Trust
Security and data use.
How Luxe protects store data, written from how the app works.

| Area | What Luxe does |
|---|---|
| Data minimised | Protected customer data Level 1 only; no names, emails, phones or addresses stored |
| Verification | Every webhook and app proxy request verified with Shopify's HMAC signature |
| Pseudonymous analytics | Consent first; IDs stored only as keyed hashes, salt per store |
| Transport | HTTPS with Strict-Transport-Security; nosniff on every response |
| Logs | Request logs never keep query strings or webhook bodies |
| Secrets | Held in the host's secret store; AI provider keys encrypted |
| Encryption at rest | The database is encrypted at rest by the database provider (Neon) |
| Deletion | All store data deleted on shop redaction, or within 30 days of uninstall |
| AI | Off until enabled; never trained on your data |
| Disclosure | Report a vulnerability to security@luxesets.com |
See the Privacy policy, DPA and Subprocessors.