and destination API are retained only as long as needed for security, abuse prevention, troubleshooting and reliability, after which they are deleted or aggregated into a form that does not identify an individual.
- When you uninstall the app, Shopify normally sends a
shop/redactrequest about 48 hours later. On receipt, we delete Service data tied to that store. Records that must be retained by law, accounting or referral-attribution records anonymised so they no longer directly identify the store, and the used-state and minimum necessary timestamps stored under a keyed hash of the store identifier to prevent repeated free-trial or campaign benefits are excepted. - Unsubscribing from installation-guidance emails stops further delivery immediately. To prevent accidental resending and retain the consent record, we keep the registration data, including its unsubscribed status, until you ask us to delete it.
- Where a retention period is prescribed by law, that period applies.
6. Security measures
We take the following measures to prevent leakage, loss or damage of personal information and otherwise manage it securely.
- Encryption of server-side data at rest and TLS 1.3 encryption in transit
- Least-privilege access control and secure storage of credentials
- Authentication via Shopify App Bridge session tokens (JWT)
- Operation logging and periodic audits
- Ongoing remediation of vulnerabilities
- A one-use, 60-second connection code and authorization tokens bound to the store, job, execution generation, scopes and expiry
- Fixed allowlists for the extension's Stocky and UreyukiBox destinations, request methods and collection paths
7. Your rights
You may make the following requests regarding your own personal information that we hold.
- Notification of the purpose of use
- Disclosure, correction, addition or deletion of the information
- Suspension of use, erasure, or suspension of provision to third parties
Send requests to support@ureyukibox.app. We will verify your identity and respond within a reasonable period.
You can stop emails about installation guidance and campaign terms immediately using the "unsubscribe" link at the end of each message. We also handle unsubscribe requests sent through our contact form.
8. Cookies, analytics and your measurement choice
The Service uses cookies and similar identifiers for authentication, session management and usage analysis. On the landing site, Google Consent Mode v2 initially sets ad storage, advertising user data, ad personalisation and analytics storage to denied.
On the landing site we load the Google Analytics tag and measure page usage whether or not you allow it. However, while “analytics storage” is denied we store no cookies or other identifiers on your device and send Google only aggregate measurement that does not identify you.
Until you explicitly select “Allow”, we do not configure the Google Ads tag or make advertising-measurement requests to Google. Only after you allow it do we use cookies for analytics and send that page view and clicks on install links to Google as advertising measurement events. Declining does not restrict use of the site or app.
Even when you allow measurement, ad personalisation remains denied. We do not configure measurement data from this landing site for personalised advertising.
We also use Cloudflare Web Analytics to count page views. It uses no cookies and produces only aggregate data that does not identify you.
Your choice is stored in your browser's localStorage. You can change it at any time using “Analytics and ad settings” in the page footer. If you disable or clear cookies or localStorage in your browser, we may ask you to choose again on a later visit.
9. Contact
Please direct enquiries about this policy to:
Mai Sato (trading as Mumu Labo)
Email: support@ureyukibox.app
Address: MIEUX Shibuya Building 8F, 5-3 Maruyamacho, Shibuya-ku, Tokyo 150-0044, Japan
10. Changes to this policy
We may revise this policy in response to changes in law or to the Service. If a change is significant, we will notify you within the Service or by email.
Mai Sato
Last updated: 2026-08-28