PRIVACY POLICY
How Botanica 1 Pty Ltd trading as Lumé collects, uses, discloses and protects personal information, including through the Lumé mobile applications.
Botanica 1 Pty Ltd (ABN: 45 647 833 583) trading as Lumé
Version 1.3 · Effective 15 August 2026
1. About this Policy
1.1 Who this Policy applies to
Botanica 1 Pty Ltd (ABN: 45 647 833 583) trading as Lumé (Lumé, we, us, our) is the entity responsible for the personal information described in this Policy. Lumé™ is a brand, trading name and trade mark of Botanica 1 Pty Ltd. An application to register the Lumé trade mark has been filed with IP Australia and remains pending as at the effective date of this Policy. Botanica 1 Pty Ltd is the developer of record for the Lumé mobile applications on the Apple App Store and Google Play.
This Policy applies to the Lumé website, the Lumé mobile applications for iOS and Android, the Service Provider dashboard, and all related services (together, the Platform).
1.2 The law we comply with
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the Spam Act 2003 (Cth) in relation to electronic marketing, the Notifiable Data Breaches scheme, and applicable State and Territory health records legislation.
1.3 What this Policy does not cover
Service Providers listed on the Platform are independent businesses. Once information is disclosed to a Service Provider in order to deliver a booked service, that Service Provider handles it under its own privacy practices and is separately responsible for compliance with privacy law. This Policy also does not apply to third-party websites or applications that we link to.
2. The personal information we collect
We collect the following categories of personal information.
2.1 Identity and contact information
Name, username, profile photograph, date of birth or age range, email address, telephone number, and residential or business address.
2.2 Account and booking information
Account credentials in hashed form, booking history, appointment times, services selected, notes you add to a booking, communications with Service Providers through the Platform, saved preferences and favourites.
2.3 Sensitive information, including health information
Where you choose to provide it, and only with your express consent, we collect sensitive information as defined in the Privacy Act, including allergies, skin sensitivities, medical conditions, medications, pregnancy status, prior treatments and adverse reactions, and photographs taken for clinical, consultation or before-and-after purposes.
We collect this information only where it is reasonably necessary to enable a Service Provider to supply a booked service safely. We do not use health information for advertising, marketing, profiling or automated decision-making, and we do not sell it.
2.4 Payment information
Billing name and address, payment method tokens, transaction records, deposits, refunds and chargebacks. Complete card numbers are collected and processed by our PCI-DSS compliant payment providers and are not stored on Lumé systems.
2.5 Service Provider information
For business users: business name, ABN, trading address, staff names and rosters, licences, qualifications, insurance details, service menus, pricing, banking details for settlement, and identity verification information required for anti-fraud or payment onboarding.
2.6 Technical and device information
IP address, device model and operating system, unique device and application identifiers, mobile advertising identifier (only where you consent), crash reports, diagnostic logs, app version, language and time zone, and information about how you interact with the Platform.
2.7 Location information
Approximate location derived from your IP address, and, only if you grant the permission, precise device location while the application is in use, in order to show nearby Service Providers and provide directions. You may withdraw this permission at any time in your device settings, and the applications remain usable without it.
2.8 User Content
Reviews, ratings, comments, photographs, and messages you send through the Platform.
3. How we collect personal information
We collect personal information:
- directly from you, when you register, complete a profile, make or change a booking, complete a consultation form, upload an image, send a message, contact support, or respond to a survey;
- automatically, through your use of the Platform, including through cookies and similar technologies described in the Cookie and Tracking Technologies Policy, and through software development kits embedded in the applications for analytics, crash reporting and security;
- from a Service Provider, where they create or amend a booking on your behalf, or record the outcome of an appointment; and
- from third parties, including payment providers, fraud prevention and identity verification providers, and mapping providers.
Where it is reasonable and practicable, we collect personal information directly from you. Where we receive information about you from another person, we take reasonable steps to ensure you are made aware of this Policy.
4. Why we collect, hold, use and disclose personal information
We use personal information for the following purposes:
- to create and administer your account and verify your identity;
- to facilitate, confirm, remind you of, change and record bookings;
- to pass to a Service Provider the information they need to supply a booked service safely, including relevant health disclosures you have consented to share;
- to process payments, deposits, refunds and settlements, and to manage chargebacks;
- to enable communication between Clients and Service Providers;
- to provide customer support and to handle complaints and disputes;
- to moderate User Content and enforce our Acceptable Use Policy and Community Guidelines;
- to detect, investigate and prevent fraud, misuse, security incidents and unlawful activity;
- to analyse and improve the Platform, including through aggregated and de-identified analytics;
- to send you service and transactional messages;
- with your consent, to send you marketing communications and personalised recommendations; and
- to comply with our legal obligations and to establish, exercise or defend legal claims.
