Legal

Privacy Policy

Privacy Policy

Last updated: 2025-11-17

This Privacy Policy explains how Lumenchain ("we", "us") collects, uses, and protects information when you use the merchant portal, customer portal, APIs, SDKs, and related sites (the "Services").

1. Information We Collect

  • Account and contact data: names, emails, company details, phone numbers, and support messages you provide.
  • Usage data: logs of API calls, webhook delivery results, browser type, pages viewed, and timestamps.
  • Billing data: plan metadata, subscription IDs, payment method references, and invoice records handled through the payments service.
  • Technical data: IP addresses, device characteristics, and basic analytics metrics. We do not set marketing cookies; analytics is limited to page views and CTA events.

2. How We Use Information

We use information to operate and improve the Services, provide support, send operational notices, monitor reliability, and satisfy legal requirements. We may generate aggregated, anonymized insights that do not identify individuals.

3. Sharing

We share data with service providers that help deliver the Services (e.g., hosting, authentication, observability). These providers are bound by confidentiality obligations. We may disclose information to comply with law or respond to lawful requests.

4. Data Retention

We retain data as long as necessary to provide the Services, fulfill contracts, or comply with legal obligations. Sandbox fixtures may be reset periodically and should not be used for production data.

5. Security

We implement technical and organizational measures including access controls, signing for webhooks, TLS, and monitoring. No system is perfectly secure; promptly notify us at security@lumenchain.io of any suspected incident.

6. International Transfers

Data may be processed in regions where we operate infrastructure. EU-friendly storage options are available by request (see /security for data residency notes).

7. Your Choices

You may update account details, rotate API keys, and manage webhook secrets in the portal. Contact support@lumenchain.io to request access, correction, or deletion where applicable. Certain records (e.g., invoices, audit logs) may be retained as required by law.

8. Children

The Services are not directed to or intended for children under 16. Do not submit personal data for minors.

9. Changes

We may update this Policy; the date above reflects the latest revision. Continued use of the Services after an update constitutes acceptance.

10. Contact

Privacy questions can be sent to privacy@lumenchain.io or support@lumenchain.io. Incident response contacts are listed on /security and /contact.