店家客戶管理 隱私權政策
一、適用範圍
「店家客戶管理」(以下稱本服務)包含 iPhone App 與電腦版程式,讓自己當老闆的店家(例如汽車修配廠、美甲美睫、電商網拍)管理客戶、車輛、預約與服務紀錄。本服務的提供者為 JIAN TING JIANG;本政策中的「我們」指本服務的提供者與營運團隊。
本服務的帳號只能由我們替店家建立,不開放自行註冊。
二、我們處理哪些資料
- 店家帳號資料:登入用的電子郵件、顯示名稱、所屬店家與角色(老闆或員工)。店家選擇用 Apple 或 Google 登入時,我們會收到該服務提供的帳號識別碼與電子郵件;使用 Apple「隱藏我的電子郵件」時,收到的是轉寄地址。
- 店家輸入的營業資料:客戶(個人或公司)的姓名、電話、電子郵件、地址與備註;聯絡人;車輛的車牌、廠牌車型、年份、車身號碼、引擎號碼與里程;預約、服務與消費紀錄(品項、金額、付款方式);待辦與互動紀錄;商機;商品與庫存;訂單,包含收件人姓名、電話與地址;以及店家在程式中建立的其他紀錄。這些資料屬於店家,由店家決定輸入哪些內容。
- 辨識用的照片與文字:店家使用「認車」時拍攝或選取的行照照片,以及輸入的車身號碼或描述。行照照片可能含有車主姓名、地址等資料。
- 回報問題:店家按程式右上角「回報問題」,或更新失敗自動回報時,會送出這台電腦的診斷資訊(版本、系統、當時的畫面位置、資料筆數、錯誤紀錄),不含客戶資料。
- 按鈕使用統計:為了改善按鈕的位置,程式會記錄每個按鈕在哪一頁被按了幾次,以及按之前在那一頁點了幾下、開著幾層視窗,並附上程式版本與帳號的角色(老闆或員工、職務與權限組合)。只記按鈕的代號與次數,不記畫面上的文字、輸入的內容,也不記任何客人或車牌資料。每台電腦或手機每天彙總送一次;帳號以代碼存放,報表不顯示帳號。老闆可以在「設定 › 隱私與個資」關掉「分享使用統計」,關掉後整家店都不再記錄、也不再送出。
- 品項與零件知識:店家輸入的品項名稱、分類與價格範圍,會先去除店家名稱、客人、車牌、電話等可以認出人或店的資料,再彙整成所有店家共用的零件知識庫,用來改善辨識與比對,例如同一個零件的不同寫法、合理的價格範圍。
- 裝置資訊:為了帳號安全(例如找出異常登入、停用遺失的裝置),伺服器會記錄每台登入過的裝置的名稱、系統、程式版本、第一次與最後使用時間,以及最後使用時的 IP 位址。這些只用於帳號安全,不會跟按鈕使用統計交叉比對。
- OBD 讀車資料(程式內「雲端資料告知」第 11 條):店家使用 OBD 讀車功能(快速讀取、完整拷貝)時,這次讀到的結果會送一份到我們的伺服器。
- 用途:驗證車輛資料庫(哪些車款真的回應哪些代碼、數值是否合理)、改進讀取與自動認車、改進故障碼的中文說明。不會用於行銷、轉售、評比店家或追蹤車主。
- 收哪些:車輛的品牌、車型、年份、引擎、變速箱(取自店家登記的車輛資料)、完整車身號碼(車上讀得到的,讀不到時用店裡登記的)、故障碼、車輛的原始回應與讀值,以及讀卡器型號、程式版本、電壓、里程(車上讀得到時)等讀車當下的資訊。完整車身號碼用來辨認車款與年份、確認這台車該用哪一套讀法。不收車主姓名與電話、車牌、店裡的客戶或車輛代號、工單內容、照片,也不收位置。
- 存在哪:我們在台灣自行管理的伺服器。完整車身號碼配合店裡的資料可以對回車主,所以跟讀車報告分開存放(報告裡只用代碼對應,另外留前 3 碼、第 4~8 碼、第 10 碼),每日備份時加密;管理者每次讀取、自動整理程式每一批讀取,都會留下紀錄。讀車的原始回應裡如果出現車身號碼,伺服器存檔前會先遮掉,完整號碼只另存這一處。伺服器會記下是哪一家店送的,只用於防止濫用與追查問題。車輛資料庫只收從車身號碼推出來的廠牌、車型代碼與年份,以及有沒有回應、讀到的值、這台車用哪一套讀法等驗證結果,不含車身號碼的序號段,也不含店家與車主資料。
- 保留多久與誰看得到:見第五、六節。
- 不能單獨關閉:這些資料是讓讀車功能更準的必要資料,所以使用 OBD 讀車就會一起送出,不能單獨關閉;使用 OBD 讀車功能,就表示同意這項收集。不想送出,請不要使用 OBD 讀車功能,其他功能不受影響。這項收集在店家同意這一版條款之後才會開始。
- 我們不收集:廣告識別碼、位置資訊、通訊錄或健康資料。App 內沒有廣告,也沒有第三方分析或追蹤工具。
三、資料存放在哪裡
