1. Who we are
wwworks AB (reg. no. 559XXX-XXXX), Street 1, 111 11 Stockholm, Sweden, is the controller of the personal data described in this policy, except where section 2 says we act for a customer.
Questions and requests about personal data: hello@example.com.
2. Our two roles
- As controller, we handle data about the people who use LOOPS for our customers, visitors to our website, newsletter subscribers and anyone who contacts us. This policy covers that data.
- As processor, we handle personal data for our customers: data in the ad accounts they connect, and the purchase events their online shops send us (section 5). The customer is the controller of that data, and its own privacy policy applies. Our data processing terms set out how we handle it.
If you shop with one of our customers and want to exercise your rights, contact that business. We’ll help them respond.
3. What we collect and why
We collect data you give us, data created when you use LOOPS, and data from the services you connect.
| Data | Why | Legal basis | How long |
|---|---|---|---|
| Account: name, email address, sign-in method, team membership and user ID. Passwords are stored only as a hash, by our sign-in provider. | To create your account, sign you in, keep it secure and let your team work together. | Contract (GDPR Art. 6(1)(b)) | While your account exists; deleted within 30 days after it closes. |
| Sign in with Google: your name, email address and profile picture. | To sign you in. | Contract | As account data. |
| Billing: company name, billing address, VAT or tax ID, subscription status and invoices. Card details are handled by Stripe; we never see or store full card numbers. | To charge the fee, issue invoices and follow accounting and tax rules. | Contract; legal obligation (Art. 6(1)(c)) | Invoices and accounting records: until the end of the seventh year after the financial year, as the Swedish Bookkeeping Act requires. Other billing data: as account data. |
| Connected ad accounts: see section 4. | To provide the service. | Contract | While connected; see section 4. |
| Products and creatives: product names, descriptions, prices, product costs (where your store shares them), links and images, the ads we write and render, and the ads you add yourself (their images, videos, texts and links). Images and videos may show people. Location data is removed from images when they are added; videos are kept as you upload them, so remove location data before uploading if you don’t want it shared. | To create and publish your ads. | Contract | While your account exists. |
| Library: files you upload or import from a web page (product photos, logos, lifestyle images and PDF guidelines), their names and your notes, your brand voice, and what the AI learned from your website (what you sell, the facts and offers it states, how it sounds, and which pages it read). Photos may show people. Location data is removed from photos when they are added. | To create ads from them: the AI reads them, and photos can become ad images. | Contract | Until you remove them, or the account closes. |
| Team: the email address of people you invite, the role you give them and who invited them; for members, their role and when they joined. | To let your colleagues work in LOOPS with the access you choose. | Contract; for people invited but not yet joined, legitimate interest in letting the customer add them | While the account exists. An invitation link stops working after 7 days. |
| Activity: your budget history, the decisions we made and why, and who changed what and when, including changes to the team, the library and settings. | To show you what we did, keep an audit trail and prevent misuse. | Contract; legitimate interest in accountability and security (Art. 6(1)(f)) | While your account exists. |
| Service email: your email address and delivery status. | To send the weekly report and messages about your account. | Contract | As account data. |
| Newsletter: your email address, when you signed up and, if you do, when you unsubscribed. | To send the monthly benchmark report you asked for. | Consent (Art. 6(1)(a)), which you withdraw by unsubscribing | Until you unsubscribe. We then keep only a note that you unsubscribed, so we don’t email you again. |
| Messages to us: what you write and your contact details. | To answer you and improve our support. | Legitimate interest in replying; contract if you’re a customer | Up to 24 months after the conversation ends. |
| Usage analytics: pages viewed, clicks, browser and device type, the referring website and approximate location. No cookies, no IP address stored, and no link to your account or to earlier visits. | To understand how the website and app are used and improve them. | Legitimate interest in improving the service | Up to seven years, in a form that can’t be linked to you. |
| Error reports: browser and operating system, the page or function that failed, and technical details of the error. No names, email addresses, cookies, headers or form contents. | To find and fix faults and keep the service secure. | Legitimate interest in a working, secure service | 90 days. |
| Security logs: IP address, browser, time and the address requested, kept by our hosting and sign-in providers. | To protect the service against abuse and attacks. | Legitimate interest in security | Hosting logs up to 30 days; sign-in activity as account data. Longer if needed to investigate an incident. |
You don’t have to give us personal data, but we can’t provide LOOPS without account and billing data. Where we rely on legitimate interests, we have weighed them against your rights, and you can object at any time (section 12).
4. Data from your ad platforms and store
When you connect an advertising platform, you choose the accounts to share and approve the permissions below. We ask only for what LOOPS needs, and we use the data only to provide LOOPS to you: to read results, decide and apply budgets, create and publish ads, and report what we did.
We don’t sell platform data, use it to profile or target individuals, use one customer’s data for another customer, or use it to train AI models. We share it only with the service providers in section 8 that need it to run LOOPS. Access tokens are encrypted with AES-256, and all data travels over TLS 1.2 or higher (section 10).
