Privacy policy · effective September 21, 2026

How NextIntent handles data.

NextIntent, Inc. reads live behavior on a customer's website and decides when, why and how to help a visitor. This policy says what we process, why, for how long, and the choices people have. It covers visitors to our own site, the businesses that use the service, and the visitors to those businesses' sites.

1. Shoppers on a customer's site

We act as a processor on the customer's behalf. What our script measures is timing and movement: which page is open and for how long, scrolling, cursor and touch movement, clicks, and whether a form was submitted. On stores it also reads the cart: item count, total, product handles, and whether a discount code was accepted. We do not read or store what a shopper types. Form values are replaced by a one-way hash before they leave the page; discount codes are never stored in clear text. Chat messages are never read.

Each shopper is represented by a random identifier held in the browser. We do not collect names, email addresses, phone numbers or postal addresses from a store. Where a store shares an order with us, we receive the order total, the currency, the order number, whether a code applied, and a one-way hash of the customer reference, so a purchase can be matched to the on-site moment that preceded it. We never receive the customer's name, email, phone or address.

Purposes: to notice the moment a shopper is stuck, to show one true sentence from the store's own facts (a shipping line, a return window, a size note), to open the store's chat with a relevant opener where the store runs one, and to measure whether that helped against a random held-out group. Identity resolution is off by default and, where a customer turns it on, runs only when the shopper's consent as recorded by the store's consent tools allows it.

Retention: live session state expires within minutes of the last activity. Behavioral records are kept for up to 13 months unless the customer sets a shorter period. Records are erased on a verified request from the customer, including requests relayed through Shopify's privacy webhooks, and when a customer's account is closed.

2. Our customers

We collect the account details a customer gives us: name, work email, company, and billing details handled by our payment provider. We use them to provide and bill the service, to support it, and to send service messages. Use of the console is logged for security and support.

3. Visitors to nextintent.ai

Our own site runs our own script under the rules above, plus standard server logs. We run no third-party advertising trackers.

4. Sharing and subprocessors

We do not sell personal data and we do not share it for advertising. We use subprocessors to run the service: Railway (hosting and databases, United States), Cloudflare (network, edge and storage, United States), Anthropic (the model that reads a behavioral snapshot to make a decision; the snapshot carries no name, email, phone or address), Shopify (where the customer's store runs on Shopify), and Clerk (customer sign-in). Changes to this list are posted here at least 30 days before they take effect.

5. Security

Data is encrypted in transit with TLS and at rest by our hosting providers. Credentials are stored as one-way hashes or encrypted. Access is limited to staff who need it and is logged, and every authenticated call to our API is recorded with who made it.

6. Your rights

Depending on where you live you may have the right to access, correct, delete or restrict the processing of your personal data, to object, and to complain to a supervisory authority. Shoppers should contact the store they visited, which is the controller of that data; we help the store respond. Everyone else can write to privacy@nextintent.ai.

7. Transfers

We process data in the United States. Where data originates in the European Economic Area, the United Kingdom or Switzerland, we rely on the standard contractual clauses incorporated in our Data Processing Agreement.

8. Changes and contact

We post changes here with a new effective date. Questions: privacy@nextintent.ai. NextIntent, Inc., United States.

See also: What the script measures · Data Processing Agreement