Bundle sets, rewards and upsells for Shopify
Legal

Data processing addendum

For merchants who need processor terms under the GDPR, UK GDPR or similar laws.

DRAFT — NEEDS LEGAL REVIEW · Effective 4 October 2026

1. Roles

The merchant is the controller; Luxe is the processor of personal data in store data it handles. A provider the merchant connects for Luxe AI is the merchant's own processor.

2. Subject matter and duration

Subject matter and duration
Subject matterProviding the Luxe app to the merchant
DurationWhile the app is installed, then until deletion as in section 7
Data subjectsThe merchant's shoppers and customers; merchant contacts
CategoriesPseudonymous identifiers (keyed hashes), order and line IDs, amounts, storefront events, short shopper requests to Complete my set (not stored), a contact email for sales requests
Special categoriesNone intended

3. Instructions

Luxe processes personal data only on the merchant's documented instructions, given through the app's settings and these terms, and tells the merchant if an instruction appears unlawful.

4. Confidentiality

People authorised to process the data are bound by confidentiality.

5. Security measures

  • Encryption in transit (TLS) and at rest (the database provider's storage encryption)
  • HMAC verification of every Shopify webhook and app proxy request
  • Keyed hashing of client and customer IDs, with a salt per store, rotated on customers/redact
  • Data minimisation: Level 1 protected customer data only; webhook payloads discarded beyond validated fields and never logged
  • Secrets in the host's secret store; production access limited to the founder and any staff who need access to provide support

6. Subprocessors

The merchant authorises the subprocessors on the Subprocessors page. Luxe updates that page and emails merchants before adding a subprocessor, and the merchant may object to the change before it applies.

7. Assistance and deletion

Luxe assists with data subject requests through Shopify's privacy webhooks (data request, redact) and deletes all store data on shop redaction, 48 hours after uninstall, or within 30 days if that request never arrives.

8. Personal data breaches

Luxe notifies the merchant without undue delay and within 72 hours of becoming aware of a breach affecting their data.

9. Audits

Luxe makes available to the merchant the information needed to demonstrate compliance with this addendum, and allows for and contributes to audits, including inspections, by the merchant or an auditor the merchant mandates, as Article 28(3)(h) of the UK GDPR and the EU GDPR requires.

10. International transfers

Luxe's subprocessors process data in the United States. Where personal data is transferred from the UK or the EEA to a country without an adequacy decision, Luxe relies on a transfer mechanism recognised by data protection law, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum.