Legal
Privacy Policy
Last updated: August 2, 2026
This policy explains what personal data ProfitLoopHQ collects, why we collect it, who we share it with, and the choices and rights you have. It applies to profitloophq.com and the ProfitLoopHQ application.
1. Who we are
ProfitLoopHQ ("ProfitLoopHQ", "we", "us") operates profitloophq.com and the ProfitLoopHQ outbound automation platform. For privacy questions, contact cyberprosoftware@gmail.com. Where GDPR applies, ProfitLoopHQ is the controller of account data and a processor of the prospect data you upload or generate through the service.
2. Data we collect
- Account data — email address, password hash (or Google sign-in identifier), and profile details you provide.
- Billing data — subscription tier, status, and billing period. Card details are collected and stored by Stripe, our payment processor; we never see or store full card numbers.
- Product data — loops, campaigns, signals, messages, and any prospect records you create, import, or generate.
- Scan data — when you run a GEO/AI-visibility scan, we process the URL you submit and the publicly available page content at that URL.
- Technical data — IP address, browser and device type, timestamps, and error logs, used for security, rate limiting, and abuse prevention.
- Communications — emails you send us and support requests.
3. Why we use it (legal bases)
- To provide the service — performance of our contract with you.
- To bill and prevent fraud — contract and legitimate interests.
- To secure the platform (rate limiting, abuse detection) — legitimate interests.
- To send service emails (confirmations, receipts, security notices) — contract. These are transactional and are not marketing.
- To send marketing emails — your consent, which you may withdraw at any time via the unsubscribe link in every marketing message.
- Analytics and marketing cookies — your consent, managed through our cookie banner.
4. Automated processing and AI
Some features use third-party AI models to summarize pages, score signals, and draft outreach copy. Content you submit for those features is transmitted to the relevant model provider to generate a response. We do not use your content to train our own models. AI output can be inaccurate — see our AI Disclaimer. We do not make decisions producing legal or similarly significant effects about you solely by automated means.
5. Who we share data with
We share personal data only with service providers acting on our instructions:
- Supabase — database, authentication, and storage.
- Stripe — payments, subscriptions, invoicing, and tax handling.
- Email delivery providers — sending transactional and, where consented, marketing email from our sender domain.
- AI and web-data providers — processing page content and generating analysis for scan and drafting features.
- Hosting and CDN providers — serving the site and application.
We do not sell personal information, and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
6. International transfers
Our providers may process data in the United States and other countries. Where data leaves the EEA or UK, transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) together with the safeguards our providers maintain.
7. Retention
We keep account and product data for as long as your account is active. After you delete your account we remove or anonymize personal data within 30 days, except records we must retain for tax, accounting, fraud-prevention, or legal-defense purposes (typically up to seven years for billing records). Security and rate-limiting logs are kept for a short rolling window.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. California residents may additionally request disclosure of categories of information collected and may opt out of any sale or sharing (we do neither). We will not discriminate against you for exercising these rights.
To exercise a right, email cyberprosoftware@gmail.com from your account address. We respond within 30 days (45 days for CCPA requests, extendable as permitted). You may also authorize an agent to submit a request on your behalf. If you are in the EEA or UK, you may lodge a complaint with your local supervisory authority.
9. Prospect data you upload
When you use ProfitLoopHQ to contact prospects, you are the controller of that data and you are responsible for having a lawful basis to process and contact those individuals, for honoring opt-outs, and for complying with GDPR, CAN-SPAM, CASL, TCPA, and any other law that applies to your outreach. We process that data only to provide the service to you.
10. Security
The service is served exclusively over HTTPS. Data is encrypted in transit and at rest by our infrastructure providers, access is restricted by row-level security policies scoped to your account, and administrative operations are limited to server-side credentials. No system is perfectly secure; report suspected vulnerabilities to cyberprosoftware@gmail.com.
11. Children
ProfitLoopHQ is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
12. Cookies
See our Cookie Policy for the categories of cookies we use and how to change your choices at any time.
13. Changes
We will update this policy as the service changes and will revise the "last updated" date above. Material changes will be announced by email or in-app before they take effect.
Other policies
Questions about this policy? Email cyberprosoftware@gmail.com.