Privacy Policy
Effective May 10, 2026
This Privacy Policy explains how Loom (“Loom”, “we”, “us”, or “our”) collects, uses, stores, and shares information when you use the website at loom.mn and related services (the “Service”). Loom is a marketplace that connects independent creators with brands for sponsorship campaigns.
By using the Service you agree to the practices described here. If you do not agree, do not use the Service.
Information we collect
We collect only what we need to run the Service and provide the features you ask for.
- Account information — name, email address, password hash, role (creator or brand), and basic profile details you provide.
- Profile content — the public-facing page you build on Loom, including bio, links, products, uploaded images, and any other content you choose to publish.
- Connected accounts — data we receive from third-party platforms you link to your Loom account, such as TikTok, Instagram, and YouTube. See the section below for specifics.
- Communications — messages you exchange with brands or creators on the Service, and any correspondence you send to Loom support.
- Usage and device data — IP address, browser type, pages viewed, and basic interaction events used to operate, secure, and improve the Service.
TikTok account data
When you connect your TikTok account to Loom via TikTok’s Login Kit, we collect the following from your TikTok profile with your explicit consent at the OAuth consent screen:
- Your TikTok user identifier (
open_id), avatar, display name, username, bio, profile link, and verification status (user.info.basic,user.info.profile). - Your follower count, following count, total likes count, and total video count (
user.info.stats). - Metadata for your most recent public videos: title, cover image, view, like, comment and share counts, and embed link (
video.list).
This data is stored in our encrypted Postgres database and is used solely to display your TikTok presence on your public Loom profile so brands can evaluate you for sponsorship campaigns. All access is read-only. We do not post to your TikTok account, modify or delete your content, contact your followers, or share your TikTok data with third parties.
You can disconnect your TikTok account at any time from your Loom settings. When you disconnect, we revoke our access token via TikTok’s /v2/oauth/revoke/ endpoint and delete the cached profile and video data within 24 hours.
How we use information
- To provide, operate, and improve the Service.
- To display your public Loom profile and connected-account content to visitors and brands.
- To match creators with relevant campaigns and let brands evaluate creators for sponsorship.
- To authenticate you, secure the Service, and prevent fraud, abuse, or unlawful use.
- To respond to support requests and send service-related notifications.
- To comply with legal obligations and enforce our Terms of Service.
Data storage and security
Data is stored in an encrypted managed Postgres database hosted on industry-standard cloud infrastructure. Access tokens for connected third-party accounts are encrypted at rest. We use HTTPS for all traffic and apply role-based access controls on the server side. No system is perfectly secure; you use the Service at your own risk.
Data retention
We retain account information for as long as your account is active. When you delete your account, we delete or anonymize your personal information within 30 days, subject to legal retention requirements (for example, financial records required for tax purposes). Cached third-party data from a disconnected integration is deleted within 24 hours.
Your rights and choices
- You can update or remove profile information at any time from your Loom settings.
- You can disconnect any linked third-party account from your Loom settings, which revokes our access and triggers deletion of cached data from that integration.
- You can request a copy of your personal information or request that we delete your account by emailing support@loom.mn. Depending on your jurisdiction, you may have additional rights under applicable law, such as the right to access, correct, port, or restrict the processing of your data.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under that age. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Effective” date at the top of this page and, if the changes are material, notify you through the Service or by email.
Contact us
Questions about this Privacy Policy or our data practices? Email support@loom.mn.