Skip to main content
On this page

Under legal review

This document was prepared for Lumtry by its parent company, Agnotiq, Inc., and is under legal review before general availability.

Legal

Privacy Policy

Effective date
Effective August 12, 2026
Last updated
Last updated August 12, 2026

This Privacy Policy explains how Agnotiq, Inc. (Agnotiq, Inc., “we”, “us”) collects, uses, shares, and protects personal information in connection with Lumtry and our related websites and services (the Service). It works together with our Terms of Service.

We are based in Toronto, Ontario, Canada and serve business customers running e-commerce operations. Lumtryorchestrates refund decisions using deterministic policy, model-assisted reasoning, and human approval, and we designed the Service to keep each organization’s data isolated and to process personal information only as needed to run the Service.

Two roles: controller and processor.

For account, billing, website, and usage information, Agnotiq, Inc. acts as the controller (in Canada, the organization accountable for the data). For the refund-case data you connect through your store and payment processor, we act as a processor / service provider on your behalf, under our Terms of Service.

Overview and scope

This Policy applies to personal information we handle through our website, sign-up and sign-in flows, dashboards, communications, and support, and to the refund-case data processed through the Service. It does not apply to third-party websites or services we link to or integrate with, which have their own privacy practices (§14).

The information we collect

Information you provide.

  • Account and contact data: your business email address, name, organization and workspace details, and role.
  • Billing data: subscription tier, billing contact, and payment records. Card details are collected and stored by our payment processor, not by us.
  • Support and communications: messages, requests, and feedback you send us.
  • Store, order, and refund data: the data your connected store and payment processor send us to operate the Service: orders, order line items, refund requests, refund decisions, and the policy and approval history attached to each case. Refund execution involves payment metadata only; we never receive or store raw card numbers, consistent with PCI scope minimization.
  • Policy and configuration data: the deterministic refund policy, approval routing rules, and workspace configuration you set up.

Information collected automatically.

When you use the Service we collect device and connection data (such as IP address, browser type, and approximate region), authentication and security event logs, and usage data (such as pages viewed, features used, and case activity), including through cookies and similar technologies (§5).

Information from third parties.

We receive information from the services you connect to run the Service: order and refund data from your store platform, refund execution status and payment metadata from your payment processor, and, if you connect Slack, the workspace and channel information needed to deliver approval requests.

When you connect Slack, we store the access credential (an OAuth token Slack issues to us) so we can post approval requests to your chosen channel. We keep this credential encrypted at rest, use it only to deliver your approvals, and delete it when you disconnect Slack.

How we use information

We use personal information to:

  • provide, operate, maintain, and secure the Service, including evaluating refund cases against your policy, generating model-assisted reasoning for cases your policy routes for review, and recording the resulting decisions and audit trail;
  • authenticate you, manage workspaces and access, and prevent abuse, fraud, and security incidents;
  • process payments, manage subscriptions, and provide support;
  • communicate with you about the Service, including transactional messages and, where permitted, product updates you can opt out of;
  • analyze and improve the Service using aggregated or de-identified data; and
  • comply with legal obligations and enforce our Terms.

Cookies and similar technologies

We use strictly necessary cookies and similar technologies to keep you signed in, remember preferences (such as your light/dark theme), and secure the Service. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent sign-in or break core functionality.

AI and policy-assisted processing of your data

The Service is policy-first: deterministic policy settles refund cases wherever your rules cover them the same way every time. For cases your policy routes as ambiguous or out-of-policy, the Service uses model-assisted reasoning, through an internal AI Model Router, to evaluate the case against your policy and propose a recommendation with a recorded rationale for your team’s review and approval.

  • Model providers. Depending on your workspace configuration, reasoning is performed using models from Anthropic, OpenAI, or Mistral, routed by the AI Model Router. See §7 for the current sub-processor list.
  • Not used for training. Agnotiq, Inc. does not train models on your refund-case data, and we contract with our model providers on terms that do not use your inputs or outputs to train their models.
  • Recorded rationale, human approval. Every AI-assisted recommendation is logged with its rationale to the append-only audit trail. Recommendations are advisory: cases your policy does not fully automate require human approval before a refund is executed (see Terms §4).

How we share information and our sub-processors

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information only as described here: to the sub-processors that help us run the Service, to professional advisors, in connection with legal requirements or a corporate transaction, or with your direction.

