Privacy Policy
Introduction
This privacy policy explains how LochStudios collects, uses, stores, and shares personal information about clients and end-users of the LochStudios Panel and associated services.
Information we collect
Depending on how you use the Panel, we may collect the following categories of information.
- Account and billing details - email address, name, phone number, billing address, and business or tax identifiers you provide (such as an Australian Business Number (ABN), Tax Identification Number (TIN), VAT Identification Number (VATIN), or an equivalent local tax registration number).
- Authentication data - password hash, TOTP secret, recovery codes, and metadata about recent login devices and IP addresses.
- Linked social sign-in - provider user ID, username or handle, email address where the provider shares it, OAuth access and refresh tokens (encrypted at rest), and for Discord the publicly linked third-party accounts exposed by the provider’s connections API.
- Service usage - hosting accounts, domain names, SSL certificates, Microsoft 365 subscriptions, generic services, and their statuses.
- Communications - SMS message bodies and delivery statuses, transactional email logs, opt-out preferences, and support notes.
- Audit records - every administrative action, including the actor, target, before/after snapshots, IP address, and user agent.
- Cookie consent - whether you have acknowledged this policy and when.
- Visitor IP intelligence - geolocation, ASN, and VPN/proxy/Tor classification attached to logged-in requests.
How we use this information
We use this information to authenticate users; to provision and manage services; to communicate operationally (account security, billing, service status); to detect and prevent abuse (rate limiting, anti-bot, fraud signals); to meet Australian tax and consumer-law retention requirements; and to operate the system (backups, error tracking, audit trails).
Legal basis (GDPR Art. 6)
Performance of a contract for service provision and billing; legitimate interest for security, fraud prevention, and operational logging; legal obligation for tax records (7-year retention under AU tax law) and audit retention; consent for any marketing communications (which is opt-in and revocable at any time via your account preferences).
Third parties we share data with
See the data processors register below. We do not sell personal information.
Retention
Active client records are retained for the duration of the relationship. Closed client records are retained for the longer of: (a) 7 years for tax records (AU); or (b) any active legal hold. Audit logs are retained indefinitely with cleared PII fields once an account is anonymised. Health logs are pruned at 90 days. SMS message bodies are pruned at 365 days. Backups are retained indefinitely on encrypted archive storage. Subject access requests are retained for 30 days after download availability begins.
Your rights
You may: request a copy of all personal data we hold about you (subject access request); request anonymisation of your records once all active services are closed (right to erasure); withdraw consent for marketing communications at any time; update your contact information; and lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or your local data-protection authority.
Cookies
We use strictly-necessary cookies to keep you signed in (lochsid session cookie), to remember devices that have completed 2FA (remember-device cookie), and to remember that you have acknowledged this policy (cookie_ack cookie). We do not use analytics, advertising, or tracking cookies. When this policy is updated, the version number changes and you are re-prompted to acknowledge.
Social logins
You can link a Google, Discord, Twitch, or X (Twitter) account to your LochStudios account for faster sign-in. Social sign-in is link-only: we never create a new account from a social login. You must already have a LochStudios account (invited or registered with email and password), then link a provider from Account → Linked sign-in. Each provider may be linked at most once per LochStudios account, and each external account may be linked to at most one LochStudios account.
When you link or sign in with a provider, we receive and store: your provider user ID; your username, handle, or display name as returned by the provider; your email address where the provider’s authorised scopes include it (Google and Discord); and the OAuth access and refresh tokens the provider issues to us, encrypted at rest. We use these tokens only to verify your identity at sign-in, keep the connection active, and support provider-related features of your account. We do not post to any provider on your behalf, read your private messages, or access your content beyond the scopes you authorise.
Google. We request openid and email scopes. We store your Google user ID, name, and email address.
Discord. We request identify, email, and connections scopes. We store your Discord user ID and username. Where available, we also fetch and store the list of third-party accounts you have publicly linked to Discord (for example Twitch, YouTube, or Steam handles exposed by Discord’s connections API), including whether each connection is verified or revoked. This list is replaced on each re-link.
