Privacy Policy
Effective October 8, 2026 · Version 1.1
- App
- Mais Brinde (Shopify App Store app)
- Legal name
- NEXTBIT DIGITAL LTDA
- Trade name
- NEXTBIT DIGITAL (brand NEXBIT)
- CNPJ (Brazilian company ID)
- 67.027.402/0001-50
- Registered office
- Rodovia SC-401, 4150, Primavera Office building, 3rd floor, room 01, Saco Grande, Florianópolis, Santa Catarina, 88032-000, Brazil
- Contact
- iagocesar-c@live.com
This policy explains what data the Mais Brinde app processes, why, who we share it with, how long we keep it and how you can exercise your rights. It follows Brazil’s General Data Protection Law (Law 13,709/2018, “LGPD”) and Shopify’s requirements for public apps. It applies to merchants who install the app and, where relevant, to the customers of stores that use it. This is an English translation of the Portuguese version, which prevails in case of conflict.
In short
- On our server we keep only what the app needs to work: your store’s address, the access keys Shopify gives us at installation, technical access logs and the app’s usage numbers for your store, with no shopper data.
- Your gift settings are stored inside your own store, on Shopify, not on our server.
- The app does not collect or store data about your store’s customers (name, email, address, orders).
- We do not sell data and we do not use advertising cookies or tracking tools.
1. Who is the controller
NEXBIT, identified in the box above, develops and operates Mais Brinde. For the merchant data described in this policy, NEXBIT is the controller: it decides how and why that data is processed.
For store customers, the controller is the store itself. As explained in section 4, Mais Brinde does not receive personal data about those customers.
2. What data we process
2.1 Installation data, stored on our server
| Data | Purpose | Legal basis (LGPD) |
|---|---|---|
Store domain (yourstore.myshopify.com) | Identify the app installation on your store. | Performance of a contract (art. 7, V) |
| Access token, refresh token, granted scopes and token expiry | Allow the app, on your behalf, to create and maintain the gifts, the progress bar and the checkout validation. | Performance of a contract (art. 7, V) |
| The app’s usage numbers for your store: installation date and first setup date, whether the bar is on in the theme, the status of each gift (active or out of units), how many times the settings were saved, and the daily count of gifts given, read once a day from the stock of the copies | Show you these numbers in the NEXBIT panel, monitor how the app works and provide support. They contain no shopper data. | Performance of a contract (art. 7, V) and legitimate interest (art. 7, IX) |
| Panel access logs: IP address, date and time of access, and the store domain | Keep the access logs required by article 15 of Brazil’s Internet Civil Framework. They contain no shopper data. | Compliance with a legal obligation (art. 7, II) |
We do not store the name, email or phone number of the people who use the app’s admin panel. Mais Brinde uses Shopify’s “offline” access, which is tied to the store rather than to a user.
2.2 Data kept in your store, on Shopify
The app reads and writes this information through the Shopify API, but it is stored in your store and is not copied to our server:
- The settings: cart value tiers, the product for each tier, the stacking rule, the maximum number of gifts, and the bar’s colors and texts.
- The gift products: unlisted zero-priced copies of the products you choose as gifts, with an app tag, a limited number of units and publication to the online store.
- The checkout validation (a Shopify Cart and Checkout Validation Function), which blocks completing an order with a gift that was not earned.
This is business data, not personal data. We process it to perform our contract with you (art. 7, V).
2.3 Subscription data
Mais Brinde is billed by Shopify, on your Shopify invoice. We receive from Shopify only the plan and the subscription status (trial, active or cancelled). We have no access to card or bank details. Legal basis: performance of a contract (art. 7, V).
2.4 Support
When you contact support, we process what you send us: name, email, store, the content of your message and any attachments. We use this data to answer and resolve your request and to improve the app. Legal basis: performance of a contract (art. 7, V) and legitimate interest (art. 7, IX). If we need to enter your store’s admin to fix a problem, we will request collaborator access through Shopify, which only takes effect after you approve it.
