Privacy Policy
Last updated: July 20, 2026
Loona Brands LLC, operating as IPzest ("we," "our," or "us"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our brand protection platform and services (collectively, the "Service").
By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our Service.
A note on how this Service works. IPzest scans public marketplaces, advertising libraries, and trademark registries on your behalf. That means we also process information about people who are not our users — sellers, advertisers, and competitors. Section 3 explains that processing specifically.
1. Who We Are
Loona Brands LLC is the data controller for the personal information described in this policy, except where we act as a processor on your behalf (see Section 3.3 and our Data Processing Addendum). You can reach us at 14359 Miramar Pkwy #262, Miramar, FL 33027, United States, or by email at info@ipzest.app.
2. Information We Collect
2.1 Information You Provide
We collect information you provide directly to us, including:
- Account Information: name, email address, company name, and phone number
- Brand Information: brand names, trademarks, product information, and intellectual property details you submit for monitoring
- Content: images, logos, product photos, and other content you upload
- Communication Data: messages, support requests, and feedback you send us
- Billing Information: billing address and payment history. Card details are collected and stored by Stripe, our payment processor — we never receive or store your full card number
2.2 Automatically Collected Information
- Usage Data: pages visited, features used, and interaction patterns
- Device Information: IP address, browser type, operating system, and device identifiers
- Log Data: access times, error logs, and performance data
- Cookies and Similar Technologies: see our Cookie Policy. Non-essential cookies are set only after you consent through our cookie banner
2.3 Information from Third Parties
- Stripe, for payment and subscription status
- Authentication providers, if you sign in with Google
- Public marketplaces, advertising libraries, trademark registries, and websites, for brand monitoring (see Section 3)
3. Information About People Who Are Not Our Users
To detect infringement, the Service collects information from public sources about third parties — marketplace sellers, advertisers, domain registrants, and, on eligible plans, competitors that a customer chooses to monitor. Some of this information is personal information. We treat it with the same care as customer data, and we describe it here because transparency about it is required even though those individuals are not our users.
3.1 What We Collect and From Where
- Marketplace listings: seller display names and shop identifiers, listing titles, descriptions, images, prices, and URLs — from eBay and Etsy public APIs and public listing pages
- Advertising data: advertiser names, ad creatives, and ad metadata — from the Meta Ad Library and Google Ads Transparency Center, both of which publish this data for public accountability
- Trademark and patent filings: applicant and registrant names and filing records — from the USPTO public register
- Websites and domains: page content, images, and publicly available registration data — collected by automated crawling
- Competitor profiles: for customers on plans that include competitor intelligence, aggregated public business information about the named competitor
We collect this from publicly accessible sources only. We do not attempt to access private accounts, circumvent access controls, or de-anonymize individuals.
3.2 Why We Are Permitted to Do This
Where the GDPR or UK GDPR applies, our legal basis is legitimate interests (Art. 6(1)(f)): the interest of rights holders in detecting and stopping infringement of their intellectual property, and the wider public interest in reducing counterfeit goods. We have assessed this against the interests and rights of the individuals concerned. We limit collection to commercial and public-facing activity, we do not collect special category data, we do not use this data for advertising or profiling unrelated to enforcement, and we apply the retention limits in Section 3.4. You may request our balancing assessment at the contact address below.
3.3 Who Controls This Data
When a customer directs monitoring of a specific brand, seller, or competitor, that customer determines the purpose of the processing and acts as controller; we act as processor on their behalf under our Data Processing Addendum. Where we determine what to scan — for example, improving detection quality across the platform — we act as controller. If you are unsure which applies to a specific record, contact us and we will tell you and, where we are a processor, forward your request to the relevant customer.
3.4 Retention
Scanned listing, advertisement, and filing records are retained while they remain relevant to an open or recently resolved monitoring matter, and for no longer than 24 months after collection unless a customer is using them as evidence in an active enforcement action or legal proceeding. Evidence captured in support of a submitted takedown is retained while that matter remains open and for a further period as needed to respond to counter-notices or disputes.
3.5 Your Rights If You Appear in This Data
If you are a seller, advertiser, or business that appears in our systems and you are not an IPzest customer, you still have rights. You may request access to the information we hold about you, ask us to correct it, object to our processing on grounds relating to your particular situation, or request erasure. Email info@ipzest.app with enough detail to identify the records — for example your shop name, advertiser name, or the URL concerned. We respond within 30 days. Note that we may need to retain records that are evidence in an active enforcement matter, and that we cannot remove the underlying listing or advertisement from the third-party platform where it is published.
4. How We Use Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Monitor for and detect potential unauthorized use of your intellectual property
- Generate takedown drafts and evidence packages
- Process transactions and manage your account and subscription
- Send service-related communications, alerts, and notifications
- Respond to your inquiries and support requests
- Detect, prevent, and address technical issues, fraud, and security threats
- Comply with legal obligations and enforce our Terms of Service
- Conduct analytics to improve detection quality and the platform
- Send marketing communications, where you have consented or where permitted by law (you can unsubscribe at any time)
5. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)): creating and managing your account, delivering monitoring and takedown features, and processing payments
- Legitimate interests (Art. 6(1)(f)): securing the Service, preventing fraud and abuse, improving detection quality, scanning public sources for infringement (Section 3.2), and sending service communications
- Consent (Art. 6(1)(a)): non-essential cookies and analytics, and marketing emails where consent is required. You may withdraw consent at any time, without affecting processing carried out before withdrawal
- Legal obligation (Art. 6(1)(c)): tax, accounting, and responding to lawful requests from authorities
6. Artificial Intelligence and Automated Processing
The Service uses machine learning and large language models — principally Google Vertex AI (Gemini) — to compare images, score potential infringements, profile competitors, and draft text. Specifically:
- Your brand assets and scanned public content are sent to our AI provider for processing and results are returned to us
- We do not use your content to train our own or any third party's foundation models, and our AI provider is contractually prohibited from using it to train its general-purpose models
- AI output can be inaccurate. It is presented to you as a suggestion for review, never as a final determination
- We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Every enforcement action requires a human decision by the customer
7. How We Share Information
We do not sell your personal information. We share it only as described below.
7.1 Service Providers and Subprocessors
We share information with the following providers, who process it on our behalf under contract and only for the purposes shown:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Authentication, Firestore database, file storage, hosting | United States |
| Google Cloud Vertex AI (Gemini) | AI detection, competitor profiling, and drafting assistance | United States |
| Vercel | Website and application hosting, product analytics | United States / global edge network |
| Stripe | Payment processing and subscription billing | United States |
| Firecrawl | Web crawling and page capture for infringement scanning | United States |
| eBay, Etsy, Meta Ad Library, Google Ads Transparency, USPTO | Public marketplace, advertising and trademark data sources | United States / global |
We will update this list before adding a new subprocessor that processes customer personal information.
7.2 Takedown Recipients
When you submit a takedown request, the notice — which typically includes your name or your company's name and contact details, as required by the receiving platform — is transmitted to that platform and may be forwarded by it to the alleged infringer or published in a transparency database such as Lumen. This is required by law and platform policy for takedown notices; we cannot anonymize it.
7.3 Legal Requirements
We may disclose information where required by law or where necessary to:
- Comply with legal process or lawful government requests
- Enforce our Terms of Service and other agreements
- Protect the rights, property, or safety of IPzest, our users, or others
- Prevent fraud or address security threats
7.4 Business Transfers
In a merger, acquisition, reorganization, or sale of assets, information may be transferred to the acquiring entity, which will remain bound by this policy or provide notice before it changes.
7.5 With Your Consent
We share information for any other purpose only with your consent or at your direction.
8. Data Security
We use the following measures to protect information:
- Encryption in transit using TLS, and encryption at rest by our infrastructure providers
- Authentication and role-based access controls; access to production data is limited to personnel who need it
- Server-side authorization rules on all customer data, so records are accessible only to their owner
- Segregation of payment card data — handled entirely by Stripe, a PCI-DSS Level 1 provider
- Logging and monitoring of access and errors
Important: no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any required regulator without undue delay and, where required, within 72 hours of becoming aware of it.
9. Your Privacy Rights
Depending on where you live, you may have the following rights:
- Access: obtain a copy of the personal information we hold about you
- Correction: have inaccurate or incomplete information corrected
- Deletion: have your personal information erased
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Restriction: restrict processing in certain circumstances
- Withdraw consent: withdraw consent at any time where processing is based on it
- Opt out: unsubscribe from marketing communications at any time
To exercise any of these, email info@ipzest.app. We respond within 30 days and may need to verify your identity first. We will not discriminate against you for exercising your rights.
If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data protection supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk).
10. California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have the rights described in Section 9 plus the rights below. In the preceding 12 months we have collected the following categories of personal information:
| Category | Examples | Disclosed to |
|---|---|---|
| Identifiers | Name, email, company, phone, IP address, account ID | Hosting, auth, payment, and email providers |
| Commercial information | Subscription plan, billing history, purchased add-ons | Payment processor |
| Internet activity | Pages viewed, features used, log and error data | Hosting and analytics providers |
| Professional information | Company, role, brand and IP portfolio details | Hosting and AI processing providers |
| Publicly available information | Seller, advertiser, and registrant data (see Section 3) | Hosting and AI processing providers |
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. We do not collect sensitive personal information for the purpose of inferring characteristics about you.
You may use an authorized agent to submit a request on your behalf; we will require proof of the agent's authorization and may still verify your identity directly. Because we do not sell or share personal information, there is no "Do Not Sell or Share My Personal Information" mechanism to offer — but we honor Global Privacy Control signals as an opt-out of non-essential analytics regardless.
11. Data Retention
We retain personal information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When you delete your account, we delete or anonymize your personal information within 30 days, except where we must retain it for legal, tax, or accounting purposes, or where it forms part of the evidence record for an enforcement matter that is still open. Retention of data about non-users is described in Section 3.4. Backups are purged on a rolling basis within 90 days.
12. International Data Transfers
We are based in the United States and our infrastructure providers process data in the United States. If you are located elsewhere, your information will be transferred to and processed in the United States, which may not offer the same level of data protection as your home country. For transfers from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, which are incorporated into our Data Processing Addendum. Request a copy at info@ipzest.app.
13. Children's Privacy
The Service is not intended for individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
14. Changes to This Privacy Policy
We may update this Privacy Policy. We will post the updated policy on this page and update the "Last updated" date. For material changes that affect how we use your personal information, we will notify you by email at least 30 days before they take effect.
15. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or our data practices:
IPzest Privacy Team
Loona Brands LLC
Email: info@ipzest.app
14359 Miramar Pkwy #262, Miramar, FL 33027, United States