Legal

Privacy Policy

Last updated: 23 September 2026

This policy explains what data Lumnya handles, why we handle it, how long we keep it, and the rights you have over it. It covers merchants who use Lumnya, the shoppers of their stores, and visitors to lumnya.ai.

01Who we are

Lumnya is operated by EMARKSS LTD, a company registered in England & Wales (Company No. 16181893), 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE (“EMARKSS”, “we”, “us”).

For merchant account data and for data collected on lumnya.ai, EMARKSS acts as the data controller. For store data and end-customer data processed inside a merchant's Lumnya workspace, EMARKSS acts as a data processor on the merchant's behalf, under our Data Processing Addendum (DPA). The merchant remains the controller of their customers' data.

02Scope

This policy applies to: (a) merchants and their staff using the Lumnya app and dashboard; (b) end customers who interact with the Lumnya chat assistant on a merchant's storefront; and (c) visitors to lumnya.ai, including anyone who submits a form on this site.

03Data we collect

Merchant data: account details (name, email address), store connection metadata, plan and billing status, settings and configuration, and support correspondence.

Store data (processed on the merchant's behalf): products, orders, customers, discounts, policies, and related commerce records made available through the Shopify connection, strictly under the access scopes the merchant granted at install.

End-customer conversational data: messages exchanged with the chat assistant on a merchant's storefront, including any images a shopper chooses to upload, and the order or cart details needed to resolve the shopper's request. Lumnya also receives the checkouts Shopify reports for the store — the shopper's email address, name, the items and totals, and whether they agreed to marketing — to show the merchant their abandoned checkouts and, only if the merchant switches reminders on, to email shoppers who agreed to marketing (or every shopper, where the merchant chooses that and takes responsibility for the legal basis).

Usage and diagnostic data: product analytics, error and performance logs, and the audit trail of actions taken through Lumnya (what changed, who approved it, and the recorded reasoning).

Website data: if you submit a form on lumnya.ai (waitlist, contact, demo, newsletter), we collect what you type into it — typically your email address and the details of your request.

Blog comments: if you comment on the lumnya.ai blog, we collect the name and comment text you submit (published after human moderation) and your email address, which is never displayed publicly and is used only for moderation and abuse prevention. You can request deletion of your comments and associated data at any time.

04How we use data

To provide the service: answering questions from a store's live data, running analysis agents against the store's data snapshot, resolving shopper requests, and executing the actions a merchant approves.

To keep the audit trail: every consequential action is logged with what changed, who approved it, and the reasoning. This is a core safety feature of the product, not marketing data.

To operate and improve reliability: monitoring, debugging, abuse prevention, and aggregate, de-identified usage signals that help us find failures and improve quality.

To communicate with you: service messages (always), and product or marketing emails only where you have opted in — every such email includes a working unsubscribe link, never a request to write to us. Where an address is not yet on any list (a pending double opt-in), the same footer offers a one-click block instead, which also voids the confirmation link in that email.

One store's intelligence is never used to advise another merchant. Data is isolated per store.

05AI processing

Lumnya uses large language models from third-party providers (currently Google only — see sub-processors) to power the chat assistant and the analysis agents. Relevant snippets of store data and conversation content are sent to these providers to generate responses, under agreements that prohibit them from using this data to train their models.

We never use merchant data or customer data — store records, conversations, uploaded images, or anything derived from them — to train or fine-tune AI or machine-learning models, ours or anyone else's. The models only ever answer from that data; they are never taught on it.

Consequential actions proposed by the AI (price changes, refunds, emails, order edits) are confirm-gated: they only execute after explicit approval by the merchant, and each execution is written to the audit trail. Lumnya does not subject individuals to purely automated decisions with legal or similarly significant effects.

06Lawful bases

Where EMARKSS is the controller, we rely on: performance of a contract (providing Lumnya to merchants, responding to your requests); legitimate interests (service security, preventing abuse, improving the product, defending legal claims) — balanced against your rights; consent (marketing emails and all non-essential cookies on lumnya.ai — each withdrawable at any time, cookies via “Cookie preferences” in the footer); and legal obligation (accounting and tax records).

Where EMARKSS is a processor, we process store and end-customer data only on the merchant's documented instructions, as set out in the DPA.

