Rillnook Labs / ProofGate

Privacy information

Published 26 September 2026 · Current pre-release implementation

The legal operator is 鎌田将矢, operating in Japan under the public brand/developer name Rillnook Labs. Contact support@rillnook.com for privacy questions. This notice describes the implemented service and its development validation, not an assertion of production compliance. Production retention/copy policies and the final merchant agreement must be adopted before public launch.

Data and purposes

Shopify scopes are read_orders for relevant order/status data and write_draft_orders for merchant-quoted revision-service Draft Orders. Initial order import is bounded to 30 days; a manual import is limited to 60 days and 100 orders. These import windows are not deletion periods.

Providers used

ProviderActual role
ShopifyStore and staff authentication, order/Draft Order APIs, App Pricing and compliance webhooks.
CloudflareWorkers application hosting, D1 tenant records, private R2 artwork/export/recovery storage and this static information site.
ResendTransactional proof email delivery and signed delivery events. Recipient mailboxes retain their own copies.

This describes direct service dependencies, not a complete list of these providers' subprocessors or a promise of Japan-only processing. Provider residual logs, backups, geographic processing and operator-held copies require their own review. These static pages have no app forms, tracking scripts, advertising pixels or application cookies; Cloudflare receives ordinary HTTP connection/request information to serve them. Contacting support creates correspondence outside the app's D1/R2 records.

Access and security

Operator policy limits production-data access to Owner/Admin roles where necessary. Application routes also enforce Shopify authentication, tenant/resource correspondence and role checks. Customer subject export download and acknowledgment are Owner-only, not general Admin permissions. Private R2 objects are not public download links.

HTTPS protects transport. Cloudflare provides storage-level protections; selected credentials and capabilities are additionally encrypted by the app. This is not a claim that every business field, downloaded file, mailbox copy or backup is application-encrypted.

Protected application reads and actions have minimized audit records, including actor, resource, outcome and time where implemented. No claim is made that application audits cover all provider-console or endpoint access. JSON bodies, customer emails, tokens and private links must not be copied into diagnostic evidence.

Retention and deletion

Different records have different lifetimes. The implementation's current bounds are disclosed below; configurable ranges are not newly adopted production periods.

RecordCurrent implementation
Ordinary artwork filesDefault file lifecycle 90 days, with inactivity warning at 83 days and archive at 90 days. This does not apply a 90-day lifetime to all order or audit history.
Customer export artifactsDevelopment/test default: download access for 2 days and replay cleanup for 30 days after expiry. Configurable bounds: 1–7 and 30–90 days respectively. Production requires an explicitly approved policy; there is no silent production default.
Protected access logsDevelopment setting: 7 days. Production requires an approved finite setting within 1–90 days.
Other history, inbox, outbox, audit and request recordsExplicit per-store finite policies within 1–730 days; replay horizons within 60–90 days. No single global production period has been adopted here.
Recovery, deletion and external copiesDeletion is subject to unfinished privacy duties, redaction/restore fences, replay protection and recoverable-copy lifetimes. Provider logs/backups, email and Owner downloads are separate copies; deleting a D1 row does not erase them.

Deletion queues and safety checks prevent premature erasure of unfinished duties. Conditional cleanup targets are not an immediate or all-copy erasure guarantee. Final production periods, provider/operator copy handling and legal-hold rules remain pre-launch requirements.

Requests and Owner provision

Customers should contact the merchant responsible for their order. Merchants can contact support@rillnook.com for service/privacy assistance without emailing tokens or unrequested sensitive files. Shopify compliance requests are processed through the app's normal queue. The app preserves the original receipt-based 30-day due date through retries and recovery.

An export download offer marked PROVIDED does not mean the customer has received the data. A same-Owner, same-artifact retry is allowed only under the existing validity and authorization checks. Actual Owner provision and a separate acknowledgment are required to mark fulfillment complete. Development validation of this path does not certify every production request or external delivery channel.

Incident contact and changes

The Rillnook Labs owner/operator is the incident-response contact through support@rillnook.com. This contact assignment is not certification of an independently audited organizational security program. Material service/policy changes will require an updated notice before the affected public service is offered.