Privacy Policy
Last updated: 20 May 2026
This Privacy Policy explains how Plumely ("we", "us", "our") collects, uses, stores and shares your personal information when you use our website at plumely.aiand our AI image generation service (the "Service").
We are based in South Africa and this policy is governed by the Protection of Personal Information Act, 2013 (POPIA).
1. Who we are
Plumely is an AI image generation service that helps customers of lighting shops visualise how a light fitting will look in their own room. Customers typically access the Service by scanning a QR code in-store, uploading a photo of the room and the chosen light, and receiving an AI-generated preview image.
For any privacy-related questions, contact us at team@plumely.ai.
2. What information we collect
Information you provide directly:
- Photographs you upload (photos of your room and the light fitting)
- Optional text notes you add to describe your preferences
- Your email address, if you choose to have a generated design emailed to you
Information collected automatically:
- Your IP address (used for rate limiting and fraud prevention)
- Basic device and browser information
- Anonymous session identifiers
- Cloudflare bot-protection signals
Information we do NOT collect:
- We do not ask for your name, address, ID number, or payment details
- We do not knowingly collect special personal information
- We do not use third-party advertising trackers or cookies
3. Why we collect it
- To provide the Service — generating the preview image you requested
- To deliver designs by email — only when you specifically request this
- To protect the Service — rate limiting, bot detection, abuse prevention
- To improve the Service — analysing aggregate usage patterns
- To comply with legal obligations — when required by South African law
4. Legal basis (POPIA)
- Your consent — given when you upload photos and use the Service
- Performance of a contract — to deliver the Service you requested
- Our legitimate interests — security, fraud prevention, and Service improvement
5. How long we keep your information
- Uploaded photos and generated images: stored indefinitely. You may request deletion at any time
- Email addresses: stored indefinitely if you opted to receive a design by email
- IP addresses: retained for up to 30 days
- Server logs: retained for up to 90 days
6. Who we share it with
We share your information only with the following service providers: Supabase (database and file storage), Vercel (hosting), Google Gemini (AI image generation), Cloudflare (bot protection), Trigger.dev (background jobs), Resend (email delivery), and Upstash (rate-limiting). Some providers process data outside South Africa under data-protection commitments equivalent to POPIA.
We do not sell your personal information to anyone, ever.
7. International transfers
Your information may be transferred to and stored in countries outside South Africa, including the USA and EU. We only use providers who maintain adequate data-protection standards.
8. Security
We take reasonable technical and organisational steps to protect your information:
- Encryption in transit (HTTPS / TLS)
- Server-side rate limiting
- Bot protection via Cloudflare Turnstile
- File type verification on all uploads
- Access controls and authentication
- Regular security review of our codebase
9. Your rights under POPIA
- Right of access — to know what information we hold about you
- Right to correction — to ask us to correct inaccurate information
- Right to deletion — to ask us to delete your information
- Right to object — to object to certain types of processing
- Right to withdraw consent — at any time, where we rely on consent
- Right to complain — to the Information Regulator
To exercise any of these rights, email team@plumely.ai. We will respond within 30 days.
Information Regulator (South Africa):
Website: inforegulator.org.za
10. Children and minors
Our Service is available to users under the age of 18. If you are under 18, you must have permission from a parent or legal guardian to use the Service. A parent or guardian may contact us at any time to request deletion of information relating to a minor.
11. Cookies and tracking
We use only essential cookies: authentication cookies (to keep you signed in) and Cloudflare Turnstile cookies (for bot protection). We do not use advertising cookies, analytics trackers, or third-party tracking pixels.
12. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will be revised, and material changes will be communicated more prominently.
13. Contact us
Plumely
Email: team@plumely.ai
Website: https://plumely.ai