07Sharing & sub-processors

We share personal data only with the sub-processors needed to run the service, each bound by a data-processing agreement. We never sell personal data. Current sub-processors:

Google Cloud Platform (Google) — application hosting, database, file storage, and backups — United States. · Google (Gemini API) — AI language models — United States. · Resend — transactional email delivery — European Union (Ireland). · Netlify — hosting of this website — United States. · Cloudflare — DNS, network services, and inbound email routing for our support address — global. · Sentry (Functional Software, Inc.) — error monitoring — European Union (Germany). · PostHog — product analytics — European Union.

Shopify is not our sub-processor: it is the platform through which the merchant runs their store, under the merchant's own agreement with Shopify. We will update this list before adding or replacing a sub-processor; DPA customers receive advance notice as described in the DPA.

08International transfers

Our primary infrastructure runs on Google Cloud in the United States. Where personal data of UK or EEA individuals is transferred outside the UK/EEA, we rely on: the EU–US Data Privacy Framework and its UK Extension where the recipient is certified; and otherwise Standard Contractual Clauses (and the UK International Data Transfer Addendum) with supplementary measures where appropriate.

09Retention

We keep data no longer than it is needed. Default retention windows in the product: chat transcripts — 90 days, adjustable by each merchant from 7 to 365; shopper-uploaded chat images — 90 days; abandoned cart records and the log of reminder emails sent for them — 90 days; behavioral and conversation analytics events — 180 days.

Waitlist and website form submissions are kept while the early-access program runs, and deleted when it ends or when you ask us to remove you — whichever comes first.

Chat transcripts (and any photos a shopper uploads) are kept for the window each merchant sets in the app — 90 days by default, adjustable from 7 to 365 days, uploaded photos never longer than 90 — and are deleted by a daily job once a conversation's last message is older than that. Support tickets are retained while the merchant's account is active. Business intelligence derived for a store (agent findings, verified facts, the audit trail) persists for as long as the account is active — because that accumulated memory is the product.

When a merchant uninstalls Lumnya or deletes their account, we delete the store's workspace data in line with our DPA and Shopify's mandatory deletion timelines, subject only to legal holds and backups that expire on a 90-day cycle.

10Security

Measures include: strict per-store data isolation enforced at the data-access layer; encryption in transit (TLS) and at rest; secrets kept in a managed secret store, never in code; least-privilege service accounts; confirm-gating on consequential actions; full audit logging; daily backups with tested restore procedures; and multi-factor authentication on operator accounts. No internet service can promise absolute security, but security failures are treated as product failures here.

11Your rights

Depending on your location, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time where processing is based on consent. Write to contact@lumnya.ai and we will respond within one month.

If you are a shopper on a store that uses Lumnya, please contact the merchant first — they control your data, and we are contractually bound to help them fulfil your request. We also implement Shopify's mandatory privacy webhooks, so data-subject requests and erasures initiated through Shopify are honored automatically. A shopper can also ask the store's chat assistant to erase their data: the erasure runs once they confirm it through a single-use link emailed to that address, and the store is notified.

12Your US state privacy rights

If you are a resident of California, Texas, Colorado, Virginia, or another US state with a comprehensive privacy law, you may have the right to know about and access the personal information collected about you, to correct it, to delete it, to obtain a portable copy, and to opt out of the “sale” or “sharing” of personal information and of targeted advertising and certain profiling. You have the right not to be discriminated against for exercising these rights.

EMARKSS does not sell or share personal information, and does not use it for cross-context behavioral advertising. Where EMARKSS acts as a service provider or processor for a merchant, it uses the personal information only to provide the service on the merchant's documented instructions, and does not retain, use, or disclose it for any purpose other than those instructions or as permitted by law.

If you are a shopper on a store that uses Lumnya, the merchant is the business/controller of your data — send your request to the merchant, and we will assist them in fulfilling it (requests raised through Shopify are honored automatically). For personal information for which EMARKSS is the business/controller (merchant account data and lumnya.ai website data), or to ask a question about these rights, write to contact@lumnya.ai; you may use an authorized agent. We verify and respond within the timeframe the applicable law requires.

13Children

Lumnya is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.

14Complaints

If you are unhappy with how we handle your data, contact us first at contact@lumnya.ai — we take this seriously. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority in the EEA.

15Contact & updates

Privacy questions go to contact@lumnya.ai (subject: “Privacy”). We will post updates to this page and, for material changes, notify merchants by email before they take effect. The “Last updated” date above always reflects the current version.

Questions about this document? Write to contact@lumnya.ai. EMARKSS LTD · Company No. 16181893 · 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE.