Privacy Policy

Last updated: 13 July 2026

Your privacy matters to us. This Policy explains what personal data Ownloop handles, why, and the rights you have - under both EU/UK and US privacy laws.

1. Introduction and who we are

This Privacy Policy explains how Gildium, UAB, a company registered in Lithuania under company code 307192563, registered address Polocko g. 17-113, LT-01205 Vilnius, Lithuania ("Ownloop", "we", "us", "our"), collects, uses, shares, and protects personal data, and describes your privacy rights.

It applies to our websites, applications, and services (the "Service"). It supplements our Cookie Policy and, for customers, our Terms of Service and Data Processing Addendum ("DPA").

If you have any questions or wish to exercise your rights, contact us at support@ownloop.io.

2. Our two roles: controller and processor

Ownloop handles personal data in two distinct roles, and it matters which one applies to you:

  • As a controller - for the personal data of our visitors, account holders, and paying customers ("Creators"): account, billing, usage, support, and marketing data. This Policy governs that processing, and we decide the purposes and means.
  • As a processor - for the personal data of Entrants and Subscribers that a Creator collects and manages using the Service ("Subscriber Data"). Here, the Creator is the controller and decides why and how the data is used; we process it on the Creator's behalf and instructions under our DPA. If you are an Entrant or Subscriber and want to exercise rights over your data, please contact the relevant Creator; we will support them in responding.
In short: if you signed up for a Ownloop account, we are the controller of your account data. If you entered a giveaway run by a Creator using Ownloop, that Creator is the controller of your entry data, and we are their processor.

3. Personal data we collect (as controller)

Data you provide

  • Account data: name, email address, password or third-party sign-in identifier (e.g. Google), and profile details.
  • Onboarding data: the platforms, audience, and channels you tell us about when setting up your account.
  • Billing data: plan, transaction history, billing name and address, tax/VAT identifiers, and limited payment metadata. Payments are processed by our third-party payment provider Stripe; card details are collected and processed by Stripe, and we do not store full card numbers (see Section 8).
  • Support and communications: messages, requests, and feedback you send us.

Data we collect automatically

  • Usage and device data: log data, IP address, device and browser type, pages and features used, referring URLs, timestamps, and approximate location derived from IP.
  • Cookies and similar technologies: as described in our Cookie Policy, including Google Tag Manager and Google Analytics, subject to your consent where required.

Data from third parties

We may receive data from sign-in providers (e.g. Google, limited to what you authorise), from Stripe (payment status), and from Connected Channels you link (e.g. Telegram/Discord identifiers needed to provide the Service).

4. Subscriber Data we process on behalf of Creators (as processor)

When a Creator runs a Campaign, we process personal data about Entrants and Subscribers on the Creator's behalf, which may include: name or username, email address, channel identifiers (e.g. a Telegram numeric user ID and, where available, @username, or a Discord handle or ID), entry and verification status, referral attribution, engagement and winner status, consent records, tags, and notes added by the Creator.

Channel-join verification (e.g. Telegram)

Where an Entrant chooses to enter by joining a Creator's Connected Channel, we gather identifiers from that channel to confirm the join actually happened and to attribute it to the entry. For Telegram, when an Entrant authenticates through our verification bot or the Telegram login, Telegram provides us with the Entrant's numeric Telegram user ID (a stable identifier we store as the primary key for that person) and, where the Entrant has set one, their @username (which may be absent and can change, so we treat it as best-effort display only), together with their first name. We use these identifiers solely to verify channel membership, prevent fraudulent or duplicate entries, select and contact winners, and provide the audience the Creator owns. We do not read message content, contacts, or other channel data beyond what is needed for these purposes. This processing is carried out on the Creator's behalf as processor, and the Creator (as controller) is responsible for the notice and consent given to Entrants.

We process this data only to provide the Service to the Creator and on their instructions, as set out in our DPA. The Creator is responsible for the lawful basis, notices, and consents for this data. We do not use Subscriber Data for our own purposes, and we do not sell it. If you are an Entrant/Subscriber, contact the relevant Creator to exercise your rights; we will assist the Creator as required.

5. Why we use your data and our legal bases

As controller, we use personal data for the following purposes and rely on the following legal bases under the GDPR (Article 6):

  • Provide and operate the Service (create your account, deliver features, support you) - *performance of a contract*.
  • Billing and payments (process Subscriptions, prevent failed payments, tax) - *performance of a contract* and *legal obligation*.
  • Secure the Service (authentication, fraud prevention, abuse detection, logging) - *legitimate interests* in protecting the Service and users, and *legal obligation*.
  • Improve and develop the Service (analytics, troubleshooting, product research) - *legitimate interests*, and *consent* for non-essential analytics cookies.
  • Communicate with you (service messages, updates, security notices) - *performance of a contract* and *legitimate interests*.
  • Marketing (newsletters, product news) - *consent* where required, otherwise *legitimate interests*; you can opt out at any time.
  • Comply with law and establish, exercise, or defend legal claims - *legal obligation* and *legitimate interests*.

Where we rely on legitimate interests, we balance them against your rights and you may object (see Section 12). Where we rely on consent, you may withdraw it at any time without affecting prior processing.

6. Marketing communications

We may send you marketing about Ownloop where permitted. You can opt out at any time via the unsubscribe link in our emails or by contacting support@ownloop.io. Service and transactional messages (e.g. billing, security, and account notices) are not marketing and will still be sent while you have an account.

