Privacy Policy

Privacy Policy

Updated on 15 May 2026

Luma & Home (“we”, “our” or “us”) is committed to protecting your privacy. This Privacy Policy explains how your personal information is collected, used, and disclosed by Luma & Home.

This Privacy Policy applies to our website and its associated subdomains (collectively, our “Service”). By accessing or using our Service, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service.


Definitions and Key Terms

To help explain things as clearly as possible in this Privacy Policy, every time any of these terms are referenced, they are strictly defined as:

  • Cookie: A small amount of data generated by a website and saved by your web browser. It is used to identify your browser, provide analytics, and remember information about you such as your language preference or login information.
  • Company: When this Privacy Policy mentions “Company,” “we,” “us,” or “our,” it refers to Matthias Moreillon (operating as Luma & Home), responsible for your information under this Privacy Policy.
  • Country: Where Luma & Home or the owners of Luma & Home are based — in our case, {org.address?.country || "Sweden"}.
  • Customer: Refers to the person or organisation that signs up to use the Luma & Home Service to place orders, manage an account, or otherwise interact with our shop.
  • Device: Any internet-connected device such as a phone, tablet, computer, or any other device that can be used to visit Luma & Home and use the services.
  • IP address: Every device connected to the internet is assigned a number known as an Internet Protocol (IP) address. These numbers are usually assigned in geographic blocks. An IP address can often be used to identify the location from which a device is connecting to the internet.
  • Personnel: Refers to those individuals who are employed by Luma & Home or are under contract to perform a service on behalf of one of the parties.
  • Personal Data: Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person.
  • Service: Refers to the service provided by Luma & Home as described in the relative terms (if available) and on this platform.
  • Third-party service: Refers to advertisers, contest sponsors, promotional and marketing partners, payment processors, hosting providers, and others who provide our content or whose products or services we think may interest you.
  • Website: Luma & Home's site, which can be accessed via this URL: https://lumaandhome.co.uk/
  • You: A person or entity that is registered with Luma & Home to use the Services.

What Information Do We Collect?

We collect information from you when you visit our website, register on our site, place an order, subscribe to our newsletter, respond to a survey, leave a review, or fill out a form. This information may include:

  • Name and username
  • Phone numbers
  • Email addresses
  • Billing addresses
  • Shipping addresses
  • Payment data (handled directly by our payment processor; we never see your full card number — only the card type, last four digits, and payment status)
  • Technical data such as IP address, browser type, device type, operating system, and referring page
  • Browsing data such as page views, clicks, searches, and cart events — collected only after you have consented to analytics cookies
  • Communications such as messages sent to support, product reviews, and emails received from us
  • Marketing preferences, including consent for our newsletter and ad measurement

How Do We Use the Information We Collect?

Any of the information we collect from you may be used in one of the following ways:

  • To personalise your experience (your information helps us better respond to your individual needs).
  • To improve our website (we continually strive to improve our website offerings based on the information and feedback we receive from you).
  • To improve customer service (your information helps us more effectively respond to your customer service requests and support needs).
  • To process transactions and fulfil orders.
  • To administer a contest, promotion, survey, or other site feature.
  • To send periodic emails.
  • To prevent fraud and protect the security of our Service.
  • To comply with our legal and accounting obligations.

Lawful Basis for Processing (UK GDPR)

Under the UK GDPR and the Data Protection Act 2018, we rely on the following lawful bases:

  • Performance of a contract (Art. 6(1)(b)): processing your order, arranging delivery, handling returns, and issuing refunds.
  • Legal obligation (Art. 6(1)(c)): keeping accounting records for 7 years under Swedish bookkeeping law, and complying with UK consumer protection regulations.
  • Legitimate interest (Art. 6(1)(f)): fraud prevention, site security, service improvement, and customer support.
  • Consent (Art. 6(1)(a)): our newsletter, analytics, advertising cookies, and remarketing. You can withdraw consent at any time from the cookie banner or any marketing email.

When Does Luma & Home Use End User Information from Third Parties?

Luma & Home collects End User data necessary to provide the Luma & Home services to our customers. End users may voluntarily provide us with information they have made available on social media websites. If you provide us with any such information, we may collect publicly available information from the social media websites you have indicated. You can control how much of your information social media websites make public by visiting these websites and changing your privacy settings.

When Does Luma & Home Use Customer Information from Third Parties?

We receive some information from third parties when you contact us. For example, when you submit your email address to us to show interest in becoming a Luma & Home customer, we may receive information from a third party that provides automated fraud detection services. We also occasionally collect information that is made publicly available on social media websites. You can control how much of your information social media websites make public by visiting these websites and changing your privacy settings.

Do We Share the Information We Collect with Third Parties?

