Mais Brinde · NEXBIT

Privacy Policy

Effective October 8, 2026 · Version 1.1

App
Mais Brinde (Shopify App Store app)
Legal name
NEXTBIT DIGITAL LTDA
Trade name
NEXTBIT DIGITAL (brand NEXBIT)
CNPJ (Brazilian company ID)
67.027.402/0001-50
Registered office
Rodovia SC-401, 4150, Primavera Office building, 3rd floor, room 01, Saco Grande, Florianópolis, Santa Catarina, 88032-000, Brazil
Contact
iagocesar-c@live.com

This policy explains what data the Mais Brinde app processes, why, who we share it with, how long we keep it and how you can exercise your rights. It follows Brazil’s General Data Protection Law (Law 13,709/2018, “LGPD”) and Shopify’s requirements for public apps. It applies to merchants who install the app and, where relevant, to the customers of stores that use it. This is an English translation of the Portuguese version, which prevails in case of conflict.

In short

1. Who is the controller

NEXBIT, identified in the box above, develops and operates Mais Brinde. For the merchant data described in this policy, NEXBIT is the controller: it decides how and why that data is processed.

For store customers, the controller is the store itself. As explained in section 4, Mais Brinde does not receive personal data about those customers.

2. What data we process

2.1 Installation data, stored on our server

DataPurposeLegal basis (LGPD)
Store domain (yourstore.myshopify.com)Identify the app installation on your store.Performance of a contract (art. 7, V)
Access token, refresh token, granted scopes and token expiryAllow the app, on your behalf, to create and maintain the gifts, the progress bar and the checkout validation.Performance of a contract (art. 7, V)
The app’s usage numbers for your store: installation date and first setup date, whether the bar is on in the theme, the status of each gift (active or out of units), how many times the settings were saved, and the daily count of gifts given, read once a day from the stock of the copiesShow you these numbers in the NEXBIT panel, monitor how the app works and provide support. They contain no shopper data.Performance of a contract (art. 7, V) and legitimate interest (art. 7, IX)
Panel access logs: IP address, date and time of access, and the store domainKeep the access logs required by article 15 of Brazil’s Internet Civil Framework. They contain no shopper data.Compliance with a legal obligation (art. 7, II)

We do not store the name, email or phone number of the people who use the app’s admin panel. Mais Brinde uses Shopify’s “offline” access, which is tied to the store rather than to a user.

2.2 Data kept in your store, on Shopify

The app reads and writes this information through the Shopify API, but it is stored in your store and is not copied to our server:

This is business data, not personal data. We process it to perform our contract with you (art. 7, V).

2.3 Subscription data

Mais Brinde is billed by Shopify, on your Shopify invoice. We receive from Shopify only the plan and the subscription status (trial, active or cancelled). We have no access to card or bank details. Legal basis: performance of a contract (art. 7, V).

2.4 Support

When you contact support, we process what you send us: name, email, store, the content of your message and any attachments. We use this data to answer and resolve your request and to improve the app. Legal basis: performance of a contract (art. 7, V) and legitimate interest (art. 7, IX). If we need to enter your store’s admin to fix a problem, we will request collaborator access through Shopify, which only takes effect after you approve it.

2.5 Technical logs

The app’s server automatically logs the requests it receives. There are two kinds of logs:

3. Shopify permissions

At installation, Shopify shows you these permissions and asks for your approval. Each one has a reason:

PermissionWhy the app needs it
read_products, write_productsChoose the product for each tier and create the zero-priced copies used as gifts.
read_validations, write_validationsInstall the checkout validation that checks the gift at checkout.
write_inventory, read_locationsSet the limited number of units of the gift copy.
read_publications, write_publicationsPublish the gift copy to the online store so it can be added to the cart.

None of these permissions gives access to customers or orders.

4. Your customers’ data

The progress bar runs in the store visitor’s browser and talks only to Shopify: it reads the cart and adds or removes the gift. It sends nothing to NEXBIT’s servers.

The checkout validation runs inside Shopify’s infrastructure. It sees only the cart lines (product, quantity and price), the checkout step, the store’s currency exchange rate and the app settings. It does not see name, email, phone number or address.

The app marks the gift line in the cart with a hidden property that indicates the tier reached. That mark stays in the cart and in the order, inside Shopify.

Therefore NEXBIT does not process personal data of store customers. The merchant remains the controller of that data, under Shopify’s rules. If a future feature needs access to orders or customers, we will update this policy first and request the new permission, which only takes effect once you approve it on Shopify.

