Effective date: 1 November 2026
Version 2. Previous versions are listed at the end of this page.
LootLocker AB (corporation registration number 559164-9289), Kaptensvägen 13B, 132 46 Saltsjö-boo, Sweden ("LootLocker", "we", "us") provides a backend platform for game developers and publishers. LootLocker AB is the controller of the personal data described in Part A and the contracting party for our services.
We handle personal data in two distinct roles, and this policy is divided accordingly.
Part A covers personal data for which we are the controller — the data of our customers, of people who visit our website, and of people who contact us. This is the part that describes our own decisions about personal data.
Part B covers player data — personal data that flows through our platform because one of our customers has integrated LootLocker into their game. For that data we are a processor. We act on our customer's instructions, and our customer, not LootLocker, decides what is collected and why.
Part C covers additional disclosures for residents of US states with comprehensive privacy laws. It supplements Parts A and B rather than replacing them.
If you are a player of a game and you want to exercise your rights over your data, Part B tells you where to go. It is not us.
Part A — When we are the controller
This part applies to you if you hold a LootLocker account, work for a customer of ours, visit our website, subscribe to our developer newsletter, join our support Discord, or contact us.
A1. What we collect and why
| Category | Examples | Source | Purpose | Legal basis | Retention |
|---|---|---|---|---|---|
| Account data | Name, email address, company name, password (stored hashed), account role | You | Creating and operating your account; authentication; account security | Performance of a contract (Art. 6(1)(b)) | Kept until you ask us to delete it, or until we close your account |
| Billing data | Company details, billing address, VAT number, invoice records, plan and usage figures. We do not receive or store card numbers | You; our systems; Stripe | Invoicing, collections, tax and accounting records | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) | 7 years, per the Swedish Bookkeeping Act |
| Dashboard usage data | Pages and features used, IP address, browser and device information, timestamps | Our systems | Operating and improving the dashboard; diagnosing faults | Legitimate interests (Art. 6(1)(f)) — running and improving a service you use | Kept until you ask us to delete it |
| Security and server logs | IP address, request metadata, error traces | Our systems | Detecting and investigating abuse, intrusion and faults | Legitimate interests (Art. 6(1)(f)) — securing the Service | 30 days |
| Support data | Correspondence with us by email or in our developer Discord, bug reports, attachments | You | Answering your questions and resolving issues | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) | Kept until you ask us to delete it |
| Marketing data | Email address, subscription status, engagement with our emails | You | Sending our developer newsletter and product updates | Consent (Art. 6(1)(a)), withdrawable at any time | Until you unsubscribe |
Where we rely on legitimate interests, we have assessed our interest against your rights and concluded the processing is proportionate. You can ask us for that assessment.
About retention. Apart from billing records, which we must keep for seven years, and logs, which are deleted after 30 days, we do not delete the categories above on a fixed timetable. We keep them for as long as you have an account with us, and we delete them when you ask. That is a description of what we actually do rather than a target, and you can make that request at any time using the contact details in A7.
Payment processing. We invoice through Stripe. Stripe receives the billing details needed to issue and collect an invoice. Card details are entered directly with Stripe and are never received or stored by LootLocker. Stripe acts as an independent controller for payment processing under its own privacy policy, rather than as our processor — see the sub-processor page.
A2. The Service is for businesses
LootLocker accounts are offered to businesses and to individuals acting in a business capacity. The Service is not directed to consumers.
A3. Who we share it with
We use a small number of service providers to operate the Service. Each of them processes personal data only on our instructions and under a written agreement.
We publish the full list, with what each provider does and where, at lootlocker.com/legal/subprocessors.
Beyond those providers, we share personal data only where we are legally required to, or where it is necessary to establish, exercise or defend legal claims.
We do not sell personal data, and we do not share it for advertising.
A4. Where your data is processed
We host the Service in the EEA. Our primary infrastructure is operated by Hetzner in Helsinki, Finland, and player and account data is stored there.
Some of the providers we use process personal data outside the EEA:
| Provider | Where | Safeguard |
|---|---|---|
| Grafana Cloud (monitoring) | London, United Kingdom | UK adequacy decision — no additional safeguard required |
| Postmark (transactional email) | United States | Standard Contractual Clauses |
| Google Workspace (internal communication and storage) | United States | Standard Contractual Clauses |
| Discord (our developer support community) | United States | Standard Contractual Clauses |
| Cloudflare (content delivery) | Global edge network | Standard Contractual Clauses |
| Stripe (invoicing) | United States | Stripe's own transfer safeguards |
Where a transfer is made to a country without a European Commission adequacy decision, we rely on the Standard Contractual Clauses adopted by the Commission in Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum or the equivalent Swiss provisions where those apply.
A5. Cookies and local storage
We do not use analytics, advertising or tracking cookies, and we do not run third-party analytics or advertising scripts on our website.
We use only storage that is strictly necessary to provide the Service you have asked for — for example, keeping you signed in to the LootLocker dashboard.
Because we set no non-essential cookies or similar storage, we do not ask you for cookie consent. If that changes, we will introduce a consent mechanism and obtain your consent before setting any non-essential storage, and we will update this page.
A6. Security
We describe the technical and organisational measures we apply at lootlocker.com/security. Those measures are also set out in Exhibit B to our Data Processing Agreement.
