Privacy Policy
FabricLoop ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our services ("Services"). It applies to account holders, administrators, and end users of FabricLoop.
B2B context — two categories of data: We distinguish between (a) Account Data — information about the organization and its administrators that we collect as a data controller — and (b) Customer Content — data that users create or upload inside the platform (tasks, notes, messages, files, etc.) that we process on behalf of the contracting organization as a data processor. This policy addresses both, with the organization as the controller of Customer Content.
By accessing or using our Services, you agree to this Privacy Policy. If you do not agree, please do not access or use our Services.
1. Information We Collect
a. Account Data (we are the controller): Name, work email address, job title, company name, phone number, billing address, payment method details, and transaction history — provided when creating an account, purchasing a subscription, or contacting support.
b. Usage & Technical Data (we are the controller): IP address, device identifiers, operating system, browser type, referring URLs, pages visited, feature usage events, and error logs — collected automatically when you use the Services.
c. Website assistant conversations (we are the controller): When you use the Ask about FabricLoop widget on our public website, we collect your prompts, the assistant's replies, optional email address if you request a human, the page URL, and locale. These conversations are stored indefinitely in our support workspace so we can answer follow-ups, and may be reviewed by our team. To request deletion, email privacy@fabricloop.com.
d. Customer Content (we are the processor): All content you or your team members create within the platform — tasks, notes, messages, files, events, and people profiles. We process this data solely on your organization's instructions.
e. Cookies & Tracking: We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies. You can manage cookies through your browser settings; disabling session cookies will prevent you from logging in.
2. How We Use Your Information
a. Service Delivery: Provisioning and maintaining your account; processing payments; providing customer support (including answering website assistant questions and escalations); sending transactional messages (invoices, security alerts, product updates).
b. Service Improvement: Analyzing aggregated, de-identified usage patterns to improve features, fix bugs, and develop new functionality. We do not use Customer Content for model training or product analytics without explicit consent.
c. Marketing (Account Data only): Sending news and promotional offers to account holders. You may opt out at any time via the unsubscribe link in any email or by emailing support@fabricloop.com.
d. Legal & Security: Detecting and preventing fraud, security incidents, and abuse; complying with legal obligations; enforcing our Terms.
3. How We Share Your Information
a. Sub-processors: We share data with third-party vendors who help us deliver the Services, including infrastructure (Supabase, Google Cloud), payment processing (Stripe), transactional email (Resend), product analytics (PostHog), and AI model providers (Anthropic, OpenAI) when you use AI features — including the public website assistant. The current list is published on our Security page. Enterprise customers may also request it via dpo@fabricloop.com.
b. Business Transfers: In a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction. We will notify affected users before data is transferred and becomes subject to a different privacy policy.
c. Legal Compliance: We may disclose data to law enforcement or courts when required by valid legal process. Where permitted by law, we will notify the affected customer before complying.
d. With Your Consent: For any other purpose, only with your explicit consent.
We do not sell or share personal information for cross-context behavioral advertising.
4. Data Retention
Account Data is retained for the duration of the subscription plus 90 days, then deleted or anonymized — except where longer retention is required by law (e.g., tax records for up to 7 years).
Customer Content is deleted within 30 days of account termination or upon a verified deletion request. Backup copies are purged within 90 days.
Website assistant conversations are retained indefinitely in our support workspace unless you request deletion via privacy@fabricloop.com.
You may request deletion at any time as described in Section 8 below.
5. Security
We implement industry-standard administrative, technical, and physical safeguards including: TLS encryption in transit, AES-256 encryption at rest, role-based access controls, SOC 2-aligned operational practices, and regular penetration testing.
In the event of a personal data breach, we will notify affected customers without undue delay and, where required by law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
6. International Data Transfers
Our Services are operated from the United States. If you access our Services from the EEA, UK, or Switzerland, your data will be transferred to the US.
For transfers of EEA/UK/Swiss personal data, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. A copy of the applicable SCCs is available upon request at dpo@fabricloop.com.
7. Your Rights and How to Exercise Them
Depending on your location, you may have the rights described below. To submit a request, email privacy@fabricloop.com with the subject line "Privacy Request" and include your name, account email, and the right you wish to exercise. We will respond within 45 days (extendable by a further 45 days for complex requests, with notice).
a. Access & Portability: Request a copy of the personal data we hold about you in a structured, machine-readable format.
b. Correction / Rectification: Request correction of inaccurate or incomplete personal data. Account holders may also update most data directly in account settings.
c. Deletion / Erasure ("Right to Delete"): Request deletion of your personal data. We will delete or anonymize your data unless we are required to retain it by law (e.g., for tax, fraud prevention, or legal proceedings). We will confirm completion of deletion in writing.
d. Restriction of Processing: Request that we restrict how we use your data while a dispute is resolved.
e. Object to Processing: Object to processing based on legitimate interests. We will stop unless we have compelling grounds that override your interests.
f. Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
g. Opt-Out of Sale / Sharing: We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
h. Non-Discrimination: We will not deny services, charge different prices, or provide a different level of service because you exercised any privacy right.
i. Complaints: If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK, or the relevant EEA supervisory authority).
8. California Residents — CCPA / CPRA
This section applies to California residents and supplements the rights in Section 7. FabricLoop is a business under the CCPA/CPRA.
Categories of personal information collected in the past 12 months: Identifiers (name, email, IP address); Commercial information (transaction and subscription history); Internet or electronic network activity (usage logs, feature events); Professional or employment-related information (job title, company name); Inferences drawn from the above to understand service usage preferences.
Sources: Directly from you; automatically from your use of the Services; from your employer (for enterprise accounts).
Business or commercial purposes: Service delivery, security, compliance, service improvement, and transactional communications as described in Section 2.
Categories of third parties with whom we share information: Cloud infrastructure providers, payment processors, analytics and error-monitoring tools. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties with whom we share it.
Right to Delete: You may request deletion of personal information we have collected. We will delete your information and direct our service providers to do the same, unless an exception applies (e.g., completing a transaction, security, legal obligations). We will confirm deletion in writing within 45 days.
Right to Correct: You may request correction of inaccurate personal information.
Right to Limit Use of Sensitive Personal Information: We do not use or disclose sensitive personal information beyond the purposes permitted by law (providing the Services, security, and legal compliance).
Authorized Agents: You may designate an authorized agent to submit requests on your behalf. We may require written proof of authorization and may verify your identity directly.
Shine the Light: California Civil Code § 1798.83 permits California customers to request information about personal information shared with third parties for direct marketing. We do not share personal information for third-party direct marketing.
To submit a CCPA/CPRA request, email privacy@fabricloop.com or write to: FabricLoop, Attn: Privacy, [Address]. We will respond within 45 calendar days.
9. EEA, UK, and Swiss Residents — GDPR / UK GDPR
This section applies to individuals in the European Economic Area, United Kingdom, and Switzerland.
Data Controller vs. Data Processor: For Account Data (account information, billing data, usage logs), FabricLoop is the data controller. For Customer Content (tasks, notes, messages, and other content created within the platform), FabricLoop is a data processor acting on behalf of the contracting organization, which is the data controller. If you are an end user seeking to exercise rights over Customer Content, please direct your request to your organization's administrator.
Data Processing Agreement (DPA): Enterprise customers may request our standard DPA, which incorporates SCCs for international transfers, by emailing dpo@fabricloop.com.
Legal Bases for Processing Account Data: Contract performance — to provide the Services you have signed up for; Legal obligation — to comply with applicable law; Legitimate interests — to improve our Services, prevent fraud, and ensure security (these interests do not override your fundamental rights); Consent — for marketing communications, which you may withdraw at any time.
Your GDPR Rights (response within one month, extendable by two months for complex cases): Right of Access (Article 15); Right to Rectification (Article 16); Right to Erasure / "Right to be Forgotten" (Article 17); Right to Restriction of Processing (Article 18); Right to Data Portability (Article 20); Right to Object (Article 21); Rights related to automated decision-making (Article 22 — we do not use automated decision-making with legal or similarly significant effects).
Data Breach Notification: We will notify you and the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to your rights and freedoms.
Sub-processors: We publish the list of sub-processors involved in processing Customer Content on our Security page. Enterprise customers may also request it via their DPA or by emailing dpo@fabricloop.com. We will provide 30 days' notice of any new sub-processor and give customers the right to object.
To exercise your GDPR rights, contact privacy@fabricloop.com. You also have the right to lodge a complaint with your local supervisory authority.
10. Data Protection Officer
We have appointed a Data Protection Officer (DPO). You may contact our DPO at: dpo@fabricloop.com
11. Children's Privacy
FabricLoop is a business productivity platform intended for use by organizations and professionals aged 18 and over. We do not knowingly collect personal data from individuals under 16. If we become aware of such collection, we will promptly delete the data.
12. Third-Party Services
Our Services may contain links to third-party websites. This Privacy Policy does not apply to those third parties. We encourage you to review their privacy policies.
13. Automated Decision-Making
We do not make automated decisions about you that produce legal effects or similarly significant effects without human review.
14. Changes to This Privacy Policy
We will notify you of material changes by email or through a notice in the Services at least 30 days before the change takes effect. Your continued use of the Services after that date constitutes acceptance of the updated policy.
15. Contact Us
For privacy questions or to submit a request: privacy@fabricloop.com
For DPO / GDPR matters: dpo@fabricloop.com
For general support: support@fabricloop.com