PIPA Audit Trail(이하 "서비스")은 Shopify 스토어 운영자가 자사 직원의 고객·주문 정보 접근 이력을 기록·보관하여 개인정보 접속기록 관리 의무를 이행할 수 있도록 돕는 도구로, ① Shopify 임베디드 앱(관리 대시보드)과 ② Chrome 확장 프로그램으로 구성됩니다. 이 방침은 서비스 운영자(이하 "운영자")가 처리하는 개인정보를 설명합니다.
스토어 운영자(고객사)는 자사 직원의 접근 기록에 대한 개인정보처리자이고, 서비스 운영자는 고객사의 위탁을 받아 기록을 수집·저장하는 수탁자로서 처리합니다. 서비스는 고객사의 최종 고객(구매자)의 이름·이메일·전화번호·주소를 수집하거나 저장하지 않습니다.
| 구분 | 항목 | 목적 |
|---|---|---|
| 접근 이벤트 (확장 프로그램·앱) | 이벤트 ID, 발생 시각, 행위 유형(조회·검색·내보내기·생성·수정·삭제), 리소스 유형과 번호(ID), 스토어 도메인, 관리자 화면 경로, 접근 직원 식별자, 접속 IP 주소(확장 프로그램 이벤트), 검색어의 SHA-256 해시와 글자 수(원문은 저장하지 않음) | 개인정보 접속기록 생성·보관, 위·변조 방지(해시 체인) |
| 점검 사유 기록 | 관리자가 입력한 열람 사유 텍스트 | 접근 사유 소명 |
| 직원 명부 | Shopify 직원 사용자 ID, 관리자가 입력한 이름·이메일(선택), 최초·최종 접속 시각 | 직원별 확장 프로그램 설치·배정 현황 관리 |
| 장치 토큰 | 장치 토큰의 해시값(원문은 서버에 저장하지 않음), 연결된 스토어·직원, 만료일 | 확장 프로그램 인증 |
| Shopify 필수 웹훅 | Shopify가 전달하는 개인정보 요청·삭제 통지(고객 ID 등 식별자 중심) | Shopify 개인정보 규정 이행 |
| 스토어 연락처 (안내 메일용) | 스토어 관리자 이메일 주소 | 설치·종료·백업 제공 안내 및 본인 확인 |
확장 프로그램 설정(서버 주소, 스토어 도메인, 직원 ID, 전송 대기열)은 이용자 브라우저의 chrome.storage.local에,
장치 토큰은 chrome.storage.session에만 저장되며 Chrome을 완전히 종료하면 삭제됩니다.
스토어 운영자는 support@doingon.com으로 백업 추출을 요청할 수 있습니다. 설치 시 확인된 스토어 관리자 이메일과 요청 메일의 발신 주소가 일치하는 경우에만 처리하며, 추출 사실은 운영 기록으로 남깁니다. 접근 기록에 포함된 직원 등 정보주체는 개인정보 열람·정정·삭제·처리정지를 소속 스토어 운영자 또는 위 이메일로 요청할 수 있습니다. 법령상 보관 의무가 있는 기록은 삭제가 제한될 수 있습니다.
수집된 정보를 광고·분석 등의 목적으로 판매하거나 제3자에게 제공하지 않습니다. 법령에 근거한 요청이 있는 경우에 한해 제공할 수 있습니다.
서비스는 아래 해외 사업자의 인프라를 이용하여 개인정보를 처리·보관합니다. 서비스 이용을 위해 필수적이며, 이용자가 이전을 거부하는 경우 서비스(확장 프로그램 포함) 이용이 불가능합니다. 거부는 확장 프로그램 삭제 및 앱 삭제로 할 수 있고, 기타 문의는 support@doingon.com으로 해주세요.
| 이전받는 자 | 국가·보관 위치 | 이전 항목 | 이용 목적 | 이전 시점·방법 | 보유 기간 |
|---|---|---|---|---|---|
| Google LLC (Google Cloud: Cloud Run, Firestore, Pub/Sub, Cloud Storage, Secret Manager, Artifact Registry) 문의: Google Cloud 개인정보 보호 문의 페이지 | 미국(본사). 데이터는 대한민국 서울 리전(asia-northeast3)에 저장되며, 운영·유지보수 과정에서 국외에서의 접근이 있을 수 있음 | 2항의 접근 이벤트, 점검 사유, 직원 명부, 장치 토큰 해시, 스토어 연락처, 필수 웹훅 | 서비스 서버 운영, 데이터베이스·백업 보관 | 서비스 이용 시 정보통신망을 통한 상시 전송·저장 | 3항의 기간 |
| Cloudflare, Inc. (Cloudflare Workers·DNS) | 미국(본사). 전 세계 엣지 서버를 경유(중계만 하며 저장하지 않음) | 서비스 호출에 포함된 접근 이벤트·접속 IP 등 통신 내용(전달 목적의 일시 처리) | 도메인(api.doingon.com) 중계, 전송 보호 | 서비스 이용 시 정보통신망을 통한 상시 전송 | 저장하지 않음(전송 처리 후 즉시 폐기, 통상적인 운영 로그 제외) |
| Shopify Inc. 및 관계사 (Shopify 플랫폼) | 캐나다 등 | 스토어 도메인, 직원 세션 정보, 필수 웹훅(앱 설치·종료·개인정보 요청) | 앱 설치·인증·웹훅 전달 | Shopify 플랫폼 이용 시 상시 | Shopify 정책에 따름 |
개인정보 보호 문의·불만 처리: support@doingon.com
개인정보 보호책임자: gray.oh / CEO
그 밖의 침해 신고·상담은 개인정보침해신고센터(국번없이 118), 개인정보 분쟁조정위원회(1833-6972)에 문의할 수 있습니다.
