DeepLumen
  • Shopify App NEW
  • Agentic Page Agentic Sales ChatGPT App UCP for Java
  • Home & Living Electronics Health & Beauty Fashion & Apparel Tools
  • Blog Whitepapers Agentic Commerce Glossary SEOWeek
  • Shop Tools
Book a Demo Get Started
Shopify App NEW
Agentic Page Agentic Sales ChatGPT App UCP for Java
Home & Living Electronics Health & Beauty Fashion & Apparel Tools
Blog Whitepapers Agentic Commerce Glossary SEOWeek
Shop Tools
Book a Demo Get Started
  1. Home›
  2. LumenCanvas Privacy

LumenCanvas — Privacy Policy

Last updated: August 23, 2026

This Privacy Policy describes how DEEPLUMEN PTE. LTD. (“we”, “us”, or “our”) collects, uses, and protects information when you use LumenCanvas (the “App”), our Shopify application for displaying product labels, badges, trust icons, highlights, and banners on your storefront.

Who This Policy Applies To

This policy applies to all users of the App, including Shopify merchants who install and use it (“Merchants”).

When We Collect Data

  • When you install the App, we create a record for your store and register the webhooks required to operate.
  • When you run a product sync, we import your product catalog data into the App.
  • When your products change, Shopify notifies the App so your product data stays current.
  • When you ask the App to check whether its storefront embed is turned on, we read your published theme’s config/settings_data.json. When you open an element editor, we read your published theme’s templates/product.json to work out which product-page positions that theme actually offers. Those are the only two theme files we ever read (see “Permissions We Request”).
  • When shoppers view your storefront, the App records anonymous, aggregate interaction counts (see “Usage Data”).

Permissions We Request

The App requests exactly three Shopify access scopes. We list them here in full because they define the outer limit of what we are technically able to see:

  • read_products — read-only access to your product catalog. This is what lets the App decide which products a label, badge, or banner applies to, and render accurate previews inside the admin.
  • read_themes — read-only access to your themes. The App reads exactly two named files from your published theme and nothing else: config/settings_data.json, to determine whether the LumenCanvas app embed is currently enabled; and templates/product.json, to determine which product-page positions your theme actually offers, so the editor does not let you place an element where it could never render. We do not read, copy, download, or store any other part of your theme — no other templates, and no sections, snippets, assets, or Liquid source. We do not retain the contents of either file. What we keep is derived status only: whether the embed is enabled and when we last checked it (stored), and which positions your theme offers (held in memory only, never written to our database).
  • write_app_proxy — this scope grants no read access to any store data. It exists solely so the App can declare an App Proxy, which lets your storefront call the App at https://<your-store>/apps/lumencanvas/…. Shopify signs those proxied requests, which is how the App verifies that a storefront request genuinely came from your store.

We do not request write_themes — the App never modifies a theme. We do not request read_customers, read_orders, read_all_orders, or any other scope that would give us access to your customers, their orders, or their payment information.

Information We Collect

We collect only the information necessary to provide, maintain, and improve the App’s core functionality (creating and displaying product labels, badges, trust icons, highlights, and banners, and targeting/scheduling them).

  • Merchant Account Data: store domain, store ID, primary locale, timezone, plan and subscription status, and your app settings.
  • Store Content Data: product information used for targeting and preview — such as product title, handle, vendor, product type, tags, collection membership, price and compare-at price, discount and availability status, publication status, and the featured product image URL.
  • Theme Embed Status: whether the App’s storefront embed is enabled on your published theme, and when we last checked. These two values are the only theme-derived data we store. No theme content is stored. Two further theme-derived values are held in memory for a few minutes and never written to our database: the list of product-page positions your theme offers (see read_themes above), and the name of your published theme, which the App shows you in Settings so you can see which theme it read.
  • Uploaded Assets: images you upload to use in your labels or badges.
  • Usage Data: aggregate, non-personal storefront interaction counts (element impressions, clicks, and add-to-cart events), stored as a daily count per element. These records contain no shopper identifier of any kind.
  • Log & Diagnostic Data: a narrow set of technical signals used to diagnose rendering problems on your storefront — an event type drawn from a fixed list, the App’s configuration version, the page type, element counts, and an error code. These records contain no IP addresses, no user agents, and no shopper identifiers; where a product handle is involved it is stored as a hash rather than in plain text.

