English version
プライバシーポリシー
AIMALON Booking(AIマロン予約)/制定日: 2026年9月24日
株式会社バルコ(以下「当社」)は、予約システム「AIMALON Booking(AIマロン予約)」(以下「本サービス」)で扱う情報を、次のとおり取り扱います。
1. 当社の立場(個人情報の取り扱いの委託)
- 本サービスは、当社が招待した会社(以下「利用会社」)が、自社のお客様の予約を受けるために使うものです。
- 予約する方(お客様)の個人情報は、利用会社が自らの責任で取り扱う情報です。当社は、利用会社から個人情報の取り扱いの委託を受け(個人情報の保護に関する法律 第27条第5項第1号)、利用会社のために本サービスを動かす範囲でだけ取り扱います。
- 利用会社の担当者の情報(ログインに使う Google アカウントなど)は、当社が本サービスを提供するために取り扱います(第 2 節)。
2. Google のユーザーデータ(担当者)
本サービスで Google アカウントを使うのは、予約を受ける担当者だけです。担当者が Google アカウントでログインし、本サービスに Google カレンダーへのアクセスを許可したときに、次のデータを扱います。予約する方(お客様)は Google アカウントを使いません。
2-1. 読む・書くデータと、その理由(許可の範囲ごと)
ログイン(openid・email)
読むもの: Google アカウントのメールアドレスと、そのアドレスが確認済みかどうか。
理由: ログインした方が、登録済みの担当者のどなたかを決めるためだけに使います。登録済みの担当者のメールアドレスと一致しなければ、ログインさせず、Google から受け取ったものを保存しません。
空き時間(calendar.events.freebusy)
読むもの: 担当者が選んだカレンダー(選んでいなければメインのカレンダー)で「予定あり」になっている時間帯(開始と終了の時刻だけ)。
理由: 予約ページに空いている時間だけを出すため、予約を受ける直前にその時間が空いているかを確かめるため、担当者の設定画面と予約枠の編集画面で、実際に予約できる時間の見本を担当者本人に見せるため。予約ページには空いている時間だけを出し、予定の名前や内容は出しません。読んだ時間帯は保存しません。
カレンダーの一覧(calendar.calendarlist.readonly)
読むもの: 担当者の Google アカウントで見えるカレンダーの ID・名前・メインのカレンダーかどうか・担当者の権限。
理由: 予約枠の設定画面で、空き時間の確認に使うカレンダーを担当者が選べるように、担当者本人に一覧を見せるため。保存するのは担当者が選んだカレンダーの ID だけで、カレンダーの名前は保存しません。
予定の読み書き(calendar.events)
書くもの: 予約が入ると、担当者のメインのカレンダーに予定を 1 件作ります。件名は予約枠の名前と予約者のお名前、説明には予約者のお名前・メールアドレス・電話番号・会議 URL・予約フォームの答え・予約番号、場所には会議 URL または場所の案内を入れます。日時が変わったら予定を直し、キャンセルされたら予定を消します。変更・削除するのは本サービスが作った予定だけです。
読むもの: 担当者が「終日の予定の扱い」を「すべて休み」または「無視」にしたときだけ、選んだカレンダーの、空き時間を調べる期間の予定の一覧を読みます。使うのは、日時・終日の予定かどうか・「予定あり/予定なし」・予定の種類(誕生日と勤務場所は予定として数えません)・取り消された予定かどうか・担当者が招待を辞退したかどうかだけです。予定の名前・説明・参加者などは使わず、保存しません。
理由: 予約を担当者のカレンダーに載せるため。終日の予定がある日に予約を受けるかどうかを、担当者が選んだとおりに決めるため。
2-2. 保存するもの・場所・守り方
- 保存するもの: Google にアクセスするための鍵(リフレッシュトークンとアクセストークン)、実際に許可された範囲(スコープ)、予定を書き込むカレンダー(メインのカレンダー)、連携した日時。予約枠ごとに、担当者が選んだカレンダーの ID。予約ごとに、本サービスが作った予定の ID と、予定の書き込みに失敗したときの理由。
- 場所: 本サービスのデータベース(Cloudflare D1)。
- 守り方: 鍵(トークン)は AES-GCM(256 ビットの鍵)で暗号化してから保存します。暗号化の鍵はデータベースとは別の場所(サーバーの秘密の設定)に置いており、データベースの中身だけでは鍵(トークン)を読めません。Google との通信はすべて HTTPS です。
- 保存しないもの: 予定の名前・説明・参加者・場所などの予定の中身、空き時間(「予定あり」の時間帯)、カレンダーの名前。ログインで受け取ったメールアドレスは照合にだけ使い、新たには保存しません(担当者のメールアドレスは、その担当者を招待・登録したときに登録したものです)。
- 障害を調べるため、Google からのエラーの応答(最大 500 文字)と失敗の理由を、サーバーの実行記録(ログ)に出すことがあります。
2-3. 共有しない・売らない・広告や AI の学習に使わない
- Google のユーザーデータは、上の 2-1 に書いた本サービスの機能を提供するためにだけ使います。
- Google のユーザーデータを売りません。
- 広告(利用者の関心にあわせた広告を含む)に使いません。
- 第三者に渡しません。ただし、本サービスを動かす基盤(Cloudflare。データの保存と処理)に預ける場合と、法令に基づく場合を除きます。
- AI や機械学習のモデル(汎用のものを含む)の開発・改良・学習に使いません。
- 当社の人が読むことはしません。ただし、担当者本人の同意がある場合、セキュリティのため(不正な利用の調査など)に必要な場合、法令に基づく場合を除きます。
2-4. 連携の解除と削除
- 本サービスの画面には、Google との連携を解除するボタンはありません(設定画面にあるのは「Google カレンダーを繋ぎ直す」だけです)。
- 解除するには、Google アカウントの「サードパーティ製のアプリとサービス」(https://myaccount.google.com/connections)で、本サービスのアクセスを削除してください。解除すると本サービスはカレンダーを読めなくなり、その担当者の予約ページは空いている時間を出せなくなります。そのあと本サービスにログインし直すと、Google の同意の画面が出て、同意すると再び連携されます。
- 解除しても、暗号化した鍵(トークン)などの連携の記録はデータベースに残ります。削除をご希望の場合は、下のお問い合わせ先にご連絡ください。連携の記録(鍵を含む)を削除します。
3. 予約する方(お客様)の情報(利用会社からの委託)
- 受け取るもの: お名前、メールアドレス、電話番号(予約枠が求める場合)、予約フォームの答え(備考など)、予約の日時、キャンセルの理由(入力した場合)。LINE で受け取ることを選んだ場合は、LINE ログインで LINE のユーザー ID を受け取り、利用会社の LINE 公式アカウントの友だちかどうかを確かめます。
