Privacy Policy
Last updated: May 4, 2026
1. Introduction
Lunipay LLC, doing business as LuniPay ("Company," "we," "us," "our," or "LuniPay"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and otherwise process information when you access and use our website, mobile applications, hosted payment pages, developer tools, and services (collectively, the "Service").
This Privacy Policy applies to:
- Business users who create LuniPay accounts ("Merchants")
- Customers of Merchants who receive invoices and make payments ("Customers")
- Visitors to our website and marketing pages ("Visitors")
Please read this Privacy Policy carefully. If you do not agree with our practices, please do not use our Service. By using LuniPay, you acknowledge that your information will be handled as described in this policy.
2. Information We Collect
2.1 Account Information
When you create a LuniPay account, we collect information such as:
- Full name and email address
- Business name and business registration details
- Physical business address
- Phone number
- Tax identification number or VAT registration
- Bank account information (for payouts)
- Profile picture or business logo (uploaded through Uploadthing)
2.2 Payment and Financial Information
When you use LuniPay to process payments, we collect financial transaction data. Importantly:
- LuniPay does not store credit card numbers or sensitive payment card data. All payment processing is handled securely by Stripe, our PCI-DSS compliant payment processor.
- We collect payment metadata including transaction amounts, currencies, payment methods used (card brand, funding type, last 4 digits where available), transaction timestamps, authorization status, settlement status, and payment status.
- We maintain records of balances, transfers, reversals, reserves, payouts to your bank account, payout destinations, payout amounts, processing fees, and FX conversions.
- We store invoice, payment link, subscription, installment, and checkout data including line items, amounts, payment history, receipts, customer communications, and hosted payment page activity.
- We collect Stripe Connect account information, including account identifiers, verification requirements, capability status, onboarding status, external account status, fraud signals, refund records, dispute records, and chargeback evidence.
2.3 Transaction and Invoice Data
We collect and store all invoice, payment link, recurring billing template, and installment plan data you create, including:
- Invoice descriptions, quantities, and pricing
- Dates (due dates, payment dates, payout dates)
- Payment statuses (draft, sent, viewed, paid, overdue, partially paid)
- Dispute and chargeback information
- Reminder history and engagement metrics
2.4 Customer Data (Your Customers)
When you add customers to LuniPay or send them invoices, we collect information about your customers, including:
- Customer name and email address
- Customer phone number
- Business/company information (for B2B invoices)
- Shipping/billing addresses (if provided)
- Information they enter when paying an invoice or accessing the customer portal
Important: For customer information that you enter to manage your own customer relationship, you are generally the data controller and LuniPay acts as a processor. LuniPay may also act as an independent controller where we use customer or payment information for payment operations, fraud prevention, security, disputes, compliance, support, reporting, or legal protection. You are responsible for obtaining necessary consents from your customers and complying with applicable data protection laws.
2.5 Usage and Analytics Data
We automatically collect information about how you use our Service:
- Device information (device type, operating system, browser type, browser version)
- IP address and geolocation data
- Pages visited, features used, and time spent on each page
- Clickstream data and navigation patterns
- Performance metrics (page load times, errors encountered)
- Search queries and filters you apply
This data is collected through analytics and monitoring tools including Vercel Analytics, PostHog, and error monitoring via Sentry.