Twitch. We request the user:read:email scope. We store your Twitch user ID and login name. Where Twitch issues a refresh token, we refresh the access token periodically (approximately every four hours) so the connection stays active; if the refresh token is revoked at Twitch, we flag the connection as needing re-authorisation.
X (Twitter). X’s sign-in flow requires us to request both users.read and tweet.read scopes in the authorisation prompt. The tweet.read scope is included because it forms part of X’s default scope bundle for login applications - not because we intend to access your tweets. LochStudios does not use tweet.read to read, retrieve, or store any of your posts, and we never will. We use users.read solely to obtain your account identifiers (user ID and username) for sign-in and account linking. The authorisation flow uses PKCE. We do not post to X on your behalf.
You can disconnect any linked provider at any time from Account → Linked sign-in. Disconnecting deletes the stored tokens and removes the link. Your LochStudios account and its services are unaffected. Each provider is also governed by its own privacy policy and terms; review those before linking.
Security
All traffic is transported over HTTPS with HTTP Strict Transport Security (HSTS) preloading. Our public-facing TLS certificates are issued by Let’s Encrypt (Internet Security Research Group). As at 17 June 2026, those certificates are signed under Let’s Encrypt’s E8 certification authority using an elliptic-curve (ECDSA) key pair and the ECDSA-with-SHA-384 signature algorithm; certificate fingerprints are derived using the SHA-256 hash function for integrity verification. Certificates are renewed automatically before expiry.
Passwords are stored as Argon2id hashes. TOTP secrets are encrypted at rest. SSL private keys submitted via the Panel are encrypted with the application key and never logged in plaintext. Database backups are encrypted off-site with public-key (age X25519) encryption; the decryption private key is stored off-server in cold storage.
SMS, MMS, and messaging programmes
Where you provide a mobile number and consent to receive messages, or where messaging is necessary to deliver a service you requested, LochStudios may send SMS, MMS, or similar messages (including WhatsApp messages where that channel is enabled) about your account, security, billing, service status, support, and other operational matters. Message frequency varies with account activity and the notifications you enable; you may receive more than one message in a short period during incidents, renewals, or security events.
Consent and opt-in data. We collect and store the mobile number you provide, the time and method of consent (for example account registration, Panel preference, keyword opt-in, or a documented verbal or written request), and related delivery and opt-out records. We do not sell, rent, or share mobile opt-in information or consent records with third parties or affiliates for their own marketing or promotional purposes. Carriers and messaging platform providers process numbers and message content solely to deliver messages and operate the network on our behalf (see the data processors register).
Opt-out and help (mobile). You can stop SMS to your number by replying STOP, UNSUBSCRIBE, CANCEL, END, QUIT, or OPT OUT to a LochStudios message. That reply places the number on our hard opt-out list, and we will not send further SMS to it through the Panel messaging system (including account-security, billing, service-status, marketing, staff-composed, and system notices) until the opt-out is removed by support or an authorised process. You can also manage category preferences when signed in under Account → Notification preferences (requires a verified phone): billing, service status, and marketing SMS only send when the matching preference is on. Account-security SMS (such as phone verification codes) may still be sent when needed for account safety if the number is not on the hard opt-out list. Signed marketing messages may also include a one-click opt-out link to /portal/sms-opt-out.
Reply HELP or INFO to a LochStudios message for an automated reply with support details: how to open a ticket in the Panel (/portal/tickets), email support@lochstudios.com, and our published regional support phone numbers (Australia, United States, United Kingdom, New Zealand, and Australian remote support). HELP replies are still delivered after a STOP opt-out so you can reach us. Message and data rates may apply depending on your mobile plan and carrier.