We will not use or disclose your personal information for a purpose other than one set out above, or a purpose you would reasonably expect that is related to it (or, for sensitive information, directly related to it), unless you consent or the law permits or requires it.
5. Consent, and how to withdraw it
Where we rely on your consent — including for sensitive and health information, precise location, tracking across other companies' apps and websites, and marketing communications — that consent is sought separately, in plain language, at the point the information is first needed. You may withdraw consent at any time through your account settings, your device settings, an unsubscribe link, or by contacting our Privacy Officer. Withdrawing consent does not affect the lawfulness of prior handling and may mean some features are no longer available to you.
Access to the Platform, and to any paid or promotional benefit, is never conditional on you granting an optional permission or consenting to tracking.
6. Who we disclose personal information to
6.1 Service Providers
When you make a booking, we disclose to the relevant Service Provider the information they need to deliver the service, which may include your name, contact details, appointment details, booking notes and any consultation or health responses you have provided for that purpose. Service Providers must use that information only to deliver the service and manage the client relationship, must protect it, and must not sell it. Those obligations are imposed by the Service Provider Partner Agreement and the Data Processing Agreement.
6.2 Our service providers
We disclose personal information to organisations that perform functions on our behalf, including cloud hosting and storage, payment processing, identity verification and fraud prevention, email and SMS delivery, push notification delivery, customer support tooling, analytics and crash reporting, mapping, and content moderation tooling. These organisations are bound by contract to use the information only for the purposes for which we disclose it, to protect it to a standard at least equivalent to this Policy, and to return or delete it when no longer required. A current list is maintained in our Subprocessor List.
6.3 Other disclosures
We may disclose personal information: where you consent or direct us to; to your parent or guardian where you are under 16; to a professional adviser, insurer or auditor under a duty of confidence; to a purchaser or prospective purchaser of our business, subject to confidentiality; to a law enforcement agency, court, tribunal or regulator where required or authorised by law, or where reasonably necessary to prevent a serious threat to life, health or safety; and to establish, exercise or defend a legal claim.
We do not sell personal information, and we do not disclose personal information to third parties for their own direct marketing purposes.
7. Overseas disclosure
Some of our service providers store or process information outside Australia, including in the United States, the European Union and Singapore. Before disclosing personal information overseas, we take reasonable steps under APP 8 to ensure the recipient does not breach the APPs, including by imposing contractual obligations equivalent to this Policy. A current list of the countries in which our service providers store data is maintained in the Subprocessor List. Where you consent to a disclosure to an overseas recipient that is not subject to a law substantially similar to the APPs, that recipient may not be accountable under the Privacy Act and you may not be able to seek redress under it.
8. The mobile applications specifically
8.1 Permissions
The applications request access to certain device features. Each request is made at the point of first use, is explained in plain language, and can be declined or later withdrawn in your device settings:
- Camera and photo library — to upload a profile image, consultation photographs or before-and-after images you choose to share;
- Location (while in use) — to show nearby Service Providers and provide directions;
- Push notifications — for booking confirmations, reminders and changes, and, with separate consent, marketing;
- Calendar — to add a confirmed appointment to your device calendar at your election; and
- Contacts — only where you expressly choose to invite a specific person. We never use contacts to build a database, never send bulk invitations, and never default to selecting all contacts.
8.2 Tracking and advertising identifiers
On iOS, we do not track your activity across apps and websites owned by other companies, and do not access the device advertising identifier, unless you grant permission through Apple's App Tracking Transparency prompt. On Android, we handle the advertising identifier in accordance with Google Play's policies and do not link it to persistent device identifiers or to sensitive or health information. Declining tracking does not reduce the functionality available to you.
8.3 Store disclosures
The information declared in Apple's App Privacy details and in Google Play's Data safety section is maintained so as to be consistent with this Policy, and is reviewed whenever our data practices change.
8.4 Prominent in-app disclosure
Where we wish to collect personal information in a way that would not be reasonably apparent from your use of the applications, we present a prominent in-app disclosure and obtain your affirmative consent before that collection begins. We do not rely on this Policy alone as the means of disclosure.