- 使い道: 利用会社の予約の受付・確認・日時の変更・キャンセル、予約についてのお知らせ(確認のメール・リマインド・LINE)、利用会社の担当者への通知、担当者の Google カレンダーへの予定の書き込み。利用会社が設定した場合は、利用会社の LINE 公式アカウントでの友だちの管理(タグ付けなど)。当社が自らの目的(広告・営業・分析・AI の学習など)に使うことはありません。
- 預け先・送り先(当社が使う外部のサービス): Cloudflare(本サービスの実行とデータの保存)、Resend(メールの送信)、Google(担当者の Google カレンダーへの予定の書き込み)。利用会社が自社の鍵をつないだ場合は、LINE(LINE ログインと LINE でのお知らせ)、Chatwork(担当者への通知)、L Harness(LINE 公式アカウントの友だちの管理)。
- 分けて保管: 利用会社ごとに別のデータベースに保存します。利用会社がつないだ外部サービスの鍵は、利用会社ごとに別の鍵で暗号化して保存します。
- 当社の人が見るとき: 利用会社の許可がある場合と、障害の対応に必要な場合だけです。見たときは記録を残します。
- お客様からの開示・訂正・削除などのご依頼: 予約を受けた利用会社にお申し出ください。当社に届いた場合は、利用会社に取り次ぎます。
- 利用の終了: 利用会社が本サービスの利用を終えたときは、利用終了の日から30日以内に、その会社のデータベース(お客様と担当者の情報を含みます)を削除します。その間は、利用会社の求めに応じてデータの取り出しに応じます。削除したデータは戻せません。
4. 委託先と、外国にある事業者への提供(個人情報の保護に関する法律 第28条)
当社は、本サービスを動かすために、次の事業者に個人データの取り扱いの一部を任せています(利用会社から受けた委託の再委託を含みます)。
- Cloudflare, Inc.(アメリカ合衆国): 本サービスの実行とデータの保存(データベースを含みます)。同社の設備は世界各地にあり、処理がアメリカ合衆国のほかの国で行われることがあります。
- Resend(アメリカ合衆国): メールの送信(予約の確認・リマインド・担当者への通知)。
- Google LLC(アメリカ合衆国): 担当者の Google アカウントでのログインと、担当者の Google カレンダーへの予定の書き込み。
- LINEヤフー株式会社(日本): LINE ログインと LINE でのお知らせ(利用会社が自社の LINE 公式アカウントをつないだ場合)。
利用会社が自社の鍵をつないだ Chatwork・L Harness には、利用会社が自ら契約したサービスとして、利用会社の設定に従って送ります。
このうち外国にある事業者(アメリカ合衆国の Cloudflare, Inc.・Resend・Google LLC)について、同法 第28条に基づき、次のとおり情報を提供します。
- 外国の名称: アメリカ合衆国(Cloudflare, Inc. は、ほかの国の設備で処理することがあります)。
- その国の個人情報の保護の制度: 個人情報保護委員会の「外国における個人情報の保護に関する制度等の調査」(https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/#gaikoku)で確かめられます。アメリカ合衆国には、日本の個人情報の保護に関する法律に相当する、連邦の包括的な個人情報の保護の法律はなく、分野ごとの連邦の法律と州の法律(カリフォルニア州消費者プライバシー法など)で保護されています。
- 講じている措置: 各事業者とは、個人データを本サービスの提供のほかに使わないこと、安全管理のための措置をとることなどを定めた利用の条件(データの取り扱いの取り決めを含みます)のもとで取引しています。当社の側でも、利用会社ごとにデータベースを分ける、外部サービスの鍵と Google の鍵を暗号化して保存する、通信をすべて HTTPS にする、といった措置をとっています。各事業者がこれらを守っているかは、各事業者が公表するセキュリティの情報と第三者の認証・監査の報告で、年に1回以上確かめます。
- これらの措置について詳しい情報をお求めの場合は、下のお問い合わせ先にご連絡ください。
委託先(再委託先)を追加・変更するときは、前もってこのページでお知らせします。
5. Google API のデータの限定的な使用(Limited Use)
AIMALON Booking's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
(和訳)AIMALON Booking が Google API から受け取った情報の使用と、ほかのアプリへの移転は、Limited Use の要件を含む Google API サービスのユーザーデータに関するポリシーに従います。
6. お問い合わせ
このポリシーについてのご質問、連携の記録の削除のご依頼は、次までご連絡ください。
- 運営者
- 株式会社バルコ(BARCO Inc.)
- 所在地
- 〒141-0032 東京都品川区大崎4-1-7
- お問い合わせ
- contact@barco-re.com
日本語
Privacy Policy
AIMALON Booking / Effective date: September 24, 2026
BARCO Inc. ("we") handles information in the booking system "AIMALON Booking" (the "Service") as described below.
1. Our role (processing on behalf of Client Companies)
- The Service is used by companies we invite ("Client Companies") to receive bookings from their own customers.
- Personal information of customers who make bookings is handled under each Client Company's responsibility. We process it on behalf of the Client Company, only to the extent needed to run the Service for them.
- Information about Client Companies' staff (such as the Google account used to sign in) is handled by us to provide the Service (Section 2).
2. Google user data (staff)
