Privacy Policy
Last updated: Loading...
This Privacy Policy explains how Loople ("we", "us", "our") collects, uses and protects your personal data when you use our services — including the Loople mobile app for daters and the Loople Venue Portal at venues.theloople.com.
We are committed to complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR).
1. Who we are (the data controller)
The data controller responsible for your personal data is:
- Trading name: Loople
- Company registration: 17332337
- Registered address: 66 Paul Street, London, EC2A 4NA, England
- Contact email: privacy@theloople.com
- ICO registration number: ZC208527 (verify on ICO register)
2. What personal data we collect
We only collect data that we need to run the service. Specifically:
2.1 If you are a Loople dater
- Account: your name, email address, date of birth (to verify you are 18+), password (hashed).
- Profile: photos, your 60-second video introduction, city, bio, interests you've selected, and your matching preferences (your gender, who you'd like to see, and the age range you're interested in). Who you'd like to see can reveal your sexual orientation, which UK GDPR treats as special-category data — we process it only because you explicitly choose it so we can show you suitable people (Article 9(2)(a), explicit consent); we never infer it, and you can change it at any time in Profile → Dating preferences. Your video is always recorded live inside the app (gallery uploads aren't allowed) so other members know you're real. Only signed-in Loople members can view it; it is stored securely by Cloudinary and permanently deleted when you delete your account.
- Activity: likes, matches, chat messages, video-call metadata (e.g. call start/end time — we do not record video or audio calls), venue bookings and cancellations.
- Safety: if you block or report someone, or someone reports you, we keep the report, the reason, and any chat context you attach so our safety team can review it. Blocked users are never told who blocked them.
- Product analytics: anonymous-style usage events tied to your account ID (for example "finished profile", "sent first message", "booked a date") so we can see where people get stuck and improve Loople. We never include the content of your messages, photos or video. You can switch this off at any time in Settings → Notifications → Share anonymous usage data. If we connect a third-party analytics provider (PostHog, hosted in the EU), the same events are sent there under the same switch.
- Notifications: your notification preferences and, if you turn on email alerts, a log of the alert emails we've sent you (so we never send more than one email per conversation per hour).
- Payments: booking deposits are handled by Stripe. We never see or store your card details. Stripe returns us a transaction reference. If you subscribe to Loople Duo or Loople Premium (£5.99/month each, separate products), that's billed via the Apple App Store or Google Play on mobile (through our billing partner RevenueCat) or via Stripe on the web. If you buy a video-call top-up (£5 one-off), that's also billed via Stripe.
- AI features: to generate your profile "vibe tags" (from your bio + interests), we send that text to our AI provider (Anthropic's Claude, via Emergent's AI infrastructure). Our seeded demo profiles (used to showcase the app) also use AI to auto-reply for demo purposes only — real matches between real daters never trigger this. This text is used only to generate that one response and is not used to train any AI model.
- Device: device type, IP address, session tokens.
2.2 If you are a Loople venue owner
- Account: name, email, password (hashed).
- Business details: venue name, address, contact info, photos, menus and packages you upload.
- Payment records: the £30/year listing fee (auto-renewing annually) and any deposits collected via Stripe.
- Integration credentials: if you connect your Epos Now account, we store your API token encrypted at rest (Fernet symmetric encryption).
