Privacy Policy

Luminara Privacy Policy

First Published: April 15, 2021
Last modified: March 9, 2026 (“Effective Date”)

Section 1. Introduction

Welcome to L&L Candle Company, LLC’s (“Luminara”) Privacy Policy.

This Privacy Policy details the types of information we may collect from you or that you may provide when you visit our website https://luminara.com/ or elsewhere and our practices for collecting, using, maintaining, protecting, and disclosing that information. It applies to information we collect both online and offline.

Not Intended for Children Under the Age of 16

Our Website is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are under 16, do not use this website or provide any information about yourself to us. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that information.

Section 2: Contact Information

If you have any questions, concerns, or complaints about our Privacy Policy, our data practices, or to exercise your data subject access rights, please feel free to contact us through the following channels:

    • Email Contact: For direct communication, you can email us at [email protected]. This email is monitored regularly, and we are dedicated to responding promptly.
    • Phone Contact: For immediate assistance, you may call our privacy team at (949) 408-3760 Ext. 6. Our team is available from 10 am to 4 pm (Pacific Time Zone), Monday through Friday except major holidays, to address your concerns.
    • By Mail: You can also mail us at 621 Lunar Avenue, Brea, CA 92821.

Section 3: Scope

Scope of This Policy This Privacy Policy applies universally to all users of our services and products within the United States. We sell and market exclusively to U.S. audiences, and as such, this policy is tailored specifically to meet the needs and legal requirements of our U.S. user base.

Section 4. Data Practices Table (Notice at Collection & 12-Month Disclosure)

We collect the following categories of personal information. This table serves as both our Notice at Collection and our historical disclosure of data practices.

Category of Personal Information Collected in Last 12 Months? Categories of Sources Business Purpose Shared with Third Parties for Cross-Context Ads? Retention Period
Identifiers (Name, IP, Email) YES Directly from you; Cookies; Social Media Partners (Meta/TikTok);Third-Party AI Platforms (e.g. Chat GPT). Order fulfillment; Marketing; Account security. YES: Ad Networks; Social Media Platforms; AI Platform Partners. Active account + 3 years.
Customer Records (Billing/Shipping) YES Directly from you; Agentic Storefront Connectors. Payment processing; Shipping. YES: AI Platform partners (for transaction updates). 7 years (Tax/Audit).
Commercial Info (Purchase history) YES Directly from you; Automated tracking. Customer trends; Inventory planning. YES: Analytics Providers. 5 years from last purchase.
Internet Activity (Browsing habits) YES Automatically via Cookies and Web Beacons. Site optimization; Personalization. YES: Ad Networks; Social Media Partners. 26 months.

More specifically, we use a third-party service provider to serve ads and/or collect data on our behalf across the Internet and sometimes on this website. Some of these service providers may collect information about your visits to our website, and your interaction with our products and services to tailor marketing messages on this website and other sites or to trigger real time interaction, customize this website or enhance your profile. Some of these service providers may be able to collect personal information that you share with this site via a web form automatically and prior to your pressing a submit button; and they may be able to use information from your visits to this site to send marketing messages to you in a way that may personally identify you. This information is collected through the use of a cookie, a JavaScript tag and/or pixel, which is industry standard technology used by most major websites. The information collected by these service providers may include your devices IP address, user agent, email addresses (where hashed or otherwise rendered pseudonymous) and other user and device level pseudonymous information. Please keep in mind that your browser settings may not permit you to control the technologies utilized by these third-party companies. If you would like more information about these practices, please click: http://optout.aboutads.info/#!/.

Finally, you may elect to receive text messages from us. When you sign up to receive text messages, we will send you information about promotional offers and more These messages may use information automatically collected based on your actions while on our sites and may prompt messaging such as cart abandon messages (IE Cookies). To the extent you voluntarily opt to have Text notifications sent directly to your mobile phone, we receive and store the information you provide, including your telephone number or when you read a text message. You may opt out of receiving text messages at any time by texting “STOP” to our text messages. For more information about text messages, see our Terms of Use. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, excluding aggregators and providers of the Text Message services.

Section 5: Sharing and Disclosure of Information

We may share your personal information by disclosing it to a third party for a business purpose or to fulfill our contract with you, or for any other legitimate purpose. We only make these business purpose disclosures under written contracts that describe the purposes, require the recipient to keep the personal information confidential, and prohibit using the disclosed information for any purpose except performing the contract.

Here are our practices in further detail:

    • Compliance with Law and Legal Requests: We may disclose information to comply with legal requirements and respond to law enforcement requests.
    • Business Transfers: During business transitions, such as mergers or acquisitions, your information may be transferred as part of the transaction.
    • With Your Consent: Your personal information may be shared with other third parties or used for additional purposes based on your explicit consent.
    • AI and Agentic Storefront Partners: If you initiate a purchase or inquiry through a third-party AI assistant or “agentic storefront” (e.g., ChatGPT, Google Gemini, or Microsoft Copilot), we disclose transaction-related data - such as order confirmation, tracking numbers, and fulfillment status - back to that platform. This allows the AI to provide you with real-time updates within your chat interface. Your interactions on those platforms are governed by the AI provider's own privacy terms.

Section 6: We Do Not Sell Personal Information:

We do not sell YOUR personal information. If this practice changes, we will update this policy and provide opt-out options as required by law.

Section 7: Consumer Rights and Choices

You may have the right to Access, Delete, Correct, or Opt-Out of the sale/sharing of your data. To exercise these rights, please contact us at [email protected]. We verify your identity by matching your provided email with our internal purchase records.

    • Right to Know and Access: You have the right to request information about the personal data we have collected, used, disclosed, and sold about you over the past 12 months.
    • Right to Deletion: You may request the deletion of your personal information that we have collected, subject to certain exceptions.
    • Right to Opt-Out of Sale or Sharing of Personal Information: While we do not sell personal information, should this practice change, you will have the right to opt-out of the sale or sharing of your personal information. We do however share your personal information with third parties as outlined elsewhere in this privacy policy. You have the right to opt out of this form of sharing. To opt out of sharing your personal information, or to obtain more information about your opt out rights, contact us at [email protected].
    • Right to Non-Discrimination: Exercising your privacy rights will not result in discriminatory treatment or penalties
    • Right to Correct Inaccurate Information: You have the right to request correction of inaccurate personal information held by us.
    • Right to Data Portability: Upon request, you have the right to receive a copy of your electronic personal information in a readily usable format.
    • How to Exercise Your Rights: To exercise any of these rights, please follow the steps below:
        • Submitting Requests: You can submit a request to know, access, or delete your personal information by contacting us at [email protected].
        • Verification Process: We will verify your identity before processing your request to protect your privacy and security.
        • Response Time: We will confirm receipt of your request within ten (10) business days. If you do not receive confirmation within the 10-day timeframe, please email [email protected]. We endeavor to substantively respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding our receipt of your request. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request. If any applicable state law requires a shorter response time, we will honor that timeline.
        • Assistance for Disabilities: If you need assistance due to a disability to access our policy or to exercise your rights, please contact us at [email protected].

Note on Agentic Transactions: When using an AI agent to facilitate a purchase, you may not see our full Privacy Policy at the moment of checkout. By authorizing an AI agent to transact with Luminara, you acknowledge that the data necessary to fulfill your order will be processed according to this Policy. You may exercise your right to access or delete this data at any time by contacting [email protected].

Section 8: Data Security Measures

At Luminara, we place a high priority on the security of your personal information. To protect your data from unauthorized access, disclosure, alteration, and destruction, we implement various security measures, including:

    • Advanced Technical Safeguards: Utilization of industry-standard encryption, firewalls, and secure server facilities.
    • Organizational Controls: Regular training for our employees on our privacy and security policies.
    • Regular Audits and Monitoring: Continuous monitoring of our systems and periodic audits to ensure the effectiveness of our security measures.
    • Data Breach Response Plan: In the event of a data breach requiring notification, we have a response plan in place to promptly notify affected individuals and take necessary remedial actions.

Section 9: Updates to the Privacy Policy

    • The date of the latest update or revision will be clearly displayed at the top of the Privacy Policy.
    • Should there be a need to modify or update our Privacy Policy, we will make these changes in a manner that is consistent with the applicable legal standards.
    • In the event of significant changes to our Privacy Policy, we will actively inform our users through various channels. This may include email notifications, alerts on our website, or other communication methods that ensure you are aware of the modifications.

Section 10: Canada Privacy Rights

Luminara understands the importance of transparent communication regarding the handling of personal information of Canada residents. In accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), we are providing information about the processing and transfer of Canadian personal information to the United States.

    • Data Processing Location: All personal data we collect from Canadian residents is exclusively processed and stored on servers located within the United States. This includes data processed by Luminara directly or through our third-party service providers.
    • Purpose of Data Transfer: The transfer of personal information to service providers in the United States is conducted for operational purposes essential to our business. These include order processing by Shopify, shipment information management by Pipe17, customer communication via Klaviyo, social media and advertising engagement through platforms such as Meta and TikTok, and enterprise resource planning with Oracle's NetSuite. Once transferred outside of Canada, Luminara may further use the data for purposes as otherwise outlined herein.
    • Privacy Compliance: We undertake to protect your data with the same level of security as would be required under Canadian law and to restrict use of the data to the purposes for which it was collected.
    • Right to Information: Canadian users have the right to obtain more detailed information on our policies and practices regarding our use of US-based service providers. To exercise your rights, please refer to Section 7: Consumer Rights and Choices.
    • Consent to International Transfer: By using our services and providing us with your personal information, you acknowledge and consent to the transfer of your data to the United States for the purposes described herein.

In cases where any aspect of our Privacy Notice may conflict with Canadian privacy law requirements applicable to you, the applicable Canadian federal or provincial law will take precedence. We will act accordingly to ensure compliance with Canadian law, respecting and adhering to the legal standards set by each state for the protection of personal data.

For additional information on privacy rights in Canada, Canada residents can consult the Office of the Privacy Commissioner of Canada.