Nxora · Refund Impact
This policy describes exactly what the app reads from a merchant's Shopify store, what it stores, what it sends to anyone else, and what it never keeps. It is written to be checked against the app, not just read. A separate policy covers our other Shopify app, AI Catalog Readiness; the two apps do not share data or a database. See also the terms of service and the data processing addendum.
This app reads text written by a merchant's customers, and stores none of it. When a shopper returns an item they may leave a note explaining why. The app reads that note so it can show it to the merchant who already owns it, alongside the product it belongs to. The note is fetched from Shopify, rendered onto the page, and discarded when the request ends. It is never written to our database, never logged, never used to train anything, and never sent to any third party. The app still never reads a customer's name, email address, phone number, shipping or billing address, or payment details.
The app is provided by Yehiel Amor, an individual trading as Nxora at getnxora.com ("Nxora", "we"). Nxora is the data controller for the information described below.
| Controller | Yehiel Amor, trading as Nxora |
|---|---|
| Location | Ramat Gan, Israel |
| Contact | support@getnxora.com |
Write to support@getnxora.com for anything in this policy, including access, correction and deletion requests. It is a monitored address, not an auto-responder.
Our customer is the Shopify merchant who installs the app. We have no relationship with that merchant's shoppers, and we hold no record of them. Where the app displays a return note a shopper wrote, it is showing the merchant their own store's data, in the merchant's own admin, for the duration of one page view.
The app requests three Shopify access scopes. All three are read-only.
read_orders |
Reads refund line items — a refunded amount, a currency, a quantity and a product id — so products can be ranked by the money actually leaving the store. The 60-day window is Shopify's limit for this scope, not a choice. The query asks for no customer field of any kind. |
|---|---|
read_returns |
Reads, per returned line: the structured return reason the store recorded, a staff note if one exists, the note the buyer wrote if they left one, and the product id. This is what lets the app say why an item came back rather than only how much it cost. Nothing else on the return is requested — no shipping label, no address, no carrier, no customer. |
read_products |
Reads product, variant, image, option and metafield data, so that when a return reason points at something in the listing the app can name it — for example a return marked "item not as described" on a product that has no description. |
The app has no write access to a store. It cannot change a product, a price, a title, a description, an order, a return or a setting, and it never attempts to.
One table. The app's database holds Shopify session records and nothing else: the shop domain, the access token issued at install, the granted scopes, and the session identifiers Shopify's own library requires to keep a merchant logged in.
There is no table of refunds, no table of returns, no table of reasons, no table of buyer notes and no copy of the catalog. Every figure on the screen — every amount, every reason, every quoted note — is read from Shopify when the page loads and exists only for as long as that request takes to render. Close the page and nothing of it remains on our side.
This section exists because it is the one place where text a shopper composed passes through our server, and a policy that buried that would not be worth reading.
If a shopper leaves no note, nothing is shown. The app has no way to obtain one by any other route.
No customer name, email address, phone number, shipping or billing address, payment method, card detail, IP address or browsing history. These fields are not requested in any query the app makes. The GraphQL documents the app sends are fixed in its source and can be checked field by field against this list.
| Shopify | The source of all store data, and the platform the app runs inside. Shopify is also the payment processor for the app's subscription; we never see a merchant's card details. |
|---|---|
| DigitalOcean | Hosts the application server and its database, in a single region. No other infrastructure provider holds any of this data. |
There is no analytics provider, no error-tracking provider, no advertising network and no AI provider in this list, because the app sends data to none of them.
We hold a session record so a merchant does not have to reauthenticate on every page load. That is its only purpose. When the app is uninstalled, the shop's session records — including the access token — are deleted, and with them everything we held about that store.
Because no refund, return, reason or note is ever written down, there is no retention period to state for any of them. They are not kept for a day, an hour or a minute past the request that displayed them.
The app implements all three webhooks Shopify requires:
customers/data_request |
Acknowledged. There is no stored customer data to return: return notes are read and displayed but never persisted, so there is no record to produce. |
customers/redact |
Acknowledged. There is no stored customer data to erase, for the same reason. |
shop/redact |
The shop's session records, including its access token, are deleted. |
A merchant may ask us, at any time, to tell them what we hold about their shop, to correct it, to send them a copy of it, or to delete it. A merchant may also withdraw access outright by uninstalling the app, which stops all reading immediately.
Email support@getnxora.com from an address on the store's domain, or from the email on the Shopify account, and we will act on the request. If we need to confirm that you control the store before deleting anything, we will ask for that and say why.
Depending on where a merchant is located, local data-protection law may give them further rights. We do not require a merchant to go through us to exercise a right they have under their own law, and we do not charge for any request in this section.
Access tokens are stored server-side and are never exposed to the browser. The app holds no payment data, no copy of a merchant's catalog, and no record of any refund, return or buyer note. That is a deliberate design decision and the most useful thing we can say here: the smaller the store of data, the less there is to lose.
We make no certification claim in this policy. We do not claim any security standard, certification or audit that we have not completed, and this app has not been audited or certified against one.
The app is a business tool for Shopify merchants. It is not directed at children and collects no data from them.
If this policy changes we update the date at the top of this page. If a change affects what data the app reads, stores or sends, we will also say so in the app before the change takes effect.
This policy is governed by the law of Israel, and the courts of Israel have jurisdiction over disputes arising from it.
support@getnxora.com
Yehiel Amor, trading as Nxora · Ramat Gan, Israel