Nimble
Privacy Data Protection Agreement Data Deletion Terms Contact

Privacy Policy

Effective date: 2026-05-07  ·  Last updated: 2026-08-20

Summary (TL;DR)

  • We read your Shopify store — products, content, files, orders, inventory, and customers — so our AI agents can run marketing and commerce operations for your brand.
  • Where you enable email, SMS, loyalty, subscriptions, or support, we process your customers' personal data on your behalf: names, email addresses, phone numbers, order history, and consent state. We do this as your processor, under our Data Protection Agreement, on your instructions.
  • We never sell, rent, or share your data or your customers' data with advertisers or data brokers.
  • We never use your data or your customers' data to train AI models.
  • Your customers' data is never mixed with another merchant's, and never used to benefit another brand.
  • We delete your data when you uninstall.
  • You can request access, correction, export, or deletion at any time.

1. Who we are

Nimble is operated by Nimble VC LLC.

  • Contact email: help@nimblevc.com
  • Security contact: security@nimblevc.com
  • Mailing address: Available on request via help@nimblevc.com

2. Scope

This Privacy Policy covers information collected via:

  • The Nimble Shopify app (embedded admin dashboard)
  • OAuth token exchange between Shopify and Nimble
  • Webhooks sent by Shopify to Nimble
  • Interactions you have with the Nimble dashboard

It does not cover:

  • The processor/controller terms that govern your customers' personal data. This policy describes what customer data Nimble receives and why (§3.2); how we process it on your behalf — your instructions, our obligations, sub-processors, deletion, and the EU Standard Contractual Clauses — is set out in our Data Protection Agreement, under which you are the controller and Nimble is your processor.
  • Your Shopify account credentials (these stay with Shopify)
  • Third-party services you may use alongside Nimble (see those services' privacy policies)

3. Information we collect

3.1 Information you provide

  • Your shop's myshopify.com domain
  • Brand context you optionally add (competitors, target audiences, approved claims, prohibited claims, language rules)
  • Content feedback (approve / edit / reject on generated pieces)

3.2 Information we collect from Shopify (via your authorization)

The Nimble app requests 16 OAuth scopes. This is the complete list — every scope the app holds, what each one exposes, and what we use it for. You grant them at install time and Shopify re-prompts you whenever we add one.

OAuth scopeWhat it exposesWhat Nimble uses it for
read_productsProduct titles, descriptions, handles, variants, prices, images, and product URLsGenerating content that references your real products; product-page and catalog audits; ad and showcase creative
read_contentYour existing blog articles, pages, and blog structureMatching your existing voice, avoiding duplicate topics, and building internal links
write_contentCreates and updates blog articles and pages on your storePublishing approved articles and pages to your Shopify blog
read_filesFiles already in your Shopify Files libraryReusing your own brand imagery instead of generating new images
write_filesUploads files into your Shopify Files libraryStoring Nimble-generated images so published content can reference them
read_ordersOrders and abandoned checkouts: dates, totals, currency, line items, the order's email address, the associated customer record, and the order's shipping city and countryRevenue, order-count, AOV and repeat-rate metrics in the app; abandoned-checkout, post-purchase and win-back flows; loyalty accrual; segmentation; looking up a customer's own order when you enable AI-assisted support
read_customersCustomer records: first and last name, email address, phone number, email and SMS marketing-consent state, and the city, region, postal code and country on the customer's default addressBuilding and maintaining your email and SMS subscriber lists with their consent state; loyalty membership; audience segments (including geographic segments); identity resolution for AI-assisted support
read_customer_eventsStandard storefront events emitted by Shopify's web-pixel sandbox — page viewed, product viewed, checkout started, checkout completedStorefront traffic and funnel measurement. What our pixel actually sends to us is a pseudonymous visitor id, the event name, a timestamp and the page URL — no name, email, or phone
write_pixelsCreates and configures Nimble's own web pixel on your storefrontInstalling the pixel above at install time, and keeping its configuration current
read_inventoryPer-variant inventory levels and inventory itemsProduct-page availability audits, back-in-stock triggers, and not promoting sold-out products
read_locationsYour store's own locations (the lookup target for inventory levels) — your locations, not your customers' addressesResolving which location an inventory level belongs to
read_shippingShipping zones, rates, and delivery profilesThe checkout health audit — finding shipping gaps and rate problems that cost you conversions
read_publicationsWhich sales channels each product is published toThe sales-channel listing audit
write_discountsCreates and modifies discount codes in your store — real, redeemable codesIssuing the discount codes that campaigns, loyalty rewards, and win-back offers depend on
write_ordersPermits Nimble to create and modify orders and draft orders in your storeNothing today. No Nimble feature writes to your orders; the scope is held for subscription and order-editing features that are not yet live. We will update this table, and notify you under §12, before that changes
write_customersPermits Nimble to create and modify customer records in your store, including their marketing-consent state and tagsNothing today. No Nimble feature writes to your customer records; the scope is held for writing consent and segment tags back to Shopify. We will update this table, and notify you under §12, before that changes

Two of these scopes — read_customers and read_orders — expose your customers' personal data. Where Nimble processes it, it does so as your processor, on your instructions, under the Data Protection Agreement.

