Privacy Policy
Effective date: July 20, 2026
Last updated: July 20, 2026
Version: consumer-privacy-v1.0
This Customer Privacy Policy explains how Charmonix, doing business as LuminPay,
handles personal information about website visitors, prospective customers and
customers. It does not cover employees, applicants, contractors, field
representatives, ambassadors or clinic personnel in those roles.
1. Privacy at a glance
|
Topic |
LuminPay's consumer commitment |
|
Payment cards |
Card checkout is hosted by Stripe; LuminPay
is not intended to receive or store full card numbers or security codes |
|
Clinical
information |
LuminPay is a marketplace, not a clinic; we minimize treatment-related
information and direct clinical information to the chosen clinic |
|
Marketing |
Email and SMS marketing are optional, separate choices;
unsubscribing does not cancel service |
|
Cookies |
Necessary
technologies run the site; optional attribution and analytics remain off
until you choose them |
|
Advertising |
No sale or rental of personal information; no third-party
behavioural advertising pixels or session replay at launch |
|
Representatives |
Ambassadors
and field representatives do not receive customer identity, contact,
treatment, payment or cancellation details |
|
Location |
Service providers may process information in Canada, the
United States and other disclosed jurisdictions |
|
Your
choices |
You may
ask for access or correction, withdraw consent, change cookies, unsubscribe
or complain |
2. Who is responsible
LuminPay is responsible for the
personal information under its control and designates a Privacy Officer.
Privacy Officer
Charmonix, doing business as LuminPay
Business and mailing address: 2482 Yonge St, Toronto,
Ontario, M4P 2H5, Canada
hello@charmonix.ca
647-947-7921
Contact the Privacy Officer to ask about this policy, access
to personal information, use of service providers outside Canada or a privacy
concern.
3. Laws and scope
Alberta's Personal Information Protection Act ("PIPA")
generally applies to LuminPay's commercial handling
of personal information in Alberta. The federal Personal Information Protection
and Electronic Documents Act ("PIPEDA") may apply to interprovincial or
international commercial activity and in other circumstances. Other mandatory
privacy, health-information, consumer or communications laws may also apply.
Clinics and regulated health professionals are separately
responsible for patient and clinical information in their custody or control,
including obligations under Alberta's Health Information Act where applicable.
If LuminPay ever acts as an information manager for a
clinic, the parties must first implement the agreement, safeguards and approved
process required by law. This policy does not replace a clinic s privacy
notice.
4. Information we collect
We collect only information reasonably required for
identified purposes. Whether information is required or optional will be
explained at the point of collection.
4.1 Information you provide
Account and eligibility: name, email, mobile number,
postal code, age or confirmation that you are at least 18, authentication data
and account preferences.
Transactions and membership: selected pass,
acceptance record, receipts, payment status, renewal and cancellation status,
credits, refunds, disputes and provider transaction identifiers. Stripe, not LuminPay, receives full card details.
Booking and scheduling:
chosen clinic or service category, booking request, availability, consent to
share, booking status and minimal scheduling communication. Please do not
provide clinical narratives through LuminPay.
Support: messages, attachments you choose to send,
complaint information and resolution history. We may remove unnecessary
sensitive content.
Consent and preferences: contract version, cookie
choices, marketing choices, unsubscribe and withdrawal records.
Optional referrals: a referral or short code you
enter and the related opaque campaign identifier.
4.2 Information collected automatically
Necessary technical data: request time, page or
route, browser and device type, session and security events, authentication
status, cookie or local-storage values described in the Cookie Policy, and
limited IP or network information needed for delivery, abuse prevention and
security.
Privacy-minimized risk data: rate-limit buckets, an
HMAC-derived risk token and fraud or duplicate-trial signals. We do not place
raw card fingerprints in analytics or customer-facing systems.
Attribution data, if you allow it: signed QR or
referral source, campaign, venue or representative identifier, first qualifying
interaction and time. The identifier is opaque to the browser and does not
contain the representative's or customer's identity.
First-party analytics, if you allow it: approved
page, performance and conversion events. Analytics must not contain name,
email, phone, postal code, raw IP, provider IDs, free text, treatment interest,
full URLs or query strings.
4.3 Information from others
We may receive payment status from Stripe; financing status
from Affirm if you choose it; booking or redemption status from a participating
clinic; masked-call status from Twilio; authentication or hosting signals from
our technology providers; and a referral source from a signed LuminPay code. We do not treat a checkout return page as
proof of payment.
