Last updated: July 18, 2026
Privacy Policy
Protecting your personal data is important to us. This Privacy Policy explains how we process personal data when you use the Loothero platform at https://loothero.io and related services (including admin support where personal data is involved).
The German version of this Privacy Policy is binding. Translations (including this English text) are provided for convenience only. In case of any conflict or ambiguity, the German version prevails.
1. Privacy at a Glance
General information
The following notes provide a simple overview of what happens to your personal data when you use this website/platform. Personal data means any data that can identify you personally. Detailed information is set out in the sections below.
Who is responsible for data collection?
Data processing is carried out by the website operator. Contact details are listed under “Controller”.
How do we collect your data?
Some data is provided by you (e.g. registration, support, withdrawals, KYC). Other data is collected automatically or after your consent when you visit the website (e.g. browser, operating system, IP address, time of access).
What do we use your data for?
Some data is collected to ensure the platform works correctly. We also process data to perform the contract (account, offers, payouts, affiliate), for communication, fraud prevention, and where required to comply with legal obligations.
What rights do you have?
You have the right to obtain free information about the origin, recipients and purpose of your stored personal data, and to request rectification or erasure. You may withdraw consent at any time with effect for the future. Under certain conditions you may request restriction of processing. You also have the right to lodge a complaint with a supervisory authority. You can contact us at any time regarding these rights.
2. Controller
The controller responsible for data processing on this website is:
Nico Ghazal
Gut-Heim-Straße 3
67657 Kaiserslautern
Email: support@loothero.io
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of processing personal data.
3. Hosting and Infrastructure
This website/platform is hosted externally. Personal data collected on the platform is stored on the servers of the providers listed below. This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access data and other data generated via the platform.
External hosting is based on performance of the contract with our users (Art. 6(1)(b) GDPR) and our legitimate interest in a secure, fast and efficient provision of our online offering (Art. 6(1)(f) GDPR). Where consent is requested (e.g. cookies / device fingerprinting under the TDDDG), processing is also based on Art. 6(1)(a) GDPR and § 25(1) TDDDG; consent may be withdrawn at any time.
We use in particular:
- Vercel Inc., 340 S. Lemon Ave #4133, Walnut, CA 91789, USA — web application hosting
- Supabase Inc., USA — database, authentication, storage, realtime and edge functions
- Cloudflare, Inc., USA — CDN, DNS, DDoS/security and performance protection (processing of IP addresses and connection data when the website is accessed)
Where required, we have concluded data processing agreements with processors and/or use appropriate safeguards (in particular Standard Contractual Clauses) for transfers to third countries.
4. General Information and Mandatory Disclosures
Data protection
We treat your personal data confidentially and in accordance with statutory data protection rules and this Privacy Policy. Data transmission on the internet may have security gaps; complete protection against access by third parties is not possible.
Retention period
Unless a more specific retention period is stated in this Privacy Policy, your personal data remains with us until the purpose for processing no longer applies. If you submit a legitimate erasure request or withdraw consent, data will be deleted unless other legally permissible grounds for retention exist (e.g. commercial or tax retention periods).
- Account data: for the duration of membership; deleted after account deletion unless retention obligations apply
- Transaction and payout data: up to 10 years where commercial/tax law applies
- Server/access logs: generally no more than 90 days
- Fraud/security events: as long as necessary for abuse prevention and legal defence
Legal bases
Where applicable, we rely in particular on:
- Art. 6(1)(a) GDPR / where relevant § 25(1) TDDDG — consent (e.g. optional cookies)
- Art. 6(1)(b) GDPR — performance of a contract / pre-contractual steps (account, offers, payouts, affiliate)
- Art. 6(1)(c) GDPR — legal obligation
- Art. 6(1)(f) GDPR — legitimate interests (IT security, fraud prevention, technical operation)
Recipients of personal data
We disclose personal data only where necessary for contract performance, where we are legally obliged, where a legitimate interest exists, or where another legal basis applies. Transfers to processors are based on a valid data processing agreement.
Withdrawal of consent
You may withdraw consent at any time. The lawfulness of processing carried out before withdrawal remains unaffected.
Right to object (Art. 21 GDPR)
WHERE PROCESSING IS BASED ON ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE DATA CONCERNED UNLESS WE DEMONSTRATE COMPELLING LEGITIMATE GROUNDS THAT OVERRIDE YOUR INTERESTS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS.
WHERE YOUR DATA IS PROCESSED FOR DIRECT MARKETING, YOU MAY OBJECT AT ANY TIME; THEREAFTER THE DATA WILL NO LONGER BE USED FOR DIRECT MARKETING. We currently do not operate classic third-party advertising pixel tracking for direct marketing.
Further data subject rights
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights: support@loothero.io. We will process requests promptly, within one month at the latest.
SSL/TLS encryption
This site uses SSL/TLS encryption for security. An encrypted connection is indicated by “https://” and the padlock icon in your browser.
5. Types of Data Processed and Purposes
We process in particular:
- Master data: username, email address, profile picture, country, preferred language
- Authentication data: login credentials, OAuth identifiers (e.g. Google), session information
- Account and usage data: point balance, transactions, offers/tasks/surveys, withdrawals, guides, notifications, support tickets and messages
- Affiliate/referral data: referral codes, attributed referred users, commission/wallet data
- KYC data: status and technical reference of identity verification (document/identity checks via Stripe Identity)
- Fraud/security data: IP address, device/browser fingerprint (generated locally), risk scores, VPN/proxy indicators
- Technical data: browser, device, access time, referrer, cookies, geo country (from IP/CDN headers)
- Payout data: e.g. crypto wallet addresses and transaction-related data
- Optional survey profiler data: demographic details (e.g. age/date of birth, postal code, gender, employment status) where you submit them to partners
Purposes include:
- Providing and operating the platform
- Registration, authentication, account management
- Processing offers, surveys, point credits and payouts
- Affiliate/referral and guide systems
- Support and system communication
- Fraud prevention, abuse detection, security
- Legal obligations (e.g. retention)
6. Affiliate and Referral Programme
Loothero operates an affiliate/referral programme. If you arrive via a referral link (e.g. the ref parameter), we store the code in a cookie (lh_ref, typically 30 days) to attribute the registration. After attribution, we process data about referred users and resulting commissions for contract performance (Art. 6(1)(b) GDPR) and/or our legitimate interest in operating the partner programme (Art. 6(1)(f) GDPR).
7. Third-Party Providers and International Transfers
For transfers to third countries (particularly the USA), we ensure an adequate level of protection through adequacy decisions where applicable (e.g. EU-US Data Privacy Framework) and/or Standard Contractual Clauses (Art. 46 GDPR).
Supabase (database & authentication)
Provider: Supabase Inc., USA. Storage of user accounts, authentication, platform data, storage (e.g. guide images), realtime. Privacy policy: supabase.com/privacy
Vercel (hosting)
Provider: Vercel Inc., USA. Hosting and delivery of the web application; IP addresses and request metadata may be processed. Privacy policy: vercel.com/legal/privacy-policy
Cloudflare (CDN & security)
Provider: Cloudflare, Inc., USA. CDN, DNS, attack protection and performance. In particular, IP addresses and connection data are processed. Privacy policy: cloudflare.com/privacypolicy
Google (OAuth login)
When signing in with Google, identity data (e.g. email, name, profile image URL, Google account ID) is obtained via Supabase Auth from Google. Provider: Google LLC, USA. Privacy policy: policies.google.com/privacy
Stripe Identity (KYC / identity verification)
For identity verification (e.g. before the first withdrawal) we use Stripe Identity (Stripe, Inc. / Stripe Payments Europe, as applicable). Identity documents and biometric verification data may be processed directly by Stripe; we typically store verification status and technical session references. Legal basis: Art. 6(1)(b) GDPR and, where applicable, Art. 6(1)(f) GDPR (fraud prevention). Privacy policy: stripe.com/privacy
IPQualityScore (IP risk checks)
To detect VPN/proxy/Tor and abuse, we check the IP address via IPQualityScore. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in fraud prevention). Privacy policy: ipqualityscore.com/privacy-policy
Device fingerprinting (FingerprintJS, open source)
For abuse detection we generate a device/browser fingerprint in the browser using the open-source FingerprintJS library. The hash and technical device information are stored by us. This is not the FingerprintJS Pro cloud service. Legal basis: Art. 6(1)(f) GDPR; where access to terminal equipment information requires consent under § 25(1) TDDDG, also on that basis.
