Privacy Policy
This Privacy Policy ("Policy") describes how Nxera Digital LLC ("Nxera," "we," "us," "our") collects, uses, discloses, retains, and safeguards information about clients, prospective clients who request a free competitive scan, the customers and plan members of our clients, website visitors, and other individuals (collectively, "you") in connection with: getnxera.com and all of its subdomains; the plan pages and member pages Nxera hosts in a client's name at getnxera.com/m/ and on custom domains (each, a "Plan Page"); the Nxera client portal; the Repeat Customer System and the Service Agreement Program (the "Services"); and any related platforms, applications, communications, and APIs (collectively, the "Services").
This Policy is incorporated by reference into the Nxera Terms of Service (the "Terms"). Capitalized terms not defined here have the meanings given in the Terms. This Policy is supplemented by the Cookie Policy (cookies and tracking technologies) and the Data Processing Addendum (B2B Processor obligations).
By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree, do not use the Services.
1. Scope and Roles
1.1 Information We Collect About You as a Client
For Nxera Clients, Nxera acts as a "controller" (or "business" under the CCPA/CPRA) of Personal Data we collect about the Client and its authorized representatives (for example your name, email, business address, payment data, and portal usage).
1.2 Information You Provide About Others
For information about other people that you provide to Nxera (your customer list and consent records, service histories, visit logs, and the records of members who enroll in your plans), Nxera acts as a "processor" (or "service provider" under the CCPA/CPRA) acting on the Client's documented instructions. The Data Processing Addendum applies to that Processing. You represent that you have a lawful basis to provide that information to Nxera.
1.3 Information We Collect About Scan Requesters
When you request the free competitive scan, Nxera acts as a controller of the business and contact details you submit and of the scan results, and may use them to follow up with you about the scan and the Services as described in Section 3.
1.4 Information We Collect on Plan Pages
A Plan Page is shown in the Client's name. Information a member or visitor enters on a Plan Page (enrollment details, messages, photos, visit requests) is collected on behalf of the Client operating that page. The Client is the controller of that data; Nxera is the processor. Members should consult the Client's own privacy notice for anything beyond what this Policy describes.
2. Information We Collect
2.1 Information You Provide Directly
- Account and contact data: business name, contact name, email, phone, mailing address, time zone, language preference.
- Business profile data: trade, services, service area, hours, logo, brand colors, Google review link, plan page copy, and anything you enter in your intake.
- Payment data: payment method information processed by Stripe, Inc. Nxera does not store full card numbers; Nxera receives and stores only the brand, last four digits, expiration, and a Stripe customer or payment-method ID.
- Communications: the content of emails, portal messages, support requests, change requests, and other messages you send to Nxera or its AI agents.
- Customer data you provide about others: names, emails, phone numbers, service addresses, first and last service dates, service types, notes, tags, and the consent basis and attestation you record when you import or add a contact.
- Visit logs: the visits you log for a customer, with date, service type, and notes.
- Business knowledge: the services, pricing notes, policies, and seasonal reminders you save so drafted messages are accurate.
- Text message consent records: when you tick the text-message box on a form, we record the mobile number you gave, the date and time, the exact consent wording shown to you and its version, the page address, the page language, and the IP address and browser used. These records are an append-only log and are never edited.
2.2 Information Collected Automatically
- Device and connection data: IP address, device identifiers, browser type and version, operating system, screen size, language, referring URL.
- Usage data: pages visited, features used, links clicked, timestamps, session length, navigation paths, and portal actions such as approving, editing, vetoing, or rescheduling a message.
- Website analytics: Google Analytics 4, loaded through Google Tag Manager, on getnxera.com marketing pages, as described in the Cookie Policy. Nxera reads aggregated GA4 reports through the Google Analytics Data API.
- Bot protection: Cloudflare Turnstile runs on our forms and records a challenge result; it may process your IP address and browser signals to distinguish people from bots.
- Error reports: Sentry receives error reports from getnxera.com and from the Nxera owner app, which may include the page or screen, the browser or device, the app version, and the IP address at the time of an error, together with crash and performance diagnostics from the app.
- Cookies and similar technologies: as described in the Cookie Policy.
- Message delivery data: for each Customer Message sent in a Client's name, delivery, bounce, complaint, unsubscribe, and link-click events reported by our email provider. We do not track email opens.
