← Back to LUCRA

Español · English

Privacy Policy

Last updated: July 14, 2026

1. Data controller

FDV ECOM SAS LLC is the controller of the personal data collected through the LUCRA platform (ecomlucra.com). This policy complies with applicable international regulations, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and equivalent data protection laws in Latin America.

2. Data we collect

We collect the following types of personal data:

  • Account data: name, email, country, phone (optional), billing details.
  • Profile data: store name, avatar, gender, and any optional data you choose to share.
  • Usage data: history of generated landings, analyzed products, produced creatives, community interactions, credit-consumption metrics.
  • Technical data: IP address, browser type, operating system, pages visited, session identifiers.
  • Payment data: processed directly by Stripe (direct users) or by the Shopify Billing API (Shopify merchants). We never store card numbers on our servers.
  • Biometric data (optional): voice samples if you choose to use the Voice Cloning feature. These are processed solely to generate your personal voice model and are never shared with third parties without your consent.
  • Optional data: connections to Dropi, Shopify, Meta (Facebook/Instagram) Ads or other logistics, e-commerce or advertising platforms you choose to integrate.
  • WhatsApp data (optional): if you use the WhatsApp automation of the Personal plans, we process your WhatsApp number and the content of the messages for that purpose (expenses and goals you log, report commands). If you also agree to receive LUCRA news and announcements via WhatsApp, we store the date and channel of that consent.

3. How we use your data

We use your data for the following purposes:

  • Provide and operate the Service.
  • Process payments and manage your subscription.
  • Generate AI content per your instructions (landings, creatives, audio, video).
  • Send you transactional notifications (confirmations, trial alerts, payment reminders).
  • Send you LUCRA news and announcements via WhatsApp, only if you gave your explicit consent (checkbox at signup or a message from you requesting it). You can revoke it at any time by replying STOP to any message — we immediately stop sending this type of communication.
  • Improve the Service and develop new features.
  • Detect fraud, abuse and violations of the Terms.
  • Comply with applicable legal obligations.

We never sell your personal data to third parties under any circumstances.

4. Sub-processors and service providers

To deliver LUCRA's features, we rely on third-party service providers that process data on our behalf, under confidentiality agreements and compliance equivalent to or stronger than this policy. These are our current sub-processors:

  • Generative AI providers — AI image, video, text and voice generation. They process the prompts and files you generate under confidentiality and data-processing agreements; they do not use your content to train their models. A detailed list is available on request via Support.
  • Stripe, Inc. — card payment processing and subscription management for direct users.
  • Shopify Inc. — for Shopify merchants, billing of plans and credit purchases is processed through the Shopify Billing API (within Shopify).
  • Supabase, Inc. — database storage, authentication and file storage.
  • Vercel, Inc. — web application hosting and content delivery (CDN).
  • Resend (Drift, Inc.) — transactional email delivery (verification codes, notifications).
  • WhatsApp Business Platform (Meta Platforms, Inc.) — messaging channel for the optional automation of the Personal plans (logging expenses/goals and receiving reports via WhatsApp). We process your WhatsApp number and the content of the messages you send/receive for this purpose.
  • TikTok (ByteDance Ltd.) — for the optional TikTok Ads integration, we access your advertising report data (metrics and spend) via the TikTok Business API to record it in your accounting. See section 13.

Each of these providers has its own robust privacy policies and complies with international regulations. We may update this list as the platform evolves; significant changes will be notified via email.

5. Cookies and similar technologies

We use cookies and similar technologies (localStorage, sessionStorage) to:

  • Keep your session active after you log in.
  • Remember UI preferences (light/dark mode, language).
  • Persist state across payment redirects.
  • Measure aggregate usage and performance (without direct personal identification).

You can disable cookies in your browser settings, though some features may stop working correctly.

6. Your rights over your data

You have the following rights over your personal data (in accordance with GDPR, CCPA and equivalent local laws):

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your account and associated data (available directly in the app under Settings → Delete account).
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to certain processing of your data.
  • Withdrawal of consent: revoke consents granted at any time.

To exercise any of these rights, contact us at support@ecomlucra.com. We respond within 30 days.

7. Data retention

We keep your personal data for as long as necessary to provide the Service and comply with legal obligations:

  • Account data: while your account is active, plus 30 days after deletion.
  • Billing data: up to 7 years for tax compliance.
  • Technical logs: up to 90 days for troubleshooting and security.
  • Cloned voice: while your account is active or until you delete it manually from the app.
  • Community messages: subject to a specific, configurable chat retention policy.

8. Security

We implement technical and organizational measures to protect your data:

  • TLS 1.3 encryption in transit.
  • Encryption of sensitive data at rest (integration tokens via AES).
  • Secure authentication with Supabase Auth.
  • Row-Level Security (RLS) in the database.
  • Rate limiting and monitoring against abuse.
  • Automated daily backups.
  • Security headers: HSTS, X-Frame-Options, Permissions-Policy.

No system is 100% secure, however. In the event of a security breach affecting your data, we will notify you without undue delay.

9. International transfers

Some sub-processors have servers outside your country of residence (mainly the United States and the European Union). These transfers are carried out under recognized legal mechanisms (Standard Contractual Clauses, Data Processing Agreements) to ensure equivalent protection.

10. Minors

LUCRA is not directed to anyone under 18. We do not knowingly collect data from minors. If you discover that a minor has created an account without parental consent, contact us to delete it.

