LuscaLusca

Version v2.4.0 · Effective 2026-08-19 · Updated 2026-08-19

Privacy Policy

The French version governs. This English translation is provided for convenience and remains materially equivalent.

1. Controller and contact

Lusca is operated by Yanis FAHEM, entrepreneur individuel, Tour Ariane, 5 Place de la Pyramide, 92800 Puteaux – La Défense, France, SIREN 920 580 404. The operator is controller for its account, security and service-administration processing. Publication director: Yanis FAHEM.

Privacy and rights contact: support@getlusca.com. Professional telephone: +33 7 83 88 19 47.

2. Service scope

Lusca is an experimental public beta for adult professional users acting for a merchant or organization. It connects an authorized workspace to Shopify, Google Ads, Merchant Center, Search Console and Google Analytics 4 and returns diagnostics, reports and supported analyses through the web interface or an authorized AI client.

New public accounts may use a supported identity provider that supplies a stable subject and verified email, or email/password with Lusca verification. Google, GitHub and Apple are supported when configured; the current public signup screen exposes Google and GitHub. Email/password signup creates only a non-operational pending account, organization and membership. Lusca sends a short-lived verification link through its dedicated Brevo transactional sender; Brevo transports the message, but only Lusca validates the one-time token and activates the account. No operational session or workspace access exists before confirmation. The current beta permits one workspace per organization.

Supported reads cover Shopify store identity, catalog, products, variants, price, status, inventory and, when Shopify grants order access during installation, order-derived sales for the last 60 days; Google Ads account configuration, campaigns, budgets, status, PMax diagnostics and performance; Merchant offers, availability, destinations, approval state, issues and Free Listings evidence; Search Console queries, pages and daily performance; and aggregated GA4 performance.

Lusca also supports six narrow provider changes only through the protected human-card process described below. It creates its own account, authentication, encrypted-token, cache, consent, review and audit records where needed to provide and secure the service.

3. Data processed

  • Account and access: email; final name and organization required when confirming a password account (or provider profile details for an identity-provider account); password hash, email-verification state and time, stable identity-provider identifier and verified-email signal, role, membership, session and security state. Historical accounts are not silently marked verified.
  • Acceptance evidence: Terms v2.4.0 and Privacy v2.4.0, server timestamp, method, language and account reference; this acceptance record does not include an IP address or user-agent.
  • Workspace and connections: store/workspace identity, domains, currency, time zone, provider, selected account or property, granted scopes, status, encrypted OAuth credentials and bounded OAuth state.
  • Shopify: catalog, products, variants, price, status, availability and inventory. Orders are limited to the preceding 60 days and to identifiers, dates, financial status, totals, currency and line data required for supported aggregates. Customer profiles and Protected Customer Data level-2 fields are not requested or intentionally stored; no order table is maintained.
  • Google: the Ads, Merchant Center, Search Console and GA4 configuration and metrics listed in section 2. Provider responses are generally handled in memory; Merchant and Shopify caches hold the documented product data needed for their features.
  • Protected actions: exact workspace/provider context, resource, current and target values, limits, state, capability hashes, decision, attempt count limited to zero or one, result and append-only events. Provider credentials, raw private capabilities, IP addresses and user-agents are excluded from action events.
  • ChatGPT analysis activation: user, tenant, client/resource/scopes, exact workspace, the closed Shopify, Google Ads, Merchant Center, Search Console and GA4 provider set, covered data categories, purpose, ChatGPT/OpenAI recipient, versioned retention and recipient policy, language, activation and withdrawal time. No raw provider account identifier is part of this policy receipt. Lusca does not read or change the user’s ChatGPT Data Controls, Memory and sync settings.
  • Email verification and recovery: purpose, language, creation, expiry and consumption state, legal-version binding, delivery outcome and only a cryptographic hash of each random one-time token. Verification and password-reset tokens are distinct. Raw tokens and links are excluded from Lusca metrics and audit records.
  • Operations and support: bounded synchronization, error, abuse-prevention and security records, including durable counters keyed by privacy-safe HMAC references derived from the email and request address; sender address and information voluntarily supplied to the support mailbox. These pseudonymous references are not anonymous. Strictly necessary session, CSRF and OAuth cookies/state are used; no advertising cookie is used by the public beta.

