Legal
Privacy Policy
LumaIQ is reporting and operations software for self-storage owners and operators. This policy explains what we collect, why we hold it, who else processes it, and how to have it removed.
Last updated August 14, 2026
The short version
We do not sell personal information, we do not share it for advertising, and we run no third-party trackers. Before you sign in, LumaIQ sets no cookies at all. Most of the personal data we hold is there because someone asked us for something: a demo, a job, or support.
Who we are
LumaIQ is the data controller for the information described below. You can reach us at info@lumaiq.dev for any question about this policy or any request under it.
What we collect
If you visit the site
Nothing that identifies you. We use Vercel Web Analytics, which is cookieless and aggregate. It records page views and referrers without building a profile or following you between sites. Our hosting provider keeps standard server logs, including IP addresses, for security and reliability.
If you request a demo or access
The form asks for your name, work email, phone number, job title, and company, along with details about your portfolio: how many facilities you operate, roughly how many units, which markets, which property management system you use, how you handle reporting today, and what you are trying to change. We use it to decide whether LumaIQ fits and to get back to you. That is all it is used for.
If you apply for a job
We collect your name, email, phone number, location, any LinkedIn or website links you provide, your résumé, your cover letter, and your answers to the application questions. Résumés are stored in a private bucket that is not readable without an authenticated request that we authorize for each file. Applicants hold accounts that exist only inside the careers area and carry no access to any customer’s data.
If you are a user of the product
Accounts are created by invitation, never by self-service sign-up. We hold your name, email address, access level, and which organization and properties you belong to, together with a record of what you did in the product: the audits you filed, the rate increases you approved, the tasks you closed. That record is what makes the product auditable for the operator you work for.
If you contact support
We keep the subject, description, and any file you attach, so the request can be worked and referred back to.
Data our customers upload
Operators upload business records: rent rolls, owner reports, vendor invoices, property documents, and photos and audio recordings from property visits. For that material LumaIQ is a processor, not a controller. The operator decides what goes in and what happens to it, and we handle it on their instructions under our agreement with them.
One point is worth stating plainly, because it is a design decision rather than an accident: the rent roll importer does not retain the names of an operator’s storage tenants. A rent roll is reduced to unit-level records (unit label, size, rate, move-in date, delinquency age) and the tenant identity column is left empty. The product is built to price and manage units, and it does not need to know who is in them.
Audio recorded during a property visit may capture the voices of the people on site. Operators are responsible for telling their staff that visits are recorded.
Cookies
LumaIQ uses only essential cookies, and none of them are set until you sign in. Once you do, our authentication provider sets cookies that keep you signed in and protect the session. They exist solely to deliver the service you asked for and cannot be turned off without breaking sign-in.
We set no advertising, profiling, or cross-site tracking cookies. There is no Google Analytics, no advertising pixel, and no session-replay tool anywhere on this site. That is why you are not being asked to accept or reject anything. There would be nothing to reject.
Who else processes your data
We use a small number of service providers, each with access to only what its job requires:
- SupabaseDatabase, authentication, and file storage. Holds essentially everything described above.
- VercelApplication hosting and cookieless analytics. Handles requests and server logs.
- ResendTransactional email: invitations, application acknowledgements, support notifications.
- AnthropicReads uploaded invoices and audit notes to produce a draft for a person to confirm.
- OpenAITranscribes property-visit audio recordings into text.
- Google Maps PlatformCompetitor locations and addresses for the market map. Receives location queries, never your business data.
We do not sell personal information or share it for cross-context behavioral advertising, as those terms are used in US state privacy law.
Automated processing
LumaIQ uses AI models to read documents and transcribe recordings, and to draft rate increases and audit write-ups. Every one of those outputs is a draft that a person reviews and confirms before it takes effect. Nothing in the product makes a decision about a person automatically, and no model output is applied to your account without a human approving it.
How long we keep things
Customer data is retained for as long as the organization holds an account with us, and is deleted on request when the relationship ends. Demo requests, job applications, and support tickets are kept until they are no longer needed for the purpose they were submitted for, or until you ask us to delete them, whichever comes first.
If you applied for a role and would like your application and résumé removed, email careers@lumaiq.dev and we will delete them.
How it is protected
Data is encrypted in transit. Every organization’s data is isolated at the database level by row-level security, so one operator’s records are not reachable from another’s account, and access within an organization is further limited by role and by which properties a person is assigned to. Uploaded files are held in private storage that cannot be read from a URL alone. Each access is authorized individually and expires.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your personal data, we will notify you and any regulator we are required to notify.
Your rights
You may ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Email info@lumaiq.dev and we will respond within 30 days. We will not treat you differently for exercising any of these rights.
If you are a user of the product, some requests are best directed to the operator whose account you belong to, since they control that data. Write to us either way and we will make sure it reaches the right place.
Children
LumaIQ is business software and is not directed at children. We do not knowingly collect personal information from anyone under 16.
Changes
If this policy changes we will update the date at the top of this page. Where a change materially affects how we handle personal data, we will tell account holders directly rather than relying on you to notice.
Contact
Questions, requests, or anything that looks wrong on this page: info@lumaiq.dev. You can also reach us through the contact form.