Who this covers
This policy covers the Lumora marketing site (lumorastudiodigital.com) and the Lumora automation platform, operated by {{LEGAL_ENTITY}}. It applies to three groups: people browsing the site, business owners with a platform workspace, and — indirectly — the customers who message those businesses on WhatsApp.
If you only read the marketing site, the story is short: no analytics scripts, no tracking pixels, no account. The rest of this page is mostly about the platform.
What we store, and why
- Account basics: your email address and password pass through the application server to Supabase Auth for sign-in or account creation. The application does not save passwords in its workspace tables.
- Workspace details — business name, industry, timezone, and the owner WhatsApp number if you add one. Used to run your flows in the right context.
- Integration credentials — Google Calendar refresh tokens and WhatsApp or payment-provider access tokens. Encrypted at rest and never returned to the browser after you save them.
- Customer conversations — once you connect WhatsApp, the messages your customers send (name, phone number, message text) and the replies the automation sends. Stored so your team can pick up where the flow left off.
- Leads and bookings — intake answers, lead scores, booking dates, and payment-link references your flows create.
- Server logs: the hosting service may record request information, including IP addresses and user agents, for operation and debugging. The application adds no analytics or advertising trackers; provider log retention needs confirmation for the deployment.
Your customers' messages: you're in charge, we're the plumbing
For conversation content, the business owning the workspace is the data controller and Lumora is a processor: we store and route messages on your instructions so your flows work. You're responsible for having a lawful basis to message your customers — in practice, WhatsApp opt-in — and for honoring their requests.
If one of your customers asks us directly to delete their messages, we'll loop you in and help you do it, or do it on your instruction.
Who else touches the data
We use a small set of processors, each for one job:
- Supabase — database, authentication, and row-level tenant isolation. This is where workspace data lives.
- Vercel — application hosting and the request logs mentioned above.
- Meta (WhatsApp Cloud API) — message delivery. What you send through WhatsApp is also subject to Meta's own terms.
- Google — calendar events, only if you connect Google Calendar. We store the refresh token encrypted and create the events you asked for.
- Stripe and Xendit: optional payment links for a business’s customer bookings, separate from Lumora subscription billing. The current early-access connection accepts test credentials only.
We do not sell personal information, share it for cross-context behavioral advertising, or run any ad network code.
How long we keep things
Workspace data is stored in the configured database. There is no self-service workspace-deletion control or automatic deletion schedule in the current platform. Contact us to request removal; the deletion process and retention periods need confirmation before live customer data is collected.
Disconnecting Google Calendar revokes its token with Google before removing the saved credential. Disconnecting an integration does not delete past conversations, leads, or bookings.
Your rights (GDPR, UK GDPR, CCPA/CPRA)
Wherever you are, we honor the strongest version: ask what we hold about you, get a copy in a portable format, correct it, restrict or object to how it's used, or have it deleted. EU and UK residents can also complain to their supervisory authority. California residents have the rights to know, correct, and delete, and to opt out of sale or sharing — moot here, because we don't sell or share personal information as the CCPA defines those terms.
To exercise any of these, email us or message us on WhatsApp from the address or number tied to your account. We answer within 30 days, usually much faster, and we never treat anyone worse for exercising a right.
Cookies used by the application
NEXT_LOCALE remembers your language choice. Supabase authentication cookies keep you signed in, and a temporary security cookie protects the Google connection flow. Local mock previews also use cookies to remember simulated connections.
The application does not include analytics or advertising scripts. Any additional cookies or tracking added by the deployment need to be reviewed before launch.
Where the data lives
Our providers (Supabase, Vercel, Meta, Google, Stripe, Xendit) run global infrastructure, so data may be processed outside your country, including in the United States. Where GDPR applies, transfers rely on the providers' standard contractual clauses and equivalent safeguards.
When this policy changes
We update the date at the top and, for anything material, tell workspace owners directly by email or WhatsApp before it takes effect.
Talk to a human
Email contact@lumorastudiodigital.com or use the WhatsApp button in the footer. Privacy questions go to the same people who wrote the code.