Privacy Policy

Last updated: 15 August 2026

NDA Signal ("the app") is a server-side conversion tracking application for Shopify stores. This policy explains what personal data the app processes, why, and for how long.

1. Roles

For personal data belonging to a merchant's customers, the merchant is the data controller and North Digital Axis LLC is the data processor. We process this data only on the merchant's documented instructions, as set out in our Data Processing Agreement.

2. What we process

DataPurposeForm in which it is stored
Email addressConversion matchingSHA-256 hash only
Phone numberConversion matching and persistent customer identificationSHA-256 hash only
First and last nameConversion matchingSHA-256 hash, transient
City, region, postal code, countryConversion matchingSHA-256 hash, transient
IP address and user agentConversion matching and automated-traffic detectionPlain, retained up to 48 hours
Advertising click identifiersAttributing a conversion to the ad that produced itPlain; these are not personal data on their own
Order value, currency, productsReporting conversion valuePlain

Personal data is normalised and hashed with SHA-256 on our servers before being transmitted. Plain-text contact details are not retained beyond the window needed to process the order.

3. Why we process it

To deliver conversion events to the advertising platforms the merchant has connected, so the merchant can measure and optimise advertising performance. We do not process personal data for any other purpose, and we never sell it.

4. Who receives it

Hashed matching parameters are sent only to the advertising platforms the merchant explicitly configures in the app, using credentials the merchant supplies. We use Cloudflare as our sole infrastructure provider (compute, database, key-value storage). We do not use any other sub-processor.

5. Consent

Where the merchant's store operates in a jurisdiction requiring consent, the app honours the visitor's choice through Shopify's Customer Privacy API. Without marketing consent, events are sent without any personal data. Advertising click identifiers, which do not identify a person on their own, may still be sent.

6. Retention

DataRetention
Checkout identity (IP, user agent, click identifiers)48 hours
Event deduplication keys7 days
Event delivery log30 days
Hashed customer identifiersUntil deletion is requested or the app is uninstalled
Access log12 months
All merchant dataDeleted within 48 hours of uninstallation

7. Security

All data is encrypted in transit (TLS 1.2 or higher) and at rest. Advertising platform credentials supplied by merchants are additionally encrypted with AES-256-GCM using a key held only in our secrets store and never written to the database. Access to production systems is limited to authorised personnel and protected by two-factor authentication. Access to personal data is logged.

8. Data subject rights

Requests should be directed to the merchant, who is the controller. We support Shopify's mandatory compliance webhooks and act on them automatically: on a deletion request we erase the customer's hashed identifiers, device links and stored order identity. On a data access request we report what we hold.

You may also contact us directly at privacy@northdigitalaxis.com.

9. International transfers

Data is processed on Cloudflare's global network. Advertising platforms may process data outside the European Economic Area under their own terms and transfer mechanisms.

10. Changes

Material changes will be communicated to merchants through the app before taking effect.