Privacy policy

Welcome to Lumos!  

 

At Lumos, we are committed to respecting your privacy and prioritizing your data security. We take the protection of your personal information seriously and strive to be transparent about how we collect, use, and share Personal Data, as well as the measures we implement to safeguard it.

 

Introduction

This Privacy Policy governs the collection of Personal Data from users who interact with Lumos or utilize our services, including visiting our websites or social media pages, or using our mobile apps, Lumos devices, or other Lumos products (referred to collectively as the “Services”). Please note that this Privacy Policy does not extend to the practices of companies we do not own or control, or individuals we do not manage. Lumos disclaims responsibility for the policies and practices of any third parties, and we neither control nor endorse any information, products, or services provided by third parties or accessible through the Services.

 

Data Collection

We gather Personal Data from various sources, including:

 

Information We Collect Directly from You

Information that you directly submit to us through our Services may include:

  • Contact details including your name, address, phone number, and email.
  • Order information including your name, billing address, shipping address, payment confirmation, email address, and phone number.
  • Account information including your username, password, security questions and other information used for account security purposes.
  • Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.

Some features of the Services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.

 

Information We Collect about Your Usage

We may also automatically collect certain information about your interaction with the Services ("Usage Data"), such as data from:

  • Lumos Devices: Data collected from Lumos devices, such as the Lumos Mask or any other Lumos device(s) you may use.
  • Lumos App: Information provided or captured within the Lumos mobile application.

We may use cookies, pixels and similar technologies ("Cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.

 

Information We Obtain from Third Parties

Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:

  • Service providers: Companies who support our Site and Services, such as Shopify. Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.
  • Automated Collection: When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.
  • Clients and Partners: Information obtained from clients and partners, such as employers, insurance companies, coaches, and teams.
  • Marketing Partners: Data provided by marketing and advertising partners with whom we collaborate. 
  • Social Media and Third-party Platforms: Information gathered from social media platforms and linked accounts, devices, or features.
  • Data Providers: Supplementary data from information services and data licensors.

 

The types of data we collect include:

  • Contact Information: If you complete a purchase, we will gather enough information to process your payment and ship your orders. This then requires the gathering and retention of your name, address, email address, and phone number. If you contact us, we will gather our name and email address. 
  • Payment and Transactional Information: We will collect details necessary to complete your orders, including name, email address, payment card information (handled securely by payment processors), billing information, and transaction history.
  • Profile Details: When you use the Lumos app, we will collect information such as username and password used to create a Lumos account, along with any additional data or images you choose to include in your Lumos profile.
  • Activity and wellness Data: We need to collect information to provide you Lumos services. This encompasses various activity data such as schedules, geolocations (GPS coordinates, IP address, movement data), sleep, activities, as well as personal details like birthday, gender identity, eye colors, and information on sleep and light sensitivity. 
  • Communications: We will have records of any exchanges we have with you, whether it's via email, the web app, or the mobile app, including questions, feedback, or reviews.
  • Marketing Preferences: Your preferences regarding marketing communications, and data related to your interaction with them, such as opened emails and clicked links.
  • Device Details: To provide better Services, we will collect information about your device, including operating system type and version, manufacturer, model, browser type, screen resolution, RAM and disk size, CPU usage, device type, IP Address, unique identifiers, language settings, mobile carrier, and general location data.
  • Online Activity: We will collect details about your online activity when you use the Lumos app, website, or Lumos contents, such as viewed pages, time spent on pages, referring websites, navigation paths, user activity on pages, access times, and session duration.

 

Data Use

We process Personal Data to operate, enhance, understand, and personalize our Services. Here’s how we use your data:

 

Provide Services:

  • Transactions: including to process your payments, fulfill your orders, to send notifications to you related to your account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and other features and functionalities related to your account. We may also enhance your shopping experience by enabling Shopify to match your account with other Shopify services that you may choose to use. In this case, Shopify will process your information as set forth in its Privacy Policy and Consumer Privacy Policy.
  • Operate: Provide, operate, enhance, develop, understand, and personalize the Services such as Lumos sleep program creation. 
  • Support and respond to Requests: Offer support and assistance for the Services. Address the reasons you provided the information, including responding to and fulfilling requests.
  • Communication: Keep you informed about the Services, including updates, service announcements, or special offers.
  • Account Management: Create and manage your account or other user profiles.
  • Customization: Tailor website content and communications based on your preferences.

Research and Development:

We may generate and use Aggregated Data, De-identified Data, or other anonymous data derived from the Personal Data we collect. This is used for our business purposes, such as analyzing the effectiveness of the Services, improving and adding features, and understanding the general behavior and characteristics of users. 

 

Marketing, Advertising, and Business Development:

We may use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or services. This may include using your personal information to better tailor the Services and advertising on our Site and other websites. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in selling our products, according to Art. 6 (1) (f) GDPR.

 

Security and Fraud Prevention:

We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in keeping our website secure for you and other customers, according to Art. 6 (1) (f) GDPR.

 

Communicating with You and Service Improvement: 

We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you according to Art. 6 (1) (f) GDPR.

 

Data Share

We may share your Personal Data with:

  • Service providers: This includes payment processors, vendors who advertise our Services or other Lumos products, security and fraud prevention consultants, hosting and other technology and communications providers, analytics providers, and staff augmentation and contract personnel. These service providers offer services to us or on our behalf. 
  • Advertising partners: These partners may collect information on our website through Cookies and other automated technologies for interest-based advertising purposes. However, we do not share your wellness data with advertising partners.
  • Distributors and retailers: This includes those who distribute and retail our Services or other Lumos products.
  • Professional advisors: This includes lawyers, auditors, bankers, and insurers, as necessary in the course of the professional services they provide to us.
  • Authorities and others: This includes law enforcement, government authorities, and private parties when we believe in good faith that sharing is necessary or appropriate to comply with the law or legal process.

