Task Relay Sync プライバシーポリシー
本ポリシーは、株式会社クリエイターズマッチ(以下「当社」)が提供する Google Workspace アドオン
Task Relay Sync(以下「本アドオン」)が取得・利用・保存する情報と、その取り扱いについて説明するものです。
本アドオンは、Google スプレッドシートと、お客様が指定する Salesforce 組織との間でデータを双方向に同期します。
サービス全体の概要はサービス概要をご覧ください。
| 提供者 |
株式会社クリエイターズマッチ |
| 所在地 |
〒105-0021 東京都港区東新橋2丁目6-10 大東城ビル 8F |
| お問い合わせ |
お問い合わせフォーム |
| 最終更新日 |
[要確認:YYYY年M月D日] |
1. 取得する情報と利用目的
本アドオンは、以下の情報をお客様が本アドオンを操作したときにのみ取得・処理します。
| 情報 |
取得元 |
利用目的 |
| 本アドオンを開いているスプレッドシートのセルデータ |
現在開いているスプレッドシート |
Salesforce への送信(データ送信)、および Salesforce から取得したレコードの書き込み(データ取得) |
| 項目マッピング・同期条件・対象オブジェクトなどの設定 |
お客様の入力 |
次回以降の同期動作の再現 |
| Salesforce のアクセストークン・リフレッシュトークン、および接続先の区分(本番/Sandbox) |
Salesforce の認可画面でお客様が「許可」した結果として発行されるもの |
お客様の許可した範囲で Salesforce API へアクセスするため |
| 言語(ロケール)設定 |
Google スプレッドシートの設定 |
アドオン画面の表示言語の切り替え |
本アドオンが Salesforce のパスワードを受け取ることはありません。認証は Salesforce の画面上で行われ、
本アドオンは発行されたトークンのみを受け取ります。
2. 情報の保存場所
- 項目マッピングや同期条件などの設定は、Google が提供する
スプレッドシート単位の保存領域(Properties Service)に保存され、当該スプレッドシートに紐づきます。
- Salesforce のアクセストークン・リフレッシュトークンは、Google が提供する
ユーザー単位の保存領域(Properties Service)に保存され、当該 Google アカウントに紐づきます。
他のユーザーから参照されることはありません。
- いずれも当社のサーバーには保存されません。
本アドオンは、お客様のスプレッドシートの内容を当社のデータベースに保存しません。
3. 第三者への送信・共有
- スプレッドシートのデータは、お客様自身が指定した Salesforce 組織との同期のためにのみ送信されます。
- Salesforce API との通信は、当社が運用する IAM 認証で保護された中継サーバーを経由します。
中継サーバーは Salesforce のドメインへリクエストを転送するのみで、
リクエスト・レスポンスの本文を保存しません(パススルー)。
監査ログには通信のメタデータ(HTTP メソッド、宛先のホストとパス、ステータス、所要時間、サイズ)のみを記録し、
アクセストークン・認証ヘッダー・クエリ文字列・本文は記録しません。
- Salesforce へのログイン・認可およびトークンの取得・更新に関する通信は、
中継サーバーを経由せず Salesforce のドメインへ直接行われます。
- 上記およびお客様自身の Salesforce 組織を除き、取得した情報を第三者へ販売・貸与・提供することはありません。
4. Google ユーザーデータの限定的使用(Limited Use)
本アドオンによる Google API から取得した情報の使用および他者への移転は、
Google API サービスのユーザーデータに関するポリシー
(その「限定的使用(Limited Use)」要件を含む)に準拠します。
具体的には、取得したデータについて以下を遵守します。
- 本ポリシー第1条に記載した機能の提供にのみ使用します。
- 広告目的では一切使用しません。
- 第三者へ販売しません。
- 人による閲覧は行いません。ただし、お客様の明示的な同意がある場合、セキュリティ目的の場合、
法令を遵守するために必要な場合、または集計・匿名化された情報を扱う場合を除きます。
5. 本アドオンが要求するアクセス権限
| 権限 |
必要な理由 |
現在開いているスプレッドシートの参照・編集
(spreadsheets.currentonly) |
アドオンを開いている当該スプレッドシートのみを読み書きするために必要です。他のスプレッドシートへのアクセス権限は要求しません。 |
使用中のファイルへのアクセス
(drive.file) |
アドオンが操作対象とする当該ファイルのみにアクセスする最小権限です。Google ドライブ全体へのアクセス権限は要求しません。 |
外部サービスへの接続
(script.external_request) |
Salesforce の認可・トークン取得、および中継サーバーを経由した Salesforce API の呼び出しに必要です。 |
トリガーの管理
(script.scriptapp) |
自動取得・自動送信のスケジュール実行に必要です。 |
設定の保存
(script.storage) |
項目マッピングや接続設定を保存するために必要です。 |
ロケールの参照
(script.locale) |
ご利用中の言語設定に合わせて画面を表示するために必要です。 |
6. データの保持と削除
- 設定は、お客様が本アドオンの画面で削除するか、当該スプレッドシートを削除するまで保持されます。
- Salesforce のトークンは、本アドオンの「接続解除」を実行するか、Google アカウント側で
本アドオンへのアクセス権を取り消すまで保持されます。
- 同期処理に伴うスプレッドシート内容の処理は一時的なものであり、処理後に当社側へ残存しません。
- Salesforce 側でのアクセス許可の取り消しは、Salesforce の「接続アプリケーションの OAuth 利用状況」から行えます。
- 削除に関するご相談はお問い合わせフォームよりご連絡ください。
7. セキュリティ
- 通信はすべて HTTPS で暗号化されます。
- Salesforce への接続には OAuth 2.0 の Web サーバーフロー(PKCE 併用)を使用します。
本アドオンがお客様の Salesforce パスワードを保持することはありません。
