Last updated: June 2026
LOOT is committed to protecting your personal data. This policy explains what we collect, why we collect it, and how we use it.
LOOT does not currently use Open Banking. You manually tell us what cards and memberships you hold — we do not connect to your accounts, read your balance, or initiate payments. If we ever add Open Banking, it will be opt-in, read-only, and fully regulated under FCA rules.
Your data is stored in Supabase on servers within the EU (Ireland region). Supabase is ISO 27001 certified and SOC 2 Type II compliant. All data is encrypted in transit (TLS) and at rest (AES-256). Access is restricted to the LOOT team only.
We use essential session cookies only — these keep you logged in between visits. We do not use advertising cookies, tracking pixels, or third-party analytics that profile you personally.
To exercise any of these rights, email privacy@loot.app. We will respond within 30 days.
We retain your account data for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where we are legally required to retain it (e.g. financial records).
Each of these providers has their own privacy policy and is bound by GDPR-compliant data processing agreements with us.
Questions about your privacy? Email us at privacy@loot.app and we’ll get back to you within 30 days.