Legal - Privacy Policy

At Looped, we believe in transparency and respect for your privacy. This policy explains what data we collect, how we use it, and your rights regarding your information.

Last updated: January 27, 2025

Previous version: None

Overview

Looped provides time tracking and invoicing tools designed for consultants, freelancers, and agencies. This privacy policy applies to all Looped applications and services, including Looped Track and Looped Invoices.

We only collect data that is necessary to provide and improve our services. We do not sell your data to third parties, and we never will.

Data Controller

The controller of your personal data is:

Looped Process Improvement and Automation Consultants (Pty) Ltd

Registration Number: 2021/782285/07

Cape Town, South Africa

Email: privacy@looped.sh

"Personal data" means any information relating to an identified or identifiable individual. This policy does not apply to anonymised or de-identified data from which no individual can reasonably be identified.

Controller vs Processor

Looped acts as a data controller when you create an account, visit our websites, or interact with us directly.

When you use Looped in a team or organisation context, the account owner or organisation administrator is typically the data controller for team member data, and Looped acts as a data processor on their behalf. If you have questions about how your organisation handles your data, please contact your account administrator.

Information We Collect

Account Information

When you create a Looped account, we collect:

  • Email address
  • Name
  • Profile picture (from your OAuth provider)

We use Auth0 for secure authentication. Your login credentials are managed by Auth0 and your chosen OAuth provider (Google, Microsoft, etc.) - we never see or store your passwords.

Time Tracking Data (Looped Track)

To provide time tracking functionality, we store:

  • Time entries with duration, task names, and descriptions
  • Project information including titles, codes, and statuses
  • Team member assignments and roles
  • Custom tags for organizing your work
  • Email reminder preferences (address, frequency, timezone)
  • Custom report configurations

Invoicing Data (Looped Invoices)

To enable invoicing functionality, we store:

  • Client information: names, VAT numbers, email addresses, phone numbers
  • Business addresses (your address and client addresses)
  • Invoice details: line items, amounts, dates, statuses
  • Bank account information for payment instructions
  • Payment integration credentials (encrypted)
  • Invoice styling preferences

Calendar Integration Data

When you connect your calendar to Looped Track, we access calendar data strictly for the purpose of importing events as time entries. This is a read-only integration.

Google Calendar:

  • Access scopes: openid, email, profile, calendar.readonly
  • Data accessed: Event subjects, start times, and end times from your selected calendar
  • Data stored: OAuth tokens (encrypted), selected calendar ID, imported event IDs
  • We do not access event attendees, locations, descriptions, or any other calendar metadata

Microsoft Calendar:

  • Access scopes: openid, profile, email, User.Read, Calendars.Read, offline_access
  • Data accessed: Event subjects, start times, and end times from your selected calendar
  • Data stored: OAuth tokens (encrypted), account email, selected calendar ID, imported event IDs
  • We do not access event attendees, locations, descriptions, or any other calendar metadata

Important: You can disconnect your calendar at any time from your Looped Track settings. When you disconnect, we immediately delete all stored OAuth tokens and calendar integration data. Previously imported time entries remain in your account but are no longer linked to calendar events.

Payment Processing

We integrate with several payment processors to enable invoice payments:

  • Stripe
  • Yoco
  • Payfast
  • Coinbase Commerce

Payment data (credit card numbers, banking information) is handled directly by these PCI-compliant processors. We never see or store your customers' payment card details.

We store: checkout session IDs, integration parameters, and merchant credentials (encrypted) required to facilitate payments on your behalf.

Analytics and Product Usage

We use PostHog for product analytics with privacy-focused configuration:

  • Only identified users are tracked (no anonymous tracking)
  • Feature flag data for product features
  • Usage patterns to improve our products
  • All analytics are proxied through our own infrastructure

We do NOT collect:

  • IP addresses
  • Precise location data
  • Device fingerprints
  • Browsing history outside of Looped

AI-Powered Features

When you use AI-powered features in Looped, we send certain data to third-party AI providers for processing:

  • Calendar event titles (for smart time entry suggestions)
  • Task names and descriptions
  • Time entry data (durations, project names)

This data is sent only when you actively use AI features. Our AI providers process this data solely to provide the requested functionality. When accessed via their APIs, these providers do not use your data to train their models. If you prefer not to have this data processed by AI providers, you can choose not to use AI-powered features.

We may use the following AI providers:

We do NOT send to AI providers:

  • Your account credentials or passwords
  • Email addresses or contact information
  • Payment or billing information
  • Client details from invoices
  • Bank account information

Note: If you include personal information in your calendar event titles, task names, or descriptions (such as someone's name), that information may be sent to AI providers if you use AI classification features.

Cookies

We use cookies for essential functionality only:

  • Authentication cookies (Auth0 session, domain: .looped.sh)
  • Theme preference cookie (dark/light mode)
  • Team preference cookies

We do not use advertising cookies or third-party tracking cookies. Our services do not respond to "Do Not Track" browser signals because we do not engage in cross-site tracking.

