Updated: 3 October 2026. Scope: Luma’s public website and documentation.
What this website stores
The public website does not load advertising pixels or analytics trackers. The Ask Luma preview is an illustrative interaction: it does not send your selections to an AI provider or create guest requests.
The application uses the following necessary cookies:
| Cookie | Purpose | Lifetime |
|---|---|---|
luma-concierge-session |
Maintains an application session, including the documentation language preference and sign-in state when you use staff access. | Currently up to 400 days; renewed through application use. |
XSRF-TOKEN |
Protects applicable application requests from cross-site request forgery. | Currently up to 400 days; renewed through application use. |
These lifetimes reflect the current production configuration. Both cookies use Secure and SameSite=Lax; the session cookie is HttpOnly. The cookies do not constitute permission for advertising or analytics.
The cookie notice
Selecting “Got it” only hides this notice. A browser session storage entry, luma.cookie-notice.v1, remembers that display preference for the current tab’s session. It is not a consent record and is not sent to an analytics service. You can reopen the notice through “Cookie information” in the footer. If browser storage is unavailable, the notice still works for the current page.
Your browser controls
You can inspect, delete or block cookies through your browser settings. Blocking necessary cookies can prevent sign-in and language preferences from working. Reading the public page does not require you to consent to optional tracking: no optional tracking is currently installed.
Other Luma surfaces
Authenticated staff and guest applications process additional information to provide their services. This page describes browser storage on the public website; it is not a complete privacy notice for guest stays, AI interactions or property operations.