Privacy Policy

Last updated: August 2026

Nerja AI (“Nerja”, “we”, “us”) operates as a Shopify App Store app providing marketing automation, customer intent scoring, and cart-recovery services. This policy explains what data we collect, how we use it, and the controls available to merchants and their customers.

1. Data We Collect

Merchant data: When you install Nerja from the Shopify App Store, we receive your shop domain, Shopify access token (encrypted at rest with AES-256-GCM), shop name, plan selection, and billing status via Shopify Managed Pricing.

Customer data:To provide cart-recovery and marketing automation, we process the following categories of your customers’ data, synced from your Shopify store via the Admin API and web pixel:

  • Email addresses and phone numbers
  • Order history and financial status (paid, refunded, etc.)
  • Product and cart information (items, quantities, prices)
  • Checkout events (checkout started, completed)
  • Browsing events on your storefront (page views, product views)
  • Customer identifiers (Shopify customer ID, anonymous visitor ID)

2. How We Use Data

  • Cart recovery: Detect abandoned checkouts and send recovery messages via email, SMS, or WhatsApp.
  • Marketing automation: Enrol customers in campaigns based on behaviour, purchase history, and intent signals.
  • Analytics: Provide merchants with insights into customer intent, segment membership, and campaign performance.
  • Compliance: Honour unsubscribe requests, frequency caps, and quiet-hours windows.

3. Data Sharing

We do not sell customer data. We share data with third-party providers only as necessary to deliver the service:

  • Email providers (AWS SES, Resend) — to send marketing and recovery emails on your behalf.
  • SMS providers (Twilio) — to send SMS messages.
  • WhatsApp providers (Meta Cloud API, WAAPI) — to send WhatsApp messages.
  • Infrastructure (PostgreSQL, MongoDB, Redis) — for data storage and event processing.

Each provider processes data under their own privacy policy and data processing agreement. Merchant credentials for these providers are encrypted at rest and decrypted only at send time.

4. Data Retention

We retain customer data for as long as your Nerja account is active. When you uninstall the app, Shopify triggers a shop/redact webhook that deletes all customer data associated with your shop within 30 days. Event data (browsing, cart activity) is retained for a rolling 90-day window for analytics purposes and then automatically purged.

5. Your Customers’ Rights

Your customers have the right to request access to, correction of, or deletion of their personal data. These requests are fulfilled via Shopify’s mandatory GDPR webhooks:

  • Customer data request: When a customer requests their data via Shopify, we compile and return a data export within 30 days.
  • Customer data deletion: When a customer requests deletion, or when a merchant initiates it, we permanently remove their profile, events, and suppression records.

See our Data Deletion Instructions for details.

6. Security

  • Provider credentials (API keys, tokens) are encrypted at rest with AES-256-GCM.
  • All API communication uses HTTPS/TLS.
  • JWT authentication with short-lived access tokens for dashboard access.
  • Suppression lists (unsubscribes, bounces, complaints) are enforced across all channels before any message is sent.
  • Security headers (HSTS, X-Frame-Options, X-Content-Type-Options) are applied to all API responses.

7. Cookies & Tracking

Nerja uses a first-party web pixel on your storefront to track browsing events (page views, product views, add-to-cart, checkout-started). This data is used solely for cart-recovery and marketing automation within your store. We do not use third-party advertising cookies or tracking pixels.

8. Contact

For privacy questions or data requests, contact us at support@nerja.ai.