5. Cookies and browser storage

6. Sharing and sub-processors

We do not sell or rent data. We share data only with the providers that make the app possible (sub-processors), and only what each function needs:

ProviderWhat it doesLocation
ShopifyStore platform, subscription billing, running the checkout validation and storing the settings.Canada, United States and other countries where Shopify operates
Vercel Inc.Hosting of the app server and technical logs.United States (Washington, D.C.)
NeonDatabase that stores the store domain, the tokens and the usage numbers.United States (AWS us-east-1, Virginia)
Microsoft (Outlook.com)Receiving and answering support messages.United States

NEXBIT panel. The usage numbers described in section 2.1 appear to you in the NEXBIT panel, which you open with the “Ver painel completo” (see full panel) button in the app. The panel is a service run by NEXBIT itself. The NEXBIT team also sees these numbers, per store and in total, to monitor the app and provide support. No shopper data is included.

We may also share data when required by law, court order or a request from a competent authority. If NEXBIT goes through a merger, acquisition or sale of assets, data may be transferred to the successor company, which will be bound by this policy. In that case we will notify you in advance.

7. International transfers

The app’s server and database are in the United States, and Shopify operates in several countries, so data is transferred internationally. The transfer relies on article 33, IX, of the LGPD (necessary to perform our contract with you, under art. 7, V).

8. Retention and deletion

DataHow long
Store domain and tokensWhile the app is installed. When you uninstall, Shopify notifies us (app/uninstalled webhook) and we delete this data immediately. Access logs follow their own period, below.
Store usage numbersWhile the app is installed. They are deleted when Shopify asks us to erase the store’s data (shop/redact webhook, 48 hours after uninstalling). Only the overall total, which does not identify the store, remains.
Database backupsThe database provider’s restore history is overwritten within 30 days.
Access logs (IP, date and time and store domain)6 months, kept confidential in the app’s database (Neon, United States), as required by article 15 of the Internet Civil Framework. Then deleted automatically. They are kept until that period ends even after uninstallation, because the legal obligation prevails.
Error and diagnostic logsUp to 30 days.
Support messagesUp to 2 years after the last contact.
Subscription dataKept by Shopify. Tax records NEXBIT must keep are retained for the legally required period.

What happens to the items created in your store

The settings, gift copies, checkout validation and other items created by the app live in your store. The Remover tudo (Remove everything) button in the app panel deletes the gift copies, the checkout validation, the tags and the app settings.

Important: click Remove everything before uninstalling. If you uninstall without it, the zero-priced copies stay published in your store and the checkout validation no longer exists, so anyone with the link to a copy can get it for free until the copy’s limited number of units runs out. After uninstalling, Shopify cuts our access and the app can no longer delete these items. In that case, archive or delete from the Shopify admin the products carrying the app’s tag.

Privacy requests sent by Shopify

Shopify forwards merchant and customer privacy requests to apps. Mais Brinde handles them as follows:

9. Your rights

Under article 18 of the LGPD, you may at any time request:

We do not use consent as a legal basis. If we ever do, you may withdraw it at any time.

To exercise these rights, email iagocesar-c@live.com with the subject “Privacy”, preferably from the email registered on your store. We may ask you to confirm your identity. This service is free of charge, and we reply within 15 days.

If you are a customer of a store that uses Mais Brinde, please contact that store, which is the controller of your data. If you write to us, we will guide you and forward your request.

You may also file a complaint with Brazil’s National Data Protection Authority (ANPD) at www.gov.br/anpd.

10. Security

No system is completely immune to failures. If a security incident may cause significant risk or harm, we will notify the ANPD and the affected merchants within 3 business days of becoming aware of it, as required by article 48 of the LGPD and ANPD Resolution CD/ANPD No. 15/2024. Merchants will be notified through the channels available to us: the app panel and, when we have your email (for example, if you have written to support), by email.

11. Minors

Mais Brinde is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children or teenagers.

12. Changes to this policy

We may update this policy. The effective date at the top always shows the current version. Material changes will be announced at least 15 days in advance, in the app panel and on the app’s Shopify App Store listing.

13. Contact and Data Protection Officer

As a small-scale processing agent, NEXBIT is exempt from appointing a Data Protection Officer (ANPD Resolution CD/ANPD No. 2/2022, art. 11). The channel for data subjects is iagocesar-c@live.com, subject “Privacy”.