Privacy policy
Last updated 1 September 2026
This policy explains what Unify Loop (“we”) collects when you use our website and product, why we collect it, and what control you have over it. It is written to be read, not to be survived.
The two roles we play
The distinction matters, because your rights differ between them.
- For your workspace data — the contacts, records, and conversations you put into the product — you are the controller and we are the processor. It is your data. We process it to provide the service, on your instructions, and we do not decide what to do with it.
- For your account and our website — your login, billing details, and how you use our marketing site — we are the controller.
What we collect
Account data
Name, work email, workspace name, and authentication credentials. If you sign in with Google we receive your name, email address, and profile image from Google — not your Google password.
Billing data
Plan, seat count, and usage totals. Card details are handled by our payment processor and never reach our servers.
Workspace data
Whatever you choose to store: records, fields, messages, attachments, and the activity history attached to them. The scope of this is determined by you, not us.
Usage and technical data
Log data — IP address, browser, pages or features used, timestamps, and errors — used to operate the service, investigate faults, and detect abuse.
Google Workspace data
If you connect a Google account — Settings → Integrations, inside the product — we ask Google for two permissions, and use them for one feature: scheduling meetings with the people in your CRM.
- Creating the meetings you schedule. When you book a meeting in Unify Loop, we create the matching event on your Google Calendar — and a Google Meet conference on it, if you chose Meet as the location. Google Calendar then sends the invitation from your own account, so the person you are meeting hears from you rather than from a generic address belonging to us.
- Respecting time you are already busy. We read the start and end times of your existing events, so your availability grid and your public booking page never offer a slot you are already committed to.
What we store, exactly
For each event on a calendar you have told us to treat as busy: the start time, the end time, and whether it marks you busy or free. That is the entire list. We do not store event titles, descriptions, attendees, locations, attachments, or any other content of your events — a scheduling grid only needs to know that something is there, not what it is.
We request no access to Gmail, Drive, or Google Contacts, and cannot read them. The tokens for your connection are encrypted before they are stored, under a key held separately and bound to your workspace, so they cannot be read by another workspace even in the event of a database compromise.
Limited Use
Unify Loop’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this information. We do not transfer it to anyone except as needed to provide the feature you asked for, or where the law requires it. We do not use it for advertising. And we do not let humans read it — except with your explicit permission, to resolve a support issue you have raised, or where the law requires it.
Turning it off
Disconnect at any time from Settings → Integrations. That tells Google to revoke our access, deletes the stored credentials, and deletes the cached busy times. You can also revoke it from your Google account’s security settings, in which case the connection shows as disconnected here and stops being used. Meetings you already scheduled stay on your calendar — they are yours — but we stop managing them.
What we do not do
- We do not use your workspace data to train AI models, and we do not permit our model providers to train on data we send them.
- We do not sell your data, and we do not sell access to it.
- We do not resell or share your contact lists with anyone, including other customers.
- We do not restrict export of your own data as a retention tactic.
Why we process it
To provide and secure the service (our contract with you); to bill you (contract); to keep the service safe and detect abuse (legitimate interests); to comply with legal obligations; and to send you product and marketing email where you have consented or where we have a legitimate interest and you can opt out in one click.
Who we share it with
Only subprocessors necessary to run the service — cloud hosting and storage, AI model inference, message delivery for SMS, WhatsApp, and email, payment processing, error monitoring, and product analytics. Each is bound by contract to process data only as instructed. A current list is available from privacy@unifyloop.com on request.
We may also disclose data where legally compelled, and we will tell you unless we are prohibited from doing so.
International transfers
Some subprocessors operate outside your country. Where data leaves the UK or EEA we rely on appropriate safeguards, including standard contractual clauses. Data residency commitments are available on Enterprise plans.
How long we keep it
- Workspace data — for as long as your workspace is active. After cancellation it is retained for a limited window so an accidental cancellation is recoverable, then deleted.
- Account and billing records — as long as needed for legal, tax, and accounting obligations.
- Logs — a rolling short retention window, then discarded.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data, to receive a portable copy, and to withdraw consent. Exercise any of these by emailing privacy@unifyloop.com. We will respond within the period the applicable law requires, and we will not make the process deliberately difficult.
If we process data as a processor on your behalf and one of your contacts exercises a right, ask us and we will help you respond.
Cookies
Our marketing site uses only what it needs to function and to understand aggregate traffic. The product uses cookies for authentication and session management on a shared parent domain, which is what keeps you signed in between the site and the app. We do not run third-party advertising trackers.
Security
Encryption in transit and at rest, least-privilege production access, audit trails, and tenant isolation enforced in the query layer rather than per feature. The detail — including what we have not certified yet — is on our security page.
Children
The service is for business use and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
If we make a material change we will tell you by email or in-product before it takes effect, rather than silently updating this date.
Contact
Privacy questions, requests, or complaints: privacy@unifyloop.com. You also have the right to complain to your local data protection authority.