Legal
Data Processing Addendum
Last updated: 5 September 2026 · Version 2026-09-19
This customer-facing summary DPA sets out how Lucreo processes data on your behalf, the security measures we maintain, who our subprocessors are, and what happens to your data when you leave. It applies automatically to every Lucreo customer — no signature required.
1. Roles of the parties
This Data Processing Addendum ("DPA") supplements the Terms of Service between you ("Customer") and Advance and Beyond LLC, a Delaware limited liability company, at 1007 N Orange Street, Wilmington, DE 19801, USA ("Lucreo"). It applies where Lucreo processes personal data on Customer's behalf and applicable data protection law — including the EU GDPR, the UK GDPR, the Swiss FADP and US state privacy laws — requires a written processing agreement. Effective 5 September 2026.
- Customer is the controller (or, where Customer itself processes on behalf of another, the processor) of the business data it imports into Lucreo.
- Lucreo is the processor of that data, acting only on Customer's documented instructions — which are given by Customer's configuration and use of the Service.
- Lucreo is the independent controller of the account, authentication, billing, support and security-log data relating to Customer's own personnel, described in our Privacy Policy.
2. Subject matter, duration and nature of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Lucreo profit intelligence service: importing advertising and commerce records, computing profitability and presenting analytics. |
| Duration | For the term of the Terms of Service, plus the deletion periods in section 9. |
| Nature and purpose | Collection by API, storage, aggregation, computation, display, export and deletion — solely to provide, secure and support the Service. |
| Types of data | Google Ads product performance metrics and identifiers; Google Merchant Center account, sub-account, product-feed configuration (feed label, content language, target countries) and product (offer) identifiers, where the Customer connects Merchant Center; Shopify products, variants, SKUs, prices, costs and order line-item financials; the two-letter shipping country code of an order, and no other component of any address; Customer-supplied cost and fee inputs; Customer's own users' email addresses and roles; connection tokens; authentication and security event logs (sign-ins, failed sign-in attempts, password resets, email verifications, connection events) including IP address and user agent; audit records of administrative and support access; and consent records showing which policy version was accepted, when, by whom, from which IP address and user agent, and by which method. |
| Categories of data subjects | Customer's authorised users (workspace members). Lucreo does not process end-consumer personal data — see section 3. |
| Special categories | None. Customer must not submit special category data to the Service. |
3. No identifying end-consumer data
The Service is designed so that no data identifying Customer's shoppers enters Lucreo. Order data is reduced to order and line-item identifiers, dates, currency, product and variant identifiers, SKUs, quantities, monetary amounts and the two-letter shipping country code of the order. Country is retained solely to attribute revenue, product costs and profit to the market of sale; it is coarse, shared by every order in that market and cannot single out an individual. Customer names, contact details, street addresses, cities, regions, postcodes, IP addresses and payment details are never requested, never stored and discarded if returned by an API. Customer must not upload consumer personal data into free-text fields.
4. Lucreo's obligations
- Process personal data only on Customer's documented instructions and as needed to provide the Service, or where required by law (in which case, unless prohibited, Lucreo will inform Customer).
- Not sell personal data, not use it for advertising, and not use it to train generalised AI or machine-learning models.
- Ensure personnel with access are bound by confidentiality and receive access on a least-privilege, need-to-know basis.
- Implement and maintain the technical and organisational measures in section 5.
- Assist Customer, at Customer's reasonable cost where the effort is substantial, with data subject requests, data protection impact assessments and regulator enquiries.
- Inform Customer without undue delay if an instruction appears to infringe applicable data protection law.
5. Security measures
Lucreo maintains at least the following measures, described more fully on our security page:
- TLS 1.2+ encryption for all data in transit; encryption at rest for the database and backups.
- AES-256-GCM encryption of Google and Shopify access tokens under a key held outside the database; decryption in memory only, server-side.
- Database-enforced row-level security providing tenant isolation on every table.
- Role-based access control within workspaces (owner, admin, viewer) and an append-only audit log of administrative actions.
- Lucreo personnel access is role-restricted and granted on a least-privilege, need-to-know basis. Support access to Customer data is read-only, explicitly initiated, time-limited and logged with the reason for access; support personnel cannot act within the Service on Customer's behalf.
