Privacy Policy

Effective date: July 20, 2026

Last updated: July 20, 2026

Version: consumer-privacy-v1.0

This Customer Privacy Policy explains how Charmonix, doing business as LuminPay, handles personal information about website visitors, prospective customers and customers. It does not cover employees, applicants, contractors, field representatives, ambassadors or clinic personnel in those roles.

1. Privacy at a glance

Topic

LuminPay's consumer commitment

Payment cards

Card checkout is hosted by Stripe; LuminPay is not intended to receive or store full card numbers or security codes

Clinical information

LuminPay is a marketplace, not a clinic; we minimize treatment-related information and direct clinical information to the chosen clinic

Marketing

Email and SMS marketing are optional, separate choices; unsubscribing does not cancel service

Cookies

Necessary technologies run the site; optional attribution and analytics remain off until you choose them

Advertising

No sale or rental of personal information; no third-party behavioural advertising pixels or session replay at launch

Representatives

Ambassadors and field representatives do not receive customer identity, contact, treatment, payment or cancellation details

Location

Service providers may process information in Canada, the United States and other disclosed jurisdictions

Your choices

You may ask for access or correction, withdraw consent, change cookies, unsubscribe or complain

 

2. Who is responsible

LuminPay is responsible for the personal information under its control and designates a Privacy Officer.

Privacy Officer

Charmonix, doing business as LuminPay

Business and mailing address: 2482 Yonge St, Toronto, Ontario, M4P 2H5, Canada

hello@charmonix.ca

647-947-7921

Contact the Privacy Officer to ask about this policy, access to personal information, use of service providers outside Canada or a privacy concern.

3. Laws and scope

Alberta's Personal Information Protection Act ("PIPA") generally applies to LuminPay's commercial handling of personal information in Alberta. The federal Personal Information Protection and Electronic Documents Act ("PIPEDA") may apply to interprovincial or international commercial activity and in other circumstances. Other mandatory privacy, health-information, consumer or communications laws may also apply.

Clinics and regulated health professionals are separately responsible for patient and clinical information in their custody or control, including obligations under Alberta's Health Information Act where applicable. If LuminPay ever acts as an information manager for a clinic, the parties must first implement the agreement, safeguards and approved process required by law. This policy does not replace a clinic s privacy notice.

4. Information we collect

We collect only information reasonably required for identified purposes. Whether information is required or optional will be explained at the point of collection.

4.1 Information you provide

Account and eligibility: name, email, mobile number, postal code, age or confirmation that you are at least 18, authentication data and account preferences.

Transactions and membership: selected pass, acceptance record, receipts, payment status, renewal and cancellation status, credits, refunds, disputes and provider transaction identifiers. Stripe, not LuminPay, receives full card details.

Booking and scheduling: chosen clinic or service category, booking request, availability, consent to share, booking status and minimal scheduling communication. Please do not provide clinical narratives through LuminPay.

Support: messages, attachments you choose to send, complaint information and resolution history. We may remove unnecessary sensitive content.

Consent and preferences: contract version, cookie choices, marketing choices, unsubscribe and withdrawal records.

Optional referrals: a referral or short code you enter and the related opaque campaign identifier.

4.2 Information collected automatically

Necessary technical data: request time, page or route, browser and device type, session and security events, authentication status, cookie or local-storage values described in the Cookie Policy, and limited IP or network information needed for delivery, abuse prevention and security.

Privacy-minimized risk data: rate-limit buckets, an HMAC-derived risk token and fraud or duplicate-trial signals. We do not place raw card fingerprints in analytics or customer-facing systems.

Attribution data, if you allow it: signed QR or referral source, campaign, venue or representative identifier, first qualifying interaction and time. The identifier is opaque to the browser and does not contain the representative's or customer's identity.

First-party analytics, if you allow it: approved page, performance and conversion events. Analytics must not contain name, email, phone, postal code, raw IP, provider IDs, free text, treatment interest, full URLs or query strings.

4.3 Information from others

We may receive payment status from Stripe; financing status from Affirm if you choose it; booking or redemption status from a participating clinic; masked-call status from Twilio; authentication or hosting signals from our technology providers; and a referral source from a signed LuminPay code. We do not treat a checkout return page as proof of payment.