2.3 Free Competitive Scan Data
When a business requests the free competitive scan we collect the business name, city, state, trade, website, and contact email and phone submitted with the request, and we generate scan data: what third-party AI platforms answered when asked customer-style questions about that trade in that market, which businesses they named, public listing details for the named businesses (Google Places), and a screenshot of the requester's public website. Scan requests and results are stored as lead records. We may verify the deliverability of a submitted email address with an email-verification provider before sending the report. The scan form also offers a separate, optional checkbox to receive marketing text messages at the mobile number you provide. It is off by default, it is never required to get the scan, and leaving it unticked has no effect on the report you receive.
2.4 Information from Third Parties
- Public data sources: Google Places (business listings and public reviews), publicly available web pages, public YouTube channel data, and creator listings from Apify, used to build the free scan and to find businesses and creators who may want to hear from Nxera.
- Payment processor: Stripe (transaction status, fraud signals, basic card metadata; for the Service Agreement Program, the connected-account status of your own Stripe account).
- Email provider: Resend (delivery, bounce, complaint, and click metadata).
- AI platforms (OpenAI ChatGPT, Google Gemini, and other Google AI products): AI-generated responses to trade and market questions, used only for the free scan. These are API responses, not user conversations.
- AI drafting provider: Anthropic (Claude), which drafts Customer Messages and plan designs from the business information you provide. Anthropic processes that content to return a draft and, under its API terms, does not use it to train models.
- Email verification: ZeroBounce (deliverability status of an email address).
- Text messaging provider: delivery, failure, and opt-out events reported by the provider that sends our text messages.
2.5 Sensitive Categories
You agree not to provide Nxera with sensitive personal data, including health, biometric, government identifier, financial-account, sexual-orientation, religious, trade-union, criminal, or children's data, except as expressly authorized in writing by Nxera. We do not knowingly request or rely on sensitive data and we are not responsible for safeguards specific to such data unless explicitly agreed.
2.6 Children
The Services are intended for adults (18+). Nxera does not knowingly collect Personal Data from individuals under 18. If you believe a minor has provided us Personal Data, contact info@getnxera.com and we will delete it.
2.7 Client-Provided Customer Data
Our business clients upload customer contact information (names, email addresses, phone numbers, service addresses, and service history) so we can send follow-up in their name. We process this data solely to provide those services, under the client's instructions, and every message waits for the client's review before it sends. The client is responsible for having a lawful basis to contact these individuals and records that basis when the contact is added. We honor unsubscribe requests across all of a client's sending, we apply monthly caps and quiet hours, and we delete client-provided contact data when the client asks, and automatically once thirty (30) days have passed after the client's subscription ends; the automatic deletion runs weekly, so it completes within thirty-seven (37) days of the end. A one-way fingerprint of any unsubscribed address is kept so the opt-out continues to be honored.
2.8 Member Data
When a customer enrolls in a client's service plan through a Plan Page, we collect the member's name, email, phone, service address, plan selection, language preference, marketing consent choice, and the Stripe customer and subscription identifiers created on the client's own Stripe account. During the plan we also collect the member's messages to the client, photos the member chooses to attach, visit requests and confirmations, renewal and payment status events reported by Stripe, and the member's unsubscribe choices. We process member data as the client's processor, to run the plan and to send plan-related messages in the client's name. Members can update their details, request visits, and manage marketing email from their manage link. When a client's subscription ends, we delete its members' data, including messages, photos and attachments, visit requests, visits, plan events and the member record, within thirty-seven (37) days of the end. The exception is a member whose plan the client still bills on the client's own Stripe account: that member's record is kept until the billing ends. A one-way fingerprint of any member who unsubscribed is kept so the opt-out continues to be honored.
2.9 The Nxera Owner App
If you use the Nxera app for iPhone or Android, we also collect an install identifier the app creates for itself (not your phone's advertising identifier), your device model and app version, which label your signed-in sessions, and the push notification token your phone issues, so we can tell you about new messages, visit requests and drafts waiting for your review. You can turn notifications off in your phone's settings. If you subscribe in the app, we receive your App Store or Google Play subscription status through RevenueCat, our in-app purchase provider; the store, not Nxera, holds your payment details. Face ID, Touch ID and fingerprint unlock run on your phone, and the app receives only whether the unlock succeeded. Apart from a logo and any business documents you choose to upload, the app sends only the business, customer and member information you enter, the same information the portal at getnxera.com holds.
