Privacy Policy
Application: Lumio (Web)
Last updated: 2026-05-15
Lumio is a bilingual (Thai / English) business management web application for Thai small and medium businesses. It helps you create and manage customers, suppliers, products, quotations, invoices, purchase orders, and payments, with built-in support for PromptPay QR, Thai VAT, withholding tax (WHT), and e-Tax workflows.
1. Introduction
This Privacy Policy describes how TM3P Tech (“we”, “us”, “our”) collects, uses, and shares information when you use Lumio (the “App”).
2. Information We Collect
Lumio handles the business data you put into it. Specifically:
- Account information: Email address, display name, role within your workspace, and a hashed password. You may belong to one or more workspaces.
- Customer and supplier records: Name (Thai and English), tax ID, branch, business type, address, phone, email, payment terms, VAT and WHT registration status, and contact details that you enter.
- Products and inventory: SKU, name, category, pricing, and stock levels by location.
- Financial records: Quotations, invoices, purchase orders, payments, line items, and the resulting accounting and tax calculations.
- Company settings: Your business’s tax ID, VAT and WHT rates, PromptPay ID, and registration details.
- Audit data: Creation and modification timestamps and stock-movement history so that changes to records can be reconstructed.
- Operational logs: Standard web-server access logs (IP address, user agent, request URL, timestamp) for security, debugging, and abuse prevention.
3. How We Use Information
We use the information we collect to: (a) provide, operate, and maintain the App; (b) improve, personalize, and expand the App; (c) understand and analyze how you use the App; (d) detect, prevent, and address technical issues, fraud, or abuse; and (e) communicate with you about the App when necessary.
4. Legal Bases for Processing (EEA/UK Users)
If you are located in the European Economic Area or the United Kingdom, we process your information based on one or more of: (i) your consent; (ii) the performance of a contract with you; (iii) compliance with a legal obligation; or (iv) our legitimate interests in operating and improving the App.
5. Sharing of Information
We do not sell your personal information. We share information only with:
- Service providers that help us operate the App, such as cloud hosting, crash reporting, analytics, and push-notification providers. These providers may include Google Firebase, Apple, and similar industry-standard services.
- Platform providers (Apple and Google) to the extent required by their respective app distribution and payment systems.
- Legal and safety recipients, where required to comply with a legal obligation, enforce our Terms, or protect the rights, property, or safety of our users or others.
- Successors, in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections.
6. Third-Party Services
Lumio is built on a small, self-contained technology stack. It uses:
- Web hosting and database providers that store the Lumio application and database on our behalf.
- Email delivery provider (where used) to send transactional messages such as password resets and document deliveries.
Lumio does not embed advertising SDKs, analytics SDKs, or third-party tracking. We do not sell your data or share it with marketers.
7. Data Retention
We retain personal information only for as long as necessary to provide the App and for the purposes described in this Policy, unless a longer retention period is required or permitted by law. Aggregated or de-identified information may be retained indefinitely.
8. Security
We use commercially reasonable administrative, technical, and physical safeguards to protect information against unauthorized access, loss, or alteration. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. International Transfers
The App and its service providers may operate from servers located outside your country of residence, including Thailand and the United States. By using the App, you consent to the transfer of your information to these jurisdictions, which may have different data-protection laws than your own.
10. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to the processing of your personal information, as well as the right to data portability and to withdraw consent. To exercise these rights, contact us at cto@tm3p.com. We will respond within the timeframe required by applicable law.
11. Children’s Privacy
Lumio is a business product and is not directed at children. We do not knowingly collect personal information from children. If a child has been given access to a Lumio workspace, the workspace owner is responsible for removing that access; you may also contact us to assist.
12. Changes to This Policy
We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date and, where required, by additional notice within the App.
13. Contact
If you have questions about this Privacy Policy or our data practices, contact us at cto@tm3p.com.