&loop
How it works See it live Talk to us
Sign in
How it works See it live Talk to us Sign in Terms Privacy

Privacy Policy

Last updated: February 25, 2026

&loop LLC ("Company", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the &loop platform ("Service"). Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information as described in this policy.

1. Information We Collect

1.1 Information You Provide

We collect information that you voluntarily provide when you register for the Service, use its features, or contact us:

  • Account Information: Name, email address, and authentication credentials (managed via OAuth, SAML, LDAP, passkeys, or magic link). We do not store passwords directly when using OAuth or SAML providers.
  • Organization Information: Organization name, team names, workspace configurations, and member roles when you create or join an organization.
  • Billing Information: Payment details (processed and stored by Stripe, our payment processor; we do not store full credit card numbers), billing address, and subscription plan selections.
  • Your Data: Any data, files, queries, pipelines, notebooks, dashboards, configurations, connectors, API templates, and other content you upload, create, or process through the Service.
  • Communications: Information you provide when contacting our support team, submitting feedback, or participating in surveys.

1.2 Information Collected Automatically

When you access the Service, we may automatically collect certain information:

  • Log Data: IP address, browser type and version, operating system, referring URLs, pages visited, time and date of access, and other diagnostic data.
  • Usage Data: Features used, actions performed (e.g., pipelines run, queries executed, dashboards created), session duration, and interaction patterns.
  • Device Information: Device type, screen resolution, unique device identifiers, and general geolocation based on IP address.

1.3 Cookies and Similar Technologies

We use cookies and similar tracking technologies to operate and improve the Service. For detailed information about our cookie practices, see Section 6 (Cookies) below and our cookie consent controls.

2. How We Use Your Information

We use the information we collect for the following purposes:

Purpose Legal Basis (GDPR)
Provide, operate, and maintain the Service Contract performance
Authenticate users and manage sessions Contract performance
Process payments and manage subscriptions Contract performance
Send transactional communications (account alerts, security notices, service updates) Contract performance / Legitimate interest
Improve and develop new features Legitimate interest
Monitor usage, detect abuse, and enforce our Terms of Service Legitimate interest
Provide customer support Contract performance / Legitimate interest
Comply with legal obligations Legal obligation
Send marketing communications (only with your consent) Consent
Analytics and performance monitoring Consent / Legitimate interest

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

3.1 Service Providers

We engage trusted third-party service providers to perform functions on our behalf, including:

  • Payment Processing: Stripe processes payment information on our behalf. Their use of your information is governed by their privacy policy.
  • Cloud Infrastructure: We use cloud providers (such as AWS, Google Cloud, or Azure) to host the Service. Your Data is processed and stored on their infrastructure.
  • Authentication Providers: When you use OAuth, SAML, or LDAP authentication, your identity information is exchanged with those providers.
  • Email Delivery: Transactional emails (magic links, alerts, notifications) are sent through third-party email services.

All service providers are contractually obligated to protect your information and may only use it to provide services to us.

3.2 Within Your Organization

If you belong to an organization on the Service, your organization administrators may have access to your account information, usage data, and content within shared workspaces, consistent with the organization's access policies.

3.3 Legal Requirements

We may disclose your information if required to do so by law, or in the good faith belief that such action is necessary to:

  • Comply with a legal obligation, subpoena, or court order
  • Protect and defend the rights or property of &loop LLC
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users or the public

3.4 Business Transfers

If &loop LLC is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your information.

4. Data Retention

We retain your information for as long as your account is active or as needed to provide you with the Service. Specifically:

  • Account Data: Retained for the duration of your account and for thirty (30) days after termination to allow for data export.
  • Your Data: Retained until you delete it or your account is terminated, plus a thirty (30) day grace period.
  • Usage and Log Data: Retained for up to twenty-four (24) months for analytics and security purposes, then anonymized or deleted.
  • Billing Records: Retained for seven (7) years as required for tax and accounting compliance.
  • Session Data: Automatically purged twenty-four (24) hours after creation or upon logout.

We may retain anonymized and aggregated data indefinitely for analytics and product improvement purposes.

