Privacy Policy
Introduction
This privacy policy explains how LochStudios collects, uses, stores, and shares personal information about clients and end-users of the LochStudios Panel and associated services.
Information we collect
Depending on how you use the Panel, we may collect the following categories of information.
- Account and billing details — email address, name, phone number, billing address, and business or tax identifiers you provide (such as an Australian Business Number (ABN), Tax Identification Number (TIN), VAT Identification Number (VATIN), or an equivalent local tax registration number).
- Authentication data — password hash, TOTP secret, recovery codes, and metadata about recent login devices and IP addresses.
- Linked social sign-in — provider user ID, username or handle, email address where the provider shares it, OAuth access and refresh tokens (encrypted at rest), and for Discord the publicly linked third-party accounts exposed by the provider’s connections API.
- Service usage — hosting accounts, domain names, SSL certificates, Microsoft 365 subscriptions, generic services, and their statuses.
- Communications — SMS message bodies and delivery statuses, transactional email logs, opt-out preferences, and support notes.
- Audit records — every administrative action, including the actor, target, before/after snapshots, IP address, and user agent.
- Cookie consent — whether you have acknowledged this policy and when.
- Visitor IP intelligence — geolocation, ASN, and VPN/proxy/Tor classification attached to logged-in requests.
How we use this information
We use this information to authenticate users; to provision and manage services; to communicate operationally (account security, billing, service status); to detect and prevent abuse (rate limiting, anti-bot, fraud signals); to meet Australian tax and consumer-law retention requirements; and to operate the system (backups, error tracking, audit trails).
Legal basis (GDPR Art. 6)
Performance of a contract for service provision and billing; legitimate interest for security, fraud prevention, and operational logging; legal obligation for tax records (7-year retention under AU tax law) and audit retention; consent for any marketing communications (which is opt-in and revocable at any time via your account preferences).
Third parties we share data with
See the data processors register below. We do not sell personal information.
Retention
Active client records are retained for the duration of the relationship. Closed client records are retained for the longer of: (a) 7 years for tax records (AU); or (b) any active legal hold. Audit logs are retained indefinitely with cleared PII fields once an account is anonymised. Health logs are pruned at 90 days. SMS message bodies are pruned at 365 days. Backups are retained indefinitely on encrypted archive storage. Subject access requests are retained for 30 days after download availability begins.
Your rights
You may: request a copy of all personal data we hold about you (subject access request); request anonymisation of your records once all active services are closed (right to erasure); withdraw consent for marketing communications at any time; update your contact information; and lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or your local data-protection authority.
Cookies
We use strictly-necessary cookies to keep you signed in (lochsid session cookie), to remember devices that have completed 2FA (remember-device cookie), and to remember that you have acknowledged this policy (cookie_ack cookie). We do not use analytics, advertising, or tracking cookies. When this policy is updated, the version number changes and you are re-prompted to acknowledge.
Social logins
You can link a Google, Discord, Twitch, or X (Twitter) account to your LochStudios account for faster sign-in. Social sign-in is link-only: we never create a new account from a social login. You must already have a LochStudios account (invited or registered with email and password), then link a provider from Account → Linked sign-in. Each provider may be linked at most once per LochStudios account, and each external account may be linked to at most one LochStudios account.
When you link or sign in with a provider, we receive and store: your provider user ID; your username, handle, or display name as returned by the provider; your email address where the provider’s authorised scopes include it (Google and Discord); and the OAuth access and refresh tokens the provider issues to us, encrypted at rest. We use these tokens only to verify your identity at sign-in, keep the connection active, and support provider-related features of your account. We do not post to any provider on your behalf, read your private messages, or access your content beyond the scopes you authorise.
Google. We request openid and email scopes. We store your Google user ID, name, and email address.
Discord. We request identify, email, and connections scopes. We store your Discord user ID and username. Where available, we also fetch and store the list of third-party accounts you have publicly linked to Discord (for example Twitch, YouTube, or Steam handles exposed by Discord’s connections API), including whether each connection is verified or revoked. This list is replaced on each re-link.
Twitch. We request the user:read:email scope. We store your Twitch user ID and login name. Where Twitch issues a refresh token, we refresh the access token periodically (approximately every four hours) so the connection stays active; if the refresh token is revoked at Twitch, we flag the connection as needing re-authorisation.
X (Twitter). X’s sign-in flow requires us to request both users.read and tweet.read scopes in the authorisation prompt. The tweet.read scope is included because it forms part of X’s default scope bundle for login applications — not because we intend to access your tweets. LochStudios does not use tweet.read to read, retrieve, or store any of your posts, and we never will. We use users.read solely to obtain your account identifiers (user ID and username) for sign-in and account linking. The authorisation flow uses PKCE. We do not post to X on your behalf.
You can disconnect any linked provider at any time from Account → Linked sign-in. Disconnecting deletes the stored tokens and removes the link. Your LochStudios account and its services are unaffected. Each provider is also governed by its own privacy policy and terms; review those before linking.
Security
All traffic is transported over HTTPS with HTTP Strict Transport Security (HSTS) preloading. Our public-facing TLS certificates are issued by Let’s Encrypt (Internet Security Research Group). As at 17 June 2026, those certificates are signed under Let’s Encrypt’s E8 certification authority using an elliptic-curve (ECDSA) key pair and the ECDSA-with-SHA-384 signature algorithm; certificate fingerprints are derived using the SHA-256 hash function for integrity verification. Certificates are renewed automatically before expiry.
Passwords are stored as Argon2id hashes. TOTP secrets are encrypted at rest. SSL private keys submitted via the Panel are encrypted with the application key and never logged in plaintext. Database backups are encrypted off-site with public-key (age X25519) encryption; the decryption private key is stored off-server in cold storage.
Contact
For privacy matters, write to privacy@lochstudios.com.
Data processors
| Name | Purpose | Data shared | Jurisdiction | Website |
|---|---|---|---|---|
| Synergy Wholesale Pty Ltd | Domain registration, hosting, SSL certificates, Microsoft 365 provisioning | name, email, phone, address, domain_name | Australia | https://www.synergywholesale.com |
| Cellcast Pty Ltd | SMS delivery | phone, message_body | Australia | https://cellcast.com.au |
| ExchangeRate-API | Currency conversion rates (anonymous queries — no PII) | United Kingdom | https://exchangerate-api.com | |
| Cloudflare, Inc. | Encrypted off-site backup storage (R2) | encrypted_database_dumps, encrypted_sar_exports | United States | https://cloudflare.com |
| ax.email | Transactional SMTP delivery + IMAP bounce mailbox (packages.lochstudios.com) | email_address, message_body | Australia | https://ax.email |
| IPLocate | IP geolocation + threat detection enrichment (visitor IP only) | ip_address | United States | https://iplocate.io |
| Google LLC | OAuth sign-in and linked-account verification (Google) | oauth_authorisation_code | United States | https://policies.google.com/privacy |
| Discord Inc. | OAuth sign-in and linked-account verification (Discord) | oauth_authorisation_code | United States | https://discord.com/privacy |
| Twitch Interactive, Inc. | OAuth sign-in, linked-account verification, and access-token refresh (Twitch) | oauth_authorisation_code, oauth_refresh_token | United States | https://legal.twitch.com/en/legal/privacy-notice/ |
| X Corp. | OAuth sign-in and linked-account verification (X / Twitter) | oauth_authorisation_code | United States | https://x.com/en/privacy |