Data Privacy & Incident Response Policy
Last Updated: August 2026
Welcome to Luminar Link ("we," "our," or "us"). Luminar Link is owned and operated by Arbaz Ali Wazir. We are committed to safeguarding client data, ensuring absolute confidentiality, and adhering strictly to data protection standards across our Google Ads management, conversion telemetry, and Amazon Advertising Optimization services.
1. Business Identification & Contact Information
The entity responsible for the collection, governance, and security of client data under this policy is:
- Organization / Legal Name: Arbaz Ali Wazir
- Operating Brand: Luminar Link
- Primary Contact: Arbaz Ali Wazir
- Official Emails: arbazkhanwazir7@gmail.com | contact@luminarlink.com | ahmedkhanwazir77@gmail.com
- Direct Phone: +92 3468399889
- Website: https://luminarlink.com
2. Scope of Services
This policy covers data processing across all professional service engagements provided by Luminar Link, including:
- Google Ads Management: High-intent search campaigns, conversion tracking setup, and call telemetry for local service businesses.
- Amazon Advertising Optimization (PPC): Sponsored Products, Sponsored Brands, Sponsored Display management, bid optimization, and search-term harvest workflows.
- Telemetry & Auditing: Google Tag Manager (GTM), GA4 event verification, Dynamic Number Insertion (DNI), and paid-traffic leak audits.
3. Information We Collect
We collect only the minimum operational information necessary to execute and audit advertising campaigns:
- Contact Details: Name, business email, phone number, and company website domain submitted via audit forms or direct correspondence.
- Campaign & Performance Metrics: Aggregate click data, conversion timestamps, impression share, search queries, ACoS, ROAS, and ad spend records.
- Technical Telemetry: Anonymized browsing patterns, browser headers, and interaction metrics gathered via Google Analytics 4 (GA4) to evaluate site performance.
4. Data Access, Credentials & Permissions
To execute campaign management and technical audits, clients may provide limited, role-based access to relevant advertising consoles (Google Ads, Google Tag Manager, GA4, or Amazon Seller Central / Advertising Console). We enforce the following access controls:
- We request only standard operational or analyst-level roles necessary to optimize ad performance.
- Multi-Factor Authentication (2FA) is enforced across all administrative accounts and devices accessing client systems.
- Client account ownership, administrative structures, and permissions are never altered without prior written approval.
5. Information Sharing & Non-Disclosure
We do not sell, rent, lease, or trade client data or customer PII to third parties, external organizations, or other clients under any circumstances. Data is utilized strictly for campaign performance analysis and is shared solely with certified platform APIs (Google Ads API, Amazon Advertising API) in accordance with platform terms.
6. Data Retention & Permanent Purging
We retain operational records and performance logs only for the duration of the active service engagement. Upon termination of an engagement or upon written request, all client-specific data, stored records, and temporary configuration files are permanently purged from our systems within 30 days.
7. Organizational Change Notification Policy
In accordance with platform compliance standards, Luminar Link maintains a mandatory policy requiring us to notify Amazon and relevant enterprise partners within 30 days of any material organizational changes, ownership transfers, or operational adjustments that alter our organization's need for or use of client information.
8. Risk Assessment & 5-Step Incident Response Plan
We maintain continuous threat monitoring to protect the integrity of client advertising assets. In the event of a suspected security vulnerability, unauthorized access, or data incident, the following 5-step response protocol is immediately executed:
- Step 1 - Detection: Monitor operational systems, access logs, and API connections to immediately identify unauthorized access or anomalous activity.
- Step 2 - Containment: Instantly isolate compromised devices or accounts, revoke active credentials/API tokens, and terminate unauthorized access points.
- Step 3 - Eradication: Identify and eliminate the root cause of the vulnerability, patch system components, and reset security keys.
- Step 4 - Recovery: Restore operations securely from clean configurations and verify system integrity through controlled tests.
- Step 5 - Notification: If Amazon information or platform systems are affected, a formal incident report will be transmitted directly to security@amazon.com and affected clients within 24 hours of confirmation.
9. Contact & Inquiries
For questions regarding this policy or to request data verification, contact us directly at:
arbazkhanwazir7@gmail.com / contact@luminarlink.com