Privacy Policy
Last updated: April 29, 2026
NexusStatus ("we", "us") helps U.S. ecommerce businesses track economic nexus and sales tax liability across states. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. If you have any questions, email us at sales@nexusstatus.com.
Information we collect
- Account information you provide when you register: name and email address.
- Team data: team name, member roles, and invitations.
- Sales data you upload or import: order date, U.S. state, amount, tax remitted, marketplace facilitator flag, external order ID, and buyer ZIP code.
- Integration credentials: when you connect a third-party platform (such as eBay), we store the access and refresh tokens needed to retrieve your data on your behalf. Tokens are encrypted at rest.
- Service usage data: server logs, error reports, and basic, privacy-respecting analytics.
How we use information
- Operate the service and calculate your economic-nexus position against each state's thresholds.
- Send transactional emails (account verification, password reset, team invitations, important service notices).
- Diagnose problems, prevent abuse, and improve the product.
We do not sell your personal information, and we do not use your sales data to train machine-learning models.
How we share information
We share information only with service providers who help us run NexusStatus, and only to the extent necessary:
- Hosting and infrastructure: Laravel Cloud and Amazon Web Services (including S3 for file storage).
- Email delivery providers used to send transactional messages.
- Connected platforms you authorize (such as eBay): we exchange OAuth tokens with the platform and read order data from it on your behalf. We do not write data back to those platforms.
We may also disclose information when required by law, to protect our rights, or in connection with a corporate transaction.
eBay integration
When you connect an eBay account, NexusStatus uses the eBay OAuth flow with read-only scopes to retrieve your order history and account information. We comply with eBay's Marketplace Account Deletion / Closure notification requirements: when eBay informs us that a seller account has been closed, we promptly delete the associated integration record from our systems. You can also disconnect your eBay account at any time from the integrations page, which immediately stops new data syncs and removes your stored tokens.
Data retention
We retain your account and sales data for as long as your account is active. If you delete your account or request deletion, we will remove your personal information and stored credentials within 30 days, except where retention is required for legal, accounting, or security purposes.
Your rights
You can access, correct, export, or delete your data at any time. Email sales@nexusstatus.com and we will respond within 30 days. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA.
Security
Traffic is encrypted in transit with TLS. Integration credentials are encrypted at rest. Access to production systems is limited to personnel who need it. No system is perfectly secure; if we ever discover a breach affecting your information, we will notify you in accordance with applicable law.
Cookies
We use only the cookies needed to keep you signed in and to protect against cross-site request forgery. We do not use third-party advertising cookies.
Children
NexusStatus is not directed to children under 18, and we do not knowingly collect personal information from them.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or through the application before the change takes effect.
Contact
Questions, requests, or concerns? Email sales@nexusstatus.com.