Loopback Privacy Policy / Privacy Policy
Effective Date: 2026-07-14 · Last Updated: 2026-07-22 · Version: v1.2
Language and Authoritative Version: This policy is available in multiple languages for your convenience. The displayed language follows your interface language setting in Loopback; languages not yet available default to English.The English version is the authoritative version; other language translations are provided for reference only. In case of any discrepancy or conflict, the English version shall prevail.
0. Definitions
- "Loopback" / "we": refers to HAKKO AI PTE. LTD. (registered in Singapore, address: 120 Robinson Road #13-01 Singapore 068913), the provider of the Loopback feedback analytics service.
- "Service": refers to the multi-channel user feedback collection, aggregation, and AI analysis platform provided by Loopback (including the web application, API, and related features).
- "Customer" / "you": refers to the business or organization subscribing to or using the Service, and its authorized users.
- "End User": refers to third-party individuals who leave comments, ratings, or feedback on channels connected by the Customer (e.g., App Store reviewers, community members, etc.).
- "Personal Information / Personal Data": information that can directly or indirectly identify a specific natural person.
1. Our Two Roles in Data Processing
Loopback is a B2B software service that handles two distinct categories of data, and our role differs accordingly:
| Scenario | Data Type | Our Role |
|---|---|---|
| Customer registration, login, billing, and platform usage | Account and usage data | DataController(GDPR) / Personal Information Handler (PIPL) |
| After the Customer connects a channel, the platform collects and analyzes End User feedback on the Customer's behalf | Feedback data | DataProcessor(GDPR) / Entrusted Party (PIPL), processing on behalf of the Customer |
For feedback data, the purpose and method of processing are determined by theCustomer, and we process such data solely on the Customer's instructions. Related rights and obligations are set out in the Data Processing Agreement (DPA)(see Section 12).
2. Information We Collect
2.1 Account and Usage Data (Where We Act as Controller)
- Account Information: company name, contact name, work email, password (encrypted), role/permissions.
- Billing Information: subscription tier (Free / Pro / Max), billing address, transaction records. Actual card details are processed by Stripe; we do not store full card numbers.
- Configuration Information: connected channels, API keys, or authorization tokens (encrypted; see Section 5).
- Usage and Log Data: login records, operation logs, IP address, browser/device information, and feature usage statistics, used for security, troubleshooting, and product improvement.
- Product Usage Data: product behavior events such as page views and feature usage (e.g., opening a report, connecting a channel), tagged with a first-party anonymous identifier (Cookie
lb_aid) for anonymous attribution between our website and app. This data is used solely for product improvement, stored in our own database (no third-party analytics services involved), excludes any feedback content or your input, and is retained for no more than 180 days. - Cookies and Similar Technologies: see Section 9.
2.2 Feedback Data (Processed by Us as a Data Processor on Behalf of Customers)
Once a customer connects the following channels, the platform collects publicly available or authorized feedback content as instructed by the customer, which may include personal information:
- App Stores: Apple App Store (public RSS), Google Play (Play Developer API), and others;
- Communities and Tickets: Reddit, Discord, Slack, Telegram, Lark / WeCom, Zendesk, Intercom;
- Surveys and Reviews: Typeform, Lark Surveys, Trustpilot, and others.
This content may include: review/comment text, ratings, post timestamps, author nicknames or identifiers displayed on the platform, and other information voluntarily included by the author.We do not proactively request end users' identification documents, precise location, or other sensitive personal information; if such information incidentally appears in feedback content, it is processed only as instructed by the customer and not used for any other purpose.
3. How We Use Information
- Providing and Maintaining the Service: account management, channel integration, feedback collection and aggregation, AI classification and insight generation, and dashboard display.
- AI Analysis Processing: submitting feedback content to large language models for classification, summarization, sentiment, and topic analysis (see Section 6 for the model list).
- Billing and Customer Support。
- Security, Fraud Prevention, and Compliance: anomaly detection, access auditing, and fulfilling legal obligations.
- Product Improvement: enhancing features based on aggregated, de-identified usage statistics.We will not use customer feedback data to train our own general-purpose models without the customer's written consent (see Section 6 for third-party model training policies).
Legal Basis for Processing (GDPR / PIPL)
- Performance of Contract: necessary to provide you with the service you have subscribed to;
- Legitimate Interests: to ensure security, prevent fraud, and improve our products (balanced against your interests);
- Consent: where applicable (e.g., optional cookies, marketing emails);
- Legal Obligation: as required by applicable laws and regulations.
- For feedback data, the lawful basis is determined and disclosed byCustomeras the data controller.
