Privacy Policy
This policy explains what personal information NexiNext collects, why we collect it, who we share it with, and what you can ask us to do about it. It is written to be read, not to be survived.
1. Who we are
NexiNext is operated by NexiNext LLC, a Texas limited liability company, with its registered address at 2 Petal Park Pl, The Woodlands, TX 77382, United States.
For privacy questions or to exercise any of the rights in section 13, write to privacy@nexinext.com.
2. What this policy covers
- The marketing website at www.nexinext.com
- The NexiNext application at app.nexinext.com
- The NexiNext mobile apps for iOS and Android
Together we call these “the Service”.
3. Our two roles — please read this one
NexiNext is a business tool. Companies subscribe to it, and their employees use it to run their work and to manage their own customers. That means we handle two different kinds of personal information, under two different responsibilities.
We are the controller for the information about the companies that subscribe and the people who hold accounts with us — their names, email addresses, sign-in records, billing details. We decide how that information is used, and this policy governs it.
We are a processor for everything a subscribing company puts into the Service about its own customers, leads, vendors and contacts — the prospect records, contracts, invoices, appointments and messages. We hold and process that information on that company’s instructions, for that company’s purposes. We do not decide what goes in it, and we do not use it for our own ends.
So if you are a customer of a business that uses NexiNext and you want to see, correct or delete your records, your request goes to that business, not to us. They control that data; we are the filing cabinet. If you contact us anyway, we will pass your request to them and tell you we have done so.
4. What we collect
Account and profile
Your name, email address, phone number, language preference, job title, and profile photo if you upload one. Your password is stored only as a bcrypt hash — we never hold the password itself. If you turn on two-factor authentication, we store the encrypted secret and your backup codes.
Sign-in records
Each sign-in updates a count, a timestamp, and the IP address you signed in from. We keep the current and previous values. This is standard account-security telemetry: it is how you and we can tell whether someone else has been in your account.
Company and tax information
For companies that issue Mexican CFDI invoices, we store the RFC, fiscal legal name, postal code, régimen fiscal, and the related SAT fields. We also store the company’s Certificado de Sello Digital — the certificate, its private key, and its password — because stamping an invoice requires them. These are encrypted at rest and are the most sensitive material we hold. See section 10 for who else touches them.
Customer records entered by a subscribing company
Under our processor role: prospect and contact names, email addresses, phone numbers, Instagram usernames and Instagram-scoped IDs, organisation names, notes and message history; vendor names and tax IDs; appointments; support tickets; uploaded files.
Payments
We store Stripe customer and connected-account identifiers, and for saved cards only the brand, last four digits, and expiry date. Full card numbers and security codes go directly from your browser or device to Stripe and never reach our servers. For Mexican OXXO and SPEI payments we store the voucher link and the receipt email address.
Electronic signature evidence
When a contract is viewed, signed or declined in the Service, we record the signer’s name, IP address, browser user-agent string, and the timestamps of each step, along with the signature image and the resulting signed PDF. We are explicit about this because it is the point: an electronic signature is only worth something if there is evidence attached to it. That evidence is retained with the contract.
Support reports and diagnostics
If you report a problem, the report carries the app version, device model, operating system, device type, screen and viewport size, timezone, language, browser user-agent, your IP address, the page you were on, and — only if you choose to attach one — a screenshot.
Files you upload
Receipts, bills, contracts, library documents, quote and invoice attachments, profile photos, company logos, and CFDI XML and PDF files.
Mobile app
When you sign in on a phone we store the device name, the platform, and a Firebase push token so we can deliver notifications. The app asks for camera and photo access when you take or pick a picture to upload, and for contacts access only when you refer someone to a company. Your contacts are read on your device and shown to you in a picker — the list is never uploaded. Only the single contact you actually choose is sent, and only so the referral can reach them.
Audit history
The Service keeps a version history of record changes and an audit log of significant actions. Both are keyed to the acting user’s ID — not to an IP address. When a member of our support team accesses a company’s account to help with an issue, that access is logged with a mandatory written reason.
5. What we do not collect
We think this is as informative as the list above.
- No location data. The mobile apps request no location permission of any kind, and there is no latitude, longitude or coordinate field anywhere in our database.
- No advertising identifiers. We do not read IDFA or the Android advertising ID, we show no App Tracking Transparency prompt, and we are in no ad network.
