Nxora · AI Catalog Readiness
This addendum describes the processing Nxora carries out on behalf of a merchant who installs AI Catalog Readiness. It supplements the terms of service and should be read alongside the privacy policy, which it does not contradict: where the two describe the same fact, the privacy policy is the more detailed source. In this addendum, the merchant is the controller and Nxora is the processor.
By installing the app, the merchant accepts this addendum. No separate signature is required or requested.
The subject matter is the processing described in section 2, carried out so the app can score a merchant's product catalog and rank suggested fixes. Processing runs for as long as the app remains installed on the merchant's store, and ends as described in section 8.
Nxora processes a merchant's product and, on paid tiers, order data for the sole purpose of scoring the merchant's catalog against the criteria Shopify publishes for its Catalog and Agentic Storefronts pipeline, and ranking the resulting fixes by the commercial impact — units sold — behind each affected product. On the Pro tier, a subset of product content is also sent to an AI sub-processor for a review of titles and descriptions, as described in section 4 and in the privacy policy.
No customer personal data is processed at all. Nxora does not read, and has no means to read, a customer's name, email address, phone number, shipping or billing address, or payment details.
The data categories processed are:
lineItems { quantity, product { id } }: a quantity and a product id, nothing more.
No customer field, name, address or payment detail is part of that query. The result is
reduced to a single per-product integer — a units-sold count — before anything is written to
storage. No order record is stored.
This is the same list, and the same wording where it overlaps, as the privacy policy's description of what the app stores.
Nxora uses three sub-processors, all already named in the privacy policy.
| Shopify | The source of all store data, and the platform the app runs on. Governed by the merchant's own agreement with Shopify. |
|---|---|
| Anthropic | Used only by the Pro tier's AI review of titles and descriptions. For up to 25 products per review, in batches of five, it receives the product id, title, category, product type, vendor, a plain-text description truncated to 1,200 characters, option names (not values), metafield keys (not values), and a variant price range. No order data, no customer data and no access token is ever included. Merchants on Free and Growth never reach this code path. |
| DigitalOcean | Hosts the application and its database on a single virtual machine in Frankfurt. No managed database service and no third-party analytics, logging or error-reporting service is used. |
Sub-processor changes. If Nxora adds or replaces a sub-processor that would receive any of the data categories in section 3, we will update this page and the privacy policy before the change takes effect, and note the change date. Given the size of this operation, that update is the mechanism of notice; we do not operate a separate notification list.
Because no customer personal data is processed, Nxora expects no data-subject requests concerning a merchant's customers to reach it, and none are technically possible to fulfil beyond confirming that nothing is held. If a merchant needs to respond to a request from one of their own customers and needs written confirmation of that fact for their own records, email support@getnxora.com and we will provide it.
For a merchant's own data — the data described in section 3 — the access, correction and deletion rights in the privacy policy apply, and the same contact address handles them.
Traffic between a merchant's browser and the app, and between the app and Shopify, runs over TLS; requests over plain HTTP are redirected. The database holds no customer personal data. The one credential it does hold, the Shopify access token, is encrypted at rest with AES-256-GCM, with a separate initialisation vector per record and an authentication tag, using a key held outside the database.
The database file sits on a single-tenant host, in a directory readable only by the service account that runs the app. There is no full-disk encryption on that host, and this addendum does not claim any. In practice, that means a copy of the database file, a stolen backup, or a decommissioned disk exposes no customer data and no usable credential; someone with administrative access to the running host could read the key, and we do not represent otherwise.
Nxora is operated by two people. We do not offer on-site audits, and we do not hold, or claim to be pursuing, SOC 2 or any other certification, and there is no named security officer. What we will do, proportionate to that size: on written request, provide a description of the technical and organisational measures in section 6 sufficient for a merchant to assess this addendum against their own obligations, and answer specific written questions about how a data category in section 3 is handled.
On uninstall, and on receiving Shopify's shop/redact webhook, the app deletes the
store's session records, including its access token, through the same purge routine in both
cases — there is one code path, not two, so a difference in behavior between the two
triggers is not possible. Scan reports, watched-product rows and change-event rows contain no
customer data and are not currently deleted automatically on uninstall; email
support@getnxora.com and we will delete all of a
shop's records on request and confirm it in writing. This matches the retention section of the
privacy policy.
If Nxora becomes aware of a breach affecting a merchant's data under this addendum, we will notify the merchant without undue delay, describe what is known about the incident, and describe what we are doing about it. Given the categories in section 3, the most a breach could expose is a store's access token and its stored findings — not customer data, because none is held.
This addendum is accepted by installing the app, alongside the terms of service. If a provision here conflicts with the privacy policy on a factual point, the privacy policy's description of the app's actual behavior controls, and we will correct the conflicting page.
support@getnxora.com
Yehiel Amor, trading as Nxora · Ramat Gan, Israel