Luria
DATA PROCESSING

Data Processing at Luria

Last updated: 2 October 2026

This page explains how Luria handles data when it runs on a merchant's store. It also explains how our Data Processing Addendum (DPA) works. It sits beside our Privacy Policy and Terms of Service.

1. Roles: you are the controller, we are the processor

When the Luria snippet runs on your store, the visitor data it collects is your data. You are the data controller. Luria is your data processor. We use visitor data only to run the service for you. That means showing page versions, counting events, and linking each sale to the version shown. We do this only on your instructions and under our DPA.

2. What the snippet collects and processes on your store

3. Subprocessors

We use a short, fixed list of service providers:

SubprocessorPurpose
CloudflareHosting the app, the database (D1: events, tests, and accounts, United States), scan machines that load your public pages during audits, transactional email, and R2 object storage for session recordings and page screenshots (global)
VercelForwards visits that still reach our old address to Cloudflare until it is shut down in October 2026; stores nothing (United States)
Moonshot AI (Kimi)AI reads your public page content, screenshots, and pseudonymous summaries of visitor journeys (pages and clicks, never form input) during scans and while it drafts page versions (China)
DeepSeekAI reads the same text, without images, for analysis and copy drafts (China)
Cloudflare, Vercel, Stripe, Calendly (your own accounts)Only when you connect them (off by default): your own Cloudflare or Vercel account runs the tracking script at the edge and passes the visitor's IP and country to us with each request; your Stripe sales and Calendly bookings come in with buyer emails stored only as a one-way hash

We will tell you before we add or swap any subprocessor that handles visitor data.

4. Consent, GPC, and regional rules

5. How long we keep data, and how to delete it

6. How we keep data safe

7. Getting a signed DPA

Every customer can get a DPA that is ready to sign. It uses standard processor terms and it includes the subprocessor list above. Ask for one at privacy@luriart.com and we will send it out for both sides to sign.

8. What the variant engine collects (v2026-08-14)

Some stores run the Luria variant engine. That means the Luria theme app embed plus the Luria web pixel. On those stores, the rules below apply as well as all the rules above:


This page is a plain summary, not legal advice. It does not replace the signed DPA or the Terms of Service.

← Back to luriart.com · Privacy · Terms