Skip to content

Privacy Policy

Effective

This Privacy Policy explains how Nextsense Solution FZC LLC ("PixlBridge", "we", "us"), with its registered address at CWS-2V-195841, 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates, collects, uses, shares and retains personal data when you use the PixlBridge website (pixlbridge.com), the PixlBridge application (app.pixlbridge.com and api.pixlbridge.com), the tracked redirect service (go.pixlbridge.com), the PixlBridge Shopify app and the PixlBridge web pixel (together, the "Service").

PixlBridge acts in two roles. For the people who create accounts and use the dashboard ("Customers"), we are the data controller. For data about our Customers' shoppers that we process in order to provide the Service (clicks on tracked links, events from Shopify stores, purchase data from Amazon Attribution), we act as a data processor on the Customer's documented instructions; the Customer is the controller. Our Data Processing Addendum governs that processing.

1. Data we collect

1.1 Account and workspace data (controller)

  • Name, email address, password (stored as a bcrypt hash), email verification status, timezone and currency preferences.
  • Workspace name and logo, team memberships and roles, invitations you send (invitee email and role).
  • Subscription plan, billing status and Stripe customer and subscription identifiers. Payment card details are collected and stored by Stripe, not by us.
  • Support correspondence and, if you use the booking link, the details you provide to the scheduling provider.
  • Technical logs: IP address, user agent, timestamps and request paths for security, rate limiting and debugging.

1.2 Provider connection data (processor for advertising data; controller for credentials)

  • Meta: an OAuth access token obtained through Facebook Login for Business, the ad account, business and Pixel/dataset identifiers you select, and campaign, ad set, ad, creative names and spend metrics retrieved from the Marketing API.
  • Amazon: Login with Amazon access and refresh tokens, advertising profile and Amazon Attribution advertiser identifiers, attribution tags created for your links, and aggregated Attribution report metrics (clicks, detail page views, add-to-carts, purchases, sales) per tag.
  • Shopify: an offline access token for each connected store, the shop domain and shop information, webhook subscription identifiers and web pixel identifiers.

All tokens are encrypted at rest with AES-256-GCM.

1.3 Shopper data processed on behalf of Customers (processor)

  • Click data when a shopper opens a tracked link: link code, timestamp, the fbclid Meta appends to the URL, a first-party _fbp cookie value, device and browser type, a normalised IP address and a hashed IP address, user agent, and the destination.
  • Shopify storefront events from the PixlBridge web pixel: event type and id, page URL, product or variant identifiers, cart value and currency, the _fbp and _fbc cookie values, user agent, and a hashed customer id for logged-in customers.
  • Shopify order and checkout data from webhooks: order id and number, checkout token, totals, currency, line item identifiers and quantities, browser IP and user agent, landing page URL, and customer email, phone, first and last name, city, state, postal code and country. Personal fields are normalised and SHA-256 hashed at ingest; raw values are not stored or logged.
  • Amazon purchase data is received only as aggregates per attribution tag. Amazon does not share buyer identities with us.

1.4 Website visitors

pixlbridge.com is a static website. It sets no cookies of its own. If the operator enables an analytics tool, it is limited to aggregate, cookieless or consent-gated usage statistics and is identified here: none.

2. How we use data

  • To provide the Service: authenticate you, run your workspace, create tracked links and attribution tags, record clicks, receive Shopify events, match purchases to clicks and send conversion events to Meta on your behalf.
  • To send hashed customer identifiers, click identifiers and purchase details to the Meta Conversions API for the Meta dataset you selected, so that Meta can attribute and optimise your advertising. This is done on your instruction and for your benefit as the advertiser.
  • To produce reports for you (spend, clicks, conversions, ROAS by campaign, ad, creative, period and product).
  • To bill you through Stripe and to send transactional email (verification, password reset, invitations, billing notices, scheduled reports) through Resend.
  • To secure the Service: rate limiting, abuse prevention, audit logging of administrative actions, debugging.
  • To comply with law and enforce our Terms.

We do not sell personal data, do not use Customer or shopper data to build profiles across Customers, and do not use it for our own advertising.

  • Contract: providing the Service to Customers.
  • Legitimate interests: security, fraud prevention, service improvement and communicating with Customers about the Service.
  • Legal obligation: tax, accounting and responding to lawful requests.
  • Consent: where a Customer's storefront requires consent for the web pixel or for Meta tracking, obtaining that consent is the Customer's responsibility as controller.

