Last updated 29 July 2026
Privacy, in plain language.
This notice explains what PDFLoom Business collects, why it is needed, where it is stored, and how you can exercise your data rights.
Data we collect and why
For account access, we use your email address to send a one-time sign-in link and maintain a secure session. To provide your workspace, we store the business profile fields you enter, customer and recipient details, invoice metadata, generated PDFs, payment status, usage counts, and any logos or custom designs you upload. We process these items only to generate, save, organize, retrieve, and bill for the services you request.
Guest document data
Guest PDFs are generated in the browser and downloaded directly. PDFLoom stores an anonymous usage identifier in a secure cookie so the two-document guest allowance can be enforced.
Account and business data
When you request a sign-in link, PDFLoom uses your email only for authentication and account communications. New customers receive an account after opening the verified link. No ChatGPT or other third-party social account is required.
Private files
Saved PDFs and uploaded templates are stored in private object storage. File access routes check the signed-in account before returning a document or design. Customers should avoid uploading information they are not authorized to process.
Existing PDF files
For PDF Tools marked as locally available, processing happens inside your browser. Your browser may keep ordinary temporary data while a tool runs; closing the tab clears that working session.
Usage and billing
PDFLoom counts signed-in monthly document generations to enforce plan limits. When paid checkout is enabled, payment details are collected by the payment provider rather than PDFLoom; PDFLoom stores customer and subscription identifiers, plan, cycle, and subscription status.
Service providers
Cloudflare infrastructure is used for hosting, database storage, and private file storage. The configured email delivery provider sends one-time login messages. The configured payment provider handles card and billing information. These providers receive only the data needed to perform their service.
Security
Sign-in links are single-use and expire after 15 minutes. Session cookies are HttpOnly, Secure, and SameSite protected. Login tokens are stored as cryptographic hashes, files are served only after account checks, and billing webhooks require a valid provider signature.
Deletion and retention
Expired sign-in links and sessions are not usable. Account documents and uploaded designs are retained while the account remains active so the dashboard and history work. You may request access, correction, export, or deletion of your personal data, withdraw optional consent, or raise a grievance using the contact below.
Your choices and contact
You can stop using guest cookies by clearing them in your browser, sign out at any time, and ask us to correct or delete account information. Privacy and grievance requests can be sent to hello@pdfloom.app. Include the email used for your account so the request can be verified.