- 雲端:提供者在台灣自行管理的伺服器(包含帳號與登入)。資料在網路上傳送時全程加密,經 Cloudflare 的加密通道轉送,Cloudflare 不保存店家資料。伺服器每天備份,備份保留 30 天,並另存一份在提供者的網路儲存設備。
- 店家的電腦:電腦版程式在店家電腦保存一份資料,並與伺服器同步。
- 手機:App 會在手機上暫存資料,方便沒有網路時使用;登出時清除。
- 更新前的備份:電腦版更新前,會自動把資料備份到店家電腦的「文件/客戶管理系統備份」資料夾。這份備份只存在店家電腦,不會上傳。
- 檢查更新:電腦版檢查新版本時會連到 GitHub,不會傳送任何店家資料。
四、人工智慧處理
店家使用人工智慧功能時(電腦版與手機相同),當次需要的資料會先送到我們的人工智慧處理服務(由本服務營運團隊管理的主機),再由它透過 OpenRouter 送到人工智慧模型供應商(例如 Google Gemini)處理;這些服務依其各自的隱私權政策處理傳入的資料。給人工智慧的指示與人工智慧金鑰只放在我們的處理服務,不在店家的電腦裡。各功能送出的內容如下:
- 認車:行照照片,或店家輸入的車身號碼、車款描述。照片可能含車主姓名、地址。照片處理完成後即從我們的雲端刪除。
- 查原廠保養資料、零件問答:只送車款(廠牌、車型、年份、引擎)、車身號碼前 11 碼,以及店家輸入的問題,並上網查詢公開的原廠資料;不送車主資料。
- 智慧建檔:店家貼上的對話或文字,可能含客戶姓名、電話。
- 整理分類:客戶資料的摘要。
- 公開資料補齊:只用於公司客戶,上網查詢公開的營業資訊。
- 店家小幫手:使用「小幫手」問問題時,您打的那句話會送到提供者的人工智慧處理主機判斷要帶您去哪裡。送出前,程式會先把這台電腦裡客人的姓名、電話、車牌、電子郵件、地址、統一編號,以及看起來像電話、車牌、身分證字號、電子郵件、地址的文字換成代號;沒有記在客人資料裡的稱呼(例如「王先生」)會照原句送出。為了改善程式,提供者會保存這句話(再遮一次電話、車牌、電子郵件、身分證字號、金額)與使用情形(問了哪一類、有沒有找到);這句話保存 30 天後清空,使用情形的統計保存 180 天,只有提供者看得到,不會給其他店家。
另外,電腦版認車時,17 碼的北美規格車身號碼會送到美國公路交通安全署(NHTSA)的公開解碼服務,查詢車款資料。
五、誰可以看到資料
- 店家:店家老闆與店家授權的員工帳號。員工不能刪除資料。
- 我們:只有在管理帳號、提供技術支援、處理店家回報的問題或備份還原需要時,我們才會查看店家資料。我們不出售、不出租資料,也不用於廣告。
- OBD 讀車資料:讀車報告與完整車身號碼只有我們的管理者與讀車資料處理程式在伺服器本機讀得到,其他店家看不到;車輛資料庫只有我們的維護人員使用。店家自己的讀車結果照常存在店裡的資料,店家看得到的範圍不變。
- 服務供應商:Cloudflare(加密傳輸,不保存店家資料);店家使用人工智慧功能時,另有我們的人工智慧處理服務、OpenRouter 與人工智慧模型供應商;電腦版認車時的美國公路交通安全署(NHTSA)公開車身號碼解碼服務。
- 店家自己開啟的人工智慧操作接口:電腦版有「人工智慧操作接口」(本機網址介面與 MCP),預設關閉。店家自己開啟後,店家指定的本機人工智慧工具(例如 Claude Desktop)可以讀寫店家的資料;要不要開、給哪個工具用,由店家決定並負責。
- 依法要求:法院或主管機關依法要求提供時。
六、保存與刪除
- 店家刪除的紀錄會先標記為已刪除,30 天後從伺服器清除;每日備份保留 30 天後刪除。
- 人工智慧工作:電腦版送出的,拿到結果後立即從雲端刪除;手機送出的,完成 7 天後刪除。
- 每日的人工智慧用量彙總(次數與費用,不含內容)會上傳到雲端,供我們管理額度。
- 店家小幫手:問的那句話(已遮過)保存 30 天後清空;使用情形的統計(問了哪一類、有沒有找到)保存 180 天。
- 按鈕使用統計(每店每天、依帳號代碼分開的次數彙總,不含內容)保存 400 天後刪除。
- OBD 讀車資料:讀車報告與完整車身號碼保存 1 年後自動刪除;車輛資料庫裡的驗證結果(不含完整車身號碼與店家資料)長期保存。
- 店家停止使用時,可以聯絡我們刪除整個店家的帳號與雲端資料。
- 店家的客戶如果想查詢、更正或刪除自己的資料,請直接聯絡該店家,店家可以在程式中修改或刪除;我們也會協助店家處理。
