Privacy Policy
Effective 19 August 2026
The short version
We collect what the product needs to work: your account details, the campaign data you and your suppliers enter, and a log of what happened. There is no advertising, no third-party analytics, and no tracking across other websites. We do not sell personal data and we do not train machine learning models on your content. Three companies process data on our behalf, all named below. Any administrator can download the whole workspace at any time, and you can ask us to delete it.
This policy explains what LumoSheet ("we", "us") does with personal data in the LumoSheet application at app.lumosheet.com and on the lumosheet.com website.
1. Two different roles
Which role we hold depends on the data, and it changes what you should ask us versus what you should ask the buying organization.
- We are the controller for the data we need to run our business: account records, billing details, support conversations, demo requests from the website, and server logs. This policy governs that data.
- We are a processor for everything inside a customer's workspace: campaigns, submitted line items, uploaded files, notification history, and the audit trail. The buying organization that owns the workspace is the controller, decides what goes in, and decides how long it stays. We act on their instructions. If you are a supplier contact and want your campaign data changed or removed, ask the buyer who invited you. If you ask us, we will pass it to them.
2. What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Name, work email, organization name, hashed password, timezone and display preferences, role in the workspace | To create your account, sign you in, and address you correctly |
| Workspace content | Campaigns, schemas, submitted line items, decisions and their reasons, comments, supplier and vendor records | This is the product. It exists because you entered it |
| Uploaded files | Attachments and Excel workbooks suppliers submit, with their file name, type, and size | To store, scan, and serve them back to the people entitled to see them |
| Activity and audit | Sign-ins, mutations with the acting user and a timestamp, notification and email history including subject and body | Accountability inside the workspace, and support when something needs explaining |
| Billing | Plan, seat count, subscription and customer identifiers from Stripe | To bill the right amount. We never receive or store card numbers |
| Website enquiries | Name, email, company, and the message on the demo request form | To answer you |
| Technical logs | IP address, request path, timestamp, error traces | To keep the service up and to investigate abuse and faults |
We do not ask for special-category data, government identifiers, or payment card numbers, and the product has no field that calls for them. Do not put them in free-text fields.
3. Cookies
We use four cookies, all first-party and all functional. There is no advertising cookie, no third-party analytics script, and no cross-site tracking anywhere on the site or in the app.
| Cookie | Purpose | Lifetime |
|---|---|---|
| ch_session | Keeps you signed in | 14 days, cleared on sign out |
| ch_theme | Remembers light or dark | 1 year |
| ch_tag_scope | Remembers which brand a broker narrowed their screens to | Until changed or cleared |
| ch_sso | Holds the single sign-on request while your identity provider answers | Minutes, deleted when the sign-in completes |
The marketing site also stores your light or dark preference in your browser's local storage. None of this needs a consent banner because none of it tracks you.
4. Why we are allowed to process it
Where the UK or EU GDPR applies, our legal bases are: performance of a contract, for account, workspace, and billing data; legitimate interests, for security logging, abuse prevention, and answering enquiries you send us; and legal obligation, for tax and accounting records. For workspace content we process on a customer's instructions, that customer determines the basis.
5. Who else processes data
We keep this list short on purpose. These are our sub-processors:
| Provider | What they do | Where |
|---|---|---|
| Railway | Application hosting, database, and file storage | United States |
| Resend | Delivers the notification and system emails we send on your behalf | United States |
| Stripe | Processes payments and holds card details, which never reach us | United States |
Each is bound by a data processing agreement. We will give at least 30 days notice by email to workspace administrators before adding a sub-processor that handles workspace content. Beyond these, we disclose data only when the law compels it, and we will tell you unless we are prohibited from doing so.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use your content to train machine learning models.
6. Where data is stored
The application, its database, and uploaded files are hosted in the United States. If you are in the UK or EEA, that means your data is transferred to the United States, and we rely on the Standard Contractual Clauses with our providers for that transfer. Traffic to the service uses TLS, and our hosting provider encrypts stored data at rest.
7. How long we keep it
| Data | Kept for |
|---|---|
| Workspace content on an active plan | As long as the workspace exists. The customer decides |
| An expired trial | Read-only for 60 days after expiry, then permanently deleted with two email warnings first |
| A closed paid workspace | Read-only for 30 days so you can export, then deleted |
| Sign-in sessions | 14 days, or until you sign out |
| Audit trail and email log | The life of the workspace, then deleted with it |
| Technical logs | 30 days |
| Backups | Purged within 35 days on their own rotation |
| Billing and tax records | As long as the law requires, typically 7 years |
8. Security
- Every organization's data is separated at the data layer, not by a filter in the interface. An adversarial test suite runs on every change and tries to cross that boundary and the boundary between suppliers; a failure blocks the release.
- Passwords are hashed with scrypt. We never store or email them in readable form.
- Single sign-on client secrets are encrypted at rest.
- Every upload is checked against an allow-list of file types, size-limited, and scanned for malware before anyone can download it. A file that cannot be scanned is not served.
- Every change in a workspace is written to an audit trail attributed to the person who made it, which administrators can read.
If a breach affects your data we will notify the relevant administrators without undue delay, and any regulator required, within the deadline that applies.
9. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict, or object to our processing of your personal data, and to receive it in a portable form.
- Portability is built in. Any workspace administrator can download the entire workspace as one Excel workbook from the admin area, at any time, on any plan, without asking us.
- Write to [email protected] for anything else. We respond within 30 days.
- If your data sits inside a customer's workspace, we will route the request to that customer, who is the controller, and support them in answering it.
- You can complain to your data protection authority. We would rather you came to us first.
10. If you are a supplier contact
Your account was created because a buying organization invited you to one of their campaigns. Your account is free and always will be. You see only the campaigns you were invited to and only the brands assigned to you, and other suppliers cannot see your submissions. The buyer who invited you controls the campaign data you submit, so questions about correcting or removing it go to them first.
11. Children
LumoSheet is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children.
12. Changes to this policy
If we make a material change we will email workspace administrators at least 30 days before it takes effect, and the effective date at the top of this page will change.
13. Contact
Privacy questions and requests go to [email protected].