Legal
Privacy Policy
Last updated: 5 September 2026 · Version 2026-09-19
This policy explains what Lucreo collects, why, who we share it with, how long we keep it, and how to get it back or have it deleted. It is written to describe our actual data flows — including the fact that we deliberately store nothing that identifies your customers: from an order address we read the country code and nothing else.
1. Who we are and scope
Lucreo is a profit intelligence service for e-commerce merchants. It connects your Google Ads account and your Shopify store, joins advertising spend with revenue, product costs, shipping and fees, and reports true profitability per product.
Lucreo is operated by Advance and Beyond LLC, a Delaware limited liability company, at 1007 N Orange Street, Wilmington, DE 19801, USA. For the purposes of the EU and UK General Data Protection Regulation, Advance and Beyond LLC acts as controller for the personal data of Lucreo account holders (you, our customer), and as processor for the business records you instruct us to import from your connected Google Ads and Shopify accounts.
This policy applies to lucreo.io, the Lucreo web application, and our scheduled data-synchronisation jobs. It does not apply to Google, Shopify, Stripe or any other third-party service you use, each of which has its own privacy policy.
Effective date: 5 September 2026.
2. Data we collect
2.1 Account data
Your email address, your display name if you provide one, and the workspace, store and team-member records you create. Passwords are never stored in readable form: authentication is handled by our managed authentication provider, which stores only a salted password hash. If you sign in with Google, we receive your email address and basic profile information from Google instead of a password.
2.2 Connection data
- Google Ads: the OAuth refresh token issued when you authorise Lucreo (encrypted at rest with AES-256-GCM under a key held outside the database), the Google Ads customer IDs available to your login, and the account ID you select. See the Google API Services disclosure.
- Google Merchant Center (optional): a separate OAuth refresh token for the Merchant Center scope, stored in its own record and encrypted at rest with AES-256-GCM, the scopes Google reported as granted, the Merchant Center account IDs your login can reach, and the account you select. It can be deleted on its own, without affecting your Google Ads connection.
- Shopify: your shop domain (for example your-shop.myshopify.com), the Admin API access token for the app you install or the custom-app token you paste (encrypted at rest with AES-256-GCM), and the granted access scopes.
2.3 Business and performance data
- From Google Ads: product (offer) identifiers, product titles, brand and product type, campaign identifiers, and aggregated metrics — cost, impressions, clicks, conversions and conversion value — by product and by day or reporting window.
- From Google Merchant Center, if you connect it: your account and sub-account names and IDs, the primary product feeds configured there with their feed label, content language and target countries, and product (offer) identifiers and their feed assignment. Lucreo does not copy your product catalogue content and does not read customer data from Merchant Center.
- From Shopify: products and variants (title, SKU, variant and product IDs, price, status, inventory item cost), and order line items — order identifier, order date, currency, product and variant identifier, SKU, quantity, unit and line price, discounts, taxes, shipping amounts and refunded amounts.
- From Shopify orders, the shipping country only — the two-letter country code of the delivery address, and nothing else from that address. We use it for a single purpose: attributing revenue, product costs and profit to the market a product was sold in, so you can see which countries make or lose you money. We never collect the city, postcode, street, region, name, email address or phone number from an address, and an order with no shipping address is stored without a country.
- From you: product cost overrides (COGS), per-unit shipping or fulfilment costs, payment processing and platform fee assumptions, currency settings, and profitability thresholds.
2.4 Usage and technical data
Server and edge request logs (timestamp, IP address, requested path, response status, user agent), and diagnostic records of synchronisation jobs including error messages returned by Google or Shopify. We use these for security monitoring, abuse prevention, debugging and support — not for profiling or advertising.
2.5 Authentication and security event logs
We keep a record of security-relevant events on your account, specifically:
- successful sign-ins, sign-outs and the sign-in method used;
- failed sign-in attempts, including the email address submitted;
- password reset requests and completions;
- email verification requests and confirmations;
- connection events (connecting, reconnecting or disconnecting Google Ads or Shopify) and denied requests to protected endpoints.
Each record includes the event type, timestamp, outcome, the account or user it relates to where known, and the IP address and user agent of the request. We use these logs to detect unauthorised access and abuse, to investigate incidents, and to answer your own questions about activity on your account. They are never used for advertising or profiling.
2.6 Consent and acceptance records
When you accept our Terms of Service and this Privacy Policy — at signup, when installing our Shopify app, or when we ask you to re-accept an updated version — we store a record of that acceptance as compliance evidence. Each record contains the document type and the exact version identifier accepted, the date and time, the user and workspace it belongs to, the IP address and user agent captured server-side, and the method of acceptance (for example signup form, Shopify install, or in-app re-acceptance prompt). You can view your own acceptance history in Settings.
2.7 Billing data
Subscriptions are billed through Stripe. Stripe collects your payment method directly and stores it on its own systems. Lucreo never receives or stores card numbers. We store only the Stripe customer and subscription identifiers, plan name, subscription and trial status, period dates, and billing country where Stripe provides it for tax purposes.
3. We do not collect your customers' personal information
Lucreo does not collect, request or store personal information that identifies your end customers. When we read your Shopify orders, we retain only what is needed to attribute revenue and profit to a product and a market:
- order and line-item identifiers, order date and currency;
- product and variant identifiers, SKU and product title;
- quantities, prices, discounts, taxes, shipping and refunded amounts;
- the shipping country of the order — the two-letter country code only.
Country is the only component of an address we ever read. We do not store customer names, email addresses, phone numbers, street addresses, cities, regions, postcodes, IP addresses of shoppers, payment details, or any other buyer identifier. A country code shared by every shopper in a market cannot single anyone out, so order records in Lucreo still cannot be used to identify a shopper.
Where Shopify's API returns customer or address fields other than the country code, they are discarded and never written to our database. Where Shopify requires it, we support the mandatory customer-data-request, customer-redaction and shop-redaction webhooks; since we hold no customer records, a redaction request is acknowledged and requires no data removal beyond what these endpoints already perform.
4. How we use data
- Compute profitability. Join Google Ads spend with Shopify revenue, COGS, shipping and fees to produce per-product profit, margin and ROAS across 7, 14, 30 and 90-day windows.
- Display analytics. Render dashboards, product tables, underperformer reports, cost editors and profit-and-loss views inside your workspace.
- Run scheduled syncs. Refresh performance and order data on a recurring schedule, and when you trigger a sync manually, using your stored connection tokens.
- Perform actions you request. Set a Shopify product to draft or active when you explicitly click that action. Lucreo takes no other write action in your stores.
- Support. Respond to your requests and investigate faults you report.
- Security and integrity. Detect abuse, prevent unauthorised access, maintain audit logs, and keep the service reliable.
- Billing. Manage trials, subscriptions, invoices and plan limits through Stripe.
- Service communications. Send transactional email such as password resets, sync failure alerts and billing notices.
5. Legal bases for processing (GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — creating and operating your account, running syncs, computing profitability, providing support and billing you.
- Legitimate interests (Art. 6(1)(f)) — securing the service, preventing fraud and abuse, authentication and security event logging (section 2.5), maintaining audit logs of administrative and support access (section 9), diagnosing faults and improving reliability. We balance these interests against your rights and use the minimum data necessary.
- Legal obligation and legitimate interests (Art. 6(1)(c) and 6(1)(f)) — keeping consent and policy-acceptance records (section 2.6) as evidence that we obtained and documented agreement to our terms and privacy policy.
- Consent (Art. 6(1)(a)) — optional analytics cookies, and your authorisation of each Google Ads or Shopify connection. You may withdraw consent at any time by rejecting non-essential cookies or disconnecting the integration.
- Legal obligation (Art. 6(1)(c)) — retaining billing and tax records.
7. Retention
- Connection tokens — retained until you disconnect the integration, revoke access at the provider, or delete your account. Disconnecting deletes the stored token immediately.
- Performance, order and cost data — retained while your account is active so that historical windows remain comparable, and deleted within 30 days of account deletion, after which encrypted backups are purged within 90 days.
- Encrypted backups — purged within 90 days.
- Request and edge logs — retained up to 90 days.
- Authentication and security event logs (section 2.5) — retained 12 months, then deleted.
- Audit logs of administrative and staff support access — retained 24 months.
- Consent and acceptance records (section 2.6) — retained for the life of the account and for 6 years after it is closed. These records are legal compliance evidence and therefore intentionally outlive the account; they contain no business, order or performance data.
- Billing and tax records — retained for as long as applicable law requires, typically seven years.
8. Security
- All traffic to and from Lucreo is encrypted in transit with TLS 1.2 or higher.
- Google and Shopify tokens are encrypted at rest with AES-256-GCM using a key stored outside the database as a managed secret. Tokens are decrypted only in memory, inside a server-side job, for the duration of an API call, and are never sent to the browser.
- Every table is protected by row-level security so that a request can only reach rows belonging to workspaces the authenticated user is a member of. Tenant isolation is enforced by the database, not only by application code.
- Privileged service credentials are restricted to server-side jobs, are never exposed to client code, and follow least-privilege scoping.
- Administrative actions on a workspace are recorded in an append-only audit log.
- Databases are backed up by our infrastructure provider with encryption at rest.