5. Why we use personal information

We use personal information to:

create and secure an account, verify age and service area, and authenticate you;

display, form and evidence the online contract;

process payment status, issue and reconcile credits, administer renewal and cancellation, detect duplicate trials and resolve refunds or disputes;

accept, route and track a booking request and, with permission, create a temporary masked scheduling connection;

provide receipts, security alerts, payment and booking notices, customer support and accessibility;

prevent fraud, abuse, unauthorized access and ledger manipulation;

meet tax, accounting, consumer-protection, privacy, anti-spam, legal and regulatory obligations;

measure campaign attribution or site performance only when the applicable optional choice is enabled; and

send marketing only with consent or another lawful basis.

We will not use personal information for a new purpose that a reasonable person would not expect without explaining the purpose and obtaining any required consent.

6. Consent and choices

We seek meaningful consent by explaining what information is collected, which parties receive it, the purposes and meaningful risks or consequences. We do not bundle optional marketing, optional cookies or clinic sharing into the required purchase acknowledgement.

Some information is necessary to provide the requested contract or meet law. If you do not provide it, we may be unable to create an account, process a payment, issue credits or send a booking request. Other information is optional. Refusing or withdrawing an optional choice will not prevent purchase unless that information is genuinely required for the selected feature.

You may withdraw consent, subject to reasonable notice and legal or contractual limits, by using the relevant settings or contacting the Privacy Officer. Withdrawal does not operate retroactively and may prevent a feature that requires the information. We will explain material consequences.

7. Who receives information

We do not sell or rent personal information. We do not disclose customer information to third parties for their own behavioural advertising.

We may disclose limited information to:

Payment and financing providers: Stripe for hosted payments and, only if you choose it, Affirm for financing. These providers also handle information under their own privacy notices.

Infrastructure and security providers: hosting, database, authentication, content delivery, monitoring, fraud prevention and support providers acting for LuminPay.

Communications providers: email/SMS delivery and Twilio for the optional 72-hour masked scheduling connection. No audio recording or transcription is authorized.

Participating clinics: only the information needed for the booking or service process, after the relevant notice and authorization. Clinics use patient information under their own legal duties and notices.

Professional advisers and authorities: auditors, accountants, insurers, legal advisers, regulators, courts or law enforcement where reasonably necessary or legally required.

A successor organization: in a genuine financing, reorganization or sale, under confidentiality and privacy safeguards and subject to applicable consent or notice requirements.

Field representatives and ambassadors receive only pseudonymous or aggregated performance information. They do not receive your name, contact details, treatment interest, clinic choice, payment status, cancellation reason or support content.

8. Service providers and processing outside Canada

LuminPay uses service providers to operate the Platform. Our current provider page at https://luminpay.charmonix.ca identifies material providers, their purpose, the categories of information they process, relevant processing locations and links to their notices.

Current deployment-confirmed providers: Stripe, Clerk, Microsoft Clarity, Cloudflare.

Some providers may store or process information in Canada, the United States or other jurisdictions identified in LuminPay s current provider list at https://luminpay.charmonix.ca Information processed outside Canada is subject to the laws of that jurisdiction and may be accessible to courts, law enforcement or national-security authorities under those laws.

LuminPay remains accountable for information transferred to a service provider for processing. We use contractual, access, security and retention controls appropriate to the sensitivity and purpose. Contact the Privacy Officer for information about our policies and practices concerning service providers outside Canada.

9. Clinic and health-information boundary

A service category, clinic choice or booking request may reveal sensitive information about your interests. We minimize that information, do not place it in advertising or general analytics, and share it only for the service you request or as otherwise authorized by law.

The clinic independently collects the health information required for assessment and care. Its privacy notice explains its authority, purposes, records, access process and complaints. LuminPay does not use clinic health records for marketing, representative attribution or automated advertising.

If a clinic mistakenly sends unnecessary clinical information to LuminPay, we will restrict access, notify the appropriate privacy owner, and securely return, transfer or delete it as law and the applicable agreement require.

10. Marketing communications

Email and SMS marketing use separate, optional controls. A consent record may include the address or number, consent language and version, date, time, source and withdrawal. Commercial messages identify the sender, provide required contact information and include a working unsubscribe method.

We process unsubscribe requests promptly and no later than the legal deadline. We retain a minimal suppression record so we can honour the request. Unsubscribing does not stop transaction, account, security, renewal, cancellation, receipt, booking or support messages that are necessary to provide the service.

11. Cookies and similar technologies

The Cookie Policy identifies each technology, purpose, provider and duration. Necessary technologies support authentication, security, checkout, fraud prevention and privacy choices. Optional campaign attribution and first-party analytics remain off until you choose them. You can reject optional technologies without losing access to purchase or account functions.