 

Online Tracking

Like many websites, we use Cookies on our Site. For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services). We may also permit third parties and services providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites.

Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls. Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.

Please note that while your browser may allow you to transmit a “do not track” signal, like many websites, our Site is not designed to respond to such signals. To learn more about “do not track” signals, you can visit http://www.allaboutdnt.com/.

 

How We Disclose Personal Information

In certain circumstances, we may disclose your personal information to third parties for contract fulfillment purposes, legitimate purposes and other reasons subject to this Privacy Policy. Such circumstances may include:

  • With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
  • With business and marketing partners to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
  • When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
  • With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
  • In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

We have in the past 12 months disclosed the following categories of personal information and sensitive personal information about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":

Category

Categories of Recipients

  • Identifiers such as basic contact details and certain order and account information
  • Personal information categories listed in the California Customer Records statute such as basic contact details and certain order and account information
  • Commercial information such as order information, shopping information and customer support information
  • Internet or other similar network activity, such as Usage Data
  • Geolocation data such as locations determined by an IP address or other technical measures
  • Vendors and third parties who perform services on our behalf (such as Internet service providers, payment processors, fulfillment partners, customer support partners and data analytics providers)
  • Business and marketing partners
  • Affiliates

We do not use or disclose sensitive personal information without your consent or for the purposes of inferring characteristics about you.

 

Third Party Websites and Links

Our Site may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites. Information you provide on public or semi-public venues, including information you share on third-party social networking platforms may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.


 

Data Handling Options

You have options on how you want Lumos to handle your data:

  • Access, Update, or Delete Information: When you log in to your Lumos account, you can access and, in some cases, edit or delete certain personal information you have provided to us. This includes your first and last name, username, password, email and mailing address, and other profile information. Please note that when you update your information, we may retain a copy of the unrevised information in our records. You can request access to or a complete deletion of your account and corresponding data by contacting support@lumos.com.  We may need to retain certain personal data in our records, as well as aggregated or de-identified data derived from your personal data that does not identify you, even after you update or delete it.
  • Push Notifications and Device Permissions: You can manage your push notification preferences and device permissions by accessing the settings on your Lumos mobile application or device. 
  • Geolocation Data: You may allow or disallow Lumos to collect geolocation data by enabling or disabling location services on your mobile device. If you decline to grant Lumos access to this data, we will not be able to provide certain services, capabilities, or features to you.
  • Activity and wellness Data: You may choose to not provide such data through the Lumos app. If you decline to grant Lumos access to this data, we will not be able to provide certain services, capabilities, or features to you.
  • Marketing Communications: We give you the ability to opt-out of marketing-related emails and other communications by following the opt-out or unsubscribe instructions contained in the marketing-related message. You cannot opt-out of receiving certain non-marketing emails regarding the service.
  • Online Tracking Opt-Outs There are several ways you can opt out of certain interest-based advertising and other online tracking activities:
    • Blocking Cookies in Your Browser: Most browsers allow you to remove or reject Cookies, including those used for interest-based advertising. To do this, follow the instructions in your browser settings. Many browsers accept Cookies by default until you change your settings. 
    • Blocking Advertising ID Use in Your Mobile Device Settings: Your mobile devices may offer settings that enable you to make choices about the collection, use, or transfer of your advertising ID associated with your mobile device for interest-based advertising purposes.
    • Using Privacy Plug-Ins or Browsers: You can block our websites from setting Cookies used for interest-based ads by using a browser with privacy features, or by installing browser plugins like Privacy Badger, Ghostery, or uBlock Origin, and configuring them to block third-party Cookies/trackers. 

 

Your Rights

Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.

  • Right to Access / Know: You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.
  • Right to Delete: You may have a right to request that we delete personal information we maintain about you.
  • Right to Correct: You may have a right to request that we correct inaccurate personal information we maintain about you.
  • Right of Portability: You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
  • Restriction of Processing: You may have the right to ask us to stop or restrict our processing of personal information.
  • Withdrawal of Consent: Where we rely on consent to process your personal information, you may have the right to withdraw this consent.
  • Appeal: You may have a right to appeal our decision if we decline to process your request. You can do so by replying directly to our denial.
  • Managing Communication Preferences: We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.

You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below.

We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request. In accordance with applicable laws, you may designate an authorized agent to make requests on your behalf to exercise your rights. Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.

 

 

Data Security and Retention 

Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” In addition, any information you send to us may not be secure while in transit. We recommend that you do not use insecure channels to communicate sensitive or confidential information to us.

How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.

 

 

International Users

Please note that we may transfer, store and process your personal information outside the country you live in. Your personal information is also processed by staff and third party service providers and partners in these countries.

If we transfer your personal information out of Europe, we will rely on recognized transfer mechanisms like the European Commission's Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the UK, as relevant, unless the data transfer is to a country that has been determined to provide an adequate level of protection.

 

 

Modifications to This Privacy Policy

As part of our ongoing effort to enhance our Services, we may need to revise this Privacy Policy periodically. We will notify you of any changes by posting a notice on the Lumos website, sending you an email, or through other means. Your continued use of the Services following any modifications to the Privacy Policy indicates your acceptance of all such changes.