Privacy policy
Last updated: 6 September 2026
This translation is provided for convenience only. Only the French version is legally binding.
Introduction
LIORA attaches great importance to the protection of your personal data. This policy explains what data we collect, why, who it is passed on to, how long we keep it and what your rights are.
It covers the data of YOUR account, for which we are the controller. The data of your own customers, which you entrust to us by connecting your store, falls under a different regime: you are the controller of it, we are its processor, and it is our Data processing agreement that applies.
Data we collect
When you create your account, we ask you for:
- Your identity: first name, surname and date of birth.
- Your contact details: personal email address (which serves as your login), telephone number and, where applicable, a business email address.
- Your business: SIREN number, legal form and, if you wish, a trading name.
To these are added, through your use of the service:
- Your password: kept hashed, and therefore irreversible. We do not know it and cannot remind you of it.
- Your logins: date, IP address and browser used, for every session opened. These details are used to show you your connected devices and to detect unusual access.
- Your store: the Shopify domain you link to your account.
- Your subscription: plan, status, renewal dates and history of changes. Your card details, for their part, never reach us — they are entered with our payment provider.
- Our exchanges: messages sent through our forms, service emails that have been addressed to you, and internal notes our team may write about your file — to follow up a support request, for instance.
- Your feedback: when you indicate, in the application's help centre, whether an article was useful to you.
We collect no sensitive data within the meaning of Article 9 of the GDPR, and we build no automated profile producing legal effects concerning you.
Purposes and legal basis
- Managing your account and your subscription — performance of the contract.
- Issuing your invoices and meeting our accounting obligations — legal obligation. This is why your SIREN number and legal form are requested.
- Checking that you have the legal capacity to subscribe — this is the only use made of your date of birth.
- Replying to you and providing support — performance of the contract and legitimate interest. The internal notes relating to your file fall under this purpose.
- Keeping the service secure — legitimate interest: logging of logins and of our team's actions on accounts, so that unusual access can be established and explained.
- Writing to you about the service — performance of the contract for essential messages (address confirmation, password reset, renewal dates, incidents), legitimate interest for messages relating to your experience, such as a satisfaction request. The latter always include a way of objecting, and refusing has no consequence whatsoever for the service.
Your data is neither sold, rented out nor passed on to third parties for commercial purposes. We do not market to people who are not our customers, and we do not use your data to train models.
Who receives your data
Your data leaves us only for the providers strictly necessary to the service. Each acts on our instructions, and only for the part that concerns it:
- Vercel Inc. — hosting of the site and execution of the processing. Located in the European Union, in Paris.
- Neon Inc. — database. Located in the European Union, in Frankfurt (Germany).
- Stripe Payments Europe Ltd — collection of subscription payments and issuing of invoices. Receives your name, your email address and your payment details, which we never see.
- Resend Inc. — delivery of our emails. Receives your email address and the content of the message.
- Scaleway SAS — hosting of the application, in France.
Hosting and processing take place in the European Union. Vercel, Stripe and Resend, however, belong to groups established in the United States: access from that country, for operational or support purposes, cannot be ruled out. Where that happens, it is framed by the European Commission's standard contractual clauses. We would rather flag this reservation than claim a watertightness we could not demonstrate.
How long we keep it
- Account, profile, store and internal notes — for as long as your account exists. Everything is deleted when it is closed, including the notes written about you and your help centre feedback.
- Login log (dates, IP addresses, browsers) — twelve months, then automatic erasure.
- Confirmation and reset tokens — a few hours. They are erased as soon as they have expired.
- Log of the emails we have sent you — three years, so that we can prove what was sent to you and not write to you again in error.
- Log of our team's actions on accounts — three years. This is what makes it possible to say who did what, should you ask us.
- Messages sent through our forms — three years after our last exchange.
- Invoices and accounting records — ten years, as the law requires, regardless of whether the account is closed. This is the only category that outlives your departure.
- Register of security incidents — five years. It contains the technical identifier of the accounts affected, never the content of your data.
These periods are applied automatically, every night, and not by hand. Encrypted backups may keep a copy beyond them, for the time it takes them to rotate; they are never consulted and are overwritten of their own accord.
Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, objection, restriction and portability, as well as the right to withdraw at any time a consent you have given.
Most of your information can be changed directly from your customer area, where you can also close your account yourself — deletion is then immediate and final. For any other request, write to direction@liora-eu.com: we reply within one month.
If our reply does not satisfy you, you may refer the matter to the French data protection authority (Commission nationale de l'informatique et des libertés, CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or lodge a complaint at cnil.fr.
Our Security and incident response sets out what we do when an incident affects your data: how to report it, how we assess it, and who is notified.
Cookies
This site sets NO analytics, advertising or social network cookies. There is therefore no consent banner, and that is deliberate: asking your permission would suggest that something is happening which is not.
The only cookies set are those strictly necessary for the site to work, which are exempt from consent: the one that keeps your session open while you are logged in, and the one that remembers the language you have chosen. Should an analytics tool ever be added, it would be preceded by a request for consent, and this page would say so beforehand.
This text is a faithful description of the data actually collected by the service. Data controller: LIORA, entreprise individuelle, SIREN 923 209 183 — direction@liora-eu.com.