3. How We Use Information
We use information for purposes including:
(a) Service delivery: drafting, scheduling, and sending Customer Messages in a client's name; designing plans and hosting Plan Pages; enrolling members and operating renewals, visit reminders, and failed-payment follow-up; providing customer support. (b) Account management: creating and maintaining your account, verifying identity through sign-in links, communicating with you about your account, and sending the review digests your settings call for. (c) Billing and fraud prevention: processing payments, retrying failed payments, detecting and preventing fraud, enforcing the Terms. (d) Transactional and operational communications: sending you receipts, billing notices, setup emails, portal claim links, review digests, security alerts, scheduled-maintenance announcements, legal notices, and similar messages. (e) Free scan and follow-up: producing the free competitive scan you requested, delivering the report, and following up about the scan and the Services by email; you can unsubscribe from follow-up at any time. (f) Marketing communications: sending product updates and other marketing content to clients and scan requesters (you can unsubscribe at any time using the link in those messages). (g) Product improvement: analyzing usage to improve features, performance, and stability; improving Nxera's internal prompts and agents in aggregated, anonymized, or de-identified form. (h) Analytics and reporting: generating internal analytics from GA4 and portal usage, and the counts shown in your portal. (i) Legal compliance: complying with legal obligations, responding to lawful requests, defending Nxera's legal rights, enforcing the Terms. (j) Business operations: corporate development, audits, financial planning, accounting, tax compliance, insurance. (k) Text messages: sending marketing text messages, including messages sent by automated means, only to a mobile number whose owner ticked the text-message box, and sending the automatic replies required when someone texts HELP or STOP. We do not send marketing texts to anyone who has not opted in. Consent to texts is never a condition of buying anything. Message frequency varies. Message and data rates may apply.
We process information based on the following lawful grounds (where required by law): performance of contract, our legitimate interests (operating the business, security, fraud prevention, product improvement), your consent (where applicable, for example marketing emails in some jurisdictions and the marketing choice a member makes at enrollment), and compliance with legal obligation.
4. How We Share Information
We share information only as described below. We do not sell or share Personal Data for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
4.1 Sub-processors / Service Providers
We share information with vetted third-party providers who perform services on our behalf and are bound by contract to use the information only for those services and consistent with our instructions. The current list is published in Section 5.2 of the Data Processing Addendum and at getnxera.com/sub-processors.
4.2 Recipients of Customer Messages
When a client approves a Customer Message, the client's business name and the content of the message appear in that message by design, and the recipient sees the content the client authorized. The message carries the client's name as sender and an unsubscribe link.
4.3 Public Display on Plan Pages
Information a client provides for display on its Plan Page (business name, plan names, prices, inclusions, page copy, and brand) is publicly visible to anyone who visits the page. Member data is never displayed publicly.
4.4 Stripe and the Client's Own Stripe Account
For the Service Agreement Program, a member's enrollment and payment details are processed by Stripe on the client's own Stripe account. The client, as a Stripe account holder, can see its members' payment records in Stripe under Stripe's privacy terms.
4.5 Legal and Safety Disclosures
We may disclose information when we reasonably believe disclosure is necessary to: (a) comply with applicable law, regulation, court order, or other legal process; (b) protect the rights, property, or safety of Nxera, our Clients, or any third party; (c) detect, prevent, or address fraud, security, or technical issues; (d) defend against legal claims.
4.6 Business Transfers
In the event of a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be transferred to the successor or acquirer. We will require any successor to honor this Policy or provide notice and choices.
4.7 With Your Consent
We may share information for any other purpose with your express consent.
4.8 No Sale; No Cross-Context Behavioral Advertising
We do not sell Personal Data for money or other valuable consideration. We do not share Personal Data for cross-context behavioral advertising. If we ever change this practice, we will provide notice and a meaningful opportunity to opt out before the change takes effect.
4.9 Text Messaging
To deliver text messages we use a licensed messaging provider, which passes the message to mobile carriers. The provider receives the mobile number and the message content solely to deliver it and is bound by contract to use it for nothing else. The provider is named in the sub-processor list at getnxera.com/sub-processors before any message is sent. We do not sell, rent, or share mobile numbers or text-message consent records with third parties or affiliates for their own marketing. Mobile numbers collected for text messaging are disclosed to no one other than the provider that delivers the message. Carriers are not liable for delayed or undelivered messages.