2.6 Authentication Data
We collect authentication information to verify your identity:
- For Google OAuth: we receive your Google account profile information including name and email from Google
- For email/password authentication: we store a cryptographically hashed version of your password (we do not store your password in plain text)
- Session tokens and authentication cookies to maintain your login state
- For customer portal access: magic link tokens and session data
2.7 Mobile, Wallet, Notification, and Developer Data
When you use LuniPay mobile, wallet, notification, or developer features, we may collect additional operational data, including:
- Device platform, app version, notification permission status, Expo push tokens, browser push subscriptions, and related delivery records
- Apple Wallet pass identifiers, Apple device library identifiers, Apple push tokens, pass update status, and pass download or registration activity
- Tap to Pay readiness status, supported-device checks, setup state, terms acceptance status, acceptance timestamps, and information needed to diagnose reader or checkout failures
- Developer API keys metadata, API request logs, webhook endpoint settings, webhook delivery attempts, response codes, retry history, and event payload metadata
2.8 Communications
We collect information when you communicate with us:
- Contact form submissions (name, email, subject, message)
- Customer support inquiries and replies
- Email addresses you provide for notifications and invoices
- Feedback and bug reports you submit
2.9 Information from Third Parties
We may receive information about you from:
- Stripe: account verification status, account balance, charge history, dispute data
- Google: when you authenticate via Google OAuth
- Your customers: when they provide information to pay your invoices
- Team members: when they are invited to your organization
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve the LuniPay platform and features
- Payment Processing: To process payments, issue payouts, manage connected accounts, apply platform fees and reserves, process refunds, and maintain financial records
- Account Management: To create and manage your account, process sign-ups and password resets
- Communications: To send transactional emails (invoices, receipts, payment confirmations), service updates, and customer support responses
- Marketing: With your consent, to send promotional emails about new features, product updates, or special offers
- Analytics & Improvement: To understand how you use LuniPay, identify usage patterns, and optimize our service
- Fraud Prevention & Security: To detect, prevent, investigate, and address fraud, abuse, account takeover, customer complaints, and security incidents
- Compliance: To comply with legal obligations, including tax reporting, anti-money laundering (AML) requirements, and regulatory inquiries
- Dispute Resolution: To investigate and resolve disputes, chargebacks, refunds, evidence reviews, and complaints
- Legal Protection: To enforce our Terms of Service and other agreements, and to protect our legal rights
4. How We Share Your Information
We may share your information with the following categories of recipients:
4.1 Service Providers and Processors
We share information with third-party service providers who help us operate our Service:
- Stripe: For payment processing, invoicing, Connect account management, financial data, payouts, refunds, disputes, verification, and compliance
- Neon: For secure cloud database hosting of operational account, payment, invoice, customer, ledger, and reporting data
- SendGrid: For sending transactional and marketing emails
- Vercel: For hosting, server infrastructure, analytics, and performance monitoring
- Sentry: For error tracking and application monitoring
- PostHog: For product analytics, feature usage, session diagnostics, and account-level product insights
- Uploadthing: For secure file storage (logos, invoice PDFs, documents)
- Upstash: For Redis caching, rate limiting, and session management
- Trigger.dev: For scheduled jobs, background processing, notification delivery, webhook retries, and other operational workflows
- Expo, Apple, Google, and browser push providers: For mobile push notifications, web push notifications, wallet passes, and device-level platform services
- NextAuth.js: For authentication infrastructure and session management
All service providers are contractually obligated to use your information only as necessary to provide their services and to maintain the confidentiality and security of your data.
4.2 Your Customers
When you send an invoice or payment link to a customer, they will receive your business name, contact information, invoice or payment details, and any other information you choose to include. They may access the customer portal using a magic link, where they can view their payment history and manage their payment methods.
4.3 Team Members
If you invite team members to manage your LuniPay account, they may have access to your customer data, invoices, and financial information based on their assigned role and permissions.
4.4 Legal Requirements and Enforcement
We may disclose your information when required by law or when we believe in good faith that such disclosure is necessary to:
- Comply with legal process (subpoena, warrant, court order)
- Enforce our Terms of Service and other agreements
- Respond to government or law enforcement requests
- Protect the safety, rights, and property of LuniPay, our users, or the public
- Prevent fraud, security incidents, or other illegal activities
- Investigate customer complaints, suspected scams, refund requests, chargebacks, payout reviews, or merchant compliance concerns with Stripe, card networks, banks, affected customers, or other parties involved in the transaction
4.5 Business Transfers
If LuniPay is involved in a merger, acquisition, bankruptcy, dissolution, reorganization, or similar transaction or proceeding, your information may be transferred as part of that transaction. We will provide notice of such change in ownership or control of your information where required by law.
5. Data Retention
We retain your information for as long as necessary to provide our Service and to comply with legal obligations:
- Account Information: Retained while your account is active. If you delete your account, we retain your information for up to 30 days to allow recovery, then securely delete it unless longer retention is required by law.
- Transaction & Invoice Data: Retained while your account is active and generally for up to 7 years after account closure for financial record-keeping, tax compliance, audit, fraud prevention, and dispute resolution, unless a longer period is required or permitted by law.
