Privacy Policy

Last updated: July 24, 2026 · Applies to NextGenCode and OrderFlow

NextGenCode ("we", "us", "our") operates www.nextgencode.dev and the Shopify application OrderFlow (available at https://www.nextgencode.dev/apps/orderflow). This Privacy Policy explains how we collect, use, and protect information when you use our website or install our Shopify apps.

1. Who we are

Data controller: NextGenCode
Contact: ngencode.dev@gmail.com

2. Information we collect

When you use OrderFlow (Shopify app)

  • Shop information: store domain, shop name, and installation metadata provided by Shopify.
  • Session data: OAuth tokens required to access your store via the Shopify Admin API (stored securely on our servers).
  • Order data: when you run an export, we fetch order information from your store via Shopify's API solely to generate your export file. We do not permanently store order contents beyond what is needed to provide the service.
  • App settings: export templates, schedules, usage counters, and onboarding preferences you configure in the app.
  • Scheduled export email: if you enable scheduled exports, we store the email address you provide and send export files to that address.

When you visit our website

  • Standard server logs (IP address, browser type, pages visited, timestamps).
  • Contact information if you email us.

We do not sell personal data. We do not use merchant data for advertising.

3. Legal basis (GDPR)

For users in the European Economic Area, UK, and similar jurisdictions:

  • Contract: processing necessary to provide the app you installed.
  • Legitimate interests: improving our apps, security, and support.
  • Legal obligation: responding to lawful requests and compliance requirements.
  • Consent: where required, e.g. optional marketing communications.

4. How we use your information

  • Provide order export and scheduling features.
  • Authenticate your store with Shopify.
  • Enforce free-tier limits and billing for Pro plans.
  • Respond to support requests.
  • Maintain security and prevent abuse.

5. Shopify API & customer data

OrderFlow accesses order data through Shopify's Admin API with scopes you approve during installation (e.g. read_orders). Customer personal data in exports (email, name, address) is included only when you select those columns. You control what is exported.

We implement Shopify's mandatory GDPR compliance webhooks: customers/data_request, customers/redact, and shop/redact. When a shop uninstalls the app or requests deletion, associated shop data is purged from our systems.

6. Data retention

  • Session and shop settings: retained while the app is installed.
  • On uninstall or shop/redact webhook: shop data deleted within 30 days unless law requires longer retention.
  • Export files: generated on demand and delivered to you; not stored long-term on our servers unless required for scheduled email delivery in transit.

7. Data sharing & processors

We may share data with:

  • Shopify — platform provider (see Shopify's privacy policy).
  • Hosting providers — to run our application infrastructure.
  • Email providers (SMTP) — only if you configure scheduled exports.
  • Payment processing — Shopify Billing for Pro subscriptions (we do not store card numbers).

8. International transfers

Our services may be hosted outside your country. Where required, we use appropriate safeguards (e.g. Standard Contractual Clauses) for cross-border data transfers.

9. Your rights

Depending on your location, you may have the right to access, correct, delete, restrict, or port your personal data, withdraw consent, or lodge a complaint with your local data protection authority.

Contact us at ngencode.dev@gmail.com.

10. Security

We use industry-standard measures including HTTPS, secure token storage, access controls, and regular updates.

11. Children

Our services are for businesses and are not directed at children under 16.

12. Changes

We may update this policy. Material changes will be posted on this page with an updated date.

13. Contact

Questions about privacy?
Email: ngencode.dev@gmail.com

Terms of Service · Portfolio privacy (RODO)

Privacy Policy — NextGenCode & OrderFlow | NextGenCode House of Technology