Privacy Policy & Data Security
NEXA's comprehensive commitment to safeguarding merchant privacy, customer data, and operational confidentiality
Executive Summary
At NEXA, protecting your business intelligence and customer trust is our foundational commitment. This policy outlines how we collect, process, encrypt, and safeguard your data.
1. Information We Collect
To deliver automated CRM workflows, AI-powered conversational sales, and order management, NEXA collects and processes:
- Account Credentials: Full name, business email, mobile phone number, and securely hashed passwords.
- Store & Catalog Data: Product catalog details, pricing structures, variant inventories, descriptions, and media assets.
- Conversational Streams: Inbound and outbound customer messages across connected messenger channels (Telegram and supported platforms) for AI reasoning and unified inbox display. Instagram Direct is coming soon.
- Order & Fulfillment Details: Customer shipping information, itemized checkout orders, and banking gateway confirmation receipts.
2. Tenant Isolation & AI Processing Safeguards
Your catalog data and customer conversations are strictly isolated within dedicated tenant silos and are never shared across accounts.
Your customer interactions and sales dialogues are never used to train public global foundational AI models or exposed to competitors.
Enterprise Silo Architecture: Every store's embeddings and conversational state reside in tenant-isolated encrypted partitions.
3. API Token & Credential Encryption
All third-party access tokens (Meta Graph API, Telegram Bot Tokens, Webhook secrets) are encrypted at rest using industry-standard AES-256 encryption with rotating key management.
4. Data Portability & Complete Deletion
You retain full ownership of your data at all times. You can export complete CSV/JSON datasets of your products, orders, and customer base whenever needed, or request total cryptographic erasure upon account closure.