DATA PROCESSING
Data Processing at Luria
Last updated: 5 August 2026
This page summarises how Luria processes data when it runs on a merchant's store, and how our
Data Processing Addendum (DPA) works. It complements our
Privacy Policy and Terms of Service.
1. Roles: you are the controller, we are the processor
When the Luria snippet runs on your store, the visitor data it collects is your
data. You are the data controller; Luria acts as your data processor and processes visitor data
only to provide the service, variant delivery, event measurement, and conversion attribution,
per your instructions and our DPA.
2. What the snippet processes on your store
- Visitor identifiers: a random first-party UUID per visitor. No fingerprinting
(no canvas, audio, or device-entropy techniques), ever.
- Behavioral events: page views, clicks on goal elements, scroll depth, variant
exposures, add-to-cart and checkout events.
- Conversion events: order events received from your platform (e.g. Shopify
webhooks), carrying the variant attribution written at order time.
- Not collected: passwords, payment details, or form contents. Analytics events
are content-free by design.
3. Subprocessors
We use a small, fixed set of infrastructure providers:
| Subprocessor | Purpose |
| Vercel | Application hosting and content delivery |
| Supabase | Postgres database (events, experiments, accounts) |
| Anthropic | AI analysis of publicly visible page content during scans and variant drafting |
| Hetzner | Scan workers (rendering publicly reachable pages during audits) |
We will notify customers before adding or replacing a subprocessor that handles visitor data.
4. Consent, GPC, and regional rules
- Merchants remain responsible for presenting any legally required consent banner to their
visitors; the snippet is built to be consent-gated where consent is required (EU/UK).
- We honour Global Privacy Control (GPC) signals.
- Visitor-level data is partitioned per store. Cross-store learning uses anonymized,
aggregated patterns only, no cross-site visitor profiles.
5. Retention and deletion
- Raw event data: retained 90 days, then deleted or aggregated.
- Aggregated, non-identifiable statistics: retained indefinitely.
- Deletion requests: honoured for both merchants and their visitors, email us and we will
delete within 30 days, including from backups on their rotation schedule.
6. Security posture
- All traffic over TLS; strict Content-Security-Policy and security headers on every page.
- Every page change made by Luria is logged, reversible, and covered by a kill switch that
stops the snippet serving changes.
- Access to production data is limited to Luria's operators.
7. Getting a signed DPA
A signature-ready DPA (based on standard processor terms, including the subprocessor list above)
is available to every customer, request one at
privacy@luriart.com and we'll send it for counter-signature.
8. Variant engine data collection (v2026-08-14)
On stores running the Luria variant engine (the Luria theme app embed plus the Luria web pixel),
the following applies in addition to everything above:
- Visitor behavioral data: pageviews, scroll depth, clicks, and cart and checkout
funnel events (checkout started, contact, address, shipping, payment, completed), keyed to the
random first-party visitor ID.
- Order and conversion data: order ID, order totals and currency, and the page
variant the order is attributed to. Never customer names, emails, phone numbers, or addresses.
- Site content: the structure and copy of your public storefront pages, read in
order to generate and serve page variants on your store.
- Roles: you (the merchant) remain the data controller; Luria acts as your data
processor under the DPA described above.
- Cross-client learning: aggregated, anonymized learnings from experiment outcomes
may inform cross-client statistical models, as permitted by the terms. Never individual visitor
profiles, and never data that identifies your store or your customers to anyone else.
- Visitor consent: honored per region through the Shopify Customer Privacy API and
Global Privacy Control. The assignment cookie that keeps a visitor on the same page variant is a
functional, strictly-necessary cookie; behavioral collection is reduced or held wherever consent is
required and has not been given.
This page is a plain-language summary, not legal advice, and does not replace the
signed DPA or the Terms of Service.
← Back to luriart.com · Privacy · Terms