Privacy Policy
Your privacy matters to us. This policy explains how Nextmerce collects, uses, protects, and shares your information when you use our AI-powered ecommerce intelligence platform.
1. Introduction
Nextmerce (“Nextmerce,” “we,” “us,” or “our”) operates the website located at https://nextmerce.app and provides an AI-powered ecommerce intelligence platform (the “Service”) designed to help Shopify merchants analyze business performance, identify profit leaks, optimize advertising spend, and improve profitability through data-driven insights and artificial intelligence.
This Privacy Policy (“Policy”) describes how we collect, use, disclose, and safeguard your information when you visit our website, install our Shopify application, connect third-party advertising platforms, or otherwise interact with our Service. This Policy applies to all users of the Service, including Shopify store owners, authorized team members, and visitors to our website.
By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy. If you do not agree with the practices described in this Policy, please do not access or use the Service. We encourage you to read this Policy carefully and contact us at founder@nextmerce.app if you have any questions.
This Privacy Policy is designed to comply with applicable data protection laws and regulations, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and other applicable privacy frameworks. This Policy also complies with the requirements of the Shopify App Store, TikTok Marketing API, and Meta Platform Terms.
2. Information We Collect
We collect several categories of information to provide, maintain, and improve our Service. The types of information we collect depend on how you interact with our platform and the integrations you choose to enable.
2.1 Personal Information
When you create an account, install our Shopify application, or otherwise interact with our Service, we may collect the following personal information:
- Full name and email address associated with your Shopify account
- Business name, business address, and store URL
- Phone number (if voluntarily provided for account recovery or support purposes)
- Account credentials and authentication tokens generated during the OAuth authorization flow
- Billing and subscription information processed through our payment provider
- Profile preferences, notification settings, and communication preferences
- Any other information you voluntarily provide when contacting support or submitting feedback
2.2 Business & Store Data
To deliver our core intelligence and analytics services, we access and process business data from your connected Shopify store. This data may include:
- Order data, including order values, line items, fulfillment status, refunds, and transaction history
- Product catalog information, including titles, descriptions, variants, pricing, and inventory levels
- Customer data (as permitted by Shopify’s API access scopes), including anonymized purchase patterns and customer segments
- Revenue metrics, gross and net profit calculations, and cost-of-goods-sold (COGS) data
- Shipping costs, tax calculations, and discount code usage data
- Store configuration, theme information, and checkout settings relevant to analytics
2.3 Advertising & Marketing Data
When you connect third-party advertising platforms to Nextmerce, we collect advertising performance data to provide cross-channel attribution and optimization insights:
- TikTok Ads: campaign performance metrics, ad spend, impressions, clicks, conversions, and audience insights via the TikTok Marketing API
- Meta/Facebook Ads: campaign and ad set performance data, spend, reach, conversion events, and attribution data via the Meta Marketing API
- Google Ads and Google Analytics: website traffic data, acquisition channels, user behavior flows, conversion data, and advertising performance metrics
- Attribution data that connects advertising spend to store revenue outcomes
2.4 Usage Data
We automatically collect certain information when you access or use our Service, including:
- Device information: browser type and version, operating system, device type, and screen resolution
- Log data: IP address, access timestamps, pages viewed, features used, and referring URLs
- Interaction data: clicks, scrolls, navigation paths, feature engagement, and session duration
- Performance data: page load times, errors, and diagnostic information
- Geolocation data derived from your IP address (country and region level only)
2.5 Cookies & Tracking Technologies
We use cookies, web beacons, pixels, and similar tracking technologies to collect usage data and improve your experience. These technologies help us understand how users interact with our Service, maintain session state, remember preferences, and measure the effectiveness of our communications. For detailed information about our cookie practices, please see Section 11 of this Policy.
3. How We Use Your Information
We process your information for the following purposes, each supported by a lawful basis under applicable data protection law:
Service Delivery & Performance
- Providing, operating, and maintaining the Nextmerce platform and its core features
- Generating AI-powered business intelligence, anomaly detection alerts, and profitability analytics
- Processing and analyzing your Shopify store data to identify profit leaks and optimization opportunities
- Performing cross-channel advertising attribution and return-on-ad-spend (ROAS) calculations
- Delivering personalized recommendations and actionable insights based on your business data
Account Management & Communication
- Creating, authenticating, and managing your user account
- Processing subscription payments and managing billing cycles
- Sending transactional communications such as account verification, security alerts, and service notifications
- Responding to support inquiries, feedback, and feature requests
- Sending product updates, tips, and educational content (with your consent where required)
Improvement & Development
- Analyzing usage patterns to improve the user experience and develop new features
- Training and improving our AI models and algorithms using aggregated, anonymized data
- Conducting internal research and analytics to measure product performance
- Performing A/B testing and feature experimentation to optimize the Service
Legal & Compliance
- Complying with applicable laws, regulations, legal processes, and governmental requests
- Enforcing our Terms of Service, protecting our rights, and preventing fraud or abuse
- Detecting, investigating, and preventing security incidents and unauthorized access
- Maintaining audit trails and records as required by applicable law
4. Shopify Data Access & Usage
Nextmerce operates as a Shopify application and accesses your store data through Shopify’s authenticated API in compliance with the Shopify App Store Requirements and Shopify API Terms of Service. This section specifically addresses how we handle Shopify merchant data.
