Luminous Social Privacy Policy
Luminous Social · planned entity: Luminous Social LLC
Last Updated: July 27, 2026
1. Introduction
This Privacy Policy explains how the operator of Luminous Social ("Company," "we," "us," or "our"), currently doing business as Luminous Social, collects, uses, shares, and protects personal information when you visit luminoussocial.com or use the Luminous Social dashboard and related services (the "Service").
We intend to organize as Luminous Social LLC. When formed, that LLC will become the Company under this Policy. Until then, the current operator of the Service is responsible for the practices described here.
By using the Service, you acknowledge this Policy. If you do not agree, please do not use the Service.
Privacy contact: help@luminoussocial.com
2. Roles: Controller and Processor
For personal data about agency account holders (owners, admins, and members)—such as name, email, billing identifiers, and account preferences—we act as a data controller (or “business”).
For personal data and marketing data that agencies process about their clients or end users through the Service (including metrics and content from connected ad/social accounts), the agency is the controller and we act as a processor (or “service provider”), processing that data only to provide the Service on the agency’s instructions.
Agencies are responsible for providing required notices to their clients and for having a lawful basis to process client data in the Service.
3. Who This Policy Covers
This Policy applies to agency users, visitors to our marketing site, and individuals whose information is processed when agencies connect client accounts or upload client-related data.
4. Information We Collect
We collect information in the following categories:
- Account data: name, email address, password (hashed), agency name, role, and preferences.
- Billing data: plan, subscription status, and payment-related identifiers processed by Stripe (we do not store full card numbers).
- Workspace / Customer Data: clients, notes, reports, schedules, goals, media, content drafts, and settings you create.
- Integration data: OAuth tokens, account IDs, property IDs, profile names, and metrics from connected platforms (Meta, Google, TikTok, LinkedIn, Snapchat, Shopify, Stripe Analytics, HubSpot, Klaviyo, Mailchimp, and similar).
- Usage and device data: log data, IP-derived approximate location, browser/device type, pages viewed, and feature usage.
- Support communications: messages to our support email or in-product contact forms.
- AI inputs/outputs: prompts and generated text or insights you request through AI features.
5. How We Collect Information
We collect information you provide directly, information we receive from Integrations when you authorize a connection, and information collected automatically through cookies or similar technologies.
6. Lawful Bases (Where Applicable)
Where GDPR/UK GDPR or similar laws apply, we process personal data based on: performance of a contract (providing the Service); legitimate interests (securing and improving the Service, preventing abuse); consent (certain marketing or non-essential cookies, where required); and legal obligation (tax, accounting, compliance).
7. How We Use Information
We use personal information to:
- Provide, maintain, and improve the Service (reports, dashboards, scheduling, publishing).
- Authenticate users, manage team access, and secure accounts.
- Connect and refresh Integrations you authorize.
- Process subscriptions and send transactional emails (billing, invites, report delivery, security notices).
- Provide customer support.
- Generate AI-assisted insights and content at your request.
- Monitor reliability, prevent abuse, and comply with law.
- Send product or marketing emails where permitted; you may unsubscribe from marketing emails. Transactional emails are required to operate the Service.
7a. No Misuse of Data
We have no intention to misuse personal information or Integration data. We process data only for the purposes described in this Policy: providing, securing, and improving the Service you request.
We do not sell personal information. We do not rent or trade Customer Data or TikTok/other Integration data. We do not use platform data to spam users, to build unrelated advertising audiences for sale, or for any purpose incompatible with providing agency reporting, insights, and publishing tools.
Access to Customer Data and Integration tokens is limited to operating the Service, providing support you request, and meeting legal obligations.
8. Third-Party Platforms (Including TikTok)
If you connect TikTok or other platforms, we receive credentials and data those platforms make available through their APIs (such as advertiser or account identifiers, campaign/performance metrics, profile information, and—where you enable publishing—content you choose to post).
We use Integration data only to provide features you request (analytics reporting, insights, scheduling, and publishing you initiate). We will not misuse TikTok or other Integration data. We do not sell it, do not use it for unrelated advertising profiles, and do not use it outside the Service purposes described here.
Your use of TikTok and other platforms remains subject to their terms and privacy policies. You can disconnect an Integration in the Service; tokens may also be revoked in the third-party account settings. After disconnect, we stop new data pulls and invalidate tokens per our retention practices.
