Lumeneer.← Back to home

Privacy Policy

Last updated: 22 July 2026

This policy explains how Lumeneer ("Lumeneer", "we", "us") handles personal data across the platform: the studio dashboard, the image processing, client galleries and this website. Data protection is a design constraint, not an afterthought.

1. Who the data is about

For subject and buyer data, the studio is the data controller and Lumeneer acts as a data processor on the studio's instructions. Studios are responsible for obtaining the consents their shoots require, including parental consent for minors.

2. What we collect and why

We do not sell personal data, and we do not use it for third-party advertising.

3. Processors we rely on

Each processor is bound by its own data processing terms, and we limit what each one receives to what its role needs.

4. Retention

Photographers can archive or delete older jobs whenever they wish. Account and billing records are kept as long as the account exists and thereafter as required for tax and accounting. When a photographer deletes a job, gallery or account, the associated personal data is deleted within 30 days, except where law requires longer retention.

6. Your rights (GDPR and PDPA)

We operate under Singapore's Personal Data Protection Act (PDPA) and, where it applies to data subjects in the European Economic Area or the UK, the GDPR. Depending on your jurisdiction you have the right to:

Parents and subjects should direct requests to the studio that ran the shoot, as the controller of that data; we support studios in fulfilling them. You can also contact us directly at hello@lumeneer.io and we will route the request. We respond within 30 days.

7. Security

8. International transfers

Data is hosted in Singapore (AWS ap-southeast-1). Where a processor handles data outside your jurisdiction (for example Stripe for payments), transfers rely on that processor's recognised safeguards, such as standard contractual clauses.

9. Cookies

The platform uses strictly necessary cookies only: session authentication for studio and gallery logins, and security tokens. We do not run third-party advertising or cross-site tracking cookies. Payment pages served by Stripe set Stripe's own cookies under Stripe's policy.

10. Children's data

Galleries containing minors are private by default, protected by per-subject access codes, and are never indexed or publicly listed. Studios must have the consent of a parent or guardian, or of the commissioning school, before photographing minors and uploading their data. We act on studio instructions and delete on request.

11. Changes and contact

We will post updates to this policy here and notify studios of material changes by email. Contact for privacy matters: hello@lumeneer.io.