Privacy Policy
Introduction
This privacy policy explains how LochStudios collects, uses, stores, and shares personal information about clients and end-users of the LochStudios Panel and associated services.
Information we collect
Depending on how you use the Panel, we may collect the following categories of information.
- Account and billing details - email address, name, phone number, billing address, and business or tax identifiers you provide (such as an Australian Business Number (ABN), Tax Identification Number (TIN), VAT Identification Number (VATIN), or an equivalent local tax registration number).
- Authentication data - password hash, TOTP secret, recovery codes, and metadata about recent login devices and IP addresses.
- Linked social sign-in - provider user ID, username or handle, email address where the provider shares it, OAuth access and refresh tokens (encrypted at rest), and for Discord the publicly linked third-party accounts exposed by the provider’s connections API.
- Service usage - hosting accounts, domain names, SSL certificates, Microsoft 365 subscriptions, generic services, and their statuses.
- Communications - SMS message bodies and delivery statuses, transactional email logs, opt-out preferences, and support notes.
- Audit records - every administrative action, including the actor, target, before/after snapshots, IP address, and user agent.
- Cookie consent - whether you have acknowledged this policy and when.
- Visitor IP intelligence - geolocation, ASN, and VPN/proxy/Tor classification attached to logged-in requests.
How we use this information
We use this information to authenticate users; to provision and manage services; to communicate operationally (account security, billing, service status); to detect and prevent abuse (rate limiting, anti-bot, fraud signals); to meet Australian tax and consumer-law retention requirements; and to operate the system (backups, error tracking, audit trails).
Legal basis (GDPR Art. 6)
Performance of a contract for service provision and billing; legitimate interest for security, fraud prevention, and operational logging; legal obligation for tax records (7-year retention under AU tax law) and audit retention; consent for any marketing communications (which is opt-in and revocable at any time via your account preferences).
Third parties we share data with
See the data processors register below. We do not sell personal information.
Retention
Active client records are retained for the duration of the relationship. Closed client records are retained for the longer of: (a) 7 years for tax records (AU); or (b) any active legal hold. Audit logs are retained indefinitely with cleared PII fields once an account is anonymised. Health logs are pruned at 90 days. SMS message bodies are pruned at 365 days. Backups are retained indefinitely on encrypted archive storage. Subject access requests are retained for 30 days after download availability begins.
Your rights
You may: request a copy of all personal data we hold about you (subject access request); request anonymisation of your records once all active services are closed (right to erasure); withdraw consent for marketing communications at any time; update your contact information; and lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or your local data-protection authority.
Cookies
We use strictly-necessary cookies to keep you signed in (lochsid session cookie), to remember devices that have completed 2FA (remember-device cookie), and to remember that you have acknowledged this policy (cookie_ack cookie). We do not use analytics, advertising, or tracking cookies. When this policy is updated, the version number changes and you are re-prompted to acknowledge.
Social logins
You can link a Google, Discord, Twitch, or X (Twitter) account to your LochStudios account for faster sign-in. Social sign-in is link-only: we never create a new account from a social login. You must already have a LochStudios account (invited or registered with email and password), then link a provider from Account → Linked sign-in. Each provider may be linked at most once per LochStudios account, and each external account may be linked to at most one LochStudios account.
When you link or sign in with a provider, we receive and store: your provider user ID; your username, handle, or display name as returned by the provider; your email address where the provider’s authorised scopes include it (Google and Discord); and the OAuth access and refresh tokens the provider issues to us, encrypted at rest. We use these tokens only to verify your identity at sign-in, keep the connection active, and support provider-related features of your account. We do not post to any provider on your behalf, read your private messages, or access your content beyond the scopes you authorise.
Google. We request openid and email scopes. We store your Google user ID, name, and email address.
Discord. We request identify, email, and connections scopes. We store your Discord user ID and username. Where available, we also fetch and store the list of third-party accounts you have publicly linked to Discord (for example Twitch, YouTube, or Steam handles exposed by Discord’s connections API), including whether each connection is verified or revoked. This list is replaced on each re-link.
