Lumous Privacy Policy
Last Updated: March 20th, 2026
Your privacy is important to us. This Privacy Policy explains what information Lumous (“we,” “us,” or “our”) collects, how we use it, who we share it with, and what measures we take to protect it. By using our website (lumous.app) and software (“Software”), you agree to the practices described in this policy.
1. Information We Collect
We collect the following categories of information:
a) Information You Provide Directly
- Contact form submissions: When you use our contact form, we collect your name, email address, and message content.
- Payment information: When you subscribe, we collect your name and email address. All payment card details are processed and stored exclusively by our payment processor, Stripe. We never see or store your full card number.
- Account information: Upon subscribing, we store your name, email address, Stripe customer ID, and subscription ID to manage your license.
b) Information Collected Automatically
- Device and license data: When you activate and use the Lumous Software, we collect a device identifier, install identifier, and a timestamp of your last activity. This data is used solely for license enforcement (e.g., limiting usage to one device per license).
- Analytics data: We use Google Analytics (GA4) to collect anonymized usage data about how visitors interact with our website, including pages visited, time spent on pages, referring URLs, browser type, operating system, and general geographic region. This data is collected via cookies and does not personally identify you.
- Cookies: Our website uses cookies for analytics (Google Analytics) and to maintain session state for administrative functions. You can control cookie preferences through your browser settings.
c) Information We Do Not Collect
- The Lumous Software does not monitor, record, or transmit your screen contents, keystrokes, browsing activity, files, or any personal content on your device.
- We do not collect biometric data, social security numbers, or government-issued identification.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Providing and managing the Service: To create and manage your subscription, issue license keys, deliver software updates, and enforce license terms (such as single-device usage).
- Communication: To respond to your contact form inquiries, send transactional emails (e.g., license keys, subscription confirmations), and provide customer support.
- Improving our website: To analyze aggregated, anonymized analytics data to understand how visitors use our site and to improve performance, content, and user experience.
- Payment processing: To facilitate recurring subscription billing through Stripe.
- Legal compliance: To comply with applicable laws, regulations, or legal processes.
3. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only with the following third parties, and only as necessary to operate our Service:
- Stripe (payment processing): Receives your name, email, and payment details to process subscription payments. Stripe’s privacy policy is available at stripe.com/privacy.
- Formspree (contact form processing): Receives your name, email, and message when you submit our contact form. Formspree’s privacy policy is available at formspree.io/legal/privacy-policy.
- Google Analytics (website analytics): Receives anonymized, cookie-based usage data about website visits. Google’s privacy policy is available at policies.google.com/privacy.
- Vercel (website hosting): Our website is hosted on Vercel. Vercel may process server logs that include IP addresses. Vercel’s privacy policy is available at vercel.com/legal/privacy-policy.
- Law enforcement or legal authorities: We may disclose information if required by law, subpoena, court order, or other legal process, or if we believe disclosure is necessary to protect our rights or the safety of others.
4. Method of Disclosure
All data shared with third-party service providers is transmitted securely via encrypted HTTPS connections. We share only the minimum data necessary for each provider to perform its function:
- Payment data is transmitted directly from your browser to Stripe’s servers and is never stored on our infrastructure.
- Contact form data is transmitted from your browser to Formspree’s API endpoint.
- Analytics data is collected client-side by Google Analytics scripts and transmitted directly to Google’s servers.
- License and device data is transmitted over HTTPS to our API server.
5. Data Retention
- Account and license data: Retained for the duration of your subscription and for a reasonable period after cancellation to handle disputes or reactivation.
- Contact form submissions: Retained only as long as necessary to respond to and resolve your inquiry.
- Analytics data: Retained by Google Analytics according to Google’s standard data retention settings (typically 14 months).
- Payment records: Retained by Stripe in accordance with their data retention policies and applicable financial regulations.
6. Security Practices
We take the security of your information seriously and implement the following measures to safeguard it:
- Encryption in transit: All data transmitted between your browser and our servers, and between our servers and third-party providers, is encrypted using TLS/HTTPS.
- Secure payment handling: We never store, process, or have access to your full payment card details. All payment processing is handled by Stripe, which is PCI DSS Level 1 certified.
- Access controls: Administrative access to our backend systems is protected by authentication and restricted to authorized personnel only.
- Minimal data collection: We follow the principle of data minimization, collecting only the information strictly necessary to provide the Service.
- Secure hosting: Our website is hosted on Vercel, and our API infrastructure uses industry-standard security practices.
While we strive to protect your personal information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: You may request a copy of the personal data we hold about you.
- Correction: You may request that we correct inaccurate or incomplete data.
- Deletion: You may request that we delete your personal data, subject to legal or contractual retention requirements.
- Opt-out of analytics: You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on or by adjusting your browser’s cookie settings.
To exercise any of these rights, please contact us at [email protected].
8. Children’s Privacy
Lumous is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.
9. Third-Party Links
Our website may contain links to third-party websites (e.g., Stripe billing portal, social media profiles). We are not responsible for the privacy practices or content of these external sites. We encourage you to review their privacy policies before providing any personal information.
10. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time. When we do, we will revise the “Last Updated” date at the top of this page. Continued use of our website or Software after changes are posted constitutes your acceptance of the revised policy.
11. Governing Law
This Privacy Policy is governed by the laws of Ontario, Canada.
12. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at [email protected].