5. Why we use personal information
We use personal information to:
create and secure an account, verify age and service area,
and authenticate you;
display, form and evidence the online contract;
process payment status, issue and reconcile credits,
administer renewal and cancellation, detect duplicate trials and resolve
refunds or disputes;
accept, route and track a booking request and, with
permission, create a temporary masked scheduling connection;
provide receipts, security alerts, payment and booking
notices, customer support and accessibility;
prevent fraud, abuse, unauthorized access and ledger
manipulation;
meet tax, accounting, consumer-protection, privacy,
anti-spam, legal and regulatory obligations;
measure campaign attribution or site performance only when
the applicable optional choice is enabled; and
send marketing only with consent or another lawful basis.
We will not use personal information for a new purpose that
a reasonable person would not expect without explaining the purpose and
obtaining any required consent.
6. Consent and choices
We seek meaningful consent by explaining what information is
collected, which parties receive it, the purposes and meaningful risks or
consequences. We do not bundle optional marketing, optional cookies or clinic
sharing into the required purchase acknowledgement.
Some information is necessary to provide the requested
contract or meet law. If you do not provide it, we may be unable to create an
account, process a payment, issue credits or send a booking request. Other
information is optional. Refusing or withdrawing an optional choice will not
prevent purchase unless that information is genuinely required for the selected
feature.
You may withdraw consent, subject to reasonable notice and
legal or contractual limits, by using the relevant settings or contacting the
Privacy Officer. Withdrawal does not operate retroactively and may prevent a
feature that requires the information. We will explain material consequences.
7. Who receives information
We do not sell or rent personal information. We do not
disclose customer information to third parties for their own behavioural
advertising.
We may disclose limited information to:
Payment and financing providers: Stripe for hosted
payments and, only if you choose it, Affirm for financing. These providers also
handle information under their own privacy notices.
Infrastructure and security providers: hosting,
database, authentication, content delivery, monitoring, fraud prevention and
support providers acting for LuminPay.
Communications providers: email/SMS delivery and
Twilio for the optional 72-hour masked scheduling connection. No audio
recording or transcription is authorized.
Participating clinics: only the information needed
for the booking or service process, after the relevant notice and
authorization. Clinics use patient information under their own legal duties and
notices.
Professional advisers and authorities: auditors,
accountants, insurers, legal advisers, regulators, courts or law enforcement
where reasonably necessary or legally required.
A successor organization: in a genuine financing,
reorganization or sale, under confidentiality and privacy safeguards and
subject to applicable consent or notice requirements.
Field representatives and ambassadors receive only
pseudonymous or aggregated performance information. They do not receive your
name, contact details, treatment interest, clinic choice, payment status,
cancellation reason or support content.
8. Service providers and processing outside Canada
LuminPay uses service providers to
operate the Platform. Our current provider page at https://luminpay.charmonix.ca
identifies material providers, their purpose, the categories of information
they process, relevant processing locations and links to their notices.
Current deployment-confirmed providers: Stripe, Clerk,
Microsoft Clarity, Cloudflare.
Some providers may store or process information in Canada,
the United States or other jurisdictions identified in LuminPay s
current provider list at https://luminpay.charmonix.ca Information processed
outside Canada is subject to the laws of that jurisdiction and may be
accessible to courts, law enforcement or national-security authorities under
those laws.
LuminPay remains accountable for
information transferred to a service provider for processing. We use
contractual, access, security and retention controls appropriate to the
sensitivity and purpose. Contact the Privacy Officer for information about our
policies and practices concerning service providers outside Canada.
9. Clinic and health-information boundary
A service category, clinic choice or booking request may
reveal sensitive information about your interests. We minimize that
information, do not place it in advertising or general analytics, and share it
only for the service you request or as otherwise authorized by law.
The clinic independently collects the health information
required for assessment and care. Its privacy notice explains its authority,
purposes, records, access process and complaints. LuminPay
does not use clinic health records for marketing, representative attribution or
automated advertising.
If a clinic mistakenly sends unnecessary clinical
information to LuminPay, we will restrict access,
notify the appropriate privacy owner, and securely return, transfer or delete
it as law and the applicable agreement require.
10. Marketing communications
Email and SMS marketing use separate, optional controls. A
consent record may include the address or number, consent language and version,
date, time, source and withdrawal. Commercial messages identify the sender,
provide required contact information and include a working unsubscribe method.
We process unsubscribe requests promptly and no later than
the legal deadline. We retain a minimal suppression record so we can honour the
request. Unsubscribing does not stop transaction, account, security, renewal,
cancellation, receipt, booking or support messages that are necessary to
provide the service.
11. Cookies and similar technologies
The Cookie Policy identifies each technology, purpose,
provider and duration. Necessary technologies support authentication, security,
checkout, fraud prevention and privacy choices. Optional campaign attribution
and first-party analytics remain off until you choose them. You can reject
optional technologies without losing access to purchase or account functions.
LuminPay does not use third-party
advertising pixels or session-replay tools on checkout, account, booking or
health-related pages at launch. We treat Global Privacy Control as a signal to
reject optional tracking where technically received
and applicable.
