LumaReviewBack to home
Your information

Privacy Policy

This policy explains how personal information is handled when businesses use LumaReview and when their customers respond to a review request.

Last updated 28 July 2026

1. Who we are

LumaReview is operated by Michael Overton, trading as LumaReview in the United Kingdom. Questions about this policy or our use of personal information can be sent to support@lumareviews.co.

2. When we are controller or processor

For account administration, security, billing and operation of the LumaReview service, LumaReview acts as a data controller. When a client business uploads a customer’s name and email address, sends a review request, or receives feedback, that business decides why the information is used. The business is normally the controller and LumaReview processes the information on its behalf.

If you received a review request, the business named in that email is the best first contact for questions about why it used your information.

3. Information we collect

  • Account details: name, email address, password hash, login sessions and account status.
  • Business settings: business name, sender name, Google review URL and encrypted SMTP configuration.
  • Review-request information: customer name and email, unique request token, delivery time, selected rating and private feedback.
  • Billing information: Stripe customer, subscription and price identifiers, billing interval and subscription status. LumaReview does not store full payment-card details.
  • Security and diagnostic information: request timestamps, rate-limit records, encrypted authenticator-app secrets, hashed recovery codes, passkey public keys and usage counters, IP or forwarding information available in server logs, and error information. Passkey biometrics remain on your device and are not received by LumaReview.
  • Messages: information supplied when someone contacts us for support, privacy or legal enquiries.

4. How and why we use information

Provide the serviceTo create accounts, send requested emails, display dashboards and process feedback. For account users this is necessary to perform our contract; for review recipients it supports the legitimate interests of the client business in requesting genuine feedback.
Security and abuse preventionTo authenticate users, enforce rate limits, investigate misuse and protect the service. We rely on legitimate interests in maintaining a secure service.
Billing and administrationTo manage subscriptions, payments, records and service communications. We rely on contract and, where applicable, legal obligations.
Support and improvementTo answer enquiries, diagnose faults and improve reliability. We rely on contract and legitimate interests.
Legal complianceTo establish, exercise or defend legal claims and comply with lawful requests or accounting requirements.

5. Where information comes from

Account users provide their own account and business information. A review recipient’s name and email address normally come from the client business that had the customer interaction. Ratings and feedback come directly from the recipient when they use their unique request link.

6. Who we share information with

We share information only where needed to operate the service, including with the relevant client business, hosting and infrastructure providers, the SMTP provider chosen by that business, Stripe for subscription billing, and professional advisers or authorities where legally required. We do not sell personal information.

Some providers may process information outside the UK. Where required, transfers are protected using an adequacy decision or appropriate contractual safeguards.

7. Retention

We keep account and service data while an account is active and for a reasonable period afterwards where needed for security, support, disputes, accounting or legal obligations. Review-request information is retained for the client business until the account or relevant records are deleted. Encrypted backups may remain for a limited backup cycle before being overwritten. We delete or anonymise information when it is no longer needed.

8. Security

We use access controls, password hashing, protected sessions, optional authenticator-app two-factor authentication, passkeys, encrypted SMTP passwords and authenticator secrets, TLS and database isolation measures. No online service can guarantee absolute security, and account users must keep their passwords, recovery codes and SMTP credentials confidential.

9. Cookies

LumaReview uses an essential, HTTP-only session cookie to keep account users signed in. It is required for the dashboard to work. We do not currently use advertising or analytics cookies.

10. Your rights

Depending on the circumstances, UK data-protection law may give you rights to access, correct, erase or restrict personal information, object to processing, receive portable data, or complain about how it is used. These rights are not absolute.

Review recipients can contact the business named in their email or contact us at support@lumareviews.co. You may also complain to the Information Commissioner’s Office.

11. Changes to this policy

We may update this policy as the service or law changes. The latest version will be published here with its updated date. Material changes affecting account users may also be communicated through the service or by email.

Privacy PolicyTerms of Servicesupport@lumareviews.co© 2026 LumaReview