How We Use Your Information

We use your data exclusively to:

  • Provide and maintain our time tracking and invoicing services
  • Process your time entries and generate reports
  • Create and send invoices on your behalf
  • Import calendar events into your time tracking workspace
  • Send email notifications and reminders you've requested
  • Process payments through your chosen payment integrations
  • Improve our products based on usage patterns
  • Provide customer support
  • Communicate important service updates

We do not use your data for advertising purposes, and we do not sell, rent, or share your personal information with third parties for their marketing purposes.

Legal Basis for Processing

Under GDPR and similar data protection laws, we must have a legal basis for processing your personal data. We rely on the following grounds:

PurposeLegal Basis
Providing our services (time tracking, invoicing)Contract performance
Processing paymentsContract performance
Sending service notificationsContract performance
Calendar integrationConsent (you authorise the connection)
Product analytics and improvementLegitimate interest
Customer supportContract performance / Legitimate interest
Security and fraud preventionLegitimate interest / Legal obligation
Tax and financial recordsLegal obligation
Marketing communications (if opted in)Consent

Where we rely on legitimate interest, we have assessed that our interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interest by contacting us at privacy@looped.sh.

Data Storage and Security

Your data is stored securely using industry-standard practices:

  • All data transmission is encrypted using TLS/SSL
  • Sensitive credentials (OAuth tokens, payment integration keys) are encrypted at rest
  • Database access is restricted and audited
  • Regular security updates and monitoring

We use trusted infrastructure providers with strong security practices and compliance certifications. However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.

Data Retention

We retain your data for as long as your account is active or as needed to provide you services.

When you delete your account:

  • All personal data, time entries, projects, and invoices are permanently deleted within 30 days
  • Calendar integration tokens are immediately deleted when you disconnect your calendar
  • Some anonymized usage data may be retained for analytics purposes
  • We may retain certain records for legal compliance (e.g., tax records) as required by law, typically for 5-7 years

Third-Party Services and Subprocessors

We use carefully selected third-party services to operate Looped. These subprocessors may have access to your personal data only to perform specific tasks on our behalf and are obligated to protect your data:

ServicePurposeLocation
Auth0 (Okta)Authentication and user managementUSA/EU
GoogleCalendar integration, OAuth (inbound data only)USA
MicrosoftCalendar integration, OAuth (inbound data only)USA/EU
AI Providers (OpenAI, Anthropic)AI-powered featuresUSA
PostHogPrivacy-focused product analyticsEU
StripePayment processingUSA
YocoPayment processingSouth Africa
PayfastPayment processingSouth Africa
Coinbase CommerceCryptocurrency paymentsUSA

Data Flow Clarification

Google and Microsoft integrations: These are inbound integrations only. We receive data from these services (such as calendar events) when you authorise the connection. We do not send your Looped data to Google or Microsoft.

AI providers: When you use AI-powered features in Looped, we send certain data to our AI providers (such as OpenAI or Anthropic) for processing. This may include:

  • Calendar event titles (for smart time entry suggestions)
  • Task names and descriptions
  • Time entry data

These providers process this data to provide AI features and do not use data received via their APIs to train their models. You can choose not to use AI-powered features if you prefer not to have this data processed by AI providers.

Each of these services has their own privacy policy and security practices. We only share the minimum necessary data with these services to provide functionality. We are not responsible for the privacy practices of third-party services, and we encourage you to review their privacy policies.

International Data Transfers

Looped is operated from South Africa. Your data may be transferred to, stored, and processed in locations where our service providers operate, including the United States. We use reputable service providers with strong security practices to protect your data.

Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of all personal data we hold about you
  • Rectification: Update or correct your information at any time through your account settings
  • Erasure: Request deletion of your personal data (subject to legal retention requirements)
  • Portability: Export your data in machine-readable formats
  • Restriction: Request that we limit processing of your data in certain circumstances
  • Object: Object to processing based on legitimate interest
  • Withdraw consent: Where processing is based on consent, withdraw it at any time (this does not affect prior lawful processing)
  • Disconnect integrations: Remove calendar or payment integrations at any time
  • Opt-out: Unsubscribe from marketing communications (essential service communications will continue)

To exercise any of these rights, contact us at privacy@looped.sh. We will respond within 30 days (or sooner if required by applicable law). We may need to verify your identity before processing your request.

Right to Lodge a Complaint

If you believe we are processing your personal data in violation of applicable law, you have the right to lodge a complaint with a supervisory authority:

South Africa: Information Regulator — www.inforegulator.org.za

Children's Privacy

Looped is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at privacy@looped.sh and we will take steps to delete such information.

Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.

When we make significant changes, we will notify you via email or through a prominent notice in the application at least 30 days before the changes take effect. Your continued use of Looped after such notification constitutes acceptance of the updated policy.

We encourage you to review this policy periodically. The "Last updated" date at the top of this page indicates when this policy was last revised.

Contact Us

If you have questions, concerns, or requests regarding this privacy policy or how we handle your data, please contact us:

Looped Process Improvement and Automation Consultants (Pty) Ltd

Privacy enquiries: privacy@looped.sh

General enquiries: hello@looped.sh

Location: Cape Town, South Africa

Registration: 2021/782285/07

We aim to respond to all privacy-related enquiries within 5 business days.

Compliance

Looped is committed to complying with applicable data protection laws, including South Africa's Protection of Personal Information Act (POPIA).