Privacy Policy
Last updated: 23 August 2026
Who we are, and who is responsible
Nudgely LLC provides a Shopify app that shows popups on merchants' online stores, collects contact details from shoppers who choose to give them, and sends text messages on the merchant's behalf.
Two different relationships are described in this policy, and they carry different rights.
- Shopper data. When a shopper gives their phone number to a store using Nudgely, the merchant is the controller of that data. Nudgely is a processor and a service provider, acting on the merchant's documented instructions. Shoppers should contact the store they signed up with first. We help that store answer.
- Merchant data. When a merchant registers for text messaging, we collect business and personal details about that merchant and their representative and file them with carrier registries. For that information Nudgely is the controller. There is no Shopify process covering this, so merchants exercise their rights by writing to us directly at the email address at the end of this policy.
What we collect about shoppers
- Phone number and email address, when a shopper enters them in a popup or lead capture form on a merchant's store.
- City, state or region, and country, together with the first name on the order. See the section below on where this comes from.
- Time zone, taken from the shopper's browser and from the region on their address, so that messages arrive at a reasonable hour and within the quiet hours the law requires.
- Consent records. When a shopper opts in we record the exact wording they were shown, the time, the page, and their IP address and browser user agent. This is evidence that consent was given and is required by telemarketing law.
- Message records. What was sent, when, whether it was delivered, and any reply such as STOP or HELP.
- Popup interaction data, such as which popup was shown and whether it was completed.
- Store domain, so that data is associated with the correct store.
Where location comes from, and what it is not
We use a shopper's city and state or region. We derive them from the shipping address the customer already gave the merchant when placing an order.
This is not GPS. It is not device location, and it is not precise location of any kind. We do not access location services, we do not track phones, and we do not use background location. We do not know a shopper's street-level position and we do not try to find it.
We use it for three things: to work out the right time zone so messages are not sent in the middle of the night, to look up the local weather forecast, and to choose a product to mention in a message where a merchant has switched weather messages on.
We do not sell location data and we do not share it with third parties for their own purposes.
How we use shopper data
- To show popups and deliver the discount code a shopper has earned.
- To send the text messages a merchant has asked us to send, which may include the discount code, a reminder about an unused code, and, where the merchant has turned it on, a message about a product chosen using the local weather forecast.
- To decide when a message may lawfully be sent, using quiet hours, state rules and federal holidays.
- To honour opt-outs, keep a suppression list, and prove that consent existed.
- To operate, secure and support the service, and to comply with law.
Message copy is drafted with the help of an AI model. The model receives the shop name, the product, the discount code and the weather signal. It does not receive the shopper's name, phone number, email address or address.
Data sharing
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
We use a small number of service providers to run the service. They act on our instructions, may use the data only to provide their service to us, and may not use it for their own purposes:
- Twilio, to deliver text messages and to register merchants with carrier registries.
- Supabase, for database hosting.
- Render, for application hosting.
- Anthropic, to draft message copy. Shopper contact details and addresses are not sent to it.
- A weather data provider, which receives a city name only.
Data is shared with the merchant whose store collected it, because it is their data. We may disclose information if the law requires it, and if Nudgely is ever sold or merged, data may transfer as part of that business, subject to this policy.
SMS and phone compliance
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. Mobile numbers and opt-in records are used only to send the messages the shopper agreed to receive from the store they signed up with.
Phone numbers are collected only with express written consent, given through clear opt-in wording shown on the form before submission. Consent is never a condition of purchase.
Recipients can opt out at any time by replying STOP, and can reply HELP for help. We also honour CANCEL, END, QUIT, UNSUBSCRIBE, STOPALL, OPTOUT and REVOKE. Opting out is immediate and free. Message and data rates may apply, and message frequency varies.
Nudgely operates under the merchant's registered sender identity. The merchant is the sender of record and is responsible for the content they ask us to send.
What we collect about merchants
To register a merchant for text messaging, carriers and The Campaign Registry require business details. We collect the legal business name, Employer Identification Number, business address, business website, business email and business phone, and we submit them to Twilio and to the registry.
We also record which person at the store started the registration and which person completed the form. This comes from the signed session token Shopify provides and is used to answer questions about who supplied what.
Nudgely is the controller of this information. We hold it because we have a legal obligation to identify the sender of a text message and a legitimate interest in operating the service. An Employer Identification Number identifies a business rather than a person, but the representative's name, email and phone number are personal data and are treated as such.
How long we keep things
- Subscriber records: for as long as the merchant uses the service, or until deletion is requested.
- Consent records: the IP address and browser user agent are deleted after two years. The rest of the record is deleted after five years. The limitation period under the Telephone Consumer Protection Act is four years and runs from the message rather than the sign-up, so the evidence has to outlast the messaging, not the opt-in.
- Message records: kept as proof of what was sent and under which consent. When someone asks for deletion these are anonymised rather than deleted: the link to the person and the message text are removed, and what remains is information about the shop rather than about a person.
- Suppression records survive deletion, and this is deliberate. If someone has replied STOP we keep their phone number and the fact that they opted out, and erase everything else about them. If we deleted the record outright, the same number could be added again tomorrow and messaged, because a do-not-contact list works by matching the number. Deleting it would solve a privacy duty by creating a worse one. This is permitted where processing is necessary to comply with a legal obligation.
- When a merchant uninstalls: Shopify notifies us 48 hours later and we delete that store and all of its records.
- Merchant registration data: kept for as long as the registration exists, because carriers may ask us to confirm or re-verify it.
Your rights
Depending on where you live you may have the right to know what we hold, to get a copy, to correct it, to delete it, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of, but the other rights apply.
Shoppers: contact the store you signed up with. They are responsible for your data and Shopify gives them a process for it. We answer their request within the time the law allows them, which is 30 days.
Merchants: write to us at the email address below. Shopify's process does not cover the details you gave us for carrier registration, so this is the route for that data.
Storage and security
Data is stored in Supabase, a hosted PostgreSQL service, and is encrypted at rest and in transit. Access is limited to those who need it to run the service. Data is stored and processed in the United States.
Children
Nudgely is not intended for children under 13 and we do not knowingly collect their information. If you believe a child has given us information, write to us and we will delete it.
Changes
If we change this policy we will update the date at the top. If the change is significant we will tell merchants through the app.
Contact
Questions about this policy, or to exercise a right: graham@nudgely.io. Nudgely LLC.