NexusDrop GNR
Product Architecture Who It's For Contact ES

Data Handling and Security Architecture

1. What Data We Process

Our middleware intercepts events (webhooks) from destination platforms (for example TikTok Shop) that may include end-buyer data — name, shipping address, phone number, email address — and forwards them to the sourcing platform (AutoDS) to process order fulfillment. We also store integration credentials (OAuth access and refresh tokens) required to keep the B2B User's accounts connected to those platforms.

2. How This Data Is Stored and Protected

Our infrastructure is designed to maintain the operational state required for reliable event delivery — idempotency, retries, accounting reconciliation — through a managed database with encryption at rest and in transit. OAuth access tokens and any in-memory structure retaining sensitive information are covered under a forced memory purge regime (zeroization) immediately after operational use. Financial records tied to transactions are designed to be retained in an append-only repository with immutable retention, for the period required by our accounting and regulatory obligations — not to be retained indefinitely nor used for purposes other than operating the Service, accounting reconciliation, and legal compliance.

This section describes the system's target architecture; it does not constitute a certification that the infrastructure described is deployed in production as of the date of this publication.

3. Session Data and Fraud Prevention (Compelling Evidence 3.0)

To protect the payment processing account against fraudulent disputes, our architecture provides for the passive logging of the IP address and device identifier of the B2B User holding the subscription (not the end buyer) during login and billing. This data is intended exclusively to qualify for card network pre-dispute resolution mechanisms and is not sold or shared with third parties for advertising purposes.

4. PCI DSS Compliance

We do not store payment card numbers; payment processing is delegated entirely to our Merchant of Record, which reduces our PCI DSS compliance scope to the outsourced cardholder data environment (SAQ-A).

© 2026 NexusDrop GNR LLC. All rights reserved. Contact: support@nexusdropgnr.com

Terms of Service Privacy Refund