We do NOT access, collect, or store customer personal data (such as names, emails, addresses, order history, or payment information) or order data through the Shopify API. The three scopes listed above under “Permissions We Request” are the complete set of permissions the App holds, and none of them grant access to customers or orders. All API usage complies with Shopify’s API Terms and Platform Policies.

The App uses Shopify offline access tokens only. It does not use online (per-staff-member) tokens, so the staff-identity fields present in Shopify’s standard session storage schema — staff name and staff email — are never populated by the App.

Optional personalization variables (a logged-in customer’s order count, total amount spent, or customer tags) are read from Shopify’s storefront Liquid at render time to display personalized label text in that shopper’s own browser. This happens on the storefront only — we do not fetch this data through the Shopify API, and we do not transmit it to or store it on our servers.

These variables are off by default and require you, the merchant, to switch them on in your theme’s app embed settings — separately for customer tags and for order count / total spent. While a switch is on, that field is readable by other scripts running on the same storefront page, which is why it is opt-in and split by sensitivity. Leave a switch off and the corresponding field is never written to the page at all.

How We Use Your Information

  • Provide, operate, and maintain the App’s core functionality.
  • Determine which products each label, badge, or banner applies to (targeting), and schedule when elements appear.
  • Render your elements on your storefront and generate in-app previews.
  • Produce aggregate analytics (impressions, clicks, add-to-carts) so you can see how your elements perform.
  • Diagnose storefront rendering failures and provide support.
  • Improve service performance, security, and user experience.
  • Comply with legal requirements and Shopify platform policies.

We do not sell your data or your customers’ data to third parties, and we do not use your store data to train third-party or general-purpose AI models.

Storefront Delivery and Your Theme

LumenCanvas is delivered as a Shopify theme app extension. You turn it on from your theme editor (the “app embed”), and it renders your elements on the storefront at display time. We do not edit, overwrite, or delete your theme’s template files, checkout, cart, or product templates. The App does not hold write_themes and makes no write calls to the Asset API. Its theme access is read-only and limited to the two files named under read_themes above — config/settings_data.json and templates/product.json — and nothing else. Any content you create (label text, uploaded images) is processed through a strict allow-list before it is published; we do not store or output raw store markup.

Third-Party Subprocessors

The App’s application, database, and origin file storage are operated by DEEPLUMEN PTE. LTD. on its own application servers. We do not use a third-party cloud provider to host the App or its database, and we do not use a third-party object-storage service as the origin or system of record for the images you upload (see “Data Storage”). Cloudflare’s network-delivery role is separate from those origin systems.

One subprocessor sits in the path of the service:

  • Cloudflare, Inc. — network transit, TLS termination, and delivery for the App’s domain. Requests between your browser or your storefront and the App travel over Cloudflare’s network, where Cloudflare may process ordinary request metadata and temporarily cache public responses as part of that delivery. Cloudflare does not host the App or its database and is not the origin, object-storage provider, or system of record for your store data or uploaded images.

We do not send your data to advertising networks, data brokers, or third-party analytics services.

Data Sharing and Disclosure

We share information only in these limited circumstances:

  • With Shopify, as required to enable app integration and comply with Shopify API terms.
  • When required by law, regulation, or legal process.
  • In connection with a merger, acquisition, or sale of assets, under confidentiality obligations.

Data Security

We implement reasonable technical and organizational measures to protect data from unauthorized access, use, or disclosure, including encryption in transit (TLS), access controls, content sanitization (including SVG sanitization and input allow-listing), signature verification on storefront requests, and regular security reviews. No method of transmission over the Internet is fully secure.

Data Storage

Your data is stored on application servers operated by DEEPLUMEN PTE. LTD., not on a third-party cloud platform:

  • Your store’s records — settings, elements, targeting rules, product index, aggregate analytics, and diagnostic records — are stored in a PostgreSQL database.
  • The images you upload are stored as files on the application server itself, and are served back through the App.

Uploaded image URLs are public storefront assets. Browsers and network delivery services may cache those public responses according to their cache headers. Deletion works as described under “Data Retention”: on shop/redact the database records are deleted and the origin image files are removed from the application server’s disk, but a previously delivered public image response may remain in a browser or network cache until that cache expires.

