Privacy Policy
Contents
- Who We Are
- Scope
- What We Process — Three-Tier Model
- Legal Bases (GDPR Article 6)
- Subprocessors
- International Data Transfers
- Data Retention
- Your Rights (GDPR Articles 15–22)
- California Privacy Rights (CCPA / CPRA)
- Automated Decision-Making
- Children's Privacy
- Security
- Changes to This Policy
- Contact and Supervisory Authorities
1. Who We Are
ConsentCraft is a Shopify application published by Lucent Labs LLC ("Lucent Labs," "we," "our," or "us"), a California Single-Member Limited Liability Company (EIN 42-2711201). Our principal place of business is in California, United States.
For data protection inquiries, contact us atprivacy@consentcraft.ai.
2. Scope
This Privacy Policy applies to three distinct groups:
- Merchants — Shopify store owners who install the ConsentCraft app via the Shopify App Store.
- Store Visitors — Visitors to a Merchant's Shopify storefront where a ConsentCraft consent banner is active.
- Website Visitors — Visitors to our own website at consentcraft.ai.
Our legal role differs across these groups. For Merchants and Website Visitors, we act as a data controller. For Store Visitors, we act as a data processor on behalf of the Merchant, who is the data controller for that processing.
3. What We Process — Three-Tier Model
Tier 1 — Merchant Account Data (we are the controller)
When a Merchant installs ConsentCraft, we collect and process:
- Shopify shop domain and store metadata (shop name, country, email address)
- Shopify OAuth access tokens required to operate the app
- Billing and subscription information (managed via Shopify Billing API)
- App configuration settings (banner content, consent categories, discount rules)
- Support correspondence and contact form submissions
Legal basis: Article 6(1)(b) GDPR — processing is necessary for the performance of the contract between Merchant and Lucent Labs LLC.
Tier 2 — Store Visitor Consent Data (we are the processor)
When Store Visitors interact with a ConsentCraft banner on a Merchant's storefront, we collect and process on behalf of that Merchant:
- Consent decision (accepted, declined, or partial preferences by category)
- Consent timestamp and consent version identifier
- Anonymized device metadata (browser type, screen width) for audit-trail integrity
- Partial IP address — the last octet is masked (e.g., 192.168.1.xxx) to provide geographic compliance signals without storing a fully identifying address
In this tier, the Merchant is the data controller for their Store Visitors. We process this data only on the Merchant's documented instructions. Our Data Processing Agreement governs this relationship. See consentcraft.ai/legal/dpa.
Tier 3 — Website Visitor Data (we are the controller)
When you visit consentcraft.ai, we collect:
- Server access logs (URL, HTTP referrer, anonymized IP, user-agent, timestamp)
- Contact form submissions (name, email address, message)
- Aggregate, non-identifying analytics (page views, traffic sources)
Legal basis: Article 6(1)(f) GDPR — legitimate interests in operating and improving our website. We do not build individual profiles of Website Visitors.
4. Legal Bases (GDPR Article 6)
| Processing Activity | Legal Basis |
|---|---|
| Merchant onboarding and app operation | Art. 6(1)(b) — contract performance |
| Billing and payment processing | Art. 6(1)(b) — contract performance |
| Customer support | Art. 6(1)(b) — contract performance |
| Fraud prevention and platform security | Art. 6(1)(f) — legitimate interests |
| Website analytics (consentcraft.ai) | Art. 6(1)(f) — legitimate interests |
| Store Visitor consent record processing | Art. 6(1)(c) + Merchant's documented instruction (DPA) |
| Marketing communications (opt-in only) | Art. 6(1)(a) — consent |
| Legal, accounting, and tax record keeping | Art. 6(1)(c) — legal obligation |
5. Subprocessors
We engage the following subprocessors to deliver the Service. We will provide at least 30 days' advance notice before engaging any new subprocessor.
| Subprocessor | Role | Location | Safeguard |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure (Lambda, DynamoDB, S3, CloudFront) | United States | SCCs + AWS DPA |
| Amazon Simple Email Service | Transactional email delivery | United States | SCCs + AWS DPA |
| Shopify Inc. | App distribution, billing, and OAuth | Canada / United States | SCCs + Shopify DPA |
| Bunny CDN | Static asset delivery (JavaScript, CSS) | EU + global | Bunny CDN DPA |
6. International Data Transfers
Our primary infrastructure is hosted by Amazon Web Services in the United States. Transfers of personal data from the European Economic Area (EEA) to the United States are safeguarded by Standard Contractual Clauses (SCCs) pursuant to European Commission Implementing Decision 2021/914. A copy of the applicable SCCs is available upon written request toprivacy@consentcraft.ai. The SCCs and UK International Data Transfer Addendum (B1.0) are incorporated by reference into our Data Processing Agreement (Section 6).
