English version
プライバシーポリシー
AIMALON Booking(AIマロン予約)/制定日: 2026年9月21日
株式会社バルコ(以下「当社」)は、予約システム「AIMALON Booking(AIマロン予約)」(以下「本サービス」)で受け取る情報を、次のとおり取り扱います。
1. Google のユーザーデータ(担当者)
本サービスで Google アカウントを使うのは、予約を受ける担当者だけです。担当者が Google アカウントでログインし、本サービスに Google カレンダーへのアクセスを許可したときに、次のデータを扱います。予約する方(お客様)は Google アカウントを使いません。
1-1. 読む・書くデータと、その理由(許可の範囲ごと)
ログイン(openid・email)
読むもの: Google アカウントのメールアドレスと、そのアドレスが確認済みかどうか。
理由: ログインした方が、登録済みの担当者のどなたかを決めるためだけに使います。登録済みの担当者のメールアドレスと一致しなければ、ログインさせず、Google から受け取ったものを保存しません。
空き時間(calendar.events.freebusy)
読むもの: 担当者が選んだカレンダー(選んでいなければメインのカレンダー)で「予定あり」になっている時間帯(開始と終了の時刻だけ)。
理由: 予約ページに空いている時間だけを出すため、予約を受ける直前にその時間が空いているかを確かめるため、担当者の設定画面と予約枠の編集画面で、実際に予約できる時間の見本を担当者本人に見せるため。予約ページには空いている時間だけを出し、予定の名前や内容は出しません。読んだ時間帯は保存しません。
カレンダーの一覧(calendar.calendarlist.readonly)
読むもの: 担当者の Google アカウントで見えるカレンダーの ID・名前・メインのカレンダーかどうか・担当者の権限。
理由: 予約枠の設定画面で、空き時間の確認に使うカレンダーを担当者が選べるように、担当者本人に一覧を見せるため。保存するのは担当者が選んだカレンダーの ID だけで、カレンダーの名前は保存しません。
予定の読み書き(calendar.events)
書くもの: 予約が入ると、担当者のメインのカレンダーに予定を 1 件作ります。件名は予約枠の名前と予約者のお名前、説明には予約者のお名前・メールアドレス・電話番号・会議 URL・予約フォームの答え・予約番号、場所には会議 URL または場所の案内を入れます。日時が変わったら予定を直し、キャンセルされたら予定を消します。変更・削除するのは本サービスが作った予定だけです。
読むもの: 担当者が「終日の予定の扱い」を「すべて休み」または「無視」にしたときだけ、選んだカレンダーの、空き時間を調べる期間の予定の一覧を読みます。使うのは、日時・終日の予定かどうか・「予定あり/予定なし」・予定の種類(誕生日と勤務場所は予定として数えません)・取り消された予定かどうか・担当者が招待を辞退したかどうかだけです。予定の名前・説明・参加者などは使わず、保存しません。
理由: 予約を担当者のカレンダーに載せるため。終日の予定がある日に予約を受けるかどうかを、担当者が選んだとおりに決めるため。
1-2. 保存するもの・場所・守り方
- 保存するもの: Google にアクセスするための鍵(リフレッシュトークンとアクセストークン)、実際に許可された範囲(スコープ)、予定を書き込むカレンダー(メインのカレンダー)、連携した日時。予約枠ごとに、担当者が選んだカレンダーの ID。予約ごとに、本サービスが作った予定の ID と、予定の書き込みに失敗したときの理由。
- 場所: 本サービスのデータベース(Cloudflare D1)。
- 守り方: 鍵(トークン)は AES-GCM(256 ビットの鍵)で暗号化してから保存します。暗号化の鍵はデータベースとは別の場所(サーバーの秘密の設定)に置いており、データベースの中身だけでは鍵(トークン)を読めません。Google との通信はすべて HTTPS です。
- 保存しないもの: 予定の名前・説明・参加者・場所などの予定の中身、空き時間(「予定あり」の時間帯)、カレンダーの名前。ログインで受け取ったメールアドレスは照合にだけ使い、新たには保存しません(担当者のメールアドレスは、担当者を登録するときに当社が登録したものです)。
- 障害を調べるため、Google からのエラーの応答(最大 500 文字)と失敗の理由を、サーバーの実行記録(ログ)に出すことがあります。
1-3. 共有しない・売らない・広告や AI の学習に使わない
- Google のユーザーデータは、上の 1-1 に書いた本サービスの機能を提供するためにだけ使います。
- Google のユーザーデータを売りません。
- 広告(利用者の関心にあわせた広告を含む)に使いません。
- 第三者に渡しません。ただし、本サービスを動かす基盤(Cloudflare。データの保存と処理)に預ける場合と、法令に基づく場合を除きます。
- AI や機械学習のモデル(汎用のものを含む)の開発・改良・学習に使いません。
- 当社の人が読むことはしません。ただし、担当者本人の同意がある場合、セキュリティのため(不正な利用の調査など)に必要な場合、法令に基づく場合を除きます。
1-4. 連携の解除と削除
- 本サービスの画面には、Google との連携を解除するボタンはありません(設定画面にあるのは「Google カレンダーを繋ぎ直す」だけです)。
