1. Our role
Luxe Upsell & Bundle Engine ("Luxe") is a Shopify app operated by DIGITALSTORE SOLUTIONS LTD, registered in England and Wales (company number 13960141). For store data, Luxe is a service provider (processor) to the merchant who installs it. The merchant is the controller of their customers' data and remains responsible for their own privacy notice.
2. What we collect
Store and merchant information
| Data | Why |
|---|---|
| The store's myshopify.com domain, shop ID, name and currency | Identify the store and price sets in its currency |
| An offline Admin API token and the granted scopes | Call Shopify for the store. We do not request staff names or emails |
| Shopify plan name and development-store flag | Never bill development stores |
| Plan, trial and billing period mirrored from Shopify | Apply plan features and limits |
| Settings the merchant chooses, including AI consent and its date | Run the app as configured |
| A Talk to sales request: reply email, volume range, optional message | Reply about Enterprise terms |
The Luxe order ledger
To bill only orders Luxe built, Luxe reads the orders/paid, orders/cancelled and refunds/create webhooks and keeps the order ID and name, currency, dates, each line's IDs, quantity, amount and whether it counted, refunds, cancellations, disputes and the usage event sent to Shopify.
The ledger holds no customer names, emails, phone numbers, addresses, payment details or order notes. Webhook fields outside the list above are discarded and never logged. Luxe uses Shopify's default 60-day order access.
Storefront analytics
- Consent first. Events are sent only when Shopify's Customer Privacy API reports the shopper allowed analytics. Without it nothing is sent and no Luxe identifier is created.
- Pseudonymous. A random client ID kept in the browser, stored by Luxe only as a keyed hash unique to each store. A logged-in customer's ID is stored only as a keyed hash.
- Not stored: IP addresses, user agents, raw client or customer IDs, names or contact details. IPs are used in memory for rate limiting.
- Cart attribute. With consent, a
_luxe_touchattribute with surface codes and timestamps travels with the order to show influenced revenue. It is never used for billing.
Luxe requests Shopify's protected customer data Level 1 only.
3. How we use it
- To run the app: build and price sets, run rewards ladders and upsells, show analytics.
- To bill: one usage event per Luxe order to Shopify, carrying the shop, meter, time, key and value, and no personal data.
- To support merchants and keep Luxe secure.
We do not sell personal information, share it for cross-context advertising, or make automated decisions with legal effects.
4. Luxe AI
Luxe AI is off until the merchant turns it on in Settings > AI, which records the date, and the merchant chooses what it may use. Turning it off stops all AI processing.
- Processor: Anthropic, PBC, called from Luxe's servers. No storefront code or checkout function calls a model.
- Sent: product titles, types, vendors, tags, descriptions, prices, availability, filter definitions and at most one product image per item; store-level counts and brand voice only if allowed.
- Shopper requests for Complete my set: at most 120 characters, scrubbed of emails and long digit runs, never stored.
- Never sent: customer names, emails, phones, addresses or IDs, order IDs or names, or the store domain.
- No training. Inference only, under commercial terms that do not permit training on inputs or outputs.
- Your own provider. A Pro or Enterprise merchant may connect their own AI provider. That provider is the merchant's processor under the merchant's account, not Luxe's subprocessor.
- Retention: AI job inputs and results for 90 days, then usage totals only.
5. Subprocessors
We share data only with the providers needed to run Luxe. The current list, with purpose and location, is on the Subprocessors page.
6. Retention and deletion
| Data | Kept |
|---|---|
| Storefront analytics events | Up to 365 days |
| Webhook delivery records | 30 days |
| AI job inputs and results | 90 days, then usage totals |
| Customer data request exports | 90 days |
| Order ledger and billing records | While installed, then deleted with the rest of the store's data |
| Everything for an uninstalled store | Deleted on shop redaction, 48 hours after uninstall, or within 30 days if that never arrives |
Shopify privacy webhooks
- customers/data_request: Luxe prepares an export of ledger rows and pseudonymous events for the merchant to download and send.
- customers/redact: Luxe deletes events linked to the customer's hashed ID and rotates the store's hashing salt.
- shop/redact: Luxe deletes everything it holds for the store.
7. Security
TLS in transit and encryption at rest by the hosting and database providers. Webhooks and app proxy requests are verified with Shopify's HMAC signatures. Secrets live in the host's secret store. Access to production data is limited to the founder and any staff who need access to provide support.
8. International transfers
Luxe is operated by DIGITALSTORE SOLUTIONS LTD, a company registered in England and Wales. Subprocessors may process data in the United States. Where the law requires a safeguard for such a transfer, we rely on one it recognises, such as the European Commission's Standard Contractual Clauses or the UK International Data Transfer Addendum.
9. Your rights
Merchants can export their billing audit, change or delete configuration, turn AI off, and request access, correction or deletion at privacy@luxesets.com. Shoppers should contact the merchant; their request reaches Luxe through Shopify's privacy webhooks. You may complain to your supervisory authority.
10. Changes and contact
We post changes here and notify installed merchants by email before material changes take effect. Contact: DIGITALSTORE SOLUTIONS LTD, privacy@luxesets.com.