2.5 Technical logs
The app’s server automatically logs the requests it receives. There are two kinds of logs:
- Access logs (IP address, date and time of access, and the store domain, when the merchant uses the app panel): kept confidential in the app’s database for the 6 months required by article 15 of Brazil’s Internet Civil Framework (Law 12,965/2014). They contain no shopper data. Legal basis: compliance with a legal obligation (art. 7, II).
- Error and diagnostic logs (route accessed, store domain and error message): used for security, fraud prevention and fixing failures. Legal basis: legitimate interest (art. 7, IX).
3. Shopify permissions
At installation, Shopify shows you these permissions and asks for your approval. Each one has a reason:
| Permission | Why the app needs it |
|---|---|
read_products, write_products | Choose the product for each tier and create the zero-priced copies used as gifts. |
read_validations, write_validations | Install the checkout validation that checks the gift at checkout. |
write_inventory, read_locations | Set the limited number of units of the gift copy. |
read_publications, write_publications | Publish the gift copy to the online store so it can be added to the cart. |
None of these permissions gives access to customers or orders.
4. Your customers’ data
The progress bar runs in the store visitor’s browser and talks only to Shopify: it reads the cart and adds or removes the gift. It sends nothing to NEXBIT’s servers.
The checkout validation runs inside Shopify’s infrastructure. It sees only the cart lines (product, quantity and price), the checkout step, the store’s currency exchange rate and the app settings. It does not see name, email, phone number or address.
The app marks the gift line in the cart with a hidden property that indicates the tier reached. That mark stays in the cart and in the order, inside Shopify.
Therefore NEXBIT does not process personal data of store customers. The merchant remains the controller of that data, under Shopify’s rules. If a future feature needs access to orders or customers, we will update this policy first and request the new permission, which only takes effect once you approve it on Shopify.
5. Cookies and browser storage
- App admin panel. It runs inside the Shopify admin and authenticates with Shopify’s own session tokens. Mais Brinde does not set its own advertising, analytics or tracking cookies. Admin cookies belong to Shopify and follow Shopify’s privacy policy.
- Storefront bar. It sets no cookies. It uses the browser’s session storage (
sessionStorage) only for technical controls, such as the time of the last cart update and the tiers already processed. It holds no personal data, and the browser deletes it when the tab is closed. The cart cookie belongs to Shopify.
6. Sharing and sub-processors
We do not sell or rent data. We share data only with the providers that make the app possible (sub-processors), and only what each function needs:
| Provider | What it does | Location |
|---|---|---|
| Shopify | Store platform, subscription billing, running the checkout validation and storing the settings. | Canada, United States and other countries where Shopify operates |
| Vercel Inc. | Hosting of the app server and technical logs. | United States (Washington, D.C.) |
| Neon | Database that stores the store domain, the tokens and the usage numbers. | United States (AWS us-east-1, Virginia) |
| Microsoft (Outlook.com) | Receiving and answering support messages. | United States |
NEXBIT panel. The usage numbers described in section 2.1 appear to you in the NEXBIT panel, which you open with the “Ver painel completo” (see full panel) button in the app. The panel is a service run by NEXBIT itself. The NEXBIT team also sees these numbers, per store and in total, to monitor the app and provide support. No shopper data is included.
We may also share data when required by law, court order or a request from a competent authority. If NEXBIT goes through a merger, acquisition or sale of assets, data may be transferred to the successor company, which will be bound by this policy. In that case we will notify you in advance.
7. International transfers
The app’s server and database are in the United States, and Shopify operates in several countries, so data is transferred internationally. The transfer relies on article 33, IX, of the LGPD (necessary to perform our contract with you, under art. 7, V).
