NextBatch is a Shopify app made and run by Jamie Farrell through TFC Business Solutions LLC, Orlando, Florida ("I" and "me" below). This policy explains what NextBatch stores when a merchant installs it on a Shopify store, why, where it is kept and how it is deleted. It is written for the merchant who installs the app and for the people who shop at that store.
For shoppers' data, the merchant decides what the program is for, and I process that data on the merchant's behalf. If you are a shopper, the store you bought from is your first point of contact. You can also email me.
What NextBatch stores
About the store
- The store's Shopify domain, name, currency and plan, the settings the merchant chooses, and the subscription plans created through the app with the products they apply to.
- For orders with a NextBatch subscription line: order ID and number, subtotal, the amount counted, refund amounts and dates.
About subscribers (the store's customers)
| Data | Why |
|---|---|
| Shopify customer ID, name and email | To show the merchant who each subscription belongs to |
| Delivery address | Mirrored from the subscription so the merchant can see where it ships |
| Subscription details: products, prices, frequency, status, next billing date | To bill renewals on the right day and show customers their subscriptions |
| Billing attempt results: success or failure, an error code and the resulting order | To retry failed payments and keep a record |
| Portal actions (skip, pause, resume, change frequency, cancel), the cancellation reason and any note the customer writes | To run the portal and the cancellation flow |
NextBatch stores no card numbers or other payment details. Shopify keeps payment methods and NextBatch only asks Shopify to charge the one on file. It stores no phone numbers. The portal identifies customers through Shopify's own customer accounts, so NextBatch never sees passwords.
Why, and the Shopify access it asks for
NextBatch uses this data only to run the store's subscriptions and to work out its 1% usage fee. It asks Shopify for access to manage products and purchase options (to create subscription plans), manage its own subscription contracts (which lets it bill renewals to the payment method the customer saved at checkout, without seeing card details), and read customers and orders.
Where data is kept and who sees it
The copy of NextBatch you install from the Shopify App Store runs at nextbatch.shoplyft.online on shared web hosting from Spaceship, my hosting provider, and keeps its data in a database file on that server. I also run private copies of the app for a few stores I work with directly. Those run on Railway, which says it encrypts the data it stores. Data travels only between Shopify and the app, and every connection is served over HTTPS.
Shopify is the platform the app runs on. To bill the 1% usage charge, the app sends Shopify the store's ID and an amount, nothing about shoppers. Apart from Shopify and those two hosts, there are no sub-processors. For merchants, the data processing agreement sets out how I handle this data on your behalf.
Studio keeps a log of each time someone opens a list or record with personal data in it, or downloads an export: what was opened, when, and the staff account when Shopify provides it. I keep each entry for 180 days, then delete it, and the whole log goes sooner if the store's data is erased.
What I never do
- I never sell data or share it with advertisers.
- There are no third-party trackers, analytics tools or advertising pixels in the app or its storefront blocks.
- The app stores no phone numbers and no payment details. Shopify handles payments.
Cookies
NextBatch sets no cookies of its own in the store, the portal or Shopify admin, beyond what Shopify itself provides. Studio uses a short-lived signed token held in memory while it is open.
Keeping and deleting data
NextBatch keeps subscription records while the app is installed.
- When a customer asks to be deleted. Shopify sends the app a redact request. NextBatch removes that customer's name, email and delivery address from their subscription records and clears any note they wrote when cancelling. Any data request file prepared for them is deleted too. Billing records without those details stay until the store's data is erased.
- When a merchant uninstalls. The app stops working on the storefront right away. Shopify asks apps to erase a store's data 48 hours after uninstall. When that request arrives, the app deletes everything it holds for the store.
- Data requests. When a customer asks a merchant for their data, Shopify tells the app. NextBatch gathers everything it holds about that customer into a file, and the merchant downloads it from Studio (Subscribers, under Customer data requests) and sends it to the customer. Nothing goes to the customer automatically. I will help if asked. I keep the file for 30 days after the merchant first downloads it, or 90 days if it is never downloaded, then delete it.
This website
The website at shoplyft.online sets no cookies, runs no analytics and loads nothing from other servers. It uses your device's own fonts. My web host may keep standard server logs, such as IP addresses and the pages requested, to keep the site running.
Changes and contact
If this policy changes, I will update this page and the date at the top. Questions or requests: him@thejamiefarrell.com, or write to TFC Business Solutions LLC, Orlando, Florida.