- Customer Data: Retained as long as the customer relationship exists and for compliance purposes, typically 6-7 years for tax and regulatory requirements.
- Dispute, Fraud, and Compliance Records: Retained for as long as needed to investigate complaints, respond to chargebacks, comply with Stripe or card-network requirements, enforce our Terms, or protect legal rights.
- Developer API and Webhook Logs: API request logs are generally retained for up to 30 days, and developer webhook event records are generally retained for up to 90 days, unless needed longer for security, fraud, or dispute investigation.
- Device, Push, and Wallet Tokens: Retained while the feature remains enabled, until you unregister the device, disable notifications, remove a pass, delete your account, or until the token is no longer valid.
- Analytics & Usage Data: Retained for up to 12 months for analytics and improvement purposes.
- Support Communications: Retained for 2 years from the date of your last communication for customer service records.
- Marketing Communications: Retained until you unsubscribe or request deletion.
Some information may be retained longer if retention is required by law (tax records, regulatory compliance, dispute resolution).
6. Data Security
We take data security seriously and use technical and organizational measures designed to protect your information:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS/SSL protocol.
- Encryption at Rest: Sensitive data is encrypted when stored in our databases.
- PCI-DSS Compliance: Payment card information is processed through Stripe, which is PCI-DSS Level 1 compliant. We do not store or transmit unencrypted card data.
- Access Controls: We restrict access to your personal information to employees and contractors who need access to perform their duties, and require them to maintain confidentiality.
- Secure Authentication: We use bcrypt hashing for password storage and OAuth tokens for secure third-party authentication.
- Security Reviews and Testing: We review and test our security controls as appropriate for the Service and the risks we identify.
- Monitoring & Logging: We monitor our systems for suspicious activity and maintain audit logs.
While we implement strong security measures, no system is completely secure. We cannot guarantee absolute security. If you become aware of a security breach, please contact us immediately at support@lunipay.io.
If we become aware of a security incident affecting personal information, we will assess the incident and provide notices to affected users, regulators, or other parties where required by applicable law.
7. Your Rights and Choices
7.1 General Rights
Subject to applicable law, you have the following rights:
- Access: You have the right to access your personal information by logging into your LuniPay account or contacting us.
- Correction: You can update, correct, or modify your account information through your account settings.
- Deletion: You have the right to request deletion of your account and associated personal data, subject to applicable legal requirements.
- Data Portability: You can request a copy of your data in a structured, machine-readable format.
- Marketing Opt-Out: You can opt out of receiving marketing emails by clicking the unsubscribe link in any email or by contacting us.
7.2 Jamaica Data Protection Rights
If Jamaica's Data Protection Act applies to your information, you may have rights to be informed about how your personal data is processed, access personal data held about you, request correction of inaccurate data, object to certain processing, prevent processing likely to cause damage or distress, and complain to Jamaica's Office of the Information Commissioner.
We will handle Jamaican data protection requests in line with applicable law and may need to verify your identity before responding.
7.3 EU and UK Data Protection Rights (GDPR)
If you are located in the European Union or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to Restrict Processing: You can request that we limit how we use your data.
- Right to Object: You can object to our processing of your personal data for legitimate interests.
- Right to Withdraw Consent: You can withdraw consent you've provided at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority.
Our legal basis for processing your data includes performance of a contract with you, compliance with legal obligations, and our legitimate interests (fraud prevention, security, service improvement).
7.4 California Privacy Rights (CPRA/CCPA)
If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to Know: You can request to know what personal information we collect and how we use it.
- Right to Delete: You can request deletion of personal information we hold about you (with certain exceptions).
- Right to Opt-Out: You can opt out of the "sale" or "sharing" of your personal information (as defined by CCPA).
- Right to Correct: You can request correction of inaccurate personal information.
- Right to Limit Use: You can limit our use of your sensitive personal information where applicable.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
LuniPay does not sell personal information for money and does not knowingly sell or share personal information of children under 16. We also do not use sensitive personal information for purposes that require a right to limit under California law unless we provide the required notice and choice.
To exercise these rights, contact us at support@lunipay.io.