- No third-party analytics or tracking. There is no Google Analytics, no tag manager, no advertising pixel, no session-recording tool, and no heatmap script — not on the marketing site, not in the application, not in the mobile apps.
- No full card numbers or security codes, no biometric data, no microphone access, and no bulk upload of your contact list.
6. Cookies
The application sets four cookies. All of them are first-party, and each is set only because of something you chose to do:
- A session cookie, encrypted, which keeps you signed in.
- A
remember_two_factor_devicecookie, signed and HTTP-only, set for 30 days only if you ask us to remember a device for two-factor authentication. It is invalidated immediately if you change your password or your two-factor settings. - A remember-me cookie, set for 30 days only if you tick “remember me” at sign-in, and cleared when you sign out.
- An account-switching cookie, signed, encrypted and HTTP-only, set for 30 days only if you choose to add a second account to this browser so that you can move between your own accounts without typing a password again. It holds sign-in tokens — never a password — for at most five accounts. Each one is invalidated immediately if that account’s password or two-factor settings change, if the account is suspended or deleted, if a member of our staff revokes that account’s sessions, if you remove the account or sign out of all accounts, or after 30 days without use. It is never set unless you explicitly add a second account, and it is deleted when the last one is removed.
There are no advertising or analytics cookies, which is why you have not seen a cookie banner here.
One third-party request does exist: the marketing site loads its typefaces from Google Fonts, which means Google receives your IP address and user-agent when a page loads. It is the only external request the marketing site makes.
7. Why we use it, and on what basis
| Purpose | Basis |
|---|---|
| Providing the Service, your account, and support | Performance of our contract with you |
| Billing, invoicing, collections | Performance of contract; legal obligation |
| Issuing and storing CFDI and tax records | Legal obligation (Mexican tax law) |
| Security, fraud prevention, rate limiting, audit logging | Legitimate interest |
| Service emails you cannot opt out of (password resets, security alerts, billing) | Performance of contract |
| Product news and marketing email | Consent — withdrawable at any time |
| Optional integrations (Gmail, Instagram, calendar) | Your consent, given per integration |
8. Artificial intelligence features
Some features use a large language model to draft text, summarise records, and extract data from documents. These run on Anthropic’s Claude API.
Be aware of what this means in practice. When you use an AI feature, the relevant record content is sent to Anthropic. For the document-extraction features specifically — reading a bill, a receipt or an invoice so its line items can be filled in for you — the contents of the uploaded file itself are transmitted.
Anthropic processes this as our sub-processor, under commercial terms that do not permit the content to be used to train their models. AI features are used only when you invoke them; they do not run in the background over your data.
AI output is assistive and can be wrong. Review it before relying on it, particularly for anything fiscal.
9. We do not sell your information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done so. There is no advertising business here to sell it to.
10. Who we share it with
We use the following sub-processors. Each receives only what its job requires.
| Sub-processor | What it does | What it receives | Where |
|---|---|---|---|
| DigitalOcean | Hosting and managed PostgreSQL database | All application data | United States |
| Amazon Web Services (S3) | File storage | All uploaded files, including digital seal certificates | United States |
| Stripe (incl. Connect) | Card payments, payouts, identity verification | Card data directly from your device; receipt email; payout account identity | United States |
| Facturapi | Authorised Mexican PAC — seals and stamps CFDI with the SAT | Issuer and receiver RFC, legal names, invoice contents, digital seal certificate | Mexico |
| Anthropic | AI features (see section 8) | Prompt content and uploaded document contents | United States |
| Postmark | Sending email | Recipient name, email address, message contents | United States |
| Google Firebase Cloud Messaging | Mobile push notifications | Device push token, notification title and body | United States |
| Twilio | SMS delivery of two-factor codes | Phone number, verification code | United States |
| Google (Gmail API) | Optional, per user — mailbox sync for logging client email | OAuth token, message headers, message contents for messages you send | United States |
| Meta (Instagram) | Optional, per company — Instagram direct message integration | OAuth token, Instagram-scoped ID, username, message contents | United States |
| Google / Microsoft | Single sign-on, if you use it | Provider account ID, email address | United States |
| Cloudflare | Delivering the marketing website | Request IP address | Global edge network |
Two clarifications. The Gmail and Instagram integrations are off unless you turn them on, per user and per company — if you never connect them, nothing is ever sent. And we determine a visitor’s country from their IP using a local database so the site can pick a language: that lookup happens on our own server, and nothing is sent to the database vendor.
