Last updated 16 August 2026
Privacy
Loopberry reads the analytics you already own and turns it into something you can act on. This page explains exactly what we collect to do that, what we deliberately don't, and how to get any of it deleted.
Loopberry is in private beta. We’ll update this page as the product grows, and we’ll tell you before any change that affects what we collect about you.
Who we are
Loopberry is a product of Loopberry, LLC, 1301 N Broadway STE 92334, Los Angeles, CA 90012. We’re the data controller for the account information described below, and you can reach us any time at hello@loopberry.app.
Who this covers
This policy covers you — the brand operator with a Loopberry account — and separately the people who visit your store, pay you, or fill out a form on your website, if you connect Shopify, Stripe, or your own site for lead tracking, and share-link partners you invite to look at a brand-collaboration mockup. Those are very different relationships, so we describe them separately below. For your store visitors, payers, and site visitors, you are the data controller and we act on your instructions as a processor. For a share-link partner, the workspace that created the link is the controller of the name and email collected at the gate; we store that record so the workspace can see who opened it.
What we collect about you
- Your account. Your email address, your workspace name, and which workspaces you belong to. We sign you in with a magic link, so we never ask for or store a password.
- Your billing status. Your plan, whether your subscription is active, and the Stripe customer and subscription identifiers. Card details go straight to Stripe’s hosted checkout — they never touch our servers.
- Connected-account tokens. When you connect Google Analytics, Meta, TikTok, or Shopify, we store the access and refresh tokens that let us read your data. They are encrypted at rest with AES-256-GCM under a key held separately from the database. Stripe is the one exception: we store no token for it at all — only your connected Stripe account’s identifier, which is all Stripe’s own recommended integration pattern asks us to keep.
- What you create in the app. Campaigns, strategies, generation prompts, scheduled posts, and the settings you choose.
- Brand-collab shares. When a workspace shares mockups with you and asks for your name and email, we store them and pass them to that workspace so they can follow up. We also record that the link was opened, as a count and a coarse, non-identifying signal — never your IP address. The workspace that created the share sees the name, email, and open counts. Open records are deleted after 90 days; name and email stay with the share until that workspace deletes the link or asks us to erase it.
- In-app reports. When you send a bug report, feedback, or question from the app, we store what you type, which workspace you were in, your account email, and — only if you choose — the page path you were on. That free text may include other people’s details if you paste them; please don’t unless you need to. We use it only to respond or fix the issue, never to train models. We do not send your raw report text to GitHub or other trackers — if we open an engineering issue later, an operator writes a paraphrase.
What we pull from the platforms you connect
We only read what the scopes you grant allow, and only for the workspace you connected. Nothing is written back to your accounts except actions you explicitly ask for — publishing a post you scheduled, or applying a budget change you approved.
- Google Analytics 4. Aggregate metrics only — sessions, conversions, revenue, active users, new users, event counts, and landing-page performance. We never request user-level or individual-visitor GA4 data.
- Instagram and Meta. Your own organic posts and their per-post insights (reach, likes, comments, shares, saves, views). While Overview is open we also refresh like and comment counts on those posts. Daily Facebook Page metrics (reach, impressions, engagements, and Page likes), and your ad-account spend and performance. When you schedule a Facebook post we publish it to the connected Page as the Page. We do not collect your followers’ profiles, their messages, or their personal details.
- TikTok. Your creator profile basics, and — for videos published through Loopberry — that video’s own view and engagement counts. Ad spend, if you connect a TikTok advertiser account.
- Shopify. Order totals, currency, and timestamps. See the next section for what we strip out first.
- Stripe. Payment amounts, currency, and timestamps for the Stripe account you connect — never card numbers or other payment-method details, which stay with Stripe. See the next section for how, and whether, we can tie a payment to the ad click that preceded it.
How we use Google user data
This section describes, specifically, how Loopberry accesses, uses, stores, and shares data from your Google account — your Google user data.
- What we access. When you connect Google Analytics, you grant the read-only
analytics.readonlyscope. We use it solely to call the Google Analytics Data API and read aggregate metrics — sessions, conversions, revenue, active users, new users, event counts, page views, and landing-page performance — for the GA4 property you choose. We request no user-level or individual-visitor data, and we never write to, or delete anything in, your Google Analytics. - How we use it. Only to provide the feature you connected it for: showing your own analytics back to you inside your Loopberry dashboard — charts, week-over-week changes, anomaly alerts, top-performing pages, and the suggested actions derived from them. We do not use Google user data for advertising, and we do not use it to train machine-learning or AI models.
- How we store it. The OAuth tokens that let us read your Analytics are encrypted at rest (AES-256-GCM) and scoped to your workspace. The metrics we read are stored per workspace so your week-over-week and year-over-year comparisons work. Disconnecting Google Analytics in the app deletes those tokens and asks Google to revoke our access.
- How we share it. We do not sell, rent, or trade your Google user data, and we do not share it with advertisers or pool it with any other customer’s data. We transfer it to no one except the infrastructure providers that run Loopberry for you (listed below), and only as needed to operate the service.
Loopberry’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Store attribution, lead tracking, and what we throw away
If you connect Shopify or Stripe, Loopberry can show you which ad clicks actually preceded orders. This is a deliberately narrow, deterministic join — not an identity graph, and not a cross-site tracking network. We do not build profiles of your shoppers, and we do not share or combine data between different Loopberry customers.
Our first-party pixel runs on your storefront and is gated on your store’s consent banner. If Shopify reports no analytics or marketing consent — or reports nothing at all — the pixel sends us nothing. It also stays quiet on ordinary visits: it only reports a visit that carries an ad click identifier or a UTM tag.
When it does report a visit, it sends:
- the ad click identifier in the URL (Meta’s
fbclidor TikTok’sttclid) and any UTM tags, - the landing page URL, the referring page, and a timestamp,
- a random identifier generated in that browser, so a later order can be matched to the click that preceded it.
It sends no name, no email, no phone number, no address, and no payment details. When an order comes in, we strip it down before it is stored anywhere: we keep the order id, subtotal, total, currency, and creation time, and we discard the customer record, email, name, phone, billing address, and shipping address. Any other note the merchant attached to the order is dropped too, because a merchant could have put personal information there.
If you connect Stripe, we record each payment the same way — the amount, currency, and timestamp, never the card number or other payment-method details, which stay with Stripe. We don’t yet run a click-collecting pixel on a Stripe-only storefront, so a payment we can’t tie to a stored click is recorded as an unattributed sale rather than credited to any ad — never guessed, never invented.
If you run a lead-generation business instead of a store — say, an agency whose only conversion is someone filling out a form — you can connect your own website instead of Shopify or Stripe. A small script you paste into your site records the same kind of ad-click information described above for every visit, and — once you tell it which page your form redirects to, or add one line of code to the form itself — that a visitor submitted it.
When it records an ordinary visit, it sends:
- the ad click identifier in the URL (
fbclidorttclid) and any UTM tags, - the landing page URL, the referring page, and a timestamp,
- a random identifier generated in that browser, so a later form submission can be matched to the click that preceded it.
When your form is submitted, it sends far less — just the path of the page it landed you on, never the full URL (so nothing your thank-you page carries in its query string, like a submitted name or email, ever reaches us), a timestamp, and that same opaque identifier so we can match the submission back to the visit that preceded it.
Either way, it sends no name, no email, no phone number, and nothing you or your visitor typed into the form — only what’s listed above. Like the storefront pixel above, it is gated on a consent banner and reports nothing at all until a visitor accepts. Most small sites don’t have a banner of their own, so we provide a minimal drop-in one that does exactly this and nothing else.
The 90-day automatic deletion described below applies only to the visit records above — the ones with no form submission attached. A form submission itself is kept for as long as your site stays connected, the same as a Shopify order, because it is what makes your numbers meaningful over time; it is not deleted on a timer. You can erase all of it — visits and submissions alike — at any time by disconnecting your site, which (unlike Stripe) erases everything immediately — see “How to delete your data” below.
The practical result: we hold no individual customer identity data — not in our database and not in our raw-event storage. We want to be straight with you about the flip side, though. The random browser identifier and the ad click identifiers are pseudonymous, and they still count as personal data under the GDPR. We treat them that way: click and visit records are deleted automatically after 90 days, and raw events are stored under a per-workspace prefix specifically so they can be erased wholesale on request.
Who else touches your data
We keep this list short on purpose. Each of these is a service we need to run Loopberry, not a data-sharing arrangement:
- Cloudflare — hosting, storage, queues, and outbound email.
- Neon — our Postgres database.
- Stripe — subscription billing and card processing.