이 방침이 변경되는 경우 시행일과 변경 내용을 이 페이지에 게시합니다. 이전 버전(2026-09-28)은 Chrome 확장 프로그램에 한정된 방침이었으며 이 방침으로 대체됩니다.
PIPA Audit Trail (the "Service") helps Shopify merchants record and retain a log of their own staff's access to customer and order data, so they can meet access-log obligations under privacy laws such as Korea's Personal Information Protection Act (PIPA). It consists of (1) an embedded Shopify app (admin dashboard) and (2) a Chrome extension. This policy describes the personal data processed by the Service operator (the "Operator").
The merchant is the controller of its staff's access records; the Operator processes them on the merchant's behalf as a processor. The Service does not collect or store the name, email, phone number or address of the merchant's end customers.
| Category | Data | Purpose |
|---|---|---|
| Access events (extension and app) | Event ID, timestamp, action type (view, search, export, create, update, delete), resource type and ID, store domain, admin page path, staff identifier, source IP address (extension events), SHA-256 hash and length of search text (the text itself is never stored) | Producing and retaining access logs; tamper detection (hash chain) |
| Inspection reasons | Free-text reasons entered by administrators | Documenting why data was accessed |
| Staff roster | Shopify staff user ID, optional name and email entered by an administrator, first/last seen times | Tracking which staff have a working extension token |
| Device tokens | Hash of the device token (the raw token is not stored on our servers), linked store and staff, expiry | Extension authentication |
| Shopify mandatory webhooks | Privacy request / erasure notices sent by Shopify (mainly identifiers) | Complying with Shopify privacy requirements |
| Store contact (for notices) | Store administrator email address | Install, termination and backup-handover notices; identity verification |
Extension settings (server address, store domain, staff ID, retry queue) are stored in your browser's chrome.storage.local.
The device token is kept only in chrome.storage.session and is removed when Chrome fully quits.
A merchant can request a backup export at support@doingon.com. We process the request only if the sender matches the store administrator email verified at installation, and we log each export. Individuals whose data appears in access records (e.g. staff) may request access, correction, deletion or restriction through their merchant or at the address above. Deletion may be limited where records must be retained by law.
We do not sell personal data or share it with third parties for advertising or analytics. We may disclose it where required by law.
The Service processes and stores data on the infrastructure of the overseas providers below. This is necessary to provide the Service; if you refuse the transfer, the Service (including the extension) cannot be used. You can refuse by removing the extension and uninstalling the app; for other questions contact support@doingon.com.
| Recipient | Country / location | Data | Purpose | When / how | Retention |
|---|---|---|---|---|---|
| Google LLC (Google Cloud: Cloud Run, Firestore, Pub/Sub, Cloud Storage, Secret Manager, Artifact Registry) | United States (HQ). Data is stored in the Seoul, South Korea region (asia-northeast3); operational access from outside Korea may occur | Access events, inspection reasons, staff roster, token hashes, store contact and mandatory webhooks (section 2) | Hosting the Service; database and backup storage | Continuously over the network while the Service is used | As in section 3 |
| Cloudflare, Inc. (Workers, DNS) | United States (HQ). Traffic passes through its global edge network (relay only, no storage) | Access events, IP address and other request contents in transit | Relaying api.doingon.com, transport protection | Continuously over the network while the Service is used | Not stored (transient processing, apart from routine operational logs) |
| Shopify Inc. and affiliates (Shopify platform) | Canada and others | Store domain, staff session information, mandatory webhooks (install, uninstall, privacy requests) | App installation, authentication, webhook delivery | Continuously while using the Shopify platform | Per Shopify's policies |
Privacy questions and complaints: support@doingon.com
Privacy officer: gray.oh / CEO
Changes will be posted on this page with the effective date. This policy replaces the 2026-09-28 version, which covered only the Chrome extension.