4. Sources, permissions and Shopify order access

Data comes from the user, authorized workspace members, the chosen identity provider and the commerce or Google accounts explicitly connected. Connections are optional; disconnecting one makes its related capabilities unavailable or incomplete.

Shopify requests exactly read_orders, write_products and write_inventory for this release; the write scopes include the corresponding product and inventory reads. It excludes read_all_orders, write_orders and customer level-2 fields.

Installing Lusca and granting read_orders authorizes Lusca technically to read orders for that exact verified store. Access fails closed if the app is uninstalled, the scope is missing or revoked, or the store and connection identity is not proven. A legacy connection without that complete proof must reconnect once through Shopify’s official flow. Reads are limited to 60 days, minimized to the fields listed above, handled in memory and protected by encryption in transit and at rest; Lusca requests no level-2 customer fields, maintains no order table and performs no automatic provider write.

This Shopify permission records the merchant’s technical authorization for the requested service. It does not replace any data-processing agreement or other data-protection obligation that may apply when Lusca acts as a processor on the merchant’s documented instructions.

5. Purposes and legal bases

Account, workspace and connected-account data is used to create and secure the account, verify control of an email address, recover access, provide requested features, connect selected providers and return requested results under the Terms. A pending email/password signup and a limited user-requested pre-install Shopify step rely on steps requested before contract formation.

Security, abuse prevention, service integrity and narrowly scoped operational records rely on Lusca’s legitimate interests, balanced against user rights. Legal records and rights handling are processed for applicable legal obligations. Support relies on the Terms, legal obligations or legitimate interests according to the request.

The separate delivery of merchant and Google results to ChatGPT follows the affirmative, workspace-specific and revocable service-activation instruction described in section 6. Lusca does not sell personal data, conduct marketing profiling or use connected data for unrelated advertising.

6. Separate ChatGPT analysis activation

Connecting a provider or accepting the Terms does not activate delivery of its results to ChatGPT. In the ChatGPT onboarding path, workspace creation requires a separate, initially unchecked, affirmative and versioned service activation. It is one instruction for the closed policy scope, not an optional provider-by-provider consent matrix.

The receipt binds the user, tenant, client/resource/scopes and exact workspace to Shopify, Google Ads, Merchant Center, Search Console and GA4, the published categories, visible purpose, ChatGPT/OpenAI recipient and versioned retention/recipient policy. A workspace may be activated while empty. Connecting one of those five covered providers later does not require activation again and does not invalidate the ChatGPT connection.

The activation notice is shown before the first transfer. Users should review their ChatGPT Data Controls and Personalization settings before activating. Lusca sends only the minimized results requested for the visible feature and never sends OAuth tokens, passwords, client secrets, private card capabilities or data from another workspace.

Revalidation is required only when policy scope changes through a new provider, data category, purpose, recipient or retention policy. Withdrawal blocks future transmission for the exact client/workspace/resource/scope context and revokes its active Lusca refresh-token families. It does not erase content already retained in ChatGPT; the user manages that content through ChatGPT.

This activation never authorizes a provider write. Every supported write remains subject to the separate protected card, a fresh human click and at most one provider attempt.

OAuth tokens, passwords, client secrets, private card capabilities and unrelated workspace data are never part of the AI result. The professional user must have authority to disclose the selected merchant/provider data.

7. Google API data and Limited Use

Lusca accesses Google data only for user-facing features requested by an authorized user. Merchant Center, Search Console and GA4 remain read-only. The Google Ads adwords scope is not intrinsically read-only, but Lusca restricts writes to the three protected Ads actions, the exact store-linked Google Ads customer account and a fresh human card decision; there is no global merchant-action fallback.

A Google Ads production write also fails closed unless a current assessment binds the exact customer to an eligible developer-token access level, ad-creation/management permissible use and the applicable Required Minimum Functionality status. Possession of a developer-token string alone never opens a write.

