Skip to main content
NextIntent is built so that personal data does not arrive. On the page the SDK reads movement and hashes values before they leave; the collector logs that a signal arrived and not what it carried; the engine keeps a short-lived picture of the visit and a record keyed by an opaque visitor id. This page is what a site owner needs to know and say. The developer view, with each protection named at its layer, is Data and privacy (API); the shop-owner view is Privacy and data for Shopify.

What is read

Pages visited and time on them, scroll depth and direction, clicks and their timing, hover that settles on an element, stillness, form submits (field names and hashed values), the validation messages a page shows, page load timing, device type and screen size, and the cart when the page reports one. On a store, orders and refunds from your server with the order reference, totals and line items.

What is kept, and for how long

What is never kept

Typed values (hashed on the page), email addresses, names, phone numbers, postal addresses, payment details, the text of discount codes, IP addresses in the signal record. A validation message a page showed is scrubbed of email addresses, long digit runs and quoted text, used to decide, and recorded as a field name and a hash.

Visitor identification

One site setting changes the answer above. With visitor identification on, the SDK may read an email a visitor typed into a form and NextIntent may attach an identity (name, company) to the visitor record, and a chat agent may be told it. It is off by default, off on every Shopify site, and only turned on for an account that has asked for it and has the consent basis to use it. If you are not sure whether you need it, you do not.

What your privacy policy can say

“We use NextIntent to notice when a visitor appears stuck and to show a short message drawn from our own store information. NextIntent reads how visitors move through our pages (scrolling, clicks, time on page, form errors) and cart contents. It does not receive names, email addresses, typed form values or payment details, and it sets no cookie on our domain; a visitor identifier is held in a frame it controls. Visit records are kept for 90 days. A visitor’s data is deleted on request.” Adjust the last sentence if you have visitor identification on.

Erasure

POST https://sdk.nextintent.ai/SITE_ID/privacy/erase with the site’s key in X-NextIntent-Token and the customer’s id or email (hashed on arrival and used only to find matching records) or the order references, or scope: "shop" for the whole site. It clears the ledger rows, deletes the visitor records, and publishes an erase signal; the engine forgets everything live for the visitor and writes a tombstone so archived moments for that visitor drop out of every view. It answers 5xx on any failure so your caller can retry. A site-wide erase does the same for every visitor on the site. Details in Commerce endpoints.

Sub-processors and transport

Everything runs over HTTPS. Signals, the fold and the engine run on hosted infrastructure in the United States. The engine’s model calls carry the visit snapshot and the facts sheet and never an identity unless visitor identification is on. Ask support for the current sub-processor list for your data processing agreement.