七、資料安全
資料傳輸一律加密(HTTPS);雲端依帳號與角色限制存取;電腦版保存的金鑰經過加密。
八、兒童
本服務供店家營業使用,不是為兒童設計。
九、政策變更
政策更新時會修改本頁並標示日期;有重大變更時會在 App 內通知。
十、聯絡我們
對本政策有疑問,或要查詢、刪除資料,請來信 [email protected]。
Shop CRM Privacy Policy
1. Scope
Shop CRM (the "Service"), consisting of the iPhone app and the desktop app, helps owner-operated shops (such as car repair shops, nail and beauty salons, and online sellers) manage customers, vehicles, appointments and service records. The Service is provided by JIAN TING JIANG; in this policy, "we" means the provider and the team operating the Service.
Accounts are created by us for each shop. Public sign-up is not available.
2. Data we process
- Shop account data: sign-in email, display name, shop and role (owner or staff). If a shop signs in with Apple or Google, we receive the account identifier and email provided by that service (a relay address if Apple's "Hide My Email" is used).
- Business data entered by the shop: names, phone numbers, emails, addresses and notes of customers (individuals or companies); contacts; vehicle plates, make and model, year, VIN, engine number and mileage; appointments and service or purchase records (items, amounts, payment method); tasks and interaction records; deals; products and inventory; orders, including recipient names, phone numbers and addresses; and any other records the shop creates in the app. This data belongs to the shop, which decides what to enter.
- Photos and text for vehicle identification: registration photos taken or selected in "Identify", and VINs or descriptions typed in. Registration photos may include the owner's name and address.
- Problem reports: when the shop presses "Report a problem" in the app, or when an update fails, diagnostic information about that computer (version, system, current screen, record counts, error logs) is sent to us. It contains no customer data.
