Luminous Social Privacy Policy
Luminous Social© · owned by 1602637 B.C. Ltd.
Last Updated: August 7, 2026
1. Introduction
This Privacy Policy explains how 1602637 B.C. Ltd. ("Company," "we," "us," or "our"), doing business as Luminous Social, collects, uses, shares, and protects personal information when you visit luminoussocial.com or use the Luminous Social dashboard and related services (the "Service").
Luminous Social is owned and operated by 1602637 B.C. Ltd., a British Columbia corporation.
By using the Service, you acknowledge this Policy. If you do not agree, please do not use the Service.
Privacy contact: luminoussocialhelp@gmail.com
2. Roles: Controller and Processor
For personal data about agency account holders (owners, admins, and members)—such as name, email, billing identifiers, and account preferences—we act as a data controller (or “business”).
For personal data and marketing data that agencies process about their clients or end users through the Service (including metrics and content from connected ad/social accounts), the agency is the controller and we act as a processor (or “service provider”), processing that data only to provide the Service on the agency’s instructions.
Agencies are responsible for providing required notices to their clients and for having a lawful basis to process client data in the Service.
3. Who This Policy Covers
This Policy applies to agency users, visitors to our marketing site, and individuals whose information is processed when agencies connect client accounts or upload client-related data.
4. Information We Collect
We collect information in the following categories:
- Account and business data: legal name, email address, password (hashed), agency or business name, individual/corporation status, country, province/state/region, optional city, team size, role, preferences, signup date, and legal-acceptance records.
- Billing and subscription data: plan, subscription status, billing cycle, subscription and renewal dates, cancellation status, and payment-related identifiers processed by Stripe (we do not store full card numbers).
- Workspace / Customer Data: clients, notes, reports, schedules, goals, media, content drafts, and settings you create.
- Integration data: OAuth tokens, account IDs, property IDs, profile names, and metrics from connected platforms (Meta, Google, TikTok, LinkedIn, Snapchat, Shopify, Stripe Analytics, HubSpot, Klaviyo, Mailchimp, and similar).
- Usage and device data: log data, IP-derived approximate location, browser/device type, pages viewed, and feature usage.
- Support communications: messages to our support email or in-product contact forms.
- AI inputs/outputs: prompts and generated text or insights you request through AI features.
5. How We Collect Information
We collect information you provide directly, information we receive from Integrations when you authorize a connection, and information collected automatically through cookies or similar technologies.
6. Lawful Bases (Where Applicable)
Where GDPR/UK GDPR or similar laws apply, we process personal data based on: performance of a contract (providing the Service); legitimate interests (securing and improving the Service, preventing abuse); consent (certain marketing or non-essential cookies, where required); and legal obligation (tax, accounting, compliance).
7. How We Use Information
We use personal information to:
- Provide, maintain, and improve the Service (reports, dashboards, scheduling, publishing).
- Authenticate users, manage team access, and secure accounts.
- Connect and refresh Integrations you authorize.
- Process subscriptions and send transactional emails (billing, invites, report delivery, security notices).
- Maintain a private, owner-access customer and subscription history for account administration, invoicing, financial reconciliation, tax and accounting recordkeeping, legal compliance, audits, and billing or other disputes.
- Provide customer support.
- Generate AI-assisted insights and content at your request.
- Monitor reliability, prevent abuse, and comply with law.
- Send product or marketing emails where permitted. Commercial electronic messages are sent in compliance with Canada’s Anti-Spam Legislation (CASL) and the U.S. CAN-SPAM Act: we send them only with consent or another lawful basis, identify ourselves, and include a working unsubscribe mechanism honored promptly. Transactional emails are required to operate the Service.
7a. No Misuse of Data
We have no intention to misuse personal information or Integration data. We process data only for the purposes described in this Policy: providing, securing, and improving the Service you request.
We do not sell personal information. We do not rent or trade Customer Data or TikTok/other Integration data. We do not use platform data to spam users, to build unrelated advertising audiences for sale, or for any purpose incompatible with providing agency reporting, insights, and publishing tools.
