Nuvina Customer HubSupport

Privacy policy

Effective September 2, 2026

This policy explains how Nuvina Customer Hub (the “App”, “we”, or “us”) processes information when a Shopify merchant installs and uses the App. The App acts on the merchant’s instructions to show order, checkout, and customer information from their Shopify store, to prepare customer messages, and to apply customer tags. The merchant is the controller of their customers’ personal data; we process it only on the merchant’s behalf.

Information the App accesses

  • Shop domain, Shopify shop ID, authentication session, and granted access scopes.
  • Order data from the last 60 days: order number, dates, fulfillment and payment status, line items, totals, tracking numbers, and the order status page link.
  • Protected customer data: customer name, email address, phone number, and shipping address, together with the email and SMS marketing consent state that Shopify records.
  • Abandoned checkouts: checkout number, items, total, the customer’s contact details, and the recovery link.
  • Customer profile totals: lifetime order count, lifetime amount spent, tags, and the customer note.
  • Webhook events for fulfillments and paid orders, minimized to identifiers, status, and tracking fields.

How information is used

  • Authenticate the merchant and keep the App connected to their Shopify store.
  • Display orders, abandoned checkouts, and customer profiles inside Shopify Admin so merchant staff can answer customer questions.
  • Fill the merchant’s own message templates with a customer’s first name, order number, tracking details, or recovery link, and open a WhatsApp or email draft the merchant sends themselves.
  • When the merchant enables the delivery connector, send the rendered shipping update or checkout-recovery message, together with the customer’s contact details, to the endpoint the merchant configured.
  • Evaluate the merchant’s customer rule and add the merchant’s chosen tag to qualifying customers.
  • Prevent duplicate webhook processing, maintain security, keep an access log, and troubleshoot failures.

We do not sell personal information, use it for advertising, build profiles outside the merchant’s store, or share it with anyone other than the service providers below and the endpoint the merchant configures.

Consent

Shipping updates are service messages about an order the customer placed. Checkout-recovery messages are marketing messages. The App reads the marketing consent state recorded in Shopify and, under its default policy, enables recovery messaging only for customers with a recorded opt-in. Customers who opted out are always blocked. A merchant may switch to merchant-managed outreach, in which case the merchant confirms that they hold their own lawful basis for contacting customers who have not recorded an opt-in. The App never changes a customer’s consent state.

Information retained

Customer names, contact details, and addresses are read from Shopify while a screen is open or a webhook is processed and are not written to the App database. We retain: the merchant’s settings (message templates, outreach policy, connector URL, and an encrypted signing secret); Shopify authentication sessions; message records for 90 days containing the order number, event, channel, and delivery status only; an access log for 90 days recording which staff user read which kind of record; aggregate rule-run counts for 90 days; and webhook delivery identifiers for 7 days.

Disclosure and service providers

Information is processed by our hosting provider (Vercel), our database provider (Neon, encrypted PostgreSQL), and Shopify. Providers act under contract and access controls and only to operate and secure the App. If the merchant enables the delivery connector, the rendered message and the order contact details are sent to the endpoint URL the merchant entered; that endpoint and its provider are chosen and controlled by the merchant. We may disclose information when required by law or to protect the security and integrity of the service.

Security and international processing

Data is encrypted in transit using TLS. The production database and its backups are encrypted at rest, merchant secrets are additionally encrypted at the application layer, staff access is limited to the App owner and protected by strong passwords and two-factor authentication, and development data is kept separate from production data. Our security and incident response policy is published at /security. Infrastructure providers may process data in countries other than the merchant’s country, subject to applicable contractual and legal safeguards.

Deletion and privacy requests

The App verifies Shopify’s mandatory customer data-request, customer-redaction, and shop-redaction webhooks. Because customer-level data is not retained, there is no customer profile in our database to export or erase. When the App is uninstalled, we delete shop settings, sessions, message records, access logs, and rule history. The later Shopify shop-redaction request is handled idempotently.

Buyers should direct privacy requests to the Shopify merchant from whom they purchased. Merchants can contact us for help responding to a request.

Changes

We may update this policy when the App or legal requirements change. The effective date above will be updated, and material changes will be communicated through the App or merchant contact information when appropriate.

Contact

Email privacy and security questions to support@nuvina-shop.co.il.