Legal
Privacy Policy
Table of contents
01Introduction
This Privacy Policy explains how Loadcurl Pvt Ltd ("Loadcurl," "we," "us," or "our") collects, uses, stores, and protects information when you use our marketing website, documentation, dashboard (app.loadcurl.com), APIs, and related services.
By creating an account, accessing the platform, or using any Loadcurl service, you agree to the practices described in this Privacy Policy.
02Information We Collect
We collect information you provide, information generated by the Service, and limited data from integrated providers (for example Google sign-in).
- Account data: name, email address, hashed password, email verification status, Google account connection when you use Google to sign in
- Workspace data: personal or company organization name and type, membership roles (Owner, Admin, Member), invites
- Billing and wallet: workspace request quota (allotted, available, held, used), ledger entries, and payment records when Razorpay checkout is used (card details are handled by the processor)
- Test data: scenario name, HTTP method, URL, query parameters, headers, JSON body, load configuration, run status, live metrics, and report metrics (latency, throughput, HTTP outcomes)
- Session and device data: device id, device name, device type, browser, user agent, IP address, last used time; we may derive an approximate location from IP for new-session emails
- Technical data on the marketing site: IP address, device/browser details, and analytics cookies as described in the Cookie Policy
03How We Use Information
We use this data to operate Loadcurl, keep accounts secure, and communicate with you.
- Create and maintain your account, personal workspace, and company membership
- Authenticate you (access tokens, refresh tokens, Google ID tokens) and restore sessions
- Run load tests you request and generate reports and PDF downloads
- Enforce organization permissions and test limits
- Send transactional email: email verification, password reset, organization invites, and new-device notices
- Track request-wallet usage at the workspace level
- Detect abuse, unauthorized testing, and fraud
- Improve product quality and respond to support and legal requests
04Legal Bases for Processing
Where required by law (including GDPR), we rely on one or more legal bases:
- Contract performance: to provide the dashboard, tests, reports, and workspaces you request
- Legitimate interests: to secure accounts, prevent abuse, and improve the platform
- Legal obligations: to comply with applicable laws
- Consent: where specifically requested (for example optional marketing or non-essential cookies)
05Cookies and Local Storage
The dashboard sets an HttpOnly refresh_token cookie so we can issue new access tokens without storing the access token in a cookie. Access tokens are held in memory in the browser. A device identifier is stored in local storage (app_device_id) so we can match sessions and revoke other devices.
The marketing site may use analytics cookies. See our Cookie Policy for details. Disabling essential cookies or storage will prevent sign-in from working.
06Data Retention
We retain data only as long as necessary to deliver the Service, meet legal obligations, resolve disputes, and enforce agreements.
- Account and workspace records: while your account is active
- Test configurations, runs, and reports: while the workspace exists and subject to product limits
- Sessions: until they expire, you revoke them, or you change your password (which invalidates sessions)
- Security and audit-style records (for example login IP): retained for abuse prevention
- Deleted accounts: deleted or anonymized within a reasonable period unless law requires retention
07Data Sharing and Disclosures
We do not sell your personal data. We share information only as needed to operate the Service.
- Infrastructure and email providers (hosting, databases, transactional email)
- Google, if you choose Google sign-in (we receive an ID token to authenticate you)
- A public IP geolocation lookup may be used to add approximate location to new-session emails
- Organization Owners and Admins, according to workspace role (members, tests, wallet)
- Payment processors (Razorpay) when you purchase a plan
- Legal authorities when required by law or valid legal process
- Successor entities in a merger, acquisition, or asset sale
08International Transfers
Your data may be processed in countries other than your own, including where our hosting, email, and analytics providers operate. When we transfer personal data internationally, we apply safeguards required by applicable law.
09Security Measures
We use technical and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, or disclosure.
- TLS in transit; hashed passwords; encrypted token storage for refresh and reset tokens
- HttpOnly refresh cookies; access tokens not persisted in cookies
- Role-based organization access (Owner, Admin, Member)
- Session listing and revocation from the dashboard
- Monitoring and logging for suspicious activity
No online service is 100% secure, but we continuously improve our defenses and incident response procedures.
10Your Privacy Rights
Depending on your location, you may have rights regarding your personal data, including access, correction, deletion, portability, and objection or restriction.
You can update profile details, revoke sessions, and leave a company workspace from the dashboard. For other requests, contact us at the email below. We may need to verify your identity.
11Children's Privacy
Loadcurl is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If we learn that we have collected such data, we will delete it promptly.
12Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and provide additional notice where required.
13Contact Us
If you have privacy questions, data requests, or concerns about this policy, contact our Privacy Team.
Loadcurl Pvt Ltd Privacy Team
Email: privacy@loadcurl.io