4.1 API Access Scopes
During the OAuth installation flow, we request only the minimum API access scopes necessary to deliver our Service. The specific scopes we request and their purposes are:
- read_orders — Access to order data for revenue analysis, profitability calculations, anomaly detection, and trend identification
- read_products — Access to product catalog information for product performance analysis, margin calculations, and inventory insights
- read_customers — Access to customer data for cohort analysis, lifetime value calculations, and retention metrics (data is processed in aggregated and anonymized form)
- read_analytics — Access to store analytics for comprehensive performance dashboards and benchmarking
- read_inventory — Access to inventory levels for stock monitoring, demand forecasting, and inventory optimization recommendations
We do not request write access to your store unless explicitly required for a specific feature, and any such access will be clearly communicated and require your explicit consent before activation.
4.2 How Shopify Data Is Processed
All Shopify store data accessed through the API is processed solely for the purpose of delivering the Nextmerce analytics and intelligence services to you. Specifically:
- Store data is fetched via Shopify’s authenticated REST and GraphQL APIs using encrypted OAuth tokens
- Data is processed in real-time and stored in our secure cloud infrastructure for ongoing analytics
- AI models analyze your data to generate insights, detect anomalies, and surface profit optimization opportunities
- Aggregated, anonymized patterns may be used to improve our AI algorithms without identifying individual merchants or their customers
- We do not sell, rent, or share your raw Shopify store data with any third party
4.3 Data Deletion & Shopify Compliance Webhooks
We comply with Shopify’s mandatory privacy webhooks and data protection requirements:
- Customer Data Request: When we receive a customer data request webhook from Shopify, we respond with all customer-related data we hold within 30 days
- Customer Data Erasure: When we receive a customer erasure request webhook, we delete all associated customer data from our systems within 30 days, except where retention is required by law
- Shop Data Erasure: When you uninstall our application, we receive a shop erasure webhook and delete all associated store data from our systems within 30 days
Upon uninstallation of the Nextmerce app from your Shopify store, we revoke all API access tokens immediately and begin the data deletion process. Backup copies are purged from our systems within 90 days following deletion, in accordance with our backup retention schedule.
4.4 Shopify Customer Data Handling
With respect to end-customer data from your Shopify store (i.e., data about your customers), we act as a data processor on your behalf. We access customer data solely to provide analytics services to you and do not use this data for our own independent purposes, including marketing or advertising. Customer data is processed in aggregated and anonymized form wherever possible, and we implement strict access controls to limit exposure of personally identifiable customer information within our systems.
5. Third-Party Integrations
Nextmerce integrates with third-party platforms to provide comprehensive, cross-channel ecommerce intelligence. When you connect a third-party integration, we access data from that platform in accordance with its API terms, developer policies, and your authorization.
5.1 TikTok Marketing API
When you connect your TikTok Ads account, we access advertising data through the TikTok Marketing API in compliance with the TikTok Marketing API Terms. The data we access includes:
- Campaign, ad group, and ad-level performance metrics (impressions, clicks, conversions, spend)
- Audience and targeting configuration for attribution analysis
- Conversion event data for ROAS calculations and cross-channel attribution
- Account-level information necessary for integration management
We use TikTok advertising data exclusively to provide analytics, attribution reporting, and optimization recommendations within the Nextmerce platform. We do not share your TikTok data with any unauthorized third parties, use it for purposes outside the scope of the Service, or combine it with data from other advertisers. You may disconnect your TikTok account at any time through the Nextmerce settings, after which we will cease accessing new data and delete stored TikTok data within 30 days.