Only staff members who receive bookings use a Google account with the Service. We handle the data below when a staff member signs in with their Google account and allows the Service to access their Google Calendar. People who make bookings (customers) do not use a Google account.
2-1. Data we read or write, and why (by scope)
Sign-in (openid, email)
What we read: the Google account email address and whether it is verified.
Why: only to determine which registered staff member is signing in. If the address does not match a registered staff member, sign-in is refused and nothing received from Google is stored.
Availability (calendar.events.freebusy)
What we read: the busy time ranges (start and end times only) on the calendars the staff member selected (or their primary calendar if none are selected).
Why: to show only free times on the booking page, to check that a time is still free just before accepting a booking, and to show the staff member a preview of the times that can actually be booked, in their settings and when editing a booking type. The booking page shows only free times, never event titles or details. The busy time ranges are not stored.
Calendar list (calendar.calendarlist.readonly)
What we read: the ID, name, whether it is the primary calendar, and the staff member's access role for each calendar visible in their Google account.
Why: to show the list to the staff member themselves in the booking settings, so they can choose which calendars are checked for availability. We store only the IDs of the calendars they choose, not the calendar names.
Reading and writing events (calendar.events)
What we write: when a booking is made, we create one event on the staff member's primary calendar. The title contains the booking type name and the customer's name; the description contains the customer's name, email address, phone number, meeting URL, answers to the booking form and the booking number; the location contains the meeting URL or the place. We update the event when the booking is rescheduled and delete it when the booking is cancelled. We only change or delete events that the Service created.
What we read: only when the staff member sets "all-day events" handling to "block the whole day" or "ignore", we read the list of events on the selected calendars for the period being checked for availability. We use only the date and time, whether it is an all-day event, whether it is shown as busy or free, the event type (birthdays and working locations are not counted), whether it was cancelled, and whether the staff member declined the invitation. We do not use or store event titles, descriptions, attendees or other details.
Why: to put bookings on the staff member's calendar, and to decide, as the staff member chose, whether to accept bookings on days with all-day events.
2-2. What we store, where, and how we protect it
- What we store: the keys used to access Google (refresh token and access token), the scopes actually granted, the calendar that events are written to (the primary calendar), and when the connection was made; for each booking type, the IDs of the calendars the staff member selected; for each booking, the ID of the event the Service created and, if writing the event failed, the reason.