7. Cookies and tracking

We use cookies and similar technologies for essential functionality and, subject to your consent where required, for analytics. Outside regions requiring prior consent we may set analytics cookies by default; within such regions we ask for consent first and default to denying non-essential storage. You can manage your choices at any time via the Cookie Settings link in the footer. See our Cookie Policy for details.

8. How we share personal data

We do not sell your personal data. We share it only as follows:

  • Service providers / sub-processors who process data on our behalf under contract, including: Stripe (payments), cloud hosting and infrastructure providers, Google (Tag Manager / Analytics), email/communications providers, and support and logging tools. A current list of sub-processors is available on request.
  • Connected Channels you link (e.g. Telegram, Discord, email providers), to the extent needed to provide the Service you have configured.
  • Professional advisers (legal, accounting, audit) under confidentiality.
  • Authorities and others where required by law, regulation, legal process, or to protect our rights, users, or the public, or to prevent fraud or harm.
  • Corporate transactions - in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and to this Policy.

We require our sub-processors to protect personal data and to process it only on our instructions. For Subscriber Data, our sub-processors act under the DPA between us and the Creator.

Payments (Stripe)

We use Stripe as our third-party payment provider to process payments. When you pay for the Service, your payment-method details (including card data) are provided directly to and processed by Stripe in a PCI-DSS-compliant environment; we do not receive or store full card numbers. In respect of that payment data, Stripe acts as an independent controller for its own payment-processing, fraud-prevention, and legal-compliance purposes, and its processing is governed by Stripe's privacy policy (stripe.com/privacy). We receive from Stripe only limited billing metadata (such as card type, last four digits, expiry, and transaction/subscription status), which we process as a controller to manage your Subscription. For EU/EEA customers, the relevant Stripe entity is Stripe Payments Europe, Ltd.

9. International data transfers

We are based in the EU. Some of our providers may process data outside the EU/EEA (including the United States). Where we transfer personal data to a country without an EU adequacy decision, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses, and, for the UK, the UK Addendum/IDTA, together with supplementary measures where needed. You can request more information about these safeguards at support@ownloop.io.

10. Data retention

We keep personal data only as long as necessary for the purposes described, including to provide the Service, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Account and usage data are generally retained for the life of your account and for a reasonable period afterwards; billing records are retained for the periods required by law. When no longer needed, we delete or anonymise data. Retention of Subscriber Data is determined by the Creator under the DPA; note that some in-product deletions are "soft" deletions that retain a record until the account is closed.

11. How we protect your data

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, authentication, network protection, logging, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential. If a personal-data breach is likely to result in a risk to your rights, we will notify affected parties and authorities as required by law.

12. Your rights (EU/EEA and UK)

If the GDPR or UK GDPR applies to you, you have the right, subject to conditions and exemptions, to:

  • access your personal data and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • restrict or object to processing, including processing based on legitimate interests and direct marketing;
  • data portability - receive your data in a structured, machine-readable format;
  • withdraw consent at any time where we rely on consent; and
  • not be subject to solely automated decisions with legal or similarly significant effects (we do not carry out such decision-making).

To exercise these rights, contact support@ownloop.io. We will respond within the timeframes required by law and may need to verify your identity. You also have the right to lodge a complaint with your local supervisory authority. Our lead authority is the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija, VDAI), L. Sapiegos g. 17, Vilnius, https://vdai.lrv.lt.

If you are an Entrant or Subscriber, direct your request to the Creator who ran the Campaign (the controller of your data); we will assist them as their processor.

13. Your rights (United States)

Depending on your state of residence (e.g. California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws), you may have the right to: know/access the categories and specific pieces of personal information we collect; delete and correct your personal information; opt out of "sale" or "sharing" of personal information and of targeted advertising; limit use of sensitive personal information; and not be discriminated against for exercising your rights.

We do not "sell" personal information and do not "share" it for cross-context behavioural advertising as those terms are defined under California law, and we do not knowingly process sensitive personal information for such purposes. We collect the categories of personal data described in Sections 3–4 (identifiers, commercial/billing information, internet/usage activity, and inferences), use them for the business purposes in Section 5, and disclose them to the service providers in Section 8.

California residents may also request information under the "Shine the Light" law. To exercise any US privacy right, contact support@ownloop.io; you may use an authorised agent where permitted. We will not discriminate against you for exercising your rights, and we will verify requests as required by law.

14. Children's privacy

The Service is intended for users aged 18 and over and is not directed to children. We do not knowingly collect personal data from children. Creators must not use the Service to knowingly collect data from children below the applicable age of digital consent (16 in many EU countries, subject to national law; 13 under US COPPA) without required parental consent. If you believe a child has provided us personal data, contact support@ownloop.io and we will take appropriate steps.

15. Automated decision-making

We do not use your personal data for solely automated decision-making that produces legal or similarly significant effects on you. Some features (such as fraud/abuse detection and analytics) use automated processing to support, but not solely determine, decisions.

16. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice where required. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

17. Contact and how to exercise your rights

Controller: Gildium, UAB, Polocko g. 17-113, LT-01205 Vilnius, Lithuania (company code 307192563).

Privacy / data-protection contact: support@ownloop.io

General support: support@ownloop.io · Website: ownloop.io

Supervisory authority: State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija, VDAI), L. Sapiegos g. 17, Vilnius, https://vdai.lrv.lt.

Questions about this document? Contact us at support@ownloop.io.