We use essential cookies

We use strictly necessary cookies for authentication and, with your consent, optional analytics cookies to improve the product.

← Home
Legal

Privacy Policy

Version 6 · Last updated: 9/6/2026

Effective date: 16 July 2026 · Version 2

This Privacy Policy explains how LOFT PRESS LTD (“LoftPress”, “we”), a company registered in England and Wales under number 16676296 with registered office at Unit 501 Leroy House, 434-436 Essex Road, London, England, N1 3FY, processes personal data when you use the LoftPress API platform at loftpress.shop (the “Service”). LOFT PRESS LTD is the controller of that personal data.

This notice is written for people protected by the UK GDPR and the Data Protection Act 2018, by the EU GDPR where applicable, and by the Turkish Personal Data Protection Law (KVKK) for users in Turkey.

Contact for privacy matters: support@loftpress.shop.

1. What personal data we process

  • Account and contact data: name, email, chosen language, account role, password hash (we never store your password in the clear).
  • Authentication and security: session cookies, JWTs, IP address of login, user-agent, timestamps, brute-force protection state.
  • Billing metadata from Creem: order ID, amount, currency, VAT/tax lines Creem calculated for the transaction, invoice URL, subscription status, refund/dispute events. We do not receive or store full card numbers. Card data stays with Creem and its processors.
  • API usage: API-key identifiers (keys themselves are stored hashed), endpoint called, timestamp, HTTP status, response latency, credits consumed, request IP, request ID.
  • Support communications: your messages to support@loftpress.shop and any attachments you send.
  • Consent evidence: legal document slug, version, content hash, language, IP, user-agent and timestamp for every consent you give.
  • Cookies and analytics: strictly-necessary cookies always; optional analytics only after you opt in through the cookie banner. See § 8.
  • Marketing: only if you actively opt in.

2. Where the data comes from

Directly from you (registration, dashboard actions, forms), automatically from your use of the Service (usage logs, security events), and from Creem for transactions you complete at checkout.

PurposeUK/EU GDPR basisKVKK basis
Provide the Service, run your subscription and API keysContractContract necessity
Bill and issue receipts (via Creem)Contract & legal obligationContract & legal obligation
Keep records for tax, accounting and auditLegal obligationLegal obligation
Prevent fraud, protect the Service, investigate abuseLegitimate interestsLegitimate interests
Provide support and handle complaintsContract & legitimate interestsContract & legitimate interests
Optional analytics cookiesConsentExplicit consent
Marketing emailsConsentExplicit consent
Legal claims and defenceLegitimate interests / legal obligationLegal obligation

Where we rely on legitimate interests we balance them against your rights and describe the interest clearly.

4. Who we share it with (processors and recipients)

  • Creem (Armitage Labs OÜ) – payments, invoicing, tax compliance, chargebacks and refunds. Creem is a separate controller for the payment transaction.
  • Hosting, database and infrastructure providers we use to run the Service.
  • Email delivery provider for transactional messages.
  • Analytics providers — only if you consent to analytics cookies.
  • Professional advisers (accountants, lawyers) when required by law or to defend legal claims.
  • Public authorities where we are legally obliged to disclose.

We do not sell personal data. We do not name vendors that are not actually configured. Where a vendor changes, we update this list.

5. International transfers

The Service is delivered from the United Kingdom. Depending on the provider, data may be processed outside your country, including outside the UK, EEA and Turkey. Where transfers happen, we rely on lawful transfer mechanisms:

  • UK: adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.
  • EEA: European Commission adequacy decisions or Standard Contractual Clauses (SCCs) with supplementary measures where appropriate.
  • Turkey: transfer mechanisms permitted under the KVKK, including explicit consent where required and, once formally in force, the KVKK cross-border transfer regime and any KVKK-approved undertakings.

6. How long we keep it (retention)

  • Account and contract data: while your account is active and for 6 years after closure, to comply with UK tax and accounting record-keeping rules and defend legal claims.
  • Invoices and financial records: 6 years (UK statutory retention).
  • API keys: hashed values are deleted when the key is revoked or the account is closed.
  • API and security logs: normally 12 months, longer if reasonably needed for an active incident.
  • Support tickets: 3 years from closure of the ticket.
  • Consent evidence: for as long as we rely on the consent plus the applicable limitation period.
  • Marketing preferences: until you withdraw.
  • Backups: rolling short-term retention on a strict schedule; deleted data is overwritten on the next cycle.

Where the admin configures a shorter retention for logs, the shorter setting applies.

7. Your rights

Subject to legal limits and time bars, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have data deleted where the legal basis for keeping it no longer applies;
  • restrict or object to processing;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time (this does not affect prior lawful processing).

To exercise a right, write to support@loftpress.shop with enough information to verify your identity. We respond within the legal time limits.

UK / EEA complaints. You can complain to the UK Information Commissioner’s Office (ICO) or your local EU supervisory authority.

Türkiye / KVKK. KVKK Madde 11 kapsamındaki haklarınızı, Veri Sorumlusuna Başvuru Usul ve Esasları hakkında Tebliğ’e uygun şekilde support@loftpress.shop adresi üzerinden kullanabilirsiniz. Yanıtımız yasal süreler içinde verilir; ayrıca KVKK’ya şikâyet hakkınız saklıdır.

8. Cookies and analytics

We use strictly necessary cookies to run the site (session, CSRF, language, consent banner state). These do not require consent. Optional analytics cookies run only after you opt in through the cookie banner. You can change your choice at any time from the Cookie Preferences link in the footer.

9. Automated decision-making

We do not use solely automated decisions that produce legal or similarly significant effects on you. Rate-limiting and fraud-scoring are decision-support tools reviewed by humans before any account is suspended.

10. Security

We hash API keys and passwords, encrypt admin-managed secrets at rest, isolate environments, enforce role-based access, and maintain audit logs for security-sensitive actions. No online service is perfectly secure; we cannot guarantee absolute security but we work continuously to protect your data.

11. Children

The Service is not directed to individuals under 18 and we do not knowingly collect personal data from them. If you believe a child has provided personal data, contact us and we will delete it.

12. Creem as a separate controller

Creem processes payment data as a separate controller under its own privacy notice available at creem.io/legal/privacy. LOFT PRESS LTD does not control Creem’s processing.

13. Changes to this policy

We may update this policy. Material changes are notified by email and in-app and shown on this page with a new effective date and version number. Older versions are archived and available on request.

14. Contact

  • LOFT PRESS LTD, Unit 501 Leroy House, 434-436 Essex Road, London, England, N1 3FY
  • Privacy contact: support@loftpress.shop
  • Response window: within 3 business days during Monday to Friday, 09:00–17:00 UK time
LOFT PRESS LTD
Companies House no. 16676296 — England & Wales
Unit 501 Leroy House, 434-436 Essex Road, London, England, N1 3FY