Legal

Privacy policy

Effective: August 28, 2026 · Version 2026-08-28-trust-v3-agent-phone-location-optional-web-analytics

Last updated: August 28, 2026

Version history: Added explicit opt-in controls and disclosures for privacy-minimized Google Analytics on public pages; essential-only use remains available.

This Privacy Policy explains what information Loppee, Inc. collects, how we use it, and the choices you have. It applies to our website, public business registry, customer and business-owner accounts, Jobs, APIs, MCP connector, and related services (the Services).

1. Who we are

Loppee, Inc., a Florida Profit Corporation (document number P26000036106), operates the Loppee public business-trust registry, directory, and related Services. For the purposes of this policy, Loppee is the controller of the personal information described below. Contact us at info@loppee.com with “Privacy request” in the subject line. Mailing address available on request.

2. Information we collect

  • Account & authentication data. Depending on the account and enabled providers, sign-in may use a passwordless email magic link, an enabled OAuth provider, or a passkey. We process identifiers supplied by that provider and authentication events (such as sign-in timestamps, authenticator type, and multi-factor status) to operate accounts.
  • Business information. Business owners and authorized agents may submit business details, documents, media, and verification evidence. Raw submitted documents remain private. Public Trust Cards expose only approved minimized business metadata; owner-provided insurance, when shown, carries this disclosure: “Insurance certificate provided by the business. Not independently confirmed by Loppee.”
  • Submissions & requests. Information you provide through forms (for example, agent-access requests, claims, reviews, or messages).
  • Optional AI-assisted support drafting. If this feature is enabled and an authorized Loppee support teammate explicitly requests a draft, we may process a bounded portion of the relevant support conversation and an optional drafting instruction. The feature does not send replies automatically, and AI-assisted replies are reviewed by a person and visibly labeled.
  • Agent/API usage. If you use Loppee through an API key, MCP connector, OAuth-connected app, or third-party agent, we process request metadata, tool/action names, scoped credential and connection identifiers, the permissions you approved, account and selected-business scope, rate-limit events, and audit logs needed to authenticate, authorize, and secure those requests. We do not ask a connected agent to collect passwords, one-time authentication codes, payment-card data, or raw device coordinates. A signed-in customer may deliberately share a fresh device position for a short-lived nearby search by using a Loppee location link. On a supported iPhone, the customer may separately enable “Location for your assistant” with Precise Location and Always access so Loppee can answer a specific request from the customer’s connected agent even when the app is not open. Loppee encrypts the device position and uses it only to apply nearby-business reach for that customer’s agent. The agent receives business results, not the coordinates or exact distance. The position does not become the customer’s saved home location, stops being usable after 15 minutes or 20 searches, and revoked or inactive ciphertext is scrubbed by the location-retention cleanup. The customer can turn off assistant location in Loppee or change iPhone location access in Settings. When OpenAI for ChatGPT, or another supported AI platform, supplies optional approximate location metadata with an individual tool request, Loppee treats it as untrusted, best-effort, request-scoped context. Loppee may use sanitized general-area information only to label an area or disambiguate duplicate literal business names; it does not persist those values or intentionally write them to ordinary application logs, and it never returns raw coordinates to the connected app. This metadata does not authenticate or bind an account, expand plan reach or entitlement, change candidate membership, alter trust or verification, affect quality ranking or commercial ordering, activate Sponsored placement, record an impression, or prove precise location. Precise local discovery for an external agent requires a customer-consented current- or service-destination handoff, or the customer's selection of an opaque saved_exact Home reference. The connected agent receives business results, never the Home or destination address or coordinates.
  • Service-destination address. If you choose to search from a full service address, after you enter four normalized characters Loppee sends partial address text through its server to Google Maps Platform as you type so Loppee can display address suggestions. Loppee does not retain those partial inputs or returned suggestions. When you submit a selected suggestion or manually typed address, Loppee sends that full address from its server to the Google Maps Platform Address Validation API to validate it and derive a geographic point. Loppee does not retain the submitted address. When a nearby-point confirmation is required, Loppee temporarily stores one-way digests that bind the confirmation to the address, customer or browser authority, and provider-derived point, together with an AES-256-GCM-encrypted Google validation-sequence identifier. The identifier is used only server-side to make Google's required follow-up validation request; it is never returned to the browser, app, agent, or listed business. That confirmation can be used once and for no more than two minutes. A used binding and encrypted identifier are deleted atomically when the proof is created; unused or expired confirmation data is removed by scheduled cleanup within about one minute after expiration. Loppee stores the derived point only inside an encrypted location authority usable for no more than 15 minutes or 20 searches; ordinary confirmation- and proof-lifecycle and security records follow the retention rules in Section 6. Later searches use an opaque, short-lived proof identifier and show rounded distance; Loppee does not place the entered address or coordinates in the search URL or return them to connected agents or listed businesses. For addresses in the United States and Puerto Rico, Google may use United States Postal Service data and services to validate the address under its terms. Google's current service-specific terms state that, if an artificially created U.S. or Puerto Rico address is submitted, Google will stop USPS-based validation for Loppee and report to USPS Loppee's name and address as Google's customer (not the end user's Loppee account information), the relevant input address, and aggregated Address Validation API usage data, subject to Google's agreement and USPS security measures. Google's handling of the address is governed by the Google Maps Platform Terms of Service and the Google Privacy Policy.
  • Billing, jobs, and workflow data. Paid business features may involve subscription, invoice, and checkout metadata handled by our payment processor. Viewing or applying for jobs requires an authenticated personal customer account. Publishing or managing a job requires an authenticated business-owner account with appropriate authority. Job applications, resumes, screening responses, customer messages, owner replies, account details, and employer workflow data are stored privately and made available only through scoped account or business access. They are not public registry content and are not authorized for general indexing, crawling, redistribution, or public AI display.
  • Usage & device data. Standard server logs, including IP address, browser/user-agent, pages requested, and timestamps, used for security, abuse prevention, and analytics.
  • Optional public-page analytics. If you choose “Allow analytics” in Cookie preferences, Loppee loads Google Analytics 4 to measure use of public marketing, directory, and business-profile pages. We send a canonical, low-cardinality page category and a limited set of closed interaction categories. We do not intentionally send search terms, typed locations, coordinates, names, email addresses, phone numbers, street addresses, account or business identifiers, message or review contents, application data, URL query strings, or fragments. We do not run this analytics lane on account, owner, administrator, Jobs, application, or OAuth authorization routes.

3. How we use information

  • To provide, maintain, and secure the Services and your account.
  • To verify businesses and publish Trust Cards and directory listings.
  • To operate public agent endpoints, MCP tools, scoped API keys, rate limits, and audit logs.
  • To respond to your requests, claims, and messages.
  • To process billing, subscriptions, job applications, reviews, and owner workflows.
  • To detect, prevent, and investigate fraud, abuse, and security incidents.
  • To comply with legal obligations and enforce our Terms of Service.

4. How information is shared

Published business information (such as Trust Cards and directory listings) is, by design, publicly visible and accessible to people and to AI agents. We also share information with service providers who process data on our behalf (for example, hosting through Render, database and authentication through Supabase, email delivery through Resend/SMTP, payment processing through Stripe, and—only after your optional analytics consent—public-page measurement through Google Analytics), under contracts that require them to protect it. When optional AI-assisted support drafting is enabled, the bounded conversation excerpt needed for a human-requested draft is also sent to the AI provider selected in Loppee's protected control plane, subject to that configured provider account's data-use terms. Third-party AI agents or connector clients may retrieve public registry data when they call public endpoints. We may disclose information if required by law or to protect rights, safety, and the integrity of the Services. We do not sell personal information.

When you deliberately connect a third-party AI app through OAuth, including an app in ChatGPT from OpenAI, the provider may receive the Loppee inputs and outputs needed for the tools you use within the permissions shown on the consent screen. Depending on the connection, that may include public registry data or private, scoped account or selected-business information such as messages, notifications, reviews, and job applications. A connected app may carry out only the actions you approved, and consequential actions require human confirmation. Applicant ranking or employment decisions are not delegated to the app: an authorized human owner must independently choose the exact status before the app can record it. The third-party provider handles the information it receives under its own terms and privacy policy. You can disconnect the app in Loppee to revoke its future access.

The optional service-destination address feature includes Google Maps Platform features and content through address autocomplete while you type and the Address Validation API after you submit. Loppee sends partial address text through its server to Google after four normalized characters and does not retain the partial input or returned suggestions. For addresses in the United States and Puerto Rico, Google may use United States Postal Service data and services for address validation. Google's current service-specific terms state that, if an artificially created U.S. or Puerto Rico address is submitted, Google will stop USPS-based validation for Loppee and report to USPS Loppee's name and address as Google's customer (not the end user's Loppee account information), the relevant input address, and aggregated Address Validation API usage data, subject to Google's agreement and USPS security measures. Use of the feature is subject to the Google Maps Platform Terms of Service and the Google Privacy Policy.

Loppee keeps customer-support conversation egress disabled unless an administrator has separately approved external processing and confirmed that the connected Gemini account receives Google's paid-tier data-use treatment. Google currently states that content on its free tier may be used to improve Google products, while paid-tier content is not used for that purpose. Provider terms can change, so administrators must review Google's current data-use terms before enabling this feature. Credential testing does not include a customer conversation.

5. Cookies & similar technologies

We use a small number of strictly necessary, privacy-preserving cookies and local-storage items to keep you signed in, remember your preferences (including your cookie choice), and operate core features. You may separately choose “Allow analytics” before Google Analytics loads or sends measurement data. Choosing “Essential only” leaves Google Analytics unloaded. You can change or withdraw that choice at any time through the Cookie preferences link in the footer. Withdrawing consent stops future analytics events and Loppee attempts to remove its first-party Google Analytics cookies. We keep Google advertising storage, ad-user data, ad personalization, and Google Signals disabled and do not use advertising or cross-site-tracking cookies. Disabling essential storage in your browser may break sign-in and other core features.

6. Data retention

We retain information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Published business records may persist in the public registry until removed through our business-removal process. Scoped-key audit logs, moderation records, billing records, and security logs may be retained as needed to investigate abuse, prove authorization, resolve disputes, and meet legal or accounting obligations. Loppee's support-copilot control plane retains an immutable hash and authorization receipt for an AI-generated draft, but does not durably store the raw generated draft body in that receipt. A human-sent support message is retained as part of the support conversation under the ordinary message-retention rules. OAuth connection, permission, revocation, and audit records may be retained as needed to prove authorization, enforce revocation, prevent replay, and investigate abuse; disconnecting stops future access but does not erase records we must retain for security, legal, or accounting purposes.

If you allow optional public-page analytics, Google processes the minimized analytics events under our configured Google Analytics retention settings and Google's terms. Withdrawing consent stops future collection from your browser but does not automatically erase aggregate reports or records already retained for the applicable analytics period.

7. Your choices & rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing. To make a request, email info@loppee.com with “Privacy request” in the subject line. Business owners can request changes or removal of a listing through our business-removal request process.

8. Security

We use technical and organizational measures designed to protect information, including transport encryption, access controls, and multi-factor authentication for privileged accounts. No method of transmission or storage is completely secure.

9. Children's privacy

The Services are intended for businesses and adults. Account-based Loppee Services, including Jobs, reviews, messaging, business claims, billing, and connected-application workflows, are not directed to anyone under 18. A person under 18 is not authorized to create or use a Loppee account. If we learn that a minor provided personal information, we will review it and take appropriate action. Contact us if you believe this occurred.

10. Changes to this policy

We may update this policy from time to time. We will revise the "Last updated" date above and, where appropriate, provide additional notice.

11. Contact

Questions or requests: info@loppee.com. Use “Privacy request” in the subject line. Mailing address available on request.