Privacy policy

Last updated: September 22, 2026.

This policy explains how 株式会社モリモリダ handles information about merchants and shoppers through Talkbot. The store's own terms and privacy policy also apply to purchases, delivery, returns and its separate data practices.

Information and purposes

From Shopify, we obtain store identity, name, currency, product and variant information, prices, publication and availability information, app installation status, and subscription and billing-period information. We also process merchant-written greetings, guidance and display settings. We use these for product advice, catalog synchronization, subscription verification, usage limits and secure operation. We do not request Shopify API permissions to access customer or order data.

After consent to start, we process questions, preferences and recent conversation history. Voice requires a separate start action and microphone permission. Do not enter names, addresses, payment details or other personal or confidential information unnecessary for shopping advice. If you contact support, we process your contact details and message to respond and investigate.

Optional interaction analytics are recorded only when the Shopify Customer Privacy API allows analytics processing. If permission cannot be determined, we do not record those analytics. Voice usage, subscription verification and abuse-prevention records are processed as necessary to provide the service.

External services

Processing can occur outside Japan in the locations used by these services. Provider retention, logs and processing are governed by the applicable provider agreements and notices below. Not storing information in our app database does not mean that external services never process or retain it.

Browser storage and abuse prevention

A signed random identifier may be stored in your browser for each store to authenticate usage and enforce limits. It expires after 24 hours and is renewed on your next consultation. The expired value itself can remain until replaced or browser storage is cleared. It is a pseudonymous identifier, not a guarantee of anonymity. Display preferences such as language remain until changed or browser storage is cleared. We do not use these for advertising tracking. Disabling storage may prevent some features from working.

We transform the source IP supplied by the trusted hosting edge into a keyed hash and count requests in one-minute windows in memory. The app does not store that IP in its database or application logs. Expired counters are removed on subsequent requests. Hosting infrastructure logs are separate.

Stored records and retention

We store settings, product information, encrypted Shopify credentials, subscription verification, random usage identifiers, voice session identifiers and duration/closure status, processing jobs, daily interaction counts and data-request status. The app database is not designed to retain recordings, conversation text, customer names, addresses, emails or order contents. Conversations are processed in memory and by external services.

Scheduled cleanup may be delayed during outages or downtime. Support correspondence is retained while needed for responses, investigations and legal obligations.

For disaster recovery, encrypted database backups are stored privately and contain the database records described above. Expiry deletion is configured for 7 days after creation; actual removal depends on storage processing. Data removed from the active database can remain in a backup until expiry. Before restoring service, deletion requests and revoked access must be reconciled; unreconciled recovery data is not returned directly to service.

Stopping use, deletion and your requests

Shoppers can use the voice-stop control. Merchants can disable the assistant or uninstall the app. Uninstallation revokes app access but does not instantly erase every record. When Shopify requests store deletion, we check the store and installation identity and unresolved voice activity before processing removal of related records.

For access, correction, deletion, restriction or withdrawal-of-consent requests, contact the store administrator or the address below. We verify identity and authority and respond under applicable law. Random usage identifiers without a name or contact detail may prevent matching a specific person's usage. Access is restricted to authorized personnel and protected in transit and storage.

Operator:株式会社モリモリダ
Contact:contact@morimorida.com

Provider notices and changes

OpenAI · TypeSafe · Cloudflare · Render · Shopify

We update this page when practices change and provide notice and obtain additional consent where required.