Privacy policy
Last updated ·
The controller of LoopClub's personal databases is [LEGAL NAME OR REGISTERED NAME OF THE OPERATOR], established in [OPERATOR'S COUNTRY OF ESTABLISHMENT], with its registered address at [FULL LEGAL ADDRESS], tax identification [CUIT IF APPLICABLE, OR THE OPERATOR'S TAX IDENTIFICATION] and privacy contact hello@loopclub.app. The databases used for the account and the community are identified as [NAME OF THE DATABASES AND REGISTRATION DETAILS WHERE APPLICABLE]. You can also contact us at loopclub.app/contact.
This policy explains how data is processed when you use the website, the app and its community features, in accordance with the Argentine personal data protection framework. Specific information about an identity check will also be given to you before it starts.
What data we collect
We collect the data you provide when you create and complete your account: email address, date of birth, username, display name, neighbourhood, interests, bio and photo, when you add one. We also record your acceptance of the terms, your confirmation that you are of legal age and the status of your email confirmation. Your password is stored as a cryptographic hash, not as readable text.
When you use the community, we process the plans you create, save or join; their place and time details; changes to your participation; recommendations; messages and replies in chats; blocks; reports; and optional reasons for removing participants. We may receive information about an incident when another member reports it.
To manage sessions and security, we process account and session identifiers, access dates, IP address and technical client data recorded during authentication or in the service's systems. Data associated with Didit is explained in the verification section. The required fields are indicated during each process; without them it may not be possible to create an account or use the relevant feature.
How we use your data
We use account and profile data to give you access to LoopClub, show your profile according to the visibility rules, help you find plans by neighbourhood and interests, and manage your participation and chats. We also use it to send access or verification codes and communications needed to run your account.
We process blocks, reports and technical data to prevent misuse, investigate incidents and keep the service secure. Matches by neighbourhood or interests and automatic name filters help organise the experience, but should not be read as judgements about your personality or conduct.
We process your data with your free, express and informed consent, unless an exception in Law 25,326 applies, such as data arising from our contractual relationship that is necessary to carry it out or perform it, or compliance with a legal obligation. The notice for each process must identify [CONSENT OR LEGAL EXCEPTION THAT APPLIES TO EACH PURPOSE]. Service security is not, on its own, a general exception to consent. Reading this policy or accepting the terms does not amount to authorising every processing activity.
Any additional purposes of analytics, advertising or commercial communications, if used, are described in [OPTIONAL PURPOSES THAT ARE ACTUALLY ACTIVE, OR A STATEMENT THAT NONE EXIST], together with their legal basis and controls. We do not reuse data for an incompatible purpose without the information and authorisation that apply.
Identity verification
We use Didit to carry out the identity checks configured for LoopClub. To start a session, we send the provider an internal identifier for your account. The process takes place in its verification environment and may ask for an identity document, a photo or video of your face, and liveness or facial-match checks, depending on the flow shown to you.
LoopClub records the session identifier, its status and the dates related to the verification. It may look up result information to explain an incident or a rejection. That lookup may include the sex or gender marker returned by the provider where it is tied to the eligibility rules. Documents, photos and verification results are not shown to other members; only the relevant badge or profile status is shown.
The notice shown before the process must identify the specific data, the purpose, the recipients, [CONSENT OR LEGAL EXCEPTION FOR VERIFICATION], [CONDITIONS AND SAFEGUARDS FOR BIOMETRIC PROCESSING UNDER ARGENTINE LAW], [ALTERNATIVE AND CONSEQUENCES OF NOT VERIFYING] and [RETENTION PERIOD AT DIDIT]. If the flow includes sensitive data within the meaning of Law 25,326, its specific restrictions apply and a general authorisation is not enough. Didit's privacy information is available at didit.me/terms/privacy-policy and in the specific notice shown during verification.
If an automated check stops you from accessing a feature and you believe it is wrong, you can ask for a review through our privacy contact. Where processing is based on your consent, you can withdraw it; we will explain its effects on the feature that depends on it. Accepting the terms does not replace the specific consent that may be needed.
Location and neighbourhood
We use the neighbourhood you choose to give context to your profile and to plans. Your neighbourhood is not your home address, and you do not need to publish your home address on your profile. Plans may include the name of the venue, its address and coordinates to describe the meeting point or to open an external map.
We do not show your real-time personal location to other members. Do not include a private address in your bio, in a plan or in a chat if you do not want to share it. An address that you add to a plan or a message may be visible to anyone who can access that content.
If a future feature asks for your device's location, it must explain its purpose and ask for the relevant permission before using it. Opening an external map service may mean that provider processes data under its own policy.
Who we share data with
Other members can see the profile information that makes the community possible, such as your username, display name, photo, neighbourhood, interests, bio, verification status and activity data shown in the app. Visibility depends on the feature, the account status and block relationships. A plan's chats are accessible to its participants under the participation rules.
We do not show your email address, password, full date of birth, identity documents or the private reason for a removal to other participants. Reports and private reasons are handled as security information, without prejudice to a legal duty to disclose or the rights of the people concerned. Remember that we cannot stop someone from copying content they can legitimately access.
We use providers for hosting, database, image storage, email delivery and identity verification. The providers and their roles are [LIST OF CONTRACTED PROVIDERS AND THEIR ROLES, INCLUDING DIDIT'S CONTRACTING ENTITY]. Access is limited to what is needed for their service and to the applicable contractual terms. We may disclose information to authorities where there is a valid legal obligation.
