# Data and privacy Source: https://docs.luriart.com/reference/data-and-privacy Plain text: https://docs.luriart.com/reference/data-and-privacy.txt What Luria collects on your site, what it never collects, where data lives, how long it is kept, who can see it, and your rights. Luria runs on your visitors' behalf, so it is worth knowing exactly what it touches. This page is the plain-language version. The legal version is Luria's privacy policy at [luriart.com/privacy](https://www.luriart.com/privacy). ## Your role and ours You own your visitors' data. Luria processes it on your instructions, under a Data Processing Addendum you accept when you install. In privacy-law terms: you are the controller, Luria is the processor. That means Luria does not reuse your visitors' data for anything except running your site's optimisation and the aggregate learning described below. ## What Luria collects From visitors to your site: | Collected | Why | | ------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------- | | A random first-party visitor id, stored in your domain | So the same visitor sees the same version of a page and results can be measured. No fingerprinting. | | Page views, clicks on buttons and links, scroll depth, form starts | To see what visitors do before and after a change. | | Which version of a page was shown | To measure lift. | | Conversions (goal, value) | To know what worked. | | Coarse context: device type, referrer, UTM parameters, country or region | To segment results. Never precise location. | On Shopify, additionally through the app you authorise: orders (for attribution and revenue), products and collections (so Luria can write accurate copy), and your store's name, currency, and plan. Luria never sees your customers' card details; Shopify never shares those. From you, the merchant: your email, store URL, onboarding answers, brand inputs you give the Brand Brain, and billing details held by the payment processor (Luria never stores full card numbers). ## What Luria never collects * Card numbers or any payment field. * Passwords. * Typed form values. Luria records that a form was started, not what was entered. * Health, biometric, or other special-category data. * Cross-site identity. Luria does not recognise a visitor from one merchant's site on another's. Where session recordings are enabled, all inputs are masked by default and text on checkout and account pages is masked. ## Where data lives Luria is hosted in the United States on Supabase (database and storage) and Vercel (hosting and serverless). Sub-processors, and transfer safeguards for UK and EEA data, are listed in the privacy policy. Luria is a US company, so data is stored in the US. ## How long it is kept | Data | Retention | | ------------------------------------------------- | ------------------------------------------------------------------------------------------------------ | | Raw visitor events (pageviews, clicks, exposures) | About 90 days, then deleted automatically. | | Aggregate results (test outcomes, lift, winners) | Kept for the life of your account so your history stays readable. | | Your account records | While your account is active, then up to 24 months unless you ask for earlier deletion. | ## Who can see it * You and anyone you invite to your account. See [Team access](/dashboard/team-access). * Luria staff, only to support you or keep the service running, and never to browse. * Nobody else. Luria does not sell data and does not share it for advertising. ## How Luria learns across merchants Luria gets better over time partly because it sees what works across many stores. This uses only anonymised, aggregate patterns: for example, "benefit-led headlines beat feature-led ones in this category." It never involves your customers' identities, your order data, or your copy reproduced verbatim for another merchant. Your Brand Brain and your winning pages are yours. ## Your rights * **Export.** Download your results from the dashboard. For a full export of account data, email [privacy@luriart.com](mailto:privacy@luriart.com). * **Delete.** You can erase every visitor-level record Luria holds for your site at any time, from your account or by asking support. This is permanent. Your test history (what changed, when) is kept so your dashboard stays auditable; it contains no visitor personal data. * **DPA.** A Data Processing Addendum is included in Luria's terms and available on request for your records. * **Visitor requests.** If one of your visitors asks you to delete their data, forward the request to [privacy@luriart.com](mailto:privacy@luriart.com) with your Site ID and Luria will action it. On Shopify, Luria also handles Shopify's customer data request and redact webhooks automatically. See [Security](/reference/security). ## Next steps - [Consent](/reference/consent) - [Security](/reference/security) - [Uninstall Luria](/reference/uninstall)