Your evidence stays private.

Updated for the launch of paid plans. This notice describes the information used by LumaTrust’s verification service.

Information we collect

Account details include your name, email address, Microsoft customer identity reference and the date you accepted our terms. Microsoft Entra External ID handles email-code authentication; LumaTrust does not collect customer passwords. Business applications include registration details, website and contact links, uploaded evidence, domain ownership checks, and review decisions. Reviews include your displayed name, rating, text, experience date and any business response.

Why we use it

We use this information to operate accounts, assess applications, substantiate verification decisions, show current business profiles and badges, publish customer experiences, and prevent misuse. Confirming access to an email account does not authorize you to represent a business. Business ownership and verification are checked separately.

Website analytics

We use Google Analytics on public website pages to understand visits and navigation. Google Analytics uses cookies to distinguish visits. Our page-view tracking excludes the account portal and administrator pages and removes URL query strings and fragments. We do not send uploaded evidence, application details or form entries through this tracking. Google advertising signals and automatic enhanced measurement are disabled.

Public and private information

Public profiles show selected business facts, status and verification dates. Reviews publish the name you provide alongside your experience. Account emails, registration documents, Microsoft identity references and internal review notes are not public. Authorized reviewers can access uploaded evidence for application assessment.

Storage and retention

LumaTrust stores business records in Microsoft Azure SQL and documents in a private Azure Blob Storage container. Uploaded documents are removed from active storage once they are more than 90 days old, unless the application is still under review. Document hashes and decision audit records remain to substantiate the review. Expired sign-in sessions are removed automatically. Backup retention follows the underlying Azure service settings.

Browser storage

Microsoft’s authentication library uses session storage for customer sign-in tokens and account information. The reviewer console uses Microsoft sign-in and its associated authentication storage. The application does not include advertising trackers.

External services

Microsoft Azure provides hosting, database, storage, customer authentication through LumaTrust’s dedicated External ID tenant, and reviewer authentication. Domain ownership checks query Google Public DNS for the relevant public TXT record. Following a business’s website link takes you to that business’s own site and privacy practices.

Payments and subscriptions

Stripe processes Business subscriptions and hosts checkout and billing management. We send your account email and internal business, owner and checkout references to connect the subscription to the correct website. Payment details are entered directly with Stripe. LumaTrust stores Stripe customer and subscription references, payment-event references, subscription status and paid-access dates; it does not store card numbers. These billing records are private and are used to operate subscriptions, resolve billing requests and maintain payment history. Verification documents are not sent to Stripe.

AI document reviews

Authorized reviewers can use OpenAI to assess registration evidence. Selected PDFs or images and the application's legal name, registration number, formation date and jurisdiction are sent to OpenAI. Findings are saved in the private audit history. AI-assisted approval requires independent reviewer checks of the registry, authority, trading name and contact details, a recent domain check and six-month eligibility. Unclear results remain for human review.

Requests disable OpenAI Responses storage. OpenAI's standard abuse-monitoring settings may still retain content for up to 30 days. See OpenAI's data controls. You can request a human review through the portal support form.

Managing your information

You can edit application details and remove uploaded documents before submission. Evidence is locked during review and while verified. Use the privacy request form in your signed-in portal for account-data access, correction or deletion requests. We review requests against the records needed to maintain an accurate verification history.

Do not upload unrelated personal identification, bank details or sensitive information that is unnecessary for business verification. Redact unnecessary details before uploading.