Privacy Policy
Last updated: August 8, 2026
Who we are
Loopful is owned and operated by RUS E. ADRIAN PFA, registered in Romania.
- Registered office: 136 Bulevardul Bucureștii Noi, ground floor, apartment 5, Sector 1, Bucharest, Romania
- VAT ID: RO55335763
- Registration number: F40/372/2024
- Contact: [email protected]
Loopful provides customer feedback boards, roadmaps, changelogs, and an embeddable feedback widget at loopful.app.
Two different roles
This matters for who is responsible for what, so it is worth being precise.
When you hold a Loopful account (you signed up, you run a workspace), we are the data controller for your account data and we answer to you directly.
When you post on a feedback portal someone else runs, that company is the controller of their portal. They decide what to collect and why. We host it on their behalf as a processor, acting on their instructions. Requests about that data are best sent to them, though you can always contact us and we will help.
To be direct about what that means in practice: if you sign in to a portal, the company running it can see your name and email address, alongside everything you post, comment on, and vote for. They can also export that list. Your email is not shown to other visitors, only to the team running the portal.
Where a portal allows it you can take part without signing in. Anonymous votes and posts carry no name or email, and the portal owner sees only that an anonymous person took part.
What we collect
Account data: your name, email address, and a hashed password. We never store passwords in a readable form.
Content you create: posts, comments, votes, boards, statuses, changelog entries, survey responses, and any files you upload.
Portal identities: people who take part in a portal may give an email address and name, or take part anonymously. Anonymous participants get a random per-browser identifier and no personal data beyond it.
Technical data: IP address and request logs used for rate limiting, abuse prevention, and troubleshooting. Your IP is recorded at signup for the same reason.
We do not collect special category data, we do not build advertising profiles, and we do not sell personal data to anyone.
Why we are allowed to use it
Under the GDPR we rely on performance of a contract to run the service you signed up for, legitimate interests to keep the platform secure and working, consent for marketing email (which you can withdraw at any time), and legal obligation for tax and accounting records.
Who else sees it
We use a small number of providers to run the service. Each only receives what it needs:
- Hosting and databases in the European Union, where your data is stored at rest.
- Cloudflare, if you connect a custom domain to your portal, to issue and serve the certificate for it.
- Our email provider, to deliver transactional and newsletter email.
- Google Analytics, on our marketing pages, to count visits and see which pages people find useful. It does not run on customer feedback portals or inside the app.
- Gravatar, only where someone has chosen to show their Gravatar as their picture. We send Gravatar nothing: the browser displaying the page fetches the image from gravatar.com, and the image address includes a scrambled version of the email tied to that Gravatar account, so gravatar.com can see that the request happened and the IP address it came from. Anyone who would rather avoid this can pick a different picture, or none, in their profile settings.
Payments. Paddle.com Market Ltd is the merchant of record for Loopful subscriptions. When you buy a plan you are contracting with Paddle: they take the payment, handle VAT and issue your invoice. You give your billing details to Paddle directly, and they act as their own controller for that data rather than as a provider acting on our instructions. We never see or store your full card number. Payments appear on your bank or card statement as PADDLE.NET* LOOPFUL. What Paddle does with those details is covered by Paddle's privacy notice.
Third-party integrations. If you connect an integration to your workspace such as Slack, Discord, Intercom, Asana, a webhook, or your own outgoing mail server, feedback content is sent to the destination you configure. Intercom and your own mail server additionally receive the email address of the person a notification concerns, because that is what identifies them at the other end. Those are your integrations, and what happens to the data once it leaves us is your responsibility.
Some providers may process data outside the European Economic Area. Where they do, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.
How long we keep it
Content and account data are kept while your account is active. Some things are cleared automatically:
- Portal sign-in codes: 24 hours after expiry
- Anonymous portal identities that left no votes, posts, or comments: 24 hours
- Uploaded import files that were never completed: 7 days
When you delete your account we remove your workspaces and everything in them, including uploaded files and any custom domain we provisioned for you. Anything you contributed to a workspace you do not own is unlinked from you rather than deleted, so the workspace owner's records stay intact. Tax and accounting records are kept for as long as Romanian law requires.
Cookies and local storage
We use a strictly necessary session cookie for sign-in and CSRF protection, and a long-lived cookie so portal visitors are not asked for a code on every visit. Your browser also stores your light or dark theme preference and a note of which survey prompts you have dismissed. The feedback widget stores a random identifier so your votes are remembered on the site you are visiting.
Our marketing pages also load Google Analytics, which sets its own cookies. It does not run on customer feedback portals, in the dashboard, or in the widget.
We do not use advertising cookies, and we neither sell your data nor share it to target ads at you.
Your rights
You can ask for access, correction, export, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. Email [email protected] and we will respond within 30 days.
You do not have to ask for an export: Settings has a one-click complete export of your workspace on every plan, including Free. Marketing email carries an unsubscribe link in every message.
If you believe we have handled your data badly, you can complain to your local supervisory authority. In Romania that is the ANSPDCP.
Data processing agreement
If your organisation needs a Data Processing Agreement in place before using Loopful, email [email protected]. We are happy to provide one and to work through your document if you would rather use your own.
Our sub-processors are the providers listed under “Who else sees it” that handle data on our instructions. Paddle is not one of them: as merchant of record it is a separate controller for your payment, so it sits outside that agreement and outside our DPA with you.
Security
Traffic is encrypted in transit. Passwords are hashed. Uploaded files are stored outside the web root and re-encoded so they cannot execute. Access to production data is limited to the operator of the service.
If you find a security problem, please tell us at [email protected] before disclosing it publicly. We will take it seriously and credit you if you would like.
Changes
If we change this policy in a way that materially affects you, we will update the date above and tell account holders by email before it takes effect.