3. Why we collect it (lawful bases)
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Providing the core service (accounts, matches, bookings) | Performance of a contract |
| Processing your payments | Performance of a contract |
| Preventing fraud, spam, and abusive behaviour | Legitimate interests |
| Sending you service notifications (booking receipts, refunds, safety notices) | Performance of a contract |
| Activity alerts (new match, new message, Loople Duo updates) in-app and by email | Legitimate interests — every alert type can be switched off in Settings, and every alert email has a one-tap unsubscribe link |
| Product analytics to improve Loople | Legitimate interests — you can opt out in Settings at any time |
| Keeping the community safe (blocking, reporting, bans) | Legitimate interests and legal obligation (Online Safety Act 2023) |
| Marketing emails / newsletters | Consent (you can opt out any time) |
| Compliance with legal, tax, or regulatory obligations | Legal obligation |
4. Who we share your data with
We only share your data with trusted service providers who help us run Loople:
- Stripe — for card payments (stripe.com/privacy)
- RevenueCat — manages Loople Duo subscription billing on iOS/Android (revenuecat.com/privacy)
- Apple App Store / Google Play — process subscription payments if you subscribe to Loople Duo on a mobile device
- Cloudinary — for storing your video and photo uploads (cloudinary.com/privacy)
- Anthropic (Claude) — processes profile bio/interests text to generate vibe tags, and (demo profiles only) auto-reply text for our sample accounts (anthropic.com/legal/privacy)
- MongoDB Atlas — database hosting
- Netlify — hosting for our Venue Portal and marketing website
- Emergent — cloud infrastructure and Google sign-in
- Google — if you sign in with Google we receive your name, email address and profile picture from your Google account (policies.google.com/privacy)
- Resend — delivers our emails (receipts, alerts) (resend.com/legal/privacy-policy)
- PostHog (EU) — product analytics, only if you haven't opted out (posthog.com/privacy)
- Jitsi Meet — for live video calls (calls are peer-to-peer where possible; jitsi.org/security)
- Epos Now — only if a venue chooses to connect their Epos Now account, we push booking-related customer contact data on their instruction
We never sell your personal data to advertisers or data brokers.
5. How long we keep it
- Active accounts: for as long as you use Loople.
- Deleted accounts: we delete personal data within 30 days of your deletion request, except where we must legally retain it (e.g. financial records for 6 years under HMRC rules).
- Chat messages: visible while both parties are matched. When either party unmatches (or blocks) the conversation is hidden from both immediately and permanently deleted 90 days later — we keep it that long only so our safety team can review it if someone reports the conversation.
- Payment records: retained 6 years for tax compliance (this covers booking deposits, the annual venue listing fee, Loople Duo subscription payments, and video-call top-ups).
- Safety logs: reports, blocks and moderation decisions are retained for up to 7 years for legal-hold purposes.
- Video introductions: deleted from our systems and from Cloudinary when you re-record (the old one is replaced) or delete your account.
- Product analytics events: kept in pseudonymised form (account ID only); once your account is deleted they can no longer be linked to you.
6. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Correct anything that's inaccurate
- Delete your data (the "right to be forgotten")
- Restrict how we process it
- Data portability — get a copy in a machine-readable format
- Object to processing (especially for marketing)
- Withdraw consent at any time
Download your data yourself: in the app go to Profile → Privacy & Data → Download a copy of my data — you get a machine-readable file instantly. Delete your account yourself: Profile → Delete my account. For anything else, email privacy@theloople.com and we will respond within one month.
7. Complaints
If you are unhappy with how we handle your data, you have the right to complain to the UK Information Commissioner's Office (ICO):
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
8. Security
We use industry-standard security measures including:
- HTTPS/TLS encryption for all data in transit
- bcrypt password hashing (we never store your password in plain text)
- Fernet encryption at rest for sensitive third-party API credentials (e.g. Epos Now)
- JWT session tokens with expiry
- Automated safety filters that block phone numbers, emails and social handles in chat to protect you from scams
No system is 100% secure. If we ever become aware of a data breach affecting you, we will notify you and the ICO within 72 hours as required by UK GDPR.
9. Age restriction
Loople is strictly for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If we discover an account belongs to a minor, we will delete it immediately.
10. International transfers
Your data is primarily stored in the UK / EU. Some of our service providers may transfer data outside the UK (e.g. to the US). Where this happens, we rely on UK-adequacy decisions or the UK International Data Transfer Agreement to ensure your data is protected to UK GDPR standards.
11. Cookies
We use only strictly necessary cookies (like a sign-in token). For details see our Cookie Policy.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. Material changes will be notified by email.
13. Contact us
Any questions? Please email privacy@theloople.com. For general Loople support, email support@theloople.com.
We collect only what we need to run the app. We never sell your data. We keep it secure. You can delete your account any time and we'll wipe your data within 30 days.