Skip to main content

Legal

Privacy Policy

Last updated 3 September 2026

What we collect, why, who else sees it, and what you can ask us to do about it. Written to be understood rather than to cover us.

1.Two kinds of people, two different roles

This matters for what rights apply, so it comes first.

Hosts are our customers. For their data we are the controller — we decide what to collect and why.

Attendees register for a host’s webinar. For their data the host is the controller and we are the processor: we hold and process it on that host’s instructions. If you attended a webinar and want your data removed, the fastest route is the host who ran it, though you can also contact us.

2.What we collect

From hosts: name, email, password (hashed, never stored in readable form), and billing details. Card numbers go directly to Stripe and never touch our servers — we store only the last four digits and expiry that Stripe returns.

From attendees: name, email, phone number and country, plus what happened in the session — whether they joined, how much they watched, whether they clicked the offer, and their chat messages.

Automatically: device type, browser, operating system, and the country your IP address resolves to. We store the country, not the IP address itself. We also record which link brought someone to a registration page.

Errors: when something breaks we log the message, the page, and the browser, so we can fix it.

3.Why we use it

  • To run the service — playing webinars, showing chat, tracking attendance.
  • To send the reminders and follow-ups a host has configured.
  • To give hosts analytics about their own webinars.
  • To take payment and prevent fraud.
  • To support you when you ask, and to fix faults.

4.AI-generated replies

Some chat replies are generated by AI. When that happens, the message being replied to and the webinar’s context are sent to Anthropic’s API to produce the reply.

We do not send attendee email addresses or phone numbers for this. Anthropic does not train its models on data submitted through its API.

5.Who else sees it

We use these providers, each for one job:

  • Supabase — database and authentication.
  • Vercel — hosting.
  • Cloudinary — video storage and delivery.
  • Stripe — payments. They receive billing data directly.
  • Resend — email delivery.
  • Twilio — SMS and WhatsApp, where a host enables them.
  • Anthropic — AI chat replies, as described above.

If a host connects their own tools, their attendee data is also sent there at that host’s instruction.

We do not sell personal data. Some of these providers are outside the UK and EEA; transfers rely on standard contractual clauses or an adequacy decision.

6.How long we keep it

  • Host accounts: while the account is open, then 30 days after closure.
  • Attendee records: while the host’s account is open, or until the host deletes them.
  • Message and delivery logs: 12 months.
  • Error logs: 90 days.
  • Invoices: 7 years, because tax law requires it.

7.Your rights

Under UK and EU data protection law you can ask to:

  • See what we hold about you.
  • Correct anything wrong.
  • Have it deleted.
  • Receive it in a portable format.
  • Object to or restrict how it is used.
  • Withdraw consent, including by unsubscribing from any message.

Email support@loopinglive.com and we will respond within 30 days. You can also complain to the ICO (ico.org.uk) or your local supervisory authority.

8.Cookies

We use as few as we can get away with:

  • Essential: your login session, and the impersonation flag used by our support staff. The site does not work without these.
  • Referral: if you arrive through an affiliate link we store that code for 30 days so the referrer is credited.

We set no advertising or cross-site tracking cookies. A host may add their own analytics or pixel to their registration page — that is their choice and their disclosure to make.

9.Security

Everything is served over HTTPS. Passwords are hashed. API keys are stored as hashes, so a leak of our database does not expose usable keys. Database access is restricted by row-level security so one account cannot read another’s data.

No system is perfectly secure. If a breach affects you we will tell you and the regulator within 72 hours of becoming aware.

10.Children

Loopinglive is not for under-18s and we do not knowingly collect their data. Tell us if you believe we have, and we will delete it.

11.Contact

Email support@loopinglive.com for anything in this policy, including data requests.

Questions about this document? Email support@loopinglive.com. See also our Terms and Privacy Policy.