3.3 Information we create on your behalf (and write back to Shopify)

  • Blog articles and pages published to your Shopify blog, OAuth scope write_content
  • Images uploaded to your Shopify Files, OAuth scope write_files
  • Discount codes created for campaigns, loyalty rewards, and offers, OAuth scope write_discounts
  • The Nimble web pixel installed on your storefront, OAuth scope write_pixels

3.4 Technical information

  • Shopify-provided session tokens (JWT) for authentication
  • OAuth access tokens (refreshed automatically, encrypted at rest)
  • Request logs (shop domain, endpoint, status code, timestamp), retained 30 days for operational reliability

3.5 What we do not collect

  • Payment credentials. We never receive card numbers or payment instruments. Shopify and our payment processors handle these; we see only whether a charge succeeded.
  • Your Shopify account password or staff credentials.
  • Your store's own web analytics — visitor sessions and recordings held in Shopify Analytics or any third-party analytics tool you use.

3.6 Website analytics (our marketing website)

Separately from the Shopify app, we measure traffic on our own marketing website (nimblevc.com) to understand which pages help merchants. This is standard, privacy-conscious website analytics about visits to our site — not your store's data:

  • We use PostHog (product analytics) and Google Analytics 4 (web analytics).
  • Analytics are anonymized — website analytics events carry no directly identifying information about a visitor to nimblevc.com, and we do not build a profile of an individual visitor.
  • Session replay / session recording is disabled — we never record your screen, keystrokes, or page interactions on our website.
  • Analytics requests are routed first-party through our own domain (a /ingest path on nimblevc.com), so analytics still respects your browser's tracking and cookie protections.
  • For visitors in the EU/EEA/UK, advertising and analytics storage default to denied (cookieless measurement) unless you grant consent.

3.7 Connected third-party accounts

You can optionally connect third-party accounts to Nimble from inside the Shopify app — today that includes Meta (Facebook and Instagram ads), TikTok, Pinterest, Reddit, Canva, Slack, Klaviyo, Intuit QuickBooks, and your bank and card accounts through Plaid (our financial data provider — see §3.8). The Connections screen in the app is the live list. When you connect one, here is exactly what we store and how we handle it:

  • What we store: the connected account's access token and, where that provider issues one, its refresh token (plus the minimal account identifiers needed to use them). We do this only after you complete that provider's own consent screen and authorize the connection. The bank connection in §3.8 is one of the providers that issues no refresh token — Plaid returns an access token only.
  • How it's stored: tokens are encrypted at rest in Supabase Vault (§7), scoped to your store only — never logged and never shared with another merchant or with advertisers.
  • What we use it for: only to perform the actions you authorized — for example, pushing a Nimble-generated image into a "Nimble" folder in your Canva account, publishing an approved post to a social channel, or managing your Meta ads on your behalf. We use the connection for nothing else.
  • What we do NOT store: we do not store your Canva designs or your Meta ad content beyond what Nimble creates on your behalf. We do not copy your existing designs, ad library, audiences, or creative out of those accounts. Where a connection is an import you asked for — for example bringing your existing subscriber list over from Klaviyo — we store what you asked us to import, and §3.2's customer-data terms apply to it.
  • Deletion: tokens are deleted when you disconnect the account in the app, and when you uninstall Nimble (§8). For most providers the token is destroyed immediately. The bank connection in §3.8 is the exception and is stated separately there, because it must first be removed at Plaid before the token can be destroyed: its outer deadline is 24 hours. See the Data Deletion page for the deletion flow, including the bank-connection path.

3.8 Financial account connections (bank and card accounts)

Where this connection is enabled for your store, you can optionally connect your business bank and card accounts to Nimble from the Bank & card accounts card in Settings → Integrations. It is being rolled out store by store, so the card appears only once it is switched on for you — the Settings → Integrations screen in the app is the live list. The connection is made through Plaid, our financial data provider. You sign in to your bank inside Plaid's own window — your bank username and password are entered in Plaid and are never transmitted to, proxied by, or visible to Nimble. No money movement of any kind is possible through this connection: Nimble can read, and cannot pay, transfer, or withdraw. We hold no capability that would let us move money, and we do not have your account or routing numbers.

