LoopSuite
  • Home
  • Pricing
  • Try LoopSuite

Privacy Policy

Last updated: 18 April 2026

Contents

  1. Who We Are
  2. What This Policy Covers
  3. What Data We Collect
  4. How We Use Your Data
  5. AI Processing
  6. Outreach and Lead Generation
  7. Third-Party Integrations (via Composio)
  8. Messaging Integrations
  9. Team Members and Multi-User Accounts
  10. Automations and Scheduled Actions
  11. AI Memory
  12. Subscription and Billing
  13. Push Notifications
  14. Third-Party Processors
  15. International Data Transfers
  16. Data Retention
  17. Your Rights (UK GDPR)
  18. Data Security
  19. Children
  20. Cookies
  21. California Residents (CCPA/CPRA)
  22. Supervisory Authority
  23. Google Workspace Integration
  24. Changes to This Policy
  25. Contact Us

1. Who We Are

LoopSuite is a trading name of Trovelogic Ltd, a company registered in England and Wales.

  • Registered address: 1 Hurley Lane, Norton Canes, Atherstone, Staffordshire, CV9 2JJ, United Kingdom
  • Data protection contact: [email protected]
  • Website: https://loopsuite.ai

We are the data controller for the personal data we collect about our customers. Where our customers use LoopSuite to contact third-party leads, we act as a data processor on behalf of our customers, who are the controllers of that outreach.

Worldwide availability. LoopSuite is operated from the United Kingdom and is available to businesses worldwide (primarily English-speaking markets today). Regardless of where you use LoopSuite from, the data-handling practices described in this policy apply. Where your local law grants you additional rights (for example, CCPA/CPRA in California, the Australian Privacy Act, or Canadian PIPEDA), we respect those rights — see §17 Your Rights and §21 California Residents.

Our Privacy Commitments

Four promises we make and back up with how the platform is built:

  • We do not sell your personal data. Not to advertisers, not to data brokers, not to anyone. Never have, never will.
  • Your data lives in your own isolated environment. Every customer runs inside a dedicated, per-customer environment on our infrastructure. Your chat, memory, files, and connected-service data are kept separate from every other customer.
  • Your data is not used to train AI models. Our AI providers (OpenAI and Google) operate under enterprise terms that exclude your content from training. We do not fine-tune or train any model on your content either.
  • You stay in control. You can export, delete, or disconnect at any time. We are your data processor for anything you do with your AI teammate — you remain the controller of your business content.

2. What This Policy Covers

This policy explains how we collect, use, store, and protect personal data when you:

  • Visit our website (loopsuite.ai)
  • Create a LoopSuite account
  • Use the LoopSuite platform and its features (the "Service")
  • Communicate with us

It also explains the rights of individuals whose publicly available business contact information is found through our LoopGen (lead generation) feature.

3. What Data We Collect

3.1 Account Information

When you sign up, we collect:

  • Name and email address
  • Password (stored securely hashed — we never see or store your plaintext password)
  • Business name, website URL, and industry
  • Google account data (if you sign up via Google OAuth — name and email only)

3.2 Business Profile Data

During onboarding and ongoing use, we collect and analyse:

  • Your business website content (scraped from your publicly available website to understand your brand)
  • Brand voice, tone, and style preferences
  • Target audience and ideal customer descriptions
  • Services, products, and pricing information you provide
  • Social media account connections (via OAuth — you explicitly grant access)
  • Google Ads and Meta Ads account connections (via your own ad accounts)
  • Google Workspace connections (Gmail, Calendar, Drive — via OAuth)
  • WhatsApp Business connection (company phone number linked for business messaging)

3.3 Connected Services Data

When you connect a third-party service to LoopSuite (for example Gmail, Google Calendar, social media, advertising accounts, a CRM, a shop platform, a messaging channel, or any of the other integrations we support), we collect and process:

  • The OAuth authentication credentials for that service
  • Data you ask your AI teammate to read, send, or act on within that service (e.g. emails, calendar events, contacts, posts, ads, orders, messages)
  • Metadata about the actions taken (timestamps, delivery status, errors)

We only access the data you explicitly authorise through the connection flow. Authentication tokens and connected-service data are handled through our sub-processor Composio — see §7 Third-Party Integrations (via Composio).