- Button usage statistics: to improve where buttons are placed, the app records how many times each button is pressed on each page, how many clicks were made on that page before it and how many windows were open, together with the app version and the account's role (owner or staff, position and permission set). Only button codes and counts are recorded — never on-screen text, anything typed, or any customer or plate data. Each computer or phone sends a daily summary once a day; accounts are stored as codes and reports do not show accounts. The owner can turn off "Share usage statistics" in Settings › Privacy; the whole shop then stops recording and sending.
- Item and parts knowledge: item names, categories and price ranges entered by shops are first stripped of anything that could identify a person or a shop (shop names, customers, plates, phone numbers and the like), then combined into a parts knowledge base shared by all shops to improve identification and matching — for example, different ways of writing the same part, or a reasonable price range.
- Device information: for account security (for example, spotting unusual sign-ins and disabling lost devices), the server records each signed-in device's name, system, app version, first and last use time, and the IP address it last used. This is used only for account security and is never cross-referenced with button usage statistics.
- OBD vehicle-reading data (in-app cloud data notice, item 11): when a shop uses the OBD reading features (Quick read, Full copy), a copy of the results is sent to our server.
- Purpose: to verify the vehicle database (which models actually respond to which codes and whether the values are reasonable), improve reading and automatic vehicle identification, and improve the trouble-code explanations. It is not used for marketing, resale, rating shops or tracking vehicle owners.
- What is collected: the vehicle's brand, model, year, engine and transmission (taken from the vehicle details the shop entered), the full VIN (read from the car, or the one recorded in the shop's data if it can't be read), trouble codes, the vehicle's raw responses and readings, plus information from the moment of reading such as the adapter model, app version, voltage and mileage (when the car reports it). The full VIN is used to identify the model and year and to confirm which reading method the car needs. We do not collect the owner's name or phone number, license plates, the shop's customer or vehicle IDs, work order contents, photos, or location.
- Where it is stored: on a server we manage ourselves in Taiwan. Because the full VIN can be matched back to an owner using the shop's data, it is stored separately from the reading reports (the reports only link to it by a code, and keep the 1st–3rd, 4th–8th and 10th characters), it is encrypted in the daily backups, and every read by an administrator and every batch read by the automatic processing program is logged. If a VIN appears in the raw responses, the server masks it before saving, so the full number is kept in this one separate place only. The server records which shop sent each report, only to prevent abuse and trace problems. The vehicle database only receives the brand, model code and year derived from the VIN, plus verification results such as whether there was a response, the values read and which reading method the car uses — without the VIN's serial-number part and without any shop or owner data.
- Retention and access: see sections 5 and 6.
- Cannot be turned off separately: this data is essential for making vehicle reading more accurate, so it is sent whenever OBD reading is used and cannot be turned off separately; using the OBD reading features means agreeing to this collection. If you don't want it sent, don't use the OBD reading features — other features are not affected. This collection only begins after the shop agrees to this version of the terms.
- We do not collect advertising identifiers, location, the phone's address book or health data. The app has no ads and no third-party analytics or tracking.
3. Where data is stored
- Cloud: servers in Taiwan managed by the provider (including accounts and sign-in). Data is encrypted in transit and relayed through Cloudflare's encrypted tunnel; Cloudflare does not store shop data. The server is backed up daily; backups are kept for 30 days, with an additional copy on the provider's network storage.
- The shop's computer: the desktop app keeps a copy and keeps it in sync with the server.
- Phone: the app caches data on the phone for offline use and clears it on sign-out.
- Backups before updates: before updating, the desktop app automatically backs up its data to the "Documents/客戶管理系統備份" folder on the shop's computer. This backup stays on the shop's computer and is never uploaded.
- Update checks: the desktop app connects to GitHub to check for new versions; no shop data is sent.
