Legal
Privacy Policy
Last updated 3 September 2026
What we collect, why, who else sees it, and what you can ask us to do about it. Written to be understood rather than to cover us.
1.Two kinds of people, two different roles
This matters for what rights apply, so it comes first.
Hosts are our customers. For their data we are the controller — we decide what to collect and why.
Attendees register for a host’s webinar. For their data the host is the controller and we are the processor: we hold and process it on that host’s instructions. If you attended a webinar and want your data removed, the fastest route is the host who ran it, though you can also contact us.
2.What we collect
From hosts: name, email, password (hashed, never stored in readable form), and billing details. Card numbers go directly to Stripe and never touch our servers — we store only the last four digits and expiry that Stripe returns.
From attendees: name, email, phone number and country, plus what happened in the session — whether they joined, how much they watched, whether they clicked the offer, and their chat messages.
Automatically: device type, browser, operating system, and the country your IP address resolves to. We store the country, not the IP address itself. We also record which link brought someone to a registration page.
Errors: when something breaks we log the message, the page, and the browser, so we can fix it.
3.Why we use it
- To run the service — playing webinars, showing chat, tracking attendance.
- To send the reminders and follow-ups a host has configured.
- To give hosts analytics about their own webinars.
- To take payment and prevent fraud.
- To support you when you ask, and to fix faults.
4.AI-generated replies
Some chat replies are generated by AI. When that happens, the message being replied to and the webinar’s context are sent to Anthropic’s API to produce the reply.
We do not send attendee email addresses or phone numbers for this. Anthropic does not train its models on data submitted through its API.
6.How long we keep it
- Host accounts: while the account is open, then 30 days after closure.
- Attendee records: while the host’s account is open, or until the host deletes them.
- Message and delivery logs: 12 months.
- Error logs: 90 days.
- Invoices: 7 years, because tax law requires it.
7.Your rights
Under UK and EU data protection law you can ask to:
- See what we hold about you.
- Correct anything wrong.
- Have it deleted.
- Receive it in a portable format.
- Object to or restrict how it is used.
- Withdraw consent, including by unsubscribing from any message.
Email support@loopinglive.com and we will respond within 30 days. You can also complain to the ICO (ico.org.uk) or your local supervisory authority.
9.Security
Everything is served over HTTPS. Passwords are hashed. API keys are stored as hashes, so a leak of our database does not expose usable keys. Database access is restricted by row-level security so one account cannot read another’s data.
No system is perfectly secure. If a breach affects you we will tell you and the regulator within 72 hours of becoming aware.
10.Children
Loopinglive is not for under-18s and we do not knowingly collect their data. Tell us if you believe we have, and we will delete it.
11.Contact
Email support@loopinglive.com for anything in this policy, including data requests.
Questions about this document? Email support@loopinglive.com. See also our Terms and Privacy Policy.