Privacy Policy
Nexforge: Granular Restore
Effective date: August 18, 2026
1. Scope and overview
This Privacy Policy explains how Nexforge: Granular Restore (“Nexforge”, “the App”, “we”, “us”, or “our”) Shopify app collects, uses, stores, discloses, and deletes information when a Shopify merchant installs or uses the App. Nexforge is a catalog backup and restore service for Shopify stores. It is designed to create merchant-requested catalog snapshots, retain those snapshots according to the applicable plan, and restore selected catalog resources or attributes when requested by the merchant.
This policy applies to information processed through the Nexforge Shopify application and related service infrastructure. Shopify separately processes information under Shopify's own terms and privacy practices.
2. Information we process
2.1 Shopify store, installation, and authentication information
When the App is installed, authenticated, reauthenticated, or used, we process information needed to identify and securely connect the Shopify store. This can include:
- the store's
myshopify.comdomain and Shopify Shop identifier; - installation status and installation, uninstall, and reinstallation timestamps;
- Shopify authorization scopes granted to the App;
- Shopify access and refresh credentials and related token-status metadata needed to call Shopify APIs on the merchant's behalf;
- technical authentication and token-audit metadata used to protect and operate the service.
Authentication credentials are service credentials, not catalog backup content. They are used only for authenticated Shopify operations and service security.
2.2 Catalog information requested for backup and restore
Nexforge processes the Shopify catalog information necessary to provide its backup and restore functions. Depending on the snapshot type and features used, this can include:
- products and product variants;
- collections, including collection configuration and membership information where supported;
- metafields, metafield definitions, metaobjects, and related references;
- inventory quantities and Shopify locations;
- fulfillment-service and location-management information used to identify app-managed or third-party logistics (3PL) locations so that those locations can be protected from inappropriate restore operations;
- publication or sales-channel state;
- shipping-related variant data used by the supported backup and restore contract;
- product and collection image metadata, image ordering and identity, featured-image and variant-image relationships, and Shopify CDN source URLs;
- for media-protected snapshots, copies of supported product and collection image files and generated backup thumbnails.
A standard catalog snapshot preserves catalog data and image metadata/relationships without independently archiving raw product or collection image bytes. A media-protected catalog snapshot additionally stores supported raw product and collection image files so that media can be independently recovered.
Merchants control the content they place in Shopify catalog fields, metafields, and metaobjects. If a merchant places personal data in those catalog resources, that information can consequently be included in a Nexforge backup because the App preserves the merchant-selected Shopify catalog state.
2.3 Backup, restore, and service-operation information
We process information created when a merchant uses Nexforge, such as:
- backup and restore identifiers and merchant-provided backup or restore names;
- snapshot type, selected products or collections, selected attributes, and location-related restore instructions;
- job creation, start, completion, cancellation, and failure timestamps;
- job status, progress, stage, result, and failure information;
- backup manifests, reports, checksums, content types, object locations, and other metadata needed to publish, verify, materialize, restore, and delete backup artifacts;
- usage counters used to enforce plan quotas and service limits.
2.4 Billing, subscription, and free-trial information
Paid subscriptions are handled through Shopify. Nexforge processes the minimum billing state needed to authorize service access and keep its records synchronized with Shopify, which can include Shopify subscription identifiers, selected Nexforge plan, subscription status, billing interval, billing-period timestamps, scheduled cancellation or plan-change information, and verification timestamps.
For free-trial eligibility and abuse prevention, Nexforge also processes the store's Shopify identity, whether the store has ever started its one-time Nexforge trial, the first trial start time, the trial tier, product count used for eligibility, trial status, and relevant trial timestamps.
2.5 Technical, security, and operational logs
We generate logs and technical records needed to operate, secure, troubleshoot, and monitor the App and its cloud infrastructure. Depending on the request or event, these records can include request timestamps, route or resource information, response/error information, job and store identifiers, IP address, user-agent or network metadata, infrastructure events, security events, and diagnostic details. We design application logs so that Shopify access tokens and other application secrets are not intentionally written to logs.
2.6 Privacy and compliance request records
Nexforge receives Shopify's mandatory privacy/compliance webhooks. We keep limited request-processing metadata needed to prove, retry, and complete those requests, such as an idempotency/request key, webhook topic, request status, receipt/completion timestamps, and error information when processing temporarily fails. After completion, the stored compliance record is designed not to retain the Shopify shop identifier from the request.
