Privacy Policy
Last updated: 22 July 2026
This policy explains how Lumeneer ("Lumeneer", "we", "us") handles personal data across the platform: the studio dashboard, the shoot-day scanner, client galleries and storefronts, and this website. We build for work that involves children's photographs, so data protection is a design constraint, not an afterthought.
1. Who the data is about
- Studios: account holders and their team members (name, email, business details, billing records).
- Subjects: the people photographed, often schoolchildren (name, class or group, roster references, access codes, and the photographs themselves).
- Buyers: parents and clients who view galleries and purchase photos (email, order history, delivery details).
For subject and buyer data, the studio is the data controller and Lumeneer acts as a data processor on the studio's instructions. Studios are responsible for obtaining the consents their shoots require, including parental consent for minors.
2. What we collect and why
- Account and billing data, to provide and charge for the service.
- Rosters and subject lists, to create galleries and match photos to people.
- Photographs and shoot metadata, to deliver the core product.
- Order and payment records, to process purchases and payouts.
- Technical logs (IP, device, timestamps), for security and reliability.
We do not sell personal data, and we do not use it for third-party advertising.
3. Face matching
Automated face detection checks that photos landed in the right subject's gallery and flags mismatches for human review by the studio. Matching runs against the photos of the specific job only. We do not build cross-studio biometric profiles, do not use face data to train models, and delete derived face vectors when the job's photos are deleted.
4. Processors we rely on
- Amazon Web Services: hosting, storage and face detection (Singapore region, ap-southeast-1).
- Stripe: payment processing and payouts.
- Resend: transactional email delivery.
Each processor is bound by its own data processing terms, and we limit what each one receives to what its role needs.
5. Retention
Photographs are retained for 5 years from upload as part of the service promise, with originals moving to cold storage 90 days after a job closes. Account and billing records are kept as long as the account exists and thereafter as required for tax and accounting. When a studio deletes a job, gallery or account, the associated personal data is deleted within 30 days, except where law requires longer retention.
6. Your rights (GDPR and PDPA)
We operate under Singapore's Personal Data Protection Act (PDPA) and, where it applies to data subjects in the European Economic Area or the UK, the GDPR. Depending on your jurisdiction you have the right to:
- access a copy of your personal data;
- correct inaccurate data;
- request deletion ("right to be forgotten");
- restrict or object to certain processing;
- data portability for data you provided;
- withdraw consent where processing is based on consent;
- complain to your supervisory authority (in Singapore, the PDPC).
Parents and subjects should direct requests to the studio that ran the shoot, as the controller of that data; we support studios in fulfilling them. You can also contact us directly at hello@lumeneer.io and we will route the request. We respond within 30 days.
7. Security
- Encryption in transit (HTTPS everywhere) and at rest.
- Per-subject access codes with brute-force rate limiting.
- Row-level tenant isolation between studios.
- Short-lived signed URLs for media access; immutable originals.
- PII encryption for sensitive fields.
8. International transfers
Data is hosted in Singapore (AWS ap-southeast-1). Where a processor handles data outside your jurisdiction (for example Stripe for payments), transfers rely on that processor's recognised safeguards, such as standard contractual clauses.
9. Cookies
The platform uses strictly necessary cookies only: session authentication for studio and gallery logins, and security tokens. We do not run third-party advertising or cross-site tracking cookies. Payment pages served by Stripe set Stripe's own cookies under Stripe's policy.
10. Children's data
Galleries containing minors are private by default, protected by per-subject access codes, and are never indexed or publicly listed. Studios must have the consent of a parent or guardian, or of the commissioning school, before photographing minors and uploading their data. We act on studio instructions and delete on request.
11. Changes and contact
We will post updates to this policy here and notify studios of material changes by email. Contact for privacy matters: hello@lumeneer.io.