- Credentials, OAuth refresh tokens and Admin API access tokens are not accessible to support personnel; they are stored encrypted and decrypted only in memory by automated server-side processes.
- Authentication and security events, and consent records, are logged for security, incident investigation and compliance evidence, with the retention periods stated in the Privacy Policy.
- Least-privilege handling of service credentials, which are never exposed to client code.
- Managed, encrypted backups; monitoring, alerting and automated recovery of failed jobs.
- Secure software development practices, dependency scanning and code review.
Lucreo may update these measures provided the overall level of protection is not materially reduced.
6. Subprocessors
Customer authorises Lucreo to engage the subprocessors listed at /subprocessors, currently:
| Subprocessor | Purpose | Location |
|---|---|---|
| Lovable Cloud (Supabase) | Application hosting, managed PostgreSQL database, authentication and encrypted storage of account, connection and performance data | European Union / United States |
| Stripe, Inc. | Subscription billing and payment processing. Stripe collects and stores payment card details directly; Lucreo never receives them | United States (global processing) |
| Resend, Inc. | Transactional email delivery (password resets, account and billing notifications). Receives email address and message content only | United States |
| Google LLC (Google Ads API) | Source system. Read-only retrieval of the Google Ads reporting data you authorise; Google receives the API requests Lucreo makes on your behalf | United States (global processing) |
| Shopify Inc. | Source system. Read-only retrieval of products, variants and order line items, plus product status changes you explicitly request | Canada / United States |
| Cloudflare, Inc. | Edge delivery, TLS termination, DDoS protection and request logging | United States (global edge network) |
Lucreo imposes data protection obligations on each subprocessor no less protective than this DPA and remains liable for their performance. Lucreo will give at least 30 days' notice before adding or replacing a subprocessor that processes personal data — subscribe by emailing privacy@lucreo.io. Customer may object on reasonable data protection grounds within that period; if the parties cannot agree on a resolution, Customer may terminate the affected subscription and receive a prorated refund of prepaid fees.
7. International transfers
Lucreo operates from the United States and some subprocessors process data outside the EEA, the UK and Switzerland. Where personal data is transferred out of those regions, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914, Module Two controller-to-processor, or Module Three where Customer is itself a processor), as supplemented by the UK International Data Transfer Addendum and, for Switzerland, the FADP-adapted clauses. Those clauses are incorporated into this DPA by reference, with Customer as data exporter and Lucreo as data importer, the annexes populated by sections 2, 5 and 6, and the docking clause applying. Lucreo additionally maintains encryption in transit and at rest and will challenge any unlawful government request for Customer data.
8. Breach notification
Lucreo will notify Customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer's data, by email to the account owner. The notification will describe the nature of the breach, the categories and approximate volume of data affected, the likely consequences and the measures taken or proposed. Lucreo will cooperate reasonably with Customer's own notification obligations. A notification is not an admission of fault.
9. Return and deletion
Customer may export its data from the Service at any time. On termination, or on Customer's written request, Lucreo will delete Customer's data within 30 days, with encrypted backups purged within 90 days, except where retention is required by law (for example billing and tax records). Disconnecting an integration deletes the stored access token immediately.
Deletion steps are described on the data deletion page.
10. Audits and information rights
On reasonable written request, and no more than once in any 12-month period unless a regulator or a breach requires otherwise, Lucreo will provide the information reasonably necessary to demonstrate compliance with this DPA, including a description of its security measures and any third-party attestations then available for its infrastructure providers. Where Customer's obligations under Article 28(3)(h) GDPR cannot be met that way, the parties will agree a proportionate audit scope, conducted under confidentiality, during business hours, without disrupting the Service and at Customer's expense.
11. Acceptance and precedence
This DPA takes effect on Customer's acceptance of the Terms of Service and requires no signature. In the event of a conflict, this DPA prevails over the Terms of Service and the Privacy Policy in respect of the processing of personal data, and the Standard Contractual Clauses prevail over this DPA. If Customer requires a countersigned copy or a negotiated enterprise DPA, email privacy@lucreo.io with your entity details.
This is Lucreo's standard DPA. If your procurement process requires a countersigned document or your own template, contact privacy@lucreo.io.