We may share the information we collect, both personal and non-personal, with carefully selected third parties such as payment processors, fulfilment partners, marketing partners, and others whose products or services support our ability to provide the Service. We may also share it with our current and future affiliated companies and business partners, and if we are involved in a merger, sale of assets, or other business reorganisation, we may also share or transfer your personal and non-personal information to our successors.

We engage trusted third-party service providers to perform functions and provide services to us, such as hosting and maintaining our servers and the website, database storage and management, email management, marketing communications, credit card processing, customer service, and fulfilling orders for products and services you may purchase through the website. We share your personal information, and possibly some non-personal information, with these third parties to enable them to perform these services for us and for you.

We have a data processing agreement (DPA) with each processor where required by the UK GDPR. The processors we currently rely on include:

  • Stripe (EU + USA) — payments. We share name, email, billing address, IP and transaction data. stripe.com/privacy
  • Brevo (France, EU) — transactional and marketing email. We share name, email and order details. brevo.com/legal/privacypolicy
  • Google Analytics 4 (USA) — anonymised analytics with IP anonymisation enabled. Loaded only after consent. policies.google.com/privacy
  • Google Ads (USA) — conversion tracking and remarketing. Loaded only after consent to marketing cookies.
  • Google Tag Manager (USA) — container that loads other tags according to your consent.
  • Google Search Console — server-side verification only; no user-side tracking.
  • Cloudflare (USA + EU edges) — CDN, firewall and DDoS protection. Logs IP addresses briefly for security. cloudflare.com/privacypolicy
  • Shipping carriers (Royal Mail, Evri, DPD or equivalent) — name, address, phone and email for delivery.

We may share portions of our log file data, including IP addresses, for analytics purposes with third parties such as web analytics partners, application developers, and ad networks. If your IP address is shared, it can be used to estimate the general location and other technical data such as connection speed, whether you have visited the website in a shared location, and the type of device used to visit the website.

We may also disclose personal and non-personal information about you to government or law enforcement officials or private parties as we, in our sole discretion, believe necessary or appropriate to respond to claims, legal processes (including subpoenas), to protect our rights and interests or those of a third party, the safety of the public or any person, to prevent or stop any illegal, unethical, or legally actionable activity, or to otherwise comply with applicable court orders, laws, rules, and regulations.

We never sell your personal data.

Where and When Is Information Collected from Customers and End Users?

Luma & Home will collect personal information that you submit to us. We may also receive personal information about you from third parties as described above, primarily in the context of payment authorisation, fraud prevention, and shipping fulfilment. Information is collected at the moment you visit our Service, create an account, place an order, subscribe to our newsletter, contact our support team, or otherwise interact with us.

How Do We Use Your Email Address?

By submitting your email address on this website, you agree to receive emails from us. You can cancel your participation in any of our email lists at any time by clicking on the unsubscribe link included in every commercial email we send. We only send emails to people who have authorised us to contact them, either directly or through a third party. We do not send unsolicited commercial emails — we dislike spam just as much as you do.

By submitting your email address, you also agree to allow us to use your email address for customer-audience targeting on platforms such as Facebook and Google, where we display custom advertising to specific people who have opted in to receive communications from us. Email addresses submitted only through the order processing page will be used for the sole purpose of sending you information and updates pertaining to your order, unless you have also subscribed to our newsletter or otherwise opted into marketing communications.

If at any time you would like to unsubscribe from receiving future emails, detailed unsubscribe instructions are included at the bottom of every commercial email we send.

How Long Do We Keep Your Information?

We keep your information only as long as we need it to provide the Luma & Home Service to you and to fulfil the purposes described in this policy. This is also the case for anyone with whom we share your information and who carries out services on our behalf. When we no longer need to use your information and it is not required to be kept by law, we will either remove it from our systems or depersonalise it so that we cannot identify you.

  • Order data and invoices: 7 years (Swedish bookkeeping law applies to the controller).
  • Customer support tickets: 12 months after the ticket is closed.
  • Newsletter subscription: until you unsubscribe.
  • Google Analytics 4: 14 months retention.
  • Cookies: per the lifetimes listed in our Cookie Policy, maximum 24 months.
  • Reviews: for as long as the product is listed on the site.

How Do We Protect Your Information?

We implement a variety of security measures to maintain the safety of your personal information when you place an order or enter, submit, or access your personal information. We use industry-standard encryption: all data transmitted between your browser and our servers is protected by TLS (HTTPS). All sensitive payment information is transmitted via Secure Socket Layer (SSL) technology and processed directly by our PCI-DSS compliant payment provider — we never store full payment card numbers on our systems.

