LumioBI
Privacy Policy
Last updated: August 6, 2026
This policy explains how the LumioBI brand ("LumioBI," "we," "us," or "our") handles information when business customers and their authorized users use our websites, portal service, support channels, and Lumio PBI browser extension. Questions and privacy requests may be sent to support@lumiobi.com.
Information we handle
Depending on how you use LumioBI, we may handle:
- Signup and contact information, such as name, business email, company, job title, phone number, and the portal or service requested.
- Authentication and account records, such as account identifiers, email-verification status, sign-in timestamps, roles, and security events.
- Portal configuration and access records, including portal names, approved users, administrator relationships, selected Power BI or Fabric workspace and report identifiers, navigation settings, branding, and display preferences.
- Billing and transaction records, such as Paddle customer, subscription, price, and transaction identifiers; subscription and payment status; billing contact details; invoice or purchase-order information; and tax or address details needed for billing. Paddle processes payment-card information. LumioBI receives billing identifiers and status but does not receive or store complete card numbers or security codes.
- Support submissions, including messages, attachments, screenshots, diagnostic details, and any other information a person chooses to provide when asking for help.
- Internal service activity, such as portal openings and report names or identifiers used for account operations and aggregate portal reporting. LumioBI does not collect report contents, filter selections, clicked report URLs, IP addresses, or device details as portal activity events.
- Website and technical information, such as authentication cookies, browser or extension storage, security logs, and standard hosting request information that may include an IP address, browser, device, referring page, and event timestamps.
Browser extension and Power BI data
The Lumio PBI extension reads the signed-in Power BI account email to check whether that account is approved for a LumioBI portal. It may store that email, the selected portal, display preferences, and cached portal configuration in browser or extension storage. It sends the email, portal choice, saved preferences, and limited activity events to LumioBI over HTTPS only to provide portal access, personalization, and portal reporting.
For workspace discovery, the extension uses the existing Power BI or Fabric bearer token already available in the browser. The token remains in local extension storage and is never sent to LumioBI, our database, or administrator pages. Workspace names and identifiers are returned only to an authorized administrator's local browser session; the administrator may choose to save selected workspace details as portal configuration.
How and why we use information
We use information to create and administer accounts; authenticate and authorize users; configure, operate, personalize, and improve the service; process subscriptions and maintain billing records; send transactional email; provide support; monitor reliability and internal product usage; prevent fraud and abuse; enforce agreements; and comply with legal obligations.
Where a law requires a stated legal basis, our bases may include performing a contract, taking steps requested before a contract, pursuing legitimate interests in operating and securing a business service, complying with law, and consent where required. A business customer may separately determine how it uses information about its administrators and approved users.
Service providers and other recipients
We disclose information only as reasonably needed to operate LumioBI, including to the following categories and providers:
- Supabase for database, authentication, and storage services.
- Vercel for application hosting and delivery.
- Resend for transactional email.
- Cloudflare Turnstile for bot and abuse prevention.
- Paddle as payment processor and merchant of record for applicable purchases.
- Microsoft Power BI and Fabric when an authorized user interacts with those services through LumioBI.
- Customer portal administrators who manage their organization's portal configuration, approved users, and service activity.
We may also disclose information when required by law, to protect LumioBI or others, during a business transaction, or with the relevant person's direction. We do not sell personal information or use it for cross-context behavioral or targeted advertising.
Cookies and local storage
LumioBI uses cookies and similar browser storage needed for authentication, security, signup continuity, preferences, and core service operation. The extension uses local extension storage for the limited purposes described above. Browser controls can clear this storage, and an extension user can remove local extension data by uninstalling the extension, although doing so may require signing in or configuring preferences again.
Retention
We keep information only for as long as reasonably needed for the purposes described in this policy. Retention depends on the type of record and may continue while an account or customer relationship is active, for a reasonable period for support and backup recovery, and as needed for security, disputes, tax, accounting, contracts, or other legal obligations. Customer administrators may remove approved-user access, but some audit, billing, or legal records may be retained.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls and encrypted network connections. No internet service or storage system can guarantee absolute security. Please contact us promptly if you believe an account or information has been compromised.
International processing
LumioBI and its providers may process information in countries other than the country where a user or customer is located. Those countries may have different data-protection laws. Where required, we use contractual or other recognized safeguards for international transfers.
Privacy choices and rights
Depending on location and applicable law, a person may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or an appeal, and may be able to complain to a local data-protection authority. These rights may be limited by law and by LumioBI's need to retain certain records.
For information controlled by a customer organization, contact that organization or its portal administrator first. LumioBI will assist customers where appropriate. Direct requests can be sent to support@lumiobi.com; we may need to verify the requester's identity and authority.
Children
LumioBI is a business service and is not directed to children. We do not knowingly collect personal information from children through the service. Contact us if you believe a child has provided information to LumioBI.
Policy changes
We may update this policy as LumioBI, our providers, or legal requirements change. We will post the revised policy here, update the effective date, and provide additional notice when appropriate. Material changes to extension data handling will be disclosed before the new handling begins.
See also our Terms of Service, Refund Policy, and Support page.
Document version: 2026-08-06
