What is read on the storefront
The script the app embed loads reports, as a shopper moves:- Movement. Scroll position and direction, time on the page, time since the last click or scroll, clicks (which element, not what was typed), hovering that settles on one part of the page.
- Pages. The path of each page visited (
/products/merino-crew-tee,/cart), and the page title. - Forms. When a form is submitted or your theme shows a validation message, the field name and the message text (“Enter a valid discount code”). Every value is hashed on the page before it is sent: the app can tell that the same code was tried twice, but never what the code was. Email fields on the page are not read.
- The cart. Item handles, variant ids, quantities, prices, the total, the shopper’s country from the store’s country selector, and whether a discount code was applied. The code is hashed on the page; the app keeps the hash and whether Shopify accepted it.
- Checkout steps. Through Shopify’s web pixel: started, contact, shipping, payment, completed, with the order total and currency and the order reference. Nothing the shopper typed into checkout.
- A visitor id. A random identifier the script assigns in a NextIntent-owned frame, so the same browser is the same visitor across pages. It is not derived from anything about the person.
What is read from orders
Shopify sends every new order and refund to the app. The app strips the order before anything leaves for NextIntent. What goes:- The order id, name and number, the time, the currency, the totals (including the USD figure Shopify states), the financial status, and whether it is a test order.
- Discount codes used, with amounts.
- Line items as product handle, product and variant ids, price and quantity.
- The one cart attribute that carries the NextIntent visitor id.
- The customer’s Shopify id, as a number. NextIntent hashes it on arrival with a per-store key and keeps the hash, so an erasure request can find the orders.
What is kept
- A record per visitor, keyed by the random visitor id: visits, moments, whether they were spoken to, whether they bought.
- The moments: page, cart, reason, sentence, outcome.
- The order ledger: order reference, totals, refunds, the hashed customer reference, the visitor id when the cart carried one.
What is never kept
- Names, email addresses, phone numbers, postal addresses.
- Anything typed into a form, in the clear. Values are hashed on the page.
- Chat transcripts. The app does not read a chat tool’s messages.
- A shopper’s IP address on the moment record.
The claim on nextintent.ai/shopify is “No name or email address is ever shown to you or kept.” The precise version: the app never receives them from the storefront, strips them from the order before forwarding, and keeps a one-way hashed reference to the customer id so an erasure request can be honoured.
Erasure
Shopify’s privacy webhooks are handled as follows:- A customer asks what you hold (
customers/data_request). The app holds no personal fields for the customer: a behavioural record keyed by an opaque visitor id and orders with a hashed customer reference. The honest answer you can relay is “no personal data; a behavioural record with no identifying fields”. - A customer asks to be erased (
customers/redact). The app tells NextIntent to erase everything for that customer: the orders matching the hashed customer reference, the visitor records linked to those orders, and the moments for those visitors. If NextIntent is unreachable the app answers Shopify with an error so that Shopify retries, rather than dropping the request. - You uninstall (
shop/redact, 48 hours later). Everything for the store is erased at NextIntent, then the app deletes its own record of the store. If the erasure fails, the store record is kept so the erasure can be retried; it is never deleted before the erasure succeeds.
The frame
The script stores the visitor id in a small hidden frame served fromiframe.nextintent.ai, not in your store’s cookies. Your store’s pages ask the frame for the id and it answers only pages from the frame’s expected origin. The storefront never sets a NextIntent cookie on your domain.
