Legal

Privacy Policy

Effective date: April 26, 2026Applies to: Nudge - Checkout Optimizer
Contents
  1. 1. Overview
  2. 2. Data We Collect
  3. 3. How We Use Data
  4. 4. Data Sharing & Third Parties
  5. 5. Data Retention
  6. 6. Security
  7. 7. Merchant Rights
  8. 8. Shopper / End-Customer Rights
  9. 9. Cookies & Tracking
  10. 10. Children's Privacy
  11. 11. Changes to This Policy
  12. 12. Contact Us

1. Overview

Nudge ("we", "us", or "our") is a Shopify application that adds AI-personalised checkout blocks, a post-purchase engagement game, and conversion analytics to Shopify stores. This Privacy Policy explains what personal data we collect, why we collect it, how it is used, and the rights available to merchants and their customers.

By installing and using Nudge, the merchant ("you") agrees to the practices described in this policy. If you do not agree, please uninstall the application.

Nudge acts as a data processor on behalf of the merchant, who is the data controller for their customers' personal data. Merchants are responsible for ensuring their use of Nudge complies with applicable data protection laws in their jurisdiction.

2. Data We Collect

2.1 Merchant Account Data

When you install Nudge we receive and store:

2.2 Shopper / End-Customer Data

When a shopper interacts with your checkout or post-purchase page, Nudgemay receive and transiently process:

2.3 Analytics Data

2.4 Support & Enquiry Data

3. How We Use Data

PurposeData usedLegal basis
Deliver checkout blocks to shoppersBlock settings, shop identifierContract performance
AI personalisation of block content and placementCart contents, order history, customer name and locationLegitimate interests / contract
Post-purchase game rewards (gift cards, discount codes)Session key, customer email, Shopify admin APIContract performance
Plan limit enforcementAnonymised session counts per shop per monthContract performance
Analytics dashboard shown to the merchantImpression records, order analyticsLegitimate interests
Billing and subscription managementShop domain, Shopify billing APIContract performance
Security, fraud prevention, rate limitingIP address, shop domainLegitimate interests
Responding to support requests and enquiriesSupport messages, contact form submissionsLegitimate interests
Improving the applicationAggregated, anonymised usage dataLegitimate interests

Shopper data passed to AI providers for personalisation is used solely to generate a response for that individual request. It is not used to train AI models, build advertising profiles, or shared with any other party.

4. Data Sharing & Third Parties

We do not sell personal data. We share data only with the sub-processors listed below, and only to the extent necessary to deliver the service.

Sub-processorPurposeData sharedLocation
Shopify Inc.Store authentication, billing, order data APIStore domain, access token, order history queriesUSA / Global
Cloud infrastructure providerPersistent storage and hosting of all app dataAll data described in Section 2USA
Anthropic PBCAI personalisation (if Anthropic is the active provider)Cart contents, order history, customer name & locationUSA
OpenAI LLCAI personalisation (if OpenAI is the active provider)Cart contents, order history, customer name & locationUSA
Google LLCAI personalisation (if Gemini is the active provider)Cart contents, order history, customer name & locationUSA / Global
Content delivery networkCDN delivery of merchant-uploaded product imagesImage files only — no personal dataGlobal edge network

Shopper data is sent to an AI provider only when Nudge Assist is enabled on a block and a session is within the plan's AI session allowance. Merchants on the Spark plan (no AI) have no shopper data transmitted to AI providers. Merchants who supply their own API key control which provider is used.

We may disclose data if required by law, court order, or to protect the rights, property, or safety of Nudge, its users, or the public.

5. Data Retention

Data typeRetention period
Merchant account, settings, subscriptionDuration of app installation + 30 days after uninstall
AI session usage records (UsageSession)3 months (automated cleanup runs daily)
Block impression records90 days (automated cleanup runs daily)
Order analyticsDuration of app installation
Error logs60 days (automated cleanup runs daily)
Game rewards and outcomesDuration of app installation
Support messages and enquiries2 years or until you request deletion
Shopper data sent to AI providersNot stored by us — transmitted per-request only; subject to each provider's retention policy

Upon uninstall, we delete all personally identifiable merchant and shopper data within 30 days, in compliance with Shopify's Partner Program requirements. Aggregated, non-identifiable analytics data may be retained longer for service improvement purposes.

6. Security

We implement industry-standard technical and organisational measures to protect personal data, including:

No method of transmission or storage is 100% secure. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.

7. Merchant Rights

As a merchant (data controller), you have the right to:

To exercise any of these rights, contact us at info@tactech.tech. We will respond within 30 days.

8. Shopper / End-Customer Rights

Shoppers whose data is processed via Nudge should direct privacy requests to the merchant (the store they purchased from), as the merchant is the data controller for their personal data.

If a shopper believes their data has been mishandled and cannot resolve it with the merchant, they may contact us at info@tactech.tech and we will assist in facilitating a resolution.

Shoppers in the European Economic Area (EEA) and United Kingdom have additional rights under GDPR / UK GDPR, including the right to lodge a complaint with their local supervisory authority. California residents have rights under CCPA, including the right to know, delete, and opt-out of the sale of personal information (we do not sell personal information).

9. Cookies & Tracking

The Nudge admin application (this website and the Shopify embedded app) uses strictly necessary session cookies required for authentication with Shopify. No advertising, analytics, or third-party tracking cookies are set.

The checkout extension and post-purchase extension run inside Shopify's checkout iframe and do not set cookies independently. Session keys used for rate limiting and deduplication are derived from existing Shopify-provided identifiers and are not persisted as cookies.

10. Children's Privacy

Nudge is a business-to-business service intended for Shopify merchants. We do not knowingly collect personal data from children under the age of 13 (or the applicable age of digital consent in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable legal requirements. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email or through a notice in the Nudgeadmin interface.

Continued use of Nudge after changes become effective constitutes your acceptance of the revised policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Have a privacy question?
We typically respond within 2 business days.
Contact privacy team →