Privacy Policy
Lumo Packaging is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to that information.
Effective date: 2024-01-01. Last updated: 2026-05-08.
1. Information We Collect
We collect the following categories of personal data:
- Contact & account data: name, email, phone number, company and billing details provided when you contact us or create an account. Retention: account data retained while account is active and for up to 5 years thereafter for recordkeeping.
- Transactional data: order details, invoices, and payment transaction identifiers. Retention: 7 years for tax and accounting requirements.
- Communications: inquiry messages, support correspondence and email history. Retention: up to 3 years.
- Usage & analytics: IP address, browser, device, pages visited, and interaction data collected by analytics tools. Retention: aggregated or pseudonymized where possible; raw logs retained up to 12 months.
- Cookies & tracking: see the Cookies section below for types and purposes.
2. How We Use Your Information
We process personal data for the following purposes and legal bases (where applicable):
- To provide services and process orders — performance of a contract (GDPR Art.6(1)(b)).
- To respond to inquiries and customer support — legitimate interests (Art.6(1)(f)) and where required, consent.
- To comply with legal obligations — legal compliance (Art.6(1)(c)).
- To improve our website and marketing — legitimate interests and, where required, your consent.
Your Rights
Where applicable, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion (erasure) or restriction of processing.
- Object to processing based on legitimate interests or for direct marketing.
- Request data portability where processing is based on consent or contract.
To exercise these rights, contact us using the details below. We may need to verify your identity before responding.
Cookies and Tracking
We use cookies and similar technologies for:
- Essential cookies: required for site functionality (session cookies).
- Performance & analytics: Google Analytics or similar for traffic and usage metrics (opt-out available via browser controls).
- Functional cookies: remember preferences and UI states.
- Advertising & targeting: third-party services may set cookies for personalized ads; opt-out instructions are available from the providers.
You can manage or disable cookies through your browser settings, but disabling certain cookies may affect site functionality.
Third-Party Services
We use third-party providers for analytics, hosting, payments and email. These providers process data on our behalf under contracts that include data protection obligations. Examples include:
- Hosting & CDN: Vercel, Supabase (storage)
- Analytics: Google Analytics
- Payments: Stripe/checkout partners (where used)
- Transactional email: Brevo
International Transfers
Personal data may be transferred to, and stored in, countries outside your jurisdiction. Where transfers occur we rely on adequacy decisions, standard contractual clauses, or other appropriate safeguards.
Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect personal data from children; if we become aware we will take steps to delete it.
Changes to This Policy
We may update this policy from time to time. When we do, we will update the effective/last-updated date above. For material changes, we will provide a more prominent notice.
Contact & Data Protection Officer
For privacy-related questions or to exercise your rights, contact our DPO at privacy@lumopackaging.com.
