Last updated: 25 July 2026
Luria provides an automated website conversion-optimization service. This policy covers luriart.com and the Luria service. It explains what we collect, why, where it lives, and how to get it deleted.
Which rules apply depends on whose data it is:
From merchants and prospects (we control):
luria_session) once you sign in. It is strictly necessary,
HttpOnly, Secure, and SameSite=Lax. We do not use advertising or cross-site tracking cookies on
luriart.com.From visitors to merchant sites (we process):
We do not knowingly collect data from children, and we do not collect special-category data (health, biometrics, political opinions, and similar). Please do not send it to us.
Where the UK/EU GDPR applies, our lawful bases are: contract (running your account and the service), legitimate interests (securing the service, preventing abuse, improving the product using aggregated data), and consent where consent is required for analytics or session recording on a merchant's site. You can withdraw consent at any time.
| Processor | What it holds | Where |
|---|---|---|
| Vercel | Website hosting, serverless functions, server logs | United States |
| Supabase (Postgres + Storage) | Accounts, sites, events, scan results, screenshots | United States |
| PostHog | Optional session replay and heatmaps, with input masking on by default | United States / EU |
| Anthropic | Page content sent for analysis and copy generation. Not used to train their models. | United States |
| Cloudflare | Turnstile bot check on public forms | Global |
| Shopify | Store data you authorise via OAuth | United States |
| Resend | Transactional email (sign-in links, reports) | United States |
We are based in the United States, so data is transferred to and stored there. For transfers out of the UK/EEA we rely on Standard Contractual Clauses with our processors. We will keep this list current; material changes are announced to customers before they take effect.
Wherever you live, you may ask us to access, correct, delete, or export your personal information, and to object to or restrict how we use it. Under the UK/EU GDPR you may also complain to your data protection authority (in the UK, the ICO).
If you are in California: we do not sell or share your personal information as those terms are defined by the CPRA, and we will not discriminate against you for exercising any right. You may exercise your rights through an authorised agent.
To make a request, email privacy@luriart.com. We reply within 30 days and may need to verify your identity first.
If you are a merchant using Luria: you are the data controller for your visitors,
and you can erase their data yourself at any time without contacting us. Sending
DELETE /api/sites/<your-site-id>/data from your account, or asking us to run it for
you, permanently removes every visitor-level record we hold for that site: events, conversions,
variant assignments, sessions, visitor IDs, scans, reports, brand-brain data and integration
records. It cannot be undone. Your site and experiment rows are kept so the history of what was
changed on your website remains auditable; those contain no visitor personal data. We log that a
deletion happened, and who asked for it, so both of us can evidence that the request was honoured.
Luria uses automated systems, including AI, to propose and apply changes to a merchant's website, and to allocate which page variant a visitor sees. These decisions affect page content only. They do not produce legal or similarly significant effects about any individual, and no pricing decision is made about a person based on their personal data.
Data is encrypted in transit (HTTPS/TLS) and at rest by our processors. Access is restricted per merchant and enforced by row-level security in the database. Third-party access tokens are encrypted before storage. If a breach affects your personal data, we will notify you and the relevant regulator as required by law.
Our snippet honours the Global Privacy Control signal and DNT: 1. When
either is present it sets no visitor ID, emits no analytics events, and loads no session recording.
The page still works normally.
If we change this policy we will update the date above, and tell customers directly when the change is material.
Questions, requests, or complaints: privacy@luriart.com.
This page describes our actual practices. It is not legal advice, and it is pending review by privacy counsel before the paid tier launches. โ luriart.com ยท Terms of Service