LuminPay does not use third-party advertising pixels or session-replay tools on checkout, account, booking or health-related pages at launch. We treat Global Privacy Control as a signal to reject optional tracking where technically received and applicable.

12. Automated processing and human review

We may use rules to prevent duplicate introductory offers, rate-limit abuse, authenticate payments, identify suspicious ledger activity and protect accounts. Those rules may pause a transaction or request additional verification. They do not make clinical decisions. You may contact support to request human review of a materially adverse automated result.

Affirm independently decides financing eligibility under its own processes. LuminPay does not receive a right to override that decision.

13. Retention

We keep personal information only as long as reasonably needed for the identified purpose, legal requirements, a dispute or a documented legal hold. Different fields in the same record may have different retention periods.

Record class

Launch retention

Main safeguard

Financial, credit-ledger, payment, refund, dispute and reconciliation records

Six years from the end of the last tax year to which the record relates; longer only for an unresolved audit, claim or legal hold

Preserve financial integrity while tokenizing or deleting unrelated identity fields

Raw Stripe/Affirm event payload

180 days after terminal processing

Encrypted; then reduce to minimal event, amount, status, ID and integrity evidence

Trial payment-fingerprint HMAC

Life of the introductory program plus 24 months

Keyed HMAC only; no card number or raw fingerprint

Member and clinic private phone numbers

While the verified contact relationship is active, then 30 days after closure unless a support case or hold applies

Encrypted; delete derived search tokens and retain only deletion proof

Twilio participant IDs

30 days after masked session close

Minimize provider callback data

Minimal masked-call status/time/duration

90 days

No audio, transcript, voiceprint or treatment narrative

Masking consent and withdrawal proof

24 months after the final session or complaint resolution, whichever is later

Notice version, time, purpose, clinic and closure only

Application and security logs

30 days searchable plus 335 days restricted archive

Redact secrets, contact data, treatment interest and raw provider payloads

Cookie preference record

Current preference plus prior evidence needed to demonstrate consent or withdrawal, normally up to 24 months

No advertising profile

Marketing consent and suppression

Consent while relied on; suppression as long as reasonably needed to honour opt-out and prove compliance

Limited to evidence and contact channel

Audio, call recordings, transcripts, sentiment analysis and voiceprints have a launch retention of zero days because LuminPay does not collect them.

When a retention period ends, we securely delete, de-identify or aggregate the information unless a lawful hold applies. Backups are protected from ordinary use and expire under the approved backup schedule.

14. Security

LuminPay uses administrative, technical and physical safeguards appropriate to the sensitivity of the information. Controls include least-privilege access, encryption in transit and at rest where appropriate, hosted payment fields, multifactor protection for privileged access, environment separation, signed webhooks, rate limits, audit records, secure development and incident response.

No system is perfectly secure. If a privacy breach creates a real risk of significant harm or another reporting threshold is met, LuminPay will notify the appropriate regulator and affected individuals as required by law. Please report suspected unauthorized access to hello@charmonix.ca

15. Your privacy rights

Subject to applicable law and identity verification, you may:

request access to personal information LuminPay holds about you and information about its use and disclosure;

request correction of inaccurate or incomplete information;

withdraw consent where processing depends on consent;

change cookie preferences or unsubscribe from marketing;

request deletion or de-identification where retention is no longer required;

ask for human review of a materially adverse fraud or duplicate-trial decision; and

complain to LuminPay or a privacy regulator.

Send a request to hello@charmonix.ca. Describe the request and the account email, but do not send a password, one-time code, full card number or unnecessary clinical information. We may ask for proportionate identity verification. We will respond within the period required by law, explain any lawful refusal and identify available complaint options.

You may complain to the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca) or, where applicable, the Office of the Privacy Commissioner of Canada (priv.gc.ca).

16. Minors

The consumer Platform is for adults aged 18 and older. We do not knowingly offer accounts to minors. If you believe a minor provided personal information, contact the Privacy Officer so we can investigate and take appropriate action.

17. Changes to this policy

We may update this policy to reflect lawful changes to the Platform. We will post the new date and version. If a change is material, we will provide prominent notice and obtain consent where required. We will not rely on a revised policy to justify a materially new use of previously collected sensitive information without the notice and consent the law requires.

18. Contact

Privacy Officer

Charmonix, doing business as LuminPay

Business and mailing address: 2482 Yonge St, Toronto, Ontario, M4P 2H5, Canada

hello@charmonix.ca

647-947-7921

For billing or account support, contact hello@charmonix.ca or 647-947-7921.