LUMIBRICKS Privacy Policy
1. Data Controller
[CONTROLLER LEGAL NAME] is the controller of personal data processed through the App.
Registered address: [REGISTERED ADDRESS]
Contact: [privacy@your-domain]
For EEA/UK matters, our Data Protection Officer / EU representative can be reached at [dpo@your-domain].
2. Information We Collect
2.1 Information from your Shopify sign-in
When you authorize sign-in via Shopify, we receive the following (as present in your Shopify account):
| Category | Fields | Purpose |
|---|---|---|
| Account identifier | Shopify customer ID | Identify your account |
| Contact | Email address | Account binding, notices |
| Profile | Name, display name | Personalization |
| Contact | Phone number (if provided to Shopify) | Account binding |
| Credentials | OAuth access & refresh tokens | Maintain sign-in |
2.2 Device & usage data (collected automatically)
| Category | Examples | Purpose |
|---|---|---|
| Device info | Device model, OS version, app version, Firebase instance ID | Compatibility, analytics, crash diagnosis |
| Logs | Crash logs, error and event logs | Stability |
| Usage | Feature usage, screen views | Product improvement |
| Network | Network type (Wi-Fi / cellular) | Performance |
2.3 Bluetooth device data
When you control LUMIBRICKS lighting we process scan data (device address, signal strength), control commands (brightness, color, etc.), and device configuration. This is processed mainly on your device; some device configuration is synced via the Broadlink cloud to enable multi-device/home sync.
2.4 Location permission
Android requires location permission to perform Bluetooth scanning. We use this permission solely for BLE scanning and do not collect, record, or upload your geographic location.
2.5 Push notifications
With your permission, Firebase Cloud Messaging obtains a push token so we can send service notifications. You can disable notifications at any time in system settings.
3. How We Use Your Information & Legal Bases (GDPR)
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account sign-in & authentication | Account info, OAuth tokens | Performance of a contract — 6(1)(b) |
| Smart-light control | Bluetooth device data | Performance of a contract — 6(1)(b) |
| Security & stability | Device info, crash logs | Legitimate interests — 6(1)(f) |
| Analytics & product improvement | Usage, device info | Consent — 6(1)(a) |
| Service notifications | Push token | Consent — 6(1)(a) |
| Legal compliance | As required | Legal obligation — 6(1)(c) |
4. Third-Party SDKs & Data Sharing
The App integrates the following SDKs, which may collect data independently under their own policies:
| SDK | Provider | Purpose | Data | Policy |
|---|---|---|---|---|
| Firebase Analytics Intl | Google LLC | Usage analytics | Device info, app usage, Firebase instance ID | https://firebase.google.com/support/privacy |
| Firebase Crashlytics Intl | Google LLC | Crash reporting | Device info, crash stack, install UUID | https://firebase.google.com/support/privacy |
| Firebase Cloud Messaging Intl | Google LLC | Push notifications | FCM registration token | https://firebase.google.com/support/privacy |
| Shopify Customer Account API All | Shopify Inc. | OAuth sign-in | Account info (after your authorization) | https://www.shopify.com/legal/privacy |
| Broadlink BLE Light SDK All | Broadlink | BLE light control & sync | Device address, control commands, device config | Broadlink privacy policy |
We do not sell your personal information. We may disclose data to respond to lawful requests from authorities, to protect safety, to prevent fraud or abuse, or to enforce our Terms.
5. International Data Transfers
Your data may be processed in countries other than your own. Account data handled via Shopify is processed by Shopify Inc. (e.g., Canada/USA); analytics/crash/push data via Google is processed primarily in the USA. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and the UK Addendum for transfers from the EEA/UK.
6. Data Storage & Retention
- On device: authentication tokens and account/device configuration are stored encrypted on your device (Android DataStore);
- Account data: processed by Shopify;
- Analytics/crash/push: processed by Google (Firebase);
- Device sync: processed by the Broadlink cloud.
| Data | Retention |
|---|---|
| Account info (via Shopify) | Deleted or anonymized within 30 days of account deletion |
| OAuth tokens | Invalidated and deleted on expiry |
| Analytics & crash data | Up to 12 months |
| Local device data | Removed when you uninstall the App |
7. Your Rights
To exercise your rights, email [privacy@your-domain] ("Privacy Request"). We respond within 30 days. You can also manage Shopify-held data by signing in to Shopify.
7.1 California residents (CCPA / CPRA)
- Right to know the categories and purposes of personal information collected;
- Right to delete and right to correct your personal information;
- Right to opt out of sale/sharing — we do not sell or share your personal information for cross-context behavioral advertising;
- Right to limit use of sensitive personal information;
- Right to non-discrimination for exercising your rights.
7.2 EEA / UK residents (GDPR)
In addition to the rights above, you may lodge a complaint with your local supervisory authority. For GDPR matters contact [dpo@your-domain].
8. Data Security
- Encryption in transit: HTTPS/TLS for network communication;
- Encryption at rest: tokens and sensitive data stored encrypted on device;
- OAuth PKCE: OAuth 2.0 + PKCE; we do not store your password;
- Access control & audits: restricted internal access and periodic review.
No method of storage or transmission is fully secure. In the event of a personal-data breach we will notify the relevant authorities and affected users as required by law.
9. Children's Privacy
The App is not directed to children under 13 (or under 16 in the EEA, subject to member-state law). We do not knowingly collect children's personal data. If you believe we have, contact us and we will delete it.
10. Changes to This Policy
We may update this Policy. For material changes we will notify you in-app and update the "Last updated" date; where applicable we will give at least 30 days' notice to EEA/UK users. Continued use after the effective date constitutes acceptance.
11. Contact Us
[CONTROLLER LEGAL NAME] — Privacy Team
📧 Privacy: [privacy@your-domain]
📧 DPO / GDPR: [dpo@your-domain]
📬 Address: [REGISTERED ADDRESS]
⏱ Response time: within 30 days
© 2026 [CONTROLLER LEGAL NAME]. All rights reserved.