Lumeneer.← Back to home

Privacy Policy

Last updated: 22 July 2026

This policy explains how Lumeneer ("Lumeneer", "we", "us") handles personal data across the platform: the studio dashboard, the shoot-day scanner, client galleries and storefronts, and this website. We build for work that involves children's photographs, so data protection is a design constraint, not an afterthought.

1. Who the data is about

For subject and buyer data, the studio is the data controller and Lumeneer acts as a data processor on the studio's instructions. Studios are responsible for obtaining the consents their shoots require, including parental consent for minors.

2. What we collect and why

We do not sell personal data, and we do not use it for third-party advertising.

3. Face matching

Automated face detection checks that photos landed in the right subject's gallery and flags mismatches for human review by the studio. Matching runs against the photos of the specific job only. We do not build cross-studio biometric profiles, do not use face data to train models, and delete derived face vectors when the job's photos are deleted.

4. Processors we rely on

Each processor is bound by its own data processing terms, and we limit what each one receives to what its role needs.

5. Retention

Photographs are retained for 5 years from upload as part of the service promise, with originals moving to cold storage 90 days after a job closes. Account and billing records are kept as long as the account exists and thereafter as required for tax and accounting. When a studio deletes a job, gallery or account, the associated personal data is deleted within 30 days, except where law requires longer retention.

6. Your rights (GDPR and PDPA)

We operate under Singapore's Personal Data Protection Act (PDPA) and, where it applies to data subjects in the European Economic Area or the UK, the GDPR. Depending on your jurisdiction you have the right to:

Parents and subjects should direct requests to the studio that ran the shoot, as the controller of that data; we support studios in fulfilling them. You can also contact us directly at hello@lumeneer.io and we will route the request. We respond within 30 days.

7. Security

8. International transfers

Data is hosted in Singapore (AWS ap-southeast-1). Where a processor handles data outside your jurisdiction (for example Stripe for payments), transfers rely on that processor's recognised safeguards, such as standard contractual clauses.

9. Cookies

The platform uses strictly necessary cookies only: session authentication for studio and gallery logins, and security tokens. We do not run third-party advertising or cross-site tracking cookies. Payment pages served by Stripe set Stripe's own cookies under Stripe's policy.

10. Children's data

Galleries containing minors are private by default, protected by per-subject access codes, and are never indexed or publicly listed. Studios must have the consent of a parent or guardian, or of the commissioning school, before photographing minors and uploading their data. We act on studio instructions and delete on request.

11. Changes and contact

We will post updates to this policy here and notify studios of material changes by email. Contact for privacy matters: hello@lumeneer.io.