What Nimble receives today, when you connect an account:

  • The connection itself — an access token, held encrypted in a vault scoped to your store alone, used only to keep the connection alive.
  • Account display details — the account name, its type and subtype, and the last-four mask Plaid itself shows you during sign-in, so you can tell your connected accounts apart.
  • Connection status — whether the connection is healthy or needs re-authenticating.

What Nimble does NOT receive:

  • Your account and routing numbers — the numbers that would let someone debit or credit the account directly. Plaid calls this product Auth, and Nimble does not enable it, so this data never enters Nimble's systems.
  • Your name, address, phone, or email as your bank holds them — the contact details on file at your institution. Plaid calls this product Identity, and Nimble does not enable it.
  • Your loan, credit-card, and mortgage balances — what you owe, your APRs, and your payment due dates. Plaid calls this product Liabilities, and Nimble does not enable it.
  • Your bank username and password — these are entered inside Plaid and never reach us.
  • Your balances. Nimble does not request, read, use, or store them, and our database carries no balance column. Stated precisely: when we look up the account display details above, Plaid's reply can carry a balance figure alongside the fields we asked for, and Nimble discards it unread — it is never parsed, never surfaced, and never written down.
  • Your individual transactions. When you connect, the authorization you grant does cover Plaid's Transactions product, so that reporting can be built on it later — but Nimble retrieves and stores no transaction record at this time, and our database carries no column for one. When transaction retrieval ships, it will be read-only, and this policy will state the retention period before the first record is retrieved.

Where it is stored. The Plaid access token is encrypted at rest in Supabase Vault (§7), keyed to your store and to the individual connection, never written to a database table, never logged, and never sent to another provider. The account display details and connection status are stored in our Supabase database (§6). Two separate controls keep them isolated per merchant: row-level security is enabled and forced on that table with no public-role policy at all, so the database's own web interface returns nothing to any browser-side caller; and every read the application makes runs under a dedicated server-side service identity that scopes the query to your store. Your financial data is never mixed with another merchant's, and is never shared with advertisers or data brokers.

How long we keep it. These periods are the same ones stated in our Data Retention and Disposal Policy:

  • Access token: kept for the life of the connection, and destroyed within 24 hours of disconnection or of your account being terminated.
  • Account display details and connection status: kept for the life of the connection, and deleted within 30 days of disconnection or account termination.
  • Transaction records: not collected at this time. If and when transaction retrieval is deployed, they will be kept on a rolling 24 months while connected and deleted within 30 days of disconnection or account termination. We state the rule now so that it governs from the first record retrieved rather than being written afterwards.

How you disconnect, and what is deleted when you do. Press Disconnect on the Bank & card accounts card in Settings → Integrations, at any time and without contacting us. Nimble first removes the connection at Plaid — so nothing is left authorized against your bank — and only then destroys the stored access token and deletes the stored connection. That order is deliberate: destroying the token first would leave an authorization at your bank that we could no longer revoke. If the removal at Plaid does not succeed, we keep the connection and its token rather than clearing it silently — dropping our token while your bank still had the connection authorized would leave something we could no longer switch off. The card shows the connection as still pending removal and offers a Retry disconnect button. To be plain about who acts: nothing retries on its own — there is no background sweep. A retry happens when you press that button, or when Shopify re-delivers the uninstall notification. Uninstalling Nimble runs the same removal automatically, and the deadlines above — 24 hours for the token, 30 days for the account display details and connection status — apply from that point (§8).

4. How we use your information

We use the information above only to:

  1. Generate marketing content tailored to your brand (SEO blog articles, social media copy, email content, Pinterest posts, video scripts, strategy briefs)
  2. Publish approved content to your Shopify store
  3. Display an embedded dashboard in your Shopify admin showing your brand profile, content feed, activity log, and billing status
  4. Run automated quality checks on generated content before delivery
  5. Run the email, SMS, loyalty, subscription, and customer-support programs you turn on — including sending messages to the customers who have consented to receive them, and honoring their opt-outs
  6. Build the audience segments those programs send to, from the customer data described in §3.2
  7. Create and manage the paid and organic social campaigns you approve
  8. Measure storefront traffic, funnel steps, and campaign performance so we can show you what worked
  9. Support you via the email you have on file with Shopify
  10. Comply with legal obligations (tax, record-keeping, lawful requests)