- 当社が運用する中継サーバーは IAM 認証で保護され、許可されたサービスアカウントのみが呼び出せます。
- トークンおよび設定は、Google が提供する保存領域に保持され、当社のサーバーへは複製されません。
8. 本ポリシーの変更
本ポリシーは、法令の改正やサービス内容の変更に応じて改定される場合があります。
重要な変更がある場合は、本ページまたはアドオン内でお知らせします。
9. お問い合わせ
本ポリシーに関するお問い合わせは、お問い合わせフォームよりご連絡ください。
English
Overview
This policy explains how Task Relay Sync (the “Add-on”), a Google Workspace Add-on provided by
CREATORS MATCH Ltd. (the “Provider”), accesses, uses, and stores information. The Add-on synchronizes data
bidirectionally between Google Sheets and a Salesforce organization specified by the user.
Information We Access
The Add-on accesses the following only while the user actively uses it:
- Cell data of the spreadsheet in which the Add-on is opened — to push to Salesforce and to write records fetched from Salesforce.
- Field mappings, sync conditions, and target object settings — to reproduce sync behavior.
- Salesforce access and refresh tokens, and the login environment (production or sandbox), issued when the user approves access in Salesforce’s own authorization screen.
- Locale setting — to localize the Add-on UI.
The Add-on never receives the user’s Salesforce password.
Where Information Is Stored
- Settings are stored in Google’s per-spreadsheet Properties Service storage.
- Salesforce tokens are stored in Google’s per-user Properties Service storage.
- Neither is stored on the Provider’s servers. The Add-on does not store spreadsheet contents in any Provider database.
Disclosure / Sharing
- Spreadsheet data is transmitted only to the Salesforce organization specified by the user.
- Salesforce API traffic passes through a Provider-operated, IAM-authenticated relay that forwards requests to Salesforce domains only and does not store request or response bodies. Audit logs record metadata only (HTTP method, destination host and path, status, duration, size) and never access tokens, authorization headers, query strings, or bodies.
- Salesforce authorization and token requests go directly to Salesforce domains, bypassing the relay.
- We do not sell, rent, or otherwise share the accessed information with third parties.
Limited Use of Google User Data
The Add-on’s use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. Data is used solely to provide the features described above;
it is not used for advertising, is not sold to third parties, and is not read by humans except with the user’s
explicit consent, for security purposes, to comply with applicable law, or when aggregated and anonymized.
Retention and Deletion
Settings persist until deleted by the user or until the spreadsheet is deleted. Salesforce tokens persist until the
user disconnects in the Add-on or revokes access from their Google account. Processing of spreadsheet content during
sync is transient and does not persist on the Provider side.
Contact
For questions about this policy, please use the contact form.