Privacy policy.
What we collect, why we collect it, and what we won't do. Written to be readable, not legally bulletproof — the binding obligations live in our GDPR notice.
What we collect
Booking essentials: name, contact (email or phone), the salon and service you booked, the time, any deposit. Account essentials if you sign up: a single login method (email link or password), a display name, an optional phone for confirmations. Operational essentials: the device and browser you used (for security), and the salon's public-facing data (services, prices, photos).
Why we collect it
To deliver the service you asked for: confirm the booking, remind you it's coming up, let the salon prepare. To keep the platform safe: detect fraud, prevent slot abuse, support disputes. To improve Lumi: aggregate, anonymous metrics about how the booking flow performs. We don't profile you for advertising; Lumi has no advertising surface.
What we share, and with whom
With the salon you booked: your name, contact details, and the booking. With Stripe: payment details, only when you pay a deposit (Stripe is the processor; we don't store card numbers). With Resend / Twilio: your email or phone, only to deliver booking confirmations and reminders. With Supabase: as our database vendor, under a Data Processing Agreement. We don't sell your data and we won't.
How long we keep things
Active booking history: as long as your account is open. Closed account: we keep operational records for 24 months for fraud-prevention and tax compliance, then delete. Marketing emails: never, because we don't send them. Logs: 30 days, then aggregated and anonymised.
Your rights
Access: ask for a copy of your data. Rectification: correct anything that's wrong. Erasure: delete your account and the personal data attached to it. Portability: export your data as CSV. Objection: tell us to stop processing for a specific purpose. Email [email protected] to exercise any of these. We respond inside 30 days.
Marketing
Lumi never sends you marketing email or SMS for products or services we don't offer. The only messages you'll receive are: booking confirmations, reminders, and changes to bookings you made. You don't have to opt out — there's nothing to opt out of.
Cookies
We use a small number of strictly necessary cookies: a session cookie to keep you signed in, a CSRF cookie to prevent attacks, a theme-preference cookie so light/dark stays consistent. We don't use advertising cookies, and we don't run third-party analytics with cross-site tracking. Sentry is the only third-party SDK in the stack; it's used for error reporting and IP-anonymises by default.
Children
Lumi isn't directed at children under 16. If you're under 16, please don't create an account; ask a parent or guardian to book on your behalf.
Changes to this policy
We'll update this page when something material changes — and email you if you have an account. The current version is always at /legal/privacy. The 'last updated' date at the top is canonical.
Contact our DPO
Privacy questions, data requests, or anything else: [email protected]. Subject line 'Privacy' speeds it through to the right person.