3.4 Chat Conversations

All conversations with your AI teammate are stored to provide context and continuity across sessions, improve responses based on your preferences, and maintain a record of instructions and decisions you have made.

3.5 Usage Data

We track how you use the platform, including features used, content generated, outreach activity, subscription events, and token/usage metrics for billing and cost control.

3.6 Lead Data (Publicly Available Business Information)

When you use our lead-generation feature, we find potential business contacts on your behalf by searching the public web. We collect:

  • Business name and website URL
  • Publicly listed email addresses
  • Publicly listed phone numbers
  • Business address (if publicly available)
  • Industry and service descriptions

Important: We find this information exclusively through web search. We do not scrape LinkedIn or social media, scrape directories or databases, purchase data lists, access private databases, or collect personal (non-business) contact information.

3.7 Subscription and Billing Information

How payment information is collected depends on where you subscribe. See §12 Subscription and Billing for the full breakdown. In summary:

  • Web subscriptions are processed by Stripe. We never see, handle, or store your full card details. Stripe provides us with the last four digits of your card, card expiry date, billing address, and Stripe customer identifiers.
  • iOS subscriptions are processed by Apple via the App Store. Apple handles payment data; we receive only the subscription status and a customer identifier through RevenueCat, our mobile-subscription manager.
  • Android subscriptions are processed by Google via Google Play. Google handles payment data; we receive only the subscription status and a customer identifier through RevenueCat.

3.8 Device and Push Notification Data

If you enable push notifications on our mobile apps, we store a device push token (issued by Apple for iOS or Google Firebase Cloud Messaging for Android) so we can send notifications you've opted into. Tokens are tied to your account and rotated by the operating system. See §13 Push Notifications.

3.9 Technical Data

We automatically collect IP address, browser type and version, device information, pages visited, and referring website.

3.10 Cookies

We use minimal cookies: authentication tokens (essential) and preferences (functional). We do not use advertising or third-party tracking cookies.

4. How We Use Your Data

PurposeData usedLegal basis (GDPR)
Provide the ServiceAccount info, business data, conversationsContract performance (Art. 6(1)(b))
Process subscription paymentsAccount info, subscription state from Stripe/Apple/Google via RevenueCatContract performance (Art. 6(1)(b))
Generate leadsBusiness profile, target criteriaLegitimate interest (Art. 6(1)(f))
Send outreach on your instructionLead and contact data, message content, connected-service credentialsContract performance; your instruction as controller (Art. 6(1)(b) / Art. 6(1)(f))
Act in third-party services on your instruction (email, calendar, social, ads, CRM, shop, messaging, etc.)Business profile, connected-service credentials, action-specific dataContract performance; OAuth consent
Run scheduled automations on your instructionBusiness profile, connected-service credentials, automation parametersContract performance (Art. 6(1)(b))
Send push notifications you've opted intoDevice push token, notification contentContract performance; consent for marketing-style notifications
Improve the ServiceUsage data, aggregated analyticsLegitimate interest (Art. 6(1)(f))
Prevent fraudAccount info, technical dataLegitimate interest (Art. 6(1)(f))
Legal obligationsAccount and billing recordsLegal obligation (Art. 6(1)(c))

5. AI Processing

5.1 How AI Is Used

LoopSuite uses large language models and other AI services to power your AI teammate, analyse your business, generate content (text, images, video), find and research leads, optimise advertising, and provide business insights.

5.2 Who Processes Your Data

Your chat messages and business context are sent to AI providers for processing. Today we use:

  • OpenAI — primary text model (GPT family) for chat, reasoning, agent execution, content generation, and transcription
  • Google — Gemini models for image and video generation, plus fallback text reasoning

Each customer runs inside an isolated environment — your data is never mixed with other customers' data. Both providers operate under Data Processing Agreements with us and do not use your data to train their models. API-tier usage by enterprise customers is excluded from model training by default under OpenAI and Google's enterprise terms.

