Last updated: August 18, 2026
Lootvm operates the Lootvm webhook orchestration service and related features such as publishing content to social platforms you connect, managing Meta ads you authorize, and handling Page, Instagram, and WhatsApp messages. For privacy questions or data requests, contact us at [email protected] or +62 814 1092 9492.
We process account data such as name and email for authentication, workspace membership, invitations, and product communications you request. Usage metrics (events, runs, deliveries) support billing, quotas, and reliability.
Webhook payloads you forward through Sources may include personal data from your systems. You are the controller of that content; we process it to deliver the orchestration features you configure. You should only send data you are entitled to process.
If you connect a Facebook Page, Instagram professional account, Threads profile, Meta ad account, or WhatsApp Business asset, we process data from Meta’s APIs that you authorize: account and Page identifiers, names, tasks, encrypted access tokens, content you compose, platform post IDs, ad account and campaign identifiers and performance metrics, and the contents of messages or comments you send or receive through Lootvm (Page Messenger, Instagram DMs/comments, WhatsApp). We use this only to connect accounts, publish or manage content, run or measure ads, operate inbox features you request, and show status in your workspace. We do not sell Graph data or use message contents to advertise to other people.
Secrets (source tokens, destination secrets, API keys, and Meta Page/user/Threads tokens) are stored hashed or encrypted at rest. Access tokens are not sent to the browser. Access is scoped to your workspace. We apply technical and organizational measures appropriate to a cloud SaaS product, including transport encryption and tenant isolation controls.
We use Better Auth (and Google OAuth when enabled) for authentication; Postgres for application data; Redis for queues and caching; Cloudflare R2 for payload archives and media you upload to publish; Xendit when you subscribe to a paid Lootvm plan; and Meta (Facebook, Instagram, Threads, Marketing API, Messenger, WhatsApp Cloud API) when you connect those products. The public marketing homepage may load Facebook’s JavaScript SDK (cookies and App Events page views) so Meta can recognize the Login product for this site; Graph access tokens are not sent to the browser. Providers process data only as needed to run the service.
Account and workspace data are kept while your account is active. Usage and delivery metrics are retained for billing, quotas, and operational history. Archived payloads follow product retention settings and operational needs. Connected social tokens are kept while the connection is active and removed or revoked when you disconnect or we complete a verified deletion request. You may request deletion as described below.
You may request access, correction, or deletion of your account, workspace, and Meta platform data by contacting [email protected] or +62 814 1092 9492, or by using the Data deletion page linked in this legal section. We will verify the request and respond within a reasonable time. Disconnecting Meta or deleting Graph-derived records does not delete unrelated tenant webhook events (for example payment provider webhooks). Deleting a workspace removes associated configuration and, subject to legal or billing retention, related records.
For privacy requests, contact us at [email protected] · +62 814 1092 9492