Beyond this list, we disclose personal information only when the law requires it, and to professional advisers under confidentiality. If NexiNext is ever acquired or merged, your information would transfer with the business; we would tell you before that happened.
11. Where your information is stored
All personal information is stored in the United States — our servers and database are in DigitalOcean’s New York region, and uploaded files are in Amazon S3 in the US East region. This is true no matter where you or your customers are located.
For users in Mexico, this is an international transfer of personal data, made so that we can provide the Service you have contracted for. For users in the European Union or the United Kingdom, transfers rely on the European Commission’s Standard Contractual Clauses and the equivalent UK addendum.
The single exception is CFDI stamping: invoice data goes to our PAC, Facturapi, in Mexico, because Mexican law requires a Mexican authorised provider to stamp it.
12. How long we keep it
Honestly stated, including where the answer is “indefinitely”.
- Account and company data — for as long as the account is open, and then until deletion is requested.
- Fiscal and CFDI records — retained for five years, as Mexican tax law requires. We cannot delete these on request within that period.
- Contracts and their signature evidence — retained for the life of the account, since their evidentiary value is the reason they exist.
- Audit and version history — retained for the life of the account.
- Suppressed-notification and automation logs — automatically deleted after 90 days.
- Records you delete in the app — removed from your view immediately and retained in the database in a deleted state, so that an accidental deletion can be undone. They are permanently erased when you close your account or ask us to erase them.
When an account is closed, we delete or anonymise its data within 90 days, except for records we must keep to meet the tax and legal obligations above.
13. Your rights
Wherever you live, you may ask us to:
- Access the personal information we hold about you, and get a copy of it
- Correct anything inaccurate or incomplete
- Delete it, subject to the retention obligations in section 12
- Object to or restrict how we use it
- Port it to another provider in a machine-readable format
- Withdraw consent you have given, at any time, without affecting what was done before
If you are in Mexico, these are your ARCO rights — Acceso, Rectificación, Cancelación and Oposición — under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares. The Spanish-language Aviso de Privacidad sets out the procedure and the statutory deadlines in full.
If you are in the European Union or United Kingdom, these are your rights under the GDPR, and you may complain to your national supervisory authority.
If you are in California, you have the right to know what we collect, to delete it, to correct it, and to opt out of sale or sharing — though as section 9 says, there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
How to make a request. Email privacy@nexinext.com with what you want and enough detail for us to find your records. We may ask you to verify your identity — we are not going to hand over someone’s data to whoever asks for it. We will respond within 30 days (for ARCO requests, within 20 business days, and if granted we will act on it within a further 15 days). Requests are free; we may charge only for repeated or excessive copies, and we will tell you before we do.
One limit, repeated from section 3: if your data was entered into NexiNext by a business you deal with, that business decides what happens to it. We will forward your request to them.
14. How we protect it
- All traffic is encrypted in transit with TLS, and it is enforced — there is no unencrypted route in.
- Passwords are hashed with bcrypt at a deliberately slow work factor.
- Two-factor secrets, integration access tokens, and digital seal passwords are encrypted at rest with authenticated encryption.
- Two-factor authentication is available by authenticator app, SMS or email, with backup codes, and is mandatory for our own administrative accounts.
- Sign-in, password reset, two-factor and payment endpoints are rate-limited, and accounts lock after repeated failed attempts.
- Access within a company is governed by roles; data belonging to one company is scoped away from every other.
- When our support staff need to access an account, the access is logged with a required written justification.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information, we will notify you and the relevant authority as the law requires.
15. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it.
16. Changes to this policy
We will update this page when our practices change, and the date at the top will change with it. For anything that materially affects your rights we will notify account holders by email before it takes effect. Continuing to use the Service after that means you accept the updated policy.
17. Contact
NexiNext LLC
2 Petal Park Pl, The Woodlands, TX 77382
United States
Privacy: privacy@nexinext.com
General: hello@nexinext.com
If you are unhappy with how we have handled a privacy request, please tell us first — we would rather fix it. You also have the right to complain to your data protection authority.