Meta (Facebook and Instagram)
Through Facebook Login for Business you grant these permissions for the business assets you select:
ads_management: to change budgets and the account spending limit, pause and resume ads, create ads and send purchase events to your dataset.ads_read: to read your ad accounts, campaigns, ad sets, ads and their results.business_management: to reach the ad accounts, Pages and datasets you share from your business portfolio.pages_show_list: to list the Pages you can advertise as.pages_manage_ads: to publish ads as your Page.pages_read_engagement: to read your Page's name and the posts used in your ads.
We receive and store the ID of the Meta user or system user that authorizes us, the permissions granted and an encrypted access token. For the assets you share we store ad account details (name, currency, time zone, status, spending limit and amount spent); campaigns, ad sets and ads with their names, status and budgets; ad creatives (text, images, links and the Page they run as); and results such as spend, impressions, clicks, conversions and conversion value.
We keep this data while the connection is active. When you remove LOOPS in Meta, ask us to disconnect or close your account, we delete the access token and the data we received from Meta within 30 days, except aggregated figures that can’t identify you or anyone else. See Delete your data.
Sign in with Google. If you choose it, we receive your name, email address and profile picture from Google through our sign-in provider, Clerk. We use them only to create your account and sign you in, and delete them with your account.
Google Ads (coming soon). When you connect Google Ads, you grant access to manage your Google Ads accounts (scope https://www.googleapis.com/auth/adwords). We read account details (ID, name, currency and time zone), campaigns, ad groups, ads, budgets and performance reports, and change budgets, status and ads as described above. If you turn on conversion tracking through LOOPS, we send your shop’s purchase events to your Google Ads account with email addresses and phone numbers hashed. We keep Google Ads data while connected and delete it within 30 days after you disconnect or close your account.
The use and transfer by LOOPS of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
That means we use Google user data only to provide and improve the features you use in LOOPS. We don’t transfer it except as needed for those features, to comply with law or as part of a merger or acquisition. We don’t use it for advertising, sell it, or use it to develop, improve or train generalized AI or machine learning models. No one at wwworks AB reads it unless you ask us to, it’s needed for security, or the law requires it. You can revoke access at any time under Third-party apps & services in your Google Account.
TikTok (coming soon)
When you connect TikTok for Business, you authorize access to the advertiser accounts you choose. We read account details, campaigns, ad groups, ads, budgets and reports, and change budgets, status and ads as described above. If you turn it on, we send your shop’s purchase events to your TikTok pixel through the Events API, with email addresses and phone numbers hashed. We keep TikTok data while connected and delete it within 30 days after you disconnect or close your account. You can revoke our access in TikTok for Business at any time.
Shopify
When you connect your Shopify store, you approve access to read your products (read_products) and to add the LOOPS pixel to your store (write_pixels, read_customer_events). We store an encrypted access token and your store’s name, myshopify.com address and currency, and copy your active products: names, descriptions, prices, links, vendor, type and images, and each product’s cost where your store allows apps to see it. The AI uses them to write about your real products, and their photos can become ad images. Costs are used to work out your margins when your goal is profit. We don’t read your orders or your customer list.
If you turn on purchase tracking, the LOOPS pixel sends each completed checkout to us as described in section 5. Shopify runs the pixel only for shoppers who allowed analytics and marketing in your store’s cookie settings.
We keep your products while the store is connected and update them every night. When you disconnect, we delete them at once; if you remove the app in Shopify, tracking stops at once, and when Shopify asks us 48 hours later to delete the store’s data, we delete it right away.
5. Server-side events from your shop
Browsers increasingly block tracking, so a customer’s online shop can send purchase and other events to LOOPS server to server. We pass them on to the customer’s own dataset at Meta and, when available, Google and TikTok.
An event can contain a shopper’s email address, phone number, customer ID, IP address, browser user agent, Meta click and browser IDs, the page, and the purchase (products, value and currency). Before forwarding, we hash the email address, phone number and customer ID with SHA-256, as the platforms require. We don’t store the shopper’s personal data: we keep only the event’s ID, name, time and value, to avoid counting a purchase twice and to show results.
For Shopify stores with purchase tracking on, the LOOPS pixel sends the event from the shopper’s browser after checkout, including the Meta browser and click IDs stored in the shop’s own cookies and the IP address the request comes from. Email and phone are included only where Shopify has approved our access to protected customer data.
We do this as the shop’s processor. The shop decides what to send and must have a legal basis for it, such as consent to marketing cookies where the law requires it. Shoppers should contact the shop about their data.
6. AI and automated decisions
We use Claude, an AI model from Anthropic, to write and revise ad copy. It receives product information, the text of your best-performing ads, your brand voice, the instructions you give when you revise an ad, and the images and PDFs in your library. When you give us your website, Claude reads its public pages through Anthropic’s web fetch, limited to your site’s own domain, and we keep a summary of what it learned. When you import from a web page, our servers download the files you choose. Library photos can show people; the rest isn’t meant to contain personal data. Anthropic processes it as our service provider and, under its commercial terms, doesn’t use it to train its models.
