Lumien Lighting
Privacy Policy

Privacy Policy

COLLECTION OF PERSONAL INFORMATION ​

When you use our Products or Website, you may be asked for personally identifiable information such as your name, address, email address, and telephone number.

By giving us such information, you will need to consent by using it in the manner described in this policy.

You may withdraw your consent at any time by emailing us at sales@lumienlighting.com. We will return or destroy your personal information within five days of receipt of your withdrawal of consent.

COOKIES ​

Cookies are small data files that a website you visit may save on your computer or handheld device that usually includes an anonymous unique identifier. Our Websites and those of our Products may use cookies for user authentication, keeping track of your preferences, promotional campaigns, tracking our audience size and traffic patterns, and in certain other cases. We may include small graphic images in our email messages and newsletters to determine whether the messages were opened and the links were viewed.

SECURITY ​

All security on our Website is treated seriously. Where applicable, we undertake security steps, including use of SSL technology, on our back-end systems that store customer account information and to protect data transmissions. However, this is not a guarantee that such data transmissions cannot be accessed, altered or deleted due to firewall or other security software failures.

If you have any further concerns about security, please email our Customer Service team.


Lumien App Privacy Policy
Version Date: July 2026
Effective Date: July 23 2026

1. Introduction and Scope

Welcome to the LUMIEN App (the "App," "LUMIEN," "we," "us," or "our"). LUMIEN is a smart landscape lighting control application that lets you configure, control, and manage smart lighting equipment (such as transformers and fixtures). The App supports two user roles: Contractors and Homeowners.

This Privacy Policy is issued by Lumien Enterprise Inc. (registered address: 1488 Bells Ferry Rd, Marietta, GA 30066). We operate the App and determine how personal information is collected, used, and shared in connection with the App.

This Privacy Policy applies only to the LUMIEN App and related services we provide. It does not apply to third-party websites, products, or services that you may reach through links or redirects from the App.

Please read this Privacy Policy carefully before using the App. When you first launch the App, we will present this Privacy Policy to you. Until you tap "Agree," the App and any embedded third-party SDKs will not collect your personal information and will not request system permissions. By tapping "Agree," you acknowledge and agree that you have read and understand this Privacy Policy and agree to all its terms. If you do not agree, please do not register for or use the App.

If we update this Privacy Policy, we will use reasonable efforts to notify you in the App, such as by notice, pop-up, or other prominent means. Where a change materially affects your rights under applicable law (for example, a change to the purposes of processing, how we process information, or the categories of personal information we collect), we will notify you before the updated version takes effect, where legally required. You can always view the latest version in the App under Privacy & About. Your continued use of the App signifies your consent to any updates to this Privacy Policy.


2. Information We Collect and How We Use It

We collect only the information needed to provide the App's features. Below we explain what we collect, why, and where it is stored.

2.1 Account Information
Item
Details
What we collect
Name (or company name), email address, phone number, and login password
Why we collect it
To create and authenticate your account, verify identity at sign-in, reset passwords, send system notices (such as project-handoff emails), and let collaborators identify you in shared projects
Where it is stored
On our cloud servers (authentication powered by Supabase, hosted on our cloud instance under the hyeco-smart.com domain). Passwords are transmitted using encryption; we do not store passwords in plain text
The App allows registration as either a Contractor or a Homeowner. Both roles provide the same types of account information, but project access rights differ (see Section 6).

2.2 Device and Project Data
Item
Details
What we collect
Project ("Location") details you create or receive: project name, street address, city, state/province, ZIP/postal code, and project description; transformer serial numbers and configuration relationships; fixture lists, custom fixture names and groups; lighting settings (brightness, color temperature, color, etc.); and schedules you set (name, run times, repeat rules, holiday selections, and custom special dates)
Why we collect it
To provide project management, device setup, lighting control, and scheduling, and so your projects and settings can be restored when you sign in on a new phone
Where it is stored
On our cloud servers, linked to your account. Project data is synced among accounts associated with that project (see Section 6)

You agree not to enter sensitive personal information in custom fixture names, project descriptions, or custom dates.


2.3 Location Information
Item
Details
What we collect
In certain features (such as device Wi-Fi setup), Android may require location permission to read Wi-Fi network names (SSID) and related information. When that happens, the App may access your device's precise and/or approximate location
Why we collect it
(1) To meet Android requirements for reading current Wi-Fi information used in device setup; and (2) to support scheduling-related features. Sunrise/sunset scheduling is calculated from the project address you enter—not from continuous GPS tracking on your phone. The App does not continuously collect your location in the background
Where it is stored
Device location accessed for these features is processed on the device as needed for the feature. We do not upload or retain a continuous real-time location history of your phone on our cloud servers. Project addresses you enter are stored as project data in the cloud (see Section 2.2)

2.4 Wi-Fi Setup Credentials
Item
Details
What we collect
The on-site Wi-Fi network name (SSID) and password you enter when setting up lighting devices
Why we collect it
To send Wi-Fi configuration to your lighting devices over the local network (multicast/broadcast using the Espressif ESPTouch protocol) so devices can join your local network
Where it is stored
Wi-Fi passwords are used only for the local setup process and are sent directly to the device over the local network. They are not uploaded to our cloud servers


2.5 Camera / QR Code Scanning
Item
Details
What we collect
When you use scan-to-add for a transformer, the App uses the camera to read the device serial number from a QR code or barcode
Why we collect it
To identify and bind your lighting device quickly without typing the serial number
Where it is stored
Camera frames are processed on your device in real time (on-device recognition via Google ML Kit). We do not save or upload camera images. The recognized serial number is stored as project data in the cloud (see Section 2.2)


2.6 Logs and Diagnostic Information

Item
Details
What we collect
Device operating logs and alerts, including power events (voltage issues, power restore), fixture events (offline, command failure, timeout), schedule execution records (start/end/conflict), device online/offline status, and timestamps, types, and results of command execution
Why we collect it
To show device status and fault information in the App and to support troubleshooting and remote diagnostics (for example, read-only diagnostics by a Contractor during a warranty period)
Where it is stored
On our cloud servers. Associated project accounts can view this information in the App (after project handoff, Contractors have read-only access)
Information we do not collect: The App does not integrate advertising SDKs, analytics SDKs, or push-notification SDKs. We do not collect your contacts, SMS messages, call logs, or installed app list, and we do not use your personal information for advertising or interest-based profiling.

3. Device Permissions

To provide certain features, the App may request the following system permissions when you use the related feature (only after you agree to this Privacy Policy, and only at the time of use). You can turn permissions off at any time in your device settings. Turning a permission off affects only the related feature.
Permission Purpose Can you turn it off? What happens if you do?
t access (INTERNET)
Communicate with our cloud servers for sign-in, project sync, and remote device control
Core system capability; cannot be turned off separately. Without network access, remote control and cloud sync are unavailable
Network state (ACCESS_NETWORK_STATE)
Check whether the device is connected to a network
Core system capability; cannot be turned off separately
Precise location (ACCESS_FINE_LOCATION)
Required by Android to read current Wi-Fi information for device setup; also supports scheduling features
Yes. Device Wi-Fi setup will be unavailable
Approximate location (ACCESS_COARSE_LOCATION)
Same as above, as a fallback
Yes. Device Wi-Fi setup may be unavailable
Wi-Fi state (ACCESS_WIFI_STATE)
Read current Wi-Fi connection details for setup
Yes. Device Wi-Fi setup will be unavailable
Change Wi-Fi state (CHANGE_WIFI_STATE)
Switch/connect networks during setup
Yes. Device Wi-Fi setup will be unavailable
Wi-Fi multicast (CHANGE_WIFI_MULTICAST_STATE)
Send setup data to devices over local-network multicast (ESPTouch)
Yes. Device Wi-Fi setup will be unavailable
Nearby Wi-Fi devices (NEARBY_WIFI_DEVICES)
On Android 13+, discover nearby Wi-Fi devices for setup (declared as not used to infer location)
Yes. Setup on affected Android versions will be unavailable
Camera (CAMERA)
Scan transformer/device QR codes to add devices
Yes. Scan-to-add will be unavailable; you can still enter serial numbers manually
Microphone (RECORD_AUDIO)
Declared by the camera component (expo-camera). The App does not use recording features and does not record or collect audio
Yes. Turning it off does not affect any App features we provide
Read storage (READ_EXTERNAL_STORAGE)
Read local files (declared by a file-system component)
Yes. Turning it off does not affect core lighting control
Write storage (WRITE_EXTERNAL_STORAGE)
Write local files (applies mainly on older Android versions; newer versions use scoped storage)
Yes. Turning it off does not affect core lighting control
Vibrate (VIBRATE)
Haptic feedback for certain actions
Yes. You will not feel vibration feedback; features still work
Important notes: This version of the App does not request Bluetooth permissions (device setup uses Wi-Fi, not Bluetooth) and does not request push-notification permission (this version does not provide in-App push notifications; system notices are delivered by email).

4. Third-Party SDKs and Service Providers

We use the following third-party SDKs and service providers to operate the App. We require them to protect your information in accordance with their privacy policies. The App does not integrate advertising, analytics, or push-notification SDKs.

SKD/Service Provider Purpose Types of data Privacy Policy
Supabase (supabase-js)
Supabase, Inc.
Cloud backend: authentication, database, file storage, real-time sync
Account information (name, email, phone), authentication credentials, and business data (projects, devices, schedules, etc.)
https://supabase.com/privacy
ESPTouch (Espressif SmartConfig)
Espressif Systems
Send Wi-Fi credentials to smart lighting devices over local-network multicast/broadcast
Wi-Fi SSID and password (processed on the local network only; not uploaded to the internet)
https://www.espressif.com/en/privacy-policy
Google ML Kit Barcode Scanning
Google LLC
On-device recognition of device QR codes/barcodes
Camera frames (processed on your device by default; not sent off-device for this purpose)
https://developers.google.com/ml-kit/terms
Google Play Services (including location services and barcode scanner components)
Google LLC
System-level location services and Google platform services used by ML Kit
Device location (when location features are used), device identifiers, and related data as described by Google
https://policies.google.com/privacy
Expo Modules (including expo-camera, expo-location, expo-file-system, and related modules)
Expo (Expo Technologies, Inc.)
App framework and camera, location, and file modules
Device locale/language and similar device settings; camera, location, and file access only when you use the related features
https://expo.dev/privacy
For Google ML Kit, barcode recognition is performed on your device by default. If your device uses Google Play Services barcode-scanning components, that processing is governed by Google's privacy policy. We review third-party SDKs on an ongoing basis and will update this section when the list changes.

5. Storage and Security

5.1 Where We Store Information

Your personal information is stored on our cloud servers (Supabase service instance, domain hyeco-smart.com). Server location: United States.

5.2 How Long We Keep Information

We keep personal information only as long as needed for the purposes described in this Privacy Policy:

• Account information: from registration until you delete your account;
• Project and device data: from creation until you delete the project or delete your account;
• Logs and diagnostic information: for as long as needed for troubleshooting, then deleted or de-identified;
• Longer retention where required by law.

After the retention period ends, we delete or de-identify the information.

5.3 Security Measures

We use safeguards designed to protect your personal information, including:

• Encrypted transmission (HTTPS/TLS) for passwords and data in transit;
• Account-based access controls so project data is visible only to authorized associated accounts;
• Access controls on cloud services so only authorized personnel can access data when needed.

No method of transmission or storage over the internet is 100% secure. If we become aware of a security incident affecting your personal information, we provide notice as required by applicable law.


6. Sharing, Sale, Transfer, and Disclosure

6.1 Disclosure

We do not disclose your personal information to third parties except in the following cases:

A. Service providers / SDKs. Processing by SDKs and providers needed to operate the App, as listed in Section 4.

B. Project collaboration visibility (part of the product). For example:

· When a Contractor creates a project and starts a handoff to you (Homeowner), the Contractor enters the email address you provided;

· In Contractor Management, invited Collaborating Contractors on a project can see one another's name, email address, phone number, and join date;

· After handoff, project data (project details, device status, fixture activity, and logs) is visible to the Homeowner, invited household members (with the same access as the Homeowner), and the Contractor (read-only after handoff, for warranty-period remote diagnostics);

· You can remove invited household members or Collaborating Contractors at any time in member management; after removal, they lose the related access.

C. Legal requirements. When required by applicable law, legal process, or government request.


6.2 Sale of Personal Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use your personal information for targeted advertising.

6.3 Transfer

We may transfer your personal information to another company, organization, or individual in connection with a merger, acquisition, reorganization, asset sale, or similar transaction.


6.4 Public Disclosure

We do not publicly disclose your personal information, except where required by applicable law or a valid government request.

7. Your Privacy Rights and Choices

Depending on where you live (including under applicable U.S. state privacy laws such as the California Consumer Privacy Act, as amended by the CPRA, and applicable Canadian privacy laws), you may have some or all of the following rights regarding your personal information.


7.1 Access and Portability

You can view your account profile, project information, device data, and logs in the App at any time. To request a copy of your personal information, contact us using the details in Section 9.


7.2 Correction

You can update your name, phone number, and password in App settings. You can edit project information in project management.

7.3 Deletion

You can delete projects you created in the App (deleting a project also removes associated transformers, fixtures, groups, and schedules and cannot be undone). To request deletion of other personal information, contact us using the details in Section 9.


7.4 Withdraw Consent / Manage Permissions

You may withdraw consent or limit collection by turning off permissions in your device settings (see Section 3) or by contacting us to withdraw consent to this Privacy Policy. After you withdraw consent, we will stop the related processing going forward. Withdrawal does not affect processing that already occurred based on prior consent. Some features depend on certain information or permissions and may no longer work after withdrawal.

7.5 Account Deletion

To delete your account, email the privacy contact listed in Section 9 (Privacy Contact Email). After we receive and verify your request, we will complete account deletion timely, generally within 15 business days. After account deletion, we will delete or de-identify your personal information, except where we are required to retain it by law. Account deletion permanently removes your account and all associated cloud projects, device configurations, and schedules. This cannot be undone.


7.6 How We Respond to Requests

To protect your account, we may need to verify your identity before fulfilling a request. We aim to respond within the time required by applicable law (and, where not otherwise specified, within 15 business days). If you are not satisfied with our response, you may contact us again using the channels in Section 9. Residents of certain U.S. states may also have the right to appeal our decision; if we deny your request, we will explain how to appeal where required.


8. Children's Privacy

The App is intended for adult users. We do not knowingly collect personal information from children under 13 years of age (or the equivalent age of digital consent in your jurisdiction). If you are under 13, please do not register for or use the App or provide any personal information to us.

If we are notified that we have collected personal information from a child under 13 without verifiable parental consent where required, we will delete that information as soon as reasonably practicable. If you are a parent or guardian and believe your child under 13 has provided personal information to us, please contact us using the details in Section 9.

9. How to Contact Us

If you have questions, comments, requests, or complaints about this Privacy Policy or our handling of personal information, contact us at:

• Privacy contact email: sales@lumienlighting.com
• Phone: 770-485-9002
• Mailing address: 1488 Bells Ferry Rd, Marietta, GA 30066

After we receive your message and verify your identity where needed, we will respond within 15 business days (or sooner if required by applicable law).

10. Appendix: Features, Permissions, and Data
Feature
Permissions used
Personal information involved
How it is processed
Register / sign in / reset password
Internet
Name (or company name), email, phone, password
Sent to cloud (encrypted in transit)
Create and manage projects
Internet
Project name, street address, city, state/province, ZIP/postal code, description
Stored in cloud; synced among associated accounts
Scan to add transformer
Camera
Device serial number (camera frames processed on-device)
Serial number stored in cloud; camera frames stay on devic
Wi-Fi device setup
Precise/approximate location; Wi-Fi state read/change; Wi-Fi multicast; nearby Wi-Fi devices
Wi-Fi SSID and password; current Wi-Fi information
Sent to the device over the local network only; not uploaded to cloud
Sunrise/sunset scheduling
Internet
Project address (used to derive coordinates and time zone)
Calculated from project address in the cloud; does not collect continuous phone GPS
Lighting control and grouping
Internet
Fixture names, groups, lighting parameters
Stored in cloud and sent to devices
Schedule automation
Internet
Schedule name, timing rules, holiday selections, custom dates
Stored in cloud and executed on schedule
Faults and logs
Internet
Device logs, alerts, command records
Stored in cloud; shown in App to associated accounts
Project handoff / member invites
Internet
Recipient's registered email; collaborators may see name/email/phone
Processed in cloud; notification emails sent
Haptic feedback
Vibrate
None
On device only
Display language
None (language preference is an account setting)
UI language preference
Saved with account settings
Version date: July 2026.
This Privacy Policy is issued by Lumien Enterprise Inc..