1. Who operates Nerve OS
Nerve OS is operated by Ice Blueprint PTY Ltd (ACN 643 051 174), with an address at 2/8 Russell Court, Miami, QLD, Australia. Privacy, support and deletion questions should be sent to ice@yktr.com.au.
2. Information we collect
When you begin the Nerve OS pre-qualification questionnaire, we collect your work email and the answers you choose to provide about your store platform, revenue range, data sources, decision-making context, business blind spots and previous attempts to solve them. Partial and completed questionnaire responses are stored in the shared Nerve OS Supabase project. On completion, we also collect your name, business name, optional store URL and any optional explanation you provide about what a clearer operating picture would unlock. Completed submissions may be sent through Resend to a configured internal recipient so that we can respond. Do not submit passwords, access tokens, payment-card details, government identifiers or other secrets through the questionnaire.
We also receive ordinary server and anti-abuse information needed to deliver and protect the questionnaire, such as request time, approximate technical identifiers and delivery status. When a customer uses workspace features or enables a connection, we may process:
- Account and workspace information, such as email address, display name, role, invitations, permissions and notifications.
- Meta OAuth identity information and advertising reporting data, including account, campaign, ad set, ad hierarchy, budgets, attribution settings, spend, impressions, reach, clicks, purchases and Meta-reported revenue, if the Meta connection is enabled.
- Shopify shop and store information, products, variants, inventory, orders, refunds and related financial data required for the configured workspace, if the Shopify connection is enabled.
- Workspace, operational, supplier, launch, OKR and creative information entered by authorised users, including supplier contact details, notes and messages, where the relevant workspace modules are enabled.
- Uploaded images, PDF files and notes, together with file names, types, sizes, checksums and thumbnails. These materials may contain sensitive or confidential information supplied by the customer.
- Inventory metrics and, where enabled, SKU, product and category context used by the read-only inventory advisor. AI recommendations, assumptions, usage and request metadata may also be stored when that feature is enabled.
- If enabled for a workspace, approved competitor configuration and data received from a customer-authorised API provider.
The public site, questionnaire, private file uploads and notifications are part of the current service surface. Some dashboard modules and integrations remain in testing or are available only when enabled, so this policy describes them conditionally rather than as universally active functionality.
3. How we use information
We use questionnaire information to respond to the request, understand the business context, personalise a demonstration and arrange a conversation. Partial responses may be retained when someone leaves before completion so that the lead is not lost. We use connected data to provide the Nerve OS operating view, reporting and related workspace functions. We may use technical information to prevent abuse, troubleshoot delivery and protect the service.
Completing the questionnaire is not marketing consent. If you separately opt in to marketing communications, we may use your contact details for those communications and will provide an unsubscribe option. For customer workspace data, Ice Blueprint generally acts as a service provider or processor on the customer’s behalf. For data needed to operate its own accounts, support, security, compliance and separately consented marketing, Ice Blueprint acts as the controller responsible for those uses.
4. Optional Meta and Shopify connections
The Nerve OS Meta connection is designed to be reporting-only when enabled. It requests ads_read and business_management as configured for the application. It does not request ads_management and is not used to create, edit, pause, publish or delete Meta campaigns.
Removing Nerve OS from Meta Business Integrations can stop future access, but it may not remove information Nerve OS already stored. Use the instructions at Data Deletion to request deletion of stored information. Shopify-related deletion and shop-redaction requests can also be sent to the contact below and reviewed under the applicable Shopify requirements when that connection is enabled.
5. Storage, security and providers
Shopify and Meta access tokens are encrypted server-side using AES-256-GCM before storage. No security measure can guarantee absolute security. Nerve OS uses Supabase for database, authentication and private file storage; Vercel or the configured hosting provider for hosting and scheduled jobs; Resend for email delivery; Anthropic for the read-only inventory advisor when enabled; and Frankfurter/ECB for foreign-exchange reference data. Meta and Shopify process information when you authorise those connections. Provider legal names, processing locations, retention terms, subprocessors and transfer details remain subject to confirmation before publication.
6. Retention and deletion
Questionnaire records are targeted for deletion within 30 days when that lead-capture feature is enabled. Related email copies may remain according to provider and mailbox settings. Connected workspace data is retained while the workspace is active and for up to 60 days after closure. Shopify data is targeted for deletion within seven days after disconnection, and Meta identity and reporting data within seven days after disconnection when that connection is used.
Files and certain Creative Studio and Supplier Hub records use soft deletion with a fixed 30-day recovery window before scheduled purge. Audit events, job records, webhook payloads, synchronisation logs and email-event records are targeted for 30 days. Backups and disaster-recovery copies are targeted for 90 days. The read-only AI advisor is not treated as a live retention category while it remains in testing.
You may request access, correction or deletion by emailing ice@yktr.com.au. We aim to respond to verified privacy and deletion requests within seven days, but completion may take longer where identity verification, provider action or a lawful retention exception applies. See Data Deletion for the information to include and the applicable process.
7. International processing and rights
Nerve OS is currently intended to serve customers in Australia and New Zealand. Service providers may process information in other countries, including through their infrastructure, email systems, integration services or backups. The exact provider processing locations and legal transfer mechanism remain subject to confirmation before publication. Depending on your location, you may have rights to access, correct, delete, restrict or object to processing and to receive a copy of certain information.
8. Children and changes
Nerve OS is intended for business users and is not directed to children. We may update this policy as the service changes. The effective date above will be updated when a material revision is published.
9. Contact
Privacy, support and deletion contact: ice@yktr.com.au
Address: 2/8 Russell Court, Miami, QLD, Australia
ACN: 643 051 174