Privacy Policy

1. Scope

This policy explains how we collect, use, store and protect your information when you use lumip.io and related services.

2. What we collect

  • Account data: email address, hashed password credentials, account creation and sign-in times
  • Order and billing data: plan, amount, payment channel, transaction reference. We do not store your card number or payment password
  • Service data: allocated resource identifiers, provisioning and expiry times, bandwidth usage totals
  • Technical logs: timestamps, request paths, IP address, user agent and error traces, kept for troubleshooting and security
  • Correspondence: the content of support tickets you send us

3. What we do not collect

We do not log the destinations you visit through the proxy, the pages you load, or the bodies of the data you transmit. Our logs exist for metering, billing, troubleshooting and abuse prevention — not to profile your browsing.

4. Why we use it

  • To provide and maintain the Service, and to handle provisioning, billing and renewals
  • To verify identity and prevent fraud and account takeover
  • To detect and act on breaches of the Acceptable Use Policy
  • To support you when you contact us
  • To meet legal obligations

5. Cookies

We use strictly necessary cookies to keep you signed in and to run security checks. These cannot be disabled without breaking the Service.

We do not use third-party advertising trackers, and we do not sell or share your browsing data with ad networks.

6. Retention

  • Account and billing data: kept while the account exists; after closure, retained for the financial record period required by law, then deleted or anonymised
  • Technical logs: no more than 90 days by default, for troubleshooting and security audit only
  • Support tickets: 12 months after closure

7. Third parties

To run the Service we pass the minimum necessary information to these categories of provider: payment channels (to take payment and reconcile), email providers (to send verification and notifications), and infrastructure and network suppliers.

We require these providers to process data only on our instructions and to apply appropriate safeguards. We do not sell your personal information to anyone.

8. Security

We take reasonable technical and organisational measures to protect your information, though no system can be absolutely secure.

  • HTTPS everywhere
  • Passwords stored as irreversible hashes — we cannot read your plaintext password
  • Database and cache services are not exposed to the public internet, and credentials follow least privilege
  • Sensitive administrative actions are recorded in an audit log

9. Your rights

You can review and correct your account information at any time, or ask us to close your account and delete the associated data — except records we must keep for legal or reconciliation reasons.

To exercise these rights, open a ticket in the console.

10. Minors

The Service is for businesses and adults. We do not offer it to anyone under 18, and we do not knowingly collect their information.

11. Changes

We will announce material changes to this policy on the site or by email. Please check this page for the current version.