Privacy Policy
Last Updated: August 3, 2026
This Privacy Policy describes how Lutely Inc., doing business as Mirour ("Mirour," "we," "us," or "our"), collects, uses, shares, and protects information in connection with the Mirour platform and related services.
This policy applies to two types of users:
Brands — businesses that use the Mirour platform to create in-store experiences
Shoppers — individuals who interact with Mirour experiences in stores (via QR codes, NFC tags, tablets, or links)
By using our platform or interacting with a Mirour-powered experience, you agree to the practices described in this policy.
1. Information We Collect
1.1 Information from Brands
When a brand signs up for Mirour, we collect:
Business name, contact name, email address, and phone number
Billing and payment information
Product catalog and inventory data (synced from Shopify, Square, Lightspeed, or uploaded directly)
Brand content including images, descriptions, and branding materials
Platform usage and activity data
1.2 Information from Shoppers
When a shopper interacts with a Mirour experience in a store, we may collect:
Name, email address, and phone number (if voluntarily provided)
Product preferences, quiz and flow responses, and saved products
AI chat conversations and search queries
Engagement data including pages viewed, products browsed, and time spent
Device type, browser, and general location (city/region level, not precise GPS)
Referral source (e.g., QR code, NFC tag, direct link)
We do not collect information from shoppers who do not interact with Mirour. All shopper data collection requires the shopper to initiate an interaction (scanning a QR code, using a tablet, etc.).
1.3 Information Collected Automatically
When anyone accesses the platform, we automatically collect:
IP address (used for security and general location only)
Device and browser information
Cookies and similar tracking technologies
Platform usage patterns and analytics
2. How We Use Information
2.1 To Provide and Operate the Platform
We use information to deliver guided in-store experiences, process product recommendations, enable AI-powered chat and product matching, send SMS and email communications on behalf of brands (with shopper consent), sync data with integrated platforms (Shopify, Square, Klaviyo, Mailchimp, etc.), and process payments and manage accounts.
2.2 To Improve and Develop Our Services
We use information to train and improve our AI and machine learning models, analyze platform performance and user engagement, develop new features and services, and conduct research and analytics.
2.3 To Create Aggregated Insights
We create de-identified, aggregated data from platform usage to produce industry benchmarks and reports, generate anonymized performance insights for platform users, conduct and publish research, license or distribute aggregated insights to third parties, and improve the overall platform experience.
2.4 To Communicate
We use information to send service-related notices and updates, respond to inquiries and support requests, and send marketing communications (with consent, and with the ability to opt out at any time).
3. How We Share Information
3.1 With Brands
When a shopper interacts with a Mirour experience, we share that shopper's information with the brand that operates that experience. This includes any information the shopper voluntarily provides (name, email, phone number, preferences) and engagement data from that brand's experience.
We do not share a shopper's data from one brand's experience with a different brand, unless the data has been aggregated and de-identified.
3.2 With Integrated Platforms
When a brand connects Mirour to third-party platforms (such as Shopify, Square, Klaviyo, or Mailchimp), we share data as necessary to enable those integrations. The use of data by those platforms is governed by their own privacy policies.
3.3 Aggregated and De-Identified Data
We may share, publish, license, or sell aggregated and de-identified data that cannot reasonably be used to identify any individual shopper or brand. This includes industry benchmarks, category-level trends, engagement statistics, and similar insights.
3.4 Service Providers
We share information with third-party service providers who help us operate the platform, including hosting and infrastructure providers, payment processors, email and SMS delivery services, and analytics tools. These providers are contractually obligated to use information only to provide services to us.
3.5 Legal Requirements
We may disclose information if required to do so by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect the rights, property, or safety of Mirour, our users, or the public.
3.6 Business Transfers
If Mirour is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
4. We Do Not Sell Personal Information
Mirour does not sell, rent, or trade individual personal information to third parties for their marketing purposes.
Our use of aggregated and de-identified data (as described in Section 3.3) does not constitute a sale of personal information, as this data cannot be linked back to any individual.
For purposes of the California Consumer Privacy Act (CCPA), we do not "sell" or "share" personal information as those terms are defined under the CCPA.
5. Your Rights and Choices
5.1 All Users
You may request access to the personal information we hold about you, request correction of inaccurate information, request deletion of your information, opt out of marketing communications at any time, and disable cookies through your browser settings.
5.2 California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; request deletion of your personal information; opt out of the sale of personal information (we do not sell personal information); and not be discriminated against for exercising your privacy rights.
To exercise these rights, contact us at hello@mirourmirour.com.
5.3 Shopper Data Requests
If you are a shopper and want to access, correct, or delete the information Mirour holds about you, contact us at hello@mirourmirour.com. We will respond within 30 days.
You may also contact the brand directly — brands can access and manage their customer data through the Mirour platform.
6. Data Retention
We retain brand account data for the duration of the account plus 90 days after termination. We retain shopper data for as long as needed to provide services to the brand and fulfill the purposes described in this policy. We retain aggregated and de-identified data indefinitely, as it cannot be linked to individuals.
Brands may request export of their customer data at any time. Upon account termination, customer data is retained for 90 days to allow export, after which it may be permanently deleted.
7. Data Security
We implement commercially reasonable technical and organizational measures to protect information, including encryption of data in transit and at rest, access controls and authentication, regular security assessments, and incident response procedures.
No system is completely secure. In the event of a data breach, we will notify affected brands within 72 hours and cooperate in any required notifications.
8. Children's Privacy
Mirour is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will delete it promptly. If you believe a child has provided us with personal information, contact us at hello@mirourmirour.com.
9. Third-Party Links and Services
Mirour experiences may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify brands of material changes via email or through the platform. The "Last Updated" date at the top indicates when the policy was last revised.
11. Contact Us
If you have questions about this Privacy Policy, contact us at:
Lutely Inc. (dba Mirour) Email: hello@mirourmirour.com
Mirour is operated by Lutely Inc., a Delaware corporation.