Luria
DATA PROCESSING

Data Processing at Luria

Last updated: 5 August 2026

This page summarises how Luria processes data when it runs on a merchant's store, and how our Data Processing Addendum (DPA) works. It complements our Privacy Policy and Terms of Service.

1. Roles: you are the controller, we are the processor

When the Luria snippet runs on your store, the visitor data it collects is your data. You are the data controller; Luria acts as your data processor and processes visitor data only to provide the service, variant delivery, event measurement, and conversion attribution, per your instructions and our DPA.

2. What the snippet processes on your store

3. Subprocessors

We use a small, fixed set of infrastructure providers:

SubprocessorPurpose
VercelApplication hosting and content delivery
SupabasePostgres database (events, experiments, accounts)
AnthropicAI analysis of publicly visible page content during scans and variant drafting
HetznerScan workers (rendering publicly reachable pages during audits)

We will notify customers before adding or replacing a subprocessor that handles visitor data.

4. Consent, GPC, and regional rules

5. Retention and deletion

6. Security posture

7. Getting a signed DPA

A signature-ready DPA (based on standard processor terms, including the subprocessor list above) is available to every customer, request one at privacy@luriart.com and we'll send it for counter-signature.

8. Variant engine data collection (v2026-08-14)

On stores running the Luria variant engine (the Luria theme app embed plus the Luria web pixel), the following applies in addition to everything above:


This page is a plain-language summary, not legal advice, and does not replace the signed DPA or the Terms of Service.

← Back to luriart.com · Privacy · Terms