LoopAware

Privacy Policy — LoopAware

Effective Date: April 1, 2026

This Privacy Policy describes how Marco Polo Research Lab ("we", "us", "MPRLAB") collects, uses, stores, and protects information when you use LoopAware.

1. Information We Collect via Shared Sign-In

LoopAware uses the shared MPR sign-in surface to authenticate users. When you sign in, LoopAware receives your name, email address, and profile image from the shared authentication service. We use this information solely to identify you within the application and to manage your session. LoopAware does not request access to provider-specific files, mail, contacts, or other services.

2. Information You Provide

When you use LoopAware, you may create site configurations, receive feedback submissions from your website visitors, collect email subscriber lists, and view traffic analytics. This data is created by you or by visitors to your websites through the LoopAware widget, subscribe form, or traffic pixel.

3. How We Store Your Data

Your data is stored in a SQLite database on servers operated by MPRLAB. Session credentials are stored in encrypted, HTTP-only cookies. We do not store Google access tokens or passwords. Account and feedback data are retained while your account is active. Daily aggregate counts have the shorter retention period below. We use TLS encryption for all data in transit between your browser and our servers.

4. How We Use Your Data

We use your data exclusively to operate the LoopAware service: authenticating your sessions, displaying your dashboard, delivering feedback and analytics, and sending email subscription confirmations on your behalf. We do not use your data for advertising, profiling, or any purpose unrelated to the service.

5. Data Sharing

We do not sell, rent, or share your personal information or your users' data with any third party. We may disclose data only if required by law or to protect the rights and safety of MPRLAB or its users.

6. Cookies

LoopAware uses a session cookie (app_session) to maintain your authenticated session. This cookie is HTTP-only and is not accessible to client-side JavaScript. We do not use third-party tracking cookies or advertising cookies.

7. End-User Data

If you embed the LoopAware widget, subscribe form, or traffic pixel on your website, data from your visitors (feedback messages, email addresses, page visits) is collected and stored by LoopAware on your behalf. You are the data controller for this information. We act as a data processor and do not use end-user data for any purpose other than providing the service to you.

Aggregate Analytics

A site can use daily aggregate counts. This collector stores only the site identifier, UTC date, and accepted request count. It does not store individual visits, visitor identifiers, device records, page addresses, or IP addresses. Network transport processes an IP address to deliver the request. The count client sends no cookies or referrer.

Daily counts do not identify unique people or installations. The collection profile is fixed when the site is created. Feedback and operator accounts have separate data records.

8. Data Retention and Deletion

Daily aggregate counts use a retention window of up to 90 UTC calendar days in the active database. Cleanup runs at service startup and each day. Site deletion removes its daily counts. Account and feedback data are retained while your account is active. You may request deletion of your account and all associated data at any time by contacting us. Upon receiving a deletion request, we will remove your data within 30 days.

9. Your Rights

You have the right to access, correct, export, or delete your personal data. If you are located in the European Economic Area, you have additional rights under the GDPR, including the right to object to processing and the right to data portability. If you are a California resident, you have rights under the CCPA, including the right to know what data we collect and the right to request deletion.

10. Children's Privacy

The LoopAware operator dashboard is intended for adults. An application can use aggregate counts without persistent visitor records. Its owner must separately address its audience, consent requirements, feedback, and other services. We do not knowingly collect personal information from children through operator accounts or feedback. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date. Continued use of LoopAware after changes constitutes acceptance.

12. Contact

For questions about this Privacy Policy or to request data deletion:

Marco Polo Research Lab
Email: support@mprlab.com
Phone: (650) 265-1193

See also: Terms of Service

Logging out...

Logging out...