Access to Customer Data and Integration tokens is limited to operating the Service, providing support you request, and meeting legal obligations.
8. Third-Party Platforms (Including TikTok)
If you connect TikTok or other platforms, we receive credentials and data those platforms make available through their APIs (such as advertiser or account identifiers, campaign/performance metrics, profile information, and—where you enable publishing—content you choose to post).
We use Integration data only to provide features you request (analytics reporting, insights, scheduling, and publishing you initiate). We will not misuse TikTok or other Integration data. We do not sell it, do not use it for unrelated advertising profiles, and do not use it outside the Service purposes described here.
Your use of TikTok and other platforms remains subject to their terms and privacy policies. You can disconnect an Integration in the Service; tokens may also be revoked in the third-party account settings. After disconnect, we stop new data pulls and invalidate tokens per our retention practices.
We may share limited technical data with those platforms as required to complete OAuth, API calls, or publishing you initiate.
8a. Google User Data (Limited Use)
If you connect Google services (including Google Analytics, Google Ads, Search Console, and YouTube Analytics), we access Google user data that you authorize through Google’s OAuth consent screen—typically account/property identifiers, performance and analytics metrics, and related configuration needed to generate reports and insights in the Service.
We use Google user data only to provide and improve user-facing features of Luminous Social that are visible in the product (client reporting, dashboards, algorithm-built report summaries based on connected metrics, AI Strategist insights, and related agency workflows). We do not use Google user data for any other purpose.
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements (see https://developers.google.com/terms/api-services-user-data-policy).
- We do not sell Google user data.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features (for example trusted subprocessors under contract), to comply with applicable law, or as part of a merger/acquisition with notice where required—and not for any other purpose.
- Human access to Google user data is limited to cases where a user gave us permission to investigate a support issue, where required for security/compliance, or where necessary for the operation of the Service with appropriate controls.
- You may disconnect Google Integrations in the Service at any time, and you may revoke access in your Google Account permissions. After disconnect or revoke, we stop new Google API access and invalidate tokens per our retention practices.
9. Artificial Intelligence
AI features may send prompts and limited context you provide to AI providers to generate outputs. We do not use Customer Data to train our own foundation models. We prefer provider settings that limit training on customer inputs where available; third-party provider policies also apply and may change.
Do not include unnecessary sensitive personal data in AI prompts.
11. Subprocessors
We use carefully selected service providers. Core subprocessors include:
- Supabase — authentication, database, and file storage.
- Vercel — application hosting and delivery.
- Stripe — subscription billing and payment processing.
- Resend — transactional and product email delivery.
- OpenAI — AI model inference for assisted features you request.
- Connected advertising/social platforms (Meta, Google, TikTok, etc.) — only when you authorize a connection.
11a. Subprocessor Updates
We may update subprocessors from time to time as we change vendors. Material changes will be reflected in this Policy. A security overview is also available at https://luminoussocial.com/help.
12. Data Retention
Account, authentication, business, consent, and product data are primarily stored using Supabase. Subscription and payment records are also processed and stored by Stripe, and the application is hosted through Vercel. Authorized owner personnel can view limited account and subscription fields through a protected internal directory for the purposes described in Section 7. These providers may process data in the locations described in Section 15.
We retain account and workspace data while your account is active and for a reasonable period afterward for backups, legal compliance, dispute resolution, and fraud prevention.
You may request deletion of your account and associated personal data by emailing luminoussocialhelp@gmail.com. We may retain limited account, consent, transaction, invoice, subscription, cancellation, refund, and deletion records for as long as reasonably necessary or legally required for tax, accounting, corporate recordkeeping, audits, fraud prevention, legal claims, and regulatory compliance. Retained records remain access-restricted and are not used for unrelated marketing. Integration tokens are deleted or invalidated when you disconnect an Integration or close your account, subject to backup cycles.
13. Security and Incidents
We use industry-standard measures including HTTPS encryption in transit, hashed passwords, access controls, and protected databases. No method of transmission or storage is 100% secure.
If we become aware of a security incident affecting personal information, we will investigate and notify affected users and regulators as required by applicable law.
More detail: https://luminoussocial.com/help
15. International Transfers
We may process and store information in the United States, Canada, and other countries where we or our subprocessors operate. Where required, we use appropriate safeguards for cross-border transfers.
For Canadian users: personal information may be stored and processed outside Canada (including in the United States). While outside Canada, it is subject to the laws of the jurisdiction where it is held and may be accessible to courts, law enforcement, and national security authorities of that jurisdiction. Questions about our transfer practices may be sent to the privacy contact below.
16. Your Privacy Rights
Depending on your location (including EEA/UK and certain U.S. states), you may have rights to access, correct, export, delete, or restrict processing of personal information, and to object to certain processing or withdraw consent where processing is consent-based.
To exercise these rights, email luminoussocialhelp@gmail.com. We will verify your request and respond within the time required by applicable law. You may also have the right to lodge a complaint with a supervisory authority.
17. U.S. State Privacy Disclosures (Including California)
We collect the categories of personal information described in Section 4. We use them for the business purposes described in this Policy.
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising as defined by the CCPA/CPRA.
California residents may request to know, delete, or correct personal information, and may use an authorized agent, by contacting luminoussocialhelp@gmail.com. We will not discriminate against you for exercising privacy rights.
Residents of other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Texas, Oregon, and Utah) may have similar rights to access, correct, delete, and port personal data, and to opt out of targeted advertising, sale, and certain profiling. We do not engage in the sale of personal data or targeted advertising as defined by those laws. To exercise a right, or to appeal a decision we make on a request, contact the email above.
17a. Canadian Privacy Disclosures (PIPEDA and Provincial Laws)
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector privacy laws, including British Columbia’s Personal Information Protection Act (PIPA) and, for Quebec residents, the Act respecting the protection of personal information in the private sector (as amended by Law 25).
In line with the fair information principles under those laws: we identify the purposes for collection at or before the time of collection (this Policy); we collect, use, and disclose personal information only with meaningful consent or as otherwise permitted by law; we limit collection to what is necessary for the identified purposes; we retain it only as long as needed; and we protect it with safeguards appropriate to its sensitivity.
You may, subject to limited legal exceptions: request access to your personal information and an account of how it has been used and disclosed; request correction of inaccurate information; and withdraw consent at any time on reasonable notice (which may affect our ability to provide the Service). Submit requests to our privacy contact at luminoussocialhelp@gmail.com; we respond within the time required by law (generally 30 days).
We have designated a privacy contact accountable for our compliance with these laws, reachable at the email above. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca), or your provincial privacy regulator, including the Commission d’accès à l’information du Québec for Quebec residents.
17b. European (GDPR / UK GDPR) and Australian Privacy Disclosures
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the legal bases described in Section 6 (performance of contract, legitimate interests, consent, and legal obligations), consistent with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection.
In addition to the rights in Section 16, you have the right to data portability, the right to object to processing based on legitimate interests, and the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects (we do not make such decisions). Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
When we transfer personal data outside the EEA, UK, or Switzerland (including to Canada and the United States, where our infrastructure providers operate), we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision.
You may lodge a complaint with your local data protection supervisory authority, or with the UK Information Commissioner’s Office (ico.org.uk), if you believe our processing violates applicable law. We would appreciate the chance to address your concerns first at luminoussocialhelp@gmail.com.
If you are in Australia, we handle personal information consistent with the Australian Privacy Act 1988 and the Australian Privacy Principles. You may request access to or correction of your personal information using the contact below, and you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) if you are not satisfied with our response.
18. Children’s Privacy
The Service is not directed to children under 16 (or the age required by local law). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
19. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top of the page will change when we do. Material changes will be posted on this page; continued use of the Service after changes become effective constitutes acceptance of the updated Policy.
20. Contact Us
Brand / operator: Luminous Social · Owner: 1602637 B.C. Ltd.
Privacy questions and data requests: luminoussocialhelp@gmail.com
Website: https://luminoussocial.com
Terms of Service: https://luminoussocial.com/legal/terms
Security: https://luminoussocial.com/help