Introduction
Luvon Labs (“we”, “us”, or “our”) is a full-stack design and development studio based in Newark, Delaware, United States. We build web products, mobile applications, Web3 systems, and AI agents for clients worldwide.
This Privacy Policy explains how we collect, use, share, and protect personal data when you visit luvonlabs.com, contact us about a project, or engage us to deliver services. It also explains the rights available to you and how to exercise them.
Information We Collect
2.1 Information You Give Us Directly
- Contact form & project inquiries — name, email address, company name, project description, budget range, and timeline submitted via the /contact page or sent to contact@luvonlabs.com.
- Email correspondence — any information you include when you email us.
- Client onboarding documents — NDAs, Master Service Agreements (MSAs), Statements of Work (SOWs), and related files exchanged during engagement setup.
- Payment & invoicing details — business name, billing address, and VAT/GST number as required for invoicing. We do not store full card numbers; payments are processed by third-party providers.
2.2 Information Collected Automatically
- IP address, approximate location (city/country), device type, operating system, and browser type.
- Pages visited, time on site, scroll depth, and referral source.
- Cookies and similar technologies — see our Cookie Policy for full details.
2.3 Information from Third Parties
- Analytics providers — aggregated usage data to help us improve the site.
- Payment processors — confirmation of payment status; we receive only what is necessary to reconcile invoices.
- Hosting & infrastructure providers — Vercel (hosting), AWS and/or Supabase (backend infrastructure) may log access requests as part of their standard operations.
How We Use Your Information
- Responding to project inquiries and scoping calls.
- Delivering contracted services — scoping, design, development, and deployment.
- Sending invoices, project status updates, and delivery confirmations.
- Improving the website experience and our service offerings through analytics.
- Meeting legal and compliance obligations (tax records, accounting, regulatory requests).
- Sending marketing communications about Luvon Labs — only with your explicit consent, and only if you have opted in. You can withdraw consent at any time.
Legal Basis for Processing
If you are located in the EU or UK, our processing of your personal data is governed by the General Data Protection Regulation (GDPR) and UK GDPR respectively. We rely on the following legal bases:
- Contractual necessity — processing required to deliver services you have engaged us to provide.
- Legitimate interest — analytics to improve the site, fraud prevention, and internal record-keeping, where our interests do not override your rights.
- Consent — marketing communications and non-essential cookies. You may withdraw consent at any time.
- Legal obligation — retaining financial records as required by US federal and state tax law and any other applicable regulation.
Data Storage & International Transfers
Our primary operations are based in Newark, Delaware, United States. Data may also be processed in the United States and European Union via our infrastructure providers (Vercel, AWS).
Where data is transferred outside your home country, we rely on appropriate safeguards — such as Standard Contractual Clauses (SCCs) for EU data transfers or equivalent mechanisms — to ensure your data receives an adequate level of protection.
Retention Periods
- Project inquiry data — retained for up to 2 years if no engagement follows; indefinitely for active or completed engagements.
- Client engagement records (contracts, invoices, SOWs) — retained for the duration of the engagement plus 7 years for accounting and tax compliance.
- Website analytics data — retained for up to 26 months or as configured by the analytics provider.
- Email correspondence — retained for as long as reasonably necessary for business purposes.
When data is no longer required, we delete or anonymise it securely.
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you.
- Correction — ask us to correct inaccurate or incomplete data.
- Deletion — request erasure of your data where we no longer have a lawful basis to retain it.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Restriction — ask us to restrict processing while a dispute is resolved.
- Withdrawal of consent — withdraw consent for marketing or non-essential cookies at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at contact@luvonlabs.com. We will respond within 30 days. We may need to verify your identity before fulfilling a request.
If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
Security
We implement reasonable technical and organisational measures to protect your data, including:
- Encryption in transit (TLS/HTTPS) and at rest where supported by our infrastructure.
- Access controls — data is accessible only to team members who need it.
- NDA-bound team members and subcontractors.
- Regular review of third-party subprocessor security practices.
No method of transmission over the internet is completely secure. In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify affected individuals and, where required, the relevant supervisory authority without undue delay.
Children's Privacy
Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18 (or 16 for residents of the EU/UK). If you believe a minor has submitted personal data to us, please contact us and we will delete it promptly.
Third-Party Links
Our website contains links to external sites — including client portfolio links, blog references, and GitHub repositories. Once you leave luvonlabs.com, this Privacy Policy no longer applies. We have no control over the content or privacy practices of third-party sites and encourage you to read their policies before submitting any personal data.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. The “Last updated” date at the top of this page reflects the most recent revision.
For material changes that significantly affect your rights, we will notify you via the email address on file (if you are an active client) or by displaying a prominent notice on the website. Continued use of the site after the effective date constitutes acceptance of the updated policy.
Contact
For any privacy-related questions, requests, or concerns, please contact us at:
- Email: contact@luvonlabs.com
- Postal address: Luvon Labs, 131 Continental Drive, Suite 305, Newark, DE 19713, United States
If you have appointed a Data Protection Officer or Grievance Officer for your organisation, please include their contact details in your correspondence so we can address your request appropriately.
Jurisdiction-Specific Disclosures
United States — Delaware & Federal Law
Luvon Labs is incorporated in the State of Delaware and operates under applicable US federal and state privacy laws. Where US state privacy laws apply to your data, you may have rights to access, correct, delete, or opt out of the sale of your personal information. We do not sell personal information. To exercise your rights, contact us at contact@luvonlabs.com.
European Union & United Kingdom — GDPR / UK GDPR
EU and UK residents have additional rights under the GDPR and UK GDPR, including the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK or your national data protection authority in the EU). Our legal basis for processing is set out in Section 4.
California — CCPA / CPRA
California residents have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete it, and the right to opt out of its sale. Luvon Labs does not sell personal information. Categories of personal information collected are described in Section 2. To submit a verifiable consumer request, email contact@luvonlabs.com.