5.2 Meta (Facebook & Instagram) Marketing API
Nextmerce supports integration with the Meta Marketing API for Facebook and Instagram advertising data. When you connect your Meta Ads account, we access data in accordance with the Meta Platform Terms and Meta Developer Policies. The data we access includes:
- Campaign, ad set, and ad performance metrics from Facebook and Instagram Ads
- Ad spend, reach, frequency, and conversion data
- Attribution and conversion event data for cross-channel performance analysis
- Account and business manager information for integration configuration
We process Meta advertising data solely for the purpose of delivering analytics, attribution insights, and advertising optimization recommendations. We do not sell Meta platform data, use it for independent advertising purposes, transfer it to data brokers, or use it in ways that violate Meta’s Platform Terms. Meta data is stored in encrypted form and access is restricted to authorized personnel and automated systems required for service delivery. You may revoke our access at any time through the Nextmerce settings or directly through Meta’s Business Settings.
5.3 Google Analytics & Google Ads
When you connect your Google Analytics (GA4) or Google Ads accounts to Nextmerce, we access website traffic and advertising data through Google’s APIs in compliance with the Google API Services User Data Policy, including its Limited Use requirements.
The data we retrieve includes:
- Google Ads: campaign metadata (names, statuses), ad group structures, and daily performance metrics (clicks, impressions, conversions, ad spend) via the Google Ads API.
- Google Analytics 4: website traffic sources, session volumes, ecommerce transactions, and channel attribution metrics via the Google Analytics Reporting API.
We use this data strictly to calculate your blended profit and return-on-ad-spend (ROAS) dashboards. Nextmerce does not share, sell, or utilize your Google account data for profiling, targeting, or commercial purposes outside of your direct store analytics dashboard. You can completely revoke access at any time through our Integrations settings panel by clicking Disconnect, which immediately deletes all stored Google API tokens from our database.
5.4 Payment Processors
We use third-party payment processors (such as Stripe) to handle subscription billing and payment transactions. We do not directly store your credit card numbers or bank account details on our servers. Payment information is transmitted directly to our payment processor via encrypted channels and is subject to their privacy policies and PCI DSS compliance standards. We retain only transaction identifiers, subscription status, and billing metadata necessary for account management.
6. Data Sharing & Disclosure
We are committed to protecting your data and share it only under the following limited circumstances:
- Service Providers: We share data with trusted third-party service providers who assist us in operating the Service, including cloud hosting providers, database services, analytics tools, email delivery services, and customer support platforms. These providers are contractually obligated to protect your data and may only process it on our behalf in accordance with our instructions.
- Legal Obligations: We may disclose your information when required to do so by law, regulation, subpoena, court order, or other governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, enforce our Terms of Service, protect your safety or the safety of others, or investigate potential violations.
- Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Service of any change in ownership or uses of your personal information, as well as any choices you may have regarding your information.
- Aggregated & Anonymized Data: We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. This data may be used for industry benchmarking, research, marketing, or other business purposes.
- With Your Consent: We may share your information with third parties when you have given us explicit consent to do so, or when you direct us to share data through a specific integration or feature of the Service.
We do not sell your personal information to third parties. We do not share your raw store data, customer data, or advertising data with other Nextmerce merchants or any unaffiliated third parties for their own marketing or commercial purposes.
7. Data Retention
We retain your information for as long as your account is active or as needed to provide you with the Service. Specific retention periods vary based on the type of data and the purpose of its collection:
- Account Data: Retained for the duration of your active account and deleted within 30 days of account closure or app uninstallation, except where longer retention is required by law
- Store Analytics Data: Historical analytics data is retained for the duration of your subscription to enable trend analysis and year-over-year comparisons
- Advertising Data: Data from connected advertising platforms is retained for up to 24 months to support long-term performance analysis and seasonality insights, unless you request earlier deletion
- Usage Logs: Server logs and usage data are retained for up to 12 months for security monitoring, debugging, and service improvement purposes
- Billing Records: Transaction records and invoices are retained for up to 7 years to comply with tax and financial reporting obligations
- Backup Copies: Encrypted backup copies of data may persist for up to 90 days after deletion from production systems, after which they are permanently purged
When data is no longer required for the purposes described in this Policy, or upon your valid deletion request, we securely delete or anonymize the data using industry-standard methods. Anonymized data that can no longer identify you may be retained indefinitely for analytical and research purposes.
8. Data Security
We implement comprehensive technical and organizational security measures designed to protect your information against unauthorized access, alteration, disclosure, destruction, or loss. Our security program includes:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. API communications with Shopify, TikTok, Meta, and Google are conducted over encrypted HTTPS connections.
- Encryption at Rest: All stored data, including database records, backups, and API tokens, is encrypted at rest using AES-256 encryption.
- Access Controls: We implement strict role-based access controls (RBAC) to limit access to personal and business data to authorized personnel who require it for service delivery. Access is logged and audited regularly.
