Last updated: June 2026

Legal

Privacy Policy

We believe privacy is a right, not a feature. Here's exactly how we handle your data — clearly, without legal jargon.

1. Identity of the Data Controller

The Lustra platform ("Lustra", "we", "us") is operated by:

Lustra Platform Email: [email protected]

As the operator of this platform, Lustra Platform acts as the data controller within the meaning of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.

2. Who This Policy Applies To

Lustra has two types of people who interact with the Platform:

(A) CLIENTS — individuals who visit the Platform to search for and book local services. Clients do not create an account. They provide only the minimum information necessary to complete a booking (name, address, email address).

(B) SERVICE PROVIDERS (BUSINESSES) — independent professionals or businesses who register an account on the Platform to offer local services. Service Providers undergo identity and tax verification and are subject to additional data processing obligations including DAC7 reporting.

This Privacy Policy addresses both groups separately where their situations differ.

By using the Platform in any capacity, you acknowledge that you have read and understood this Privacy Policy.

3. Data We Collect and Why

3.1 DATA COLLECTED FROM CLIENTS (no account required)

Clients do not create an account. We collect only what is strictly necessary to facilitate a booking:

Full name Purpose: Shared with the Service Provider to perform the service Legal Basis: Contract (Art. 6(1)(b))

Service address Purpose: Shared with the Service Provider to attend the booking location Legal Basis: Contract (Art. 6(1)(b))

Email address Purpose: Send booking confirmation, cancellation link, and service updates Legal Basis: Contract (Art. 6(1)(b))

Booking details (date, time, service, price) Purpose: Record of the transaction for both parties Legal Basis: Contract / Legitimate interest

IP address / cookies Purpose: Platform security, basic analytics (see section 9) Legal Basis: Legitimate interest / Consent

We do not collect payment data from Clients. Payment is processed entirely by Stripe (see section 7).

We do not build a profile on Clients. We do not store Client personal data beyond the period necessary to complete the booking and fulfil our legal obligations (see section 5).

3.2 DATA COLLECTED FROM SERVICE PROVIDERS (registered accounts)

Service Providers create an account and are subject to more extensive data collection, partly because of legal obligations (DAC7, VAT) and partly because of the ongoing nature of the business relationship.

Full name / business name Purpose: Account identity, public profile Legal Basis: Contract (Art. 6(1)(b))

Email address Purpose: Account management, communications Legal Basis: Contract (Art. 6(1)(b))

Phone number Purpose: Booking coordination Legal Basis: Contract (Art. 6(1)(b))

Business address Purpose: Public profile, BCE verification Legal Basis: Contract / Legal obligation

Tax Identification Number (TIN) Purpose: DAC7 reporting to FPS Finance Legal Basis: Legal obligation (Art. 6(1)(c))

VAT number (if applicable) Purpose: VAT compliance, invoicing Legal Basis: Legal obligation (Art. 6(1)(c))

BCE/KBO number Purpose: Identity verification Legal Basis: Legal obligation (Art. 6(1)(c))

Service descriptions, pricing, availability Purpose: Public listing on Platform Legal Basis: Contract (Art. 6(1)(b))

Booking history Purpose: Transaction records, dispute resolution Legal Basis: Contract / Legal obligation

Reviews received Purpose: Platform quality system Legal Basis: Legitimate interest

IP address / device data Purpose: Security, fraud prevention Legal Basis: Legitimate interest

Bank account details Purpose: Held by Stripe Connect (not stored by Lustra) Legal Basis: Contract (Art. 6(1)(b))

Identity documents Purpose: Held by Stripe Connect (not stored by Lustra) Legal Basis: Legal obligation (Art. 6(1)(c))

3.3 DATA COLLECTED FROM PROSPECTIVE PARTNERS (WAITLIST)

When you apply to join Lustra as a Service Provider through our waitlist, we collect data to evaluate your application:

Full name / Business name Purpose: Application identity Legal Basis: Legitimate interest / Pre-contractual steps

Email address / Phone number Purpose: Contacting you regarding your application status Legal Basis: Legitimate interest / Pre-contractual steps

City Purpose: Assessing service area coverage Legal Basis: Legitimate interest

Insurance status & Optional message Purpose: Evaluating your suitability for the platform Legal Basis: Legitimate interest

3.4 DATA WE DO NOT COLLECT

We do not collect: - Payment card details (handled entirely by Stripe) - Government ID documents (handled entirely by Stripe) - Sensitive personal data (health, religion, ethnicity, etc.) - Data from children under 18

4. How Long We Keep Your Data (Retention)

4.1 CLIENT DATA

Name and service address Retention Period: Deleted within 30 days of service completion, or sooner once shared with the Service Provider and the booking is closed

Email address Retention Period: Deleted within 30 days of service completion

Booking reference (anonymised) Retention Period: Kept for 7 years in anonymised form for accounting and legal purposes (Belgian law)

IP address / session data Retention Period: 13 months maximum (standard analytics retention)

We do not retain Client personal data beyond what is necessary. Once a booking is completed and the 30-day window has passed, your name, address, and email are deleted. We retain only an anonymised record of the transaction (date, service type, amount) for accounting purposes.

4.2 SERVICE PROVIDER DATA

Account data Retention Period: Duration of account + 3 years after closure

Booking and transaction records Retention Period: 7 years (Belgian accounting law)

DAC7 tax reporting data Retention Period: 5 years minimum (as required by Belgian DAC7 transposition law)

TIN and tax ID data Retention Period: 5 years from the year of reporting

Marketing consent records Retention Period: Until withdrawal of consent + 1 year

When data is no longer needed, it is securely deleted or anonymised.

5. Who We Share Data With

5.1 BETWEEN CLIENTS AND SERVICE PROVIDERS

When a Client confirms a booking, the following data is shared with the relevant Service Provider: - Client's full name - Service address - Booking details (date, time, service type)

This sharing is strictly necessary to perform the service and constitutes the core function of the Platform. Service Providers must not use this data for any purpose other than fulfilling the booked service, and must handle it in compliance with applicable data protection law.

5.2 STRIPE (PAYMENT PROCESSOR)

All payments are processed by Stripe, Inc. / Stripe Payments Europe Ltd. Stripe receives payment and booking data necessary to process the upfront payment and handle any partial refunds (e.g. in case of late cancellation). Stripe acts as an independent data controller for the data it collects. See section 7 for more detail.

5.3 BELGIAN TAX AUTHORITIES (DAC7)

As required by EU Directive 2021/514 (DAC7), transposed into Belgian law by the Act of 21 December 2022, Lustra is legally obligated to report certain data about Service Providers to the Belgian Federal Public Service Finance (FPS Finance) annually. This applies only to Service Providers, not to Clients.

Service Providers are notified of the specific data to be reported by 10 January each year, before submission.

5.4 HOSTING AND INFRASTRUCTURE PROVIDERS

- Vercel: web hosting and infrastructure - Resend: transactional emails (booking confirmations, cancellation links) - Cloudflare: security, content delivery network (CDN), and bot protection (Turnstile) - Cloudinary: image hosting and optimization (business profile pictures, portfolio images)

These providers act as data processors under written agreements and may only process data on our instructions.

5.5 ANALYTICS PROVIDERS

- Google (Analytics / Tag Manager): understanding platform usage, traffic, and user behavior.

5.6 LEGAL AUTHORITIES

We may disclose data to law enforcement or judicial authorities where required by Belgian or EU law.

5.7 NO DATA SALES

We do not sell personal data to any third party under any circumstances.

5.8 INTERNATIONAL TRANSFERS

Stripe processes some data in the United States under Standard Contractual Clauses approved by the European Commission, providing equivalent protection to EU law. All other processing takes place within the EEA.

6. Data Shared with Service Providers — Their Obligations

When Client data (name, address) is shared with a Service Provider to fulfil a booking, the Service Provider becomes an independent data controller for that data. Service Providers:

- May only use Client data to perform the booked service - Must not retain Client data beyond what is necessary - Must not share Client data with third parties - Must comply with GDPR in their handling of Client data

Lustra is not responsible for how Service Providers handle personal data once it has been shared for the purpose of fulfilling a booking. Clients who have concerns about how a Service Provider handled their data may contact us at and we will assist where possible.

7. Stripe Connect and Payments

All payments on the Platform are processed by Stripe via Stripe Connect.

For Clients: when you pay for a booking, your payment details are entered directly into Stripe's secure payment interface. Lustra never sees, receives, or stores your card details.

For Service Providers: your bank account details and identity documents provided during Stripe Connect onboarding are held by Stripe, not by Lustra. Lustra receives only limited status information (e.g. "verification complete", "payment successful").

Stripe's Privacy Policy applies to all data Stripe collects: stripe.com/en-be/privacy

In the event of a late cancellation (less than 24 hours before the booking), Stripe processes the partial refund of 50% of the booking value to the Client, with the remaining 50% released to the Service Provider as a cancellation fee. This is handled automatically and Lustra does not manually access payment data to do so.

8. Your Rights Under GDPR

All individuals whose data we process have the following rights:

RIGHT OF ACCESS (Art. 15) Request a copy of all personal data we hold about you.

RIGHT TO RECTIFICATION (Art. 16) Request correction of inaccurate or incomplete data.

RIGHT TO ERASURE (Art. 17) Request deletion of your data. Note: we cannot delete data we are legally required to retain (e.g. tax records, DAC7 data).

RIGHT TO RESTRICTION (Art. 18) Request that we limit processing of your data in certain circumstances.

RIGHT TO DATA PORTABILITY (Art. 20) Request your data in a structured, machine-readable format (applies to data processed by automated means on the basis of contract or consent).

RIGHT TO OBJECT (Art. 21) Object to processing based on legitimate interest. You have an unconditional right to object to direct marketing at any time.

RIGHT TO WITHDRAW CONSENT (Art. 7(3)) Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any right, contact:

For Clients with no account: please include your email address and the approximate date of your booking so we can locate your data.

We will respond within 30 days and may ask you to verify your identity.

COMPLAINTS If you are not satisfied with our response, you may lodge a complaint with the Belgian Data Protection Authority:

Autorité de protection des données (APD/GBA) Rue de la Presse 35, 1000 Brussels [email protected] www.autoriteprotectiondonnees.be

9. Cookies

9.1 WHAT WE USE COOKIES FOR

Strictly necessary Purpose: Session security, booking flow, remembering booking in progress Consent Required: No

Analytics Purpose: Understanding how users navigate the Platform (anonymised) Consent Required: Yes

Preferences Purpose: Language or display settings Consent Required: Yes

Marketing Purpose: Targeted advertising (if used) Consent Required: Yes

9.2 YOUR CHOICES A cookie consent banner will appear on your first visit. You may change your preferences at any time via the [Cookie Settings] link in the footer. Refusing non-essential cookies does not prevent you from using the Platform or completing a booking.

10. Security

We implement appropriate technical and organisational measures including: - Encrypted data transmission (HTTPS/TLS) - Password hashing for Service Provider accounts - Access controls limiting who can access personal data - Short retention windows for Client data (see section 4) - Regular security reviews

In the event of a personal data breach posing a risk to your rights, we will notify the APD/GBA within 72 hours and notify affected individuals where required.

11. Children

The Platform is not directed at persons under 18. We do not knowingly collect data from minors. Contact if you believe a minor has submitted data through the Platform.

12. Changes to This Policy

Material changes will be notified by email (to Service Providers) and by prominent notice on the Platform at least 14 days before taking effect. The "Last updated" date at the top always reflects the current version.

13. Contact

Lustra Platform

Legal

Related policies

Related legal documents for Lustra customers and service providers.