United States (including A2P 10DLC and CTIA expectations). For US-destined traffic, our messaging practices are designed to align with applicable carrier and industry requirements for application-to-person (A2P) messaging, including clear programme description, prior express consent where required (including prior express written consent for certain commercial or marketing messages under the Telephone Consumer Protection Act (TCPA) and related rules), identification of the sender, reasonable message frequency disclosure, and functioning STOP and HELP keywords. Consent is not a condition of purchase unless a specific product expressly requires a phone number to deliver the service.
Australia and other countries. Commercial electronic messages we send remain subject to the Spam Act 2003 (Cth) and the Australian Privacy Principles where they apply. Outside Australia and the United States, we apply the same core practices (identity of sender, lawful basis or consent, easy opt-out, and processor controls) and comply with local electronic-messaging and privacy rules that apply to us as an Australian business serving customers in those places. Where local law is stricter than this policy, we follow the stricter rule for that traffic.
International users and additional privacy rights
LochStudios is based in Australia. If you are located outside Australia, your information may be processed in Australia and in the countries where our processors operate (including the United States for certain payment, messaging, backup, and sign-in services listed in the data processors register).
United States state privacy laws. Depending on your state of residence (for example California under the CCPA/CPRA, and similar state laws), you may have rights to know, access, correct, or delete personal information, and to opt out of “sale” or “sharing” of personal information as those terms are defined by statute. We do not sell personal information and we do not share mobile opt-in data for third-party marketing. To exercise applicable rights, email privacy@lochstudios.com. We will verify requests as required by law and will not discriminate against you for exercising privacy rights.
European Economic Area, United Kingdom, and similar regimes. Where the GDPR or UK GDPR applies, the legal bases described earlier in this policy continue to apply. You may also lodge a complaint with your local supervisory authority. Cross-border transfers to our processors are covered by the commercial and contractual arrangements we maintain with those providers, together with the technical measures described under Security.
Contact
For privacy matters, write to privacy@lochstudios.com.
Data processors
| Name | Purpose | Data shared | Jurisdiction | Website | DPA URL |
|---|---|---|---|---|---|
| Synergy Wholesale Pty Ltd | Domain registration, hosting, SSL certificates, Microsoft 365 provisioning | name, email, phone, address, domain_name | Australia | https://www.synergywholesale.com | - |
| Australian Phone Company | Transactional SMS to client mobile numbers | phone, message_body | Australia | https://www.australianphone.com.au | - |
| Twilio Inc. | SMS/MMS and WhatsApp delivery fallback (and related messaging webhooks) for destinations not served by Australian Phone; carrier routing may include US A2P traffic | phone, message_body, delivery_status | United States | https://www.twilio.com/legal/privacy | https://www.twilio.com/legal/data-protection-addendum |
| ExchangeRate-API | Currency conversion rates (anonymous queries - no PII) | United Kingdom | https://exchangerate-api.com | - | |
| Cloudflare, Inc. | Encrypted off-site backup storage (R2) | encrypted_database_dumps, encrypted_sar_exports | United States | https://cloudflare.com | - |
| ax.email | Transactional SMTP delivery + IMAP bounce mailbox (packages.lochstudios.com) | email_address, message_body | Australia | https://ax.email | - |
| IPLocate | IP geolocation + threat detection enrichment (visitor IP only) | ip_address | United States | https://iplocate.io | - |
| Google LLC | OAuth sign-in and linked-account verification (Google) | oauth_authorisation_code | United States | https://policies.google.com/privacy | - |
| Discord Inc. | OAuth sign-in and linked-account verification (Discord) | oauth_authorisation_code | United States | https://discord.com/privacy | - |
| Twitch Interactive, Inc. | OAuth sign-in, linked-account verification, and access-token refresh (Twitch) | oauth_authorisation_code, oauth_refresh_token | United States | https://legal.twitch.com/en/legal/privacy-notice/ | - |
| X Corp. | OAuth sign-in and linked-account verification (X / Twitter) | oauth_authorisation_code | United States | https://x.com/en/privacy | - |