7.5 How to Exercise Your Rights
To exercise any of your rights, please contact us at:
Email: support@lunipay.io
We will respond to your request within the timeframe required by applicable law. We may request verification of your identity to protect your privacy and security. Some information may not be deleted or restricted where we need it for payment records, accounting, fraud prevention, security, disputes, legal compliance, or enforcement of our Terms.
8. Cookies and Tracking Technologies
LuniPay uses cookies and similar tracking technologies to provide and improve our Service:
8.1 Types of Cookies We Use
- Essential Cookies: Required for authentication, session management, and basic functionality. These cannot be disabled.
- Analytics Cookies: Used to understand how users interact with our Service. These are used by Vercel Analytics and PostHog to track page views, product usage, user flows, and performance metrics.
- Performance Cookies: Used to monitor application performance and errors (Sentry).
8.2 Third-Party Tracking
LuniPay does not use third-party advertising networks or tracking pixels for retargeting or behavioral advertising. We do not allow advertisers to track you across websites. We do use product analytics tools, including PostHog, to understand and improve how the Service is used.
8.3 Managing Cookies
Most web browsers allow you to control cookies through browser settings. You can typically enable, disable, or delete cookies, or set your browser to notify you before a cookie is placed. However, disabling essential cookies may affect your ability to use LuniPay.
9. Children's Privacy
LuniPay is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected information from a child under 18, we will promptly delete such information and terminate the child's account. If you believe we have collected information from a child under 18, please contact us immediately at support@lunipay.io.
10. International Data Transfers
LuniPay is based in the United States and your information may be transferred to, stored in, and processed in the United States or other countries where we or our service providers operate. The United States and other countries may not have data protection laws equivalent to those in your country of origin.
When required by applicable law, we use appropriate safeguards such as contractual protections, Standard Contractual Clauses, and other transfer mechanisms to protect your information when it is transferred internationally.
If you are located in the EU, UK, or other jurisdictions with strict data protection requirements and have questions about international data transfers, contact us at support@lunipay.io.
11. Third-Party Links and Services
Our website and Service may contain links to third-party websites, applications, and services that are not operated by LuniPay, including Stripe, Google, Apple, Expo, SendGrid, and others. This Privacy Policy does not apply to third-party services, and we are not responsible for their privacy practices.
We encourage you to review the privacy policies of any third-party services before providing your information or using their services. Your use of third-party services is governed by their terms and privacy policies, not ours.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by updating the "Last updated" date at the top of this policy and, for significant changes, by sending you an email notice or displaying a prominent notice on our website.
Your continued use of LuniPay following the posting of a revised Privacy Policy means that you accept and agree to the changes. We encourage you to review this policy periodically to stay informed about how we protect your information.
13. Contact Information
If you have questions about this Privacy Policy, our privacy practices, or your personal information, please contact us:
Lunipay LLC, doing business as LuniPay
Privacy Contact: support@lunipay.io
General Contact: support@lunipay.io
Mailing Address:
1111B S Governors Ave, STE 23835
Dover, DE 19904
United States
We aim to resolve any privacy concerns within 30 days of receiving your inquiry. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority.
14. Data Processing for Customer Data
Important: When you enter customer information into LuniPay to manage your own customer relationship (names, email addresses, phone numbers, etc.), you are generally the "data controller" and LuniPay is generally a "data processor" for that customer relationship data.
- You are responsible for: Obtaining necessary consent from your customers, complying with applicable data protection laws, and providing data protection notices to your customers.
- LuniPay is responsible for: Processing customer data as needed to provide the Service, maintaining appropriate security measures, and assisting with your legal obligations where required and reasonably possible.
- Data Processing Agreement: For EU/UK customers subject to GDPR, we are prepared to enter into a Data Processing Agreement (DPA) to govern the processing of personal data. Please contact us at support@lunipay.io.
LuniPay may act as an independent controller for payment operations, fraud prevention, security, customer complaints, disputes, chargebacks, refunds, compliance, support, platform analytics, and legal protection. We do not use your customer list to market unrelated third-party products to your customers.
This Privacy Policy is effective as of May 4, 2026 and is subject to change. Please review it regularly for updates.