Bundle sets, rewards and upsells for Shopify
Legal

Privacy policy

How Luxe Upsell & Bundle Engine handles merchant and shopper data. Written from what the app actually stores and processes.

DRAFT — NEEDS LEGAL REVIEW · Effective 4 October 2026

1. Our role

Luxe Upsell & Bundle Engine ("Luxe") is a Shopify app operated by DIGITALSTORE SOLUTIONS LTD, registered in England and Wales (company number 13960141). For store data, Luxe is a service provider (processor) to the merchant who installs it. The merchant is the controller of their customers' data and remains responsible for their own privacy notice.

2. What we collect

Store and merchant information

DataWhy
The store's myshopify.com domain, shop ID, name and currencyIdentify the store and price sets in its currency
An offline Admin API token and the granted scopesCall Shopify for the store. We do not request staff names or emails
Shopify plan name and development-store flagNever bill development stores
Plan, trial and billing period mirrored from ShopifyApply plan features and limits
Settings the merchant chooses, including AI consent and its dateRun the app as configured
A Talk to sales request: reply email, volume range, optional messageReply about Enterprise terms

The Luxe order ledger

To bill only orders Luxe built, Luxe reads the orders/paid, orders/cancelled and refunds/create webhooks and keeps the order ID and name, currency, dates, each line's IDs, quantity, amount and whether it counted, refunds, cancellations, disputes and the usage event sent to Shopify.

The ledger holds no customer names, emails, phone numbers, addresses, payment details or order notes. Webhook fields outside the list above are discarded and never logged. Luxe uses Shopify's default 60-day order access.

Storefront analytics

  • Consent first. Events are sent only when Shopify's Customer Privacy API reports the shopper allowed analytics. Without it nothing is sent and no Luxe identifier is created.
  • Pseudonymous. A random client ID kept in the browser, stored by Luxe only as a keyed hash unique to each store. A logged-in customer's ID is stored only as a keyed hash.
  • Not stored: IP addresses, user agents, raw client or customer IDs, names or contact details. IPs are used in memory for rate limiting.
  • Cart attribute. With consent, a _luxe_touch attribute with surface codes and timestamps travels with the order to show influenced revenue. It is never used for billing.

Luxe requests Shopify's protected customer data Level 1 only.

3. How we use it

  • To run the app: build and price sets, run rewards ladders and upsells, show analytics.
  • To bill: one usage event per Luxe order to Shopify, carrying the shop, meter, time, key and value, and no personal data.
  • To support merchants and keep Luxe secure.

We do not sell personal information, share it for cross-context advertising, or make automated decisions with legal effects.

4. Luxe AI

Luxe AI is off until the merchant turns it on in Settings > AI, which records the date, and the merchant chooses what it may use. Turning it off stops all AI processing.

  • Processor: Anthropic, PBC, called from Luxe's servers. No storefront code or checkout function calls a model.
  • Sent: product titles, types, vendors, tags, descriptions, prices, availability, filter definitions and at most one product image per item; store-level counts and brand voice only if allowed.
  • Shopper requests for Complete my set: at most 120 characters, scrubbed of emails and long digit runs, never stored.
  • Never sent: customer names, emails, phones, addresses or IDs, order IDs or names, or the store domain.
  • No training. Inference only, under commercial terms that do not permit training on inputs or outputs.
  • Your own provider. A Pro or Enterprise merchant may connect their own AI provider. That provider is the merchant's processor under the merchant's account, not Luxe's subprocessor.
  • Retention: AI job inputs and results for 90 days, then usage totals only.

5. Subprocessors

We share data only with the providers needed to run Luxe. The current list, with purpose and location, is on the Subprocessors page.

6. Retention and deletion

DataKept
Storefront analytics eventsUp to 365 days
Webhook delivery records30 days
AI job inputs and results90 days, then usage totals
Customer data request exports90 days
Order ledger and billing recordsWhile installed, then deleted with the rest of the store's data
Everything for an uninstalled storeDeleted on shop redaction, 48 hours after uninstall, or within 30 days if that never arrives

Shopify privacy webhooks

  • customers/data_request: Luxe prepares an export of ledger rows and pseudonymous events for the merchant to download and send.
  • customers/redact: Luxe deletes events linked to the customer's hashed ID and rotates the store's hashing salt.
  • shop/redact: Luxe deletes everything it holds for the store.

7. Security

TLS in transit and encryption at rest by the hosting and database providers. Webhooks and app proxy requests are verified with Shopify's HMAC signatures. Secrets live in the host's secret store. Access to production data is limited to the founder and any staff who need access to provide support.

8. International transfers

Luxe is operated by DIGITALSTORE SOLUTIONS LTD, a company registered in England and Wales. Subprocessors may process data in the United States. Where the law requires a safeguard for such a transfer, we rely on one it recognises, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum.

9. Your rights

Merchants can export their billing audit, change or delete configuration, turn AI off, and request access, correction or deletion at privacy@luxesets.com. Shoppers should contact the merchant; their request reaches Luxe through Shopify's privacy webhooks. You may complain to your supervisory authority.

10. Changes and contact

We post changes here and notify installed merchants by email before material changes take effect. Contact: DIGITALSTORE SOLUTIONS LTD, privacy@luxesets.com.