Skip to main content
NextIntent is built so that personal data never arrives. This page is the developer’s view of what the merchant page Privacy and data states: where each protection sits and what a site that integrates directly has to keep true on its side.

Hash-and-drop on the page

  • Form values. The SDK hashes every value on submit before it leaves the page. The engine receives field names and hashes, and can tell “the same code twice” from “two different codes” without either code.
  • Validation messages. invalid_form carries the field and the message text the page showed. The engine scrubs the message (email addresses, long digit runs and quoted strings are removed) and keeps it only long enough to decide; the reason recorded on the moment is the field and a hash, not the message.
  • Discount codes in the cart. Hashed by the cart beacon on the page. See Commerce endpoints.
  • Email fields. Not read unless the site has visitor identification on. NextIntent for Shopify never turns it on.
If you write your own cart beacon or form handling, keep the same rule: hash on the page, send the hash.

What the collector logs

One line per signal with the event type and site id, and one per connection with the site id. No page URL, no IP address, no payload. The collector holds the visitor and device registry (visitor id, device fingerprint, user agent, first and last seen) and nothing else.

What the engine records

  • The fold, a live, short-lived picture of each visitor’s current visit in memory: pages, scroll, clicks, form state, cart. It expires soon after the visit ends.
  • The visitor record: visit count, moments, spoken-to, outcomes, keyed by visitor id, with a 90-day expiry.
  • The moments log: each decision with the page, cart, reason, sentence and outcome, kept in an archive and served to the views.
  • The order ledger: order reference, totals, refunds, the visitor id when known, and a one-way hashed customer reference.
Identity fields (name, email, company) exist in NextIntent only where a site has visitor identification enabled; NextIntent for Shopify does not, and the Shopify app strips them from orders before forwarding.

Erasure

POST /SITE_ID/privacy/erase is the entry point. It clears the ledger rows, deletes the visitor records, and publishes an erase signal. The engine forgets the fold and every key for the visitor and writes a tombstone so archived moments for that visitor are filtered out of every view. A site erasure does the same for every visitor on the site. The endpoint answers 5xx on any failure so the caller retries; the Shopify app answers Shopify’s webhook with an error in that case so Shopify retries.

Retention

Transport

Every endpoint is HTTPS. Storefront routes vary on Origin and are never cached across origins. The visitor frame answers only its embedding page. Management API tokens are bearer tokens; keys start with ni_live_ and are shown once at creation.