Privacy Policy
Last updated: , Version 1.0
The short version
- We collect what we need to run your account, sell and deliver licenses, pay creators, keep the platform safe, and meet legal duties.
- We do not sell your personal data, share it for targeted advertising, or use advertising trackers. Our analytics are cookieless and aggregated.
- Sign-in is handled by Clerk; the website is hosted by Vercel; our API, database, and files run on our own servers. Card details go to our payment provider, not to us.
- Financial records are kept as long as the law requires, even after you delete your account; everything else is deleted or anonymised.
- You can access, correct, export, or delete your data, and complain to our Grievance Officer at legal@assetloom.io.
This summary is for convenience. The full text below is what applies.
1.Who we are and what this policy covers
This Privacy Policy explains how Anirudh Negi (“AssetLoom”, “we”, “us”), with a business address at Faridabad, Haryana 121006, India, collects, uses, shares, and protects personal data when you use assetloom.io and related services (the “Service”).
We are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the controller under the EU General Data Protection Regulation and the UK GDPR (together, “GDPR”). For California residents, we are a business under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
This policy does not cover third-party websites you reach from the Service, or the payment provider's own processing when it acts as an independent controller or merchant of record; their own privacy notices apply.
2.Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email address, username, profile image, sign-in method, multi-factor settings, account identifiers. We never see your password. | You, via our authentication provider (Clerk), or a social sign-in provider you choose |
| Profile | Creator handle, display name, bio, links, and anything else you add to a public profile | You |
| Transactions | Credit purchases (amount, currency, date, payment reference, country for tax), orders, licenses, refunds, and the related ledger entries | You, the Service, and our payment provider |
| Payment details | Card or bank details are collected and stored by our payment provider. We receive only limited details such as card brand, last four digits, and payment status. | Our payment provider |
| Creator payout and tax | When payouts open: identity verification status, payout account status, tax identifiers and forms (for example PAN, GSTIN, W-9/W-8BEN) as required by law | You and our payment provider |
| Content | Assets, previews, listings, reviews, reports, copyright notices and counter-notices, and support messages | You |
| Technical and security | IP address, browser and device type, request identifiers, timestamps, error logs, and signals used to detect fraud and abuse | Your device and our servers |
| Analytics (aggregated) | Pages viewed, referrer, approximate country, device type, and performance metrics, collected without cookies and without identifying you across sites | Vercel Web Analytics and Speed Insights |
We do not ask for sensitive data such as health, religion, or biometric information, and we ask you not to include it in Content. We do not knowingly collect data from children (see Children).
3.How we use personal data, and our legal bases
Under the DPDP Act, we process personal data on the basis of your consent, which you give when you create an account or submit information for a specified purpose, or for the “legitimate uses” permitted by section 7 (for example, where you voluntarily provide data for a specified purpose, or to comply with law or a court order). Under the GDPR, we rely on the bases below.
| Purpose | GDPR legal basis |
|---|---|
| Create and secure your account; authenticate you | Performance of a contract |
| Sell credits, process orders, grant licenses, deliver files, and keep your library | Performance of a contract |
| Calculate creator earnings, process payouts, and handle refunds and chargebacks | Performance of a contract; legal obligation |
| Keep accounting, tax, and ledger records | Legal obligation |
| Review and moderate Content, scan uploads for malware, and act on reports and copyright notices | Legitimate interests (a safe, lawful marketplace); legal obligation |
| Detect and prevent fraud, abuse, and security incidents | Legitimate interests; legal obligation |
| Send service messages such as receipts, security alerts, and moderation outcomes | Performance of a contract |
| Understand aggregate usage and site performance to improve the Service | Legitimate interests |
| Send optional product news (only if you opt in) | Consent, which you can withdraw at any time |
| Respond to legal requests and enforce our terms | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced our interests against your rights. You can object at any time (see Your rights).
4.Who we share personal data with
We share personal data only as described here. We do not sell personal data and we do not share it for cross-context behavioural advertising. We do not use advertising cookies, pixels, or trackers.
| Provider | What they do | Location |
|---|---|---|
| Clerk | Account sign-up, sign-in, sessions, and multi-factor authentication; bot protection at sign-up | United States |
| Vercel | Hosting and delivery of the website; cookieless Web Analytics and Speed Insights | Global edge network; United States |
| Our own servers | Our API, database, background jobs, malware scanning, and file storage, operated by us on rented servers (Hostinger, United States) | Hostinger, United States |
| Our payment provider | Processing credit purchases, refunds, and chargebacks; creator identity verification and payouts; tax calculation. It may act as merchant of record for credit purchases. | Varies; see the provider's notice at checkout |
| Our email provider | Sending transactional emails such as receipts and security alerts | Varies |
We may also share personal data:
- With Creators, to the limited extent needed to operate a sale: Creators see order details such as the Asset, license type, date, and amount. We do not give Creators your email address.
- Publicly, where you choose to publish it, such as your creator profile or reviews.
- With rights holders, where we forward a counter-notice as required by copyright law (see the Copyright & Takedown Policy).
- With authorities, where required by law, court order, or a lawful request from a government agency, including under section 69 or 79 of the Information Technology Act, 2000 and the rules made under it, or to protect the rights, safety, or property of users or others.
- With professional advisers, such as lawyers, auditors, and insurers, under confidentiality duties.
- In a business transfer, such as a merger or acquisition, in which case this policy continues to apply to your data and we will notify you.
5.International transfers
We are based in India, and our providers operate in other countries, including the United States. The DPDP Act permits transfers outside India except to countries the Central Government restricts by notification; we will comply with any such restriction.
Where the GDPR applies, we transfer personal data outside the EEA or UK only where the destination has an adequacy decision or where we use appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Contact legal@assetloom.io for a copy of the relevant safeguards.
6.How long we keep personal data
We keep personal data only as long as needed for the purposes above, then delete or anonymise it.
| Data | How long |
|---|---|
| Account and profile data | While your account is open. After deletion, registration information is kept for 180 days as required by rule 3(1)(h) of the IT (Intermediary Guidelines) Rules, 2021, then deleted or anonymised. |
| Ledger, order, payment, payout, and tax records | As long as required by tax, accounting, and other applicable laws (in India, generally at least eight years). Ledger entries are append-only and are linked to an anonymised identifier after account deletion. |
| Audit logs of administrative actions | As long as the related financial or moderation records, so that every change remains accountable. |
| Content you publish | Until you delete it or your account is deleted. Purchased Asset versions may be kept so that existing Buyers can continue to download them, as described in the Creator Terms. |
| Moderation, takedown, and repeat-infringer records | As long as needed to enforce our policies and defend legal claims. |
| Security and server logs | For a limited period for security and troubleshooting, then deleted, unless needed to investigate an incident. |
| Database backups | Rotated on a short cycle (currently 7 days); deleted data disappears from backups when they expire. |
| Aggregated analytics | Does not identify you; may be kept indefinitely. |
We may keep data longer where required by law, a court order, or to establish, exercise, or defend legal claims.
7.How we protect personal data
We use reasonable security safeguards appropriate to the risk, as required by section 8(5) of the DPDP Act and Article 32 of the GDPR. These include encryption in transit, private networking between our servers, least-privilege database roles, append-only financial records, short-lived signed download links, malware scanning of uploads, multi-factor authentication for staff, redaction of secrets and personal data from logs, and audit logging of administrative actions. No system is perfectly secure. If a personal data breach occurs, we will notify you and the relevant authorities (including the Data Protection Board of India and, where applicable, the Indian Computer Emergency Response Team or an EU or UK supervisory authority) as the law requires.
8.Your rights
8.1Everyone
Wherever you live, you can ask us for a copy of your personal data, ask us to correct it, ask us to delete your account, and withdraw any consent you have given. Withdrawing consent does not affect processing that already happened, and we may still keep data we are legally required to keep.
8.2Users in India (DPDP Act)
Under the DPDP Act, you have the right to:
- obtain a summary of the personal data we process about you, the processing activities, and the identities of others we have shared it with;
- correct, complete, and update your personal data, and have it erased where it is no longer needed and retention is not required by law;
- withdraw your consent at any time, as easily as you gave it;
- nominate another person to exercise your rights in the event of your death or incapacity; and
- readily available grievance redressal through our Grievance Officer (see Contact and Grievance Officer). If you are not satisfied with our response, you may complain to the Data Protection Board of India.
8.3Users in the EEA and UK (GDPR)
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including an absolute right to object to direct marketing), and the right to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority, such as the data protection authority in your EU country of residence or the UK Information Commissioner's Office.
We have not appointed a representative in the EU or the UK. You can contact us directly using the details in this policy.
8.4California residents (CCPA)
In the last 12 months we have collected the categories of personal information described in Personal data we collect: identifiers, customer records, commercial information, internet or other electronic network activity, and approximate geolocation derived from IP address. We collect them for the business purposes described in How we use personal data and disclose them only to the service providers and other recipients in Who we share personal data with.
You have the right to:
- know what personal information we collect, use, and disclose, and to receive a copy of it;
- request deletion and correction of personal information;
- opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined in the CCPA, and have not done so in the last 12 months;
- limit the use of sensitive personal information. We only use sensitive personal information (such as account log-in credentials) for purposes permitted without an opt-out; and
- not be discriminated against for exercising any of these rights.
You may use an authorised agent to make a request; we may ask the agent for proof of authorisation and ask you to verify your identity.
8.5How to exercise your rights
Use the account settings in the Service where available, or email legal@assetloom.io. To protect your account, we will verify your identity, usually by asking you to confirm the request while signed in or from the email address on your account. We respond within the period the applicable law requires (for example, one month under the GDPR and 45 days under the CCPA, extendable where the law allows). We will not charge you unless a request is manifestly unfounded or excessive.
9.Deleting your account
When you ask us to delete your account:
- We confirm the request and verify that it comes from you.
- We delete or anonymise your account, profile, and contact details within 30 days, except where we must keep them for the periods in How long we keep personal data.
- Ledger, order, and tax records are retained under our legal obligations but are linked to an anonymised identifier instead of your identity.
- Reviews you posted are removed or anonymised.
- You lose access to your library and any remaining credits. Read the Loom Credits Terms before deleting, as you may be able to request a refund of unused purchased credits first.
Licenses for Assets you have already downloaded continue on their terms, but we can no longer show you your purchase history, so please keep your receipts. Creators should also read the Creator Terms on removing content and earnings.
10.Automated processing
We use automated tools to scan uploads for malware, validate files, compute listing-quality checklists, and flag possible fraud or abuse. Our payment provider also uses automated fraud screening. Decisions that significantly affect you, such as rejecting a listing, suspending an account, or withholding earnings, are reviewed by a person. You can ask for a human review of any decision by contacting support@assetloom.io.
11.Cookies
We use only strictly necessary cookies, mainly to keep you signed in. Our analytics do not use cookies. See the Cookie Policy for details.
12.Children
The Service is not intended for anyone under 18. We do not knowingly process personal data of children (as defined in the DPDP Act, anyone under 18), track them, or target advertising at them. If you believe a child has created an account, contact legal@assetloom.io and we will delete it.
13.Changes to this policy
We will update this policy when our practices change. If a change is material, we will notify you by email or in the Service before it takes effect and, where the law requires, ask for your consent again. The version and “Last updated” date above show the current version.
14.Contact and Grievance Officer
For privacy questions or to exercise your rights, email legal@assetloom.io. Complaints about our processing of personal data may be sent to our Grievance Officer, appointed under the Information Technology Act, 2000, the rules made under it, and the DPDP Act:
Anirudh NegiGrievance OfficerAnirudh NegiFaridabad, Haryana 121006, Indialegal@assetloom.ioWe acknowledge complaints within 24 hours and aim to resolve them within 15 days. Information about the Data Protection Board of India is available from the Ministry of Electronics and Information Technology (opens in a new tab).