LuscaLusca

Last updated: 2026-07-19

Privacy Policy

Overview

Lusca helps merchants connect authorized commerce and marketing accounts to an AI workspace. The service is designed to read live context only when an authorized user asks for an analysis, starts an audit or approves a specific workflow.

Data Lusca collects

Lusca stores account information for authorized users, organization and store records, OAuth connection metadata, encrypted OAuth tokens, granted permissions, approval history and operational logs needed to run the service securely.

For Shopify, Lusca stores the shop domain, shop identity and access token after authorization. Product, inventory and order data is read from Shopify when a user requests an analysis or launches an audit. Lusca does not run a full product or order sync by default at installation time.

For identity sign-in providers such as Google, Apple or GitHub, Lusca stores the verified email address, display name when provided and stable provider account identifier so the user can create an account and sign back in without a password.

For connected Google services, Lusca stores encrypted OAuth refresh tokens, connection metadata and the selected external account or property ID. Google Ads data can include campaigns, budgets, status and performance metrics. Merchant Center data can include product feed items, approval status, availability, prices, links and product issues. Free Listings eligibility, impression and click reports are queried live when requested and are not persisted by this tool. Search Console data can include site properties, queries, pages, clicks, impressions, CTR and average position. Google Analytics data can include GA4 account/property metadata and aggregated traffic, engagement and conversion metrics.

How data is used

Connected account data is used to answer user requests, summarize store health, prepare audits, generate reports and propose approval-gated actions. Lusca does not sell personal data and does not use connected account data for unrelated advertising.

When a user connects Lusca to ChatGPT or another AI client, Lusca may return requested store context to that user-controlled AI conversation so the user can compare, reason and decide what to do next.

Actions that could change a store, catalog, inventory, product feed or campaign require explicit human approval before execution.

Google Ads, Merchant Center, Search Console and Google Analytics data is used only for the store/workspace selected by the user, such as comparing ad performance with catalog and feed health, identifying product issues, understanding organic search demand and reviewing traffic quality.

Customer and order data

Lusca requests order access so merchants can analyze recent commercial performance, stock pressure and catalog opportunities. The app is designed to use the minimum order fields required for these analyses and does not request customer names, addresses, phone numbers or emails for the current Shopify analytics flow.

If a Shopify customer data request, customer erasure request or shop erasure request is received, Lusca processes the compliance webhook and removes or confirms the relevant stored connection data according to the request type.

Storage, retention and deletion

OAuth tokens are stored encrypted or through the configured runtime secret storage. Cached audit snapshots, approval records and operational logs are retained only as needed to provide the service, support security, debug errors and maintain an approval trail.

Users can disconnect a provider from Lusca or request deletion of their Lusca account data. Disconnecting a Google provider removes the Lusca-side connection and encrypted token material for that provider. When a Shopify shop is redacted, Lusca deletes the stored Shopify connection and token material for that shop.

Security and data protection

Lusca uses security procedures designed to protect the confidentiality of Google user data and other sensitive connected account data. Google OAuth tokens are encrypted at rest or stored through the configured runtime secret storage, and traffic to Lusca public pages and APIs is protected in transit with HTTPS/TLS.

Access to Google data is limited to the authorized Lusca service components needed to provide the selected workspace and store features. Lusca applies least-privilege handling for connected providers, avoids intentionally logging OAuth tokens or client secrets, and stores operational logs only for service reliability, security review, debugging and approval records.

Google user data is not sold, is not used for unrelated advertising, and is not used to train general-purpose AI or machine-learning models. When a user disconnects a Google provider or requests deletion, Lusca removes the Lusca-side connection and encrypted token material for that provider.

Sharing, transfer and disclosure of Google user data

Lusca shares, transfers or discloses Google user data only when necessary to provide user-facing features that the user requests or approves. Google user data may be processed by Scalingo, Lusca's hosting and managed PostgreSQL infrastructure provider, solely to host, store and operate the service on Lusca's behalf.

When a user explicitly invokes Lusca from ChatGPT or another user-selected AI client, Lusca may return only the Google account data needed to answer that request to the user's own conversation. Lusca does not send Google OAuth tokens, refresh tokens, client secrets or unrelated connected-account data to AI clients.

Lusca may send data back to Google services or to another user-selected connected platform, such as Shopify, only as needed to perform a feature or an action the user has explicitly requested and, for changes, approved. Lusca may also disclose data when required by law or to protect the service and its users.

Lusca does not otherwise share, transfer or disclose Google user data to third parties. It does not sell Google user data or disclose it to advertising platforms, data brokers or information resellers. Service providers process data only on Lusca's instructions for the purposes described in this policy and are subject to confidentiality and security obligations.

Contact

For privacy questions, data access requests or deletion requests, contact support@getlusca.com.