Privacy Policy
Effective date: July 5, 2026
One Nudge ("we," "us," "the app") is a Shopify application that helps merchants recover abandoned checkouts by sending a single SMS reminder per abandoned cart, using the merchant's own SMS provider account. This policy explains what information the app collects, how it is used, how long it is kept, and the choices available to merchants and their customers.
In privacy terms, the merchant who installs One Nudge is the controller of their customers' personal data; One Nudge acts as a service provider (processor) handling that data only to provide the service described here.
1. Information we collect
From merchants (the store that installs the app)
- Your store's myshopify.com domain and Shopify API session tokens needed to operate the app.
- Your app settings: message templates, send timing, minimum cart value, excluded products, brand signature, A/B test configuration, and any image or GIF URLs you attach to messages.
- The SMS provider credentials you choose to connect (Twilio Account SID, Auth Token, and phone number; or Sinch Service Plan ID, API Token, region, and phone number). These are stored solely so the app can send messages on your behalf through your own provider account. You can remove them at any time with the Disconnect button on the Nudge page.
- A test phone number, if you send yourself a test message.
About a store's customers (only when a checkout is started)
When a customer begins a checkout on a store that has One Nudge installed, Shopify sends the app a checkout event. From that event the app stores only what is needed to send one reminder:
- Customer first and last name and phone number (if the customer provided one), and whether the customer ticked the SMS-marketing consent checkbox at checkout.
- The cart contents (product IDs and product titles), cart value and currency, and the Shopify-generated checkout recovery link.
- After a reminder is sent, a delivery record containing a masked phone number (last four digits), send status, cart value, provider used, which message template was used, whether the reminder link was tapped, and — if the customer then completes their purchase — the order total.
The app does not collect or store payment card details, full mailing addresses, email addresses of customers, order histories, or browsing behavior. It does not use advertising trackers or analytics cookies, and it does not sell or share personal information for advertising.
2. How the information is used
- To send exactly one SMS reminder per abandoned checkout, at the delay the merchant configures, through the merchant's own Twilio or Sinch account. A built-in record of sent reminders prevents repeat messages to the same cart.
- Reminders are only sent to customers who consented. The app checks the SMS-marketing consent the customer gave (or didn't give) at checkout, and will not message a customer without an affirmative opt-in. Where the customer provided a dedicated SMS-marketing number with their consent, that is the number used.
- To skip reminders the merchant has ruled out (below a minimum cart value, containing excluded products, or when the app is turned off) and to never message a customer who has already completed their purchase.
- To show the merchant their own activity history (with masked phone numbers) and aggregate A/B test results inside the app.
- To verify the merchant's subscription status with Shopify before any message is sent.
The app makes no automated decisions that produce legal or similarly significant effects about any customer, and does no profiling. When a merchant runs an A/B test, each cart is assigned to variant A or B at random — the assignment is not based on anything about the customer.
3. Data retention and deletion
- Captured checkout data (name, phone, cart details, recovery link) is automatically deleted 30 days after the checkout was captured. A scheduled cleanup job enforces this daily.
- Reminder activity records (masked phone, status, cart value) are automatically deleted after 12 months.
- On uninstall, all of the store's settings, provider credentials, captured checkouts, and reminder records are deleted immediately, and a second cleanup runs when Shopify issues its post-uninstall redaction request 48 hours later.
- Merchants can also delete everything at any time, without uninstalling first, using Delete Account on the app's Account page — this cancels the subscription and permanently erases all stored settings and history.
4. Customer rights — access and deletion requests
One Nudge implements Shopify's mandatory privacy webhooks. When a customer asks a merchant for their data or requests deletion, and the merchant submits that request through Shopify, the app automatically locates any matching records it holds and, for deletion requests, permanently removes them. Customers control whether they hear from the app at all: no reminder is sent without the SMS consent they gave at checkout, and they can stop messages instantly by replying STOP to any reminder — opt-outs are enforced by the SMS carrier network via Twilio or Sinch and are honored automatically.
Anyone may also contact us directly at onenudge@pilence.com with a privacy question or request, and we will respond within 30 days.
5. Who the data is shared with
The app shares data only with the services required to operate, and only the minimum each needs:
- Shopify — the platform the app runs on; the source of checkout events and the processor of all billing.
- The merchant's own SMS provider (Twilio or Sinch) — receives the recipient phone number and message content in order to deliver each SMS. This account belongs to the merchant, under the provider's own terms and privacy policy.
- DigitalOcean — hosts the application and its managed database. Data is encrypted in transit (TLS).
- GIPHY — only if a merchant uses the optional GIF search while composing a message, the search terms they type are sent to GIPHY. No customer data is ever sent to GIPHY.
We do not sell personal information, and we do not share it with data brokers or advertisers.
6. Security
All data moves over encrypted connections (HTTPS/TLS). Access to stored data is restricted to the application itself; every in-app request is authenticated against the merchant's live Shopify session, and one store can never access another store's data. Provider credentials are used only server-side to place send requests with the merchant's own SMS provider. Phone numbers shown anywhere in the app interface are masked to their last four digits.
7. Children
One Nudge is a business tool for Shopify merchants and is not directed at children. We do not knowingly collect personal information from anyone under 16.
8. Changes to this policy
If our data practices change, we will update this page and its effective date. Material changes will be communicated to merchants inside the app or by email.
9. Contact
Questions about this policy or your data:
legal@pilence.com