EU/UK Article 27 representative: As of the effective date of this Policy, Lucent Labs LLC has not yet appointed a formal representative in the European Union or United Kingdom pursuant to GDPR Article 27. We are a small provider actively evaluating representative services and will update this Policy when a representative is appointed. Merchants whose stores serve a significant number of EU-established visitors should be aware of this limitation and may wish to seek independent legal advice.
7. Data Retention
| Data Category | Retention Period |
|---|---|
| Merchant account data | Duration of active subscription, then 5 years for tax and accounting purposes |
| Store Visitor consent records | 13 months rolling — automatically purged thereafter |
| App configuration settings | 30 days after app uninstall, then deleted |
| Server access logs (consentcraft.ai) | 90 days |
| Support correspondence | 3 years from resolution |
| Marketing opt-in records | Until consent is withdrawn |
8. Your Rights (GDPR Articles 15–22)
If you are located in the EEA, United Kingdom, or Switzerland, you have the following rights:
- Right of access (Art. 15) — receive a copy of your personal data and information about how we process it.
- Right to rectification (Art. 16) — correct inaccurate or incomplete personal data.
- Right to erasure (Art. 17) — request deletion of your personal data, subject to legal retention obligations.
- Right to restriction (Art. 18) — limit our processing while a dispute is being resolved.
- Right to data portability (Art. 20) — receive your personal data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing carried out on the basis of legitimate interests.
- Rights regarding automated decision-making (Art. 22) — see Section 10 below. We do not conduct this processing.
To exercise any of these rights, emailprivacy@consentcraft.ai. We will respond within 30 days. Where we cannot fulfill a request, we will explain why.
Note for Store Visitors: If you are a visitor to a Merchant's Shopify store and wish to exercise rights regarding your consent record, please contact that Merchant directly. We will assist Merchants in fulfilling such requests as described in our DPA.
9. California Privacy Rights (CCPA / CPRA)
California residents have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know — what personal information we collect, use, disclose, or sell.
- Right to delete — request deletion of personal information.
- Right to correct — request correction of inaccurate personal information.
- Right to opt out — opt out of the "sale" or "sharing" of personal information.
- Right to non-discrimination — we will not discriminate against you for exercising your California privacy rights.
We do not sell or share personal information as those terms are defined under the CCPA/CPRA. We do not engage in cross-context behavioral advertising. No opt-out action is required.
To exercise your California rights, emailprivacy@consentcraft.ai with the subject line "California Privacy Request."
10. Automated Decision-Making
We do not use personal data to make solely automated decisions that produce legal effects or similarly significant effects on any person. No profiling for automated decision-making occurs within our Service pursuant to GDPR Article 22.
11. Children's Privacy
ConsentCraft is not directed at children under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has submitted personal data to us, please contactprivacy@consentcraft.ai and we will delete it promptly.
12. Security
We implement industry-standard technical and organizational measures, including:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest
- Role-based access controls limited to authorized personnel
- Multi-tenant data isolation (shop-scoped partition keys)
- Regular security reviews and vulnerability assessments
- 48-hour breach notification procedures for EEA/UK data; 72 hours for all other data
No method of transmission over the internet is 100% secure. While we implement appropriate safeguards, we cannot guarantee absolute security.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The updated policy will be posted at this URL with a revised "Last updated" date. For material changes, we will notify active Merchants by email at least14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
14. Contact and Supervisory Authorities
Data controller: Lucent Labs LLC
Email:privacy@consentcraft.ai
Website: consentcraft.ai
We encourage you to contact us first if you have a concern. You also have the right to lodge a complaint with a supervisory authority:
- EEA residents: contact your national data protection authority. A full list is available atedpb.europa.eu.
- UK residents: contact the Information Commissioner's Office (ICO) atico.org.uk.
- California residents: contact the California Privacy Protection Agency (CPPA) atcppa.ca.gov.