9. Cookies and similar technologies
Our use of cookies, software development kits, pixels and similar technologies is described in the Cookie and Tracking Technologies Policy, which forms part of this Policy.
10. Direct marketing
We send marketing communications only with your express or inferred consent. Every marketing message identifies Lumé as the sender, includes our contact details, and contains a functional and conspicuous unsubscribe facility. We action unsubscribe requests within 5 business days and, in any event, within the time required by the Spam Act 2003 (Cth). We do not use sensitive or health information for marketing. You may also ask us at any time to tell you the source of information we used to contact you.
11. Data quality
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete and relevant. You can review and correct most of your information directly in your account.
12. Automated tools and automated decision-making
Lumé may use automated tools to assist with security, fraud detection, search ranking, recommendations, content moderation and platform operations. Where we use personal information in a substantially automated decision that could significantly affect an individual's rights or interests, we will provide the information, review rights and processes required by Australian privacy law, and you may ask us for an explanation of the decision or for it to be reviewed by a person. We do not use health or other sensitive information for profiling, ranking or automated decision-making.
13. Security
We hold personal information in secure cloud infrastructure located in [Insert Data Location, e.g. Australia] and protect it using measures including encryption in transit using TLS, encryption at rest, role-based access controls, multi-factor authentication for administrative access, logging and monitoring, secure software development practices, vendor due diligence, and staff confidentiality obligations and training. Photographs and health information are subject to additional access restrictions.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact us immediately at hello@lumebook.com.
14. Data breaches
We maintain a Data Breach Response Plan. If we suspect a data breach we will contain and assess it promptly. Where a breach is likely to result in serious harm to an individual and we cannot prevent that harm through remedial action, we will notify the affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and, where relevant, the affected Service Providers.
15. Retention and deletion
We retain personal information only for as long as it is needed for the purposes described in this Policy, or for as long as we are required to retain it by law. Indicative periods are:
- Account and profile information — for the life of the account, then deleted or de-identified within 30 days of a deletion request, subject to the exceptions below.
- Booking and transaction records — a minimum of 5 years, as required by Australian taxation law.
- Health and consultation information — retained while the account is active and for the period required by applicable State or Territory health records law, then securely destroyed.
- Records needed for a legal claim, regulatory request, fraud or security investigation — for as long as reasonably necessary for that purpose.
- Reviews and ratings — may be retained in de-identified form after account deletion so that a Service Provider's aggregate rating remains accurate.
Detail on how to delete your account and what is retained is set out in the Account Deletion and Data Rights Policy.
16. Your rights
16.1 Access
You may request access to the personal information we hold about you. We will respond within 30 days. We may refuse access in the limited circumstances permitted by APP 12, in which case we will give you written reasons and tell you how to complain. We do not charge for making a request; we may charge a reasonable, non-excessive fee for providing access, and will tell you before we do.
16.2 Correction
You may ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. If we refuse, we will give you written reasons and you may ask us to attach a statement of your view to the record.
16.3 Deletion
You may delete your account from within the applications, or by using the account deletion page at https://lume-book.com/delete-account, or by contacting our Privacy Officer. See the Account Deletion and Data Rights Policy.
16.4 Anonymity and pseudonymity
You may deal with us anonymously or by pseudonym where it is lawful and practicable, for example when making a general enquiry. This is not practicable where you are making a booking.
16.5 How to make a request
Send requests to hello@lumebook.com, marked to the attention of the Privacy Officer. We may need to verify your identity before acting on a request.
17. Complaints
If you believe we have breached the APPs or mishandled your personal information, please contact our Privacy Officer at hello@lumebook.com. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner: www.oaic.gov.au · 1300 363 992 · GPO Box 5218, Sydney NSW 2001.
18. Children
The Platform is not directed to children. We do not knowingly collect personal information from a person under 16 without the consent of a parent or guardian. If you believe we hold such information, contact us and we will delete it.
19. Changes to this Policy
We may update this Policy. The current version is always available at https://lume-book.com/privacy and within the applications. Where a change is material we will notify you by email or by in-app notice before it takes effect. The version number and effective date at the top of this Policy indicate the current version.
20. Contact us
Privacy Officer, Botanica 1 Pty Ltd trading as Lumé
Email: hello@lumebook.com
Lumé™ is a brand and trade mark of Botanica 1 Pty Ltd (ABN 45 647 833 583). An application to register the Lumé trade mark has been filed with IP Australia and, as at the effective date of this document, remains pending. Nothing in this document represents that registration has already been granted.