1. Our core promise
- We do not sell, rent, or lease your account data, business content, or your customers’ / end-users’ data.
- We do not share your data or your clients’ data with third parties for marketing, advertising lists, data brokerage, profiling for sale, or similar commercial use.
- We do not use your store data, customer data, messages, forms, feeds, or customer content to train AI models, improve third-party AI systems, or build machine-learning datasets.
- Data is processed only to provide, secure, and support the Lutastore Cloud services you subscribe to.
2. Your customers’ data stays yours
When you use Lutastore Cloud (for example Image Swift, WhatSync, ShopShort, CollectX, Feeds, or Commerce Agent), any end-customer or client data you process through the platform remains under your control as the merchant / account owner.
- We act as a service provider / processor for that data — not as the owner of your customer relationships.
- We do not mine, resell, or monetize your clients’ personal data.
- We do not use customer data for AI learning, model training, or third-party AI improvement.
- Access by our team is limited to support and security needs, under confidentiality and least-privilege practices.
3. No third-party sharing for commercial use
Disclosure to other parties happens only when strictly necessary:
- Infrastructure & operations — trusted hosting, payment, or delivery subprocessors required to run the service, under appropriate agreements.
- Legal obligation — where required by applicable law, regulation, or valid legal process.
- Never for sale or advertising networks — we do not provide your data or your customers’ data to third parties for their marketing or AI training.
4. No AI training on your data
- Customer content is not used to train Lutastore, SonoTrix, or third-party AI / machine-learning models.
- Where a feature uses AI (for example Commerce Agent), it is configured to serve your storefront and leads — not to harvest your data for model training.
- We do not grant AI vendors rights to retain or learn from your proprietary or personal customer data beyond what is required to deliver the feature you enabled.
5. GDPR & legal standards
Lutastore Cloud follows GDPR-aligned privacy practices and standard data-protection principles used in modern SaaS:
- Lawfulness, fairness & transparency — clear purpose for processing; no hidden secondary use.
- Purpose limitation — data used to operate and secure the service you requested.
- Data minimisation — we collect only what is needed for the product and support.
- Integrity & confidentiality — technical and organisational measures to prevent unauthorised access.
- Accountability — documented policies, retention limits, and a clear contact channel for requests.
- Your rights — where applicable, you may request access, correction, restriction, or deletion of personal data we hold about your account. Contact [email protected].
If you are a merchant serving EU/EEA individuals, you remain responsible for your own privacy notices and lawful bases toward your end customers. Lutastore Cloud supports you by not exploiting that data beyond the service.
6. Data imprint & legal information
- Service: Lutastore Cloud — ecommerce SaaS platform
- Operator: SonoTrix
- Website: lutastore.net
- Head office: 8 Atlas, Taksim Yaqoub Land, Amin El Sherif Street, Behind Aswan Sports Club, Kornish El Nile, Aswan, Egypt
- Privacy & support: [email protected] · [email protected]
- Sales: [email protected]
- Related: Privacy Policy · Terms of Service · Contact Us
7. Security
We apply a high level of security so your data and your customers’ data are not casually exposed:
- Encryption in transit — HTTPS with industry-standard SSL/TLS.
- Access control — authenticated accounts, restricted internal access, least privilege.
- Isolation & hardening — modern hosting security practices for production.
- Monitoring & response — security-minded operations to detect and address issues.
- Secure payments — trusted payment gateways; we do not store full card details for resale or misuse.
- Retention discipline — after deactivation, data is kept for a limited period (see Privacy Policy: typically 30 days) then permanently deleted.
No system can claim absolute immunity from every threat; we continuously work to keep protections strong and data inaccessible to unauthorised third parties.
8. Respect & transparency
- We treat merchants and their customers with respect and confidentiality.
- We communicate privacy changes clearly; significant updates are notified where appropriate.
- Questions about data handling are welcome — privacy should never feel opaque.
9. Contact for privacy requests
Data privacy inquiries, access requests, or concerns:
Quick summary
| Topic | Commitment |
|---|---|
| Your / client data | Not sold, not rented, not used as a product |
| Third parties | No sharing for marketing or resale; only operational necessity or law |
| AI learning | Customer data is not used to train AI models |
| GDPR | GDPR-aligned principles; rights requests supported |
| Security | HTTPS/TLS, access control, hardened operations |
| Imprint | SonoTrix / Lutastore Cloud — contacts and office listed above |