NOWPayments (crypto payouts)
Processing of cryptocurrency payouts. Wallet addresses and transaction-related data are processed in particular. Privacy policy: nowpayments.io/privacy-policy
Offerwall, survey and partner networks
To provide offers and surveys we integrate partners via API and/or iframe and/or receive conversion postbacks. Typically a technical user identifier (e.g. user ID), IP address, user agent, geo country, offer/event data and, where applicable, information you enter in partner forms are transmitted. Partners may set their own cookies and tracking technologies once their content is loaded. Legal basis: Art. 6(1)(b) GDPR (contract performance) and/or Art. 6(1)(f) GDPR (technical operation / abuse prevention); for optional profiler answers, consent where applicable.
Partners used or connected include in particular:
- ayeT-Studios (offers, surveys, profiler)
- GemiAd / GemiWall (offers)
- Adtowall (offers)
- TheoremReach (surveys / profiler)
- AdGem, MM Wall, Plarium Play (where connected via postbacks)
Please also review the privacy policies of the respective partners when you start their offers.
Geo and utility services
To determine country we may use IP-based geo services (e.g. via CDN/hosting headers and fallbacks such as ipapi.co / ip-api.com). Exchange rates may be fetched via services such as Frankfurter (no personal data). Loading UI assets (e.g. flag or icon CDNs) may involve IP addresses being processed by the respective CDN.
Email delivery
Transactional and authentication emails may be sent via Supabase Auth email infrastructure or the SMTP provider configured there. Support and operational emails may be sent or received via Google Workspace (Google LLC, USA) and via Resend (Resend, Inc., USA; in particular notifications from the admin area). Email address and message content are processed. Google privacy: policies.google.com/privacy; Resend: resend.com/legal/privacy-policy.
Payouts
Withdrawals are currently processed exclusively via NOWPayments (crypto). Other payout methods (e.g. PayPal or gift cards) are not currently offered as active payment channels; if added later, this Privacy Policy will be updated accordingly.
8. Cookies and Similar Technologies
Our pages use cookies and similar technologies. Cookies are small data packets and do not harm your device. Session cookies are deleted after your visit; persistent cookies remain until you delete them or the browser removes them.
- Necessary cookies: including session/auth (including Supabase
sb-*cookies), consent (loothero_consent), language (loothero_locale), referral (lh_ref). Legal basis: Art. 6(1)(b) or (f) GDPR. - Functional cookies: e.g. theme (
loothero_theme) — only after opt-in (Art. 6(1)(a) GDPR / § 25(1) TDDDG). - Analytics / advertising cookies: Google Tag Manager (
GTM-MDT8D3HF) is loaded to measure site usage and paid advertising conversions. Tags enabled in GTM may set additional cookies from Google or ad partners (Art. 6(1)(f) GDPR — legitimate interest in measuring advertising effectiveness; where required under § 25 TDDDG, storage/access may also rely on our disclosed use of the Tag Manager for this purpose).
Details and management: Cookie Settings in the footer and https://loothero.io/cookies. We typically store consent for 365 days.
Session duration (login)
Logged-in users receive a session of up to 30 days of inactivity (sliding expiration). After 30 days without activity the session ends automatically.
9. Contact by Email
If you contact us by email, your enquiry and resulting personal data are stored and processed to handle your request. Legal basis: Art. 6(1)(b) GDPR (where contract-related) or Art. 6(1)(f) GDPR (efficient handling) or consent. Data remains until the purpose ends or you request deletion, subject to statutory retention obligations.
10. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority — in particular at your habitual residence, place of work or the place of the alleged infringement.
For the controller’s seat in Rhineland-Palatinate, the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate is competent in particular. Overview of authorities: bfdi.bund.de
11. Data Security
- Encrypted transmission via SSL/TLS (HTTPS)
- Access controls and role-based permissions
- Authentication via Supabase Auth
- Row Level Security (RLS) in the database
- Fraud and abuse prevention measures
12. Obligation to Provide Data / Minors
Providing certain personal data is required for registration and use. Without this data we cannot provide the services.
Loothero is intended for persons aged 18 or older, or the legal minimum age in the respective country. We do not knowingly collect data from minors; such accounts will be deleted once we become aware of them.
13. Updates
This Privacy Policy is current as of 18 July 2026. The current version is always available at https://loothero.io/privacy.