- Where: the Service's database (Cloudflare D1).
- How: tokens are encrypted with AES-GCM (256-bit key) before they are stored. The encryption key is kept separately from the database (in the server's secret settings), so the tokens cannot be read from the database contents alone. All communication with Google uses HTTPS.
- What we do not store: event contents such as titles, descriptions, attendees and locations; availability (busy time ranges); calendar names. The email address received at sign-in is used only for matching and is not newly stored (a staff member's email address is the one registered when the staff member was invited or added).
- To investigate failures, the Service may write error responses from Google (up to 500 characters) and the reason for the failure to the server's execution logs.
2-3. No sharing, no selling, no advertising, no AI training
- We use Google user data only to provide the features of the Service described in 2-1.
- We do not sell Google user data.
- We do not use it for advertising, including personalized or interest-based advertising.
- We do not transfer it to third parties, except to the infrastructure that runs the Service (Cloudflare, for storage and processing) and when required by law.
- We do not use it to develop, improve or train AI or machine learning models, including generalized models.
- No person at BARCO Inc. reads it, except with the staff member's consent, when necessary for security purposes (such as investigating abuse), or to comply with applicable law.
2-4. Disconnecting and deletion
- There is no button in AIMALON Booking to disconnect Google (the settings screen only offers "reconnect Google Calendar").
- To disconnect, remove the Service's access under "Third-party apps & services" in your Google Account (https://myaccount.google.com/connections). After that, the Service can no longer read your calendar and your booking page can no longer show free times. If you sign in to the Service again, Google shows the consent screen, and the connection is made again if you agree.
- Disconnecting does not remove the connection record (including the encrypted tokens) from our database. To have it deleted, contact us at the address below and we will delete the connection record, including the tokens.
3. Customer information (processed on behalf of Client Companies)
- What we receive: name, email address, phone number (if the booking type asks for it), answers to the booking form, the booking date and time, and the cancellation reason (if entered). If the customer chooses LINE, we receive their LINE user ID through LINE Login and check whether they are a friend of the Client Company's LINE Official Account.
- How we use it: only to run the Client Company's bookings (accepting, confirming, rescheduling and cancelling; confirmation emails, reminders and LINE messages; notifying staff; writing events to the staff member's Google Calendar; and, if set by the Client Company, managing friends of its LINE Official Account). We never use it for our own purposes such as advertising, sales, analytics or AI training.
- Service providers: Cloudflare (running the Service and storing data), Resend (sending email), Google (writing events to staff calendars); and, if the Client Company connects its own keys, LINE, Chatwork and L Harness.
- Each Client Company's data is stored in a separate database. Keys for external services connected by a Client Company are encrypted with a key specific to that company.
- Our staff look at the data only with the Client Company's permission or when necessary to handle an incident, and we keep a record when we do.
- Requests from customers (access, correction, deletion, etc.) should be made to the Client Company that received the booking. If we receive one, we forward it to that company.
- When a Client Company stops using the Service, we delete that company's database (including customer and staff information) within 30 days after the end of use. During that period, we provide the data to the Client Company on request. Deleted data cannot be restored.
4. Service providers and transfers to foreign countries (Article 28 of Japan's Act on the Protection of Personal Information)
To run the Service, we entrust part of the handling of personal data to the following providers (including sub-entrustment of what Client Companies entrust to us):
- Cloudflare, Inc. (United States): running the Service and storing data. Its facilities are located around the world, and processing may take place in countries other than the United States.
- Resend (United States): sending email.
- Google LLC (United States): staff sign-in with Google and writing events to staff calendars.
- LY Corporation (Japan): LINE Login and LINE messages (if the Client Company connects its own LINE Official Account).
Chatwork and L Harness receive data only when a Client Company connects its own keys, as services contracted by that Client Company.
Information on the personal information protection system of the United States is available in the survey by Japan's Personal Information Protection Commission (https://www.ppc.go.jp/personalinfo/legal/kaiseihogohou/#gaikoku). The United States has no comprehensive federal privacy law equivalent to Japan's Act; personal information is protected by sector-specific federal laws and state laws (such as the California Consumer Privacy Act). We work with each provider under terms (including data processing terms) that prohibit use of personal data other than to provide the Service and require security measures. We also separate databases per Client Company, encrypt stored keys and tokens, and use HTTPS for all communication. We check each provider's compliance at least once a year through its published security information and third-party certifications or audit reports. Please contact us for more information about these measures.
We will announce any addition or change of providers on this page in advance.
5. Limited Use
AIMALON Booking's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
6. Contact
- Operator
- BARCO Inc.
- Address
- 〒141-0032 東京都品川区大崎4-1-7
- Contact
- contact@barco-re.com