Luma POS Privacy Policy
Last Updated: January 4, 2026
Luma POS ("Luma," "we," "us," or "our") values your privacy and is committed to protecting personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you access or use the Luma POS platform, applications, and services (collectively, the "Service").
This Privacy Policy is incorporated into and forms part of the Luma POS Terms of Service.
1. Information We Collect
1.1 Information You Provide
We collect information you provide directly to us, including:
Merchant Information
- Business name, address, and contact details
- Owner or authorized representative name
- Email address and phone number
- Business licenses and permits
- Tax identification numbers
Account Information
- Login credentials (hashed and encrypted)
- User roles and permissions
- Support communications
Transaction Metadata (Non-Card Data)
- Order details (items, amounts, timestamps)
- Device identifiers
- Location data (event or venue-level)
- Transaction status and logs
Important: Luma POS does not store full credit card numbers, CVV codes, or sensitive authentication data.
1.2 Information Collected Automatically
When you use the Service, we may automatically collect:
- IP address
- Browser and device type
- Operating system
- Usage data (pages viewed, features used)
- Log files and diagnostic data
1.3 Payment Information (Stripe)
All payment processing is handled by Stripe Connect.
- Payment card data is collected directly by Stripe
- Luma POS only receives limited payment tokens and transaction references
- Stripe's use of data is governed by Stripe's Privacy Policy and Terms
Luma POS is not the merchant of record and does not control Stripe's data practices.
2. How We Use Information
We use collected information to:
- Provide, operate, and maintain the Service
- Facilitate payment processing via Stripe Connect
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal, tax, and regulatory obligations
- Provide customer support and respond to inquiries
- Improve product performance, features, and analytics
- Enforce our Terms of Service
- Communicate service updates and operational notices
3. How We Share Information
We may share information in the following circumstances:
3.1 With Service Providers
We share data with trusted third parties who perform services on our behalf, including:
- Payment processors (Stripe)
- Cloud hosting providers
- Analytics and monitoring services
- Customer support platforms
These providers are contractually required to safeguard your information.
3.2 With Stripe
We share necessary information with Stripe to:
- Enable payment processing
- Manage fraud, chargebacks, and compliance
- Meet card network and regulatory requirements
3.3 Legal & Compliance Disclosures
We may disclose information if required to:
- Comply with laws, regulations, subpoenas, or court orders
- Respond to lawful requests from public authorities
- Enforce our agreements or protect our legal rights
- Investigate fraud or security issues
3.4 Business Transfers
If Luma POS is involved in a merger, acquisition, restructuring, or sale of assets, information may be transferred as part of that transaction.
4. Data Retention
We retain information only as long as necessary to:
- Provide the Service
- Meet legal and regulatory requirements
- Resolve disputes and enforce agreements
Transaction records may be retained for up to 7 years for financial, tax, and compliance purposes.
5. Data Security
We implement reasonable administrative, technical, and physical safeguards, including:
- Encryption in transit and at rest
- Role-based access controls
- Secure authentication mechanisms
- Continuous monitoring and logging
However, no system is 100% secure, and we cannot guarantee absolute security.
6. Your Rights & Choices
Depending on your location, you may have the right to:
- Access your personal information
- Request correction or updates
- Request deletion (subject to legal retention requirements)
- Object to certain processing activities
Requests can be submitted using the contact details below.
7. Merchant Responsibilities
As a merchant using Luma POS, you are responsible for:
- Posting your own customer-facing privacy notice (if required)
- Obtaining customer consent where legally required
- Complying with applicable data protection laws
- Ensuring your staff follows data protection best practices
8. Children's Privacy
Luma POS is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children.
9. International Users
Luma POS is operated in the United States. If you access the Service from outside the U.S., you consent to the transfer and processing of information in the United States.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
- Material changes will be communicated via email or in-app notice
- Continued use of the Service after updates constitutes acceptance
11. Contact Information
For privacy-related questions or requests:
Luma POS
Email: support@lumapos.co
12. Acknowledgment
By using Luma POS, you acknowledge that you have read, understood, and agree to this Privacy Policy.