Legal

Privacy Policy

Effective date: May 5, 2026

This Privacy Policy explains what information Social Loop AI collects, how we use it, who we share it with, and the choices you have. It applies to the Social Loop AI website, the Shopify app, and any related services that link to this policy.

1. Who we are

Social Loop AI ("Social Loop AI", "we", "us") is an advertising-creative platform that turns product pages and connected Shopify stores into Meta and TikTok ad creatives, along with an audience, angles, page audit, and test plan. We operate the service from the United States.

For data collected through your account, Social Loop AI is the data controller. For Shopify merchants who install our app, we act as a processor for any product data you import through the Shopify Admin API, on the lawful basis you maintain with Shopify and your customers.

Questions about this policy can be sent to [email protected].

2. Information we collect

Account data

When you sign up we collect your email address and a salted, hashed password (we never store your password in plain text). If you are an admin or support staff member, we also store your role.

Billing data

For users billed through Stripe, we store your Stripe customer ID, subscription ID, plan, and invoice history. For Shopify-installed users, we store your Shopify subscription identifiers and one-time credit-pack charge IDs. We do not see or store credit-card numbers, CVCs, or bank-account details — those are handled directly by Stripe or by the Shopify Billing API.

Shopify install data (Shopify users only)

If you install the Social Loop AI Shopify app, we receive and store your shop domain, an offline Shopify Admin API access token (encrypted at rest), and the products you choose to import through our product picker. When you uninstall, Shopify fires a shop/redact webhook 48 hours later that triggers a hard delete of the connected shop, the encrypted access token, and any imported products. The mandatory customers/data_request and customers/redact webhooks are acknowledged immediately because we never store Shopify customer or order data — see Section 3.

Product and creative data

To generate creatives, we process the product URLs you submit, the page metadata we scrape from them (product title, description, images, price), the AI strategy we generate (audience, angles, page audit), the creatives we generate, your like / dislike feedback, and any post-launch performance metrics you choose to log (impressions, spend, clicks, ATCs, purchases).

Support communications

When you open a support ticket through the in-app support flow or email [email protected], we store the conversation, your email address, and any attachments so we can help you and audit our responses.

Usage and device data

Like most web applications, our servers and analytics tools record basic technical information when you use the service: your IP address, browser user agent, the pages you visit, the time of each request, and product events such as “wizard step completed” or “creative generated”.

Cookies and similar technologies

We use a small number of cookies and browser-storage entries:

  • A session cookie that keeps you signed in.
  • A CSRF token cookie that protects against cross-site request forgery.
  • Google Analytics cookies that measure aggregate website usage.
  • Mixpanel identifiers that attribute product events to your account.

You can clear cookies at any time through your browser. Disabling session cookies will prevent you from staying signed in.

3. What we do not collect

We do not store Shopify customer records, orders, or any buyer-identifying data. The mandatory Shopify privacy webhooks (customers/data_request and customers/redact) are acknowledged immediately because there is nothing to look up or delete on our side. We also do not collect special categories of personal data, biometric identifiers, or precise GPS location.

4. How we use information

  • To provide the service — generate strategy, page audits, and creatives from your product data.
  • To bill you and keep records required by tax law.
  • To respond to support requests and operate the support inbox.
  • To send transactional email (password resets, receipts, ticket replies, account notifications).
  • To secure the service, detect fraud and abuse, and enforce our Terms.
  • To understand product usage in aggregate so we can improve the wizard, the AI, and the creatives.
  • To comply with legal obligations and respond to lawful requests.

We do not sell personal data, and we do not use your data to train third-party AI models. The creatives we generate for you are produced by sub-processors (see Section 6) under contracts that prohibit them from using your inputs to train their general models.

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:

  • Contract — to deliver the service, run billing, and provide support.
  • Legitimate interests — to secure the service, prevent abuse, debug issues, and improve the product in aggregate.
  • Consent — for analytics and similar non-essential cookies where consent is required by local law. You can withdraw consent at any time.
  • Legal obligation — to keep tax-relevant billing records and respond to lawful requests.

6. How we share information

We share personal data only with vetted sub-processors who help us operate the service, and only to the extent necessary for the purpose listed:

  • Stripe — subscription billing and one-time credit-pack purchases (Stripe-billed users).
  • Shopify — install, billing, product import, and mandatory privacy webhooks (Shopify-installed users).
  • OpenAI — AI strategy and creative generation. Inputs and outputs are processed under OpenAI's API data-handling terms, which prohibit using API content to train their models.
  • Amazon Web Services (S3) — storage for generated creative assets.
  • Mailgun — transactional email delivery.
  • Mixpanel — product analytics, event-level only.
  • Google Analytics — aggregate website usage metrics.

We may also disclose information to comply with applicable law, a lawful court order, or a binding government request, and to protect the rights, property, or safety of Social Loop AI, our users, or the public. If Social Loop AI is involved in a merger, acquisition, or asset sale, personal data may transfer to the successor entity under the same protections.

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.

7. International transfers

Our infrastructure and team are based in the United States. If you access the service from outside the United States, your personal data will be transferred to and processed there. Where we transfer personal data of EEA, UK, or Swiss users to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum) with our sub-processors.

8. Retention

  • Account data, products, creatives, and feedback are retained for the life of your account plus a 30-day grace period after cancellation.
  • Billing records (invoices, charges) are retained for as long as required by tax law — typically up to seven years.
  • For Shopify users, the encrypted Admin API access token and any imported products are hard-deleted within 48 hours of the shop/redact webhook firing after uninstall.
  • Support tickets are retained for up to two years after closure so we can audit our support quality.
  • Analytics events are retained per the relevant sub-processor's default retention.

9. Security

We use industry-standard safeguards to protect your data, including TLS in transit, salted bcrypt hashing for account passwords, encryption at rest for the Shopify Admin API access token, role-based access controls for our admin tools, and isolated background workers for side-effecting jobs. No system can be guaranteed perfectly secure, so we encourage you to use a strong, unique password and to notify us immediately if you suspect your account has been compromised.

10. Your rights

Wherever you live, you can ask us to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Delete your account and associated data — see our Data Deletion page.
  • Receive a portable copy of your data.
  • Object to or restrict certain processing.
  • Withdraw any consent you previously gave (for example, for analytics cookies).

To exercise these rights, email [email protected] from the address on your account. We respond within 30 days, or sooner if local law requires it.

11. GDPR rights (EEA / UK)

In addition to the rights above, users in the EEA and UK have the right to lodge a complaint with their local data-protection supervisory authority. We are the data controller for personal data we collect about your account. Where we use sub-processors (Section 6), they act as processors under written agreements that include the Standard Contractual Clauses or equivalent safeguards.

12. California rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the rights described here. In the past 12 months we have collected the following categories of personal information:

  • Identifiers — account email, IP address, online identifiers (Mixpanel / GA IDs).
  • Commercial information — subscription plan, billing history, credit-pack purchases.
  • Internet or other electronic activity — pages visited, product events, support interactions.
  • Geolocation (coarse) — approximate region inferred from IP address.
  • Inferences — product-usage patterns derived from event data.

We collect these categories from you directly and from cookies on our website. We disclose them for the business purposes described in Sections 4 and 6 to the sub-processors listed in Section 6.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under California law. We do not knowingly collect or disclose the personal information of consumers under 16.

As a California resident, you have the right to:

  • Know what personal information we have collected about you.
  • Delete personal information we have collected about you.
  • Correct inaccurate personal information.
  • Limit the use and disclosure of sensitive personal information (we do not use sensitive PI for any purpose other than providing the service).
  • Opt out of the sale or sharing of personal information (not applicable — we do neither).
  • Not be discriminated against for exercising these rights.

To submit a request, email [email protected] from the email on your account. You may also use an authorized agent; we will ask the agent for written proof of your authorization and may verify your identity directly before responding.

13. Children

The service is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please email [email protected] and we will delete it.

14. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Effective date” above and post the new policy on this page. For material changes that affect how we use your personal data, we will email account holders at the address on file before the change takes effect.

15. Contact

Questions, requests, or complaints about this policy can be sent to [email protected]. For self-serve account deletion, see our Data Deletion page.