1. Information We Collect
We collect information directly from you when you register an enterprise merchant account, configure storefront settings, or communicate with our engineering concierge. This includes your merchant name, business email, contact telephone, billing preferences, and custom domain DNS records.
2. End-User Data & Meta CAPI Processing
As a merchant operating on NexaStore, you collect order details from your buyers. We act strictly as a Data Processor on your behalf. When you enable the Meta Conversions API (CAPI) Dual-Engine, conversion telemetry (order value, currency, cryptographic SHA-256 hashed customer identifiers) is transmitted directly to Meta Graph API endpoints via HMAC-authenticated channels. We never sell, monetize, or harvest buyer records.
3. Logistics & Courier Telemetry
To fulfill 1-Click Courier bookings, necessary consignment parameters (Recipient Name, Phone, Delivery Destination, and COD Amount) are securely passed to your connected logistics providers (Pathao, Steadfast Logistics, RedX) strictly for package transit and tracking updates.
4. Cryptographic Data Security
NexaStore enforces TLS 1.3 encryption across all public edge nodes, zero-trust backend VPC peering, encrypted PostgreSQL databases at rest (AES-256), and cryptographic HMAC signature validation on all incoming and outgoing webhooks.
5. Authorized Cloud Infrastructure
NexaStore utilizes SOC-2 certified global cloud providers including AWS (Database and Server Clusters), Cloudflare (Edge CDN & WAF Protection), and Redis Cloud (Real-time in-memory deduplication).