Legal
Cookie Policy
Last updated: 18 September 2026
This policy lists the cookies and similar browser storage that lumnya.ai and the Lumnya product actually set. The short version: this website uses essential storage only, there are no advertising or cross-site tracking cookies anywhere in Lumnya, and the storefront chat widget keeps its optional storage only with the shopper's consent — and sets no cookies at all.
01What cookies are
Cookies are small files a website stores in your browser; localStorage is a similar browser storage mechanism that is not sent to servers automatically. Both can be “essential” (needed for the site to work) or “non-essential” (analytics, preferences, marketing). The law treats them the same way: non-essential storage requires your consent.
02What this website (lumnya.ai) uses
lumnya-consent-v1 (localStorage, essential): remembers that you dismissed the storage notice, so we don't show it again. Kept until you clear your browser data.
We also run Cloudflare Web Analytics, which counts page views without cookies and without any browser storage — nothing is placed on your device and no individual is identified.
That's it. The marketing site sets no advertising or third-party tracking cookies today. If we introduce them, we will ask for your consent with a real accept/reject banner before anything non-essential is set, and update this page first.
03What the Lumnya app uses (merchants)
Inside the Shopify admin, Lumnya uses Shopify's own session mechanisms to authenticate you — governed by Shopify's cookie policy.
The standalone dashboard sets one essential, signed session cookie so you stay logged in (expires after 8 hours). The operator console (staff-only) similarly sets an essential authentication session cookie. Neither is used for tracking, and no advertising cookie is ever set inside the product.
04What the storefront chat widget uses (shoppers)
The chat widget sets no cookies. Everything it keeps lives in the shopper's own browser — localStorage and sessionStorage, scoped to the merchant's store — contains no advertising identifiers, and is never used to track shoppers across different websites or stores. It falls into three groups:
Necessary (always): a random session identifier and a per-session owner key, so a conversation can continue across pages and only the browser that started it can read it; the open conversation's messages while the chat is in use, and the last-activity timestamp that expires them. Without these the chat cannot work.
Preferences (only with consent): the conversation history, so a shopper can pick up where they left off, kept for 7 days of inactivity and then deleted. The widget keeps this only after the shopper has consented through the store's own cookie banner — it reads that choice via Shopify's Customer Privacy API — or where no banner is required for that visitor, or where the merchant has switched consent gating off for their store.
Analytics (only with consent, under the same rule): which proactive message was shown or fired, so the shopper is not shown it twice, a per-store visit counter, and session-only signals about the current visit (the pages viewed and which assistant actions were used) that go when the browser session ends. Nothing in this group identifies the shopper.
To clear it, delete the store's site data in your browser settings; the session-scoped part goes when the browser session ends. Withdrawing consent in the store's cookie banner stops the optional groups from being kept. Blocking storage entirely may stop the chat from keeping a conversation across pages.
05Managing cookies
You can clear or block cookies and site data in your browser settings at any time. Blocking essential storage may break login sessions or the chat widget's ability to keep a conversation. Because this website sets no non-essential cookies today, there is nothing to opt out of here; for the storefront chat widget, the choice is made in the store's own cookie banner, as described above.
06Changes
If our use of cookies changes — in particular if any non-essential category is introduced — we will update this page, refresh the “Last updated” date, and ask for consent where required before the change takes effect.