4. Sharing and sub-processors

We share data with the following categories of recipients, only as needed to provide the Service:

RecipientPurposeData
Meta Platforms, Inc. / Meta Platforms Ireland LtdConversions API events for your dataset; Marketing API readsHashed identifiers, click ids, purchase values, event metadata
Amazon.com, Inc. / Amazon AdvertisingAttribution tag creation and report retrieval in your Amazon Ads accountTag metadata; report aggregates returned to us
Shopify Inc.App installation, webhooks, web pixelStore data as described above
Stripe, Inc.Subscription billingName, email, billing details, payment card (held by Stripe)
Resend, Inc.Transactional email deliveryRecipient email address and message content
Contabo GmbH (Germany) for servers and Cloudflare, Inc. (United States) for network security and content deliveryInfrastructure hosting, edge redirects and backupsAll Service data, encrypted at rest
noneWebsite usage statisticsAggregate page views

We may also disclose data to professional advisers, to authorities where required by law, and to a successor in a merger or acquisition (with notice to you). The current sub-processor list is maintained in the DPA.

5. International transfers

Our infrastructure is located in the European Union (Germany). The recipients above may process data in the United States and elsewhere. Where data leaves the EEA, UK or Switzerland we rely on the recipient's adequacy status, the EU Standard Contractual Clauses (and UK Addendum) or the EU-U.S. Data Privacy Framework where the recipient is certified.

6. Retention

  • Account data: for the life of the account and up to 30 days after deletion, then removed from live systems; backups expire within 14 days.
  • Provider tokens: until you disconnect the provider or delete the workspace, at which point they are overwritten immediately.
  • Click data: 13 months, covering attribution windows and year-over-year reporting.
  • Shopify events (hashed): 90 days after they are sent, failed or skipped. Meta does not accept events older than 7 days.
  • Aggregated report snapshots and billing records: for the life of the account and as required by tax law (typically 7 to 10 years for invoices).
  • Audit logs and security logs: 12 months.

7. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to withdraw consent. EEA and UK residents may lodge a complaint with their supervisory authority. Contact us at privacy@pixlbridge.com; we respond within 30 days.

Shoppers whose data we process for a Customer should direct requests to that merchant, who controls the data; we assist the merchant in fulfilling them, and we honour Shopify's customers/data_request and customers/redact webhooks automatically.

California (CCPA/CPRA)

We do not sell or share personal information for cross-context behavioural advertising as those terms are defined in the CPRA. Sending a Customer's hashed purchase data to Meta on the Customer's instruction is processing as a service provider. California residents may exercise the rights to know, delete, correct and to non-discrimination by contacting us.

8. Cookies and similar technologies

  • go.pixlbridge.com sets a first-party _fbp cookie (SameSite=Lax, Secure) on the redirect domain so that a shopper's later purchase can be matched to the click for Meta attribution. It contains a random identifier and no personal data.
  • app.pixlbridge.com stores your session token in the browser's local storage to keep you signed in.
  • The PixlBridge web pixel on a Shopify store reads the store's existing _fbp and _fbc cookies; it does not set cookies of its own. It runs in Shopify's customer-privacy sandbox and respects the store's consent settings.
  • pixlbridge.com sets no cookies.

9. Security

Tokens are encrypted with AES-256-GCM, passwords are hashed with bcrypt, shopper identifiers are hashed with SHA-256, every database query is scoped to a single workspace, webhooks are signature-verified, and administrative actions are audit logged. Details are on the security page. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay and, where the law requires, within 72 hours.

10. Children

The Service is for businesses and is not directed to children under 16. We do not knowingly collect their data.

11. Platform terms

Our use of Meta data complies with the Meta Platform Terms and Developer Policies; our use of Amazon Ads API data complies with the Amazon Advertising API License Agreement; our Shopify app complies with the Shopify Partner Program Agreement and API Terms, including the protected customer data requirements. You can revoke our access at any time from the respective platform (Facebook settings → Business integrations; amazon.com → Login with Amazon; Shopify admin → Apps) or by disconnecting in PixlBridge.

Data deletion instructions (Meta App Review): to have all data associated with your Meta account removed, disconnect Meta in PixlBridge or delete your workspace, or email privacy@pixlbridge.com with the subject "Data deletion". We confirm completion within 30 days.

12. Changes

We will post changes on this page and update the effective date. For material changes we email Customers at least 14 days before they take effect.

13. Contact

Nextsense Solution FZC LLC, CWS-2V-195841, 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates, the United Arab Emirates (Emirate of Ajman). Email privacy@pixlbridge.com. EU/UK representative (if required): Nextsense Solution FZC LLC, CWS-2V-195841, 26th Floor, Amber Gem Tower, Ajman, United Arab Emirates. Data protection officer (if appointed): office@nextsensesolution.com.