Who we are
Nitro is published by Dtek Networking, which is the data controller for everything described on this page. Write to [email protected] for anything to do with your data, including the requests described under Deletion and access.
What the extension sends
The Nitro extension has to ask this server whether the store it is installed on is licensed. To do that it sends three things, and only these three:
- the store domain — the storefront hostname or hostnames the OpenCart install serves;
- the email address entered in Nitro's admin, which is what a licence is issued against;
- the extension version, so the admin can tell you when an update exists.
Once a licence or trial exists for a store, this server issues a token for it and the extension sends that token back on later checks. The token identifies the licence. It says nothing about the store, and it is generated by us — it is not derived from anything of yours.
Like any HTTP request, a licence check arrives with the network address it was sent from. We use it to rate-limit the endpoint and to cap how many brand-new trials one address can start in a day; it is not stored against your licence, and it is not used to identify you.
What it never sends
The extension collects no usage statistics. It does not report page views, traffic, cache hit ratios, settings, performance measurements, or anything else about how the store is used or how it is doing.
It sends no customer data and no order data. Your customers' names, addresses, emails, carts and orders never leave your server — Nitro reads them on your server to build pages, and there is no path in it that transmits any of that anywhere.
There is no analytics script, no beacon, no crash reporter and no third-party service inside the extension.
Your account
The first time an email address is seen by the licence API, we create an account record for it so that the trial or licence has an owner. That record is a shell: the address, and nothing else. It has no password and it is not verified, and creating it does not send you anything.
You claim that account by registering with the same address and verifying it. Verification is what proves the address is yours, and it is what grants access to the customer portal, where the licences issued to that address are listed. Until an address is verified, nobody can see anything through it.
A 7-day trial is recorded against the store domain it was issued for, permanently — that is how one trial per domain is enforced. The record is the domain and the date, and it survives the licence it belonged to.
This website
This site sets no analytics, advertising or tracking cookies, and embeds nothing from a third party — the fonts are served from this domain, not from a font provider.
If you send a message through the support form, we store what you typed — your name, your email address, the subject and the message — because that is the message. Alongside it we store a salted hash of the network address it came from, so the form can be rate-limited; the address itself is not kept.
How long we keep it
Licences and the accounts that own them are kept for as long as the licence exists — a paid licence is lifetime, so its record is too. Trial claims against a store domain are kept permanently, because the rule they enforce is permanent. Support messages are kept while they are useful for supporting you, and deleted on request.
Deletion and access
Write to [email protected] from the address you want to ask about, and tell us what you want:
- A copy of what we hold for that address — the account, its licences and any support messages.
- A correction, if something is wrong.
- Deletion of the account and its support messages.
Deleting an account deletes the licences attached to it, which means the stores those licences cover stop being licensed. We will say so before doing it rather than afterwards. One thing we cannot delete is the record that a store domain has used its one trial: it is not personal data — it is a domain and a date — and removing it would hand a fresh trial to whoever asks for that domain next.