Privacy Policy

Last updated: [DATE]

Draft template — this document must be reviewed and approved by a qualified lawyer before launch. Bracketed values (e.g. [LEGAL ENTITY], [DATE]) are placeholders to be filled in by the owner.

This Privacy Policy explains how NexBundle (the “App”, “we”, “us”), operated by [LEGAL ENTITY], CNPJ [CNPJ], located at [ADDRESS], collects, uses, stores and protects information in connection with your use of the App.

NexBundle is a “buy together / cross-sell” application embedded in the Shopify admin. It lets a merchant define product relationships (a main product and companion products) that are displayed together on the storefront. By installing or using the App, you agree to this Policy.

1. Who is the data controller

The App is provided by [LEGAL ENTITY], CNPJ [CNPJ], with address at [ADDRESS]. For any privacy-related request, contact us at suporte@nexbundle.sprezzia.live.

2. Information we store

Store / merchant data. We store your store domain (your-store.myshopify.com) and the offline access token issued by Shopify for your store (the session), which is required for the App to read your products.

Product relationships (“components”). Product IDs (main and companion) and variant IDs as Shopify GIDs, the chosen layout/template, a style JSON (colors, title, button), direction, and active/inactive status.

Store-level style configuration. A global styling preference for your store.

Metric events. Aggregated performance data: event type (impression or click), the product IDs involved, the layout, and a timestamp. These events contain NO buyer identifiers.

Admin language preference. The interface language you selected in the App admin panel.

Support / chat. Messages exchanged between you and our support team, and any attachments you upload (images / PDF), stored on our server.

3. Information we do NOT collect

We do not collect any personal data about your store’s buyers or end customers. The storefront widget only uses product IDs and records impression / click events — it does not set PII cookies and does not capture buyer name, e-mail, address or payment data.

Adding to cart uses Shopify’s standard cart endpoint (/cart/add.js); we do not process the checkout or payment.

4. Permissions (scopes)

The App requests only the read_products scope (read access to products). It does not request write access to your products, orders, or customers.

5. How we use the information

To operate the App: authenticate with Shopify, read your products, and render the buy-together widget on your storefront.

To measure performance: aggregate impression / click metrics so you can see how relationships perform (no buyer identifiers involved).

To provide support: respond to your messages and handle attachments you send us.

To remember your preferences: such as the admin panel language.

6. Hosting and sub-processors

The App is hosted on our own server (VPS) with a local database (SQLite). We integrate with Shopify’s APIs. We do not use third-party analytics providers and do not sell or share your data with advertisers.

Data is transmitted over encrypted connections. Webhooks received from Shopify are verified by HMAC signature, and uploaded attachments are served only through authenticated routes.

7. Data retention and deletion

Your data exists for as long as the App is installed. When you uninstall the App, Shopify sends the shop/redact webhook (approximately 48 hours after uninstall), and we delete all data associated with your store.

We also respond to Shopify’s mandatory compliance webhooks: customers/data_request (we hold no customer data to return), customers/redact (we hold no customer data to erase), and shop/redact (we erase all store data).

8. Your rights (GDPR / LGPD)

Depending on your jurisdiction, you may have the right to access, correct or delete your data, among others. You can exercise deletion by uninstalling the App and/or by contacting us at suporte@nexbundle.sprezzia.live.

9. Internal team accounts

We maintain accounts for our own internal support team (e-mail, name, password hash). These are our staff accounts and are not merchant or buyer data.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by updating the “Last updated” date at the top of this page.

11. Contact

For any question about this Policy, contact us at suporte@nexbundle.sprezzia.live.