Zero Personally Identifiable Information (PII) Stored for Push Subscribers
When visitors subscribe to push notifications on websites running LumaPush, we never ask for or store names, emails, phone numbers, or physical locations. Subscriptions are strictly anonymous, encrypted browser endpoints (W3C standard).
1. Introduction
LumaPush Technologies ("LumaPush," "we," "our," or "us") provides a next-generation web push notification software-as-a-service platform for digital publishers, media companies, SaaS organizations, and e-commerce stores.
This Privacy Policy details our practices concerning data collection, usage, storage, security, and disclosure when you access lumapush.com, use our web push administration platform, or interact with websites that embed our client-side push notification script.
2. Information We Collect
We process information across two primary categories:
- Account Holders (Publishers / Clients): Individuals and entities creating an account to manage push campaigns, domains, and team members.
- End Subscribers: Website visitors who choose to click "Allow" on push permission prompts on client-managed domains.
3. Account & Billing Information
When registering an account, we collect your name, email address, and hashed authentication credentials. Paid plan transactions are processed securely through PCI-DSS compliant payment processors (e.g., Stripe, PayPal, Razorpay, or Binance Crypto Gateway). LumaPush does not store raw credit card numbers or banking secrets on our servers.
4. Web Push Notification Architecture
LumaPush operates strictly within standard browser Web Push API standards (W3C Push API, Service Workers, and PushManager). When a user opts in to receive notifications:
- The browser requests a unique push subscription from the operating system push service (Google Firebase Cloud Messaging for Chrome/Edge, Apple APNs for Safari, Mozilla Autopush for Firefox).
- This subscription consists of a unique URL endpoint and two public cryptographic keys:
p256dh(public ECDH key) andauth(authentication secret). - All notification payloads dispatched by LumaPush are encrypted end-to-end using RFC 8291 Web Push Encryption.
5. Subscriber Data & No PII Commitment
We are staunch believers in privacy-by-design. Web push subscribers are identified purely by mathematical cryptographic tokens. We do not correlate subscriber tokens with external identity profiles, social security numbers, or real identities.
6. How We Use Data
Collected data is used strictly for the following operational requirements:
- Dispatching authorized push notifications scheduled by account holders.
- Displaying real-time CTR, impression counts, and delivery analytics inside the dashboard.
- Preventing fraudulent spam blasts and enforcing platform security.
- Providing 24/7 technical customer support and resolving delivery inquiries.
7. GDPR, CCPA & Legal Compliance
Under European Union General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA):
- Consent: Push notifications are only delivered after explicit, affirmative browser permission ("Allow").
- Revocability: Subscribers can revoke permission at any second directly through browser site settings without needing to contact LumaPush.
- Data Portability: Account owners can export all domain subscribers and campaign telemetry in JSON format at any time.
8. Data Security & Encryption
All data in transit is protected using TLS 1.3 encryption. Internal database clusters utilize AES-256 encryption at rest, parameterized queries, and strict role-based access control (RBAC).
9. Data Retention & Deletion
Account data is retained for as long as your account remains active. If a subscriber revokes permission or uninstalls their browser, their endpoint token returns an HTTP 410 Gone status and is automatically pruned from our database.
10. Third-Party Service Providers
We do not sell, rent, or monetize subscriber data to third-party data brokers or advertising exchanges. We only share operational data with vetted infrastructure sub-processors necessary to run the service.
11. Your Rights & Controls
You have the right to request access to, correction of, or complete erasure of your account data. You may exercise these rights at any time by contacting our privacy compliance team.
12. Contact Data Protection Officer
For all privacy queries, data subject requests, or regulatory communications, please reach out directly:
