Home

Privacy Policy

Last updated: July 25, 2026

1. Overview

This Privacy Policy explains what information Nexez collects, how we use it, and the choices you have. It applies to the Nexez dashboard, page builder, custom-domain hosting, APIs, and the Nexxi mobile buyer-agent app (together, the "Service").

2. Information You Provide

Account details: your name, company/business name, industry, and email when you sign up (including via Sign in with Apple or Google, which share your email and basic profile). Business content: the offers, descriptions, FAQs, and other information you publish. Configuration: custom domains, integration settings, and API key names.

Launch pass invitations: when a business invites another business, we process the recipient business email, sender business name, delivery and claim status, and campaign eligibility records. Invitation tokens are stored as one-way hashes. To prevent duplicate promotional claims, we record verified business identity signals such as a verified website or custom domain, connected Shopify store, or charges-enabled Stripe account.

Connected stores: when you install the Nexez Shopify app, we process your shop domain, installation status, encrypted access credentials, and the active product catalog you choose to publish through your Nexez listing. Catalog data can include product names, descriptions, variants, prices, availability, inventory signals, currency, and storefront URLs. Nexez requests read-only product access and does not request Shopify customer or order data.

Buyer activity (Nexxi app): the messages you send your buyer agent, your standing preferences (budget, interests, timing, location), and the buyer details you approve for a purchase or negotiation (such as your email and order references).

3. Information Collected Automatically

Agent & visitor analytics: when your published listings are viewed, we record events (such as page views, discovery clicks, and checkout intents) and, for AI agents, classification signals derived from the request (e.g., user-agent and referrer).

Website readiness scanner: when you submit a public URL, we fetch a limited portion of the public page and its public agent-discovery files to produce a report. We do not retain the fetched page content. We record the submitted domain, score, timing, and service telemetry needed to operate, secure, and improve the scanner. If you choose the model-assisted analysis, up to 8,000 characters of public page text are sent to our configured large-language-model provider.

Mobile app: a device push-notification token (so we can notify you about your orders), and - only if you opt in - crash and diagnostic data via our error-monitoring provider to help us fix problems.

IP addresses may be processed transiently for security and rate limiting. Where an identifier is retained for analytics or de-duplication, we use a salted hash instead of the raw address.

4. Voice & Microphone (Nexxi app)

When you use voice input, your device’s speech-recognition service converts your speech to text so the agent can act on it. We process the resulting text like any other message; we do not store raw audio recordings. Microphone access is used only while you are actively dictating, and you can use the app entirely by typing instead.

5. How We Use Information

To operate and improve the Service; to run your buyer agent and generate recommendations; to send notifications about your orders (when enabled); to generate agent-readable artifacts and analytics; to administer plans, promotional access, and business invitations; to provide support; to detect and prevent abuse; and to communicate with you about your account.

6. AI Processing

Your buyer-agent requests are sent to a large-language-model provider to interpret your intent and draft responses. When you enable external discovery sources, your search query may also be sent to a third-party search provider. These providers process the request to return a result and operate under their own terms; we do not sell your data to them.

7. Public Pages & Agents

Content you publish is intentionally public and structured so that AI agents and search engines can read it. Do not publish information you wish to keep private. Operational secrets (such as webhook signing secrets) are stored separately and are never exposed on public pages.

8. Service Providers

We use trusted processors to run the Service: Supabase (database + authentication), our hosting provider, Expo (mobile builds + push delivery), Sentry (opt-in crash/error monitoring), a large-language-model provider (buyer-agent requests), a third-party search provider (optional external discovery), and - where you enable them - commerce, payment, and scheduling providers such as Shopify, Stripe, and Calendly. These providers process data on our behalf under their own terms.

9. Data Retention & Deletion

We retain account and content data for as long as your account is active. You can delete listings at any time. Uninstalling the Nexez Shopify app revokes its stored credentials, disconnects the shop, and removes that shop’s imported offers from the linked listing. Shopify’s final shop-redaction request deletes the remaining installation record. Promotional grant, invitation, and verified-business claim records are retained while needed to administer the campaign and prevent duplicate claims. You can permanently delete your account in the Nexxi app (Profile → Delete account) or via the dashboard - this removes your account, agent data, preferences, invitations, and any listings you own, and anonymizes your buyer details on past transaction records, except where retention is required by law.

10. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. You can delete your account in-app; for access or export requests, contact us and we will respond within the timeframe your law requires.

11. Children

The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

12. Security

We use industry-standard measures including encryption in transit, row-level security on tenant data, hashed API keys, secure on-device token storage in the mobile app, and least-privilege access. No system is perfectly secure, but we work to protect your data.

13. Changes & Contact

We may update this policy; material changes will be reflected by the “Last updated” date above. Privacy questions can be sent to privacy@nexez.app.

See also our Terms of Service.