法的事項

プライバシーポリシー

私たちは、ご家族がデータの取り扱いについて明確で誠実な説明を受ける権利があると考えています。特にお子さまが関わる場合はなおさらです。

最終更新日:2025年6月1日  ·  すべての Pikidoo サービスに適用されます

1 私たちについて

Pikidoo は、Pikidoo(以下「当社」)が運営する家族向けのタスク・報酬管理サービスです。本サービスでは、保護者が家事やルールを作成し、子どもに報酬を割り当て、達成状況を記録し、お小遣いの支払いを管理することができます。これらはすべてウェブおよびモバイルアプリを通じて行えます。

本プライバシーポリシーでは、お客様が Pikidoo を利用される際に当社が収集する個人データ、その収集理由、保護方法、ならびに EU の GDPR その他の適用法令に基づきお客様が有する権利について説明します。

データ保護に関するお問い合わせ先
プライバシーに関するお問い合わせは、privacy@pikidoo.app までメールでご連絡ください。

2 収集するデータ

Account data (parents / guardians)

  • Name and email address — collected at registration
  • Encrypted password — stored as a secure hash; we never see your plain-text password
  • Family name and a unique family code you choose
  • Preferred language and currency
  • Subscription plan information (linked to your Stripe customer record)

Child profile data

  • First name (or nickname) — provided by the parent
  • Avatar icon and colour — chosen by the child or parent
  • Optional: birth year (used only to display age-appropriate content)
  • Hashed PIN — children authenticate with a 4-digit PIN; we store only the hash
  • Wallet balance — the in-app reward balance calculated from approved tasks

Task and activity data

  • Task names, reward amounts, icons, and group assignments created by parents
  • Task completion records: which child, which task, date, and approval status
  • Payout records: amounts paid, dates, and associated children

Technical data

  • Server-side logs (IP address, request path, timestamp) — retained for 30 days for security and debugging
  • No browser cookies are set by the Pikidoo application itself

Payment data

Subscription payments are processed by Stripe, Inc. We never store your full card number, CVV, or bank details. Stripe shares with us only a customer reference ID and subscription status. Stripe's privacy policy applies to payment data: stripe.com/privacy.

3 データの利用方法

  • Provide the service — authenticate users, store and display tasks, calculate balances, process payouts
  • Manage subscriptions — apply the correct plan limits, handle upgrades, downgrades, and cancellations via Stripe
  • Communicate with you — send transactional emails (account creation, password reset, subscription receipts)
  • Improve Pikidoo — analyse aggregate, anonymised usage patterns to prioritise features
  • Ensure security — detect and prevent fraudulent or abusive access
  • Comply with law — retain records required by applicable financial and tax regulations

We do not use your data for advertising, sell it to third parties, or use it to build marketing profiles.

4 法的根拠(GDPR)

For users in the European Economic Area (EEA) and United Kingdom, our legal bases are:

  • Contract performance (Art. 6(1)(b)) — processing necessary to deliver the service you signed up for
  • Legitimate interests (Art. 6(1)(f)) — security logging and aggregate service improvement
  • Legal obligation (Art. 6(1)(c)) — retaining financial records as required by law
  • Consent (Art. 6(1)(a)) — for optional analytics cookies, where applicable

For child profile data we rely on parental consent — the parent or guardian who creates the account is responsible for providing that consent on behalf of the children added to the family.

5 子どものプライバシー

Special protections for children's data

Pikidoo is designed to be used by parents on behalf of their children. Children do not register themselves — a parent or guardian creates and manages all child profiles. This means:

  • We collect only the minimum data needed for a child profile (name, avatar, PIN hash, balance)
  • Children's data is never shared with advertisers or third-party analytics providers
  • Child profiles do not have email addresses or direct marketing contact
  • Children's task history and balances are visible only to the family
  • Parents may delete any child profile at any time, which permanently removes all associated data

We comply with the GDPR provisions on children's data (Art. 8) and, for US users, COPPA. If you believe we have inadvertently collected data from a child without appropriate parental consent, please contact us immediately at privacy@pikidoo.app.

6 データの共有と処理者

We share data only with the following trusted processors, all bound by data processing agreements:

ProcessorPurposeLocationPrivacy policy
Stripe, Inc.Subscription payment processingUSA (SCCs in place)stripe.com/privacy
Cloud hosting providerDatabase and application hostingEUAvailable on request
Google FontsTypeface delivery on this websiteUSA (SCCs in place)policies.google.com/privacy

We do not sell personal data. We do not share data with law enforcement except where legally compelled.

7 Cookie とトラッキング

This marketing website (pikidoo.app)

  • Essential: A cookie_consent entry in your browser's localStorage remembers your cookie preference.
  • Third-party: Google Fonts (loaded from fonts.googleapis.com) may set its own cookies or log your IP to serve font files.
  • Analytics: We do not currently use any analytics cookies or tracking pixels on this website.

The Pikidoo app

  • The app stores your authentication token in the browser's localStorage — this is a technical necessity, not a tracking cookie.
  • No third-party tracking or advertising cookies are used inside the app.
You can review or change your cookie preference at any time using the button.

8 データの保持

  • Active accounts: Data is retained for as long as your account is active.
  • After account deletion: All personal data is permanently deleted within 30 days, except where required by law (typically 7 years for financial records — anonymised where possible).
  • Child profiles: Deleted immediately and permanently when removed by a parent, or when the parent account is deleted.
  • Server logs: Automatically purged after 30 days.
  • Backups: Encrypted backups are retained for up to 90 days before being overwritten.

9 お客様の権利

Under the GDPR (and equivalent laws in the UK and other jurisdictions) you have the following rights:

アクセス権当社が保有するお客様に関するすべての個人データの写しを請求できます。
訂正権不正確または不完全なデータの訂正を当社に求めることができます。
消去権データの削除を請求できます(「忘れられる権利」)。
制限権紛争中に処理の停止を当社に求めることができます。
データポータビリティ機械可読な形式でデータを受け取ることができます。
異議申立権当社の正当な利益に基づく処理に異議を申し立てることができます。
同意の撤回Cookie への同意をいつでも撤回できます。
苦情の申立てお住まいの地域のデータ保護当局に苦情を申し立てることができます。

To exercise any of these rights, email us at privacy@pikidoo.app. We will respond within 30 days. We may ask you to verify your identity before acting on the request.

10 セキュリティ

  • All data is transmitted over TLS (HTTPS)
  • Passwords are hashed using a strong, salted algorithm — plain-text passwords are never stored
  • Child PINs are stored as secure hashes
  • Database access is restricted to application servers over private networking
  • Encrypted backups are stored separately from production data
  • Access to production systems is restricted to authorised personnel using multi-factor authentication

If you discover a potential security vulnerability, please report it responsibly to security@pikidoo.app rather than disclosing it publicly.

11 本ポリシーの変更

We may update this Privacy Policy from time to time. When we make material changes, we will notify active users by email at least 14 days before the changes take effect. The "Last updated" date at the top of this page always reflects the most recent revision. Continued use of Pikidoo after changes take effect constitutes acceptance of the updated policy.

12 お問い合わせ

Pikidoo — Privacy Team

privacy@pikidoo.app

security@pikidoo.app (security disclosures only)

If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu.