1. Roles
The merchant is the controller; Luxe is the processor of personal data in store data it handles. A provider the merchant connects for Luxe AI is the merchant's own processor.
2. Subject matter and duration
| Subject matter | Providing the Luxe app to the merchant |
| Duration | While the app is installed, then until deletion as in section 7 |
| Data subjects | The merchant's shoppers and customers; merchant contacts |
| Categories | Pseudonymous identifiers (keyed hashes), order and line IDs, amounts, storefront events, short shopper requests to Complete my set (not stored), a contact email for sales requests |
| Special categories | None intended |
3. Instructions
Luxe processes personal data only on the merchant's documented instructions, given through the app's settings and these terms, and tells the merchant if an instruction appears unlawful.
4. Confidentiality
People authorised to process the data are bound by confidentiality.
5. Security measures
- Encryption in transit (TLS) and at rest (the database provider's storage encryption)
- HMAC verification of every Shopify webhook and app proxy request
- Keyed hashing of client and customer IDs, with a salt per store, rotated on customers/redact
- Data minimisation: Level 1 protected customer data only; webhook payloads discarded beyond validated fields and never logged
- Secrets in the host's secret store; production access limited to the founder and any staff who need access to provide support
6. Subprocessors
The merchant authorises the subprocessors on the Subprocessors page. Luxe updates that page and emails merchants before adding a subprocessor, and the merchant may object to the change before it applies.
7. Assistance and deletion
Luxe assists with data subject requests through Shopify's privacy webhooks (data request, redact) and deletes all store data on shop redaction, 48 hours after uninstall, or within 30 days if that request never arrives.
8. Personal data breaches
Luxe notifies the merchant without undue delay and within 72 hours of becoming aware of a breach affecting their data.
9. Audits
Luxe makes available to the merchant the information needed to demonstrate compliance with this addendum, and allows for and contributes to audits, including inspections, by the merchant or an auditor the merchant mandates, as Article 28(3)(h) of the UK GDPR and the EU GDPR requires.
10. International transfers
Luxe's subprocessors process data in the United States. Where personal data is transferred from the UK or the EEA to a country without an adequacy decision, Luxe relies on a transfer mechanism recognised by data protection law, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum.