Privacy Policy

Lumina Trips (luminatrips.com) Last updated: 3 August 2026

1. Who we are

Lumina Trips ("we", "us", "our") is an AI-powered travel concierge operated by Lumina Solutions from the country of Georgia. We help travelers discover flights, hotels, eSIMs, insurance, transfers, tours, and other travel services, and we earn commissions when you book through our affiliate partners.

We are the data controller for the personal data described in this policy. For any privacy question, contact us at hello@luminatrips.com.

We do not sell travel services ourselves and we never take your payment for them. Bookings and payments happen on the websites of our partners, who are separate data controllers under their own privacy policies.

2. Scope and applicable law

This policy explains how we handle personal data when you use luminatrips.com and its features (collectively, the "Service").

  • We operate from Georgia and comply with Georgian data-protection law (the Law of Georgia on Personal Data Protection) and the oversight of the Personal Data Protection Service of Georgia.
  • Because we offer our Service to visitors in the European Union / European Economic Area (EU/EEA), we also aim to comply with the EU General Data Protection Regulation (GDPR) where it applies to you.
  • If you are in the United Kingdom, references to the GDPR should be read as also covering the UK GDPR and the Data Protection Act 2018.

If GDPR applies to you, the sections on lawful basis (Section 4), your rights (Section 9), and international transfers (Section 8) are especially relevant.

3. What data we collect

We collect the following categories of personal data:

a) Information you give us directly

  • Chat messages and trip inputs — what you type into the AI concierge: destinations, travel dates, traveler counts, budgets, preferences, and any other details you choose to share. We do not store these; see Section 5 (AI provider) and Section 7 (retention) for exactly where they go and how long they last.
  • Contact details — such as your email address, if you contact us.
  • Communications — messages you send us by email or other channels.

Please do not enter sensitive personal data (for example health information, religious beliefs, or precise passport/ID numbers) into the chat. If you do, you are explicitly providing it to us for the purpose of answering your request.

b) Information we collect automatically

  • Cookies and similar technologies — see Section 6 and our Cookies Policy. Today the only non-essential technology we load is the Travelpayouts attribution script, and only after you accept cookies.
  • Click-out / affiliate events — when you click a link to a partner (for example a flight, eSIM, or tour offer), our server records that a click happened. We keep these records in our database so we can check our partners' commission reports against the clicks we actually sent. Each record contains only: which program the offer belonged to, the partner's website address (domain only), the page language (Georgian or English), the time, and a random per-conversation identifier that is not linked to your identity. We deliberately do not record your IP address, your browser or device, the page you came from, or the full link you clicked — so these records cannot be traced back to you and are not used to build a profile of you.
  • Technical data used transiently — like any website, our server briefly sees your IP address while handling a request and to prevent abuse (rate-limiting). We do not store your IP address and we do not derive your location from it. We do not run our own analytics and do not build device or browsing profiles.

We generally do not receive your payment-card details, full booking details, or passport data — those are handled by the partner you book with.

4. Why we use your data and our lawful basis (GDPR)

PurposeWhat this involvesLawful basis (GDPR Art. 6)
Provide the AI conciergeProcessing your chat messages and trip inputs to generate travel suggestions and answersPerformance of a contract / taking steps at your request (Art. 6(1)(b)); or legitimate interests (Art. 6(1)(f))
Affiliate tracking & commissionsRecording click-out events and affiliate identifiers so partners can attribute bookings to usLegitimate interests in running our business (Art. 6(1)(f)); consent for the non-essential attribution script (Art. 6(1)(a))
Security & fraud preventionProtecting the Service and detecting abuse (e.g. transient IP-based rate-limiting)Legitimate interests (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c))
Communicating with youResponding to enquiries and sending requested messagesContract (Art. 6(1)(b)), consent (Art. 6(1)(a)), or legitimate interests (Art. 6(1)(f))
Legal complianceMeeting tax, accounting, and other legal dutiesLegal obligation (Art. 6(1)(c))

Where we rely on consent (for example non-essential cookies), you can withdraw it at any time without affecting processing already carried out. Where we rely on legitimate interests, you have the right to object (see Section 9).

5. Third parties who process or receive your data

We share personal data with the following categories of recipients. Some act as our processors (handling data on our instructions); others are independent controllers with their own privacy policies.

a) Service providers (processors acting on our behalf)

  • OpenRouter (AI concierge) — when you use the concierge, we send your chat messages and trip inputs to OpenRouter (openrouter.ai), which routes the request to an underlying AI model provider to generate a reply. We configure this routing to deny data collection, which instructs providers not to retain or train on your inputs. We do not store your conversation ourselves — it lives only in your browser for the session and is discarded when you close or reload the page. Please do not enter passwords, passport or ID numbers, payment-card details, or other sensitive personal data into the chat — the concierge never needs them.
  • Cloudflare — hosts the website and routes our contact email. Standard server logs may briefly include technical request data (see Section 3b).
  • Supabase — our database provider. It stores our public catalogue of tours and travel content, and the non-personal click-out records described in Section 3b. It does not store your chat messages, your IP address, or any data that identifies you.

b) Affiliate partners and travel suppliers (independent controllers)

  • Affiliate networks — we use Travelpayouts, Stay22 (accommodation), and direct partner programs (such as SafetyWing) to connect to travel suppliers and to track click-outs and commissions.
  • Affiliate partners and suppliers — for example flight search (e.g. Aviasales), hotels (e.g. Booking, Agoda, Hotels.com, Trip.com, Expedia and others, via Stay22), car rental, eSIM (e.g. Airalo), travel insurance (e.g. SafetyWing), transfers (e.g. Kiwitaxi), and tours (e.g. GetYourGuide, Viator).

When you click through to a partner, you leave our Service and the partner collects and processes your data as an independent controller under its own privacy policy. We are not responsible for those parties' practices; please read their policies before booking.

c) Other disclosures

  • Legal and safety — authorities, regulators, or advisors where required by law or to protect our rights, users, or the public.
  • Business transfers — a successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy.

We do not sell your personal data.

6. Cookies, tracking, and consent

We use a small amount of browser local storage to remember your cookie choice, and — only if you accept — one third-party attribution script (Travelpayouts) that lets our partners credit us for bookings you make. For EU/EEA visitors and where applicable law requires it, we ask for your consent through a cookie banner on which rejecting is as easy as accepting; until you accept, no non-essential script loads. Your choice is a single accept-or-reject that we remember in your browser, and you can change it at any time through the cookie settings link in our footer. Full details are in our Cookies Policy.

7. How long we keep data (retention)

Because we store very little, retention is short:

  • Chat messages and trip inputs — we do not store these. They exist only in your browser during your session and are sent to our AI provider to generate replies (see Section 5); nothing is retained on our side once you close or reload the page.
  • Click-out / affiliate events — the non-personal records described in Section 3b are kept for up to 24 months for commission reconciliation, then deleted. Our affiliate partners keep their own attribution records under their own policies and cookie/attribution windows.
  • Emails you send us — kept only as long as needed to handle your request and keep reasonable records.
  • Account data (if we introduce accounts in future) — for as long as the account is active, then deleted within 90 days of closure.
  • Legal/financial records — kept as long as required by Georgian tax and accounting law.

When data is no longer needed, we delete it or irreversibly anonymize it.

8. International data transfers

We operate from Georgia. When you use the concierge, your chat inputs are sent to OpenRouter and the AI model provider it routes to, which may process them in the United States or other countries. Our hosting provider (Cloudflare) and database provider (Supabase) may also process data in the EU/EEA, the United States, or other countries. This means data may be transferred outside your home country, including outside the EU/EEA.

Where we transfer personal data subject to the GDPR to a country without an EU "adequacy" decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and additional measures where needed. You can request more information about these safeguards using the contact details below.

9. Your rights

Subject to applicable law (GDPR and Georgian data-protection law), you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") in certain circumstances.
  • Restriction of processing in certain circumstances.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Data portability — receive certain data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. The AI concierge produces travel suggestions only and does not make such decisions about you.

To exercise any right, contact hello@luminatrips.com. We may need to verify your identity. We respond within the timeframes required by law (generally within one month under GDPR).

Complaints. If you are in the EU/EEA, you may lodge a complaint with your local data protection supervisory authority. If you are in Georgia, you may contact the Personal Data Protection Service of Georgia. We would appreciate the chance to address your concern first via hello@luminatrips.com.

10. Security

We take reasonable technical and organizational measures to protect personal data, including HTTPS encryption in transit, a strict content-security policy, access controls, and use of reputable infrastructure providers (such as Cloudflare and Supabase). No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach affects you, we will notify you and the relevant authorities where required by law.

11. Children

The Service is not directed to children under the age of 16, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact hello@luminatrips.com and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, for significant changes, provide a more prominent notice (for example, on the site or by email). Please review this page periodically.

13. Contact us

Lumina Solutions Operating Lumina Trips / luminatrips.com Georgia Email: hello@luminatrips.com

If you have questions about this policy or how we handle your data, please reach out — we are happy to help.