- 解除するには、Google アカウントの「サードパーティ製のアプリとサービス」(https://myaccount.google.com/connections)で、本サービスのアクセスを削除してください。解除すると本サービスはカレンダーを読めなくなり、その担当者の予約ページは空いている時間を出せなくなります。そのあと本サービスにログインし直すと、Google の同意の画面が出て、同意すると再び連携されます。
- 解除しても、暗号化した鍵(トークン)などの連携の記録はデータベースに残ります。削除をご希望の場合は、下のお問い合わせ先にご連絡ください。連携の記録(鍵を含む)を削除します。
2. 予約する方(お客様)の情報
予約する方の情報は、Google のユーザーデータではありません。
- 受け取るもの: お名前、メールアドレス、電話番号(予約枠が求める場合)、予約フォームの答え(備考など)、予約の日時、キャンセルの理由(入力した場合)。LINE で受け取ることを選んだ場合は、LINE ログインで LINE のユーザー ID を受け取り、当社の LINE 公式アカウントの友だちかどうかを確かめます。
- 使い道: 予約の受付・確認・日時の変更・キャンセル、予約についてのお知らせ(確認のメール・リマインド・LINE)、担当者への通知、担当者の Google カレンダーへの予定の書き込み。予約枠で設定した場合は、当社の LINE 公式アカウントでの友だちの管理(タグ付けなど)。
- 預け先・送り先: Cloudflare(本サービスの実行とデータの保存)、Resend(メールの送信)、LINE(LINE ログインと LINE でのお知らせ)、Chatwork(担当者への通知)、Google(担当者の Google カレンダーへの予定の書き込み)、L Harness(当社の LINE 公式アカウントの友だちの管理。予約枠で設定した場合)。
3. Google API のデータの限定的な使用(Limited Use)
AIMALON Booking's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
(和訳)AIMALON Booking が Google API から受け取った情報の使用と、ほかのアプリへの移転は、Limited Use の要件を含む Google API サービスのユーザーデータに関するポリシーに従います。
4. お問い合わせ
このポリシーについてのご質問、連携の記録の削除のご依頼は、次までご連絡ください。
- 運営者
- 株式会社バルコ(BARCO Inc.)
- 所在地
- 〒141-0032 東京都品川区大崎4-1-7
- お問い合わせ
- contact@barco-re.com
日本語
Privacy Policy
AIMALON Booking / Effective date: September 21, 2026
BARCO Inc. ("we") handles information received through the booking system "AIMALON Booking" (the "Service") as described below.
1. Google user data (staff)
Only staff members who receive bookings use a Google account with the Service. We handle the data below when a staff member signs in with their Google account and allows the Service to access their Google Calendar. People who make bookings (customers) do not use a Google account.
1-1. Data we read or write, and why (by scope)
Sign-in (openid, email)
What we read: the Google account email address and whether it is verified.
Why: only to determine which registered staff member is signing in. If the address does not match a registered staff member, sign-in is refused and nothing received from Google is stored.
Availability (calendar.events.freebusy)
What we read: the busy time ranges (start and end times only) on the calendars the staff member selected (or their primary calendar if none are selected).
Why: to show only free times on the booking page, to check that a time is still free just before accepting a booking, and to show the staff member a preview of the times that can actually be booked, in their settings and when editing a booking type. The booking page shows only free times, never event titles or details. The busy time ranges are not stored.
