PRIVACY

Privacy Policy

Last updated: 25 July 2026

Luria provides an automated website conversion-optimization service. This policy covers luriart.com and the Luria service. It explains what we collect, why, where it lives, and how to get it deleted.

1. Two different roles

Which rules apply depends on whose data it is:

2. What we collect

From merchants and prospects (we control):

From visitors to merchant sites (we process):

We do not knowingly collect data from children, and we do not collect special-category data (health, biometrics, political opinions, and similar). Please do not send it to us.

3. What we do not do

4. Why we are allowed to use it

Where the UK/EU GDPR applies, our lawful bases are: contract (running your account and the service), legitimate interests (securing the service, preventing abuse, improving the product using aggregated data), and consent where consent is required for analytics or session recording on a merchant's site. You can withdraw consent at any time.

5. Where your data lives

ProcessorWhat it holdsWhere
VercelWebsite hosting, serverless functions, server logsUnited States
Supabase (Postgres + Storage)Accounts, sites, events, scan results, screenshotsUnited States
PostHogOptional session replay and heatmaps, with input masking on by defaultUnited States / EU
AnthropicPage content sent for analysis and copy generation. Not used to train their models.United States
CloudflareTurnstile bot check on public formsGlobal
ShopifyStore data you authorise via OAuthUnited States
ResendTransactional email (sign-in links, reports)United States

We are based in the United States, so data is transferred to and stored there. For transfers out of the UK/EEA we rely on Standard Contractual Clauses with our processors. We will keep this list current; material changes are announced to customers before they take effect.

6. How long we keep it

7. Your rights

Wherever you live, you may ask us to access, correct, delete, or export your personal information, and to object to or restrict how we use it. Under the UK/EU GDPR you may also complain to your data protection authority (in the UK, the ICO).

If you are in California: we do not sell or share your personal information as those terms are defined by the CPRA, and we will not discriminate against you for exercising any right. You may exercise your rights through an authorised agent.

To make a request, email privacy@luriart.com. We reply within 30 days and may need to verify your identity first.

If you are a merchant using Luria: you are the data controller for your visitors, and you can erase their data yourself at any time without contacting us. Sending DELETE /api/sites/<your-site-id>/data from your account, or asking us to run it for you, permanently removes every visitor-level record we hold for that site: events, conversions, variant assignments, sessions, visitor IDs, scans, reports, brand-brain data and integration records. It cannot be undone. Your site and experiment rows are kept so the history of what was changed on your website remains auditable; those contain no visitor personal data. We log that a deletion happened, and who asked for it, so both of us can evidence that the request was honoured.

8. Automated decision-making

Luria uses automated systems, including AI, to propose and apply changes to a merchant's website, and to allocate which page variant a visitor sees. These decisions affect page content only. They do not produce legal or similarly significant effects about any individual, and no pricing decision is made about a person based on their personal data.

9. Security

Data is encrypted in transit (HTTPS/TLS) and at rest by our processors. Access is restricted per merchant and enforced by row-level security in the database. Third-party access tokens are encrypted before storage. If a breach affects your personal data, we will notify you and the relevant regulator as required by law.

10. Global Privacy Control

Our snippet honours the Global Privacy Control signal and DNT: 1. When either is present it sets no visitor ID, emits no analytics events, and loads no session recording. The page still works normally.

11. Changes

If we change this policy we will update the date above, and tell customers directly when the change is material.

12. Contact

Questions, requests, or complaints: privacy@luriart.com.


This page describes our actual practices. It is not legal advice, and it is pending review by privacy counsel before the paid tier launches. โ† luriart.com ยท Terms of Service