3. Customer and order data
Nexforge is a catalog backup and restore application and is not designed to access Shopify customer profiles, customer contact fields, orders, or buyer behavioral data as part of its normal service. The App does not currently request access to Shopify protected customer data for its catalog backup and restore functionality.
Shopify nevertheless requires App Store applications to support mandatory customer privacy webhooks. If Shopify sends Nexforge a customer data request or customer redaction webhook, Nexforge validates and processes the request as required. Because the App's normal service does not persist Shopify customer or order records, the compliance handler does not intentionally create a separate stored copy of customer contact or order data from those webhook payloads.
Nexforge does not install buyer-facing advertising trackers or web pixels for the purpose of behavioral advertising, and the App does not sell merchant or buyer personal data.
4. How we use information
We use the information described above only for purposes reasonably necessary to provide, secure, maintain, and administer Nexforge, including to:
- authenticate the Shopify store and make authorized Shopify API requests;
- create, store, validate, display, and expire merchant-requested backups;
- restore catalog resources and selected attributes at the merchant's request;
- identify app-managed and third-party logistics (3PL) locations and automatically protect externally managed inventory/location state during restore operations;
- maintain job status, progress, reports, error recovery, cancellation, and operational integrity;
- determine product-count eligibility, enforce plan capacity and daily usage limits, administer free trials, and synchronize Shopify subscription status;
- prevent repeated use of the one-time free trial by the same Shopify store;
- protect the service against abuse, unauthorized access, fraud, and infrastructure failures;
- debug errors, monitor reliability, and maintain security and audit records;
- respond to Shopify privacy/compliance requests and other lawful requests;
- comply with applicable contractual and legal obligations.
We do not use merchant catalog backup contents to build advertising profiles or sell them to third parties.
5. Data retention
5.1 Backup retention
Each completed backup receives a retention expiration based on the Nexforge plan that authorized the backup. The current standard retention periods are:
| Plan | Backup retention |
|---|---|
| Starter | 30 days |
| Growth | 90 days |
| Pro | 6 months |
| Enterprise | 12 months |
| Enterprise Plus | 12 months |
A trial backup follows the retention policy of the trial tier assigned to the store. Retention is fixed for the backup when it completes. Expired backups are scheduled for deletion under Nexforge's retention process. Temporary worker files are disposable working data and are cleaned after job completion or failure when safe; they are not treated as the durable backup copy.
5.2 Operational and billing records
Store, job, subscription, usage, and operational records are retained while needed to provide the service, preserve job and billing integrity, comply with applicable obligations, resolve disputes or failures, and carry out the deletion processes described below. Operational log retention can differ by log type and environment; production application and orchestration log groups are configured for bounded retention rather than indefinite application-log storage.
5.3 Infrastructure backups and versions
Service infrastructure can create encrypted database backups, object versions, and security/audit records for resilience and security. These copies can persist for a limited period after the corresponding live record is changed or deleted and then expire according to infrastructure backup, versioning, or lifecycle settings. Such copies are not used to continue normal App processing after deletion.
5.4 Lifetime free-trial abuse-prevention record
Nexforge offers only one free trial per Shopify store. To enforce that restriction across uninstall and reinstall, Nexforge intentionally retains a minimal anti-abuse record after other store data is deleted. This record is limited to the immutable Shopify Shop identifier, the fact that a trial was previously started, and the first trial start time when available. It is kept separately for free-trial abuse prevention and is not used as a retained copy of the merchant's catalog, credentials, backup artifacts, billing records, or ordinary operational store data.
This minimal anti-abuse record is intended to be retained for the lifetime of the Nexforge free-trial program unless retention is no longer necessary or applicable law requires a different result. Where applicable privacy law gives a person a right that conflicts with retention of this record, we will evaluate the request and applicable legal basis rather than using this section to override mandatory legal rights.
6. Uninstalling Nexforge and deleting store data
When Shopify notifies Nexforge that the App has been uninstalled, Nexforge marks the installation inactive, clears usable Shopify access and refresh credentials, marks the token state revoked, and begins the approved cleanup lifecycle. Uninstalling alone is distinct from Shopify's later store-redaction request because Shopify can allow a short period between uninstall and the mandatory shop/redact event.