5. Data Security

We implement industry-standard technical and organizational security measures to protect your information, including:

  • Encryption: Data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption.
  • Access Controls: Role-based access controls (RBAC), multi-tenancy isolation, and the principle of least privilege are enforced throughout the Service.
  • Authentication Security: Session tokens are cryptographically generated, HTTP-only, and SameSite protected. Personal access tokens are hashed before storage.
  • Infrastructure Security: Regular security assessments, automated vulnerability scanning, and infrastructure monitoring.
  • Data Isolation: Organization and workspace data is logically isolated within our multi-tenant architecture.

Despite our efforts, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security of your information.

6. Cookies

We use cookies and similar technologies to provide, protect, and improve the Service. You can manage your cookie preferences at any time using our cookie consent controls.

Category Purpose Examples Opt-Out
Essential Required for the Service to function. Authentication, security, and consent preferences. Session cookie, cookie consent preference Cannot be disabled
Functional Remember your preferences and settings for an enhanced experience. Sidebar state, workspace selection, theme preferences Can be disabled
Analytics Help us understand how users interact with the Service to improve it. Page views, feature usage, performance metrics Can be disabled
Marketing Used to deliver relevant content and measure campaign effectiveness. Campaign attribution, referral tracking Can be disabled

You can change your cookie preferences at any time by clicking "Cookie Preferences" in the footer of any page. You can also configure your browser to refuse cookies, but this may affect the functionality of the Service.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

7.1 Rights Under GDPR (European Economic Area)

If you are located in the EEA, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete personal data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Restriction: Request restriction of processing of your personal data.
  • Portability: Receive your personal data in a structured, commonly used, machine-readable format.
  • Objection: Object to processing of your personal data based on legitimate interests.
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent.
  • Lodge a Complaint: File a complaint with your local data protection authority.

7.2 Rights Under CCPA (California)

If you are a California resident, you have the right to:

  • Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Delete: Request deletion of personal information we have collected from you, subject to certain exceptions.
  • Opt-Out of Sale: We do not sell personal information. If this changes, you will have the right to opt out.
  • Non-Discrimination: You will not receive discriminatory treatment for exercising your CCPA rights.

7.3 Rights Under Other Jurisdictions

Users in other jurisdictions (including Brazil under LGPD, Canada under PIPEDA, and others) may have similar rights under applicable local data protection laws. We will honor these rights in accordance with applicable law.

7.4 Exercising Your Rights

To exercise any of these rights, please contact us at privacy@andloop.io. We will respond to your request within thirty (30) days (or as required by applicable law). We may need to verify your identity before processing your request.

8. International Data Transfers

Your information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from the laws of your country. When we transfer data internationally, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission
  • Your explicit consent where appropriate

We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

9. Children's Privacy

The Service is not intended for use by children under the age of 16 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@andloop.io.

10. Third-Party Links and Integrations

The Service may contain links to third-party websites and integrations with third-party services. This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of any third-party services you access through the Service. We are not responsible for the privacy practices of third parties.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a prominent notice on the Service at least thirty (30) days before the changes take effect. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of the updated Privacy Policy constitutes acceptance of the changes.

12. Data Protection Officer

If you have questions or concerns about our data practices, or wish to exercise your privacy rights, you may contact our Data Protection Officer:

&loop LLC
Data Protection Officer
Email: privacy@andloop.io

13. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

&loop LLC
Email: privacy@andloop.io

&loop
Talk to us Terms Privacy Sign in

We use cookies

We use cookies and similar technologies to provide, protect, and improve our platform. Essential cookies are required for the service to function. You can choose to accept all cookies or manage your preferences. Learn more

Cookie Preferences

Choose which cookies you want to allow. Essential cookies cannot be disabled as they are required for the platform to function. Your preferences are saved and can be changed at any time.

Essential Cookies

Always Active

Required for authentication, security, and basic platform functionality. These cookies enable core features like signing in, maintaining your session, and remembering your cookie preferences.

Functional Cookies

Remember your preferences and settings such as sidebar layout, workspace selection, and UI customizations for an enhanced experience.

Analytics Cookies

Help us understand how you use the platform so we can improve features, fix issues, and optimize performance. Data is aggregated and anonymized.

Marketing Cookies

Used to deliver relevant content and measure the effectiveness of campaigns. These cookies may track your activity across websites.