Lula Privacy Policy

Last Updated: May 19, 2026  |  Effective Date: May 19, 2026

Lula, Inc. ("Lula," "we," "us," or "our") respects your privacy and is committed to protecting it through compliance with this policy. This Privacy Policy describes our practices regarding the collection, use, and disclosure of information in connection with your use of the Lula platform — including our web-based dashboard, mobile applications, APIs, and all associated products and services (collectively, the "Service").

Lula operates primarily as a B2B SaaS platform providing digital commerce solutions to retail operators ("Operators" or "Merchants"). Through those Operators, Lula also facilitates commerce transactions with end consumers ("End Customers") via products such as Lula Direct. This Privacy Policy addresses data practices across both contexts.

Please review our Terms of Service at www.lulacommerce.com/company/terms-conditions before using the Service. By using the Service, you consent to data practices described in this Privacy Policy.

1. DEFINITIONS

"Personally Identifiable Information" (PII) means information that can be used to identify an individual, including name, address, email address, telephone number, and demographic data, voluntarily provided to or collected by Lula through use of the Service.

"Merchant Data" means all data submitted by or generated on behalf of an Operator in connection with use of the Service, including store configurations, product catalogs, transaction data, and operational metrics.

"End Customer Data" means information about consumers who interact with Operator storefronts or customer-facing features of the Service, such as Lula Direct.

2. DATA WE COLLECT

We may collect, store, and process information about Operators and End Customers in connection with the Service. This data is used to operate, maintain, and improve the Service; fulfill requests; provide customer support; conduct analytics; and comply with legal obligations. All data is transmitted to US-based servers.

a. Account Information. When you create an Operator Account, we collect information such as your full name, business name, email address, phone number, business address, and any additional information you provide during setup or through account settings.

b.  Location Data. We may collect geolocation data associated with store locations to enable Services such as Marketplace Platform integration, delivery radius configuration, and location-based analytics. We do not use precise device-level location data for purposes other than providing the Service.

c.  Third-Party Service Information. We may receive or share data with third parties that provide services to you, us, or that interact with the Service:

  1. Payment Processing (Finix): We do not store credit card information. Card transactions through Lula Direct are processed by Finix, Inc. Data shared with Finix is governed by the Finix Privacy Policy.
  2. Tax Processing (Numeral): Tax calculation and remittance services are provided by Numeral. Transaction data necessary for tax compliance is shared with Numeral in accordance with their privacy practices.
  3. Authentication: If you use Google or other supported single sign-on providers to create or access your account, we may receive basic profile information (name, email) from those providers, used solely to authenticate you.

d.  POS and Transaction Data. When Operators connect point-of-sale systems (including NCR Voyix, Verifone Commander, and compatible systems) through Lula integrations, we collect inventory data, transaction records, and operational metrics necessary to provide the Service. This data is used to power Lula Analytics, financial reconciliation, and marketplace menu management.

e.  Marketplace Integration Data. When Operators use Lula Channels, we collect and process data from connected Marketplace Platforms (including Uber Eats, DoorDash, and Grubhub), including order data, payout records, performance metrics, and payout reference IDs, to provide marketplace aggregation, financial reconciliation, and reporting services.

f.  AI Voice Interaction Data. When Operators use Lula AI Voice, we may collect call recordings, transcripts, and interaction metadata. This data is used to power AI Voice responses, improve accuracy, and provide interaction analytics to the Operator. Operators are responsible for providing appropriate call-recording disclosures to End Customers as required by applicable law.

g.  Operational and Uptime Data. We collect system performance data, hardware monitoring signals, and order error logs to provide Operational Uptime and anomaly detection services. This data is used solely to support service reliability and is not shared with third parties except as required to deliver the Service.

h.  Google Business Profile Data (Signal). When Operators use Signal, we access and manage Google Business Profile listing data, including business information, reviews, and listing metrics, on behalf of the Operator. This access is governed by the Operator's Google account permissions and Google's Privacy Policy.

i.  End Customer Data. End Customer data collected through Lula Direct or Lula Virtual Kiosks — including names, contact information, order history, and payment information — is collected and processed by Lula on behalf of the Operator. The Operator is the data controller for End Customer data in this context; Lula acts as a data processor. End Customer data is not sold or shared with third parties except as required to fulfill orders or comply with law.

j.  Usage and Analytics Data. We use analytics tools including Google Analytics to collect aggregate, non-personally-identifiable data about Service usage. You can opt out of Google Analytics data collection at https://tools.google.com/dlpage/gaoptout.

3. HOW DATA IS USED

a.  To Operate, Maintain, and Improve the Service. We use Merchant Data and usage data to perform and enhance the Service, develop new features, support internal research, and improve AI models using anonymized and aggregated data.

b.  To Communicate With You. We may use your contact information to send Service-related communications, product updates, billing notices, and, with consent, marketing messages. You may opt out of:

  • Push notifications: adjust your device or browser settings
  • Emails: click the unsubscribe link in the footer of our messages
  • SMS: reply STOP to any text message from Lula

c.  Business Services and Analytics. We may provide Operators with analytics derived from their Merchant Data, marketplace data, and aggregate industry benchmarks. We may share aggregated, de-identified, non-personally-identifiable data with analytics partners, including NielsenIQ/NIQ, pursuant to data collaboration agreements. No personally identifiable Operator or End Customer information is shared with such partners.

d.  AI Model Improvement. We may use anonymized interaction data from AI Features to train, test, and improve AI models. Personally identifiable data is not used for model training without explicit consent.

4. HOW DATA IS SHARED

We do not sell PII to third parties. We do not rent or share Operator or End Customer data without consent, except as described in this Privacy Policy.

a.  Marketplace Platforms. To enable Lula Channels integrations, we share necessary Operator data (such as menu items, store hours, and pricing) with Marketplace Platforms (Uber Eats, DoorDash, Grubhub) on behalf of the Operator. This sharing is required for the integration to function and is authorized by the Operator.

b.  Technology and Service Providers. We may share data with third-party service providers acting on our behalf to enable the Service (e.g., cloud hosting, email delivery, payment processing, tax processing, POS integrations). Such providers are contractually bound to keep data confidential and may only use it to provide services to Lula.

c.  Analytics Partners. We may share aggregated, de-identified data — from which all individual identifiers have been removed — with analytics partners including NielsenIQ/NIQ for industry benchmarking and research purposes. No PII is shared in this context.

d.  Legal and Safety Disclosures. We may share data when we believe in good faith it is necessary to: (i) comply with applicable law or legal process; (ii) protect the rights, property, or safety of Lula, its users, or the public; or (iii) detect and prevent fraud or security incidents.

e.  Business Transactions. In connection with a merger, acquisition, asset sale, or similar corporate transaction, data may be transferred as a business asset. We will notify affected users of any material change in data control following such a transaction.

5. DATA RETENTION AND ACCOUNT TERMINATION

When an Operator Account is closed, we will remove or anonymize associated PII, except as we may retain data: (i) to comply with legal or regulatory obligations; (ii) to resolve disputes or enforce our agreements; or (iii) in de-identified or aggregated form for research and analytics. Merchant transaction data and order history may be retained for a period consistent with applicable record-keeping requirements. End Customer data is retained in accordance with the Operator's data retention obligations.

To close your Operator Account, contact us at legal@lulacommerce.com.

6.  Data Security

We implement commercially reasonable technical and organizational measures to protect data against unauthorized access, disclosure, alteration, or destruction. However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, and you submit data at your own risk.

7.  Do Not Track Signals

We do not currently respond to browser "Do Not Track" signals. We will update this section if our practices change.

8.  Children

The Service is intended for business use by adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at legal@lulacommerce.com. We will take prompt steps to remove such information.

9.  Your Rights and Choices

Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the processing of your personal information. To exercise any of these rights, contact us at legal@lulacommerce.com. We will respond to requests within the timeframe required by applicable law. Note that certain data may be exempt from deletion requests where retention is required by law or for legitimate business purposes.

10.  Contact

For questions or concerns about this Privacy Policy, contact us at:

Email: legal@lulacommerce.com

Address: 18 Hancock Court, Voorhees, NJ 08043

11.  Changes to This Privacy Policy

We may amend this Privacy Policy from time to time. Material changes will be communicated by posting an announcement on our platform or by emailing you, and the "Last Updated" date at the top will be revised. Continued use of the Service after changes are posted constitutes acceptance of the updated Policy. Current version always available at: www.lulacommerce.com/company/privacy-policy.