Last updated: October 2026
Quick note from us
This document explains what data we collect, why we collect it, and what you can do about it. Each section opens with a plain-language summary so children and parents can both follow along. The full text underneath is the legally binding version.
If anything is unclear, write to us at support@loopyty.com. Our Terms explain the rules of using Loopyty. This document is only about data.
Loopyty AS is the "data controller" — that's the legal word for "the company responsible for what happens to your data."
Loopyty AS
Norwegian organisation number: 933 519 708
Parkveien 15C, 0350 Oslo
Email for privacy questions: support@loopyty.com
We follow the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (Personopplysningsloven).
We only collect what we need. Here's the full list — what, why, and the legal reason we're allowed to.
If we ever want to use your data for something not on this list, we'll ask you first.
We don't sell your data. We share it only with companies that help us run Loopyty, and only for that purpose.
We share data with:
These partners are data processors. They follow our instructions and have signed data processing agreements with us as required by GDPR Article 28.
Inside Loopyty, we also share:
We may also share data with:
We do not sell your data to advertisers.
Some of our partners are based outside Europe. When data leaves the EU/EEA, we make sure it's still protected.
Stripe, Google (including Vertex AI, which reads toy photos) and Postmark may process some data in the United States or other countries outside the EU/EEA. Elastic keeps our search index in the EU, but its staff and sub-processors may have limited access from outside it. Heyo, our live-chat provider, keeps chat data in the EU. When data does leave the EU/EEA, we rely on one of the legal mechanisms GDPR allows:
You can ask us for a copy of the safeguards by emailing support@loopyty.com.
Only as long as we need to. Some things we have to keep for tax law; the rest we delete when you do.
When data is no longer needed, we delete it or anonymise it (so it can't be linked back to you).
You're in charge of your data. Here's everything you can ask us to do.
Under GDPR, you have the right to:
To use any of these rights, email support@loopyty.com. We'll respond within 30 days (sometimes sooner). We may ask you to confirm your identity first, so no one else can pretend to be you.
If you think we're handling your data wrongly, you can complain to Datatilsynet (the Norwegian Data Protection Authority) at datatilsynet.no, or to the data protection authority where you live.
The account belongs to a parent or guardian. With a subscription, children get their own login — and we treat their data with extra care.
Accounts are for parents and guardians. You must be 18 or older to open and run a Loopyty account. The account holder is responsible for the children using it.
Children's sub-accounts. With a toy store subscription, the account holder can give each child a sub-account with their own login. That means we process, for each child:
What we never do with children's data. We show a child by first name only, everywhere. We never show a child's surname, address or phone number. We don't share children's information with advertisers, we don't build advertising profiles on children, and children never pay for anything or receive payouts — money always goes through the account holder.
Photos. Please don't upload photos that show identifiable children's faces. A child's hand holding a toy is fine; a clear face shot is not. A child's avatar is a design they make, never a photo.
Article 8 GDPR. Norway sets the age at which a child can consent to digital services at 13. Children on Loopyty always use it under a parent's or guardian's account, and the account holder agrees on their behalf. If we discover an account used by someone under 18 without an account holder, we suspend it and contact the parent or guardian.
Removing a child. Email support@loopyty.com and we delete that child's data — except sales records we must keep by law (section 5).
We use industry-standard security measures. Stripe and Google handle the most sensitive parts.
On our side:
Payments — Stripe. Card numbers and bank details are stored by Stripe, not by us. Stripe is certified to PCI Service Provider Level 1, the highest standard in the payments industry. Card numbers are encrypted with AES-256, and Loopyty never sees your full card number.
Hosting — Google Cloud Platform. GCP is one of the most secure cloud platforms available.
If something goes wrong. If there's a data breach likely to put you at risk, we'll notify Datatilsynet within 72 hours and notify you directly without undue delay, as the GDPR requires.
Some cookies are necessary for Loopyty to work. Others are optional and only run if you say yes.
Necessary cookies keep you logged in, remember your settings, and keep the platform secure. We use these without asking — we have to, for the platform to work.
Children's login. When a child signs in with their PIN, we set a necessary cookie on that device so they stay signed in. It holds no name or PIN — only a session we can check.
Optional cookies help us understand how Loopyty is used so we can improve it. We use Google Analytics and PostHog for this, and we only set these cookies if you've accepted them in our cookie banner. You can change your mind at any time using the “Cookie settings” link in the footer, or by clearing your browser cookies.
Session replay. With your consent, PostHog also records on-screen interactions (clicks, scrolling, navigation) so we can spot problems and improve the experience. Sensitive content — names, addresses, email and payment details — is masked and never recorded, and this data is stored in the EU.
Live chat. With your consent, our chat provider Heyo sets a cookie so a conversation stays with you as you move between pages. The chat doesn't load at all until you've accepted cookies, and it only ever receives what you type into it.
Retention. Most cookies expire within 24 months. Session cookies disappear when you close the browser.
We follow the EU ePrivacy Directive and Norwegian electronic communications law (Ekomloven) on cookies and tracking.
If we change something important, we'll tell you.
We may update this policy from time to time. If a change meaningfully affects your rights or how we use your data, we'll let you know by email or in the app at least 30 days before it takes effect. Smaller wording changes will just be posted here with a new “last updated” date.
Questions about your data? Want to use one of your rights? Write to us.
Loopyty AS
Org. no. 933 519 708
Parkveien 15C, 0350 Oslo
Email: support@loopyty.com
For complaints you'd rather take to a regulator: Datatilsynet — datatilsynet.no.
Thanks for trusting us with your data. We'll look after it.