Loopback Subprocessor List
Last updated: 2026-07-14 · Version: v1.0
This list discloses the third-party subprocessors engaged by Loopback to provide the Service, along with the categories of data processed, purposes, and locations. The list is updated as the Service evolves; material changes will be communicated to enterprise customers as provided in the Data Processing Agreement (DPA).Sub-processor selection depends on the features and deployment model chosen by the customer.
1. Infrastructure & Platform
| Sub-processor | Purpose | Data Processed | Location/Region | Applicable Region |
|---|---|---|---|---|
| Google Cloud Platform(GCP) | Hosting, storage, compute (project loopback-500616) | Account data, configuration, Review data | US (us-central1) | All |
| Stripe | Subscription billing & payments | Contact and billing information (excluding full card numbers) | US | All |
| Resend | Transactional emails, notifications | Contact email address | US | All |
2. AI Model Providers
Usage depends on the customer's plan tier; used for Review classification, summarization, sentiment/topic analysis, and embedding generation.
| Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Anthropic(Claude) | Review classification, summarization, insight generation | Review content text | US |
| OpenAI(GPT / Embeddings) | Review classification, summarization, embedding generation | Review content text | US |
| Google(Gemini) | Review classification, summarization | Review content text | US/Global |
3. Notes
- BYO_KEY / SELF_HOSTED deployments: When customers bring their own model or cloud keys, AI calls are routed to the provider the customer specifies; the customer selects that provider and bears the corresponding disclosure obligations. Under self-hosted deployments, Loopback typically does not have access to Review data.
- Not used for model training: We prioritize commercial API channels that do not use customer data for model training, and contractually enforce this commitment.
- Channel platforms: Third-party channels that customers actively connect (App Store, Google Play, Steam, Reddit, Discord, Slack, Telegram, Lark/WeCom, Zendesk, Intercom, Typeform, Trustpilot, etc.) aredata sources, and data processing for these is governed by the relationship and terms between the customer and each channel. These are not Loopback sub-processors within the meaning of this list.
4. Change Notifications
Before adding or replacing a sub-processor, we will notify enterprise customers in advance as specified in the DPA. Customers with reasonable objections may proceed via the mechanism defined in the DPA.
Subscribe to change notifications: [email protected]