Privacy Policy

Last updated: 31 July 2026 · Applies to the Nomu app and website

What we collect

When you connect a Shopify store, Nomu accesses store data through Shopify's official APIs under the permissions you approve: orders, products, customers, checkouts, and store settings. We also collect your account email and product-usage events (which screens and actions you use) to improve Nomu.

How we protect customer data

Your customers' email addresses and phone numbers are hashed at the moment of ingestion — Nomu's analysis, AI features, and staff never see raw customer contact details. Store access credentials are stored in an encrypted vault, never in application tables. Every store's data is isolated with database-level tenant policies.

How data is used

Store data is used solely to provide Nomu's service to that store: analysis, opportunities, briefings, and the actions you approve. We do not sell data, share it across merchants, or use one store's data to serve another. AI features receive only the minimum context needed and never your customers' personal identifiers.

GDPR & data deletion

Nomu implements Shopify's mandatory privacy webhooks: customer data requests, customer redaction, and full shop redaction. Uninstalling Nomu stops all data collection; redaction requests are honoured automatically. You may also request full deletion at any time via hello@wavai.com.

Subprocessors

Nomu runs on Vercel (hosting), Supabase (database), Inngest (background processing), Anthropic (AI language features), and PostHog (product analytics, EU region). Each processes data only as needed to provide Nomu.

Contact

Privacy questions: hello@wavai.com. We reply within one business day.

Privacy Policy · Nomu