Data Retention

  • Aggregate Usage/Analytics Data is retained for approximately 400 days, after which it is deleted automatically.
  • Log & Diagnostic Data is retained for approximately 30 days, after which it is deleted automatically.
  • Store Content Data, uploaded assets, and your app settings are retained for as long as the App is installed, and are deleted on redaction as described below.

What happens when you uninstall

  • Immediately on uninstall, we delete your store’s session records and discard the access token we hold for your store. From that moment the App can no longer call the Shopify API on your store’s behalf, and it stops rendering anything on your storefront.
  • On receipt of Shopify’s shop/redact request — which Shopify sends approximately 48 hours after uninstall — we permanently delete your store’s data from the App’s origin systems: all labels, badges, banners, templates, targeting rules, compiled configuration, product index, analytics, and diagnostic records, together with the uploaded image files on the application server. As described under “Data Storage”, a public image response delivered before deletion may remain in a browser or network cache until that cache expires. We retain only a minimal tombstone record (your store domain and the redaction timestamps) so that the redaction itself remains auditable.
  • Your original store content and theme remain fully intact and unchanged throughout.

Your Data Rights

Depending on your jurisdiction, you may have the right to:

  • Access, correct, or update your information.
  • Request deletion or restriction of processing.
  • Receive your data in a portable format.
  • Object to certain types of processing.

To exercise these rights, contact us at the address below. When you uninstall the App, any content it displayed on your storefront stops rendering, and your store’s data is removed per the retention policy above.

Shopify GDPR Webhook Compliance

We support Shopify’s mandatory GDPR webhooks — customers/data_request, customers/redact, and shop/redact — and process such requests within the required timeframes. Because the App does not collect customer personal data, customers/data_request and customers/redact return no personal data; shop/redact permanently deletes your store’s data from the App as described under “Data Retention”.

AI Training and Data Usage

The App sends no store data to any AI or machine-learning service. We do not use your store data, your uploaded assets, your product catalog, or diagnostic data to train AI models — ours or anyone else’s. All processing is limited to providing, maintaining, and improving the App’s features for your store.

Cookies and Browser Storage

The App sets no cookies of its own, and no advertising, tracking, or cross-site analytics cookies of any kind. Cookies that appear while you use the App in your Shopify admin are set by Shopify’s platform and are strictly necessary to authenticate your admin session.

The App does use your browser’s local storage in two places. Both are stored on the device only, contain no identifier, and are never transmitted to us:

  • On your storefront: when a banner is dismissible and set to be remembered, the App stores one value on the shopper’s device recording when that specific banner may reappear. Nothing else about the shopper is stored or read. If you turn off “remember dismissal”, nothing is written at all.
  • In your admin: interface preferences for the staff member using the App. There are three, and this is the complete list: recently used emoji (lc-emoji-recents), whether the setup guide has been dismissed (lc.setupGuide.labels.dismissed), and whether the banner editor's drag hint has been dismissed (lc-banner-drag-tip-dismissed). None of them contains an identifier or anything about you beyond the preference itself.

You can clear this storage at any time through your browser settings; the only effect is that a dismissed banner or a dismissed guide may reappear.

Do Not Track

The App does not track individuals across sites or over time, so there is no cross-site tracking for a Do Not Track signal to switch off. We do not currently respond to DNT browser signals, and we monitor developments in this area.

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

Contact Us

DEEPLUMEN PTE. LTD.

91 Bencoolen Street #12-03 Sunshine Plaza, Singapore 189652

Email: contact@deeplumen.io

Website: https://www.deeplumen.com/

DeepLumen

DeepLumen is an AI-first technology company focused on the intersection of AI agents and agentic commerce. As the pioneers of the M2AI framework, DeepLumen builds the protocols and infrastructure that allow brands to thrive in the agentic economy.

Company

Trust Center

Product

Shopify App Agentic Page Agentic Sales ChatGPT App UCP for Java Shop Tools

Cases

Home & Living Electronics Health & Beauty Fashion & Apparel Tools

Resources

Blog Whitepapers Agentic Commerce Glossary SEOWeek
© 2026 DeepLumen (Hefei Shen Sui Future Intelligent Technology) Co., Ltd. All rights reserved.
Privacy Policy Terms of Service