Loopchat Privacy Policy
Last updated: September 4, 2026
This Privacy Policy explains how Loopchat ("Loopchat," "we," "us," or "our") collects, uses, stores, shares, and protects information when a business ("Business," "Owner," "you") uses the Loopchat platform to manage customer conversations on LINE, and when a Business's customers ("Customers," "End Users") message that Business's LINE Official Account.
Loopchat is operated by Loopchat, based in Thailand. If you have questions about this policy, contact us at milosupport.team@gmail.com.
This document is written to comply with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). If Loopchat is used by or serves individuals in other jurisdictions, additional local rights may apply and will be reflected in future updates to this policy.
1. Scope of This Policy
This policy covers two categories of people:
- Business Owners — the small business or individual who signs up for a Loopchat account, connects a LINE Official Account, and configures Loopchat's catalog, FAQs, business hours, and integrations.
- Customers — individuals who message a Business's LINE Official Account and, as a result, have their messages processed by Loopchat on that Business's behalf.
Loopchat acts as a data processor on behalf of the Business for Customer conversation data, and as a data controller for Business account and configuration data. Where PDPA terminology differs from this framing, the substantive obligations described below still apply.
2. Information We Collect
2.1 Information from Business Owners
When you create a Loopchat account and configure your business, we collect:
- Account information: email address, username, hashed password (we never store your password in plain text), and authentication session data.
- Business profile information: business name, description ("about"), business hours, payment/delivery/return policies, and any other content you choose to write into your knowledge base.
- Catalog data: products, services, prices, stock quantities, promotions, and photos you upload.
- LINE Official Account credentials: your LINE Channel ID, Channel Secret, and Channel Access Token, which you provide so Loopchat can send and receive messages on your behalf. These are stored securely and are never displayed to your Customers.
- Google Calendar authorization (optional): if you connect Google Calendar, we store an OAuth refresh token and access token issued by Google, scoped only to read your calendar and, if you enable booking, create events on it. You can revoke this access at any time in Settings or directly through your Google Account permissions.
- Notification linking data: if you link your own personal LINE account to receive handoff notifications, we store your LINE user ID for that purpose only.
2.2 Information from Customers (End Users messaging a Business)
When a Customer messages a Business's LINE Official Account, Loopchat receives and processes, on the Business's behalf:
- LINE identifiers: the Customer's LINE user ID (a unique identifier assigned by LINE, not the Customer's phone number or real name unless they choose to share it in a message) and, where available and permitted, their LINE display name and profile picture, used only to help the Business identify who they're talking to.
- Message content: the text of messages the Customer sends to the Business, and the replies (AI-generated or written by the Business Owner) sent back.
- Booking details, if the Customer requests to book a service: the service requested, proposed date and time, and any notes the Customer provides.
Customers do not create a Loopchat account and do not interact with Loopchat directly — they are messaging the Business through LINE, and Loopchat operates in the background as the Business's chosen tool.
2.3 Information Collected Automatically
- Usage and analytics data: aggregate statistics about conversation volume, AI resolution rates, and response times, used to power the Business's own analytics dashboard within Loopchat.
- Technical data: IP addresses, browser type, and similar technical metadata collected in standard server logs for security and debugging purposes.
3. How We Use Information
We use the information described above to:
- Operate the core Loopchat service: receiving Customer messages via LINE, generating AI responses grounded in the Business's own catalog and knowledge base, and delivering those responses back to the Customer.
- Allow the Business Owner to view conversation history, take over a conversation from the AI, and manage bookings.
- Send notifications to the Business Owner (via their own linked LINE account) when a conversation needs human attention.
- Provide the analytics dashboard showing conversation and response trends.
- Propose calendar bookings and, only after the Business Owner explicitly confirms, create the corresponding event on the Business's connected Google Calendar.
- Detect and prevent abuse, fraud, or security issues.
- Improve and maintain the Loopchat platform.
We do not use Customer message content to train any AI model, and we do not sell personal data to third parties.
4. Legal Basis for Processing (PDPA)
Under Thailand's PDPA, we rely on the following legal bases:
- Contractual necessity: processing Business account data is necessary to provide the Loopchat service the Business has signed up for.
- Consent: Business Owners consent to this policy when creating an account and connecting third-party services (LINE, Google Calendar). Customers, by choosing to message a Business's LINE Official Account, are engaging with that Business's own customer service channel; the Business is responsible for ensuring its own use of Loopchat is consistent with how it represents itself to Customers.
- Legitimate interests: for security monitoring, fraud prevention, and service improvement, balanced against the rights of the individuals concerned.
