Nimble
Privacy Data Deletion Terms Contact

Data Deletion

Effective date: 2026-05-07  ·  Last updated: 2026-09-04

Summary (TL;DR)

  • You can request deletion of the active account and service data Nimble holds about you at any time. Limited records can remain as described in §§4 and 6.
  • For Shopify-tied data, uninstall begins the automatic erasure lifecycle, or you can email security@nimblevc.com. Google-side revocation follows the separate path in §2.2.
  • SLA: deletion within 30 days. Encrypted backups purge on a 30-day rolling cycle.
  • Every piece of data Nimble holds is private to your store, encrypted at rest, and never shared outside the service providers we use to operate the app (see Privacy Policy § 6).

1. What this page covers

This page describes how to request deletion of data Nimble holds about you. Most service data is tied to your Shopify store via the Nimble Shopify app. A Google Ads connection, when enabled, has the provider-revocation and local-deletion paths in §2.2.

2. What gets deleted when you uninstall the app

When you uninstall the Nimble Shopify app from your Shopify admin:

  • Shopify sends Nimble an app/uninstalled webhook within minutes
  • We mark your brand as inactive immediately, and Shopify OAuth access is invalidated
  • Shopify also sends a shop/redact webhook within 48 hours per Shopify's GDPR webhook spec
  • On shop/redact, we delete your stored credentials, brand context, and all derived data within 30 days
  • Encrypted backups containing deleted data purge on a 30-day rolling cycle
  • If you have connected a bank or card account, that connection is removed at Plaid and its stored token destroyed — see §2.1 below, because it works differently from the rest

For the full list of Shopify-tied data we collect, see Privacy Policy § 3.

2.1 Bank and card account connections

A bank connection is not deleted the same way a stored token is, so it gets its own path. What Nimble holds is described in Privacy Policy §3.8 — an access token, the account display details (name, type, last-four mask) and the connection status. Nimble does not store your balances or your individual transactions, and never receives your account and routing numbers or your bank login.

  • To disconnect yourself, at any time: open Settings → Integrations in the Nimble app and press Disconnect on the Bank & card accounts card. You do not need to contact us, and you do not need to uninstall.
  • What happens, in this order: Nimble first removes the connection at Plaid, so nothing stays authorized against your bank. Only then is the stored access token destroyed and the stored connection deleted. The order is deliberate — destroying the token first would leave an authorization at your bank that we could no longer revoke.
  • Deadlines: the access token is destroyed within 24 hours of disconnection or account termination. The account display details and connection status are deleted within 30 days.
  • If the removal at Plaid does not succeed: we keep the connection and its token rather than clearing it silently, so it stays revocable, and the card shows it as pending removal with a Retry disconnect button. Nothing retries on its own — a retry happens when you press that button or when Shopify re-delivers the uninstall notification.
  • Uninstalling runs the same removal automatically, with the same order and the same deadlines.

2.2 Google Ads connections

Google Ads has separate Google-side revocation and Nimble-local deletion steps:

  • Disconnect in Nimble: an authorized merchant or Nimble operator can choose Disconnect. Nimble immediately fences new manual and scheduled Google Ads reads and attempts to revoke the authorization with Google.
  • Token deletion: after Google confirms revocation or reports the token already invalid, Nimble deletes the encrypted refresh token from Supabase Vault and deletes its credential pointer before reporting the connection disconnected. If revocation or token cleanup fails, the request remains pending and the daily deletion process retries it.
  • Reporting-data deletion: after a successful Disconnect, Nimble retains the connection, reporting, and sync rows for up to 30 days, then the daily retention process deletes them. A non-secret lifecycle value remains only to reject stale OAuth callbacks.
  • Revoke at Google: you can revoke Nimble from your Google Account permissions. This removes Google's authorization but does not initiate deletion of Nimble's local records. Use Disconnect in Nimble or email a deletion request for local deletion; an authorized Nimble operator can run the same Disconnect path for your store.
  • Shopify uninstall: the immediate app/uninstalled webhook makes the store inactive but does not revoke Google authorization. Shopify's later shop/redact request deletes Nimble's local Google Ads credential pointer and Google Ads account, reporting, sync, deletion-state, and lifecycle records with the brand. Use Disconnect or Google Account permissions before uninstalling if you want Google-side revocation.
  • OAuth connection-attempt evidence: non-secret connection-attempt records can remain after these paths for security and operational attribution. They use the store identifier, initiator, status, timestamps, outcome details, and a one-way OAuth-state fingerprint; contain no token, authorization code, credential pointer, Google response payload, or reviewer identity; cannot authorize Google Ads access; and currently have no automatic expiry.
  • Independently reviewed deletion evidence: separate non-secret proposal and approval records can remain for compliance, dispute handling, and proof of deletion. They use one-way identifiers, action and observation details, and limited reviewer identity; contain no token, authorization code, credential pointer, or Google response payload; cannot authorize Google Ads access; and currently have no automatic expiry.