Hosting and international access are described in [HOSTING AND ACCESS COUNTRIES, RECIPIENTS AND DATA TRANSFERRED]. Transfers from Argentina are made in accordance with article 12 of Law 25,326 and its supplementary rules. [ARGENTINE MECHANISM THAT ENABLES EACH TRANSFER AND HOW TO CONSULT ITS SAFEGUARDS] must be identified, such as a destination recognised as adequate by the AAIP or the contractual clauses accepted for the case. Using a foreign provider does not remove these obligations. You can ask our privacy contact for information about these safeguards.
How long we keep it
Account and profile data is kept for as long as it is needed to provide the service and manage your relationship with LoopClub. The periods after deletion and the rules for each category are [APPROVED RETENTION PERIODS OR CRITERIA FOR ACCOUNT AND PROFILE], [PLANS AND CHATS], [REPORTS AND BLOCKS], [SECURITY LOGS] and [IDENTITY VERIFICATION].
You can request deletion of your account from Settings. This removes the account from the app's database and affects its related data according to how the service works. Deletion does not mean that all backups, technical logs or data held by providers disappear at the same moment.
Backups are kept for [BACKUP PERIOD AND REPLACEMENT CYCLE]. Deletion of information at Didit and other providers is handled according to [DELETION PROCEDURE AND TIMELINES AT PROVIDERS]. These procedures must respect the legal rights and time limits for erasure; a backup does not allow deleted data to be reused. If there is a legal retention obligation or erasure would harm the rights or legitimate interests of third parties, we will explain the exception that applies and limit the use and the retention period. Anonymised information is outside this policy only if it cannot be linked to an identified or identifiable person.
Your rights
You can contact hello@loopclub.app to ask about your data, correct it or request its deletion. Tell us the account and the right you want to exercise. We will only ask for additional identification when it is necessary and proportionate.
Under Law 25,326, you can access your personal data and request its rectification, updating and, where appropriate, erasure or confidential treatment. Access lets you know what information we hold about you, where it came from and how it is used, without revealing third parties' data. You can withdraw consent under the applicable legal conditions and request removal or blocking of your data from databases used for advertising. If you have a problem with an automated verification, you can ask us for a review through the contact channel.
We will respond to access requests within ten calendar days of receiving them, and will carry out the rectification, updating or erasure that applies within the five business days set by law. If a legal exception to erasure applies, we will explain it to you. While disputed data is under review, the relevant blocking or notice that it is under review will apply. Rectification, updating or erasure of inaccurate or incomplete data is free of charge.
The data subject has the right to exercise the right of access free of charge at intervals of no less than six months, unless a legitimate interest is shown for doing so, as set out in article 14, paragraph 3 of Law 25,326.
The Agency for Access to Public Information (AAIP), as the supervisory authority for Law 25,326, has the power to deal with complaints and claims about breaches of the personal data protection rules. You can find its channels and requirements at argentina.gob.ar/aaip/datospersonales/derechos. If a request is not answered within the legal time limits or the response is insufficient, you can complain to the AAIP or bring the corresponding habeas data action. Keep a record of your request and of its receipt, to prove the breach if needed.
Security
We apply security measures to limit unauthorised access, protect credentials and control use of the service. The app uses hashed passwords, authenticated sessions, authorisation checks and access controls for chats and account features. Security also depends on the configuration of the hosting and of our providers.
No system can guarantee absolute protection. Protect your password, keep your device up to date and do not share verification codes. If you detect suspicious access or an exposure of data, tell us at hello@loopclub.app.
Chats should not be considered end-to-end encrypted. Their processing by the service makes it possible to deliver them to authorised participants and to handle incidents. When a breach requires informing those affected or an authority, we will act in line with the applicable legal obligations.
Cookies
The website and the app may use cookies, local storage and other technologies for technical functions such as keeping your session, remembering your language or telling one installation from another. Their specific use is described in [INVENTORY OF COOKIES AND STORAGE: NAME, PROVIDER, PURPOSE, DURATION AND TYPE]. Session identifiers need protection because they are linked to access to your account.
When these technologies process personal data, the information obligations and the consent or exception rules of Law 25,326 apply. An exception is not presumed just because a technology is called a technical cookie. Those used for analytics, advertising or other optional purposes, if any, are described together with [APPLICABLE CONSENT OR LEGAL EXCEPTION AND CONTROLS TO CHANGE PREFERENCES]. Where consent is needed, they will not be activated before it is obtained and it can be withdrawn using the controls indicated.
You can also manage storage from your browser or device. Clearing it may log you out or reset preferences. An external link, including the Didit environment or a map service, may use its own technologies and must report them separately.
Changes to this policy
We may update this policy when the way data is processed, the providers, the service or the applicable law change. The published version will state its update date.
If a change materially affects the use of your data, we will tell you through a suitable channel before applying it where appropriate. If a new purpose requires consent, we will ask for it specifically; continuing to use the app does not replace that consent.
To see a previous version or ask about a change, contact hello@loopclub.app. We will keep the information about versions and acceptances needed to demonstrate our obligations, in line with the applicable retention criteria.
Questions about this document? Write to us and we will get back to you.