11. Shopify integration (App Store compliance)

When you connect your Shopify store to LUCRA, we act as an "App Developer" under the Shopify Platform. Here we detail exactly what we do with your store's data:

Shopify data we collect:

  • OAuth access token: stored encrypted (AES-256) in our database. Required to publish products on your behalf.
  • Product list: we read your products (title, price, images, variants) when you manually import them from the Products section. We do NOT read products without your explicit action.
  • Active theme: we read which theme you have active to publish landings as native sections (image-banner). We do NOT modify your theme; we only create separate templates.
  • Store domain: we store yourstore.myshopify.com to associate it with your LUCRA account.

Shopify data we do NOT collect:

  • Your store's end-customer data (names, emails, addresses, purchase history).
  • Order, payment or payment-method information.
  • Store analytics data (sessions, conversions, etc.).
  • Inventory or stock levels.

OAuth scopes we request and why:

  • read_products: read your catalog to import it into LUCRA (user-initiated action).
  • write_products: publish the landings generated in LUCRA as products in your store.
  • write_files: upload the optimized landing images to Shopify's native CDN (Files).
  • read_themes: detect whether your theme supports image-banner sections (to use the PRO or LEGACY flow).
  • write_themes: create the landing JSON templates (templates/product.lucra-{productId}.json). We do NOT modify the rest of the theme.

GDPR compliance webhooks (Shopify mandatory):

  • app/uninstalled: when you uninstall the app, we delete your access token and the integration row within 24 hours.
  • customers/data_request: if a customer of your store requests their data, we respond confirming that LUCRA does not store customer data.
  • customers/redact: same — we do not store customer data, so there is nothing to erase.
  • shop/redact: 48 hours after your store closes, we delete all integration information within 30 days.

Pricing model: LUCRA is free to install. For merchants who install LUCRA from the Shopify App Store (or whose account is in Shopify context), both the plans (Starter, Pro, Empire, Business) and credit purchases are charged through the Shopify Billing API — within Shopify, on the merchant's Shopify invoice. We do NOT charge Shopify merchants outside the Shopify Billing API. Users who sign up directly at ecomlucra.com (outside Shopify) are charged via our payment processor (Stripe).

12. Meta (Facebook/Instagram) Ads integration

When you connect your Meta advertising account to LUCRA (optional feature), we access your campaign data to show you your metrics and automatically record your ad spend in your accounting, and — if you enable it — to build and create campaigns, ad sets and ads in your account. Everything LUCRA creates is ALWAYS paused: it is never activated and never spends your budget without an explicit action from you.

Meta data we collect:

  • OAuth access token: stored encrypted (AES-256) in our database. Required to query your advertising data on your behalf.
  • Ad accounts: identifier, name and currency of the ad accounts you manage, so you can choose which to connect.
  • Campaign data: name, identifier, status and daily spend of your campaigns, ad sets and ads, along with aggregate performance metrics (impressions, clicks, CPM, CTR).

Meta data we do NOT collect:

  • Personal data of people who view or interact with your ads.
  • The content of your Facebook Pages or Instagram profiles, messages, or organic posts.
  • Your friends list, contacts, or any personal profile data beyond the identifier needed for the connection.
  • Custom audiences or customer lists.

OAuth scopes we request and why:

  • ads_read: read your campaign metrics and spend to record them in your accounting and give you recommendations.
  • ads_management: create and manage campaigns, ad sets and ads in your account when you ask (always created PAUSED), and apply the actions you trigger: turn off/on, adjust budget, duplicate.
  • business_management: list the ad accounts in your business portfolio so you can select which to connect.
  • pages_show_list: list your Facebook Pages to associate the created ad with the Page you choose (Meta requires this to create ads).
  • pages_read_engagement: Meta requires this as a dependency of ads_management to create and manage ads associated with your Page. We do not read or store your Page's organic posts, photos or follower data beyond what is needed to associate the ad with the Page you choose.

Disconnection and deletion: you can disconnect the integration at any time from Settings → Integrations inside LUCRA (we delete your token immediately), or revoke access from your Facebook account's app settings. When you delete your LUCRA account, all integration tokens and data are deleted with it. We also respond automatically to Meta's callbacks: if you remove the app from your Facebook (deauthorize) or request deletion of your data (data deletion request), we delete your access token and the information obtained from Meta (ad account data and change log) with no further action needed from you.

13. TikTok Ads integration

When you connect your TikTok Ads account to LUCRA (optional feature), we access your advertising report data to show you your metrics and automatically record your ad spend in your accounting. LUCRA reads this data only — it does not create, modify or activate campaigns on TikTok.

OAuth scopes we request and why:

  • user.info.basic: identify your TikTok Business account to associate the connection.
  • advertiser.read: list your advertiser accounts so you can choose which to connect.
  • ad.report: read your campaigns' performance reports and spend to record them in your accounting.

We do NOT collect your videos' organic content, your followers, or personal data of people who view your ads. Disconnection and deletion: you can disconnect the integration at any time from Settings → Integrations inside LUCRA (we delete your token immediately). When you delete your LUCRA account, all integration tokens and data are deleted with it.

14. Changes to this policy

We may update this Privacy Policy occasionally. Substantial changes will be notified at least 30 days in advance via email to your registered address. The "last updated" date in the header indicates when it was last modified.

15. Contact

For privacy inquiries or to exercise your rights: