This notice explains how LumiDesk (“we”, “us”, “our”) handles personal data when you visit our websites, book a walkthrough, send an enquiry, or when a shop uses LumiDesk Loyalty Core (our SMS stamp-card loyalty product) for its customers.
Domains: lumideskai.com and lumideskai.co.uk
1. Who we are
LumiDesk provides digital tools for UK local businesses, including Loyalty Core — stamp-card loyalty that runs on SMS. We are a small UK SaaS provider. For company registration details, registered office address, or ICO registration status, please contact us using the details above. We do not invent registration numbers on this page.
2. What this notice covers
- Visitors to our marketing sites (lumideskai.com and lumideskai.co.uk)
- People who book a walkthrough or submit an enquiry form
- Business contacts (shop owners and staff) who buy or trial Loyalty Core or other LumiDesk services
- End customers of shops that use Loyalty Core (where we process data on behalf of the shop)
3. Roles: controller and processor
When we are the controller
We are the data controller for marketing-site visitors, walkthrough bookings, enquiries, and our own customer/prospect records (shop owners and authorised staff contacts).
When we are the processor
For Loyalty Core end customers (the people who scan a shop’s QR and join that shop’s stamp card), the shop is typically the controller. We process that data to deliver the service on the shop’s instructions. Shops should point their members to their own privacy information and to this notice where relevant.
4. Personal data we collect
From our websites and forms
- Name, email address, phone number, business name and any message you send
- Booking details if you schedule a walkthrough (date, time, contact details)
- Technical data such as IP address, browser type, device type and basic usage logs (where our hosting or analytics tools collect them)
From Loyalty Core (shop members)
- First name and UK mobile number provided on the join form
- Recorded SMS marketing/loyalty consent (the consent box starts unticked; we store the choice when someone opts in)
- Stamp balances, reward codes, redemption events and related service messages
- STOP / opt-out requests and related timestamps
From shop operators
- Business and billing contact details
- Authorised staff mobile numbers used for STAMP, REMOVE and REDEEM commands
- Configuration such as reward threshold, Google review link and privacy notice URL
We do not ask for payment card details on the marketing site. Payment arrangements, if any, are handled separately.
5. Why we use personal data (purposes and lawful bases)
Under UK GDPR we rely on one or more of the following:
- Contract — to provide Loyalty Core and related services you have asked for, including sending transactional SMS (welcome, stamp balance, reward codes, staff confirmations)
- Consent — for SMS loyalty/marketing messages where consent is required; consent is recorded and can be withdrawn by replying STOP (or by contacting us or the shop)
- Legitimate interests — to respond to enquiries, improve our sites and service, keep systems secure, and (where appropriate) send limited service or reactivation messages that are part of Loyalty Core as described to the shop
- Legal obligation — where we must keep records for tax, accounting or regulatory reasons
6. SMS, consent and STOP
Loyalty Core is an SMS product. When someone joins a shop’s stamp card:
- SMS consent starts unticked on the join form
- We record consent when the person opts in
- Welcome and stamp-related texts are part of running the card
- STOP is honoured from the first text — reply STOP to opt out of further SMS from that programme
Shops are responsible for ensuring their use of Loyalty Core (including any wording and timing) complies with PECR and UK GDPR. We help with recorded consent and STOP handling as part of the product design.
7. Who we share data with
We use carefully chosen processors to run the service. Depending on the feature, this may include:
- HighLevel (LeadConnector) — CRM, booking widgets and enquiry forms embedded on our sites
- SMS and telecom providers — to send and receive texts
- Hosting providers — to serve the websites (for example Netlify or similar)
- Email and productivity tools — to reply to you
We do not sell personal data. We may disclose data if required by law or to protect rights, safety or security.
8. International transfers
Some processors may store or process data outside the UK. Where that happens, we expect appropriate safeguards (such as UK adequacy regulations or standard contractual clauses) to be in place. Ask us if you need more detail about a specific processor.
9. How long we keep data
- Enquiries and walkthrough bookings — while we are in contact, then for a reasonable period afterwards (typically up to 24 months unless you ask us to delete sooner and we have no lawful reason to retain)
- Customer/shop accounts — for the life of the contract and then as needed for accounting and dispute resolution
- Loyalty Core member data — while the shop’s programme is active and as instructed by the shop; after cancellation we retain only what we need for backup, security or legal reasons, then delete or anonymise
- STOP / consent records — kept long enough to demonstrate compliance and honour opt-outs
10. Security
We use access controls, reputable processors and sensible operational practices to protect personal data. No method of transmission or storage is perfectly secure; if you suspect a problem, contact us straight away.
11. Your rights
Under UK data protection law you may have the right to access, rectify, erase, restrict or object to certain processing, and to data portability, and to withdraw consent where we rely on it. To exercise these rights, email Nick@lumideskai.com.
If you are an end customer of a shop using Loyalty Core, it is often quickest to contact that shop first (they are usually the controller). You can also contact us and we will help route the request.
You may complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
12. Cookies and similar technologies
Our marketing sites are primarily static. Embedded booking or form widgets (for example HighLevel) may set cookies or similar technologies needed for the widget to work. Your browser settings control cookies; blocking some cookies may break booking or forms.
13. Children
Our services are aimed at UK businesses and adult customers. We do not knowingly market Loyalty Core join flows to children.
14. Changes
We may update this notice from time to time. The “Last updated” date at the top will change when we do. Significant changes will be reflected on this page.
15. Contact
Questions about privacy or this notice:
Nick Gould · LumiDesk
Email: Nick@lumideskai.com
Phone / SMS: +44 7401 144361
Web: lumideskai.com · lumideskai.co.uk