Privacy policy
Privacy Policy
Last updated: May 18, 2026
Lumée ("we", "us", "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights regarding it. This policy applies to uselumee.com and all related services we provide.
1. Information We Collect
Information you give us directly:
- Name, billing and shipping address, email, phone number, and payment information when you place an order or sign up for our email list;
- Communications you send us (support emails, survey responses, reviews);
- Photos, videos, or written content you submit to the Site or our social channels.
Information collected automatically:
- Device information (browser type, operating system, screen size, IP address);
- Usage information (pages visited, links clicked, time on Site, referring URL);
- Cookies, pixels, and similar technologies (see Section 5);
- Approximate geographic location derived from your IP address.
Information from third parties:
- Payment processors confirm transaction success or failure;
- Shipping carriers share tracking and delivery confirmation;
- Marketing platforms (Meta, TikTok, Google) share advertising engagement data when you arrive via an ad;
- Customer-review platforms share your reviews (if you submit them);
- Analytics providers share aggregated traffic data.
2. How We Use Your Information
- To process, fulfill, and ship your orders, including handing your address to our fulfillment partner;
- To respond to your customer-service inquiries;
- To send transactional emails (order confirmations, shipping notifications, refund confirmations);
- With your consent, to send marketing emails about new products, promotions, and brand updates;
- To prevent fraud, abuse, and chargeback fraud;
- To improve our products, content, and customer experience;
- To comply with legal obligations and respond to lawful requests by public authorities.
3. How We Share Your Information
We do not sell your personal information. We share it only with the following categories of recipients:
- Fulfillment partners — our dropship and warehouse partners receive your name, address, and order details to ship your product. We use Zendrop and its affiliated carriers.
- Payment processors — Shopify Payments, PayPal, and other processors receive payment information directly via secure encrypted channels. We do not store full credit card numbers on our servers.
- Marketing and analytics platforms — Meta, TikTok, Google Analytics, Klaviyo, and similar receive event data (page views, purchases, conversions) for the purpose of measuring and optimizing advertising. These platforms operate under their own privacy policies.
- Customer-service tools — Shopify, our email service provider, and other vendors that help us run the business may have access to your information solely for the purpose of providing that service.
- Legal authorities — when required by law, court order, or to protect our legal rights, prevent fraud, or protect the safety of others.
- In the event of a merger or acquisition — if Lumée is acquired by, merges with, or sells its assets to another company, your information may be transferred as part of that transaction.
4. International Data Transfers
Lumée operates from the United States and uses fulfillment partners that may be located in China, the United States, or other jurisdictions. By using the Site, you consent to the transfer of your information across international borders, including to jurisdictions that may not have the same data-protection laws as your home country. We rely on standard contractual clauses or equivalent safeguards where required by applicable law.
5. Cookies, Pixels, and Tracking Technologies
We and our third-party partners use cookies, pixel tags, and similar technologies to recognize your browser and improve your experience. These technologies do the following:
- Essential cookies — required for the Site to function (shopping cart, checkout). These cannot be disabled.
- Functional cookies — remember your preferences (region, language).
- Analytics cookies — measure how visitors use the Site (Google Analytics, Shopify Analytics).
- Advertising cookies and pixels — used by Meta, TikTok, Google, and similar platforms to measure ad effectiveness and serve relevant ads.
You can control cookies in your browser settings. Note that disabling certain cookies may impair the function of the Site, especially checkout.
6. Your Privacy Rights
All users:
- Access — request a copy of the personal information we hold about you;
- Correction — request that we correct inaccurate information;
- Deletion — request that we delete your personal information (subject to legal exceptions, such as retaining order records for tax purposes);
- Opt-out of marketing — unsubscribe from marketing emails at any time using the unsubscribe link in any email, or by emailing us.
Residents of the European Union, UK, and similar jurisdictions (GDPR rights):
- The legal bases for our processing are: (a) performance of a contract (to fulfill your order), (b) legitimate interests (to operate and improve our business), and (c) your consent (for marketing communications);
- The right to data portability;
- The right to object to processing based on legitimate interests;
- The right to restrict processing in certain circumstances;
- The right to lodge a complaint with your local data-protection authority.
Residents of California (CCPA / CPRA rights):
- The right to know what personal information we collect and how we use it;
- The right to delete your personal information (subject to legal exceptions);
- The right to correct inaccurate information;
- The right to opt-out of the "sale" or "sharing" of personal information for cross-context behavioral advertising — to exercise this right, visit our Your Privacy Choices page;
- The right to non-discrimination for exercising these rights.
To exercise any of these rights, email hello@uselumee.com with a clear description of your request. We will respond within 30 days (or sooner where required by law). We may need to verify your identity before fulfilling certain requests.
7. Data Retention
We retain personal information for as long as needed to fulfill the purposes outlined in this policy, including legal, accounting, or reporting requirements. Typically:
- Order and transaction records: 7 years (tax-record retention requirement);
- Customer-service emails: 2 years from last contact;
- Marketing email subscribers: until you unsubscribe or 3 years of inactivity;
- Analytics data: retained in aggregated, de-identified form indefinitely; individual-level data per the analytics provider's policy.
8. Security
We use commercially reasonable measures to protect your personal information, including SSL/TLS encryption for all data transmitted between your browser and our Site, encryption-at-rest for stored data via Shopify's infrastructure, and access controls. No method of transmission over the internet or method of electronic storage is 100% secure; we cannot guarantee absolute security.
If we become aware of a security breach affecting your personal information, we will notify you within 72 hours where required by applicable law (e.g., GDPR Article 33).
9. Children's Privacy
The Site is not directed to children under 13 years of age (or 16 in the European Union). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at hello@uselumee.com and we will delete it promptly.
10. Do Not Track Signals
Some browsers transmit "Do Not Track" signals. Because there is no industry-standard interpretation of these signals at this time, the Site does not respond to them. You can use the controls in Section 5 and Section 6 to limit tracking.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will post the updated policy on this page and update the "Last updated" date. Continued use of the Site after the changes constitutes acceptance of the updated policy.
12. Contact Us
Privacy questions or requests: hello@uselumee.com. For GDPR-related inquiries, please include "GDPR" in the subject line. For CCPA-related inquiries, include "CCPA". A real person reads every email.