- Sentry — error reports, so we find out when something breaks.
- Google Workspace — our own email.
- Google Analytics — measuring our own public marketing pages, and only for visitors who accept (see cookies, above). After the same Accept we also run our own first-party collector on those pages; that data stays in our database, not with Google.
Error reports pass through a filter before they leave our servers that removes tokens, sign-in links, database URLs, email addresses, and the attribution identifiers described above. That filter is covered by tests, because a scrubber nobody tests is a scrubber that quietly stops working.
If you use the asset-generation features, the prompts you approve — and any reference images you upload for a generation to work from — are sent to the generation vendor behind that feature. Your analytics, your orders, and your store visitors’ data are never part of that.
We do not sell your data, we do not rent it, and we do not share it with advertisers. We may disclose data if the law genuinely requires it.
We don't train AI on your data
Loopberry writes weekly narratives and suggested actions, but the running application makes no AI model calls at all. Every number you see is computed deterministically by our own code. Where wording is generated, it happens in a separate authoring step against figures our servers then re-derive and re-verify before storing.
Your data is not used to train any model, ours or anyone else’s, and it is never pooled with another customer’s to produce benchmarks or insights for someone else. That is what we mean when we say your data stays yours.
How long we keep things
- Store visit and click records: 90 days, deleted automatically.
- Brand-collab open records: 90 days, deleted automatically. A partner’s name and email persist with the share until the workspace deletes the link or asks us to erase it.
- Your analytics history, campaigns, and content: for as long as your workspace is open, so your year-over-year comparisons keep working.
- Connected-account tokens: until you disconnect that source, at which point they are deleted.
- Billing records: as long as tax and accounting rules require.
- In-app reports: up to 12 months after we close the report (or sooner if you ask us to erase them).
How to delete your data
You have a few routes, depending on what you want gone.
- Disconnect one source. In the app, disconnecting Google, Meta, or TikTok immediately deletes that connection’s stored tokens and configuration, and asks the provider to revoke our access on their side too.
- Disconnect Stripe. Removes the connection right away. Unlike the sources above, we keep the payment records we already collected — that history is what makes your numbers meaningful if you reconnect — so disconnecting alone doesn’t erase them. Use the email route below if you want those erased too.
- Uninstall the Shopify app. When you uninstall, Shopify notifies us and we erase that shop completely and automatically: every visit record, every order record, the store itself, the encrypted connection, and the shop’s raw events in our storage.
- Disconnect your website tracking. Unlike the Stripe route above, this one erases everything right away — every visit and form-submission record, the connection itself, and the site’s raw events in our storage. A website you paste our tracking script into has no other way for us to be told when to erase it, so disconnecting is what triggers the erasure.
- Ask us to delete everything. Email hello@loopberry.app from the address on your account and say you want your data deleted. We’ll confirm, then within 30 days erase your workspace and everything in it — including every visit and payment record, the connections themselves, brand-collab shares and their open records, and the raw events in our storage. Unlike a Shopify uninstall, this one is done by hand, so we’ll write back when it’s finished rather than leaving you to assume it.
- If you left your name and email on a brand-collab link. Email hello@loopberry.app from that address and say which workspace shared the link (or forward the link). We’ll erase the open record that carries your details. Open counts without a name or email are deleted automatically after 90 days.
If you shopped at a store that uses Loopberry: please contact that store directly. We hold no name, email, phone, or address for you — nothing that would let us find you in our systems even if we wanted to. When a store asks us to erase a customer, we honour it, and when a store leaves Loopberry we erase everything we hold for it.
Your rights
Depending on where you live, you have the right to see what we hold about you, correct it, take it elsewhere, or have it deleted, and to object to how we use it. Email hello@loopberry.app and we’ll take care of it — no forms, no fee. We don’t sell personal information, so there is nothing for you to opt out of on that front.
Security
Connected-account tokens are encrypted at rest with AES-256-GCM. Sign-in links are signed, single-use, and short-lived. Every page and endpoint that reads your data checks who you are first and refuses by default if it can’t tell. Every workspace’s data is scoped to that workspace at the query level. No system is perfect, and if something ever goes wrong that affects you, we’ll tell you promptly and plainly.
Getting in touch
Questions, requests, or something here that doesn’t match what you’re seeing in the app? Email hello@loopberry.app. Our terms of service cover the rest of the relationship.