We do not use your data, or your customers' data, to:

  • Train or fine-tune AI models — ours or anyone else's
  • Build competitive intelligence against you or your peers
  • Benefit another merchant, in any form
  • Upload your customer list to an advertising platform, or build advertising audiences out of your customers' data
  • Enrich third-party data brokers

5. AI processing

We use Anthropic's Claude models to generate content, with Google's Gemini models as a capacity fallback when the Claude API is rate-limited. What gets sent to a model depends on the feature, and the difference matters:

  • Content generation (articles, social and email copy, ad creative, strategy briefs): your brand context and product information are sent as prompts. No customer personal data is sent. The per-recipient email and SMS send paths contain no model call at all — each message is rendered from a template, not generated per recipient.
  • AI-assisted customer support and buyer chat, where you enable them: the content of your customer's own message is sent to the model to generate a reply, and may contain personal data your customer chooses to include. Where the customer has proven who they are, the order context needed to answer is sent too — the order number, its status, and its city and country. The lookup never selects a street address, and payment details are never sent to a model.

In both cases:

  • Anthropic does not train on API inputs by default (per their published API terms; we re-verify periodically), and retains prompts briefly for abuse detection (per their published retention policy). Google's paid Gemini API terms likewise exclude API inputs from model training.
  • We do not use any AI provider that trains on API inputs.

If this changes (e.g., we evaluate a different provider), we will update this policy and notify you before any change takes effect.

6. How we share your information

We share data only with service providers that make Nimble work:

ProviderWhat they receiveWhy
ShopifyOAuth scopes, read/write requests, webhook deliveriesThe app you installed
Anthropic (AI model provider)Prompts containing your brand context + product data. Where you enable AI-assisted support or buyer chat, also the content of your customer's message and the order context needed to answer it (§5)Content generation; AI-assisted support
Google (Gemini API)The same prompts as Anthropic, on the capacity-fallback path only (§5)AI fallback when the Claude API is rate-limited
Supabase (database + authentication)All Nimble-stored data, including your customers' data (encrypted at rest)Storage
Google Cloud Run (hosting)Application traffic in transit (HTTPS)Compute
Resend (email delivery)Recipient email address and name, and the rendered message, at send timeSending the email programs you enable
Twilio (SMS delivery)Recipient phone number and the message body, at send timeSending the SMS programs you enable
Stripe (payments)Your billing contact and payment status. Card details go to Stripe directly and never pass through NimbleBilling on custom plans that are not billed through Shopify
Meta (Facebook / Instagram)Ad creative, copy, budgets and campaign settings for the ads you approve. No customer list and no customer personal data is uploaded to MetaRunning your paid social campaigns
bundle.social (social publishing)Post copy and media for the organic social channels you connectPublishing organic social posts
CanvaNimble-generated images you choose to send to your Canva accountThe "Send to Canva" action (§3.7)
Intuit QuickBooksAccounting entries and ledger data, where you connect QuickBooksAccounting sync (§3.7)
Plaid (financial data provider)Your request to connect a bank or card account, and the account display details and connection status returned for the accounts you connect. No account or routing numbers, no bank-held identity data, and no stored balances or transaction records — and no money movement is possibleBank and card account connections (§3.8)
PostHog (product analytics)Anonymized website-usage events (no session replay)Website analytics (§3.6)
Google Analytics (web analytics)Anonymized website-traffic eventsWebsite analytics (§3.6)

Every provider above is used only to deliver the feature it is named against. We do not:

  • Sell your data, or your customers' data
  • Rent your data, or your customers' data
  • Share your data, or your customers' data, with advertisers or data brokers
  • Share your data, or your customers' data, with other merchants

Where a provider above processes your customers' personal data, it is engaged as a sub-processor under our Data Protection Agreement, which names the full sub-processor list and commits us to 30 days' notice before we add or replace one.

We may disclose data when required by law (e.g., subpoena, court order) or to protect safety, rights, or property. We will notify you unless legally prohibited.

7. Data security

  • Encryption at rest: All data stored in Supabase with AES-256 encryption
  • Encryption in transit: HTTPS/TLS on every endpoint
  • Row-level security: Enforced on every database table so one merchant can never read another's data
  • Token storage: OAuth tokens stored in Supabase Vault; never logged, never sent in headers
  • Webhook verification: HMAC signatures verified on every Shopify webhook using timing-safe comparison
  • Rate limiting: in place on every endpoint to prevent abuse
  • Access controls: Production database access is limited to the named operator allowlist of Nimble VC LLC — today a single principal, the Chief Executive Officer — and every access is audit-logged. Application access runs under dedicated per-service identities holding only the permissions each service needs.
  • Regular security reviews: Codebase reviewed for common vulnerabilities (OWASP Top 10, credential leakage)

No system is 100% secure. If we discover a breach affecting your data, we will notify you within 72 hours of discovery.

