This Privacy Policy explains how Lucyd Media (“Lucyd,” “we,” “us”) handles data in connection with the Lucyd Analytics application (the “App”) when it is installed on a Shopify store.
Lucyd Analytics is a read-only reporting tool. It connects to a merchant’s Shopify store, produces a daily summary of sales — including a breakdown of new versus returning customers — and delivers that summary to a Google Sheet managed on the merchant’s behalf. The App does not modify the store, its theme, its checkout, or any customer records.
For data originating from a merchant’s store and its customers, the merchant is the data controller and Lucyd acts as a data processor, processing that data solely to provide the reporting service described here and under our agreement with the merchant.
Information the App accesses
To produce sales reports, the App reads the following from the connected Shopify store through the Shopify Admin API:
- Order data — order totals, dates, currency, and order/refund status, used to summarize daily sales and net revenue.
- Customer identifiers and order counts — a customer’s Shopify customer ID and the number of orders associated with it, used solely to classify each sale as coming from a new or returning customer.
The App is requested at the minimum scopes required for this purpose (read_orders, read_customers). The App does not collect, store, or transmit personal customer details such as names, email addresses, phone numbers, billing or shipping addresses, or payment information.
How the information is used
Accessed data is used only to:
- compile a daily summary of orders and net revenue for the merchant; and
- classify daily sales as new-customer or returning-customer revenue, consistent with Shopify’s own analytics definitions.
We do not use store or customer data for advertising, profiling of individuals, resale, or any purpose other than delivering the reporting service to the merchant. We do not sell data.
Where data is processed and stored
The App runs on Google Cloud Platform. In the course of generating reports:
- Aggregate daily reports are written to a Google Sheet controlled by the merchant (or by the merchant’s account manager at Lucyd) for the merchant’s own reporting use.
- A short-lived classification cache may temporarily retain Shopify customer IDs and associated order counts to determine new-versus-returning status efficiently. This cache expires automatically (within approximately seven days) and contains no customer names, contact details, or addresses.
- Access credentials (the offline access token issued by Shopify at installation) are stored encrypted in Google Secret Manager and are used only to make authorized API requests to the connected store.
We use the following sub-processors to operate the service: Google Cloud Platform (hosting, storage, and secret management) and DataStax Astra DB (processing and short-term caching). These providers process data only as needed to support the App.
Data retention and deletion
- The classification cache expires automatically and is not retained long-term.
- Daily report rows delivered to a merchant’s Google Sheet are controlled by the merchant; retention of that sheet is at the merchant’s discretion.
- When a merchant uninstalls the App, or upon a shop-redaction request from Shopify, we cease processing for that store and delete the store’s associated cached data and stored credentials.
Shopify compliance webhooks
The App implements Shopify’s mandatory privacy webhooks and responds to them as follows:
- Customer data request (
customers/data_request): because the App does not store customer personal information, we have no customer profile data to return; we coordinate with the merchant to address the request. - Customer redaction (
customers/redact): any cached identifier associated with the specified customer is removed. - Shop redaction (
shop/redact): all cached data and stored credentials for the specified shop are deleted.
Security
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access credentials are held in a dedicated secret store, scoped to a single store each, and used only for authorized requests. We follow the principle of least privilege and request only the access the App needs to function.
Customer and merchant rights
Because Lucyd acts as a processor on the merchant’s behalf, individuals who wish to exercise rights over their personal data (such as access or deletion under the GDPR, Swiss FADP, or similar laws) should contact the merchant operating the store, who is the controller of that data. We will assist the merchant in responding to such requests, including via the redaction webhooks described above.
International transfers
The App is operated from infrastructure that may process data in the United States, or other regions where our sub-processors operate. Where required, such transfers are carried out under appropriate safeguards.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above.