Privacy Policy
render360 turns a photo of a car into renders and clips. To do that we hold your account, the photos you upload, what you ask for, what comes back, and how much of your plan you have used. This page says exactly what that means, in plain words.
1. Who we are
render360 is operated by lumingon DWC-LLC, a company licensed in the Dubai South Business Hub Freezone, United Arab Emirates, with its registered office at Business Centre, Floor 3, Building A3, Business Park, Dubai, United Arab Emirates. lumingon DWC-LLC is the controller of the personal data described here. Questions and requests go to support@lumingon.com.
2. What we collect, and why
| Data | Where it comes from | Why we hold it |
|---|---|---|
| Your Google account's email address and name | Google Sign-In, when you sign in | To know which studio you belong to and who made each render. We never see your Google password. |
| Photos you upload | You | They are the input to every render. On arrival each photo is re-encoded, which removes camera and location metadata from the file. |
| The changes you ask for (finish, colour, wheels, scene, text) | You | To write the instruction the model receives, and to show the thread later. |
| Renders and clips | Generated for you | They are your work; the studio keeps them until you delete the session. |
| Studio name, plan, credits and a ledger of what each member spent | Your plan and your use of it | To run billing and seats, and to show the team what was used. |
| Stripe customer and subscription identifiers | Stripe, after Checkout | To connect your studio to its subscription. Card numbers never reach us; Stripe holds them. |
| IP address, browser type, request logs | Your browser | Security: rate limits on sign-in, abuse detection, and diagnosing faults. Logs are kept for 30 days. |
We do not collect anything from your customers beyond what is in the photo you upload. Every render and clip replaces the number plate with a blank one; that is our rule, not a setting, because a render or a share link travels further than the photo did. The uploaded photo itself keeps its plate and stays private to your account. Do not upload a photo that shows a person's face or a document unless you have the right to do so; the render is an edit of that photo.
3. Who processes it for us
We use a small number of providers, each for one job. None of them may use your data for their own purposes beyond what their terms with us allow.
| Provider | What they do with your data | Where |
|---|---|---|
| Google Cloud (Firebase) | Runs the service: hosting, the database, private file storage for photos and renders, and sign-in. | Belgium (europe-west1), European Union |
| Google Gemini API | Generates the renders and clips. Your photo and instruction are sent to the model for each render; under Google's paid API terms they are not used to train Google's models. | Google's global infrastructure |
| Stripe | Takes payment, stores your card, issues invoices and runs the billing portal. Stripe is an independent controller for the payment data it holds; see Stripe's privacy policy. | Stripe's infrastructure |
| Google reCAPTCHA Enterprise | Checks that requests to the studio come from a real browser and not a script. It collects device and browser signals and sets its own cookies, under Google's privacy policy and terms. | Google's global infrastructure |
Some of these providers are outside the United Arab Emirates and the European Union. Where data leaves a jurisdiction we rely on the provider's standard contractual protections.
4. How long we keep it
- Photos, renders and clips: until you delete the session that holds them, or 30 days after your studio closes.
- Account and studio records, including the credit ledger: for as long as the studio exists, then 30 days, except billing records we must keep for accounting, which are kept for the period the law requires.
- Request logs: 30 days.
- Sign-in session: a single cookie that expires after eight hours.
5. Cookies
The studio sets one cookie, __session, which keeps you signed in for eight hours and holds nothing but a signed reference to your email address. reCAPTCHA sets its own cookies to tell browsers from scripts. There is no advertising or cross-site tracking on render360.
6. Your choices and rights
- See or delete your work: every session, with its photos, renders and clips, can be deleted from the studio at any time.
- Leave a studio: ask its owner to remove you; your sign-in then no longer opens it.
- Close a studio: cancel the plan from the billing page. The studio's data is deleted 30 days after the plan ends.
- Access, correction, deletion, objection, portability: write to support@lumingon.com from the email address on the account. We answer within 30 days.
7. Security
Photos and renders live in a private bucket that has no public address; they are served only to a signed-in member of the studio that made them. Every request that changes something must come from the studio's own page, verified by a signed token. Uploads are re-encoded before anything else touches them. Staff at lumingon can open a studio to support you; that access is logged.
8. Children
render360 is a business tool for wrap and tuning studios and is not directed at anyone under 18.
9. Changes
When this policy changes we update the date at the top and, for changes that matter, tell studio owners by email before they take effect.