Third Party Index

Snapshot 43706

Document
Privacy policy
URL
https://loopster.ai/privacy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
58337 bytes
SHA-256 (raw)
174bebc515bf689bfeb1f65deffd64703869bf17fcaceefb7f4044f505e62fbd
SHA-256 (normalized text)
55424a15c100f6196d16fced8222445b38570db7c39dd8de1eeee064d74894d2

Normalized text

Scripts and page chrome removed; this is what change detection compares.

ProductPricing
Download PDF
Privacy Policy
Last updated: September 11, 2026
This Privacy Policy explains how Loopworks OÜ, a private limited company incorporated in the Republic of Estonia (registry code 17578714), with its registered address at Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 10151, Estonia ("Loopster", "we", "us", or "our") collects, uses, and protects personal data in connection with the Loopster platform, our websites (including loopster.ai and app.loopster.ai), our APIs and integrations (including our HubSpot app), and related services (together, the "Services"). We comply with the EU General Data Protection Regulation (GDPR).
1. Our Roles: Controller and Processor
Loopster processes personal data in two distinct roles:
As a controller for personal data relating to our users and website visitors (such as account, billing, usage, and support data) and for the business contact information in the Loopster database described in Section 4.
As a processor for personal data our customers upload to or sync into their Loopster workspace, including records imported from a CRM such as HubSpot ("Customer Data"). We process Customer Data only on the customer’s instructions; the customer is the controller. Our Data Processing Addendum is available on request at [email protected]. If your personal data appears in a customer’s workspace, please direct requests to that customer first; we will support them in responding.
2. Data We Collect
Account data: name, business email address, password (stored hashed), workspace and profile details.
Billing data: plan, transaction history, and payment details processed by our payment processor, Stripe; we do not store full card numbers.
Usage and device data: log data, IP address, browser and device information, and in-app usage events collected via analytics tools (such as PostHog and Google Analytics), subject to your cookie choices.
Support and communications data: messages you send to [email protected] or through in-app channels.
Customer Data: data you upload or sync into your workspace, including CRM records (processed as processor, per Section 1).
3. How and Why We Use Data
To provide, operate, and secure the Services (legal basis: performance of a contract).
To process payments and manage subscriptions (performance of a contract; legal obligation).
To provide support and communicate service updates (performance of a contract; legitimate interests).
To analyze usage and improve the Services, using aggregated or pseudonymized data where possible (legitimate interests; consent where required for analytics cookies).
To send marketing communications, from which you can opt out at any time (consent; legitimate interests for existing customers).
To comply with legal obligations and to establish, exercise, or defend legal claims (legal obligation; legitimate interests).
4. The Loopster Database and Enrichment
Loopster maintains a database of business contact and company information — such as name, job title, employer, business email address, business phone number, and public professional profile links — compiled from publicly available sources and licensed data partners. We process this data for the purpose of providing business-to-business sales and marketing intelligence, on the basis of our legitimate interests (Article 6(1)(f) GDPR). We do not knowingly include special categories of personal data or data relating to children in this database.
When a customer runs an enrichment, the relevant query data is sent to the selected third-party data providers or AI model providers, and the results are returned to that customer’s workspace. Third-party providers act under their own privacy policies for their databases.
If you are a data subject whose information appears in the Loopster database, you can exercise the rights described in Section 9, including requesting removal, by emailing [email protected].
5. CRM Integrations, Including HubSpot
When you connect a CRM such as HubSpot, we access your CRM data through the platform’s official API using OAuth. OAuth tokens are encrypted at rest and stored securely for your workspace. We access and sync only the record types, sources, and properties you configure in your import and export settings, and we use CRM data solely to provide the Services to you — we do not sell it or use it to enrich other customers’ data. You can disconnect the integration at any time in Loopster or by uninstalling the app in your CRM, which revokes our access and stops all scheduled syncs. We do not use data synced from your CRM to train, fine-tune, or improve AI or machine learning models; when AI features process your CRM data, it is used only to generate results for your workspace.
6. Sharing and Sub-processors
We do not sell your personal data. We share personal data only with:
Service providers (sub-processors) that help us operate the Services, such as cloud hosting and infrastructure providers, our payment processor, analytics providers, email and support tooling, and — when you use the relevant features — third-party enrichment data providers and AI model providers. Sub-processors are bound by data protection obligations; a current list is available on request at [email protected].
Authorities or other third parties where required by law, to comply with legal process, or to protect the rights, property, or safety of Loopster, our customers, or others.
A successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.
7. International Transfers
We are established in the European Union. Where personal data is transferred outside the European Economic Area — for example to service providers in the United States — we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an applicable adequacy decision.
8. Retention
We retain personal data for as long as your account is active or as needed to provide the Services. When you delete your account or request deletion, we delete or anonymize your personal data within 30 days, except where longer retention is required by law (for example, invoicing and accounting records) or for the establishment, exercise, or defense of legal claims. Residual copies may persist in backups for a limited period before being overwritten. Customer Data is retained and deleted according to the customer’s instructions and our Data Processing Addendum.
9. Your Rights
Subject to the conditions of the GDPR, you have the right to access, rectify, and erase your personal data; to restrict or object to its processing (including an absolute right to object to direct marketing); to data portability; and to withdraw consent at any time where processing is based on consent. To exercise any of these rights, email [email protected]; we will respond within one month. You also have the right to lodge a complaint with a supervisory authority, in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or the authority in your country of residence.
10. Security
We apply technical and organizational measures appropriate to the risk, including encryption of data in transit (TLS) and at rest, encrypted storage of integration OAuth tokens, access controls and least-privilege practices, and logging and monitoring. No method of transmission or storage is completely secure; if we become aware of a personal data breach affecting you, we will notify you and the competent authority as required by law.
11. Cookies and Analytics
We use essential cookies necessary for the Services to function, and analytics tools — PostHog and Google Analytics — to understand usage, diagnose issues, and improve the product. You can control or delete cookies at any time through your browser settings, and you can object to analytics processing by contacting [email protected]. Where consent is required for non-essential cookies, we will request it before setting them.
12. Children
The Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal data from children; if you believe a child has provided us personal data, contact [email protected] and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you (for example by email or in-app notice) before the changes take effect. The "Last updated" date at the top indicates the current version.
14. Contact
Loopworks OÜ, a private limited company incorporated in the Republic of Estonia (registry code 17578714), with its registered address at Ahtri tn 12, Kesklinna linnaosa, Tallinn, Harju maakond, 10151, Estonia. For any privacy questions or to exercise your rights, contact [email protected].