After a transaction, your private payment information (credit card details, full bank account numbers) is never kept on file by Luma & Home. However, we cannot guarantee absolute security of the information you transmit to Luma & Home, or warrant that your information on the Service may not be accessed, disclosed, altered, or destroyed by a breach of any of our physical, technical, or managerial safeguards.

Could My Information Be Transferred to Other Countries?

Luma & Home is based in Sweden, in the European Union. Information collected via our website, through direct interactions with you, or from use of our support services may be transferred from time to time to processors located outside the United Kingdom or the European Economic Area, including the United States.

Transfers outside the UK or EEA are made under the UK's International Data Transfer Addendum (IDTA), the EU Standard Contractual Clauses, and the EU–US Data Privacy Framework where the recipient is certified. To the fullest extent allowed by applicable law, by using our Service you voluntarily consent to the cross-border transfer and hosting of such information for the purposes described in this Privacy Policy.

Is the Information Collected Through the Luma & Home Service Secure?

We take precautions to protect the security of your information. We have physical, electronic, and managerial procedures in place to help safeguard, prevent unauthorised access, maintain data security, and correctly use your information. However, neither people nor security systems are foolproof, including encryption systems. In addition, people can commit intentional crimes, make mistakes, or fail to follow policies. Therefore, while we use reasonable efforts to protect your personal information, we cannot guarantee its absolute security. If applicable law imposes any non-disclaimable duty to protect your personal information, you agree that intentional misconduct will be the standard used to measure our compliance with that duty.

Can I Update or Correct My Information?

The rights you have to request updates or corrections to the information Luma & Home collects depend on your relationship with us. Customers have the right to request the restriction of certain uses and disclosures of personally identifiable information. You can contact us to:

  • Update or correct your personally identifiable information,
  • Change your preferences regarding communications and other information you receive from us, or
  • Delete the personally identifiable information maintained about you on our systems (subject to the limitations below), by closing your account.

Such updates, corrections, changes, and deletions will not affect other information that we maintain, or information that we have provided to third parties under this Privacy Policy prior to such update, correction, change, or deletion. To protect your privacy and security, we may take reasonable steps (such as requesting verification of identity) before granting you account access or making corrections. You are responsible for maintaining the secrecy of your unique password and account information at all times.

You should be aware that it is not technologically possible to remove each and every record of the information you have provided to us from our system. The need to back up our systems to protect information from inadvertent loss means that a copy of your information may exist in a non-erasable form that will be difficult or impossible for us to locate. Promptly after receiving your request, all personal information stored in databases we actively use, and other readily searchable media, will be updated, corrected, changed, or deleted, as appropriate, as soon as and to the extent reasonably and technically practicable.

Your Rights Under UK GDPR

Under the UK GDPR and the Data Protection Act 2018, you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate personal data corrected.
  • Have your personal data erased.
  • Restrict how we use your personal data.
  • Receive your personal data in a portable format.
  • Object to processing based on legitimate interest, including direct marketing.
  • Withdraw your consent at any time.
  • Lodge a complaint with the UK Information Commissioner's Office at ico.org.uk . You may also complain to the Swedish data authority, IMY , as the controller is established in Sweden.

To exercise any of these rights, please email support@lumaandhome.co.uk. We respond to all verifiable requests within 30 days.

Personnel

If you are a Luma & Home worker or applicant, we collect information you voluntarily provide to us. We use the information collected for human-resources purposes to administer benefits to workers and screen applicants.

You may contact us to (1) update or correct your information, (2) change your preferences concerning communications and other information you receive from us, or (3) receive a record of the information we have relating to you. Such updates, corrections, changes, and deletions will not affect other information we maintain or information provided to third parties under this Privacy Policy prior to such update, correction, change, or deletion.

Sale of Business

We reserve the right to transfer information to a third party in the event of a sale, merger, or other transfer of all or substantially all of the assets of Luma & Home or any of its corporate affiliates (as defined herein), or that portion of Luma & Home or any of its corporate affiliates to which the Service relates, or in the event that we discontinue our business or file a petition or have filed against us a petition in bankruptcy, reorganisation, or similar proceeding, provided that the third party agrees to adhere to the terms of this Privacy Policy.

Affiliates

We may disclose information (including personal information) about you to our corporate affiliates. For purposes of this Privacy Policy, “Corporate Affiliate” means any person or entity that directly or indirectly controls, is controlled by, or is under common control with Luma & Home , whether by ownership or otherwise. Any information relating to you that we provide to our Corporate Affiliates will be treated by those Corporate Affiliates in accordance with the terms of this Privacy Policy.

Governing Law

This Privacy Policy is governed by the laws of the United Kingdom without regard to its conflict-of-laws provisions. You consent to the exclusive jurisdiction of the courts of the United Kingdom in connection with any action or dispute arising between the parties under or in connection with this Privacy Policy.