Lusca’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is not sold, used for unrelated advertising or disclosed to data brokers. A Google-derived result is sent to ChatGPT only for the user-facing feature requested by the user and after the separate disclosure in section 6. Once sent, ChatGPT handles that result under the user’s ChatGPT account settings and applicable OpenAI terms.

8. Protected provider actions

Shopify actions are limited to one variant price, one exact available quantity at one explicitly selected location, or one product status. Google Ads actions are limited to one campaign status, one daily budget, or one asset-group status. Merchant Center, Search Console and GA4 have no Lusca write operation.

For this pilot, Shopify price and Google Ads daily-budget changes are available only when the provider-live currency is EUR. Lusca performs no currency conversion; inventory and status actions do not reinterpret a monetary currency.

Each review covers one action and lasts 15 minutes. Lusca resolves the workspace and provider account server-side, reads the live current state and displays current-to-target details. Only an authenticated active owner/admin can approve or reject through the card controls. Chat text such as ‘I approve’ never counts as a decision.

In production, card decisions remain unavailable until the target client and OAuth resource have a current evidence-backed assessment proving that private widget metadata and the decision capability are isolated from the model and that only the card control submits the decision. A widget-only label by itself is not treated as proof.

Approval revalidates live state and reserves the effect before attempting at most one provider write. A double click cannot produce a second attempt. A timeout or ambiguous response is not retried automatically; the Recheck control performs read-only reconciliation. Another write requires a new review and a new human decision.

9. Recipients, hosting and transfers

Authorized workspace members and personnel needing the minimum access for support, security or legal compliance may access relevant data. Scalingo SAS (RCS Strasbourg 808 665 483), 13 rue Jacques Peirotes, 67000 Strasbourg, France, hosts the application and database in the selected osc-fr1, France region. Contact: support@scalingo.com. Lusca does not publish an unverified host telephone number because the official Scalingo notice used here provides none.

Brevo, operated by Sendinblue SAS (Paris trade register 498 019 298), 9–17 rue Salneuve, 75017 Paris, France, is Lusca’s intended processor for transactional verification and password-recovery delivery from a dedicated getlusca.com sender. Its published Article 28 DPA is Appendix 3 to the Brevo General Terms. Brevo receives the recipient address, language, subject and message body containing the opaque Lusca link, plus bounded delivery metadata. It is not authorized for marketing and does not decide account activation.

Brevo documents core hosting by OVH in France and Google Cloud in Belgium. Its necessary-subprocessor list also covers infrastructure, security, support and reporting services, and Brevo group support entities; where a recipient is outside the EEA, the published safeguards include the EU–US Data Privacy Framework, Standard Contractual Clauses or Binding Corporate Rules as applicable. The Brevo sender, domain and Lusca privacy settings intended for production were verified on 12 August 2026. Password email still fails closed whenever its runtime configuration, delivery budget, global pause or admission controls do not allow it.

Support messages are processed through the configured mailbox service. This code review does not prove a fixed mailbox location, provider retention period or access schedule, so no more specific promise is made; users must not include credentials or unnecessary customer data.

At the user’s direction, connected Shopify, Google and identity services process connection data under their own terms. ChatGPT/OpenAI is a separate recipient only after section 6 is satisfied. The applicable OpenAI entity, role, processing locations and transfer safeguards depend on the user’s actual account contract and configuration; users should review the applicable OpenAI information and their ChatGPT controls before accepting the disclosure.

