Privacy Policy
Last updated: August 17, 2026
This policy describes how Apps Alchemy (“we”, “us”) collects, uses, and deletes information when you install or use NexusWatch, a Shopify app that monitors US economic nexus thresholds from your store’s orders.
We designed NexusWatch to minimize personal data. We do not store customer names, addresses, or emails. Order data is reduced to anonymous, state-level daily totals.
Who we are
NexusWatch is operated by Apps Alchemy. For privacy questions, email [email protected].
Information we collect through Shopify’s APIs
When you install NexusWatch, we request access to your orders so we can estimate economic nexus by destination state. From Shopify we read:
- Shop profile. Shop name, myshopify domain, shop email, Shopify plan display name, currency, and shipping-zone country codes. We persist shop name, domain, and shop email on your shop record.
- Order location and totals — not customer identity. For US orders we read order created date, order total, and shipping (or billing) province/state code. We do not store customer names, street addresses, phone numbers, or emails.
- State-level order aggregates. We keep one row per shop, calendar day, and US state with revenue and transaction count. That is the data shown on the nexus map.
- Order IDs for deduplication. We store Shopify order IDs so webhooks and daily sync never double-count an order. These IDs are not customer names and are not used to profile buyers.
- Sessions. Shopify session storage holds the shop domain, access token (and refresh token when issued), and, for online sessions, the logged-in staff user’s id, first name, last name, and email. Tokens are used only to call the Shopify Admin API on your behalf.
Information you provide
- Alert emails. Threshold alerts go to your shop email by default. You may set a different recipient email in Alerts. We store that address, whether email alerts are on, and the percent threshold you chose.
- Alert history. When we send (or skip) an alert, we log the state, alert type, progress percent, channel, and send time — not customer data.
- Compliance checklists and feature requests. Checklist progress and any feature ideas or votes you submit are stored against your shop, not against individual customers.
Information we do not collect from your customers
NexusWatch does not run on your storefront. We do not drop cookies on buyers’ devices, log how customers browse your store, or collect customer personal data for marketing. We do not sell personal information.
How we use this information
- Calculate state-by-state nexus progress and show it in the app.
- Send transactional threshold alert emails when a state approaches or crosses its limit.
- Authenticate the embedded admin app and keep your shop in sync.
- Provide support, billing plan access, and product improvements.
- Send ourselves a one-time install notice (and occasional “app opened” operational alerts) with shop name, domain, owner name, and shop email so we can support the product. We do not use this for advertising to your customers.
Service providers
We use subprocessors only to run NexusWatch:
- Shopify — authentication, Admin API, and subscription billing. We do not store card numbers.
- PostgreSQL host — application database (shops, aggregates, sessions, alert settings).
- Resend — delivery of alert emails to the address you configure.
- Crisp — optional live chat if you contact us from Support.
- Telegram — internal install/open notices to the Apps Alchemy team (shop name, domain, owner name, shop email).
Data may be processed outside the European Economic Area, including in the United States, depending on where these providers operate.
Retention and deletion
We keep your shop data while NexusWatch is installed, for as long as it is needed to provide the service.
- Uninstall. When you uninstall, we delete Shopify sessions for that shop and mark the shop as uninstalled. We stop sending alerts.
- shop/redact. Shopify sends this mandatory webhook about 48 hours after uninstall. We then delete the shop record and everything that cascades with it (state-level aggregates, order IDs, alert settings and logs, compliance progress, sync logs), plus remaining sessions and that shop’s feature votes and requests.
- customers/redact. If Shopify asks us to erase data for specific customer-linked orders, we delete the matching stored order IDs. Daily state aggregates are anonymous totals (date, state, revenue, count) with no customer names, so they stay in place unless the whole shop is redacted.
- customers/data_request. We do not keep customer names or other customer PII, so there is nothing customer-specific to return beyond acknowledging the request.
You can also email [email protected] to ask us to access, correct, or delete merchant data we hold.
Security
Access tokens and secrets are stored in our database and environment configuration, not in client-side code. Admin API calls are made over HTTPS. We request only the order access needed to compute destination-state totals.
Changes
If we change this policy, we will update the date above and post the new version at this URL.
Contact
Apps Alchemy — NexusWatch
Email:
[email protected]