5. Data Retention
We retain Personal Data for as long as necessary to fulfill the purposes described in this Policy, including:
- Active account data: for the duration of your subscription.
- Billing and tax data: for at least seven (7) years after the last transaction, as required for tax and audit purposes.
- Customer Content, client-provided customer data, and member data: for the subscription and for thirty (30) days after it ends, so a returning client can pick up where they left off, then deleted within thirty-seven (37) days of the end (sections 2.7 and 2.8). Clients can export from the portal at any time and delete their customer list from the portal at any time. A client can delete their whole Nxera account in the Nxera app (More, then Account, then Delete account): the deletion runs seven (7) days after the request, and the client can cancel it until then. A request by email to info@getnxera.com is completed within thirty (30) days. Billing and tax records are kept as described below, and data is kept where retention is required by law. A one-way fingerprint of any unsubscribed address is kept after deletion so the opt-out continues to be honored, and cannot be read back as an address.
- Free scan and lead data: up to twenty-four (24) months after the last contact with the requester, then deleted or de-identified, except that scan results about businesses are retained in aggregated, de-identified form for market trend analysis.
- Customer Message content and delivery events: for the subscription and afterwards, so clients can review what was sent and so Nxera can show that its sending followed the law. Message content is deleted with the customer list, when a client asks or after the subscription ends as above; the send record is retained as a compliance record.
- Marketing and contact data: until you opt out, after which we retain a minimal suppression record to honor your opt-out.
- Backups: rolling backups are retained per our infrastructure providers' default schedules and are subject to natural overwriting, typically within 30-90 days.
- Logs: application and access logs are retained for security, fraud, and debugging purposes for up to twenty-four (24) months, except where longer retention is needed for an open investigation.
- Text message consent and opt-out records: kept for at least four (4) years after consent is given or withdrawn, so we can show what wording you were shown and when, and longer while any claim, dispute, or investigation involving that record is open. An opt-out is kept as a permanent suppression record so STOP continues to be honored.
When we no longer need Personal Data, we will delete or de-identify it, except where retention is required by law, necessary for legal claims, or otherwise within an exception in this Policy.
6. Your Rights and Choices
Depending on your jurisdiction, you may have rights regarding your Personal Data.
6.1 Universal Rights
You may always:
- Update your account information through the portal or by emailing info@getnxera.com.
- Delete your account in the Nxera app (More, then Account, then Delete account), which runs after a seven-day window you can cancel, or by emailing info@getnxera.com.
- Unsubscribe from marketing communications using the link in any marketing email. Transactional and account messages cannot be unsubscribed from while you remain a Client.
- Stop follow-up about a free scan using the unsubscribe link in any scan email.
- As a member of a client's plan, update your details, manage marketing email, or ask the client to close your plan from your manage link; you may also contact info@getnxera.com and we will route your request to the client.
- Request export of Customer Content as provided in the Refund Policy and Terms.
- Stop text messages at any time by any reasonable means. Replying STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, or UNSUBSCRIBE to any text from us always works, and so does an email to info@getnxera.com. We do not require particular wording. Reply HELP to any text for help.
6.2 California (CCPA/CPRA)
California residents have rights to: (a) know the categories and specific pieces of Personal Data we have collected about you, the sources, the purposes, and the categories of recipients; (b) delete Personal Data, subject to legal exceptions; (c) correct inaccurate Personal Data; (d) opt out of sale or sharing (we do not sell or share, but the opt-out right exists); (e) limit use of sensitive personal information (we do not knowingly collect sensitive personal information for purposes that would trigger this right); (f) non-discrimination for exercising these rights.
To exercise CCPA rights, email info@getnxera.com with subject line "CCPA Request" and your account email and a description of the request. We will verify your identity (typically via the email on file) before fulfilling the request. We will respond within 45 days, with a possible extension as permitted by law. You may designate an authorized agent in writing. Where we hold your data as a client's processor, we will forward the request to the client and assist it in responding.
