Privacy policy
Updated 11 October 2026. Jamal Akram, sole trader trading as LustraStudio, is responsible for the personal information described here. Contact hello@lustrastudio.co for privacy questions or requests.
Scope and current availability
This notice covers our public website, support, waitlist, image studio, private Seller MCP and the separate Laser Automation engraving and label workflow. Seller access is currently private; public access is planned.
What we collect and why
Waitlist and inquiry forms collect your name, email, optional store URL and signup preferences to respond and discuss access. Support correspondence includes what you choose to send. Studio accounts and workflows process account identifiers, email, projects, prompts, reference and generated images, settings and usage records to provide the service.
The private Seller MCP processes catalog and product information, per-SKU listing details, images and issues, recent order information, product-type schemas, temporary new-listing drafts, validation results, approval and submission information. These support product inspection and seller-requested new-listing workflows. The Seller conversation workflow is intended for product and operational order information, rather than buyer customization, delivery addresses or contact details. Do not include buyer personal data in prompts or drafts.
We use account and workflow information to deliver requested services, correspondence to respond to inquiries, and operational information to maintain security and reliability. Where data protection law applies, these purposes rely on performance of a contract or steps you request before a contract, our legitimate interests in operating and securing the service, or consent where required. You may withdraw consent or ask us to stop waitlist contact by email.
Providers and sharing
Cloudflare hosts our website and integrations and stores service records and files. Amazon receives listing validation and submission requests. When you use ChatGPT tools, relevant requested seller or Studio information is returned to OpenAI for your conversation and handled under OpenAI’s privacy policy. Do not put buyer personal information in prompts or drafts.
Google image-generation services receive the prompts and reference images needed for supported Studio generation workflows, including Amazon-retrieved product images or text when used in generation. Waitlist notifications may send signup details to the operator through email service infrastructure; support correspondence is processed through our email service. The public website currently loads PostHog and Google Analytics for website analytics; these providers can receive browser, device, page and interaction information. Provider processing may occur outside the UK, according to their terms and applicable transfer safeguards. We do not sell seller data.
Separate Laser Automation workflow
For personalized-order production and shipping, Laser Automation processes buyer customization, delivery addresses and required contact details. These pass through a separate Cloudflare bridge to Windows engraving and shipping software for preparing personalized items and labels, rather than to Seller MCP or ChatGPT.
This workflow uses local files and backups on the production system. Supabase Sync is disabled and the web remote is no longer used. Historical remote copies may remain; disabling sync does not delete them. These storage locations are separate from the Seller conversation service. Deleting a record in one place does not automatically remove local files, backups or historical remote copies. Full automatic retention and deletion across these locations is not currently established; contact us to request deletion and to identify the relevant copies. Any records that must remain for legal obligations will be explained when your request is processed.
Storage, retention and deletion
Waitlist information remains in Cloudflare storage until a deletion request is processed; no automatic age-based deletion is currently configured. Studio content can remain until deleted or a deletion request is processed, and deleting a project does not by itself guarantee removal of its stored image files. Private Seller listing drafts are temporary. Related service records may remain until a deletion request is processed.
Email us to request deletion of waitlist entries, account data, seller-related records or stored files. We will verify the request, identify applicable storage and providers, and explain any information that must remain for legal obligations or resolving disputes. Disconnection stops access but is separate from deletion. Data already returned to ChatGPT and copies held by Amazon are subject to their respective controls.
Connecting and disconnecting
For the planned public service, you will authorize permissions on Amazon and connect them to your LustraStudio account. The intended design handles authorization credentials on the server and returns requested workflow information to ChatGPT. You can withdraw Amazon authorization through Seller Central; contact support for help with connection records or deletion.
For an existing private connection, contact us for help disabling access and request deletion separately. Revoke Amazon application authorization in Seller Central to stop Amazon access; disconnect LustraStudio in ChatGPT to stop that client’s connection.
Protecting information
The website and services use HTTPS. Current private new-listing submission requires human approval of the exact draft. The public waitlist endpoint checks request origin and input limits and applies rate limiting. Access to stored signup records is restricted to the operator.
Your rights and choices
You can request access, correction, deletion, restriction or portability where applicable and object to processing based on legitimate interests. Contact us using the email above. You can raise a concern with the UK Information Commissioner’s Office or your local data protection authority. We may update this notice when processing changes, including before public Seller launch.