Legal information

Public beta 2026-07-22 · Effective July 22, 2026

Privacy & Data Treatment

Julian David Mora, a natural person based in Huila, Colombia, is the operator responsible for the personal data handled directly by Loomca within this beta. Privacy requests go to anlijudavid+support@protonmail.com.

1. Who and what this policy covers

This policy applies to Merchant owners or representatives, Buyer Users, support contacts, and identifiable operators of Agents when they interact with Loomca. A Merchant applies its own privacy terms when a Buyer User continues in that Merchant's Shopify checkout.

2. Data handled by the beta

  • Account and authentication data, including email address, session information, and internal user identifiers.
  • Merchant contact and representation data, Merchant Profile, Merchant Connection, Shopify domain, and operational configuration.
  • Merchant credentials or secrets entered through the protected connection surface. These are not shown in public diagnostics.
  • Merchant catalog information and other information the Merchant makes available for product discovery.
  • Approval Links, selected products, decisions, Validation Snapshots, Checkout Sessions, Purchase Timeline, and order evidence.
  • Merchant Diagnostic Logs limited to Safe Diagnostic Detail and security or audit events.
  • Information voluntarily included in support, privacy, complaint, or security emails.

Loomca does not receive or store raw card numbers or other raw payment credentials. The Buyer User enters payment details in the Merchant's Shopify checkout.

3. Sources and purposes

Data comes from the person using the beta, a compatible Agent, the Merchant and its Shopify connection, authentication services, and records generated while operating Approval Links and checkout handoffs.

It is used to:

  • authenticate users and protect accounts;
  • register, verify, operate, and close Merchant Connections;
  • discover eligible products and prepare, revalidate, approve, cancel, and track Approval Links;
  • maintain material checkout and audit evidence;
  • diagnose incidents and keep the service secure;
  • answer support, privacy, complaint, security, and legally valid requests.

Login and onboarding data are not used for marketing unless a separate decision and authorization are introduced when required.

4. Service providers and international processing

The current implementation uses service providers for hosting, authentication and database infrastructure, and Shopify connectivity. This includes Vercel, Supabase, and Shopify in their relevant roles. Proton Mail is used for the operator's email channel. Those providers may process information in other countries according to their infrastructure and terms.

The exact legal characterization of national or international transfers and transmissions, the parties' treatment roles, and any additional contractual safeguards are pending legal and implementation review.

5. Retention and Merchant closure

Personal data is kept only as long as needed for the purposes described, platform security, applicable obligations, and material historical evidence. Fixed retention periods have not yet been published and must be defined after the implementation inventory and legal review.

When a Merchant closes its participation, Loomca revokes and destroys credentials and sensitive connection configuration while retaining only the limited, non-secret evidence required for traceability, security, applicable obligations, Approval Links, and checkout outcomes. Data is deleted or anonymized when appropriate; past facts are not reconstructed from current Merchant state.

6. Security

Loomca applies access controls, separation of Merchant secrets, input validation, safe diagnostic output, and audit-oriented records appropriate to the beta. No statement on this page represents a security certification or a guarantee that incidents cannot occur. Do not send passwords, tokens, payment credentials, or unnecessary identity documents by email.

7. Your rights and requests

Subject to applicable law, a data subject may request consultation, access, updating, correction, deletion, or revocation of an authorization when applicable, and may ask how their data is used. Some evidence may need to be preserved for legal, security, or historical purposes.

Email anlijudavid+support@protonmail.com with enough information to identify the relevant account or event and the request. Do not send unnecessary sensitive data. Identity may need to be verified before acting on a request. Valid requests from competent authorities will be handled as required by law.

8. Changes

Material changes will be communicated through an appropriate product or email notice before they become applicable when required. The current version and effective date appear at the top of this page.