Last updated: 10 September 2026

LootLocker uses a small number of service providers to operate the LootLocker platform. Each one processes personal data only on our instructions, under a written agreement that imposes the obligations required by Article 28 of the GDPR.

This page is Exhibit A to our Data Processing Agreement and forms part of it. It is the authoritative version of the list, and it supplies the sub-processor information required by Annex III to the Standard Contractual Clauses.

Providers we use to deliver the Service

ProviderWhat they doPersonal data involvedWhere it is processedProvider established in
Hetzner Online GmbHHosting, compute, networking, caching — our primary infrastructureAll customer and player data stored in the platformHelsinki, Finland (hel-1)Germany
CloudflareContent delivery, DDoS protectionIP addresses and request metadata in transitGlobal edge networkUnited States
Grafana Cloud (Grafana Labs)Metrics and monitoringOperational metrics; IP addresses in logsLondon, United KingdomUnited States
Postmark (ActiveCampaign)Transactional email — account and system messagesEmail addresses, message contentUnited StatesUnited States
LettermintCampaign and newsletter emailEmail addresses, subscription status, engagement dataNetherlandsLettermint B.V., Netherlands

Providers we use to run our business

ProviderWhat they doPersonal data involvedWhere it is processedProvider established in
Google WorkspaceInternal communication and document storageCustomer contact details and correspondenceUnited StatesUnited States
DiscordOur public developer support communityDiscord account identifiers and messages of people who choose to joinGlobalUnited States

Recipients that act as independent controllers

Some providers decide for themselves how they use personal data, so they are not our processors. We name them here because customers ask, not because they are sub-processors.

RecipientWhat they doPersonal data involvedRole
StripeInvoicing and payment collectionBilling contact details, company details, VAT number, invoice and payment records. Card details are entered directly with Stripe and never reach LootLockerIndependent controller under its own privacy policy

Stripe handles our own billing data. It never receives player data, which is why it does not appear in Exhibit A to the Data Processing Agreement — that exhibit covers only sub-processors of data we handle on a customer's behalf.

Discord and Twitch integrations. LootLocker offers integrations with Discord (rewards and key distribution) and Twitch (drops). Neither processes LootLocker customer data on our behalf, so neither is a sub-processor for that purpose. Where a customer connects its own Discord server or Twitch channel, that platform acts under its own terms and its own relationship with the customer and the player.

International transfers

Player data in the platform is hosted and stored in the EEA, on Hetzner in Helsinki, Finland.

Grafana Cloud processes monitoring data in London. The United Kingdom is covered by a European Commission adequacy decision, so no additional transfer safeguard is required.

Transfers to the United States — Postmark, Google Workspace, Discord, Cloudflare's global edge network and Stripe — are made under the Standard Contractual Clauses adopted by the Commission in Implementing Decision (EU) 2021/914, with the UK International Data Transfer Addendum or the equivalent Swiss provisions where those apply.

Changes to this list

We update this page when we add or replace a sub-processor.

Under our Data Processing Agreement, a customer may object on reasonable grounds relating to data protection within fourteen (14) days of an update. We will discuss any objection in good faith, and where it cannot be resolved the customer may terminate the affected Services. If no objection is raised in that period, the sub-processor is treated as authorised.

To be notified of changes, subscribe to the RSS feed on this page.

Questions

privacy@lootlocker.com