Skip to content
LumiraLumira home
Legal

Privacy policy

Last updated Oct 9, 2026

This policy explains what personal data Lumira (“we”) collects when you use this website, create an account or book a custom web project, why we use it, who helps us process it, how long we keep it and the rights you have under Indonesian Law No. 27 of 2022 on Personal Data Protection (UU PDP). Lumira is the controller of this data.

What we collect

  • Account: your email address and name, your profile picture if you sign in with Google or GitHub, and the sign-in methods you set up. Sign-in itself is handled by Clerk.
  • Projects: the project name, brief and quote you choose, the files you upload as materials, your checklist confirmations, revision and warranty tickets, and the progress updates on your dashboard.
  • Payments: invoice amounts and their unique codes, the method you used (bank transfer or QRIS), the payer name and note you enter, and the transfer receipt you upload. We never see your card or banking login details. For a refund we also need the bank account it should go to.
  • GitHub username: if you give it to us for the repository invitation at the handover.
  • Technical data: your IP address (for security and rate limiting), browser and device type, the pages you visit and the actions you take on them, error reports and anonymous performance measurements.
  • Email delivery: whether the emails we send you were delivered, bounced or marked as spam.

Materials you send us may contain personal data about other people, such as your staff or customers. Only share what you are allowed to share; we use it solely to build your project.

Why we use it

  • To create and secure your account and sign you in, as part of our agreement with you.
  • To quote, build, deliver and support your project, issue invoices and confirm payments, as part of our agreement with you.
  • To keep invoices and payment records, because tax and accounting law requires it.
  • To keep the site secure, prevent abuse and fix errors, which is our legitimate interest.
  • To understand how the site is used so we can improve it, which is our legitimate interest. Visitors from the EU, EEA, UK and Switzerland are counted without storing an identifier on their device.
  • To email you about your account and your projects. We do not send newsletters.

We do not sell personal data, and we make no automated decisions about you that have legal effects.

Who processes it for us

These service providers process data on our behalf, each for its own part of the service:

  • Vercel: hosting and server logs.
  • Supabase: our database.
  • Clerk: accounts and sign-in.
  • Cloudflare R2: private storage for materials, receipts and handover files.
  • Resend: email delivery.
  • Upstash: rate limiting and background jobs.
  • PostHog: product analytics.
  • Sentry: error reports, with cookies, sign-in headers and personal details removed before sending.
  • GitHub: the repository invitation, when you give us your username.

Some of these providers store data outside Indonesia, for example in the United States or the European Union. We choose providers with strong security and data protection commitments.

Cookies and similar storage

  • Necessary: Clerk’s session cookies keep you signed in, and a region cookie decides whether analytics may store an identifier.
  • Preferences: your theme and a draft of your quote, kept in your browser only.
  • Analytics: PostHog stores an identifier so that visits can be counted, except for visitors from the EU, EEA, UK and Switzerland. We do not record screens or sessions.

You can block or delete cookies in your browser. Blocking analytics does not affect the site; blocking the necessary cookies stops sign-in from working.

How long we keep it

  • Account data: while your account exists. When you delete your account, your profile is anonymized.
  • Project data and files: while your account is active, so you can reach your handover and warranty. You can ask us to delete project files at any time after the handover.
  • Invoices and payment records: as long as tax and accounting law requires, generally up to 10 years.
  • The content of emails and webhooks: removed after 90 days; only delivery details are kept.
  • Analytics and error reports: the standard retention periods of PostHog and Sentry.

Security

Data travels over HTTPS only. Uploaded files sit in private storage and open only through short-lived signed links, administrator accounts require two-factor authentication, and access is limited to the people who need it for your project. No method is completely secure; if a breach affects your data, we will notify you and the authorities within the time the law requires.

Your rights

Under the UU PDP you can:

  • get information about, and a copy of, the personal data we hold about you;
  • correct or update it, most of it directly in your account settings;
  • ask us to delete it, or to stop or limit processing, unless the law requires us to keep it;
  • withdraw consent you have given, without affecting processing before that;
  • object to processing based on our legitimate interests;
  • receive your data in a common, machine-readable format;
  • complain to the personal data protection authority.

Email muchammad.nur02@gmail.com to use any of these rights. We may first need to confirm that the request comes from you, and we answer within the time limits of the UU PDP.

Children

Lumira is meant for businesses and adults. We do not knowingly collect personal data from children; if you believe a child has given us data, contact us and we will delete it.

Changes and contact

We may update this policy. The date at the top shows the current version, and we will tell you about significant changes by email or on your dashboard. Questions or requests: muchammad.nur02@gmail.com.