12. Automated processing and human review
We may use rules to prevent duplicate introductory offers,
rate-limit abuse, authenticate payments, identify suspicious ledger activity
and protect accounts. Those rules may pause a transaction or request additional
verification. They do not make clinical decisions. You may contact support to
request human review of a materially adverse automated result.
Affirm independently decides financing eligibility under its
own processes. LuminPay does not receive a right to
override that decision.
13. Retention
We keep personal information only as long as reasonably
needed for the identified purpose, legal requirements, a dispute or a
documented legal hold. Different fields in the same record may have different
retention periods.
|
Record
class |
Launch
retention |
Main
safeguard |
|
Financial, credit-ledger, payment, refund, dispute and
reconciliation records |
Six years from the end of the last tax year to which the
record relates; longer only for an unresolved audit, claim or legal hold |
Preserve financial integrity while tokenizing or deleting
unrelated identity fields |
|
Raw
Stripe/Affirm event payload |
180
days after terminal processing |
Encrypted;
then reduce to minimal event, amount, status, ID and integrity evidence |
|
Trial payment-fingerprint HMAC |
Life of the introductory program plus 24 months |
Keyed HMAC only; no card number or raw fingerprint |
|
Member
and clinic private phone numbers |
While
the verified contact relationship is active, then 30 days after closure
unless a support case or hold applies |
Encrypted;
delete derived search tokens and retain only deletion proof |
|
Twilio participant IDs |
30 days after masked session close |
Minimize provider callback data |
|
Minimal
masked-call status/time/duration |
90 days |
No
audio, transcript, voiceprint or treatment narrative |
|
Masking consent and withdrawal proof |
24 months after the final session or complaint resolution,
whichever is later |
Notice version, time, purpose, clinic and closure only |
|
Application
and security logs |
30 days
searchable plus 335 days restricted archive |
Redact
secrets, contact data, treatment interest and raw provider payloads |
|
Cookie preference record |
Current preference plus prior evidence needed to
demonstrate consent or withdrawal, normally up to 24 months |
No advertising profile |
|
Marketing
consent and suppression |
Consent
while relied on; suppression as long as reasonably
needed to honour opt-out and prove compliance |
Limited
to evidence and contact channel |
Audio, call recordings, transcripts, sentiment analysis and
voiceprints have a launch retention of zero days because LuminPay
does not collect them.
When a retention period ends, we securely delete,
de-identify or aggregate the information unless a lawful hold applies. Backups
are protected from ordinary use and expire under the approved backup schedule.
14. Security
LuminPay uses administrative,
technical and physical safeguards appropriate to the sensitivity of the
information. Controls include least-privilege access, encryption in transit and
at rest where appropriate, hosted payment fields, multifactor protection for
privileged access, environment separation, signed webhooks, rate limits, audit
records, secure development and incident response.
No system is perfectly secure. If a privacy breach creates a
real risk of significant harm or another reporting threshold is met, LuminPay will notify the appropriate regulator and affected
individuals as required by law. Please report suspected unauthorized access to
hello@charmonix.ca
15. Your privacy rights
Subject to applicable law and identity verification, you
may:
request access to personal information LuminPay
holds about you and information about its use and disclosure;
request correction of inaccurate or incomplete information;
withdraw consent where processing depends on consent;
change cookie preferences or unsubscribe from marketing;
request deletion or de-identification where retention is no
longer required;
ask for human review of a materially adverse fraud or
duplicate-trial decision; and
complain to LuminPay or a privacy
regulator.
Send a request to hello@charmonix.ca. Describe the request
and the account email, but do not send a password, one-time code, full card
number or unnecessary clinical information. We may ask for proportionate
identity verification. We will respond within the period required by law,
explain any lawful refusal and identify available complaint options.
You may complain to the Office of the Information and
Privacy Commissioner of Alberta (oipc.ab.ca) or, where applicable, the Office
of the Privacy Commissioner of Canada (priv.gc.ca).
16. Minors
The consumer Platform is for adults aged 18 and older. We do
not knowingly offer accounts to minors. If you believe a minor provided
personal information, contact the Privacy Officer so we can investigate and
take appropriate action.
17. Changes to this policy
We may update this policy to reflect lawful changes to the
Platform. We will post the new date and version. If a change is material, we
will provide prominent notice and obtain consent where required. We will not
rely on a revised policy to justify a materially new use of previously
collected sensitive information without the notice and consent the law
requires.
18. Contact
Privacy Officer
Charmonix, doing business as LuminPay
Business and mailing address: 2482 Yonge St, Toronto,
Ontario, M4P 2H5, Canada
hello@charmonix.ca
647-947-7921
For billing or account support, contact hello@charmonix.ca or 647-947-7921.