The short version
- Your spreadsheet is read, parsed, mapped, validated and converted inside your browser tab. It is never sent anywhere.
- There is no account, no login and no cookies of any kind. Buying Pro gives us your email address, and nothing else about you.
- Two optional items may be written to
localStorageon your own device: mapping presets you save, and a signed proof-of-purchase token after you buy Pro. - An optional analytics beacon may send counts and flags only — never file contents, column names, cell values or file names.
- No advertising networks, no fingerprinting, no third-party tracking scripts.
Who operates this
Nexum Gate is operated by „АДСТИК ИНТЕРАКТИВ ЕООД“ (ADSTIC INTERACTIVE LTD), Varna, Bulgaria, EU VAT BG206749752. For GDPR purposes that company is the data controller for the limited data described below. Written enquiries go to contact@adsticorb.com.
Your files are not uploaded
Nexum Gate’s pages are a static export: HTML, CSS and JavaScript files, with no application server rendering them and no endpoint anywhere that accepts a file. When you choose a spreadsheet, your browser reads it from your own disk, and every step after that — delimiter and encoding detection, column mapping, validation, CSV generation and the download — runs in that tab, on your machine.
There are four small server functions on this domain, and they exist only for the Pro purchase: starting a Stripe checkout, confirming a completed payment, checking a restore link and sending one. They receive an email address or a Stripe session id. None of them can receive a spreadsheet, because nothing in the product ever sends one.
This is not a promise that could be quietly reversed by flipping a setting. There is no upload endpoint in the product to send a file to. We cannot see your file, cannot retain it, and could not produce it if someone demanded it from us.
One practical consequence worth knowing: closing or reloading the tab discards everything. Nothing is recoverable afterwards, by you or by us. Download the converted CSV before you leave the page.
Stored on your device
Two keys in localStorage, each created only if you use the feature that needs it, each on your own device, and neither readable by us. Both belong to Pro features, so a free-tier session writes nothing at all — not to localStorage, not to sessionStorage:
csvforge_presets— mapping presets you chose to save. A preset holds the column names, constants and formula settings you entered. It does not hold your product rows.nexumgate_pro— a signed proof-of-purchase token, your email address as Stripe reported it, and the date Pro was unlocked on this device. It is not a password and it cannot be used to charge anything.
An older version of this site stored a typed-in licence key under csvforge_license. That slot is no longer used and is deleted automatically the next time you open the converter.
Clearing your browser’s site data for this domain removes both. We hold no copy of either; there is no sync, no backup and no account to attach them to. We do not use cookies at all — not even “essential” ones, because there is no session to keep.
Analytics
The build can be pointed at a single analytics endpoint. When it is, the site sends a small beacon for a handful of product events: that a file was loaded and how many rows and columns it had, how many columns the auto-matcher matched, which preset was applied, that a bundled sample was opened, that an export completed and how many products and errors it contained, and that the Pro dialog was opened.
Those beacons carry no file contents, no column names, no cell values and no file name — only integers and flags, plus the page path and the referrer. There is no cross-site identifier, no cookie, no device fingerprint and no profile built about you.
When no endpoint is configured at build time the analytics function is a no-op and no requests are made at all. Either way, no third-party advertising, analytics or tag-manager script is loaded on any page of this site, and the web fonts are bundled at build time and served from this origin rather than fetched from a font CDN.
Payment data
The one-time Pro purchase is handled by Stripe on Stripe’s own checkout pages. Card numbers never reach this site and we never see them. Stripe acts as a separate controller for the payment itself and emails you the receipt.
What we process is deliberately small: your email address and the Stripe checkout session id, used to unlock Pro on your device and to restore it on another one later. The amount and the billing country for VAT sit in the purchase record, which tax law requires us to keep.
If you ask for a restore link, your email address is passed to Resend, our email delivery processor, for that one message. We do not add you to a mailing list; we do not have one.
Pro itself is unlocked locally. The token on your device is read by your browser, not sent back to us on each use, so using Pro does not report to us that you are using it.
Hosting and server logs
The static files are served by a hosting provider acting as a processor. Like any web host it may keep standard access logs — IP address, timestamp, user agent, requested path — for security and operational purposes under its own retention policy. Those logs record that a page was fetched. They cannot contain anything about your spreadsheet, because your spreadsheet is not transmitted.
Image URLs
The validator checks the shape of your image URLs locally — that each is http or https and well formed. It does not request them. No connection is made from this site to your supplier’s image host, so your supplier learns nothing about your conversion. Shopify fetches those URLs itself, later, when you import the CSV into your store.
Your GDPR rights
If you are in the EU/EEA you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to a supervisory authority — in Bulgaria, the Commission for Personal Data Protection (КЗЛД).
In practice there is very little for us to act on. We hold no account, no profile and no copy of your files. The presets and the purchase token live on your device and you can delete them yourself by clearing site data. If you bought Pro we hold the purchase record — your email address, the Stripe session, the amount and the VAT country — kept for as long as tax law requires and no longer. Write to contact@adsticorb.com and we will answer within 30 days.
The legal basis for the purchase record is performance of the contract and our legal obligations; for the anonymous product counts, our legitimate interest in knowing whether the tool works — limited by the fact that those counts identify nobody.
Children
This is a tool for people running a shop. It is not directed at children, and we knowingly collect nothing from them — there is no mechanism here that could collect anything from anyone.
Changes
If this policy changes, the effective date at the top changes with it and the previous wording stops applying from that date. A change that involved transmitting your file off your device would not be a policy revision; it would be a different product, and it would be announced as one.
Contact
„АДСТИК ИНТЕРАКТИВ ЕООД“ (ADSTIC INTERACTIVE LTD)
Varna, Bulgaria
EU VAT BG206749752
contact@adsticorb.com
See also the Terms, which cover the one-time Pro purchase and the 14-day refund, and Pricing.
Back to the tool: convert a supplier spreadsheet to a Shopify CSV, or read the 61-column format reference.