Shopify normally sends the shop/redact privacy webhook after uninstall. When Nexforge receives and successfully verifies an eligible store-redaction request, the App deletes the store's durable Nexforge backup artifacts and status projections and removes the store's Nexforge operational database records, including backup and restore records and token-audit records associated with that store. The minimal free-trial abuse-prevention record described in Section 5.4 is intentionally retained separately.
7. Privacy requests and individual rights
Depending on applicable law, merchants and other individuals can have rights concerning personal data, such as rights to request access, correction, deletion, restriction, or other information about processing. Shopify also provides mandatory privacy workflows that enable store owners to make requests on behalf of customers.
Nexforge supports Shopify's required customers/data_request, customers/redact, and shop/redact workflows. Requests received through those mechanisms are authenticated before processing. You can also contact us directly using the privacy contact in Section 14. We may need to verify the request and may retain information when retention is required or otherwise permitted by applicable law.
8. Service providers and disclosures
We disclose information only as necessary to operate Nexforge, comply with law, protect the service, or complete a merchant-requested function. Our principal service providers/platforms are:
- Shopify: provides the commerce platform, application authentication, Shopify APIs, App Store distribution, and Shopify-managed billing/subscription functionality used by Nexforge.
- Amazon Web Services (AWS): provides cloud infrastructure used for application execution, PostgreSQL database hosting, object storage, encryption/key management, secrets management, content delivery, job orchestration/execution, security controls, and operational/audit logging.
Within AWS, Nexforge's architecture uses services such as Amazon S3, Amazon RDS for PostgreSQL and RDS Proxy, AWS Lambda, AWS Batch on Fargate, AWS Step Functions, AWS Key Management Service, AWS Secrets Manager, Amazon CloudFront, Amazon CloudWatch, AWS CloudTrail, AWS WAF, and related networking/security services. Listing a service here does not mean every service contains merchant catalog data; each component receives only the information needed for its infrastructure role.
We may also disclose information when reasonably necessary to comply with a valid legal process, enforce agreements, investigate abuse or security incidents, or protect the rights, safety, and integrity of merchants, Nexforge, Shopify, or others. We do not sell personal data.
9. International and geographic processing
Nexforge is cloud-hosted and can process information in a country or region different from the merchant's location. AWS processes data in the cloud region selected for the Nexforge production deployment and can provide supporting global services such as content delivery, security, and infrastructure management. Shopify can also process information internationally under Shopify's own privacy and contractual framework.
Where applicable law restricts international transfers of personal data, we take the applicable transfer requirements into account and rely on appropriate contractual, organizational, or legal safeguards provided by us or our service providers as required.
10. Security
We use technical and organizational safeguards designed to protect Nexforge information against unauthorized access, alteration, disclosure, or destruction. The production architecture is designed to include encrypted transport, encrypted database storage, encrypted backup-artifact and status-object storage, private S3 buckets, restricted AWS IAM permissions, AWS-managed key and secret storage, non-public PostgreSQL infrastructure, and separation between the frontend-facing control plane and isolated backup/restore workers.
Shopify access tokens and application secrets are not placed in Nexforge backup/restore job specifications or orchestration payloads. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
11. Cookies, storefront tracking, and analytics
Nexforge is an embedded Shopify Admin application. We do not place Nexforge advertising or behavioral-tracking cookies on shoppers' storefront devices, do not use buyer-facing web pixels for advertising, and do not use Shopify customer browsing behavior to build advertising profiles. Shopify Admin and the merchant's browser can independently use technologies controlled by Shopify as part of the Shopify platform.
The public Nexforge privacy-policy page is designed as a static informational page and does not require advertising or behavioral analytics scripts to function.
12. Children
Nexforge is a business application intended for Shopify merchants and authorized store personnel. It is not directed to children and is not designed to knowingly collect personal data directly from children.
13. Changes to this policy
We may update this Privacy Policy when Nexforge's features, data practices, infrastructure, legal obligations, or service providers change. We will post the updated policy at this URL and update the effective date above. Material changes will be communicated when required by applicable law or Shopify requirements.
14. Contact us
Questions, privacy requests, or concerns about this policy or Nexforge's data practices can be sent to:
App: NexforgeEmail: support-nexforge@enforger.com
If you are a Shopify customer seeking to exercise rights concerning information held by a Shopify merchant, you should generally contact that merchant first. Shopify's mandatory privacy workflows allow merchants to send applicable customer privacy requests to installed apps.