Lucidly — Privacy Policy
Last updated: 24 June 2026
Lucidly is a Shopify app that provides advertising attribution and customer analytics. This policy explains what personal data Lucidly processes, why, who it is shared with, and the rights available to merchants and their customers under UK GDPR.
Who is responsible
Lucidly is operated by Andrew Menzies, an individual based in the United Kingdom. For data-protection questions or requests, contact: see.lucidly@gmail.com.
When Lucidly processes a merchant's customer data, it acts as a data processor on behalf of the merchant (who is the data controller of their own customers' data). For a merchant's own account and contact details, Lucidly acts as a controller.
What data Lucidly processes
When a merchant installs Lucidly, it reads, via the Shopify API:
- Order data — order totals, dates, financial status, line items, products, discount codes, refunds, and the landing / referring URLs and UTM parameters attached to an order.
- Customer data — customer first and last name, email address, order history, and approximate location (country / city) derived from the order. Email addresses are stored so the merchant can view and export their own customer list for reporting and segmentation, and are encrypted at rest.
- Product data — product titles, SKUs, and collections.
- Advertising data — performance metrics pulled from the merchant's connected Meta (Facebook/Instagram) ad account. This is ad-level data (spend, impressions, conversions); it does not contain Lucidly's end-customer personal data.
Lucidly does not process customer phone numbers, payment-card details, or full billing addresses.
Why Lucidly processes it (purpose & legal basis)
The data is used solely to provide the app's analytics to the merchant: matching orders to advertising campaigns (attribution), calculating customer lifetime value, repeat-purchase and acquisition reporting, and product-level performance. The lawful basis is the legitimate interests of the merchant in understanding their own sales and marketing performance, and the performance of the service the merchant has chosen to install. Lucidly does not sell personal data and does not use it for any purpose other than providing these analytics to the merchant.
Who it is shared with (sub-processors)
- Fly.io — cloud hosting; stores the app's database.
- Meta Platforms — Lucidly reads advertising metrics from the merchant's own connected ad account. Customer personal data is not sent to Meta.
How long it is kept
Data is retained for as long as the app is installed. When a merchant uninstalls Lucidly, or when Shopify sends a data-erasure request on behalf of a shop or customer, the associated data is deleted. Lucidly implements Shopify's mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) to handle these requests automatically.
Your rights
Under UK GDPR, individuals have the right to access, correct, or request deletion of their personal data, and to object to processing. Merchant customers should direct such requests to the merchant (the data controller); the merchant can fulfil them through Shopify, which relays the request to Lucidly. Merchants can exercise their own rights, or ask any question about this policy, by emailing see.lucidly@gmail.com.
Changes to this policy
This policy may be updated as the app evolves. The "last updated" date above reflects the most recent change.