Privacy Policy
Version: 2026-08-15 Last updated: 2026-08-15 Effective from: 2026-08-15
1. Identity of the controller and contact details
Loopfy is software that helps travel agencies prepare visa applications for their clients.
The company responsible for the information described in this policy is:
Loopfy, LLC 2093 Philadelphia Pike Suite #4591 Claymont, DE 19703 United States
Loopfy, LLC is a limited liability company formed in the State of Delaware, United States. Because Loopfy is a United States company operating on United States infrastructure, information handled by Loopfy is processed in the United States. Section 10 sets this out.
Privacy enquiries may be addressed to support@loopfy.io.
2. Scope and application
Loopfy's customer is the travel agency. The individuals whose passports and personal details pass through Loopfy are the agency's clients, the visa applicants. Those applicants ordinarily hold no account with Loopfy and have had no dealings with us.
That distinction determines who is responsible for what, and this policy is divided accordingly:
- Part A covers information about the agency and its staff, the individuals who hold Loopfy accounts. For that information, Loopfy determines what is collected and why, and is therefore the controller in data protection terms.
- Part B covers information about visa applicants and other individuals named on an application, such as parents, sponsors, accompanying adults and hosts. Loopfy holds and processes that information only because an agency has placed it there and instructed us to do so, and the agency determines what is collected and what is done with it. The agency is therefore the controller and Loopfy the processor.
An applicant who wishes to know what is held about them, or to have it corrected or deleted, should therefore address that request to the travel agency they dealt with. Section 12 sets out what happens if the request is made to Loopfy instead.
Part A. Information about agencies and their staff
3. Information we collect
On account creation: your name, your email address, your phone number, and a password. Where you sign up with Google, we receive your name and email address from Google in place of a password.
On creating or joining an agency: the agency name, the country the agency applies from, the agency's address, its time zone and language preferences, and your role in the agency (administrator or agent).
When a colleague invites you: the colleague's name and your email address, so that the invitation can be sent.
Your profile settings: time zone, display language, and your marketing preference.
Your use of the product: the pages you open, the actions you take, and timing information. Section 7 describes this.
Technical information: we do not store your IP address in our analytics, and IP collection is switched off at the analytics vendor.
4. Purposes of processing and legal bases
| Purpose | Legal basis, if GDPR applies |
|---|---|
| Creating and operating your account, and providing the service you requested | Performance of a contract |
| Keeping the service secure, preventing unauthorised access, and investigating problems | Legitimate interests: operating a secure service |
| Understanding how the product is used in order to improve it | Legitimate interests: improving the product. See section 7 on session recording |
| Sending you service messages such as password resets and team invitations | Performance of a contract |
| Meeting our legal obligations | Legal obligation |
| Marketing, if any is ever sent | Consent |
5. Recipients
Our hosting provider, our database provider, our email provider (for password resets and invitations), and our analytics provider.
We do not sell personal information and we do not share it for advertising.
6. Retention
We retain your account information for as long as your agency holds an account with us.
7. Product analytics and session recording
When you are signed in to the Loopfy dashboard, we record how the product is used. That includes a session recording, being a reconstruction of what happened on screen, which Loopfy and our analytics provider can replay.
Information excluded from the recording. Because the dashboard displays your clients' passport details, the recording is constructed to strip that information out before it leaves our systems:
- All visible text on the page is replaced with the word
[masked], at a fixed length, so that not even the length of a value is revealed. - Everything typed into a form field is masked.
- Images, photographs, canvases, video, audio, embedded frames and file previews are blocked entirely and are never recorded.
- Web addresses are reduced to a coarse page name. Query strings, page anchors and referrers are discarded, so that a page address containing an applicant's record ID is not transmitted.
- Element attributes, browser console output, network request bodies and network headers are not recorded.
- Events are assembled from a fixed list of permitted names and properties. Anything not on that list is dropped rather than passed through.
- Analytics traffic is sent through loopfy.io rather than directly to the analytics provider, and cookies, credentials and referrer information are stripped from it.
- Your IP address is not collected.
Information the recording captures: your user account ID, your agency's ID, your agency's name, your role, the page you are on, the shape and position of things on screen, where you clicked and scrolled, and timing.
Location of processing. Our analytics provider processes this information in the United States. That is a deliberate choice and it is relevant if you or your clients are in the EU or the UK. See section 10.
Part B. Information about visa applicants
Part B applies to visa applicants and to other individuals named on an application.
8. Our role
Where a travel agency has used Loopfy to prepare your visa application, the agency uploaded your documents and entered your details into our software. The agency determines what is collected, what is done with it, and how long it is kept. Loopfy acts on the agency's instructions. We do not use your information for our own purposes, we do not sell it, and we do not use it to train artificial intelligence models.
9. Categories of applicant information processed by Loopfy
From the passport, read automatically from the machine-readable strip: surname and given names, date of birth, nationality, sex, passport number, passport type (for example ordinary, diplomatic or service), issuing country, date of issue, date of expiry, and the personal or national identification number where the passport carries one.
Entered by the agency, or read from documents: place and city of birth, surname at birth, nationality at birth if different, current address, phone number, email address, marital status (single, married, divorced, separated or widowed), current occupation, employer or educational establishment, and how the trip is being paid for.
About the trip: destination country and city, the country of first entry, travel dates, number of nights, the accommodation recorded for the trip and its address, which travellers are recorded as staying together where a group travels, and previous visa information such as an earlier visa sticker number or residence permit number.
About other individuals named on the application. Government visa forms require details of persons who are not the applicant. Loopfy therefore holds:
- Parents: the mother's and father's family name, first names and nationality, and, where the applicant is a minor, the parents' address, email and telephone.
- A legal representative or guardian, where one is named.
- A sponsor or guarantor, including their name, nationality, passport number and national identification number.
- An accompanying adult travelling with a minor, including their passport details and their relationship to the child.
- A host or reference in the destination country, including their name, sex, date of birth, place of birth, nationality, address, telephone and email.
- A family member who is an EU, EEA or Swiss citizen, or a UK national covered by the Withdrawal Agreement, where the form asks for one, including their name, date of birth, nationality, travel document or identity card number, and their family relationship to the applicant.
- Children named on a parental authorisation letter, including their names and passport numbers.
Documents uploaded by the agency. Files are stored as uploaded. The document types the product supports are: passport, the mother's, father's, sponsor's and accompanying adult's passports, national identity card, residence permit, personal photograph, bank statement, employment letter, marriage certificate, birth certificate, travel insurance, previous visa, invitation letter, flight itinerary, accommodation, sponsorship letter, parental authorisation letter, and a general "other documents" category. Files may be PDFs, photographs or scans, up to 20 MB each.
Text extracted from those documents. Where a document is read, the text extracted from it is stored alongside the file.
Answers to the government's own questions. Whatever the destination country's form asks, the answer is stored. On the German Schengen form that currently includes whether the applicant's fingerprints have previously been collected for a Schengen visa, and whether they wish to exercise a right to freedom of movement.
Portal login details. Some government portals require the applicant to hold an email address and a password. Loopfy can create a mailbox for that purpose on a domain we own, and stores the portal password in encrypted form.
Records of what the automation did. Where Loopfy fills a government form, we keep a record of the run: the resolved set of answers, a screenshot or printable copy of the completed form, a per-field check of whether each value was written correctly, and any error message. Our cloud browser provider also keeps its own recording of the browser session, which shows the form being filled.
Delivery records. Where documents are sent over WhatsApp, we record the recipient's phone number, which documents were sent, the message status, and the file name.
10. Recipients and international transfers
The companies that handle this information, and what each one receives, are:
- Our database and file storage provider holds everything. AWS
ap-northeast-2(Seoul, South Korea) - Our hosting provider runs the website and the API. AWS
ap-northeast-2(Seoul, South Korea) - Our background worker provider runs the automation. It is in the United States.
- Our cloud browser provider opens the government portal and types the application in, and keeps its own session recordings. It is in the United States.
- A residential proxy provider may carry the portal traffic.
- Google Cloud Vision receives the passport file itself, in order to read it.
- MailSlurp hosts the mailbox created for the applicant, and holds the mail sent to it.
- Meta receives the recipient's phone number and the document files, where the agency chooses to deliver documents over WhatsApp.
- Our analytics provider, in the United States, receives only agency and staff identifiers and a masked recording, as described in section 7.
International transfers. Loopfy, LLC is a United States company. Personal information handled by Loopfy leaves the country in which it was collected and is processed in the United States, and by the vendors listed above, in the countries stated.
11. Retention and deletion
Nothing is deleted automatically. No timer removes an application after a period of time. Information remains until the agency deletes it.
