Loopback 子处理者清单 / Subprocessor List
最近更新:2026-07-14 · 版本:v1.0
本清单披露 Loopback 为提供服务而委托的第三方子处理者,以及其处理的数据类别、用途与所在地。清单随服务变化更新;重大变更将按《数据处理协议(DPA)》约定通知企业客户。子处理者的选用取决于客户所选功能与部署形态。
一、基础设施与平台
| 子处理者 | 用途 | 处理的数据 | 所在地/区域 | 适用区域 |
|---|
| Google Cloud Platform(GCP) | 托管、存储、计算(项目 loopback-500616) | 账户数据、配置、反馈数据 | 美国 us-central1 | 全部 |
| Stripe | 订阅计费与支付 | 联系人、账单信息(不含完整卡号) | 美国 | 全部 |
| Resend | 事务性邮件、通知 | 联系人邮箱 | 美国 | 全部 |
二、AI 模型供应商
调用取决于客户会员等级;用于反馈分类、摘要、情感/主题分析与向量化。
| 子处理者 | 用途 | 处理的数据 | 所在地 |
|---|
| Anthropic(Claude) | 反馈分类、摘要、洞察生成 | 反馈内容文本 | 美国 |
| OpenAI(GPT / Embeddings) | 反馈分类、摘要、向量化(embedding) | 反馈内容文本 | 美国 |
| Google(Gemini) | 反馈分类、摘要 | 反馈内容文本 | 美国/全球 |
三、说明
- BYO_KEY / SELF_HOSTED 部署:客户自带模型/云密钥时,AI 调用发往客户指定的供应商,相应供应商由客户自行选择并承担披露义务;私有部署下 Loopback 通常不接触反馈数据。
- 不用于模型训练:我们优先选用不将客户数据用于其模型训练的商用 API 通道,并在合同中作此约束。
- 渠道平台:客户主动接入的第三方渠道(App Store、Google Play、Steam、Reddit、Discord、Slack、Telegram、飞书/企业微信、Zendesk、Intercom、Typeform、Trustpilot 等)是数据来源,其数据处理由客户与各渠道之间的关系及各渠道条款约束,不属于本清单意义上的 Loopback 子处理者。
四、变更通知
新增或更换子处理者前,我们将按 DPA 约定提前通知企业客户;客户如有合理异议,可依 DPA 约定的机制处理。
订阅变更通知:[email protected]
Loopback Subprocessor List
Last updated: 2026-07-14 · Version: v1.0
This list discloses the third-party subprocessors Loopback engages to provide the Service, together with the categories of data they process, the purposes and their locations. The list is updated as the Service changes; material changes are notified to business Customers as provided in the Data Processing Agreement (DPA). Which subprocessors are used depends on the features and deployment model selected.
1. Infrastructure and platform
| Subprocessor | Purpose | Data processed | Location/region | Applicable region |
|---|
| Google Cloud Platform (GCP) | Hosting, storage, compute (project loopback-500616) | Account data, configuration, feedback data | us-central1, United States | All |
| Stripe | Subscription billing and payments | Contact, billing info (no full card numbers) | United States | All |
| Resend | Transactional email, notifications | Contact email | United States | All |
2. AI model providers
Invocation depends on the Customer's membership tier; used for feedback classification, summarization, sentiment/topic analysis and vectorization.
| Subprocessor | Purpose | Data processed | Location |
|---|
| Anthropic (Claude) | Feedback classification, summarization, insight generation | Feedback content text | United States |
| OpenAI (GPT / Embeddings) | Feedback classification, summarization, vectorization (embeddings) | Feedback content text | United States |
| Google (Gemini) | Feedback classification, summarization | Feedback content text | United States/global |
4. Notes
- BYO_KEY / SELF_HOSTED deployments: where the Customer brings its own model/cloud keys, AI calls are sent to the provider designated by the Customer, who selects that provider and bears the disclosure obligation; in self-hosted deployments Loopback generally does not access feedback data.
- No training use: we prioritize commercial API channels that do not use Customer data to train their models, and impose this by contract.
- Channel platforms: the third-party channels a Customer connects (App Store, Google Play, Steam, Reddit, Discord, Slack, Telegram, Feishu/WeCom, Zendesk, Intercom, Typeform, Trustpilot, etc.) are data sources; their data processing is governed by the relationship between the Customer and each channel and by each channel's terms, and they are not Loopback subprocessors within the meaning of this list.
5. Change notifications
Before adding or replacing a subprocessor, we will give business Customers advance notice as provided in the DPA; Customers with a reasonable objection may proceed under the mechanism set out in the DPA.
Subscribe to change notifications: [email protected]