Effective as of June 18, 2026
Section 1 — Scope, Purpose & Your Agreement
Luma Field Inc and its affiliates ("Luma," "we," "our," or "us") are committed to transparent data handling practices. This Privacy Policy describes the categories of information we may collect, the purposes for which such information is used, the circumstances under which it may be disclosed to third parties, the duration for which it may be retained, and the rights you may exercise depending on your jurisdiction of residence.
The Services covered by this Privacy Policy include our websites, mobile applications, interactive games, account systems, player profiles, promotional features, and any related functions or support services we may provide (together, the "Services").
This Privacy Policy forms part of and must be read in conjunction with our Terms of Service, Sweepstakes Rules, Responsible Gaming Policy, and Game Statement (collectively, the "Platform Rules"). By visiting, registering for, accessing, or using the Services in any capacity, you acknowledge that your interaction with the Services is governed by this Privacy Policy and the Platform Rules. If you do not agree to the data practices described herein, you should discontinue use of the Services.
Section 2 — Age Restriction & Underage Data
The Services are designed solely for adults who are 21 years of age or older. We do not knowingly solicit, collect, or process personal information from anyone under the age of 21. In the event we become aware that data belonging to a person below this age threshold has been submitted to or collected through the Services — whether intentionally or inadvertently — we will take reasonable steps to identify and remove such data without undue delay.
Section 3 — Categories of Information Collected
The scope of information we handle varies depending on how you interact with the Services. Data may reach us through direct submission, through platform-generated records associated with your activity, or through automated technical collection mechanisms.
3.1 Information you provide directly
Throughout your use of the Services — including during registration, communication with our team, purchases, gameplay sessions, reward redemptions, support interactions, or promotional participation — you may submit information such as:
• your name; • email address; • phone number; • mailing or residential address; • date of birth; • gender; • nationality, where needed; • account login details; • other information you choose to submit.
3.2 Account and profile data
As your relationship with the Services develops, we maintain records associated with your account activity and participation history:
• account ID or username; • password or security credentials; • account status and verification status; • gameplay records and participation history; • VIP tier or similar status indicators; • redemption and purchase records.
3.3 Technical, device, and usage data
Certain technical information is collected automatically each time you access the Services, regardless of whether you take any affirmative action:
• IP address; • device identifiers; • advertising identifiers; • SIM region; • browser type; • operating system; • device settings; • time zone; • application or browser configuration; • usage logs and interaction data.
Collection of such data may occur through cookies, SDKs, analytics tools, and similar technologies embedded within the Services.
3.4 Preference information
We may record and store your settings and preferences — including your choices regarding the receipt of marketing messages, promotional notices, or other communications — to ensure that your experience with the Services reflects your stated preferences.
Section 4 — Sensitive Information: When & Why It May Be Collected
Certain interactions with the Services may require the collection of information that is more sensitive in nature. This occurs only in limited circumstances tied to fraud control, account security, user support, or identity confirmation. The categories of sensitive data that may be requested include:
• photographs or selfies; • brief video clips; • audio recordings, including support-related recordings.
The collection of such information is undertaken only when reasonably necessary for security, verification, or compliance objectives. Where identity verification involves biometric-enabled comparison (such as matching a selfie against an identity document), this processing is performed exclusively by authorized third-party verification providers operating under contractual data protection obligations. Luma does not create, keep, or store biometric identifiers or biometric templates.
Sensitive information collected in this context serves strictly defined purposes:
• identity validation; • fraud prevention; • security review; • legal and regulatory compliance.
No sensitive information collected under this section is used for marketing, profiling for advertising purposes, or any purpose unrelated to the security and compliance objectives stated above.
Section 5 — How & Why We Use Personal Information
Personal information may be used for business, operational, security, and legal reasons. The specific purposes for which we process information include:
• providing the Services and maintaining their functionality and availability; • creating, administering, and managing user accounts; • processing transactions, purchases, and prize or reward redemptions; • sending service-related notifications and, where permitted by applicable law, marketing communications; • detecting, preventing, investigating, and responding to fraud, abuse, suspicious behavior, or unauthorized activity; • enforcing our contracts, policies, and platform rules; • complying with applicable laws, regulations, legal process, and internal compliance obligations; • improving and optimizing the performance, security, and user experience of the Services.
Where applicable law requires that we identify a legal basis before processing personal information, we may rely on one or more of the following justifications:
• your consent; • performance of a contract to which you are a party; • our legitimate interests (provided they are not overridden by your rights); • compliance with a legal obligation to which we are subject.
Section 6 — Identity Verification & KYC Procedures
Legal, regulatory, and fraud-prevention frameworks may require us to verify the identity of users before or during their use of certain features of the Services. These procedures are commonly referred to as KYC (Know Your Customer) reviews.
6.1 What information may be requested
When verification is triggered, the following categories of data may be collected or processed:
• your full legal name; • date of birth; • nationality; • government-issued identification details; • copies or images of passports, driver's licenses, or national ID cards; • selfie images for facial comparison; • proof of address documentation; • account identifiers; • photo, video, or audio materials generated during live verification sessions, if applicable.
6.2 What verification achieves
Verification information serves to:
• confirm the identity of the account holder; • confirm age eligibility for participation in the Services; • prevent fraud, identity theft, and misuse of the Services; • support anti-money-laundering or other regulatory compliance measures; • satisfy obligations under applicable jurisdictional requirements.
6.3 Third-party verification partners
We engage specialized service providers to conduct identity reviews on our behalf. These may include providers such as Sumsub or comparable vendors with demonstrated expertise in identity verification and compliance technology. Such providers may collect and analyze verification data as part of their services and are bound by contractual obligations to safeguard the information they receive and to use it only for approved compliance and verification functions.
6.4 How long verification records are kept
KYC-related information is retained only for as long as reasonably needed for the verification, compliance, and security purposes described above, or as otherwise required by law. Where appropriate and where full document retention is not legally mandated, we may retain only the outcome or status of the review rather than storing full document copies indefinitely.
We do not sell, rent, trade, or otherwise commercialize biometric data under any circumstances. Any biometric-enabled verification performed through this process is used solely to complete the identity check and to satisfy applicable legal requirements — and for no other purpose.
Section 7 — Geographic Restrictions & Location Data
Access to the Services is subject to geographic limitations imposed by applicable law. To determine whether a user is accessing the Services from a jurisdiction where access is permitted, we may assess your approximate or actual location using technical signals including IP address, device data, GPS data, network information, or similar indicators.
7.1 Jurisdictions where access is currently prohibited
At present, access to the Services is not available in the following U.S. jurisdictions:
• Alabama • California • Connecticut • District of Columbia • Idaho • Louisiana • Michigan • Montana • Nevada • New Jersey • New York • Washington State
This list is subject to change as regulatory conditions evolve. It is your responsibility to ensure that your use of the Services remains lawful in the jurisdiction where you are physically located at the time of access.
7.2 Anti-circumvention measures
To preserve platform integrity and satisfy jurisdictional compliance requirements, we actively monitor for attempts to conceal or manipulate a user's true geographic location or technical environment. Prohibited methods of circumvention include, without limitation:
• VPN services; • proxy services; • location spoofing tools; • remote desktop or remote access tools; • emulators; • virtual machines; • other techniques intended to bypass geographic or technical restrictions.
Where location cannot be confirmed to our satisfaction, or where evidence suggests that circumvention tools or techniques are in use, we may restrict access, suspend account activity, deny certain features, revoke eligibility for redemptions or prizes, or take such other action as we deem appropriate in the circumstances.
Device and location data collected for anti-circumvention and compliance purposes is handled in accordance with this Privacy Policy and retained only as long as reasonably necessary for legal, security, operational, or compliance needs.
Section 8 — Disclosure of Information to Third Parties
We do not sell your personal information for monetary consideration. Disclosure of personal information to third parties occurs only in the limited circumstances described below, where sharing is necessary for the operation of the Services, legal compliance, or protection of the platform and its users.
8.1 Service providers and data processors
Certain third parties assist us in operating and maintaining the Services. These may include:
• payment processors; • hosting and cloud infrastructure providers; • analytics vendors; • advertising and attribution partners; • customer support vendors; • fraud detection and risk management providers; • identity verification providers.
Each third-party service provider is bound by contractual obligations to use personal information only as needed to perform services on our behalf and to maintain appropriate data protection safeguards consistent with this Privacy Policy and applicable law.
8.2 Corporate transactions and reorganizations
In the event of a merger, acquisition, investment, financing transaction, reorganization, bankruptcy proceeding, or sale of all or part of our business or assets, your information may be disclosed to prospective counterparties, transferred to successor entities, or included among the assets evaluated or conveyed as part of such transaction.
8.3 Legal obligations and protective disclosures
Disclosure may occur when we reasonably believe it is necessary to:
• comply with applicable law, regulation, or binding governmental directive; • respond to court orders, subpoenas, warrants, or government inquiries; • enforce our policies, terms, and agreements; • investigate misconduct, fraud, abuse, or potential violations; • protect the rights, property, safety, or legitimate interests of the Company, our users, or the public.
Section 9 — Advertising, Analytics & Measurement Technologies
We and our advertising and analytics partners utilize cookies, SDKs, pixels, and similar technologies to understand how users interact with the Services, improve product performance, measure the effectiveness of marketing campaigns, attribute installs or conversions, detect suspicious activity patterns, and support advertising delivery and optimization efforts.
Partners engaged in analytics, attribution, and advertising measurement may include:
• Google Analytics; • Firebase; • AppsFlyer; • similar advertising or measurement partners.
These third-party partners may collect or process data in accordance with their own privacy terms and policies, which are separate from this Privacy Policy. We encourage users to review the data practices of any third-party service they interact with.
Although we do not sell personal information for monetary compensation, certain data disclosures made for advertising, attribution, or measurement purposes may be classified as "sharing" under privacy legislation in some jurisdictions. Where such classification applies, affected users may possess rights to opt out of such sharing, as described in Section 11 below.
You may be able to manage certain cookie or tracking preferences through your browser settings, device operating system controls, or in-app privacy settings where available.
Section 10 — Data Security Practices
We maintain reasonable physical, technical, and administrative safeguards designed to protect personal information from unauthorized access, misuse, accidental loss, alteration, or improper disclosure. The security measures we employ may include encryption protocols, secure infrastructure architecture, access controls based on the principle of least privilege, regular security assessments, and vendor oversight programs.
Payment card transactions are processed by qualified third-party payment providers who maintain appropriate certifications and security standards. We do not retain full credit card numbers, CVV codes, or complete payment card details on our own systems.
Despite these protections, no method of electronic transmission or data storage can be guaranteed to be completely secure against all threats. Users are encouraged to protect their own account security by choosing strong, unique passwords, safeguarding their login credentials from unauthorized access, enabling available security features, and exercising appropriate caution when accessing online services over public or shared networks.
Section 11 — California Privacy Disclosures (CCPA/CPRA)
This section provides supplemental disclosures required under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and applies exclusively to individuals who are residents of the State of California.
11.1 Categories of personal information collected
With respect to California residents, we may collect the following categories of personal information:
• identifiers, such as IP address, email address, device ID, and online identifiers; • geolocation information, including approximate location inferred from IP address or device signals.
11.2 Sources from which information is collected
Personal information may be obtained:
• directly from you through your interactions with the Services; • automatically through cookies, SDKs, and similar technologies; • from analytics, attribution, or advertising partners.
11.3 Business purposes for use and disclosure
We use and disclose the information collected from California residents to operate and maintain the Services, improve functionality, measure engagement and usage patterns, understand campaign effectiveness, and deliver relevant advertising content.
Certain disclosures to analytics or advertising partners — including platforms such as Google Analytics, Meta, or Google Ads — may constitute "sharing" for cross-context behavioral advertising as that term is defined under California law.
11.4 Your rights as a California resident
Subject to applicable limitations, verification requirements, and statutory exceptions, California residents may have the right to:
• know what categories and specific pieces of personal information we have collected about them, and how such information has been used or disclosed; • request deletion of personal information we hold about them; • request correction of inaccurate personal information; • opt out of sharing of personal information for cross-context behavioral advertising; • receive equal service and pricing regardless of whether they exercise privacy rights.
11.5 How to submit privacy requests
Requests to know, delete, or correct personal information may be directed to [email protected]. We will verify the identity of the requestor using information reasonably related to the account or device associated with the request. Responses will be provided within the timeframe required by applicable law.
Authorized agents may submit requests on behalf of a California resident. In such cases, we may require written authorization from the resident and may independently verify the resident's identity before processing the request.
11.6 Opt-out of sharing
At this time, the Services do not include a separate "Do Not Sell or Share My Personal Information" link within the platform interface. California residents who wish to exercise their right to opt out of sharing for cross-context behavioral advertising may contact us at the email address provided above to submit their request.
Section 12 — Data Retention & Deletion
Personal information is retained only for as long as it is reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law, regulation, or contractual obligation.
12.1 Requesting deletion
You may request deletion of your account or personal information by contacting us at [email protected]. Before processing any deletion request, we may need to verify your identity through reasonable means, which may include confirming your registered email address, answering security questions, or providing other account-related details sufficient to authenticate the request.
12.2 Processing of approved deletion requests
Where a valid deletion request is received and approved following identity verification, we will take reasonable steps to delete or deactivate the relevant account and associated personal information from our active systems. However, certain records may be preserved beyond deletion where retention is necessary for one or more of the following purposes:
• compliance with legal or regulatory obligations; • fraud prevention and detection; • security monitoring and incident investigation; • dispute resolution and defense of legal claims; • audit, recordkeeping, or reporting requirements; • enforcement of this Privacy Policy or the Platform Rules.
Any information retained after deletion for the purposes described above will be maintained only for as long as such purpose requires and will be protected by the same safeguards described in Section 10.
Section 13 — Third-Party Sites, Links & External Services
The Services may contain links, references, redirects, or integrations to external websites, tools, applications, or platforms operated by third parties. These external services are not owned, controlled, or operated by Luma, and their data collection, use, and disclosure practices are governed exclusively by their own terms of service and privacy notices.
We encourage you to review the privacy policies and terms of any external service before providing personal information through that service. Luma is not responsible for the content, data practices, security measures, or policies of any third-party site or service, and the inclusion of a link or reference within the Services does not imply endorsement or affiliation.
Section 14 — Feedback, Suggestions & Unsolicited Materials
Unless required otherwise by applicable law or by a separately executed confidentiality agreement between you and the Company, any ideas, comments, feedback, suggestions, concepts, proposals, or similar materials you voluntarily submit to us — whether through the Services, email, or any other channel — may be used by the Company without restriction, attribution, or any obligation to compensate you. By submitting such materials, you acknowledge that the Company may freely use, reproduce, modify, distribute, and incorporate your submission into its products, services, or operations.
Section 15 — How to Contact Us
If you have questions about this Privacy Policy, would like to submit a privacy-related request, wish to exercise any rights available to you under applicable data protection law, or want to contact us regarding any data protection matter, you may reach us at: [email protected]
We aim to acknowledge receipt of all inquiries promptly and to provide substantive responses within the timeframes required by applicable law.