Twitch. We request the user:read:email scope. We store your Twitch user ID and login name. Where Twitch issues a refresh token, we refresh the access token periodically (approximately every four hours) so the connection stays active; if the refresh token is revoked at Twitch, we flag the connection as needing re-authorisation.
X (Twitter). X’s sign-in flow requires us to request both users.read and tweet.read scopes in the authorisation prompt. The tweet.read scope is included because it forms part of X’s default scope bundle for login applications - not because we intend to access your tweets. LochStudios does not use tweet.read to read, retrieve, or store any of your posts, and we never will. We use users.read solely to obtain your account identifiers (user ID and username) for sign-in and account linking. The authorisation flow uses PKCE. We do not post to X on your behalf.
You can disconnect any linked provider at any time from Account → Linked sign-in. Disconnecting deletes the stored tokens and removes the link. Your LochStudios account and its services are unaffected. Each provider is also governed by its own privacy policy and terms; review those before linking.
Security
All traffic is transported over HTTPS with HTTP Strict Transport Security (HSTS) preloading. Our public-facing TLS certificates are issued by Let’s Encrypt (Internet Security Research Group). As at 17 June 2026, those certificates are signed under Let’s Encrypt’s E8 certification authority using an elliptic-curve (ECDSA) key pair and the ECDSA-with-SHA-384 signature algorithm; certificate fingerprints are derived using the SHA-256 hash function for integrity verification. Certificates are renewed automatically before expiry.
Passwords are stored as Argon2id hashes. TOTP secrets are encrypted at rest. SSL private keys submitted via the Panel are encrypted with the application key and never logged in plaintext. Database backups are encrypted off-site with public-key (age X25519) encryption; the decryption private key is stored off-server in cold storage.
SMS, MMS, and messaging programmes
Where you provide a mobile number and consent to receive messages, or where messaging is necessary to deliver a service you requested, LochStudios may send SMS, MMS, or similar messages (including WhatsApp messages where that channel is enabled) about your account, billing, service status, support, and other operational matters. SMS is never used for marketing. Product news, offers, and other marketing go by email only, and only when you have opted in. Message frequency varies with account activity and the notifications you enable; you may receive more than one message in a short period during incidents, renewals, or security events.
What SMS is for. SMS is operational only: account notifications, billing, service status, and when needed a code to verify that a phone number is yours - not to sign in. SMS is never used for marketing, lead generation, or affiliate promotion. SMS is not used for two-factor authentication. Login two-factor authentication uses an authenticator app, which you manage in the Panel under Account → Two-factor authentication. A texted code only proves the number is yours; it is not a sign-in code, a two-factor code, or a login recovery code.
What every SMS includes. These content rules apply to every SMS we send, in every country, not only the United States. Each message identifies the business as LochStudios, states a clear purpose, and includes Reply STOP to opt out when the message is from a number. You can text STOP, HELP, or START to +18338412463 or +61480001064; those keywords work the same on both numbers. In Australia only, some messages are from the name LochStudios (cannot reply); text STOP to either number to opt out. We do not use shortened URLs unless they are LochStudios-branded. We do not send lead-gen or affiliate content.
Consent and opt-in data. We collect and store the mobile number you provide, the time and method of consent (for example account registration, Panel preference, keyword opt-in, or a documented verbal or written request), and related delivery and opt-out records. New contacts record consent or stop/resume at /sms. Existing clients who already consented under Account do not need to opt in again. Phone numbers are collected from you directly; we do not buy lists. We do not sell, rent, or share mobile opt-in information or consent records with third parties or affiliates for their own marketing or promotional purposes. Carriers and messaging platform providers process numbers and message content solely to deliver messages and operate the network on our behalf (see the data processors register).
