Privacy Policy
Last updated: August 2026
Who we are
Looplift is an AI conversion-rate-optimization and experimentation platform. This policy explains what we collect, why, and who we share it with. Questions? Email support@looplift.io.
What we collect
- Account data — your email and optional name, held in our authentication provider (Supabase).
- Workspace data — the properties, audits, experiments, and results you create, stored in our Postgres database (Supabase).
- Audit artifacts — pages and screenshots we capture while auditing a site you own or are authorized to audit, stored in object storage (Supabase Storage).
- Billing identifiers — a customer and subscription id from our payments provider (Polar). We do not store card numbers.
- Product analytics — how you use the app, via Microsoft Clarity, to improve the product.
How the experiment snippet works
When you install the Looplift snippet (looplift.js) on your own site, it sets a first-party lpl_vid cookie to bucket a visitor into an A/B group and records experiment exposures and conversions. It does not collect personal information, read form contents, or track visitors across other sites.
Store & order data
If you connect a commerce platform such as Shopify, we read your orders for one purpose: to attribute a completed purchase to the experiment arm the visitor was in, so you see revenue per arm instead of a click-rate proxy.
We do not process customer identity. We read the order id, the total in minor units, the currency, the refund status, the timestamp, and the experiment assignment we ourselves recorded at exposure. Name, address, email, phone and the customer object as a whole are discarded when the order is read and never reach storage — our order records have no column that can hold one. We do not request the protected customer fields from Shopify at all.
We build no customer profiles, run no personalization, and make no automated decisions about individuals. The system chooses which version of a page to show; it never decides anything about a person.
Consent
On your own site, your consent banner governs. Where a visitor has not consented to the category our cookie falls under, the snippet does not write one, and that visitor is simply not measured. We treat that loss as normal and design around it: our claim is that measurement loss is symmetric across the arms of an experiment, not that measurement is complete. We never present a number as more accurate than it is.
Third parties & subprocessors
We rely on: Supabase (authentication, database, storage — primary database in the EU), Vercel (application hosting), DigitalOcean (the audit worker), Anthropic (the model that analyses audited pages and drafts variants; your content is not used to train models), Firecrawl (fetching the pages you ask us to audit), Polar (payments), Resend (transactional email), Microsoft Clarity (product analytics for the Looplift app itself, not your site), and — only if you connect it — Google Analytics (GA4). The full list, with the obligations we place on them, is in our Data Processing Agreement.
Google Analytics (GA4) connection
Connecting GA4 is optional. If you do, you grant read-only access to the GA4 property you choose, and we store an encrypted refresh token to ground audits in your real analytics. You can disconnect at any time, which revokes our access.
Cookies
We use a session cookie for authentication, a looplift_site_id cookie to remember your active workspace, and — on your own site — the first-party lpl_vid experiment cookie described above.
Retention & deletion
Order records are deleted 180 days after the order occurred. That is a scheduled job rather than a promise: past six months an order answers no question the product asks, and the per-arm figures that outlive it are aggregates computed before deletion.
Everything else is deleted by action, and we would rather say that than invent a period nothing enforces. You can delete sites, audits and experiments in the app, and you can export your data or permanently delete your account yourself from Settings → Danger zone (deletion removes any workspace where you are the only member, along with its sites, audits, experiments, and learnings). If something blocks the self-serve path, email support@looplift.io and we will process the request.
An erasure instruction sent by your commerce platform on a customer’s behalf is honoured on receipt — it does not wait out the retention period.
Security & incidents
Traffic is encrypted in transit and the database encrypts data at rest. Workspace isolation is enforced by row-level security in the database, not by application code alone. Access tokens you grant us are stored encrypted.
We maintain a written incident response procedure covering detection, containment, assessment, notification and a follow-up note. If a breach affects your data we will tell you without undue delay, and within 72 hours where the law requires it, with what we know at the time rather than after it is tidy. Report a suspected security issue to support@looplift.io.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. Export and deletion are self-serve in the app (Settings → Danger zone); for anything else, contact support@looplift.io to exercise them.
Contact
Questions about this policy: support@looplift.io.