Privacy Policy
Last updated: August 8, 2026
This policy describes how EMARKSS LTD (“EMARKSS”, “we”) collects, uses, protects and deletes data when a Shopify store installs the Lumnya app. For the plain-language short version, see “Your data”.
1. Who we are
Lumnya is operated by EMARKSS LTD, a company registered in England and Wales (Company No. 16181893), 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE. Contact: contact@lumnya.ai.
2. Roles: who is responsible for what
For your store's shopper data (conversations, orders, contact details) the merchant is the Data Controller and EMARKSS acts as a Data Processor, strictly on the instructions you give through the app's settings.
For your own merchant account data (store details, settings, support requests, billing) EMARKSS is the Data Controller.
3. What data we process
- Store details: domain, name, language, app settings
- Product catalog and basic order/return details (via Shopify APIs, under the scopes you approved at install)
- Chat-widget conversations: messages, timestamps, language, visit behaviour signals (e.g. cart state), and details a shopper volunteers (e.g. an email for an order)
- Merchant support requests and attached screenshots
- AI usage and cost metrics (conversation counts, tokens, cost) for operations and billing
- Technical error logs (without conversation content where feasible)
4. Purposes
We do not use your data to train AI models and we do not share it with advertising networks.
- Operating the AI assistant and automations (answers, recommendations, cart recovery, returns)
- Merchant-facing analytics and reports
- Usage-based billing through Shopify Billing
- Security, abuse prevention and error diagnosis
- Customer support
5. Subprocessors
We rely on the following infrastructure providers, under data-processing agreements:
- Shopify (installation platform, authentication, billing)
- Google Cloud / Firebase (application hosting, Firestore database, file storage — encrypted at rest and in transit)
- Google (Gemini API) — AI answer generation; Google does not train models on API customer data
- Email provider (notification deliverability and cart-recovery emails)
- Sentry (error monitoring) and PostHog (anonymous product-usage metrics)
6. Retention and automatic deletion
Shopper personal details in conversations, carts and behaviour signals are subject to automatic retention windows: once exceeded, they are deleted or irreversibly anonymized so an inactive shopper can no longer be re-identified. Aggregate, anonymous metrics are retained for historical charts.
Support requests auto-close after inactivity and fall under the store erasure in section 7.
7. GDPR: requests are honored automatically
These run through Shopify's mandatory GDPR webhooks, with automatic retry on transient failure.
- customers/data_request: we compile the shopper's data so the merchant can answer the access request
- customers/redact: we delete/anonymize that shopper's data
- shop/redact: after uninstall, we erase ALL of the store's data — conversations, settings, support requests and their attached files
8. Your rights
You have the UK/EU GDPR rights of access, rectification, erasure, restriction, portability and objection. For your store's shopper data, requests flow through Shopify (and we honor them automatically). For your own account data, write to contact@lumnya.ai. You may also lodge a complaint with the UK Information Commissioner's Office (ICO) or your local EU supervisory authority.
9. Your US state privacy rights
If you reside in California, Texas, Colorado, Virginia, or another US state with a comprehensive privacy law, you may have rights to access, correct, delete and obtain a portable copy of your personal information, and to opt out of any “sale” or “sharing” of it and of targeted advertising and certain profiling — with no discrimination for exercising them.
EMARKSS does not sell or share personal information and does not use it for cross-context behavioral advertising. For a store's shopper data, EMARKSS acts only as a service provider/processor on the merchant's documented instructions: the merchant is the business/controller, so shoppers should send requests to the merchant, which we assist automatically through Shopify's privacy webhooks (section 7). For merchant account data (where EMARKSS is the controller) or questions about these rights, write to contact@lumnya.ai.
10. International transfers
Our primary infrastructure runs on Google Cloud in the United States. Where personal data of UK or EEA individuals is transferred outside the UK/EEA, we rely on the EU–US Data Privacy Framework and its UK Extension where the recipient is certified, and otherwise Standard Contractual Clauses and the UK International Data Transfer Addendum, with supplementary measures where appropriate.
11. Cookies and local storage
The admin app uses one strictly necessary session cookie. The chat widget stores conversation history locally on the visitor's device (localStorage) with automatic expiry — no tracking cookies, no advertising cookies.
12. Changes and contact
Material changes to this policy are announced inside the app before they take effect.
EMARKSS LTD, 82a James Carter Road, Mildenhall, United Kingdom, IP28 7DE — contact@lumnya.ai