8. Data retention

  • While you're a Nimble customer: we retain all data necessary to provide the service
  • When you uninstall: we receive Shopify's app/uninstalled webhook and mark your brand as inactive within minutes. OAuth tokens are invalidated.
  • Your bank connection, if you have one (§3.8): uninstalling does something different from invalidating a token — the connection is removed at Plaid first, so nothing stays authorized against your bank, and only then is the stored access token destroyed. The token goes within 24 hours; the account display details and connection status go within 30 days. If the removal at Plaid fails, we keep the token so the connection stays revocable, and it is retried when you press Retry disconnect or when Shopify re-delivers the uninstall notification.
  • On shop/redact webhook (Shopify GDPR endpoint): we delete your stored credentials and brand data within 30 days, per Shopify's GDPR webhook spec.
  • Order and customer records: where you enable a feature that needs them, we store per-order rows (date, total, line-item context, and Shopify's customer id) and per-customer subscriber rows (name, email, phone, consent state, and coarse location) for as long as the app is installed. Your email, loyalty, and order-linked records for a named individual are deleted on customers/redact, and all of it is deleted on shop/redact.
  • SMS records (phone number, consent state, and message history): deleted in full on shop/redact. The automated customers/redact path does not yet reach them — to erase one individual's SMS records, email help@nimblevc.com and we do it on request.
  • Order-derived metrics (daily revenue, order counts, average order value): retained while the app is installed; permanently deleted with the rest of your brand data on shop/redact.
  • Backups: Supabase maintains encrypted backups for 30 days. Backups containing deleted data are purged on the 30-day rolling cycle.
  • Operational logs: request logs retained 30 days, then deleted.
  • Aggregate non-identifying metrics: counts of content generated and error rates, retained indefinitely and not linkable back to you or your store.

9. Your rights

You have the right to:

  • Access the data we hold about you
  • Correct inaccurate data
  • Delete your data (uninstall triggers this automatically; we honor customers/redact and shop/redact Shopify webhooks)
  • Export your data in a machine-readable format
  • Object to processing
  • Restrict certain processing activities
  • Withdraw consent at any time by uninstalling the app

For California residents (CCPA / CPRA)

In addition to the above, you have the right to know the categories of information collected, the purposes, and third parties with whom we share. This document provides that disclosure. We do not sell your information under the CCPA definition of "sell."

For EU / EEA / UK residents (GDPR / UK-GDPR)

Our lawful basis for processing is contract (the app you installed) and, where applicable, legitimate interest (e.g., abuse detection, service reliability). You have the right to lodge a complaint with your national data protection authority.

Exercising your rights: email help@nimblevc.com with "Privacy Request" in the subject. We respond within 30 days.

10. International data transfers

Nimble operates from the United States. When you use the app from outside the US, your data is transferred to the US for processing. We rely on:

  • Your consent (captured at OAuth install) for initial transfer
  • Standard Contractual Clauses (SCCs) with our processors where applicable

We do not transfer data to countries without adequate protection safeguards.

Where Nimble processes your customers' personal data on your behalf, the processor/controller terms — including the EU SCCs, the UK Addendum, and the Swiss adaptations — are set out in our Data Protection Agreement.

11. Children

Nimble is a B2B tool for merchants. We do not knowingly collect information from anyone under 18. If you believe a minor has provided information to us, please email help@nimblevc.com and we will delete it.

12. Changes to this policy

We may update this policy. When we do:

  • We will update the "Last updated" date at the top
  • For material changes (new data collection, new sharing categories, new uses), we will notify active merchants by email at least 30 days before the change takes effect
  • Continued use after the effective date constitutes acceptance

13. Contact

For privacy questions, data requests, or to report a concern:

  • Email: help@nimblevc.com (general privacy)
  • Email: security@nimblevc.com (security issues)
  • Response time: within 5 business days for general requests; 72 hours for security incidents

This policy is written in plain English deliberately. If anything is unclear, email us and we'll explain.

© 2026 Nimble · The honest call on every tool you pay for. Nimble is an independent product; not affiliated with Shopify Inc.
For founders For operators Growth agency Pricing Privacy Terms DPA Data deletion Contact