Plain English summary: I don't sell your data. I don't run ad tracking. I collect only what you give me through the contact form, use it to reply to you, and delete it when our project ends. If you want anything removed at any point, use the contact form and I'll handle it within 48 hours.
1. Who this applies to
This Privacy Policy describes how Lofts Studio ("we", "I", "us") collects, uses, and protects the information of visitors and clients ("you") of lofts.studio and related project communications.
2. What information I collect
Information you give me directly
- Contact form data — your full name, business email, website URL, and the bottleneck dropdown selection you submit.
- Project communication — emails, Loom recordings, Slack messages, and Upwork conversations exchanged during a project.
- Payment information — handled entirely by Upwork. I never see or store your card or bank details.
Information collected automatically
- Minimal server logs — IP address, browser type, and pages viewed. Used only to monitor for abuse and improve the site. Retained for 30 days, then deleted.
- No advertising cookies, no tracking pixels. This site does not run Meta Pixel, Google Ads tags, Hotjar, or any third-party retargeting.
Third-party services I use
- Google Fonts — fonts are served from Google's CDN. Per Google's policy, IP addresses are not logged for Fonts requests.
- Upwork — when you engage me as a client, our contract and communication may flow through Upwork, governed by Upwork's privacy policy.
3. How I use your information
- To reply to your inquiry and provide the strategy call you requested.
- To deliver the project we agreed on, if you become a client.
- To send transactional emails related to active projects (status updates, invoices, deliverables).
- I do not sell, rent, lease, or share your information with third parties for marketing.
4. Your rights
If you are in the UK, EU, or California, you have the following rights regarding your personal data:
- Right of access — request a copy of the information I hold about you.
- Right to rectification — correct any inaccurate information.
- Right to erasure — ask me to delete your information ("right to be forgotten").
- Right to object — opt out of any processing.
- Right to data portability — receive your data in a structured, machine-readable format.
To exercise any of these rights, email the contact form on the homepage. I'll respond within 48 hours and complete reasonable requests within 30 days.
5. Data retention
- Contact form leads that don't become projects: deleted within 90 days.
- Active project files: retained for the duration of the project + 12 months after delivery, for support and reference.
- Completed project archives: retained for 5 years for tax and contract purposes, then permanently deleted.
6. Security
I take reasonable measures to protect your information, including: encrypted email transit (TLS), password-managed credentials, two-factor authentication on all platforms I use, and minimum-necessary data collection. That said: no method of internet transmission is 100% secure. I disclaim warranties of absolute security.
7. Children's privacy
This site is not directed at children under 16. I do not knowingly collect data from anyone under 16. If you believe a child has provided me information, contact me and I will delete it promptly.
8. International transfers
I am based in Pakistan; data you submit will be processed and stored in Pakistan and (via Upwork) in the United States. By contacting me, you consent to this transfer. Standard contractual safeguards apply where required by GDPR.
9. Changes to this policy
I may update this policy from time to time. Material changes will be reflected on this page with an updated "Last updated" date. Continued use of the site after changes constitutes acceptance.
10. Contact
Questions about this policy or your data:
Email: the contact form on the homepage
Mailing address: Lofts Studio, [Street Address], Multan, 60000, Pakistan
Note: This Privacy Policy is provided as a starting point and reflects current practices honestly. It is not legal advice. Before relying on it for compliance with CCPA, GDPR, UK GDPR, or any other regulation, have a qualified attorney in your jurisdiction review it.