- Authentication Security: OAuth tokens and API credentials are stored using secure, encrypted vaults. We never store Shopify API tokens in plaintext.
- Infrastructure Security: Our cloud infrastructure is hosted on industry-leading providers with SOC 2 Type II certification. We employ network firewalls, intrusion detection systems, and automated vulnerability scanning.
- Incident Response: We maintain a documented incident response plan and will notify affected users and relevant authorities of any data breach in accordance with applicable law, typically within 72 hours of discovery.
- Regular Security Assessments: We conduct periodic security reviews, dependency audits, and code reviews to identify and remediate potential vulnerabilities.
While we strive to use commercially reasonable means to protect your information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to continuous improvement of our security practices.
9. International Data Transfers
Nextmerce is operated globally, and your information may be transferred to, stored, and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from the laws of your jurisdiction.
When we transfer personal data internationally, we implement appropriate safeguards to ensure your data receives an adequate level of protection, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA to third countries
- Data processing agreements with all sub-processors that include appropriate data protection obligations
- Compliance with the UK International Data Transfer Agreement (IDTA) for transfers involving UK personal data
- Reliance on adequacy decisions where applicable, recognizing countries that provide adequate data protection
- Implementation of supplementary technical and organizational measures where necessary to ensure effective protection of transferred data
By using the Service, you acknowledge and consent to the transfer, storage, and processing of your information in accordance with this Policy. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have the right to request information about the safeguards we have put in place for international transfers of your data by contacting us at founder@nextmerce.app.
10. Your Rights & Choices
Depending on your location and applicable law, you may have certain rights with respect to your personal information. We are committed to honoring these rights and providing you with meaningful control over your data.
10.1 Rights Under the GDPR (EEA, UK, Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and related legislation:
- Right of Access: You have the right to request a copy of the personal data we hold about you
- Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data
- Right to Erasure: You have the right to request deletion of your personal data, subject to certain legal exceptions
- Right to Restriction: You have the right to request restriction of processing of your personal data in certain circumstances
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format
- Right to Object: You have the right to object to the processing of your personal data for certain purposes, including direct marketing
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw consent at any time
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in your country of residence
10.2 Rights Under the CCPA/CPRA (California)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected, the sources from which it was collected, our business purposes for collecting it, and the categories of third parties with whom we share it
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions
- Right to Correct: You have the right to request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing: You have the right to opt out of the sale or sharing of your personal information. Note: Nextmerce does not sell personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights
10.3 General Rights for All Users
Regardless of your location, all Nextmerce users have the following rights:
- Access and update your account information through the Nextmerce dashboard settings
- Disconnect third-party integrations (Shopify, TikTok, Meta, Google) at any time
- Opt out of non-essential marketing communications by clicking “unsubscribe” in any promotional email
- Request export of your data in a machine-readable format
- Delete your account and request removal of all associated data
10.4 Exercising Your Rights
To exercise any of the rights described above, please contact us at founder@nextmerce.app. We will verify your identity before processing any request and respond within the timeframes required by applicable law (typically 30 days for GDPR requests and 45 days for CCPA requests). In certain circumstances, we may need to extend the response period, in which case we will inform you of the extension and the reasons for the delay. There is no fee for exercising your rights, although we reserve the right to charge a reasonable fee for manifestly unfounded or excessive requests.
12. Children’s Privacy
The Nextmerce Service is designed for business use by Shopify merchants and is not intended for or directed at children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under 16.
If we become aware that we have inadvertently collected personal information from a child under 16, we will take immediate steps to delete such information from our systems. If you are a parent or guardian and believe that your child has provided personal information to us, please contact us at founder@nextmerce.app so that we can take appropriate action.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes to this Policy, we will:
- Update the “Last Updated” date at the top of this Policy
- Post the revised Policy on our website at the same URL
- Notify you via email or through a prominent notice within the Service for material changes that significantly affect how we process your data
- Where required by applicable law, obtain your consent to any material changes before they take effect
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after any changes to this Policy constitutes your acceptance of the updated terms, except where additional consent is required by law.
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the following information:
Nextmerce
AI-Powered Ecommerce Intelligence Platform
For GDPR-related inquiries, you may also contact your local data protection authority. We aim to respond to all legitimate inquiries within 30 days. If you feel that your inquiry has not been adequately addressed, you have the right to lodge a complaint with your local supervisory authority.
© 2026 Nextmerce. All rights reserved. This Privacy Policy was last updated on June 6, 2025. If you have any questions, please contact us at founder@nextmerce.app.