DATA PROCESSING
Data Processing at Luria
Last updated: 2 October 2026
This page explains how Luria handles data when it runs on a merchant's store. It also explains
how our Data Processing Addendum (DPA) works. It sits beside our
Privacy Policy and Terms of Service.
1. Roles: you are the controller, we are the processor
When the Luria snippet runs on your store, the visitor data it collects is your
data. You are the data controller. Luria is your data processor. We use visitor data only to run
the service for you. That means showing page versions, counting events, and linking each sale to
the version shown. We do this only on your instructions and under our DPA.
2. What the snippet collects and processes on your store
- Visitor IDs: each visitor gets a random first-party ID (a UUID). We never use
fingerprinting. That means no canvas, audio, or device-entropy tricks, ever.
- What visitors do: page views, clicks on anything you set as a goal, how far they scroll,
which page version they saw, add-to-cart, and checkout events.
- Sale events: order events we get from your store platform (for example,
Shopify webhooks). Each one notes the page version the order came from, saved at order time.
- Not collected: passwords, payment details, or what people type in forms. Our
analytics events hold no content by design.
3. Subprocessors
We use a short, fixed list of service providers:
| Subprocessor | Purpose |
| Cloudflare | Hosting the app, the database (D1: events, tests, and accounts, United States), scan machines that load your public pages during audits, transactional email, and R2 object storage for session recordings and page screenshots (global) |
| Vercel | Forwards visits that still reach our old address to Cloudflare until it is shut down in October 2026; stores nothing (United States) |
| Moonshot AI (Kimi) | AI reads your public page content, screenshots, and pseudonymous summaries of visitor journeys (pages and clicks, never form input) during scans and while it drafts page versions (China) |
| DeepSeek | AI reads the same text, without images, for analysis and copy drafts (China) |
| Cloudflare, Vercel, Stripe, Calendly (your own accounts) | Only when you connect them (off by default): your own Cloudflare or Vercel account runs the tracking script at the edge and passes the visitor's IP and country to us with each request; your Stripe sales and Calendly bookings come in with buyer emails stored only as a one-way hash |
We will tell you before we add or swap any subprocessor that handles visitor data.
4. Consent, GPC, and regional rules
- You must show your visitors any consent banner the law asks for. Where consent is needed
(EU/UK), the snippet is built to wait for it.
- We honour Global Privacy Control (GPC) signals.
- Each store's visitor data is kept apart. What we learn across stores comes from pooled,
anonymous patterns only. We never build a profile of one visitor across sites.
5. How long we keep data, and how to delete it
- Raw event data: we keep it 90 days. Then we delete it or pool it.
- Session recordings: we keep them up to 180 days to measure and improve that one store and to train its models, then we delete them automatically. The learning rows we derive from them hold no raw recording. A store can delete them sooner, any time, with Delete my data.
- When a store uninstalls, we delete everything we hold for it. Its owner can delete all of its collected data sooner, any time, with Delete my data.
- Pooled stats that cannot be traced to a person: kept with no end date.
- Deletion requests: we honour them for you and for your visitors. Email us. We will delete
within 30 days. That includes backups, as each backup rotates.
6. How we keep data safe
- All traffic runs over TLS. We add strict security headers to every page. One of them is a strict Content-Security-Policy.
- We log every page change Luria makes. Any of them can be undone. A kill switch stops the
snippet from serving changes at all.
- Only Luria's operators can get to live data.
7. Getting a signed DPA
Every customer can get a DPA that is ready to sign. It uses standard processor terms and it
includes the subprocessor list above. Ask for one at
privacy@luriart.com and we will send it out for both sides to sign.
8. What the variant engine collects (v2026-08-14)
Some stores run the Luria variant engine. That means the Luria theme app embed plus the Luria
web pixel. On those stores, the rules below apply as well as all the rules above:
- Visitor actions: page views, how far they scroll, clicks, and cart and checkout
steps (checkout started, contact, address, shipping, payment, completed). Each one is tied to the
random first-party visitor ID.
- Order and sale data: order ID, order totals, currency, and the page version the
order is linked to. Never customer names, emails, phone numbers, or addresses.
- Site content: the layout and words on your public store pages. We read them so
we can build and serve page versions on your store.
- Roles: you (the merchant) stay the data controller. Luria is your data
processor, as set out in the DPA above.
- Learning across stores: we may pool what tests teach us in anonymous form,
and feed that into models used for all clients. The terms allow this. We never build a profile
of one visitor. We never share data that points to your store or your customers.
- Visitor consent: we honour it by region, through the Shopify Customer Privacy
API and Global Privacy Control. One cookie keeps each visitor on the same page version. That cookie
is functional and strictly necessary. We cut back or hold what we collect about what visitors do.
That applies where consent is required and a visitor has not given it.
This page is a plain summary, not legal advice. It does not replace the signed
DPA or the Terms of Service.
← Back to luriart.com · Privacy · Terms