Privacy Policy
This page covers the MultiPass Shopify app only. For the FitOnline Tech website, see the website privacy policy(日本語).
Last Updated: October 5, 2026
Company: FITONLINE Inc.
1. Introduction
MultiPass(the “App”) is an application provided by FITONLINE Inc. (the “Company”) that enables Shopify stores to sell and manage ticket packages. We respect your privacy and are committed to protecting your personal information.
This Privacy Policy explains what information we collect, how we use it, store it, and share it. By using the App, you agree to this Privacy Policy.
This Privacy Policy applies to:
- Store Owners: Businesses that use the App to sell and manage ticket packages on their Shopify stores
- Customers: Consumers who purchase tickets from store owners’ e-commerce sites
This Privacy Policy covers information collected from both store owners and customers.
2. Information We Collect
2.1 Store Information (For Store Owners)
We collect the following information from Shopify store owners:
- Shopify Domain: Store identifier (e.g., example.myshopify.com)
- Access Token: Authentication credentials required for Shopify API access (stored encrypted)
- Language Settings: App display language settings (Japanese/English)
- Custom Text Settings: Customization settings for customer-facing pages
- Plan Information: Current subscription plan information
- Installation Date: Date and time of app installation
2.2 Customer Information (For Customers)
We collect the following information from customers who purchase tickets:
- Customer ID: Customer identifier assigned by Shopify
- Customer Name: Name provided at the time of order
- Email Address: Email address provided at the time of order
- Phone Number: Phone number provided at the time of order (optional)
2.3 Ticket Information (Primarily for Customers)
We collect and store the following information for ticket management (information related to customers’ ticket purchases and usage):
- Order Information: Order ID, order number, purchase date and time
- Price Information: Product price (after discounts), currency code
- Product Information: Product ID, product name, product image URL
- Ticket Information: Ticket count, consumed count, expiration date, status
- Usage History: Consumption date and time, staff name who recorded usage, notes
- Cancellation History: Cancellation date and time, staff name who recorded cancellation, notes
2.4 Session Information (For Store Owners and Customers)
We collect the following information for authentication and security:
- Session ID: Authentication session identifier
- User Information: Basic Shopify account information (name, email address, etc.)
3. How We Use Information
We use the collected information for the following purposes:
- Ticket Management: Ticket assignment, usage recording, expiration tracking
- Customer Service: Enabling customers to view ticket information in their account page
- App Functionality: Providing features such as ticket search, filters, and analytics
- Security: Preventing unauthorized access and protecting data
- Support: Responding to customer inquiries
- Legal Compliance: Fulfilling legal obligations
3.5 Legal Basis for Data Processing (GDPR - Primarily for Customers)
We process personal data (primarily customer personal data) based on the following legal grounds:
- Contract Performance: To provide ticket sales and management services (GDPR Article 6(1)(b))
- Legal Obligation: To comply with legal requirements (GDPR Article 6(1)(c))
- Legitimate Interest: To improve services and ensure security (GDPR Article 6(1)(f))
3.6 Roles in Data Processing (GDPR)
Under the GDPR, the roles in data processing are as follows:
- Store Owners: As owners of customer personal data, are responsible for determining the purposes and means of data processing
- We (FITONLINE Inc.): As a service provider for store owners, process customer personal data on behalf of store owners in accordance with their instructions
We process personal data in accordance with store owners’ instructions and implement appropriate security measures.
4. Data Storage and Security
4.1 Data Storage Location
App data is stored securely in cloud databases.
4.2 Security Measures
We implement the following security measures to protect your information:
- Encryption: Sensitive information is stored encrypted
- Encrypted Communication: All communications are encrypted
- Authentication: Access management through appropriate authentication systems
- Data Isolation: Complete data separation between stores
- Access Control: Appropriate access control and permission management
- Security Measures: Protection against common security threats
4.3 International Data Transfers
App data is stored on servers located in Japan. When processing data of customers within the EU, data is transferred outside the EU (to Japan). We implement appropriate safeguards (encryption, access control, data isolation, etc.) to protect personal data.
4.4 Data Breach Notification
In the event of a personal data breach, we will promptly notify affected customers and supervisory authorities in accordance with legal requirements. Notifications will include the nature of the breach, the types of personal data that may have been affected, and recommended measures.
5. Information Sharing and Disclosure
We do not share or disclose your personal information to third parties except in the following cases:
- Shopify: Since the App operates on the Shopify platform, Shopify’s Privacy Policy applies
- Legal Requirements: When required by law, regulations, or legal processes
- Consent: When we have obtained explicit consent from you
We do not sell your personal information to third parties for marketing purposes.
5.1 Sub-processors
We use cloud hosting services (data processing service providers) to provide our services. Data is stored on servers located in Japan and used for application hosting and database storage.
Sub-processors implement data protection measures equivalent to this Privacy Policy and appropriately protect personal data.
6. Data Retention Period
We retain data for the following periods:
- Active Stores: While the app is installed and for 48 hours after uninstallation
- After Uninstallation: All data is automatically deleted 48 hours after uninstallation
However, this does not apply when data retention is required by legal requirements.
7. Your Rights (For Customers)
This section explains the rights of customers (end users) who have purchased tickets.
You (customers) have the following rights:
7.1 Right to Access Data
You can request to view personal data stored by the App. When you submit a data request through Shopify, the App will provide the relevant data.
7.2 Right to Delete Data
You can request deletion of personal data. When you submit a deletion request through Shopify, the App will delete the relevant data.
7.3 Right to Data Portability
You (customers who have purchased tickets) can obtain your personal data in a machine-readable format (JSON format) free of charge. When you submit a data request through Shopify, the App will provide your personal data in JSON format. This data can be used when migrating to other services.
7.4 Right to Withdraw Consent
You can withdraw your consent to data processing. However, withdrawing consent may result in some App features becoming unavailable.
7.5 Right to Rectification
You can request correction of inaccurate personal data. Please contact the store owner for rectification requests.
7.6 Right to Restriction of Processing
You can request restriction of data processing under certain conditions. Please contact the store owner for restriction requests.
7.7 Right to Object
You can object to data processing. Please contact the store owner to raise objections.
8. Compliance
The App strives to comply with the following regulations:
- APPI (Act on the Protection of Personal Information): Personal information protection under Japanese law
- GDPR (General Data Protection Regulation): Applies to users within the EU
- CCPA (California Consumer Privacy Act): Applies to users in California
- Shopify App Store Requirements: Compliance requirements set by Shopify
The App implements the following Shopify compliance webhooks:
- customers/data_request: Handles customer data access requests
- customers/redact: Handles customer data deletion requests
- shop/redact: Handles shop data deletion requests
9. Cookies and Tracking Technologies
The App uses Shopify’s session management functionality and stores session information necessary for authentication. The App does not perform tracking or ad delivery for marketing purposes.
10. Children’s Privacy (For Customers)
We do not knowingly collect personal information from children (customers) under the age of 13. If we discover that we have collected personal information from a child under 13, we will delete it immediately.
11. Changes to Privacy Policy
This Privacy Policy may be changed without notice. If there are significant changes, we will notify you through the App or Shopify. Continued use of the App after changes constitutes acceptance of the updated Privacy Policy.
12. Contact Us
If you have any questions or requests regarding privacy, please contact us at the following email address:
- Email: tech@fitonline.co.jp
- Company: FITONLINE Inc.
13. Governing Law
This Privacy Policy is governed by Japanese law. Any disputes regarding this Privacy Policy shall be subject to the exclusive jurisdiction of Japanese courts.