Plain-language summary
- LootCalc has no user accounts, password database, checkout, or player-account connection.
- Calculator inputs normally stay in browser state. Using a copy-link feature places selected values in the URL.
- A visited or shared URL, including its query string, can appear in CDN/origin logs and configured analytics. Do not put personal or secret information in calculator labels or URLs.
- Advertising code is gated by a deployment switch. When it is off, LootCalc does not request Google ad content.
Information processed
Infrastructure serving a request can process the IP address, timestamp, requested path and query, referrer, user agent, response status, and security signals. These fields are used to deliver the site, prevent abuse, investigate failures, and maintain availability.
When a Google Analytics ID is configured, LootCalc sends page-view and feature events. Google Consent Mode defaults analytics storage to denied for EEA, UK, and Swiss visitors until consent is received. Other regions use the deployment's configured Analytics behavior. LootCalc does not intentionally send names, email addresses, or calculator free-text labels as Analytics event parameters.
If you email an address on the contact page, the message and its metadata are processed by the sender's and recipient's email providers. There is no web contact form on LootCalc.
Service providers and processing roles
The following integrations are present in the current code or delivery path. A conditional service does not necessarily receive every visit.
| Provider | Purpose and activation | Typical data categories |
|---|---|---|
| Cloudflare | DNS, CDN/security controls, and delivery of static image assets from R2. | Request IP address, headers, requested URL, security signals, and asset requests. |
| Google Analytics 4 | Configured traffic and feature-usage measurement. | Page URL and title, events, browser/device information, and location derived at a coarse level. |
| Sentry | Server/edge error diagnosis; the browser SDK is loaded only after an unhandled client error when a DSN is configured. | Error and stack details plus relevant request, runtime, release, and device context. |
| Google AdSense and Funding Choices | Advertising and consent messages only when advertising is explicitly enabled. | Google may use cookies, web beacons, IP addresses, and other identifiers as described in its publisher policies. |
When a provider processes personal data on LootCalc's behalf, the applicable account agreement may incorporate processor, subprocessor, transfer, and security terms. Other features—especially advertising—may give a provider a separate controller role. The role depends on the enabled product, region, and account configuration; it is not inferred from the provider name alone. See the currentCloudflare Data Processing Addendum,Sentry Data Processing Addendum, andGoogle's product-role and data-protection terms index.
The identity and retention settings of the current origin-hosting account are deployment controls rather than facts contained in this repository. They must be verified in the hosting dashboard and kept aligned with this policy.
Cookies, consent, and advertising
LootCalc does not use an account-session cookie. Special ad-diagnostic URLs can set short-livedads_off or ads_test preference cookies; ordinary calculator use does not require them. Analytics, consent, or advertising providers may use cookies or similar storage according to the consent state and their policies.
If AdSense is enabled, Google and participating vendors may place or read cookies or use web beacons, IP addresses, and other identifiers in connection with ad delivery and measurement. Google documents these requirements in its publisher privacy policy and explains partner-site processing on Google's partner-sites page.
Where a Funding Choices message is active, use it to grant, refuse, or revisit applicable choices. You can also manage Google ad personalization through Google Ads Settings.
Purpose, legal basis, and retention
Request and security data is processed to operate and protect the service. Analytics is used to understand aggregate traffic and tool use; consent is requested where required. Advertising processing applies only after the advertising integration is enabled and remains subject to regional consent and opt-out requirements.
Retention is controlled in the relevant provider accounts. Google Analytics, for example, exposes separate user/event retention controls; aggregated reports can follow different rules. Cloudflare, Sentry, the origin host, and email providers apply their configured plans and account settings. LootCalc does not claim one universal retention period that the code cannot enforce.
Choices, rights, and security
Depending on your location, applicable law may provide rights to access, correct, delete, restrict, or object to processing, and to appeal or complain to a regulator. Send a request toprivacy [at] lootcalc.com with enough context to locate the relevant record. Identity or email ownership may need to be verified. Requests are handled within the period required by applicable law rather than a shorter unsupported promise.
LootCalc does not sell contact details. Enabling personalized advertising can fall within broader statutory definitions of sharing or targeted advertising in some jurisdictions; available consent and opt-out controls should be used where applicable.
The production site is intended to use HTTPS. No online service can promise absolute security. Please report a suspected vulnerability through the non-destructive process on the contact page.
Children and policy changes
LootCalc is a general-audience utility and is not directed to children under 13 or the higher minimum age required in a visitor's jurisdiction. Material changes to providers or data flow should update this page and its date before or when the changed processing begins.