Calendar list (calendar.calendarlist.readonly)
What we read: the ID, name, whether it is the primary calendar, and the staff member's access role for each calendar visible in their Google account.
Why: to show the list to the staff member themselves in the booking settings, so they can choose which calendars are checked for availability. We store only the IDs of the calendars they choose, not the calendar names.
Reading and writing events (calendar.events)
What we write: when a booking is made, we create one event on the staff member's primary calendar. The title contains the booking type name and the customer's name; the description contains the customer's name, email address, phone number, meeting URL, answers to the booking form and the booking number; the location contains the meeting URL or the place. We update the event when the booking is rescheduled and delete it when the booking is cancelled. We only change or delete events that the Service created.
What we read: only when the staff member sets "all-day events" handling to "block the whole day" or "ignore", we read the list of events on the selected calendars for the period being checked for availability. We use only the date and time, whether it is an all-day event, whether it is shown as busy or free, the event type (birthdays and working locations are not counted), whether it was cancelled, and whether the staff member declined the invitation. We do not use or store event titles, descriptions, attendees or other details.
Why: to put bookings on the staff member's calendar, and to decide, as the staff member chose, whether to accept bookings on days with all-day events.
1-2. What we store, where, and how we protect it
- What we store: the keys used to access Google (refresh token and access token), the scopes actually granted, the calendar that events are written to (the primary calendar), and when the connection was made; for each booking type, the IDs of the calendars the staff member selected; for each booking, the ID of the event the Service created and, if writing the event failed, the reason.
- Where: the Service's database (Cloudflare D1).
- How: tokens are encrypted with AES-GCM (256-bit key) before they are stored. The encryption key is kept separately from the database (in the server's secret settings), so the tokens cannot be read from the database contents alone. All communication with Google uses HTTPS.
- What we do not store: event contents such as titles, descriptions, attendees and locations; availability (busy time ranges); calendar names. The email address received at sign-in is used only for matching and is not newly stored (a staff member's email address is registered by us when the staff member is added).
- To investigate failures, the Service may write error responses from Google (up to 500 characters) and the reason for the failure to the server's execution logs.
1-3. No sharing, no selling, no advertising, no AI training
- We use Google user data only to provide the features of the Service described in 1-1.
- We do not sell Google user data.
- We do not use it for advertising, including personalized or interest-based advertising.
- We do not transfer it to third parties, except to the infrastructure that runs the Service (Cloudflare, for storage and processing) and when required by law.
- We do not use it to develop, improve or train AI or machine learning models, including generalized models.
- No person at BARCO Inc. reads it, except with the staff member's consent, when necessary for security purposes (such as investigating abuse), or to comply with applicable law.
1-4. Disconnecting and deletion
- There is no button in AIMALON Booking to disconnect Google (the settings screen only offers "reconnect Google Calendar").
- To disconnect, remove the Service's access under "Third-party apps & services" in your Google Account (https://myaccount.google.com/connections). After that, the Service can no longer read your calendar and your booking page can no longer show free times. If you sign in to the Service again, Google shows the consent screen, and the connection is made again if you agree.
- Disconnecting does not remove the connection record (including the encrypted tokens) from our database. To have it deleted, contact us at the address below and we will delete the connection record, including the tokens.
2. Customer information
Information about people who make bookings is not Google user data.
- What we receive: name, email address, phone number (if the booking type asks for it), answers to the booking form (such as notes), the booking date and time, and the cancellation reason (if entered). If the customer chooses to receive messages on LINE, we receive their LINE user ID through LINE Login and check whether they are a friend of our LINE Official Account.
- How we use it: to accept, confirm, reschedule and cancel bookings; to send messages about the booking (confirmation emails, reminders, LINE messages); to notify staff; and to write the event to the staff member's Google Calendar. If set on the booking type, to manage friends of our LINE Official Account (such as adding tags).
- Service providers and recipients: Cloudflare (running the Service and storing data), Resend (sending email), LINE (LINE Login and LINE messages), Chatwork (notifications to staff), Google (writing events to the staff member's Google Calendar), and L Harness (managing friends of our LINE Official Account, if set on the booking type).
3. Limited Use
AIMALON Booking's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
4. Contact
For questions about this policy or to request deletion of your connection record, please contact:
- Operator
- BARCO Inc.
- Address
- 〒141-0032 東京都品川区大崎4-1-7
- Contact
- contact@barco-re.com