Legal
Privacy Policy
Last updated: 9 June 2026
This policy explains what data Lumeops collects, how we use it, and the rights you have over it. It includes specific disclosures about data we access through Google APIs when you connect your Google account to your client portal.
Lumeops ("we", "us", "our") provides local SEO, Google Business Profile optimisation, web design and related digital services to businesses in the United Kingdom. We operate the website at lumeops.com and the client portal and admin tools hosted on it. We are the data controller for the personal data described in this policy.
We are based in Blackburn, Lancashire and registered in England & Wales. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Information we collect
Information you give us
When you request an audit, contact us, or become a client, we collect details such as your name, business name, email address, phone number, website URL and the city or area you serve. If you become a client, we also store notes, documents, photos and credentials you choose to share with us so we can deliver the service.
Information collected automatically
When you visit lumeops.com we collect standard analytics data (pages viewed, approximate location, device and browser type, referring source) via Google Analytics 4, which runs through Cloudflare Zaraz. This is used in aggregate to understand and improve the site. We do not use this data to build advertising profiles of individuals.
Information from connected Google accounts
If you are a client and choose to connect your Google account in your portal, we access certain Google data on your behalf. This is described in detail in section 4.
2. How we use your information
- To respond to enquiries and deliver the services you ask us to provide.
- To produce SEO audits, rankings reports, reviews summaries and performance dashboards inside your client portal.
- To manage and optimise your Google Business Profile when you have authorised us to do so.
- To send service-related communications (e.g. reports, invoices, account notices).
- To operate, secure and improve our website and tools.
- To meet our legal, accounting and regulatory obligations.
3. Legal bases for processing
We rely on: contract (to deliver services you have engaged us for); legitimate interests (to run and improve our business and secure our systems, balanced against your rights); consent (for connecting your Google account and for non-essential analytics, which you can withdraw at any time); and legal obligation (for tax and accounting records).
4. Google user data
When you connect your Google account in the Lumeops client portal, you grant us access to specific data through Google APIs. We only request the minimum scopes needed to provide the features you have chosen. The scopes we may request, and why, are:
- Your email address (
userinfo.email) - to identify which Google account you connected and link it to your portal account. - Google Search Console, read-only (
webmasters.readonly) - to display your search impressions, clicks and ranking queries inside your portal. - Google Analytics, read-only (
analytics.readonly) - to display your website traffic and conversion metrics inside your portal. - Google Business Profile management (
business.manage) - to read your profile insights and reviews, and to make optimisation changes (such as categories, descriptions, posts and photos) on your behalf as part of the service you have engaged us for.
How we store and protect Google data
Google OAuth tokens are encrypted at rest using AES-256-GCM and stored on our own secured infrastructure. We use this access solely to power the features above inside your portal and to perform the optimisation work you have requested. You can disconnect your Google account at any time from the Integrations section of your portal, or by visiting your Google Account permissions page. When you disconnect, we revoke the tokens and stop accessing your Google data.
Limited Use disclosure
Lumeops' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for advertising, we do not sell it, we do not transfer it to third parties except as needed to provide or improve the features you requested, to comply with law, or as part of a merger or acquisition, and we do not allow humans to read this data unless we have your consent for specific support, we are required to by law, or it is necessary for security or to comply with our terms.
5. Sharing your information
We do not sell your personal data. We share it only with trusted service providers who help us operate (for example email delivery, hosting, analytics, payment and communications providers such as Cloudflare, Twilio, Calendly and Google), strictly to provide our service, and with professional advisers or authorities where legally required. All providers are bound to protect your data.
6. Data retention
We keep personal data only as long as needed for the purposes above. Client records are kept for the duration of our engagement and for a reasonable period afterwards to meet legal and accounting obligations. Photos uploaded to the client portal are retained for up to 12 months unless you ask us to remove them sooner. Connected Google account access is retained until you disconnect it or the engagement ends.
7. Your rights
Under UK GDPR you have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent at any time. To exercise any of these, email [email protected]. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
We use encryption in transit (HTTPS) and at rest for sensitive credentials and OAuth tokens, access controls, and regular review of our systems. No method of transmission or storage is completely secure, but we take reasonable steps to protect your data.
9. Cookies
We use essential cookies to operate the site and portal (for example to keep you logged in), and analytics cookies via Google Analytics 4 to understand site usage. You can control cookies through your browser settings. Disabling essential cookies may stop parts of the portal from working.
10. Children
Our services are intended for businesses and are not directed at anyone under 16. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notifying clients directly.
12. Contact us
For any privacy question or request, contact:
Lumeops
Email: [email protected]
Blackburn, Lancashire, United Kingdom