loops
Legal

Privacy Policy

How Loops collects, uses, shares and protects personal data, for you, your team and your customers.

Effective 15 September 2026

Who is responsible

【Company legal name】, 【Registered address】, Portugal, is the controller for the personal data of people who use Loops (account holders and team members) and for visitors to our website. For the data of your customers that you add to Loops, you are the controller and we act as your processor under our Data Processing Addendum. Contact: privacy@【yourdomain】.

Data about you

When you create an account we store your name, email address and a password hash, or your Google account identifier if you sign in with Google. We store the businesses you create, their settings, logos and brand colours, your team members' email addresses and roles, and your API keys in hashed form. Stripe holds your payment details; we store only a customer reference, subscription status and the last four digits and brand of your card for display.

We use this to provide the Service, bill you, send you the monthly report and service emails, and answer support requests. The legal basis is the contract with you and our legitimate interest in running and securing the Service.

Data about your customers

For each customer you add we store the name and email address you give us, your own reference if you send one, when and whether the enquiry, reminder and follow-up were sent, the score and answers they gave, any private feedback they wrote to you, and whether they unsubscribed. We store the emails we sent them. We do this only on your instructions and only to run the enquiry; we never use your customers' data for our own marketing and we never sell it.

Google sign-in and Google user data

If you choose "Continue with Google", Google sends Loops your name, email address and profile picture, and a unique account identifier. We use them only to create your Loops account or sign you in to it and to show your name in the dashboard. We do not request access to your Gmail, Calendar, Drive, contacts or any other Google data, and we never post to Google on your behalf.

Loops's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, never used to train models, and never shared with anyone except the subprocessors that host Loops. You can revoke Loops's access at any time from your Google Account permissions page, and you can delete your Loops account from Settings, which removes the Google identifier we stored.

Website visitors

The dashboard uses a strictly necessary session cookie to keep you signed in. Google Analytics runs on our website and dashboard only if you accept it in the cookie banner, with IP anonymisation; we use it to understand which pages are useful. The legal basis is your consent, which you can withdraw from the footer. Customer enquiry pages never use analytics. See the Cookie Policy.

Who we share data with

We use a small number of providers to run the Service, listed on our Subprocessors page: hosting and database, email delivery, payments, and the Google Places API for public rating and review counts of businesses you link. Each is bound by a data processing agreement. We do not share data with anyone else unless the law requires it.

International transfers

Some providers process data in the United States. Transfers rely on the EU Standard Contractual Clauses or an adequacy decision, as documented by each provider.

How long we keep data

Account data is kept while your account exists. Business data, including customer records and sent emails, is kept while the business exists and is deleted when you delete the business; a deleted account and its businesses are removed from live systems within 30 days and from backups within 90. Stripe keeps invoices as long as tax law requires. Unsubscribe records are kept so we can continue to honour them.

Your rights

You can access, correct, export and delete your data from the dashboard, or ask us at privacy@【yourdomain】. You also have the right to object, to restrict processing and to complain to your supervisory authority. If you are a customer of one of our users and want your data corrected or deleted, contact that business, or contact us and we will pass the request on and assist.

Security

Data is encrypted in transit and at rest by our providers, access is limited to what each role needs, API keys are stored hashed, and every outbound email carries a one-click unsubscribe. No system is perfectly secure; if a breach affects you we will tell you without undue delay.

Children

The Service is for businesses and is not directed at children under 16.

Changes

We will announce material changes to this policy by email or in the dashboard.