5.3 No Automated Decision-Making

We do not use AI to make decisions that produce legal effects or similarly significantly affect you. You remain in control: the AI suggests and drafts; you approve or edit; and any action that contacts a customer, spends money, or sends a message is either explicitly authorised by you or run inside an autonomy level you have configured.

6. Outreach and Lead Generation

All outreach (email, messaging, or otherwise) sent from your business identity on your instruction:

  • Contains a clear way to stop receiving messages
  • Is professional and introductory
  • Is limited in volume
  • Respects opt-out requests immediately
  • Includes your business details

Legal basis: For UK/EU recipients, we rely on legitimate interest for B2B communications. For US recipients, emails comply with CAN-SPAM. For Canadian recipients, we rely on the implied consent exception for publicly available business information.

Your responsibilities: When using lead generation, you are the data controller for the leads found and contacted. LoopSuite acts as your data processor.

7. Third-Party Integrations (via Composio)

LoopSuite connects to third-party business services (email, calendar, cloud storage, social media, advertising platforms, CRMs, shop platforms, accounting tools, messaging channels, and more) through Composio, our integration sub-processor. When you connect a service to LoopSuite:

  1. You authorise the connection through the third-party service's own OAuth or authentication flow
  2. Composio stores the resulting access tokens on our behalf
  3. When your AI teammate needs to act in that service, the request is routed through Composio to the third-party service
  4. Composio sees the request and response payloads required to execute that action (for example, the text of an email to send, or the calendar event to create)

Responsibility: Composio is our sub-processor under a Data Processing Agreement. LoopSuite remains accountable to you for how your data is handled. Composio is accountable to us under our DPA with them.

Composio's own terms: When you interact with Composio directly (for example, during OAuth consent screens or the Composio-hosted connection page), Composio's own terms and privacy policy also apply:

  • Composio Privacy Policy
  • Composio Terms of Service

Disconnecting: You can disconnect any third-party service at any time by asking your AI teammate or from your settings. On disconnection we stop using that service and ask Composio to revoke the stored tokens. You may also revoke tokens directly from the third-party service's own permission page (for example, Google Account → Connected apps).

Your responsibilities: You are responsible for ensuring you have the right to connect the accounts you connect, and for complying with the terms of each third-party service (for example, WhatsApp's Business Terms of Service when you connect WhatsApp, or Meta's Platform Terms when you connect Facebook or Instagram).

Recommended: use a dedicated business account, not your personal account. Wherever a service supports separate sub-accounts or business-tier accounts, we strongly recommend connecting those rather than your main personal account. For example: create a dedicated Gmail/Google Workspace user for LoopSuite to act through, use a separate social media manager role rather than your personal admin, and use a business-tier account on shop or CRM platforms. This keeps permissions minimal, makes revocation cleaner if you ever disconnect, and reduces the blast radius of any credential issue.

8. Messaging Integrations

LoopSuite can send messages on your behalf through messaging channels you connect (for example, email, WhatsApp Business, SMS, social DMs, Slack, Discord). Messages are sent from your business identity or number, not from LoopSuite. Recipients see your business as the sender.

Data processed: the recipient's contact details (phone number, email, handle), message content, delivery status, and (where available) read receipts. This data is stored within your isolated LoopSuite account.

Your responsibilities: You are the data controller for messages sent via LoopSuite on your instruction. LoopSuite acts as your data processor. You must ensure you have appropriate consent or legal basis to contact recipients, and you must comply with applicable messaging regulations (UK PECR, EU ePrivacy Directive, CAN-SPAM where relevant to US recipients) and with the terms of each messaging platform you use.

Opt-out: If a recipient asks to stop receiving messages, your AI teammate will mark them and prevent further outreach on that channel.

9. Team Members and Multi-User Accounts

A LoopSuite company account can have multiple team members with different roles (e.g. admin, member). The company owner is the primary account holder. Each team member's own account information is covered by this policy. The company owner decides who has access to the shared business data within the account.

