Privacy Policy
Last updated: September 2026
1. Introduction
Lustriel ("the App") is operated by JMS Dev Lab. This Privacy Policy explains how we collect, use, and protect information when you install and use our Shopify app.
2. Information We Collect
2a. From Shopify Merchants
- Shop domain and store name (provided by Shopify during installation)
- Email address associated with the Shopify account
- Billing and subscription details (processed through Shopify Billing API)
- App configuration settings (branding, markup rules, and reviewed catalog selection)
2b. From Store Customers
- Ring configuration selections (shape, metal, size, stones) for order fulfillment
- Consultation request details (name, email, phone, message) when voluntarily submitted
- Quote request details (email and the configuration requested) when voluntarily submitted
- Product reviews (reviewer name, email, rating and text) when voluntarily submitted
- Wishlists (the Shopify customer ID and the saved configurations) for signed-in customers
- Order details needed to hand a configured order to fulfilment (customer name, email, shipping and billing address, and the ordered configuration), received from Shopify when an order containing a configured item is created
- Usage analytics events (page views, configuration steps completed)
2c. Automatically Collected
- IP address and browser user-agent, recorded with each storefront analytics event and used for security, abuse prevention and aggregated reporting; deleted with the event after 90 days
3. How We Use Information
- To provide the ring configuration service and process orders
- To communicate Stuller product specifications to fulfillment
- To display staged product media and indicative pricing, or account-specific data when an eligible merchant connects their own Stuller business account
- To generate analytics dashboards for merchants
- To manage billing and subscriptions through Shopify
- To respond to support and consultation requests
4. Third-Party Services
We integrate with the following services:
- Stuller Inc. — Product images, pricing, and catalog data are fetched via Stuller's API. Stuller's privacy policy governs their data handling when Stuller-backed catalog data is used.
- Shopify — Authentication, billing, and storefront integration are managed by Shopify. Refer to Shopify's privacy policy.
- Railway — Application hosting and databases.
- Cloudflare — DNS, email routing, and delivery of the storefront configurator files.
- Postmark — Delivery of transactional email (for example, consultation and quote notifications to the merchant).
- Google and Meta — On standalone public pages only, Google tags may send cookieless measurement pings while analytics and advertising storage remain denied. Meta, advertising storage and personalisation remain blocked until the visitor accepts optional tracking. These tags do not run in the embedded Shopify admin. Visitors can reject, accept, change or withdraw their choice through the persistent Cookie settings control.
We do not sell or rent personal data. We share data with service providers only as described above.
5. Data Retention
- Merchant configuration data is retained while the app is installed.
- After the app is uninstalled, Shopify sends a shop data-erasure request (normally 48 hours later). On receipt we delete the shop's configuration, carts, order handoffs, reviews, consultations, wishlists and analytics events. A minimal account record (shop domain and status) is kept so that a reinstall is recognised.
- When Shopify sends a customer data-erasure request, we delete or redact that customer's personal data in carts, order handoffs, consultations, wishlists and reviews.
- Consultation requests are retained for up to 12 months, then deleted.
- Raw analytics events are retained for up to 90 days, then deleted; dashboard totals are calculated from the retained window.
6. GDPR Rights
If you are in the European Economic Area, you have the right to:
- Access, correct, or delete your personal data
- Object to or restrict processing of your data
- Data portability
- Withdraw consent at any time
To exercise these rights, contact us at support@jmsdevlab.com. We will respond within 30 days.
7. Data Security
We use industry-standard measures to protect data, including encrypted connections (TLS), secure session management, and access controls. API credentials are stored as environment variables and never exposed to the client.
8. Changes to This Policy
We may update this policy periodically. Changes will be posted on this page with an updated "Last updated" date. Continued use of the app constitutes acceptance of the revised policy.
9. Contact
JMS Dev Lab
Email: support@jmsdevlab.com