VendorPurposeData categoriesLocation
SupabaseManaged Postgres database, authentication, and realtime; hosts account data and refund-case data, isolated per organization using row-level security.Account data, Refund-case data, Authentication eventsUnited States
AnthropicAI model inference for policy-assisted refund reasoning, routed through the AI Model Router.Agent inputs (case context), AI-generated outputUnited States
OpenAIAI model inference for policy-assisted refund reasoning, routed through the AI Model Router; used per workspace configuration.Agent inputs (case context), AI-generated outputUnited States
MistralAI model inference for policy-assisted refund reasoning, routed through the AI Model Router; used per workspace configuration.Agent inputs (case context), AI-generated outputEuropean Union
StripeRefund execution and payment metadata for orders paid through Stripe. We never receive or store raw card numbers; Stripe holds processor tokens on our behalf.Refund execution records, Payment metadata (no card numbers)United States
PayPalRefund execution for orders paid through PayPal.Refund execution records, Payment metadataUnited States
SlackDelivery of approval requests to a workspace's connected Slack workspace, for organizations that connect Slack via OAuth.Workspace/channel identifiers, Approval-request content, OAuth credentialUnited States
ShopifyOrder, refund, and store data ingested via the Shopify API and signed webhooks, for organizations that connect a Shopify store.Order data, Customer refund data, Store configurationUnited States
ResendWhen enabledDelivery of transactional email for the contact form, on deployments where that surface is enabled.Email address, Message contentUnited States

We require our sub-processors to protect personal information and to use it only to provide their services to us.

Legal and corporate disclosures.

We may disclose information when we reasonably believe it is required by law or legal process, to protect rights, safety, and the security of the Service, or in connection with a merger, acquisition, financing, or sale of assets (subject to this Policy).

Data retention

We retain personal information for as long as reasonably necessary to provide the Service, to comply with our legal obligations, resolve disputes, and enforce our agreements. Retention periods are documented per data category and context (for example, account data for the life of your workspace, and billing records for the period required by tax and accounting law). When information is no longer needed, we delete or de-identify it.

Audit trail.

Refund decisions, approvals, and system actions are written to an append-only audit trail as part of the Service’s design. Audit records are retained for as long as needed to support compliance, dispute resolution, and the integrity of your workspace’s history, and are not deletable by end-user request while your workspace is active.

Workspace deletion.

Your workspace settings include a deletion flow for closing an organization’s workspace. Refund-case data is handled per your Terms when you delete a workspace; export anything you need before you do.

How we protect information

We use technical and organizational measures designed to protect personal information, including:

  • Tenant isolation: every tenant-owned table is protected by row-level security keyed on your organization, with backend authorization re-checked on every request rather than relying on the database alone;
  • Encryption: data encrypted in transit (TLS) and at rest by our infrastructure providers;
  • Signed webhooks: webhook signatures from your store, payment processor, and Slack are verified before any business processing occurs; invalid signatures are rejected; and
  • Least privilege and redacted logging:restricted access to systems, and default-level logs that redact secrets, full email local-parts, and card-like substrings.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

International data transfers

We and our sub-processors store and process information in Canada, the United States, and other countries where our infrastructure operates. As a result, your information may be transferred to, and processed in, a country other than your own and may be subject to the laws of those countries, including lawful access by courts, law enforcement, and government authorities. Where required, we use appropriate safeguards for international transfers.

Your privacy rights and choices

Subject to applicable law, you may have the right to access, correct, update, or delete your personal information, to obtain a copy of it, to withdraw consent, and to opt out of marketing communications. You will not be discriminated against for exercising these rights.

To exercise a right, email privacy@agnotiq.com. We will respond within five (5) business days (or as required by law) and may need to verify your identity. If we process refund-case data on behalf of a customer organization, we will refer individual requests to that organization (the controller).

Regional disclosures (Canada / U.S.)

Canada (PIPEDA).

We are accountable for personal information under our control and have designated a contact for privacy matters (reachable at privacy@agnotiq.com). You may request access to, and correction of, your personal information, and may challenge our compliance. As noted in §10, your information may be processed outside Canada and subject to foreign lawful access.

United States (California, CCPA/CPRA, and similar laws).

In the prior 12 months we have collected the following categories of personal information: identifiers (such as email and IP address); commercial information (such as subscription and billing records); internet/network activity (such as usage and log data); geolocation inferred from IP address; and, if you connect Slack, the integration credential described in §2. We collect these for the business purposes described in §3, from the sources described in §2, and disclose them to the sub-processors and recipients described in §7.

We do not sell personal information and do not share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes that require an opt-out. California residents may exercise rights to know, delete, correct, and to non-discrimination as described in §11. Residents of other U.S. states with comprehensive privacy laws have analogous rights, which we honor where applicable.

Children’s privacy

The Service is a business tool intended for adults and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact privacy@agnotiq.com and we will take appropriate steps to delete it.

Changes to this Policy

We may update this Policy from time to time. If we make a material change, we will provide notice by a reasonable means (for example, in-product notice, email, or posting an updated version with a new effective date). The “Last updated” date above reflects the most recent revision; continued use of the Service after a change takes effect means you accept the updated Policy.

How to contact us

For privacy questions, requests, or security disclosures, contact Agnotiq, Inc. at privacy@agnotiq.com, or write to us at Toronto, Ontario, Canada. We aim to respond within five (5) business days. For contract questions, see our Terms of Service or email legal@agnotiq.com.