Privacy Policy
Lumio Booking (“Lumio”, “we”, “us”) is a booking and marketing platform for local service businesses such as salons, spas and barbershops. This policy explains what information we collect, why we collect it, and what we do with it.
Two groups of people use Lumio, and the policy treats them differently. Business customers are the salon owners and staff who log in to run their business. Consumers are the people who book an appointment through a salon’s booking page or message a salon.
1. Information we collect
From business customers
- Account details: name, email address, phone number, and the salon’s business details.
- Content you create in Lumio: appointments, services, prices, staff records, posts and schedules.
- Photos and videos you upload in order to publish them to your own social accounts.
- Access tokens for the social accounts you choose to connect (TikTok, Facebook, Instagram, Google Business Profile, Zalo). See section 3.
From consumers
- Booking details: name, phone number, email address if given, and the service and time chosen.
- Messages you send to a salon through a channel the salon has connected to Lumio, including any photos you attach.
Automatically
- Basic technical logs needed to operate and secure the service: IP address, browser type, timestamps, error traces.
We do not sell personal information, and we do not buy it.
2. How we use information
- To run the booking system: create, confirm, change and remind about appointments.
- To publish the content a business customer has scheduled, to the accounts that customer connected.
- To deliver messages between a salon and its customers, and to draft replies with the salon’s approval settings.
- To provide support, investigate problems, and prevent abuse.
- To meet legal obligations.
We do not use consumer contact details for our own marketing. A salon may message its own customers through Lumio; the salon is responsible for having permission to do so.
3. Connected social accounts
A business customer may connect their own social accounts to Lumio so that scheduled posts publish automatically. Connecting is always done by the account holder, through the platform’s own authorisation screen. Lumio never asks for, receives or stores a social account password.
What we store: the access and refresh tokens the platform issues, the account’s public display name and avatar, and the identifier the platform uses for that account.
TikTok
- We request only the permissions we use:
user.info.basic, to show you which account is connected, andvideo.publish, to post the content you scheduled. - Before every post we ask TikTok for your current creator settings and apply them. Your privacy level is never preset by Lumio — you choose it for each post.
- We do not read your videos, your followers, your analytics, your inbox or any other account data.
- You can disconnect at any time from the Channels page in Lumio, which deletes the stored tokens. You can also revoke access from TikTok directly, under Settings and privacy → Security and permissions → Manage app permissions.
Meta (Facebook and Instagram), Google Business Profile, Zalo
The same principles apply: we request the narrowest permissions needed to publish content and to handle messages the business has asked us to handle, we store only the tokens and public account identifiers, and disconnecting in Lumio deletes them.
4. Sharing
We share information only in these situations:
- With the platform you connected, in order to carry out what you asked — for example, sending your video and caption to TikTok so it appears on your profile.
- With service providers that host and operate Lumio (cloud hosting, database hosting, email and SMS delivery, and the AI provider that drafts message replies). They may process information only on our instructions.
- With the salon whose booking page or message channel a consumer used. Each salon sees only its own data; Lumio keeps every business separated.
- When the law requires it, or to protect the rights and safety of people using Lumio.
5. Retention
- Business account data is kept for as long as the account is active.
- Social access tokens are deleted as soon as you disconnect the account.
- Booking and message records are kept while the salon’s account is active, so the salon has its own history.
- After an account is closed we delete or anonymise its data within 90 days, except where we must keep records longer to comply with the law.
6. Security
Traffic to Lumio runs over HTTPS. Access tokens are stored server-side and are never sent to a browser. Staff accounts see only what their role allows, and each business’s data is isolated from every other business’s. No system is perfect, but we treat credentials and customer contact details as the most sensitive things we hold and design around that.
7. Your rights
You may ask us to show you the personal information we hold about you, correct it, or delete it. Business customers can do most of this directly inside Lumio. For anything else, write to us at the address below and we will respond within 30 days. If you are a consumer who booked with a salon, we will pass your request to that salon where the salon is the one holding the record.
8. Children
Lumio is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us information, contact us and we will remove it.
9. International transfers
Lumio is operated from Vietnam and serves businesses in the United States and elsewhere. Information may be processed in either country and by the service providers listed in section 4.
10. Changes
If we change this policy we will update the date at the top of this page, and we will tell business customers inside the product when the change is significant.
11. Contact
Questions, requests, or data deletion: support@lumiobooking.com