LOOPS decides automatically how to split your budget between ads and when to pause one. These are decisions about ads, not about people: they have no legal or similarly significant effect on anyone, so the GDPR rules on automated individual decisions (Art. 22) don’t apply. Every decision is logged with its reasons, and you can pause any ad yourself.
8. Service providers
These providers process personal data for us. The list is also the subprocessor list for data we process for customers, who get notice before it changes (see the data processing terms).
| Provider | What they do | Where the data is |
|---|---|---|
| Vercel Inc. (USA) | Hosts the website and app, and counts page views | EU (Stockholm); pages are delivered through a global network, and page-view statistics are kept in the USA |
| Supabase, Inc. (USA) | Database | EU (Stockholm) |
| Fly.io, Inc. (USA) | Runs the budget optimizer, which receives only aggregated ad results | EU (Stockholm) |
| Amazon Web Services EMEA SARL (Luxembourg) | Stores the files you upload to the library, and holds the keys that encrypt access tokens | EU (Stockholm) |
| Clerk, Inc. (USA) | Sign-in and account management | USA |
| Stripe Payments Europe, Limited (Ireland) | Payments, subscriptions and invoices | EU and USA |
| Inngest, Inc. (USA) | Schedules background jobs; sees internal IDs only | USA |
| Anthropic, PBC (USA) | AI that writes ad copy | USA |
| Resend, Inc. (USA) | Sends email | USA |
| PostHog, Inc. (USA) | Usage analytics | EU (Germany) |
| Functional Software, Inc. (Sentry) (USA) | Error monitoring | EU (Germany) |
9. Transfers outside the EU
We keep data in the EU where we can. Some providers in section 8 are in the USA or have staff there. For those transfers we rely on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses, with additional safeguards such as encryption. Data from the UK and Switzerland is covered by the UK Addendum and the Swiss adaptations of those clauses. You can ask us for a copy of the safeguards.
10. How we protect data
- Data is encrypted in transit (TLS 1.2 or higher) and at rest.
- Access tokens for advertising platforms are encrypted with AES-256 using keys held in AWS KMS in Stockholm, and each token can be decrypted only for its own customer and connection.
- Keys that shops use to send events are shown once and stored only as a hash.
- Library files and the files of your own ads are stored privately in Stockholm, encrypted, and shown only to your team. Invitation links are stored only as a hash.
- Error reports never include request contents, cookies or user details.
- Only people who need access have it, protected by two-factor authentication, and we review it regularly.
- Backups are encrypted and kept for up to 30 days.
- If a personal data breach occurs, we notify the supervisory authority within 72 hours where required, and the people affected without undue delay if it puts them at high risk.
11. How long we keep data
We keep personal data only as long as the purposes in section 3 require. In short:
- Account, ad platform, product and activity data: while your account exists, deleted within 30 days after it closes.
- Invoices and accounting records: until the end of the seventh year after the financial year, as the Swedish Bookkeeping Act requires.
- Newsletter: until you unsubscribe.
- Error reports: 90 days. Hosting logs: up to 30 days.
- Usage analytics: up to seven years, in a form that can’t be linked to you.
- Deleted data can remain in encrypted backups for up to 30 days.
Aggregated data that can’t identify anyone may be kept longer.
12. Your rights
You have the right to:
- access your personal data and get a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict how we use it;
- receive it in a machine-readable format and have it transferred to another service;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time, without affecting processing before you withdrew it.
Email hello@example.com. It’s free. We reply within one month; if a request is complex, we may need two more months and will tell you why. We may ask you to confirm your identity.
You can also complain to a supervisory authority: in Sweden, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se), or the authority where you live or work, such as the ICO in the UK or the FDPIC in Switzerland. We’d appreciate the chance to put things right with you first.
These rights apply to everyone who uses LOOPS, wherever you are. If the law where you live gives you further rights, as some US state laws do, we honor those too.
13. Delete your data
You can have us delete your data at any time, including everything we received from Meta, Google or TikTok:
- Remove our access. Meta: remove LOOPS from your business integrations, in Meta Business Suite or in Facebook under Settings & privacy → Settings → Business integrations (Meta’s instructions). Google: Third-party apps & services in your Google Account. TikTok: remove LOOPS from the apps with access to your TikTok for Business account. Shopify: remove LOOPS under Settings → Apps in your Shopify admin.
- Ask us to delete. Email hello@example.com from the address on your account and tell us what to delete: the data from one platform, or your whole account.
- Confirmation. We delete the data within 30 days and confirm by email. Invoices we must keep by law are kept apart until the retention period ends.
Removing our access stops LOOPS from reading or changing anything straight away. Ads and settings already in your ad accounts stay there; they’re yours.
15. Children
LOOPS is a service for businesses and isn’t meant for anyone under 18. We don’t knowingly collect data about children.
16. Changes to this policy
We update this policy when our processing changes; the date at the top shows the current version. Before material changes take effect, we tell customers by email or in the app.
17. Contact
wwworks AB, reg. no. 559XXX-XXXX
Street 1, 111 11 Stockholm, Sweden
hello@example.com