Version 1.1

Cookie Policy

Effective date: 10 September 2026

This Cookie Policy explains the cookies and similar browser storage Luuma uses on its website and services.

Luuma Technologies Limited is registered in England and Wales under company number 17433694. Our registered office is 38 Green Close, Renishaw, S21 3WS. Contact us at data@luuma.cloud.

1. Your choice

On public Luuma marketing and signup pages, optional analytics and advertising measurement are off by default. You can accept both, reject both, or choose each category separately. We do not load the corresponding Google technology or send it data before you make the relevant choice.

Cookie Settings lets you change or withdraw a choice at any time. We store the choice and the time each purpose was granted in local storage as luuma.analytics.consent.v1 for 180 days, then ask again. Deleting browser storage can also remove it.

2. Essential and preference storage

Essential storage supports sign-in, security, password changes, and user-selected service features. It is not used for optional website measurement.

  • ms_oauth_state: an HttpOnly, Secure in production, SameSite=Lax cookie used to bind a Microsoft sign-in or account-linking request to its callback. It expires after 10 minutes or is deleted after the callback.
  • authToken: local storage holding an authenticated service access token. It is removed on sign-out or an unauthenticated response and normally expires after two hours; a deployment can set a shorter or longer server token lifetime.
  • luuma.password-change: session storage holding a temporary password-change challenge. It is cleared after use or when the browser session ends, and the challenge expires within 15 minutes.
  • luuma.ticketing.customer-recents.v1 and luuma.insights.hiddenAssistantThreads.<client>.<scope>: local storage for service features selected by an authenticated user. They remain until the user clears browser data or the application replaces them.
  • luuma.insights.query-cache: local storage used by the application cache. The current cache policy expires retained entries after 24 hours.
  • luuma.analytics.consent.v1: local storage recording the analytics and advertising measurement choices and the time each choice was granted. It expires after 180 days and is removed when browser data is cleared.

3. Analytics measurement

If you opt in to Analytics, we use Google Analytics 4 on public Luuma marketing and signup pages to understand page use and the progress of a signup. We send sanitised page paths without query strings and limited manual page-view and signup-lifecycle events. We do not send email addresses, passwords, signup tokens, Stripe session identifiers, or authenticated application data in these events.

  • _ga and _ga_<container-id>: Google Analytics cookies used to distinguish visits and link analytics activity. Luuma sets a 180-day lifetime for these cookies.

4. Advertising measurement

If you opt in to Advertising measurement, we use Google Ads conversion measurement on the same public pages. It records account activation with an opaque server-generated event identifier to help prevent duplicate conversion reporting. We do not use remarketing, Google signals, ad personalisation, enhanced conversions, customer-list uploads, audience uploads, or URL passthrough.

Google’s conversion linker may also store ad-click information in browser local storage under _gcl_ls. Luuma removes this storage when Advertising measurement consent is withdrawn or an expired choice is detected. After Advertising measurement consent, luuma.analytics.gclid.v1 may store a valid Google click identifier from a public landing-page URL for up to 90 days. It is passed only to the isolated Google Ads measurement flow and is removed when Advertising measurement consent is withdrawn or the record expires. luuma.analytics.sent.v1 stores separate opaque markers for analytics lifecycle events and Ads conversion events for up to 180 days. Withdrawing Analytics removes its analytics markers. Withdrawing Advertising removes the click identifier and Ads conversion markers. Google controls whether it creates its own cookies and may change its own technology.

  • _gcl_*: Google Ads cookies that may be set after Advertising measurement consent. Google documents these cookies as having a typical 90-day lifetime; this can change under Google's configuration and policies.

5. Scope and first-party records

Optional Google measurement runs only on public marketing and signup pages on the production luuma.cloud website. It does not run in the authenticated Luuma application, player, or administration areas.

Luuma's first-party account, trial, billing, security, and operational records are required to provide the service and remain independent of optional cookie consent. A reviewed campaign or guide label submitted with a signup is a first-party source hint, not proof of an advertising click.

6. Google information and controls

Google processes optional measurement data under its own terms and policies. You can also use Google's controls to manage advertising personalisation and opt out of Google Analytics in supported browsers.

7. Contact and complaints

For questions about cookies or privacy, contact data@luuma.cloud. You can complain to the UK Information Commissioner's Office if you are dissatisfied with how we handle personal data.