5. AI Processing and Third-Party Service Providers
In addition to Anthropic, Loopchat relies on the following third-party service providers to operate:
| Provider | Purpose | Data Involved |
|---|---|---|
| LINE Corporation | Messaging infrastructure (LINE Official Account / Messaging API) | Customer messages, LINE user IDs, display names |
| Anthropic | AI-generated responses (see notice above) | Catalog/FAQ content, conversation snippets, current message |
| Google LLC | Optional Google Calendar integration | Calendar event data, OAuth tokens (only if the Business connects Calendar) |
| Supabase, Inc. | Database and backend infrastructure hosting | All account, catalog, and conversation data described in this policy |
| Lovable | Application hosting for Loopchat's web app | Technical/session data needed to serve the app |
Each of these providers processes data under their own privacy policies and terms, which we encourage you to review. We select providers that maintain industry-standard security practices, and we do not share more data with them than is necessary to provide the relevant feature.
6. How We Share Information
We do not sell personal data. We share information only:
- With the third-party service providers listed above, strictly as needed to operate the features described in this policy.
- Between a Business Owner and their own Customers, as the core function of the product (a Business can see its own Customers' conversation history; Customers see only their own conversation).
- If required by law, legal process, or to protect the rights, property, or safety of Loopchat, our users, or the public.
- In connection with a merger, acquisition, or sale of assets, in which case we will notify affected users as required by law.
7. International Data Transfers
Because Loopchat relies on service providers based outside Thailand (including Anthropic and Google, both US-based, and Supabase, which may host infrastructure in various regions), personal data may be transferred to and processed in countries outside Thailand.
Under the PDPA, cross-border transfers require that the receiving country maintain adequate data protection standards, or that appropriate safeguards (such as standard contractual clauses) are in place. We work with providers that offer contractual data protection commitments consistent with these requirements, and we will update this policy as Thailand's Personal Data Protection Committee (PDPC) issues further guidance on approved transfer mechanisms.
8. Data Retention
- Business account data is retained for as long as the account remains active, plus a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements.
- Conversation and message history is retained to allow the Business Owner to review past interactions, unless the Business deletes it or closes their account.
- AI processing data held by Anthropic is retained only as described in Section 5 above (currently up to 7 days), independent of Loopchat's own retention of the underlying conversation record.
- Google Calendar tokens are retained until the Business disconnects Calendar or deletes their account, at which point they are deleted and any corresponding Google authorization is revoked.
Business Owners can request full account deletion and data export at any time via Settings, or by contacting us directly.
9. Data Security
We apply industry-standard technical and organizational measures to protect personal data, including encrypted connections (HTTPS/TLS) for all data in transit, encrypted storage of sensitive credentials, row-level access controls so a Business can only ever access its own data, and restricted internal access to production systems.
No system can be guaranteed 100% secure. If we become aware of a data breach affecting personal data, we will notify affected parties and the relevant authorities as required under the PDPA's 72-hour breach notification requirement.
10. Your Rights Under the PDPA
If you are a data subject under Thailand's PDPA (whether a Business Owner or a Customer), you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete personal data.
- Erase your personal data, subject to legal retention obligations.
- Restrict or object to certain processing of your personal data.
- Data portability — receive your data in a structured, commonly used format.
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint with Thailand's Personal Data Protection Committee (PDPC) if you believe your rights have been violated.
Business Owners can exercise most of these rights directly within Loopchat (Settings → Account → Export Data / Delete Account). Customers who wish to exercise these rights regarding their own conversation data should contact the Business they messaged directly, or reach us at milosupport.team@gmail.com and we will coordinate with the relevant Business as the data controller for that conversation.
11. Children's Privacy
Loopchat is not directed at children, and Business Owners must be of legal age to enter into a binding agreement in their jurisdiction. We do not knowingly collect personal data from children through the Business Owner account creation flow. Because Customers interact with a Business's LINE Official Account rather than Loopchat directly, Business Owners are responsible for ensuring their own use of Loopchat complies with any applicable requirements regarding minors in their customer base.
12. Cookies and Similar Technologies
Loopchat's web application uses essential session cookies/local storage to keep Business Owners logged in and to remember basic preferences (such as language). We do not currently use third-party advertising or tracking cookies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify Business Owners via email or an in-app notice before the changes take effect. The "Last updated" date at the top of this document will always reflect the most recent version.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
milosupport.team@gmail.com
This Privacy Policy is intended to accurately describe Loopchat's data practices as of the date above and to align with the requirements of Thailand's PDPA. It is provided as a working draft and should be reviewed by a qualified Thai lawyer before being published or relied upon as a final, binding legal document — particularly given PDPA enforcement guidance continues to evolve.