10. Retention and recovery copies

  • Web session and CSRF cookies: up to 7 days. Identity OAuth state: 10 minutes. Shopify installation intent/reservation: 15 to 30 minutes. Provider OAuth state: valid for 10 minutes; expired or consumed rows older than one further hour are pruned opportunistically when another provider authorization starts.
  • Email-verification and password-reset links expire after approximately 20 minutes, are single-use and are stored by Lusca only as token hashes. A resend invalidates earlier verification tokens. A successful password reset revokes the relevant active Lusca sessions and token families. A retention sweep runs after service start and every hour: pending email accounts without a store are targeted for deletion after 24 hours once no verification link remains active; token rows 24 hours after expiry, consumption or invalidation; durable anti-abuse counters after 3 days; and the HMAC-referenced outcome audit after 30 days. While the service is healthy, deletion can therefore occur up to approximately one hour after a cutoff; an outage delays it until the next successful startup or sweep.
  • For the production password path, the live Brevo account was verified on 12 August 2026 with transactional logs limited to one month and message-content previews disabled. Per-contact tracking consent is enabled on the shared account. Its default for contacts with unknown consent remains enabled for other account messages, while every Lusca request explicitly refuses recipient-level tracking. Brevo therefore keeps Lusca opens and clicks only as anonymized aggregates, not against the recipient. Lusca uses its own authenticated domain, sender, key and tags within that shared account.
  • MCP authorization code: 10 minutes; expired codes and consumed codes older than one hour are pruned opportunistically when another code is created. MCP access token: 1 hour. Refresh-token family: 30 days by default, configurable to a verified shorter value, with rotation and revocation.
  • Shopify order responses are limited to the requested 60-day window and handled in memory; no order table is maintained. Raw provider responses are not permanently copied unless a documented feature requires its bounded cache.
  • Cross-source daily reports are generated and returned in memory in production; the production runtime neither reads nor writes report files on local disk.
  • Action review and private capabilities: 15 minutes. The decision capability is one-time and server-stored only as a hash. No general purge duration is yet proven for completed action reviews or append-only action events.
  • The code does not establish a general calendar retention period for accounts, workspaces, provider metadata, product caches, synchronization/error records, AI receipts or support messages. Targeted replacement, revocation and deletion paths exist, but any additional duration remains to be documented and verified before it is promised.
  • Encrypted application snapshots retain the latest 10 generations by default, a configurable generation count rather than a calendar period. The code review does not prove the separate Scalingo platform-backup rotation or deletion timing. A rights or closure request therefore includes active systems, snapshots and backups in the manual inventory; no universal backup-deletion deadline is promised.

11. Rights, export, disconnection and deletion

Depending on the processing, a person may request access and a copy, rectification, erasure, restriction, portability, object to legitimate-interest processing and withdraw consent for future processing. Requests start through Support. Lusca agrees proportionate identity and authority evidence and an exact user/tenant/workspace boundary before acting.

The beta does not promise a self-service global export or deletion. The code contains bounded local export, withdrawal and deletion controls, but the end-to-end manual identity check, secure delivery channel, provider revocation, external action store, snapshots and platform backups are not yet operationally verified as one procedure. Destructive work therefore fails closed until authority, scope, active credential state and every affected system are proven for the individual request. No unverified universal 30-day completion is promised.

After its targeted path succeeds, disconnecting a provider blocks new provider calls and invalidates the related active Lusca caches. It does not by itself prove revocation at the provider or erasure from snapshots or platform backups. Users should also revoke access through provider controls. Lusca normally responds to a GDPR request within one month and explains any lawful extension within that first month. A complaint may be lodged with the CNIL.

12. Security and automated decisions

Measures proportionate to risk include HTTPS/TLS, encrypted provider-token and snapshot storage, tenant/workspace binding, least-privilege handling, signed OAuth state, durable rate limits, server-hashed private capabilities and email tokens, atomic single-use consumption, session revocation after password reset and controls designed to avoid logging secrets. No internet service can guarantee absolute security.

Lusca does not make solely automated decisions producing legal or similarly significant effects. Diagnostics and recommendations remain informational; each supported provider change requires the separate human-card decision described in section 8.

13. Changes, governing language and contact

Material changes require renewed acceptance or acknowledgment before access resumes where the service enforces it. The French version is the governing text; this English version is provided for convenience. Privacy, rights and deletion requests: support@getlusca.com.

Exercise a right · CNIL · Google API Services User Data Policy · Scalingo legal notice · OpenAI EEA privacy