No system is perfectly secure, but we work to protect your data and will notify you without undue delay — and within 72 hours of becoming aware — of a personal data breach affecting you. Read more on our security page.
9. Support access by our staff
Authorised Advance and Beyond LLC personnel may access data inside a customer's workspace in read-only mode, solely to provide support you have asked for or to investigate a security, abuse or reliability issue affecting the Service.
- Access is explicitly initiated by a named member of staff — it is not standing or automatic.
- Access is time-limited and ends automatically when the support session expires.
- Every access is recorded in an append-only audit log with the member of staff, the workspace, the time and the stated reason.
- Staff cannot take actions on your behalf — no changing settings, editing costs, running syncs, or writing to your Google Ads or Shopify accounts.
- Staff cannot access stored OAuth tokens, access tokens or other credentials. These remain encrypted and are decrypted only in memory by automated server-side jobs.
- Access is restricted by role-based controls and enforced by the database, not only by the application interface.
We rely on legitimate interests for this processing (providing support, maintaining security and service integrity), and you may request the audit record of any staff access to your workspace by emailing privacy@lucreo.io.
10. Your rights and how to exercise them
Subject to applicable law, you may request to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete your account and associated data;
- export your data in a portable, machine-readable format;
- restrict or object to processing based on legitimate interests;
- withdraw consent you previously gave, without affecting prior processing.
Email privacy@lucreo.io from the address on your account. We respond within 30 days. We do not charge for these requests and will not discriminate against you for making one. Self-service deletion steps are on the data deletion page.
11. EU and UK GDPR
Controller: Advance and Beyond LLC, 1007 N Orange Street, Wilmington, DE 19801, USA. Contact: privacy@lucreo.io.
International transfers. Lucreo is operated from the United States and some subprocessors process data outside the EEA and the UK. Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with technical measures including encryption in transit and at rest. A copy of the relevant transfer mechanism is available on request.
Automated decision-making. Lucreo produces analytics and flags underperforming products, but it makes no automated decision that has legal effect on any individual. All merchandising and advertising decisions remain yours.
Complaints. You have the right to lodge a complaint with your local supervisory authority — for example your national data protection authority in the EEA, or the Information Commissioner's Office in the UK. We would appreciate the chance to address your concern first.
Where you act as controller for data you import into Lucreo, our Data Processing Addendum governs that processing.
12. California privacy rights (CCPA/CPRA)
In the twelve months preceding the date of this policy, we collected:
- Identifiers — name, email address, account and workspace identifiers, IP address.
- Commercial information — subscription plan, trial status, billing and subscription identifiers from Stripe.
- Internet or network activity — request logs, authentication events, diagnostic records.
- Professional or business information — the store, product, advertising and order-level business records you connect (which contain no consumer identifiers).
We collect this from you directly, from your authorised Google Ads and Shopify connections, and automatically from your use of the service. We use and disclose it for the business purposes described in sections 4 and 6. We do not collect sensitive personal information for the purpose of inferring characteristics.
We do not sell personal information and we do not share it for cross-context behavioural advertising as those terms are defined by the CCPA/CPRA. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" mechanism — there is nothing to opt out of.
California residents may exercise the right to know, the right to correct, the right to delete, and the right to limit use of sensitive personal information by emailing privacy@lucreo.io. We verify requests against the email address on your account, and an authorised agent may submit a request with written permission. We will not discriminate against you for exercising these rights.
13. Google API Services
Lucreo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Lucreo requests two Google scopes. The Google Ads scope (adwords) is used for reporting queries only; Lucreo performs no write operations on your Google Ads account. If you choose to connect Google Merchant Center, Lucreo requests the content scope. Google publishes only one Merchant Center scope, classifies it as a sensitive scope subject to Google's OAuth app verification review, and it grants both read and write access, even though Lucreo currently only reads your Merchant Center account configuration, feeds and product (offer) identifiers. Write access will be used in a future feature, and only when you explicitly ask for a specific change — never automatically or in the background.
The full scope-by-scope disclosure is at Google API Services user data disclosure.
15. Children
Lucreo is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us data, contact privacy@lucreo.io and we will delete it.
16. Changes to this policy
We may update this policy as the service evolves. The "last updated" date at the top always reflects the current version. For material changes — a new category of data, a new purpose, or a new subprocessor handling personal data — we will notify account holders by email or an in-app notice at least 14 days before the change takes effect, except where a change must take effect sooner for security or legal reasons.
17. Contact
Advance and Beyond LLC
A Delaware limited liability company
1007 N Orange Street, Wilmington, DE 19801, USA
Privacy and data requests: privacy@lucreo.io
General support: support@lucreo.io
See also our contact page.