Legal
Privacy Policy
Last updated: August 2026
This Privacy Policy explains how Luminary Crest Holdings LLC ("Luminary Crest," "we," "us," or "our") collects, uses, shares, retains and protects personal data when you visit luminarycrest.com, contact us, or engage our performance marketing services. It applies to our website and to the professional services we deliver to clients.
1. Controller Identification
The controller responsible for processing personal data described in this policy is:
Luminary Crest Holdings LLC, a limited liability company organized under the laws of the State of Delaware, United States.
501 Silverside Road, Suite #105 - 5511, Wilmington, DE 19809, United States
Phone: +1 (302) 271-7240
Email: info@luminarycrest.com
For privacy matters, the email address above is our single point of contact. We have not appointed a designated Data Protection Officer; privacy requests are handled directly by company management.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data, including collection, storage, use, sharing, and deletion.
- Controller: the party that determines the purposes and means of processing.
- Processor: a party that processes personal data on behalf of a controller.
- Data subject: the natural person to whom the personal data relates.
- Cookies: small files stored on your device by a website, and equivalent technologies such as pixels, local storage and SDK identifiers.
- Client: a business that engages Luminary Crest to deliver marketing services.
3. Personal Data We Collect
- Contact form data: name, company name, email address, phone number and the content of your message.
- Client business and billing contacts: names, roles, business email addresses and phone numbers, plus billing and invoicing details, collected during an engagement.
- Technical and log data: IP address, browser and device type, operating system, referring source, pages viewed, timestamps and approximate location derived from IP.
- Campaign and conversion data: aggregated advertising metrics, conversion and lead events, and audience segments generated by advertising and analytics platforms in the course of delivering our services.
- Lead data processed for clients: where a campaign we operate collects leads, the contact details submitted by the end user are processed on behalf of, and for, our client.
We do not intentionally collect special categories of personal data (such as health, racial or ethnic origin, religious beliefs, or biometric data) and ask that you do not submit them through our contact form.
4. Sources of Data
- Directly from you: when you complete our contact form, email us, call us, or exchange information during an engagement.
- Automatically from your device: through server logs, cookies and similar technologies when you browse our website.
- From advertising and analytics platforms: aggregated performance and conversion data associated with campaigns we manage for clients.
- From our clients: business contact and campaign information supplied to us so we can perform the agreed services.
5. Purposes and Legal Bases
Where the GDPR applies, each processing activity rests on at least one legal basis under Article 6. Where US state privacy laws apply, processing is limited to the purposes disclosed below.
- Responding to inquiries — steps taken at your request prior to entering a contract (Art. 6(1)(b)) or our legitimate interest in replying to business contacts (Art. 6(1)(f)).
- Delivering, managing and improving our services — performance of a contract (Art. 6(1)(b)).
- Planning, running and optimizing advertising campaigns for clients — performance of a contract with the client (Art. 6(1)(b)) and, for end users, the legal basis established by the client as controller.
- Measuring performance and producing reporting — legitimate interest in evaluating and improving service quality (Art. 6(1)(f)).
- Marketing communications from Luminary Crest — consent (Art. 6(1)(a)), withdrawable at any time.
- Website operation, security and fraud prevention — legitimate interest in keeping our systems available and secure (Art. 6(1)(f)).
- Complying with legal, tax and regulatory obligations — compliance with a legal obligation (Art. 6(1)(c)).
- Establishing, exercising or defending legal claims — legitimate interest and, where applicable, legal obligation (Art. 6(1)(f) and (c)).
6. Sharing With Third Parties
We do not sell personal information, and we do not share it for cross-context behavioral advertising on our own behalf. We disclose personal data only to service providers that are necessary to operate our website and deliver our services, each bound by confidentiality and data protection obligations:
- Hosting, CDN and DNS provider — serves our website and protects it against attacks. Data processed: IP address, request headers, access logs.
- Email and messaging providers — deliver and store inquiries sent to us. Data processed: name, email address, phone number and message content.
- Google LLC (Google Ads, Google Analytics, Google Tag Manager) — campaign delivery, conversion measurement, tag deployment and aggregated traffic analytics. Data processed: advertising and analytics identifiers, truncated IP, browsing and conversion events.
- Meta Platforms, Inc. (Meta Ads) — campaign delivery and conversion measurement on Facebook and Instagram. Data processed: advertising identifiers, event data.
- Marketing automation and CRM tools used within a client engagement — as instructed by, and under the account of, the client.
- Professional advisors — accountants and legal counsel, where necessary and under professional secrecy obligations.
- Public authorities — where required by law, court order or official investigation, or to establish or defend legal rights.
- A successor entity — in the event of a merger, acquisition or corporate reorganization, subject to this policy continuing to apply.
