Data Processing Agreement
Last updated: August 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Customer”) and Looplift, and applies whenever Looplift processes personal data on your behalf. Where this DPA and the Terms conflict on the subject of data protection, this DPA governs. It takes effect when you accept the Terms; a countersigned copy is available on request from support@looplift.io.
1. Roles
For personal data contained in your workspace — your storefront’s visitors, your analytics, and (where connected) your store’s orders — you are the controller and Looplift is the processor. We process that data only on your documented instructions, which are given by your use of the product and by this DPA.
For your own account data — the email address you sign in with, your billing identifiers, and how you use the app — Looplift is the controller, and our Privacy Policy governs.
2. Subject matter, duration, nature and purpose
Subject matter and purpose: running, measuring and reporting on conversion experiments on the sites you connect, and auditing the pages you ask us to audit.
Duration: for the term of your subscription, plus the retention periods in section 6.
Nature of processing: collection, storage, aggregation, statistical analysis, and deletion. We do not enrich, profile, segment or personalise per individual, and we do not sell, rent or share personal data with any third party for their own purposes.
3. Categories of data subjects and personal data
- Your site’s visitors. A first-party identifier we generate (
lpl_vid), the experiment and arm they were assigned, the pages on which they were exposed, and whether a conversion event occurred. No name, email, address, phone number or account identity. - Your store’s orders, where you connect a commerce platform. The order id, the total in minor units, the currency, the refund status, the timestamp, and the experiment assignment. No customer identity fields are requested or stored — our order records have no column that can hold one.
- Your team. The email addresses and names of the people you invite into your workspace.
We do not knowingly process special categories of personal data, and the product has no use for them.
4. Security measures
- All traffic is encrypted in transit (TLS); the database encrypts data at rest.
- Tenant isolation is enforced in the database, by row-level security policies on every table that holds workspace data, rather than by application code alone — so one workspace cannot read another’s rows even if application code asks for them.
- Third-party access tokens you grant us (for example a connected analytics account) are stored encrypted, never in plain text.
- Access to production is limited to Looplift personnel who need it, and administrative interfaces are behind authentication and an explicit allow list.
- Payment card data is never transmitted to or stored by Looplift; our payments provider handles it.
5. Subprocessors
You give general written authorisation for Looplift to engage the subprocessors below. We impose data protection obligations on each of them no less protective than this DPA, and we remain responsible for their performance.
- Supabase — authentication, database and file storage. Primary database region: EU (eu-central-2).
- Vercel — application hosting and delivery.
- DigitalOcean — hosting for the audit and variant-generation worker.
- Anthropic — the model that analyses the pages we audit and drafts experiment variants. Page content you ask us to audit is sent to it; it is not used to train models.
- Firecrawl — fetching the pages you ask us to audit.
- Polar — subscription billing.
- Resend — transactional email.
- Microsoft Clarity — product analytics for the Looplift app itself (not your site).
- Google — only if you connect Google Analytics, and only for the property you choose.
We will give notice before adding or replacing a subprocessor, and you may object on reasonable data protection grounds; if we cannot accommodate the objection you may terminate the affected service. Some subprocessors process data outside the EEA or the UK; where they do, transfers rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.
6. Retention and deletion
Order records are deleted 180 days after the order occurred, automatically. That is a scheduled job, not a policy statement: after six months an order answers no question the product asks, and the per-arm figures that outlive it are aggregates computed before deletion.
Everything else in your workspace is deleted by action: delete an audit, an experiment, a site or the workspace, and its data is deleted with it. Deleting your account removes any workspace where you are the only member, together with its sites, audits, experiments and learnings.
On termination, we delete your workspace data on request and otherwise as part of account closure. Where a commerce platform sends us an erasure instruction on a customer’s behalf, we honour it on receipt rather than waiting for the retention period — it does not wait out the six months.
7. Assisting you
Data subject requests. Because we hold no customer identity fields, we generally cannot identify a data subject from a name or an email address, and we will say so plainly rather than guess. Where you can identify the records — for example by order id — we will action access, correction, export and deletion requests without undue delay, at no charge.
Personal data breaches. We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any event within 72 hours, with what we know: what happened, which data and roughly how many records are affected, what we have done, and what we recommend you do. Our written incident response procedure covers detection, containment, assessment, notification and a follow-up note.
Impact assessments and audits. We will provide the information reasonably necessary for your data protection impact assessments and to demonstrate compliance with this DPA. Audit rights are satisfied in the first instance by that information; on-site audits are by agreement and at reasonable intervals.
8. Confidentiality and instructions
Personnel authorised to process your data are bound by confidentiality. We will tell you if, in our opinion, an instruction infringes applicable data protection law, and we will not process your data for our own purposes — including training models on your workspace content.
9. Contact
Questions about this DPA, requests for a countersigned copy, subprocessor notices and breach correspondence: support@looplift.io.