The laws of the United Kingdom, excluding its conflict-of-law rules, shall govern your use of the website. Your use of the website may also be subject to other local, state, national, or international laws. Nothing in this clause limits your statutory rights as a UK consumer.

Your Consent

We have updated our Privacy Policy to provide you with complete transparency into what is being set when you visit our site and how it is being used. By using our website, registering an account, or making a purchase, you hereby consent to this Privacy Policy and agree to its terms.

Links to Other Websites

This Privacy Policy applies only to the Services. The Services may contain links to other websites not operated or controlled by Luma & Home. We are not responsible for the content, accuracy, or opinions expressed in such websites, and such websites are not investigated, monitored, or checked for accuracy or completeness by us. Please remember that when you use a link to go from the Services to another website, our Privacy Policy is no longer in effect. Your browsing and interaction on any other website, including those that have a link on our platform, are subject to that website's own rules and policies. Such third parties may use their own cookies or other methods to collect information about you.

Advertising

This website may contain third-party advertisements and links to third-party sites. Luma & Home does not make any representation as to the accuracy or suitability of any of the information contained in those advertisements or sites, and does not accept any responsibility or liability for the conduct or content of those advertisements and sites, or the offerings made by the third parties.

Advertising helps keep Luma & Home and many of the websites and services you use free of charge or available at a reasonable cost. We work hard to ensure that advertisements are safe, unobtrusive, and as relevant as possible.

Third-party advertisements and links to other sites where goods or services are advertised are not endorsements or recommendations by Luma & Home of the third-party sites, goods, or services. Luma & Home takes no responsibility for the content of any of the ads, promises made, or the quality or reliability of the products or services offered in such advertisements.

Cookies for Advertising

These cookies collect information over time about your online activity on the website and other online services to make online advertisements more relevant and effective for you. This is known as interest-based advertising. They also perform functions like preventing the same ad from continuously reappearing and ensuring that ads are properly displayed for advertisers. Without cookies, it is very difficult for an advertiser to reach its audience or to know how many ads were shown and how many clicks they received.

Cookies

Luma & Home uses cookies to identify the areas of our website that you have visited. A cookie is a small piece of data stored on your computer or mobile device by your web browser. We use cookies to enhance the performance and functionality of our website, but these are non-essential to its use. However, without these cookies certain functionality such as remembering your basket or your login state would not be available, and you would be required to re-enter your details every time you visit the website. Most web browsers can be set to disable the use of cookies. However, if you disable cookies, you may not be able to access functionality on our website correctly or at all. We never place personally identifiable information directly in cookies.

For a full list of the cookies we use, their providers, and their lifetimes, please see our Cookie Policy. You can change your cookie choices at any time via cookie settings.

Blocking and Disabling Cookies and Similar Technologies

Wherever you are located, you may set your browser to block cookies and similar technologies, but this action may block our essential cookies and prevent our website from functioning properly, and you may not be able to fully utilise all of the website's features and services. You should also be aware that you may lose some saved information (for example, saved login details, site preferences) if you block cookies on your browser. Different browsers make different controls available to you. Disabling a cookie or category of cookies does not delete the cookie from your browser unless this is completed manually through your browser function.

Children's Privacy

Our Service is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you are under 13, you may use our website only with the involvement of a parent or guardian. If a parent or guardian discovers that a child has provided personal data to us, please contact us at support@lumaandhome.co.uk and we will delete it.

Changes to Our Privacy Policy

We may change our Service and policies, and we may need to make changes to this Privacy Policy so that they accurately reflect our Service and policies. Unless otherwise required by law, we will notify you (for example, through our Service) before we make material changes to this Privacy Policy and allow you to review them before they go into effect. If you continue to use the Service after the changes take effect, you will be bound by the updated Privacy Policy. If you do not want to agree to this or any updated Privacy Policy, you can close your account.

Third-Party Services

We may display, include, or make available third-party content (including data, information, applications, and other products or services) or provide links to third-party websites or services (“Third-Party Services”).

You acknowledge and agree that Luma & Home shall not be responsible for any Third-Party Services, including their accuracy, completeness, timeliness, validity, copyright compliance, legality, decency, quality, or any other aspect thereof. Luma & Home does not assume and shall not have any liability or responsibility to you or any other person or entity for any Third-Party Services. Third-Party Services and links thereto are provided solely as a convenience to you, and you access and use them entirely at your own risk and subject to such third parties' terms and conditions.

Contact Us

Don't hesitate to contact us if you have any questions regarding this Privacy Policy.

Contact Information

Last updated: 15 May 2026.