When we operate advertising and analytics platforms inside a client's own accounts, the client remains the controller of the data held in those accounts and their own privacy notice governs that processing; we act as their processor.
7. International Data Transfers
We are established in the United States and use global providers, so personal data may be transferred to and stored on servers located outside your country, including in the United States. Where data originates in the European Economic Area, the United Kingdom or Switzerland, transfers are made under one or more of the following safeguards:
- Standard Contractual Clauses approved by the European Commission (and the UK Addendum where relevant);
- transfers to recipients covered by an applicable adequacy decision, including certification under the EU-US Data Privacy Framework where the recipient participates;
- your explicit consent, where applicable;
- supplementary technical measures such as encryption in transit and at rest and data minimization.
You may request a copy of the safeguards in place using the contact channel in section 12.
8. Data Retention Periods
- Contact form inquiries: up to 24 months from the last interaction.
- Access logs and technical data: up to 6 months, unless required longer for a security investigation.
- Client engagement records, contracts and invoices: for the period required by applicable tax and commercial law, generally 7 years.
- Marketing consent records: for as long as the consent is active; after withdrawal, deleted within 30 days except for a minimal opt-out record.
- Data relevant to a legal claim: until the claim and any limitation period have concluded.
Once a retention period expires, data is securely deleted or irreversibly anonymized.
9. Information Security
We apply reasonable technical and organizational measures appropriate to the risk, including:
- encryption in transit (TLS) for all communication with our website;
- encryption at rest in the storage services we use;
- access control based on least privilege and need to know;
- strong authentication and periodic credential rotation for platform accounts;
- logging and monitoring of relevant security events;
- keeping dependencies and platforms up to date;
- confidentiality obligations for personnel and contractors;
- an incident response process, including notification of affected individuals and competent authorities where a breach is likely to result in a risk to their rights.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Cookies and Similar Technologies
Our website and the campaigns we operate for clients may use cookies and similar technologies in the following categories:
- Strictly necessary: required for the site to function and to protect it. These do not require consent.
- Performance and analytics: measure aggregated usage such as pages visited and session duration. Consent is requested where they involve persistent identifiers.
- Functionality: remember preferences between visits.
- Advertising and measurement: used within client campaigns for attribution and conversion measurement. Consent is required where applicable.
You can accept or refuse non-essential cookies at any time through your browser settings or, where presented, a consent banner. Refusing them does not prevent access to the public areas of the site, but may limit some functionality. To manage Google advertising preferences, see adssettings.google.com.
11. Your Rights
Depending on where you live, you may have the following rights, exercisable free of charge:
- confirmation of whether we process your personal data, and access to that data;
- correction of incomplete, inaccurate or outdated data;
- deletion of data processed without a valid legal basis, or where no longer necessary;
- portability of data you provided to us, in a structured, commonly used format;
- restriction of processing in specified circumstances;
- objection to processing based on legitimate interest, including for direct marketing;
- withdrawal of consent at any time, without affecting the lawfulness of prior processing;
- information about the entities with which we have shared your data;
- the right not to be discriminated against for exercising a privacy right;
- the right to opt out of the sale or sharing of personal information — we do not sell or share personal information as those terms are defined under California and other US state privacy laws.
12. How to Exercise Your Rights
Send your request to info@luminarycrest.com with the subject line "Privacy Request" and a description of the right you wish to exercise. We may need to verify your identity before acting, using information already in our possession. We respond within 30 days; where a request is complex, we may extend this period and will tell you why. Authorized agents may submit requests on your behalf with written proof of authorization.
If your request concerns data we process on behalf of a client, we will forward it to that client, who is the controller, and support them in responding.
13. Children's Data
Our website and services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 16 years of age. If we learn that we have collected such data, we will delete it promptly. Parents or guardians who believe a child has provided us with personal data may contact us at the address above.
14. Automated Decision-Making and Profiling
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Advertising platforms we operate on behalf of clients use their own algorithms to optimize audience targeting, bidding and delivery. These processes are aimed at advertising effectiveness and do not determine access to credit, employment, housing, insurance or comparable outcomes.
15. Complaints and Supervisory Authorities
We would like the opportunity to resolve your concerns first, so please contact us at info@luminarycrest.com. You also have the right to lodge a complaint with a competent authority: in the EEA, the supervisory authority of your habitual residence, place of work or place of the alleged infringement; in the United Kingdom, the Information Commissioner's Office; and in the United States, the attorney general of your state where your state privacy law provides that route.
16. Changes to This Policy
We may update this policy to reflect changes in our practices, technology or legal requirements. The current version is always published on this page with an updated effective date. Where changes are material, we will take reasonable steps to notify you.
17. Contact
Luminary Crest Holdings LLC
501 Silverside Road, Suite #105 - 5511, Wilmington, DE 19809, United States
Phone: +1 (302) 271-7240
Email: info@luminarycrest.com