8. Retention and deletion
| Data | How long |
|---|---|
| Store domain and tokens | While the app is installed. When you uninstall, Shopify notifies us (app/uninstalled webhook) and we delete this data immediately. Access logs follow their own period, below. |
| Store usage numbers | While the app is installed. They are deleted when Shopify asks us to erase the store’s data (shop/redact webhook, 48 hours after uninstalling). Only the overall total, which does not identify the store, remains. |
| Database backups | The database provider’s restore history is overwritten within 30 days. |
| Access logs (IP, date and time and store domain) | 6 months, kept confidential in the app’s database (Neon, United States), as required by article 15 of the Internet Civil Framework. Then deleted automatically. They are kept until that period ends even after uninstallation, because the legal obligation prevails. |
| Error and diagnostic logs | Up to 30 days. |
| Support messages | Up to 2 years after the last contact. |
| Subscription data | Kept by Shopify. Tax records NEXBIT must keep are retained for the legally required period. |
What happens to the items created in your store
The settings, gift copies, checkout validation and other items created by the app live in your store. The Remover tudo (Remove everything) button in the app panel deletes the gift copies, the checkout validation, the tags and the app settings.
Important: click Remove everything before uninstalling. If you uninstall without it, the zero-priced copies stay published in your store and the checkout validation no longer exists, so anyone with the link to a copy can get it for free until the copy’s limited number of units runs out. After uninstalling, Shopify cuts our access and the app can no longer delete these items. In that case, archive or delete from the Shopify admin the products carrying the app’s tag.
Privacy requests sent by Shopify
Shopify forwards merchant and customer privacy requests to apps. Mais Brinde handles them as follows:
customers/data_request(a customer asks for their data): we answer the request and, since the app stores no customer data, there is no data to hand over to the merchant.customers/redact(a customer asks for deletion): we answer the request; there is no customer data to delete.shop/redact(sent about 48 hours after uninstallation): we delete the store’s domain and tokens, if they still exist. The store’s access logs are kept until 6 months have passed, as required by law, and then deleted automatically.
9. Your rights
Under article 18 of the LGPD, you may at any time request:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data, or data processed unlawfully;
- portability of your data to another provider;
- information about who we share your data with;
- review of decisions made solely by automated processing (the app makes no such decisions about people);
- objection to processing based on legitimate interest.
We do not use consent as a legal basis. If we ever do, you may withdraw it at any time.
To exercise these rights, email iagocesar-c@live.com with the subject “Privacy”, preferably from the email registered on your store. We may ask you to confirm your identity. This service is free of charge, and we reply within 15 days.
If you are a customer of a store that uses Mais Brinde, please contact that store, which is the controller of your data. If you write to us, we will guide you and forward your request.
You may also file a complaint with Brazil’s National Data Protection Authority (ANPD) at www.gov.br/anpd.
10. Security
- All communication with the app uses an encrypted connection (HTTPS/TLS).
- Access tokens stay on the server and are never sent to the browser.
- Database access is restricted by credentials, and the provider encrypts data at rest.
- We verify the digital signature of every webhook sent by Shopify before acting on it.
- We request from Shopify only the permissions the app needs to work.
No system is completely immune to failures. If a security incident may cause significant risk or harm, we will notify the ANPD and the affected merchants within 3 business days of becoming aware of it, as required by article 48 of the LGPD and ANPD Resolution CD/ANPD No. 15/2024. Merchants will be notified through the channels available to us: the app panel and, when we have your email (for example, if you have written to support), by email.
11. Minors
Mais Brinde is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children or teenagers.
12. Changes to this policy
We may update this policy. The effective date at the top always shows the current version. Material changes will be announced at least 15 days in advance, in the app panel and on the app’s Shopify App Store listing.
13. Contact and Data Protection Officer
As a small-scale processing agent, NEXBIT is exempt from appointing a Data Protection Officer (ANPD Resolution CD/ANPD No. 2/2022, art. 11). The channel for data subjects is iagocesar-c@live.com, subject “Privacy”.