This page covers two different things. The first is this website. The second is the Reloop CRM software that you install on your own server.
They are separate, and the difference matters: on your own server we hold none of your data.
The controller for this website is {{DATA_CONTROLLER}}, part of {{LEGAL_ENTITY}}, {{POSTAL_ADDRESS}}. Write to {{PRIVACY_EMAIL}} with any question about your data.
When you run Reloop CRM on your own server, you are the controller of everything inside it. Your mailbox, your contacts and your deals never reach us.
The public pages load no analytics. There is no autocapture, no session replay and no tracking script on this site.
The web server that serves these pages is run by {{HOSTING_PROVIDER}}. It writes the usual server log for each request. That log is kept for {{RETENTION_PERIOD}} and is used to keep the site up and to find abuse.
If you give us your email address to hear about the hosted version, we store that address and the date you gave it. We use it to tell you when the hosted version opens. Write to {{PRIVACY_EMAIL}} to have it deleted.
Signing in sets a session cookie. That cookie keeps you signed in and is needed for the app to work. There is no advertising cookie. The fonts are served from this server, so no font service is called when you open a page.
Reloop CRM reads the mailbox you connect, over IMAP, Google Workspace or Microsoft 365. It stores the messages, the contacts and the companies in the Postgres database on your server. You choose how far back the first read goes. Nothing is copied anywhere else.
The AI parts run against an API key that you hold, from OpenRouter, OpenAI or Anthropic. The text of a conversation goes to the provider you picked, under your own contract with that provider. Without a key the CRM runs with the AI parts switched off, and no text leaves your server.
Reloop CRM can report one event a day about itself, plus a small number of setup events and one event for a failure. It sends them to the reporting project that you set up, not to us. No key means no client, and an install that sets none is silent. The event carries counts, never a value from a row. There is no contact name, no email address, no company domain and no deal amount in it.
The identifier is a single UUID made when your database was created. It is attached to nothing else. No IP address is sent, and the receiving project drops the address at ingestion. An allowlist in the source code names every property that may be sent, and anything else is dropped before the event is built.
Set CRM_TELEMETRY_DISABLED to 1 or DO_NOT_TRACK to 1 in your .env file, then restart. Nothing is sent after that. An install that never sets a reporting key sends nothing at all.
For this website: {{PROCESSORS}}. We sell no data and we share none for advertising.
You can ask what we hold about you, ask for a copy, ask for a correction and ask for deletion. You can object to a use and you can withdraw a consent you gave. Write to {{PRIVACY_EMAIL}}. You can also complain to {{SUPERVISORY_AUTHORITY}}.
This page is valid from {{EFFECTIVE_DATE}}. A change to it is published here.