Privacy Policy
Last updated: August 22, 2026
1. Who We Are
Loopback ("Loopback," "we," "us," or "our") provides an AI-assisted lead follow-up and appointment-scheduling service to cash-pay clinics (our "Customers" or "Clients"). This Privacy Policy explains how we collect, use, and protect information in two different contexts:
- Website Data — information collected when you visit loopbackai.co, request a demo, or otherwise interact with us directly as a prospective or current Customer.
- Service Data — information processed through the Loopback platform on behalf of a Customer (e.g. a clinic), such as the contact details and messages of that clinic's own leads and patients.
This entity operates under the trading name [insert registered legal entity name, e.g. "Loopback AI LLC"], registered in [insert state/country of formation].
2. Website Data We Collect
When you visit our website or book a demo, we may collect:
- Contact details you provide directly, such as your name, business email, phone number, and clinic name (for example, through our demo-booking calendar, currently powered by Cal.com).
- Basic technical and usage data (browser type, device type, pages viewed, referring URL) collected automatically to keep the site working and to understand aggregate traffic.
- Any information you send us directly by email.
We do not use advertising trackers or sell website visitor data.
3. Service Data We Process on Behalf of Clients
When a clinic becomes a Customer, Loopback connects to that clinic's own lead sources, CRM, and calendar to send and receive SMS (and, where configured, email) follow-up on the clinic's behalf. In this relationship:
- The clinic is the data controller for its leads' and patients' information — it decides what data to send us and is responsible for having the right to contact those individuals.
- Loopback acts as a service provider / processor, handling that data only to deliver the follow-up, qualification, and scheduling service the clinic has engaged us for.
- Service Data typically includes: a lead's name, phone number, email, message/conversation content with our AI assistant, and scheduling outcomes (e.g. appointment booked).
We do not use Service Data for our own marketing, do not sell it, and do not share it with any clinic other than the one that submitted it.
4. Texting & SMS Consent (TCPA)
- Leads are only messaged by the Service if they previously opted in when submitting their information to the clinic (e.g. via a form, call, or intake process) — Loopback does not source or purchase phone numbers to contact independently.
- Every SMS conversation includes a clear way to opt out (for example, replying STOP), and opt-out requests are honored immediately and are not messaged again by the Service.
- Message frequency varies based on the conversation; standard message and data rates may apply.
- This practice is intended to align with the Telephone Consumer Protection Act (TCPA) and CTIA messaging guidelines. Clinics remain responsible for obtaining and documenting valid consent from their own leads.
5. Not a Healthcare Provider — No PHI
Loopback's AI assistant is scoped to scheduling and lead qualification only. It is not designed to request, store, or process Protected Health Information (PHI), diagnoses, treatment details, or other clinical data, and it does not provide medical advice. Loopback is not a HIPAA-covered entity or business associate, and clinics should not use the Service to transmit PHI.
6. How We Use Information
- To operate, maintain, and improve the Service.
- To respond to demo requests, support inquiries, and other communications you send us.
- To send you information about your account or the Service (for Customers).
- To detect, prevent, and address fraud, abuse, or security issues.
- To comply with legal obligations.
7. Cookies & Similar Technologies
Our website uses only the cookies or local storage strictly necessary for the site and our demo-booking embed (Cal.com) to function. If we later add analytics or marketing cookies, we will update this policy and, where required, present a cookie consent option.
8. Third-Party Service Providers
We rely on a small number of vetted vendors ("subprocessors") to deliver the Service. Depending on the Customer's configuration, these may include:
- HighLevel — CRM, pipelines, SMS/email sending, and workflow automation.
- Twilio — underlying phone number and SMS/messaging infrastructure.
- Make.com — workflow automation for integrations HighLevel cannot handle natively.
- Cal.com — demo scheduling on our website.
- The Customer's own calendar or practice-management system (e.g. Google Calendar, Calendly, PatientNow, Aesthetic Record, Boulevard, Jane, Vagaro, Healthie, or Outlook), as chosen by that Customer.
Each of these providers processes data only as needed to provide their part of the Service and is bound by their own privacy and security commitments.
9. Data Sharing & Disclosure
We do not sell personal information. We may disclose information:
- To the subprocessors listed above, solely to operate the Service.
- To comply with a legal obligation, court order, or valid governmental request.
- To protect the rights, property, or safety of Loopback, our Customers, or others.
- In connection with a merger, acquisition, or sale of assets, subject to this policy continuing to apply to the transferred data.
10. Data Retention
Service Data is retained for as long as the Customer's account is active, or as otherwise instructed by the Customer, and is generally stored within the Customer's own CRM and calendar rather than a separate Loopback-only database. Website inquiry data is retained only as long as needed to respond to the inquiry and for reasonable business recordkeeping.
11. Your Rights & Choices
- Opt out of texts: reply STOP to any message at any time.
- Access, correction, or deletion: if you are a lead or patient of one of our Customers and want to exercise a data right, please contact that clinic directly, as they control the underlying data; you may also email us at info@loopbackai.co and we will route your request appropriately.
- Website inquiries: email info@loopbackai.co to access, correct, or delete information you've submitted to us directly.
California Privacy Rights
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information is collected, to request deletion, and to not be discriminated against for exercising these rights. We do not sell or "share" personal information as those terms are defined under CCPA. You can submit requests to info@loopbackai.co.
12. Children's Privacy
The Service is intended for business use by clinics and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or 16, where applicable) through our website.
13. Data Security
We rely on the security controls of our subprocessors (HighLevel, Twilio, and others) and follow reasonable administrative and technical practices to protect data we handle. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of our website or Service after changes take effect constitutes acceptance of the updated policy.
15. Contact Us
Questions, requests, or concerns about this Privacy Policy or your data? Email info@loopbackai.co.