We may share limited technical data with those platforms as required to complete OAuth, API calls, or publishing you initiate.
8a. Google User Data (Limited Use)
If you connect Google services (including Google Analytics, Google Ads, Search Console, YouTube Analytics, and Google Business Profile), we access Google user data that you authorize through Google’s OAuth consent screen—typically account/property identifiers, performance and analytics metrics, and related configuration needed to generate reports and insights in the Service.
We use Google user data only to provide and improve user-facing features of Luminous Social that are visible in the product (client reporting, dashboards, AI insights based on connected metrics, and related agency workflows). We do not use Google user data for any other purpose.
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements (see https://developers.google.com/terms/api-services-user-data-policy).
- We do not sell Google user data.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not transfer Google user data to third parties except as necessary to provide or improve user-facing features (for example trusted subprocessors under contract), to comply with applicable law, or as part of a merger/acquisition with notice where required—and not for any other purpose.
- Human access to Google user data is limited to cases where a user gave us permission to investigate a support issue, where required for security/compliance, or where necessary for the operation of the Service with appropriate controls.
- You may disconnect Google Integrations in the Service at any time, and you may revoke access in your Google Account permissions. After disconnect or revoke, we stop new Google API access and invalidate tokens per our retention practices.
9. Artificial Intelligence
AI features may send prompts and limited context you provide to AI providers to generate outputs. We do not use Customer Data to train our own foundation models. We prefer provider settings that limit training on customer inputs where available; third-party provider policies also apply and may change.
Do not include unnecessary sensitive personal data in AI prompts.
11. Subprocessors
We use carefully selected service providers. Core subprocessors include:
- Supabase — authentication, database, and file storage.
- Vercel — application hosting and delivery.
- Stripe — subscription billing and payment processing.
- Resend — transactional and product email delivery.
- OpenAI — AI model inference for assisted features you request.
- Connected advertising/social platforms (Meta, Google, TikTok, etc.) — only when you authorize a connection.
11a. Subprocessor Updates
We may update subprocessors from time to time as we change vendors. Material changes will be reflected in this Policy. A security overview is also available at https://luminoussocial.com/security.
12. Data Retention
We retain account and workspace data while your account is active and for a reasonable period afterward for backups, legal compliance, dispute resolution, and fraud prevention.
You may request deletion of your account and associated personal data by emailing help@luminoussocial.com. Some records may be retained where legally required (for example billing records). Integration tokens are deleted or invalidated when you disconnect an Integration or close your account, subject to backup cycles.
13. Security and Incidents
We use industry-standard measures including HTTPS encryption in transit, hashed passwords, access controls, and protected databases. No method of transmission or storage is 100% secure.
If we become aware of a security incident affecting personal information, we will investigate and notify affected users and regulators as required by applicable law.
More detail: https://luminoussocial.com/security
15. International Transfers
We may process and store information in the United States and other countries where we or our processors operate. Where required, we use appropriate safeguards for cross-border transfers.
16. Your Privacy Rights
Depending on your location (including EEA/UK and certain U.S. states), you may have rights to access, correct, export, delete, or restrict processing of personal information, and to object to certain processing or withdraw consent where processing is consent-based.
To exercise these rights, email help@luminoussocial.com. We will verify your request and respond within the time required by applicable law. You may also have the right to lodge a complaint with a supervisory authority.
17. U.S. State Privacy Disclosures (Including California)
We collect the categories of personal information described in Section 4. We use them for the business purposes described in this Policy.
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising as defined by the CCPA/CPRA.
California residents may request to know, delete, or correct personal information, and may use an authorized agent, by contacting help@luminoussocial.com. We will not discriminate against you for exercising privacy rights.
18. Children’s Privacy
The Service is not directed to children under 16 (or the age required by local law). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
19. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top of the page will change when we do. Material changes will be posted on this page; continued use of the Service after changes become effective constitutes acceptance of the updated Policy.
20. Contact Us
Brand / operator: Luminous Social (planned entity: Luminous Social LLC)
Privacy questions and data requests: help@luminoussocial.com
Website: https://luminoussocial.com
Terms of Service: https://luminoussocial.com/legal/terms
Security: https://luminoussocial.com/security