A7. Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw consent where we rely on it. Withdrawing consent does not affect processing carried out before you withdrew.
To exercise any of these, email privacy@lootlocker.com. We will respond within one month, and will tell you if we need longer.
You also have the right to lodge a complaint with a supervisory authority. Ours is the Swedish Authority for Privacy Protection:
Integritetsskyddsmyndigheten (IMY) Box 8114, 104 20 Stockholm, Sweden imy@imy.se · +46 8 657 61 00
Part B — Player data, where we are a processor
If you play a game that uses LootLocker, your data reaches us because the game's developer or publisher chose to send it. In that relationship:
- The developer or publisher is the controller. They decide what data is collected, why, how long it is kept, and on what legal basis.
- LootLocker is the processor. We store and process that data on their documented instructions, under our Data Processing Agreement, and we do not use it for our own purposes.
Depending on what the game has implemented, that data may include platform or device identifiers, an email address, save data and files, in-game progression and inventory, entitlements and purchases, session and presence information, and anything you submit in-game such as feedback or bug reports.
B1. Exercising your rights as a player
Contact the developer or publisher of the game, not us. They hold the relationship with you and they are the ones who can act on your request.
If you contact us directly, we will not act on the request ourselves. We will pass it to the relevant customer and tell you that we have done so, unless we are legally required to do otherwise.
B2. What we commit to our customers
Our Data Processing Agreement sets out our obligations in full, including security, the use of sub-processors, notification of personal data breaches, international transfers, and the return or deletion of data when a customer leaves. It is published at lootlocker.com/legal/dpa.
Part C — Additional information for US residents
This part applies if you are a resident of a US state with a comprehensive privacy law. It supplements Parts A and B; where it conflicts with them for those residents, this part applies.
C1. Our two roles, in US terms
For the personal information of our customers — account holders, their staff, website visitors and people who contact us — we are a business and this part describes what we do.
For player data we are a service provider. We process it only to provide the Service to the customer whose game sent it, on that customer's documented instructions, under our Data Processing Agreement. We do not retain, use or disclose it for any purpose other than providing the Service, we do not retain it outside our direct business relationship with that customer, and we do not combine it with personal information from other sources. If you are a player, direct your requests to the developer or publisher of the game, as described in Part B.
C2. Notice at collection
The categories of personal information we collect about customers, why, and how long we keep them, are set out in the table at A1. Expressed in the categories used by California law:
| Category | Do we collect it? | Examples | Purpose |
|---|---|---|---|
| Identifiers | Yes | Name, email address, account identifier, IP address | Account creation, authentication, support, security |
| Commercial information | Yes | Plan, invoice and payment records | Billing and account management |
| Internet or network activity | Yes | Dashboard usage, request logs | Operating and securing the Service |
| Professional or employment information | Yes | Company name, job role where you give it | Account management and support |
| Geolocation data | Coarse only | Country derived from IP address | Security and service operation |
| Sensitive personal information | No | — | — |
| Biometric information | No | — | — |
| Education information | No | — | — |
| Inferences used to create a profile | No | — | — |
We collect this information from you, from your use of the Service, and from Stripe in connection with billing. We keep each category for the period stated at A1.
C3. We do not sell or share personal information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months. We do not run advertising or analytics scripts on our website, and we do not have advertising partners.
We do not collect sensitive personal information, and we therefore do not use or disclose it for purposes that would give rise to a right to limit its use.
We do not knowingly sell or share the personal information of anyone under 16.
C4. Your rights
Subject to verification, you have the right to:
- know what personal information we have collected about you, where it came from, why we collected it, and who we disclosed it to;
- access a copy of it, in a portable form;
- correct inaccurate personal information;
- delete it, subject to exceptions such as records we must keep for tax and accounting; and
- not be discriminated against for exercising any of these rights. We do not offer financial incentives in exchange for personal information.
Because we do not sell or share personal information, and do not collect sensitive personal information, there is nothing for you to opt out of or limit.
C5. How to exercise them
Email privacy@lootlocker.com. We will acknowledge within ten (10) business days and respond within forty-five (45) days, and will tell you if we need a further forty-five days.
To verify a request we will ask you to confirm information we already hold, usually the email address associated with your account. We will not ask for more information than we need to verify you.
An authorised agent may make a request on your behalf if they provide written permission signed by you, and we may contact you to confirm it.
C6. Other US states
Residents of other US states with comprehensive privacy laws have broadly equivalent rights, and we handle those requests the same way. Some states also give you the right to appeal a refusal: if we decline a request, we will tell you why and how to appeal, and you may contact your state Attorney General.
Changes to this policy
We will publish any change on this page and update the version number. If a change materially affects how we handle personal data for which we are the controller, we will notify account holders by email at least 30 days before it takes effect.
Version history
- v2 — 1 November 2026 — separated controller and processor roles; corrected the description of international transfers; added the sub-processor list, legal bases and retention periods; rewrote the cookies section.
- v1 — 30 April 2025.
Contact
LootLocker AB Kaptensvägen 13B, 132 46 Saltsjö-boo, Sweden Privacy enquiries: privacy@lootlocker.com · General: hello@lootlocker.com