For the Google Ads information Nimble accesses, its read-only use, and the service providers involved, see Privacy Policy §3.9.

3. Email deletion request

If you want manual confirmation of deletion, or if you want to delete data without uninstalling the app, email security@nimblevc.com with the subject line "Data deletion request" and include:

  • Your Shopify store domain (e.g., brandname.myshopify.com)
  • The specific data you want deleted, or "all data Nimble holds about me"

We respond within 7 days and complete deletion within 30 days. If we cannot verify your identity (e.g., the request comes from an email not associated with the Shopify store), we will ask for additional verification before proceeding.

4. What gets deleted vs. what we retain

DataDeleted?Notes
Shopify access tokenYes (immediately on uninstall)Invalidated within minutes of app/uninstalled webhook
Shopify product, page, blog, theme, and file dataYes (within 30 days)On shop/redact webhook
Brand context you providedYes (within 30 days)Includes target audiences, claims, and language rules
Generated content drafts (in Nimble's database)Yes (within 30 days)Drafts already published to your Shopify blog stay in your Shopify store; Nimble's local copy is deleted
Google Ads encrypted refresh token and credential pointer — explicit DisconnectYes, after Google-side revocation is confirmed or the token is already invalidFailures remain pending and retry rather than being reported as deleted
Google Ads connection, reporting, and sync rows — explicit DisconnectYes, within 30 days after successful disconnectDeleted by the daily retention process; a non-secret lifecycle value remains to reject stale callbacks
Google Ads local data — shop/redactYes, with the brand erasureDeletes the local credential pointer and Google Ads rows, but does not prove Google-side revocation; revoke before uninstall
Google Ads OAuth connection-attempt evidenceRetained; no automatic expiry todayNon-secret security and operational-attribution evidence; no reviewer identity; cannot authorize Google Ads access
Google Ads independently reviewed deletion evidenceRetained; no automatic expiry todaySeparate non-secret proposal and approval records with limited reviewer identity; cannot authorize Google Ads access
Encrypted backupsPurge on 30-day rolling cycleMaximum 30-day retention post-deletion
Aggregate non-identifying metricsRetainedCounts of content generated and error rates; cannot be linked back to you or your store
Operational logs (request logs)30-day rolling deletionShop domain, endpoint, status, timestamp; no body content
Website analytics (nimblevc.com)Anonymized — no per-person record to deleteVisits to our marketing website are measured anonymously via PostHog and Google Analytics 4, with session replay disabled; see Privacy Policy § 3.6

Our marketing website (nimblevc.com) uses PostHog and Google Analytics 4 for anonymized website analytics (no session replay; see Privacy Policy § 3.6). Because these analytics are anonymized — we do not link them to your name, email, or store — there is no individual record tied to you to delete. You can also block analytics entirely using your browser's tracking protections.

5. Confirming deletion

Once deletion completes (within 30 days), we send a confirmation email to the address that initiated the request. If you used the self-service uninstall path (§ 2), you can verify deletion by:

  • Re-installing the Nimble Shopify app: your prior brand context will not appear, and you'll start fresh
  • Emailing security@nimblevc.com for a deletion-completion attestation

6. Limits on deletion

We may retain limited information after a deletion request when required by law or for legitimate operational reasons:

  • Tax and accounting records (subscription billing history), retained per applicable tax law
  • Records related to legal proceedings, subpoenas, or court orders
  • Anonymized aggregate metrics (cannot be linked back to you), used for service improvement
  • Limited non-secret Google Ads OAuth connection-attempt evidence described in §2.2
  • Limited non-secret independently reviewed Google Ads deletion evidence described in §2.2

If we are legally required to retain data and cannot delete it on request, we will notify you of the legal basis and the expected retention period.

7. Future integrations

If Nimble adds new third-party integrations (advertising platforms, email service providers, analytics tools, and so on), the same data-deletion principles apply: every piece of data is private to your store, encrypted at rest, and deletable within 30 days of your request. We will update this page with specific deletion paths for each integration when it launches — the bank and card account path in §2.1 is one that has already launched and is documented above.

8. Questions

For data deletion questions or to escalate a deletion request:

  • Privacy contact: help@nimblevc.com
  • Security contact: security@nimblevc.com

For broader context on data we collect, see Privacy Policy. For the terms governing your use of Nimble, see Terms of Use.

© 2026 Nimble · The honest call on every tool you pay for. Nimble is an independent product; not affiliated with Shopify Inc.
For founders For operators For consultants Growth agency Pricing Privacy Terms DPA Data deletion Contact