Privacy Policy

LUMIBRICKS Privacy Policy

International Edition · GDPR & CCPA/CPRA
Effective: June 4, 2026  |  Last updated: June 4, 2026  |  Version: 1.0 (International)
⚠️ This document contains placeholders (marked [in brackets]): controller legal name, registered address, contact and DPO emails, EU/UK representative (if applicable). Complete and have counsel review before release. Keep this policy consistent with the Google Play Data Safety form and the Apple Privacy "Nutrition Label".
Important. This Policy explains how [CONTROLLER LEGAL NAME] ("we") collects, uses, stores, and protects your personal data through the LUMIBRICKS application ("App"). Please read it before using the App. This Policy applies to the international edition of the App. If you are in the EEA/UK you have rights under the GDPR; if you are a California resident you have rights under the CCPA/CPRA — see the relevant sections below.

1. Data Controller

[CONTROLLER LEGAL NAME] is the controller of personal data processed through the App.
Registered address: [REGISTERED ADDRESS]
Contact: [privacy@your-domain]

For EEA/UK matters, our Data Protection Officer / EU representative can be reached at [dpo@your-domain].

2. Information We Collect

2.1 Information from your Shopify sign-in

When you authorize sign-in via Shopify, we receive the following (as present in your Shopify account):

Category Fields Purpose
Account identifier Shopify customer ID Identify your account
Contact Email address Account binding, notices
Profile Name, display name Personalization
Contact Phone number (if provided to Shopify) Account binding
Credentials OAuth access & refresh tokens Maintain sign-in

2.2 Device & usage data (collected automatically)

Category Examples Purpose
Device info Device model, OS version, app version, Firebase instance ID Compatibility, analytics, crash diagnosis
Logs Crash logs, error and event logs Stability
Usage Feature usage, screen views Product improvement
Network Network type (Wi-Fi / cellular) Performance

2.3 Bluetooth device data

When you control LUMIBRICKS lighting we process scan data (device address, signal strength), control commands (brightness, color, etc.), and device configuration. This is processed mainly on your device; some device configuration is synced via the Broadlink cloud to enable multi-device/home sync.

2.4 Location permission

Android requires location permission to perform Bluetooth scanning. We use this permission solely for BLE scanning and do not collect, record, or upload your geographic location.

2.5 Push notifications

With your permission, Firebase Cloud Messaging obtains a push token so we can send service notifications. You can disable notifications at any time in system settings.

3. How We Use Your Information & Legal Bases (GDPR)

Purpose Data Legal basis (GDPR Art. 6)
Account sign-in & authentication Account info, OAuth tokens Performance of a contract — 6(1)(b)
Smart-light control Bluetooth device data Performance of a contract — 6(1)(b)
Security & stability Device info, crash logs Legitimate interests — 6(1)(f)
Analytics & product improvement Usage, device info Consent — 6(1)(a)
Service notifications Push token Consent — 6(1)(a)
Legal compliance As required Legal obligation — 6(1)(c)

4. Third-Party SDKs & Data Sharing

The App integrates the following SDKs, which may collect data independently under their own policies:

SDK Provider Purpose Data Policy
Firebase Analytics Intl Google LLC Usage analytics Device info, app usage, Firebase instance ID https://firebase.google.com/support/privacy
Firebase Crashlytics Intl Google LLC Crash reporting Device info, crash stack, install UUID https://firebase.google.com/support/privacy
Firebase Cloud Messaging Intl Google LLC Push notifications FCM registration token https://firebase.google.com/support/privacy
Shopify Customer Account API All Shopify Inc. OAuth sign-in Account info (after your authorization) https://www.shopify.com/legal/privacy
Broadlink BLE Light SDK All Broadlink BLE light control & sync Device address, control commands, device config Broadlink privacy policy

We do not sell your personal information. We may disclose data to respond to lawful requests from authorities, to protect safety, to prevent fraud or abuse, or to enforce our Terms.

5. International Data Transfers

Your data may be processed in countries other than your own. Account data handled via Shopify is processed by Shopify Inc. (e.g., Canada/USA); analytics/crash/push data via Google is processed primarily in the USA. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and the UK Addendum for transfers from the EEA/UK.

6. Data Storage & Retention

  • On device: authentication tokens and account/device configuration are stored encrypted on your device (Android DataStore);
  • Account data: processed by Shopify;
  • Analytics/crash/push: processed by Google (Firebase);
  • Device sync: processed by the Broadlink cloud.
Data Retention
Account info (via Shopify) Deleted or anonymized within 30 days of account deletion
OAuth tokens Invalidated and deleted on expiry
Analytics & crash data Up to 12 months
Local device data Removed when you uninstall the App

7. Your Rights

👁
Access
Obtain a copy of your data
✏️
Rectification
Correct inaccurate data
🗑
Erasure
Request deletion
🚫
Restriction / Objection
Restrict or object to processing
📦
Portability
Receive data in a portable format
↩️
Withdraw consent
Where processing is based on consent

To exercise your rights, email [privacy@your-domain] ("Privacy Request"). We respond within 30 days. You can also manage Shopify-held data by signing in to Shopify.

7.1 California residents (CCPA / CPRA)

  • Right to know the categories and purposes of personal information collected;
  • Right to delete and right to correct your personal information;
  • Right to opt out of sale/sharing — we do not sell or share your personal information for cross-context behavioral advertising;
  • Right to limit use of sensitive personal information;
  • Right to non-discrimination for exercising your rights.

7.2 EEA / UK residents (GDPR)

In addition to the rights above, you may lodge a complaint with your local supervisory authority. For GDPR matters contact [dpo@your-domain].

8. Data Security

  • Encryption in transit: HTTPS/TLS for network communication;
  • Encryption at rest: tokens and sensitive data stored encrypted on device;
  • OAuth PKCE: OAuth 2.0 + PKCE; we do not store your password;
  • Access control & audits: restricted internal access and periodic review.

No method of storage or transmission is fully secure. In the event of a personal-data breach we will notify the relevant authorities and affected users as required by law.

9. Children's Privacy

The App is not directed to children under 13 (or under 16 in the EEA, subject to member-state law). We do not knowingly collect children's personal data. If you believe we have, contact us and we will delete it.

10. Changes to This Policy

We may update this Policy. For material changes we will notify you in-app and update the "Last updated" date; where applicable we will give at least 30 days' notice to EEA/UK users. Continued use after the effective date constitutes acceptance.

11. Contact Us

[CONTROLLER LEGAL NAME] — Privacy Team

📧 Privacy: [privacy@your-domain]

📧 DPO / GDPR: [dpo@your-domain]

📬 Address: [REGISTERED ADDRESS]

⏱ Response time: within 30 days


© 2026 [CONTROLLER LEGAL NAME]. All rights reserved.