Privacy notice
Privacy Policy
Effective and last updated September 14, 2026
This Policy explains LUXEO Reserve’s own data practices and its role as a service provider to participating businesses. A participating business may provide an additional notice governing information it controls.
1. Scope and roles
LuxWell Solutions LLC, doing business as LUXEO Reserve (“LUXEO,” “we,” “us” or “our”), provides websites, booking, customer-care, communications, payment-support and business-operations technology. This Policy applies when we determine why and how personal information is processed, including our website, sales, support, account administration and direct communications.
When we process guest, patient, employee or business records only on instructions from a participating business (“Business”), that Business is generally the controller or responsible business and LUXEO is its processor or service provider. Direct requests about those records to the Business first. We assist as required by contract and law.
LUXEOgroup inquiries and Revenue Opportunity Scan
This notice also covers LUXEOgroup business inquiries and the free Revenue Opportunity Scan. We save your submitted business details, contact information, answers, preliminary score, referral and campaign information, and email preference for team review and follow-up. The immediate score uses your answers; it does not access your private advertising or analytics accounts. Optional email recommendations are separate from submitting the scan. Public pages use Vercel Web Analytics to measure aggregate visits and completed submissions; form answers and contact details are not included in those analytics events.
2. Information we collect
- Identifiers: name, email, telephone, postal or billing address, account and device identifiers.
- Account and workforce data: credentials, roles, permissions, employer affiliation, profile, authentication events and support history.
- Commercial data: appointments, services, products, prices, deposits, refunds, memberships, gift cards, loyalty, receipts and transaction status. Payment providers may process full card or bank credentials; LUXEO generally receives tokens and transaction records.
- Communications: email, SMS, enabled calls or transcripts, consent records, opt-outs, surveys and support interactions.
- Device and usage data: IP address, browser, operating system, timestamps, referring pages, feature activity, diagnostics, security events and cookie data.
- Service and sensitive data: preferences, intake responses, accessibility needs, signed forms and, only in approved configurations, health-related or protected health information needed by a Business.
- Inferences and AI data: recommendations, classifications, risk or demand signals, summaries and other permitted inferences.
- Other information you provide or we receive lawfully from a Business, integration, payment or communications provider, or public source.
3. Sources and uses
We collect information from you; Businesses and authorized users; devices and Services; enabled integrations; and providers supporting payments, identity, fraud prevention, communications, hosting, analytics and support.
We use it to provide and administer Services; create and secure accounts; manage appointments; process and reconcile authorized transactions; deliver receipts, reminders, waitlist notices and support; personalize configured experiences; operate memberships, loyalty and reporting; migrate authorized records; prevent fraud and abuse; troubleshoot and improve performance; comply with law; enforce agreements; protect people, rights and property; and establish or defend claims.
Where permitted, we market LUXEO or enable a Business’s communications under its instructions and your preferences. We may use aggregated or deidentified information for analytics, benchmarking, security, product improvement and research and will not attempt reidentification except to test deidentification or as law permits.
4. AI and automated processing
We may use AI and automation for scheduling, service matching, migration mapping, communications assistance, forecasting, pricing suggestions, fraud detection, support and operational insights. Purpose and access controls are designed to minimize information supplied. Standard AI features are not intended to make solely automated decisions producing legal or similarly significant effects about consumers. A Business is responsible for human review and use of output. Do not submit sensitive information to an AI field unless the interface expressly authorizes it.
5. Disclosures
We may disclose information to the Business you interact with and its authorized personnel; vendors and subprocessors for hosting, databases, security, communications, support, analytics and AI; payment processors, financial institutions and card networks; integrations selected by you or a Business; professional advisers, auditors and insurers; authorities or others for legal process, safety, fraud prevention or rights protection; and parties to a merger, financing, reorganization or sale, subject to safeguards.
We do not sell personal information for money. We do not sell or share mobile numbers, SMS consent or messaging-originator data with third parties or affiliates for their own marketing. We do not use or disclose sensitive personal information to infer characteristics except to provide requested services or as law permits.
We do not currently use personal information for cross-context behavioral advertising. If that changes, we will update this notice and provide legally required choices, including recognition of applicable opt-out preference signals.
6. Cookies and analytics
We and approved providers may use cookies, local storage, pixels and similar technologies for authentication, security, preferences, performance and analytics. Browser controls can limit them, but essential features may fail. Because no universally accepted “Do Not Track” response exists, we do not respond to that signal. Where legally required and technically supported, we honor recognized opt-out preference signals such as Global Privacy Control for covered processing.
7. SMS, email and calls
Operational messages may concern appointments, payments, accounts, security, waitlists and support. Marketing is sent only with required permission. Frequency varies; message and data rates may apply. Reply STOP to opt out of SMS or HELP for assistance. Use email unsubscribe links. We retain consent and suppression records to honor choices and demonstrate compliance. Do not send payment credentials, passwords, authentication codes or detailed medical information through ordinary SMS or email.
8. Health information
Health information is not protected by HIPAA in every context. Where LUXEO processes protected health information as a Business Associate, the applicable BAA and HIPAA requirements govern and control over inconsistent language here. Clinical features must be separately enabled. Standard marketing and analytics systems are not intended to receive protected health information. Direct medical-record questions to the applicable healthcare provider.
9. Security and retention
We use administrative, technical and organizational safeguards designed for the information, which may include tenant separation, role-based access, authentication, encryption, logging, monitoring, vendor review and incident procedures. No system is guaranteed secure. Use unique credentials, protect devices and promptly report suspected misuse.
We retain information as reasonably necessary for Business instructions, account and service delivery, transaction and tax records, fraud prevention, backups, consent and suppression records, legal holds and disputes. Periods vary by data type and contract or law. We delete or deidentify information when no longer reasonably needed, subject to backup cycles and lawful exceptions.
10. Your rights and choices
Depending on where you live and applicable thresholds and exemptions, you may have rights to know or access; correct; delete; obtain a portable copy; opt out of sale, targeted advertising or certain profiling; limit certain sensitive-data uses; withdraw consent; and appeal a denial. We will not discriminate for exercising a right.
For Business-controlled records, contact the Business first. For LUXEO-controlled information, email hello@luxeoreserve.app with subject “Privacy Request.” We may verify identity and authority and limit requests where law permits. Authorized agents must show authority. Appeal a denial by replying “Privacy Appeal.” You may also complain to your state attorney general or data-protection authority.
11. Children
The Services are not directed to children under 13, and we do not knowingly collect their information through our own website. A Business serving a minor is responsible for required parent or guardian authorization and an appropriate workflow. Contact us if you believe a child supplied information without required permission.
12. Processing locations
LUXEO is based in the United States. Information may be processed in the United States and other locations where approved providers operate. Where required for an international transfer, an appropriate transfer mechanism will be used. Services are not offered where their use would violate law.
13. Changes and contact
We may update this Policy as services and laws change. We will post the updated version and effective date and give additional notice where required. Material changes apply prospectively unless law permits otherwise.
Contact LuxWell Solutions LLC, doing business as LUXEO Reserve, at hello@luxeoreserve.app or +1 (843) 212-1310. Review the EULA and Terms of Use.