10. Automations and Scheduled Actions

Your AI teammate can run automations on a schedule (for example: a daily inbox triage, a weekly review, a monthly report) and take actions autonomously at the autonomy level you have configured. Each automation operates inside your isolated account and uses only the connections you have enabled. Automation run logs are stored alongside chat conversations (see §16 Data Retention).

11. AI Memory

To work as a useful long-term teammate, your AI writes persistent notes to a memory area inside your isolated account (for example: remembered preferences, decisions made, a running ledger of your business). This memory is derived from conversations you have had with it and from data you have asked it to organise. You can review, edit, or clear this memory at any time by asking your AI teammate or through your account settings.

12. Subscription and Billing

How your subscription is processed depends on where you subscribe.

12.1 Web subscriptions (direct)

Subscriptions taken directly on our website are processed by Stripe. We never see, handle, or store your full card details. Stripe provides us with the last four digits of your card, card expiry date, billing address, and Stripe customer identifiers. Refund requests for web subscriptions are handled by us in accordance with our Terms of Service.

12.2 iOS subscriptions (App Store)

Subscriptions purchased inside our iOS app are processed by Apple under the App Store terms you accepted when you created your Apple ID. Apple handles all payment data. We receive subscription status and an anonymous customer identifier through our mobile-subscription manager RevenueCat. Refunds for iOS subscriptions are requested through Apple (reportaproblem.apple.com); we cannot issue them on Apple's behalf.

12.3 Android subscriptions (Google Play)

Subscriptions purchased inside our Android app are processed by Google under the Google Play terms you accepted when you created your Google account. Google handles all payment data. We receive subscription status and an anonymous customer identifier through RevenueCat. Refunds for Android subscriptions are requested through Google Play.

13. Push Notifications

If you enable push notifications on our mobile apps, we store a device push token issued by Apple Push Notification service (APNs) on iOS, or Firebase Cloud Messaging (FCM) on Android. The token lets us deliver notifications you've opted into. Tokens are tied to your account, refreshed by the operating system, and revoked when you sign out or disable notifications.

You can turn push notifications off at any time in your device's system settings or in the app's notification settings.

14. Third-Party Processors

ProviderPurposeLocation
SupabaseDatabase hosting, authentication, file storageEU / USA
Fly.ioIsolated per-customer environment hostingEU (London) by default; other regions on request
OpenAIAI processing (chat, reasoning, transcription, image/video generation fallback)USA (EU-US DPF)
GoogleAI processing (Gemini for image, video, and fallback text)USA (EU-US DPF)
ComposioSub-processor for all third-party service integrations (OAuth tokens, tool routing)USA (EU-US DPF)
StripePayment processing (web subscriptions)USA (EU-US DPF)
RevenueCatMobile subscription management (iOS/Android receipt verification, entitlement state)USA (EU-US DPF)
AppleiOS in-app purchase processing + APNs push deliveryUSA (EU-US DPF)
Google (Play / FCM)Android in-app purchase processing + Firebase Cloud Messaging push deliveryUSA (EU-US DPF)
MailgunTransactional email delivery (account emails, notifications from LoopSuite)USA / EU
BraveWeb search (for lead generation and research)USA
FirecrawlPublic-web scraping (for analysing your website and researching leads)USA
ElevenLabsText-to-speech audio generation (when you use voice replies)USA (EU-US DPF)

Services you connect through Composio (Gmail, Calendar, Drive, social media, advertising platforms, CRMs, shop platforms, messaging channels, etc.) are controlled by their own operators and are only involved when you explicitly connect your account. We do not sell your personal data to anyone.

15. International Data Transfers

Where personal data is transferred internationally, we rely on the UK/EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), and adequacy decisions as appropriate.

16. Data Retention

Data typeRetention period
Account and business profileDuration of account + 30 days
Chat conversations, AI memory, and workspace filesDuration of account + 30 days
Archived workspaces (after cancellation, for possible restore)Up to 12 months from cancellation, then permanently deleted
Lead dataDuration of account; deleted on closure
Email and messaging outreach recordsDuration of account + 6 months
Automation and cron run logsDuration of account; rotated after 48 hours for isolated runs
Opt-out / unsubscribe listsIndefinitely (for compliance)
Payment / billing records7 years (UK tax requirements)
Support ticketsDuration of account + 12 months
Device push tokensUntil you disable notifications or sign out
Technical / server logs90 days

17. Your Rights (UK GDPR)

You have the right to: access, rectification, erasure, restriction, portability, object to processing, withdraw consent, and lodge a complaint with the ICO.

To exercise any of these rights, contact us at [email protected]. We will respond within one month.

Rights of lead recipients: If your business contact information has been found through our lead-generation service, you can opt out, request deletion, or request to know what data we hold.

18. Data Security

  • Encryption in transit (TLS) and at rest
  • Isolated environment per customer
  • Row-level security on the database
  • Secure password hashing
  • Payment processors (Stripe, Apple, Google) handle card data at PCI DSS Level 1

19. Children

LoopSuite is a business tool and is not intended for use by anyone under 18. We do not knowingly collect data from children.

20. Cookies

CookiePurposeTypeDuration
Authentication tokenKeeps you logged inEssentialSession / 30 days
PreferencesRemembers settingsFunctional1 year

We do not currently use any third-party advertising or tracking cookies. If we introduce analytics cookies in the future, we will update this policy and implement a cookie consent banner.

21. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights: right to know, right to delete, right to correct, right to opt out of sale/sharing. We do not sell or share your personal information.

22. Supervisory Authority

You may lodge a complaint with the UK Information Commissioner's Office (ICO):

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
https://ico.org.uk

23. Google Workspace Integration

If you connect your Google Workspace account to LoopSuite, the following applies to how we access and handle your Google user data:

23.1 Scopes and Data Accessed

Google ServiceAccess LevelHow We Use It
Google CalendarRead & WriteLoopSuite syncs marketing campaign milestones, content deadlines, and publication dates with your Google Calendar. We create, update, and remove calendar events on your behalf. We also read your calendar to detect scheduling conflicts and suggest optimal content times.
Google DocsRead-onlyYou can select a Google Doc to import as a draft blog post, email newsletter, or content brief within LoopSuite. Your AI teammate LoopSuite can analyse a selected document to suggest headlines, social media excerpts, and SEO improvements. We only read documents you explicitly select — we do not scan or index all documents.
Google ContactsRead-onlyYou can import contacts into LoopSuite's CRM to use as recipients for email campaigns, outreach, or lead nurturing workflows. We use contact data (name, email, company, job title) to segment audiences for targeted campaigns.
Google SheetsRead & WriteYou can import marketing data from Sheets (e.g., product catalogues, lead lists, content calendars) and export campaign performance reports and analytics summaries back to Sheets for sharing with your team.

23.2 Data Handling

  • All Google user data is transmitted over HTTPS/TLS and stored encrypted at rest.
  • Google data is stored within your isolated LoopSuite account and is never shared with other customers or third parties.
  • Google data is not used to train generalised AI models. Your AI teammate LoopSuite uses Google data solely to provide personalised features within your LoopSuite account.
  • Google data is not sold, rented, or used for advertising purposes.

23.3 Revoking Access

You can disconnect your Google account at any time from your LoopSuite settings. You can also revoke access directly from your Google Account permissions page. Upon disconnection, we stop accessing your Google data. Previously imported data (e.g., contacts imported into your CRM) remains in your LoopSuite account until you delete it or close your account.

23.4 Limited Use Disclosure

LoopSuite's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

24. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email and/or in-app notification.

25. Contact Us

For any questions about this privacy policy or your personal data:

  • Email: [email protected]
  • Post: Trovelogic Ltd, 1 Hurley Lane, Norton Canes, Atherstone, Staffordshire, CV9 2JJ, United Kingdom
  • Website: https://loopsuite.ai
LoopSuite

Your first AI employee.

Legal

  • Privacy Policy
  • Terms of Service
  • Acceptable Use

Contact

  • [email protected]
© 2026 LoopSuite. All rights reserved.