Opt-out and help (mobile). We do not send marketing SMS. You can stop operational SMS to your number by replying STOP, UNSUBSCRIBE, CANCEL, END, QUIT, or OPT OUT to a LochStudios message from a number, by using the Stop form on /sms, or by using the one-click opt-out link to /portal/sms-opt-out when one is included. You can text STOP, HELP, or START to +18338412463 or +61480001064; those keywords work the same on both numbers. In Australia only, some messages are from the name LochStudios (cannot reply); text STOP to either number. This link, form, or STOP stops operational SMS to the number. That reply, text, form, or link places the number on our hard opt-out list, and we will not send further SMS to it through the Panel messaging system (including account-security, billing, service-status, staff-composed, and system notices) until you reply START to a message from a number, or text START to +18338412463 or +61480001064 (those keywords work the same on both numbers; in Australia only, some messages are from the name LochStudios), or use the Resume form on /sms, to resubscribe. Reply START (or that text or form) removes the number from the hard opt-out list so operational SMS can resume. You can also manage category preferences when signed in under Account → Notification preferences (requires a verified phone): billing and service status SMS only send when the matching preference is on. Account-security SMS (security notifications and, when needed, a code to verify this number is yours, not to sign in) may still be sent when needed for account safety if the number is not on the hard opt-out list. Those messages are not sign-in, two-factor, or login-recovery codes.
Reply HELP or INFO to a LochStudios message from a number for an automated reply with support details: how to open a ticket in the Panel (/portal/tickets), email support@lochstudios.com, and our published regional support phone numbers (Australia, United States, United Kingdom, New Zealand, and Australian remote support). HELP already identifies the business as LochStudios and includes Reply STOP to opt out when the reply is from a number. You can text STOP, HELP, or START to +18338412463 or +61480001064; those keywords work the same on both numbers. In Australia only, if a message is from the name LochStudios (cannot reply), you cannot reply HELP to it; text HELP to either number, or contact support by email or the Panel. HELP replies are still delivered after a STOP opt-out so you can reach us. Message and data rates may apply depending on your mobile plan and carrier.
United States. Traffic to US numbers is sent on our registered application-to-person (A2P) 10DLC programme (or an equivalent short-code registration where used). The US programme number is +18338412463. You can text STOP, HELP, or START to that number; those keywords work the same as on +61480001064. US-destined messages are subject to the Telephone Consumer Protection Act (TCPA) and related carrier campaign-filing requirements. Consent is not a condition of purchase unless a specific product expressly requires a phone number to deliver the service. The content rules under What every SMS includes apply to US traffic in the same way they apply everywhere else.
Australia and other countries. Commercial electronic messages we send remain subject to the Spam Act 2003 (Cth) and the Australian Privacy Principles where they apply. Outside Australia, we comply with local electronic-messaging and privacy rules that apply to us as an Australian business serving customers in those places. The content rules under What every SMS includes apply in every country. Where local law is stricter than this policy, we follow the stricter rule for that traffic.
International users and additional privacy rights
LochStudios is based in Australia. If you are located outside Australia, your information may be processed in Australia and in the countries where our processors operate (including the United States for certain payment, messaging, backup, and sign-in services listed in the data processors register).
United States state privacy laws. Depending on your state of residence (for example California under the CCPA/CPRA, and similar state laws), you may have rights to know, access, correct, or delete personal information, and to opt out of “sale” or “sharing” of personal information as those terms are defined by statute. We do not sell personal information and we do not share mobile opt-in data for third-party marketing. To exercise applicable rights, email privacy@lochstudios.com. We will verify requests as required by law and will not discriminate against you for exercising privacy rights.
European Economic Area, United Kingdom, and similar regimes. Where the GDPR or UK GDPR applies, the legal bases described earlier in this policy continue to apply. You may also lodge a complaint with your local supervisory authority. Cross-border transfers to our processors are covered by the commercial and contractual arrangements we maintain with those providers, together with the technical measures described under Security.
Contact
For privacy matters, write to privacy@lochstudios.com.
Data processors
| Name | Purpose | Data shared | Jurisdiction | Website | DPA URL |
|---|---|---|---|---|---|
| Synergy Wholesale Pty Ltd | Domain registration, cPanel hosting, commercial SSL, Microsoft 365 seats, and mail-hosting orders | name, email, phone, address, domain_name, mailbox_address | Australia | https://www.synergywholesale.com | - |
| Australian Phone Company | Primary operational SMS for destinations on the Australian Phone rate card | phone, message_body, delivery_status | Australia | https://www.australianphone.com.au | - |
| Twilio Inc. | Last-resort SMS/MMS (never United States; never WhatsApp) and inbound voice on the Twilio number | phone, message_body, delivery_status | United States | https://www.twilio.com/legal/privacy | https://www.twilio.com/legal/data-protection-addendum |
| ExchangeRate-API | Currency conversion rates (anonymous queries - no PII) | United Kingdom | https://exchangerate-api.com | - | |
| Cloudflare, Inc. | Encrypted platform backups (R2), CMS and Your-Wedding media object storage, and Turnstile bot protection | encrypted_database_dumps, encrypted_sar_exports, cms_media, wedding_photos, turnstile_tokens | United States | https://www.cloudflare.com/privacypolicy/ | https://www.cloudflare.com/cloudflare-customer-dpa/ |
| ax.email | Transactional SMTP delivery, IMAP bounce mailbox (packages.lochstudios.com), and hosted mailboxes for mail-hosting orders | email_address, message_body | Australia | https://ax.email | - |
| IPLocate | IP geolocation + threat detection enrichment (visitor IP only) | ip_address | United States | https://iplocate.io | - |
| Google LLC | OAuth sign-in and linked-account verification (Google) | oauth_authorisation_code, provider_user_id, handle, email | United States | https://policies.google.com/privacy | - |
| Discord Inc. | OAuth sign-in and linked-account verification (Discord) | oauth_authorisation_code, provider_user_id, handle, email | United States | https://discord.com/privacy | - |
| Twitch Interactive, Inc. | OAuth sign-in, linked-account verification, and access-token refresh (Twitch) | oauth_authorisation_code, oauth_refresh_token, provider_user_id, handle, email | United States | https://legal.twitch.com/en/legal/privacy-notice/ | - |
| X Corp. | OAuth sign-in and linked-account verification (X / Twitter) | oauth_authorisation_code, provider_user_id, handle | United States | https://x.com/en/privacy | - |
| Stripe Payments Australia Pty Ltd | Card payments, stored payment methods, invoices, and CMS subscriptions. Cards stay at Stripe | name, email, client_number, payment_method_tokens | Australia | https://stripe.com/privacy | https://stripe.com/legal/dpa |
| ClickSend Pty Ltd | Operational SMS failover when Australian Phone has no rate for the destination; Australian failover uses the sender name LochStudios. United States ClickSend traffic is not enabled | phone, message_body, delivery_status | Australia | https://www.clicksend.com/au/legal/privacy-policy/ | - |
| Meta Platforms, Inc. | Operational WhatsApp Cloud API messages when that channel is enabled (not marketing; not Twilio) | phone, message_body, delivery_status | United States | https://www.facebook.com/privacy/policy/ | - |
| Microsoft Corporation | Microsoft 365 mailboxes and seats provisioned for customers | name, email, domain_name, tenant_identifiers | United States | https://privacy.microsoft.com | - |
| Internet Security Research Group (Let's Encrypt) | Public TLS certificates for platform hosts and CMS custom client domains | domain_name | United States | https://letsencrypt.org/privacy/ | - |
| Acronis International GmbH | Hourly backups of cPanel hosting accounts (website files, databases, hosted mailbox data on those plans) | website_files, databases, mailbox_data | Switzerland | https://www.acronis.com/company/privacy/ | - |
| OpenAI, LLC | CMS site chatbot replies when a site has AI chat enabled | visitor_chat_messages | United States | https://openai.com/privacy | - |
| ID SCOUT SRL (ShortPixel) | CMS image compression when image optimisation is enabled | image_urls, image_bytes | Romania | https://shortpixel.com/privacy | - |