6.3 Other US States
We extend equivalent rights (access, deletion, correction, portability, opt-out of sale/sharing) to residents of all U.S. states with applicable comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Florida, Delaware, New Jersey, New Hampshire, Maryland, Minnesota, Rhode Island, and any others as they take effect). Same email contact and procedure as Section 6.2.
6.4 International Rights (Future)
Nxera currently provides Services to U.S. clients. If we expand internationally, we will publish jurisdiction-specific rights and procedures (including GDPR rights for the EU/UK and PIPEDA rights for Canada) at that time. We will not enroll non-U.S. clients before those procedures are in place.
6.5 Limits and Exceptions
We may decline a request where: (a) we cannot verify your identity; (b) the request is excessive, repetitive, or manifestly unfounded; (c) fulfilling the request would violate a legal obligation, infringe another person's rights, or compromise an active investigation; (d) the data is necessary to complete a transaction, protect against fraud, comply with law, or for our legitimate business interests as permitted by law. We will explain any denial in writing.
7. Cookies and Similar Technologies
See the Cookie Policy for details on cookies and tracking technologies, including the strictly-necessary, functional, and analytics cookies we use (including Google Analytics 4 through Google Tag Manager on marketing pages), and your choices.
We do not currently respond to "Do Not Track" browser signals because there is no industry consensus on how to interpret them. We do, however, honor opt-out signals required by applicable law (such as the Global Privacy Control, "GPC," to the extent applicable to our practices).
8. Security
We implement and maintain administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, and destruction, including:
- Encryption: TLS 1.2 or higher in transit; encryption at rest provided by underlying cloud infrastructure (Supabase, Vercel).
- Access controls: least-privilege role-based access for Nxera personnel; multi-factor authentication for all staff access to production systems; portal access for clients through single-use sign-in links and HttpOnly session cookies on the web, and through rotating bearer sessions tied to your device, with a Face ID, Touch ID, fingerprint or passcode lock whenever your phone has a screen lock, in the Nxera app.
- Network and platform security: bot mitigation on forms through Cloudflare Turnstile; vulnerability monitoring of dependencies and infrastructure.
- Backups and recovery: regular database backups with point-in-time recovery via Supabase.
- Personnel: confidentiality obligations and security training for staff.
- Vendor risk management: Sub-processors selected with consideration of security and data-protection commitments.
- Incident response: documented procedures for detecting, containing, and notifying on Personal Data breaches.
No security system is impenetrable. Despite our safeguards, we cannot and do not guarantee absolute security. You are responsible for safeguarding your account credentials and sign-in links and notifying Nxera of suspected unauthorized access (Section 2.4 of the Terms).
In the event of a data breach affecting your Personal Data, we will provide notice as required by applicable law.
9. International Data Transfers
We are based in the United States. Personal Data is processed in the United States. By using the Services, you consent to the transfer, processing, and storage of your information in the United States, which may have different data-protection laws than your jurisdiction. If we expand internationally, we will rely on lawful transfer mechanisms (for example Standard Contractual Clauses) for any cross-border transfer that requires them.
10. Third-Party Links
The Services may link to third-party websites, apps, or services (including Google review pages, Stripe-hosted checkout and billing pages, and links a client places in its messages). Nxera is not responsible for the privacy or security practices of those third parties. We encourage you to review their privacy policies before using them.
11. Plan Page Visitors and Members
Visitors to a Plan Page at getnxera.com/m/ or on a client's custom domain, and members who enroll there, should consult the privacy notice of the Client operating that page for anything beyond what this Policy describes. Nxera processes data on behalf of the Client; the Client decides which plans are offered and what messages are sent. For questions about a specific Plan Page, contact the Client directly using the contact details on the page, or contact info@getnxera.com and we will route your question.
12. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, the Services, or applicable law. We will post the updated Policy on the Site with a new effective date. Material changes will be communicated by email at least thirty (30) days before they take effect. Your continued use after the effective date constitutes acceptance of the updated Policy.
13. Disputes
Any dispute arising out of or relating to this Policy is subject to the dispute-resolution provisions in Section 16 of the Terms, including binding individual arbitration, class-action waiver, and the one-year limitations period.
14. Contact
For questions, requests, or complaints about this Policy or our privacy practices:
Nxera Digital LLC, Privacy 1201 E Ponce De Leon Blvd Coral Gables, FL 33134 info@getnxera.com
This Privacy Policy was last updated on September 28, 2026. Version 4.0.