4. AI processing
When a shop uses AI features (the desktop and mobile apps work the same way), the data needed for that request is first sent to our AI processing service (a server run by the team operating the Service), which sends it through OpenRouter to AI model providers (such as Google Gemini). These services handle the data under their own privacy policies. AI instructions and AI keys are kept only on our processing service, not on the shop's computer. What each feature sends:
- Identify: a registration photo, or a VIN or vehicle description typed by the shop. Photos may include the owner's name and address. Photos are deleted from our cloud once processing is complete.
- OEM maintenance data and parts Q&A: only the vehicle model (make, model, year, engine), the first 11 characters of the VIN and the shop's question, plus online searches of public manufacturer information. No owner data is sent.
- Smart entry: conversations or text pasted by the shop, which may include customer names and phone numbers.
- Organize and classify: summaries of customer data.
- Public data enrichment: for company customers only, online searches of public business information.
- Shop assistant: when you ask the in-app "Assistant" a question, the sentence you type is sent to the provider's AI processing server to work out where to take you. Before sending, the app replaces the names, phone numbers, plates, emails, addresses and tax IDs of customers stored on that computer, and any text that looks like a phone number, plate, national ID number, email or address, with placeholders; forms of address not stored in customer records (for example "Mr. Wang") are sent as typed. To improve the app, the provider keeps the sentence (masked again for phone numbers, plates, emails, national ID numbers and amounts) and usage information (which kind of question, whether it was found); the sentence is cleared after 30 days and usage statistics are kept for 180 days. Only the provider can see them; they are never shared with other shops.
In addition, when the desktop app identifies a vehicle, a 17-character North American VIN is sent to the U.S. National Highway Traffic Safety Administration (NHTSA) public decoding service to look up the vehicle model.
5. Who can see the data
- The shop: the owner and staff accounts the shop authorizes. Staff cannot delete data.
- Us: we view shop data only when needed to manage accounts, provide technical support, handle a problem reported by the shop, or restore backups. We do not sell or rent data or use it for advertising.
- OBD vehicle-reading data: reading reports and full VINs can only be read on the server itself by our administrators and the reading-data processing program; other shops cannot see them. The vehicle database is used only by our maintenance staff. The shop's own reading results are still saved in the shop's data as before, and what the shop can see does not change.
- Service providers: Cloudflare (encrypted transport; does not store shop data); our AI processing service, OpenRouter and AI model providers when the shop uses AI features; the NHTSA public VIN decoding service when the desktop app identifies a vehicle.
- AI access interface enabled by the shop: the desktop app has an "AI access interface" (a local web API and MCP), which is off by default. If the shop turns it on, local AI tools chosen by the shop (such as Claude Desktop) can read and write the shop's data. Whether to turn it on, and for which tools, is the shop's decision and responsibility.
- Legal requests: when required by a court or authority under law.
6. Retention and deletion
- Records deleted by a shop are marked as deleted and removed from the server after 30 days; daily backups are deleted after 30 days.
- AI requests: those sent from the desktop app are deleted from the cloud as soon as the result comes back; those sent from the phone are deleted 7 days after completion.
- A daily summary of AI usage (counts and costs, no content) is uploaded to the cloud so we can manage usage limits.
- Shop assistant: the (masked) question is cleared after 30 days; usage statistics (which kind of question, whether it was found) are kept for 180 days.
- Button usage statistics (daily per-shop count summaries, kept separately per account code, no content) are deleted after 400 days.
- OBD vehicle-reading data: reading reports and full VINs are automatically deleted after 1 year; verification results in the vehicle database (without full VINs or shop data) are kept long-term.
- When a shop stops using the Service, it can contact us to delete the shop's accounts and cloud data.
- A shop's customers who want to access, correct or delete their data should contact that shop, which can edit or delete it in the app; we will help the shop do so.
7. Security
All data is encrypted in transit (HTTPS); cloud access is restricted by account and role; keys stored by the desktop app are encrypted.
8. Children
The Service is for business use by shops and is not designed for children.
9. Changes
We update this page and its date when the policy changes, and notify users in the app of significant changes.
10. Contact
For questions about this policy, or to access or delete data, email [email protected].