LexaConsent Privacy Policy

Effective 5 September 2026 · Operator: Lumerexa (AC Bilişim), Türkiye · Contact: support@lumerexa.com

LexaConsent is a Shopify app that shows a cookie-consent banner on a merchant's storefront, applies the visitor's choice to Shopify and to advertising or analytics tags, keeps a record of consent decisions for the merchant, and checks how the storefront's tags behave. This policy explains what data the app processes, for whom, and for how long.

1. Roles

For storefront visitors' consent records, the merchant is the data controller and Lumerexa is the data processor acting on the merchant's instructions through the app. For the merchant's own account data (shop domain, settings, plan) Lumerexa is the controller.

2. Data we process for merchants

DataPurposeRetention
Shop domain, store handle, encrypted Shopify API access token, granted scopesOperate the app inside the Shopify admin (read theme settings, write the banner configuration, create the cookie-policy page, register the checkout pixel)Until uninstall; purged 30 days after uninstall
Banner configuration (style, colours, texts, categories)Render the banner on the storefrontUntil uninstall + 30 days
Plan name and entitlementsEnable plan features; billing itself is handled by ShopifyUntil uninstall + 30 days
Health-check results: storefront URLs opened, requests observed, consent signals, Largest Contentful Paint timingsReport whether tags respect consent and suggest fixesUntil uninstall + 30 days
Storefront password of development stores, when the merchant enters itLet the health check and the tag scan open a password-protected storefrontUntil removed by the merchant or uninstall
Merchant contact e-mail (optional)Health-check alertsUntil removed or uninstall

3. Data we process about storefront visitors

When a visitor makes a choice in the banner (or Shopify reports a consent change at checkout), the app records a consent event for the merchant:

We do not store IP addresses, names, e-mail addresses, order data or any customer account data. The banner sends no network requests until the visitor has decided; returning visitors send nothing. Merchants see their consent log in the app and can export it; retention is 30 days on the Free plan and up to 3 years on paid plans, after which events are deleted automatically. All events of a shop are deleted 30 days after the app is uninstalled or immediately on a Shopify shop/redact request.

On the storefront the app also sets Google Consent Mode defaults and forwards the visitor's decision to Shopify's Customer Privacy API and to the merchant's own Google, Meta, TikTok and Microsoft tags. Those services process data under the merchant's agreements with them, not under this policy.

4. Where data is stored

Merchants in the EEA/UK: consent records are pseudonymous and contain no direct identifiers, and they are processed in Türkiye on the merchant's instructions. Where a transfer safeguard is required we rely on the merchant's instructions under the Shopify Partner data-processing terms and on our data-processing addendum, available on request.

5. Sub-processors

Poyraz Hosting (hosting, Türkiye) · Hetzner Online GmbH (EU browser worker, Germany) · Shopify (platform) · Resend (transactional e-mail for health alerts, only when a merchant enables alerts).

6. Merchant and visitor rights

Merchants can view, export and delete consent records from the app, and can uninstall the app at any time; Shopify then sends us the mandatory shop/redact and customers/redact webhooks, which we honour. Because consent records hold no direct identifiers, neither we nor the merchant can look up a specific visitor; a visitor who wants to change a choice can reopen the banner from the merchant's cookie-settings link or clear cookies, and a visitor exercising GDPR rights should contact the merchant. Questions about this policy: support@lumerexa.com.

7. Changes

We will post changes on this page and note the effective date above. Material changes are announced in the app.