4. Cross-Border Data Transfer and Residency
Data is stored and processed on Google Cloud (us-central1, United States). For users in the EU/UK, cross-border transfers rely onStandard Contractual Clauses (SCCs)and other lawful transfer mechanisms.
Data flows vary by deployment model:
- SHARED_SAAS (Shared Hosting): data is stored within Loopback's hosted environment;
- BYO_KEY (Bring Your Own Key): your own model/cloud keys are used, and AI requests are routed to the provider you designate;
- SELF_HOSTED (Self-Hosted): data resides inyour own environment, and Loopback typically does not access your feedback data.
5. Data Security
- TLS encryption in transit; sensitive fields (passwords, third-party API keys/OAuth tokens) are encrypted at rest.
- Four-tier role-based access control (RBAC) based on the principle of least privilege, with access auditing.
- Tiered protection based on data sensitivity (from L1 data obfuscation to L4 confidential computing, depending on deployment model and plan).
- We implement reasonable technical and organizational measures, but no system can guarantee absolute security. In the event of a personal data breach, affected parties will be notified within the timeframe required by applicable law and contractual obligations.
6. Third-Party Vendors (Subprocessors)
To deliver our services, we share necessary data with the following categories of subprocessors. The AI model used depends on yourregionandsubscription tier:
| Category | Vendor (Example) | Purpose |
|---|---|---|
| Cloud Infrastructure | Google Cloud, etc. | Hosting, storage, and compute |
| AI Models | Anthropic(Claude)、OpenAI(GPT / Embedding)、Google(Gemini) | Feedback classification, summarization, and vectorization |
| Payments | Stripe, etc. | Subscription billing |
| Email/notifications | Resend | Transactional email |
- We enter into data processing terms with subprocessors requiring protection levels no lower than this policy.
- Content sent to model providers is used forgenerating analysis results; we prioritize usingcommercial API channels that do not use customer data for model training, and enforce this contractually.
- For the complete, real-time list of subprocessors, see: https://loopbackagent.com/subprocessors.html. We will notify customers of list updates as agreed in the DPA.
7. Data Retention
- Account and billing data: retained during the service period and afterward as legally required (e.g., tax, audit purposes).
- Feedback data: retained per the customer's platform configuration or DPA terms; customers may request export or deletion.
- After service termination, we will delete or anonymize customer data within the agreed period (default 30 days), except where retention is legally required.
8. Your Rights (and End User Rights)
Under applicable law (GDPR / UK GDPR / California CCPA/CPRA / China PIPL, etc.), you have the right to: access, correct, delete, restrict processing, data portability, object to processing, and withdraw consent, and to not be discriminated against for exercising these rights.
- Customer account data: please contact us via Section 13 to exercise these rights.
- End users: since feedback data is controlled by the customer as data controller, end user rights requests should generally be directed tothe relevant customer, and we will provide technical assistance to customers in responding to such requests.
- We will respond within legally required timeframes; you also have the right to file a complaint with your local regulatory authority.
9. Cookies and Similar Technologies
We use essential cookies to maintain login and security, and, with consent, analytics cookies to understand product usage. Our product usage analytics is built in-house as first-party (no third-party analytics scripts load on the page); the first-party anonymous identifier lb_aid is used only for anonymous attribution (see Section 2.1, "Product Usage Data"), and you may clear or block it via your browser settings. You can manage non-essential cookies through your browser settings. For visitors in Europe, the website's anonymous statistics cookie (lb_aid) will not be set until you select "Accept" in the cookie banner, and no statistical events are collected during that time; selecting "Reject" disables tracking, and any existing identifier will be deleted. You may change your choice at any time via "Cookie Settings" in the footer, regardless of region.
10. Children's Privacy
This service is intended for businesses and not for individuals under 16 (or the age specified by applicable law). We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via in-service notice or email, and the "Last Updated" date at the top will be revised. Continued use after changes take effect constitutes acceptance.
12. Data Processing Agreement (DPA)
For our role as processor handling feedback data, we execute a separate Data Processing Agreement (DPA) with enterprise customers, covering the scope of processing, subprocessors, security measures, assistance obligations, breach notification, audit rights, and cross-border transfer mechanisms (including SCCs). Enterprise customers may request this via Section 13.
13. Contact Us
- Data protection/privacy inquiries: [email protected]
- General inquiries: [email protected]
- Mailing Address: 120 Robinson Road #13-01 Singapore 068913
- EU/UK Representative (if applicable): To be designated and published separately
- Data Protection Inquiries: [email protected]