Deletion of an application by an agency is permanent and cannot be undone. It removes, in this order:
- Every file the agency uploaded, from our document storage.
- Every document Loopfy generated for that application, including sponsorship letters, parental authorisation letters, accommodation documents, and the completed application form.
- The screenshot of the completed government form.
- The application record itself and everything linked to it: the applicant's details, the details of the parents, sponsors and accompanying adults, every answer to the government form, the extracted text of every document, the portal mailbox record and encrypted password, the automation job records, the letter records, the accommodation records, and the WhatsApp delivery log for that application.
Information that survives that deletion. The following is retained, for the reasons stated:
- Usage and cost records survive with the application reference removed. They are counts of how many times a service was used, and deleting them would rewrite the agency's billing history. They contain no personal details.
- Cloud browser session records survive with the application reference removed. The record itself holds no applicant details. However, the session recording held by the cloud browser provider is not deleted, and it shows the government form being filled.
- The mailbox created for the applicant is not deleted at our mailbox provider. Our record of it is removed, but the inbox and the mail it received continue to exist there.
- Internal failure alerts are kept for our own operational records. They contain the agency name, the application's internal reference, the embassy, the portal address and an error message.
- Documents already delivered over WhatsApp cannot be recalled from Meta or from the recipient's phone.
- Backups. Deleting an application removes it from our live systems immediately. It does not remove it from our database provider's backups, which retain a copy for a period after deletion. Once that period passes, the backup copy expires and is gone.
Superseded documents. Where an application is reopened and a document is replaced, the earlier version is hidden from the agency's view but kept, until a replacement of the same type exists, at which point it is permanently removed.
12. Applicant rights and how to exercise them
If you are an applicant, the law of your country may give you rights over your information: to access it, to have it corrected, to have it deleted, to restrict or object to its use, and to receive a copy of it.
Requests should be made to the travel agency first. The agency decided to collect your information and controls it. It has a delete function within Loopfy that permanently removes an application and its documents, and it can correct anything that is wrong.
Requests made to Loopfy directly. We will acknowledge receipt of your request. Because we hold your information on behalf of an agency and cannot verify your identity or your relationship to the agency, we will not act on the request ourselves. We will pass your request to the agency that holds your file, tell them what you asked for, help them respond, and tell you which agency we passed it to.
Right to complain. You may complain to the data protection authority in your country.
Part C. General provisions, applying to everyone
13. Security measures
The measures set out below are those in place. We have deliberately not listed any measure we have not implemented, and Loopfy does not claim certification against any security standard.
- Separation between agencies. Every record carries the agency it belongs to, and the database itself refuses to return one agency's records to another agency's user. This is enforced in the database and not only in the application, so a fault in the application cannot leak one agency's passports to another.
- Files are private. Every file store is private. There are no public file links. Files are reached through short-lived links that expire, typically after one to two minutes.
- Encryption in transit. All traffic to and from Loopfy uses HTTPS.
- Portal passwords are encrypted with AES-256-GCM before storage, using a key that exists only in our server environment and is never stored in the database or the source code. That password is never sent to the browser.
- Secrets remain on the server. No API key or credential is exposed to the browser.
- Sign-in and password recovery. Passwords are handled by our authentication provider and are never stored by us in readable form. A password reset returns the same response whether or not an account exists, so the process cannot be used to find out who holds an account. Changing a password requires the current password. A reset link is usable only for a short window.
- Webhooks are verified cryptographically before we accept anything sent to us by WhatsApp or by our mailbox provider.
- Personal details are not logged. The automation is written so that applicant values are never written to logs, and the code carries this rule as an explicit instruction.
- Encryption at rest is provided by our database and storage provider.
14. Children
Loopfy is used by travel agency staff, who are adults. However, visa applications are frequently made for children, and information about children therefore passes through Loopfy: their name, date of birth, passport details, place of birth, which parent they are travelling with, their parents' details, and who they are recorded as staying with.
That information is provided by the agency on the instructions of the child's parent or guardian. The agency is responsible for having the right to provide it.
15. Cookies and similar technologies
Loopfy uses browser storage to keep you signed in and to hold an analytics identifier. We do not use advertising cookies and we do not permit third-party advertising trackers.
16. Changes to this policy
Where we change this policy in a way that materially affects you, we will notify agency account holders before the change takes effect and record which version applies from when.