The Loop Monster — privacy

Software ShippersBring something worth shipping.Small steps. Real progress. Good company.

Plain-language privacy

Your data, your call.

This notice explains what Software Shippers collects, why it is needed, who receives it, and what you can do about it.

Who is responsible

Rich Steinmetz operates Software Shippers and is responsible for its use of personal data. Email rich@looplabs.cc with privacy questions or requests.

What Software Shippers uses

Your email address verifies your identity, operates your account, manages enrollment and seat offers, and delivers essential account messages. This processing is necessary to provide the service you request under Article 6(1)(b) GDPR. Providing an email address is required to register; profile publication is optional.

If you add them, Software Shippers also stores your name, picture, testimonial, and product links. We use request information such as your IP address, browser details, and request time to prevent abuse, keep the service secure, and diagnose errors. Security and reliability processing is based on our legitimate interests under Article 6(1)(f) GDPR.

Cloudflare Turnstile checks the browser on sign-in forms to prevent automated registrations and unwanted email. Cloudflare receives browser and network information needed for this check; your email is not sent to Turnstile. Short-lived request limits and aggregate security counters support abuse prevention.

Sessions, attendance, transcripts, and analysis

Software Shippers stores the session schedule copied from the cohort’s Google Calendar, including event titles, descriptions, locations, times, facilitator assignments, and Google Meet links. When a session starts, it also records expected attendees, attendance status, arrival time when observed, timer and phase history, pauses, and speaker order. These records operate the cohort and preserve its shared history under Article 6(1)(b) GDPR.

A Facilitator may record a session with Wispr Flow, or the session may be transcribed in Google Meet. Software Shippers displays a recording notice on the session page and may import speaker labels, timestamps, verbatim transcript text, and Wispr Flow summary notes after the session, including the hangout. OpenAI’s Codex may process the transcript, summary notes, and prior analyses from the same cohort to prepare concise participant analysis and a one-sentence trend. A Facilitator reviews the source recording and destination session before confirming the import. A Wispr Flow record does not require Google Meet transcription. The transcript, notes, and analysis are encrypted in the Software Shippers database.

The public homepage shows only a session’s title, time, core-session duration, and a facilitator name when that facilitator has an approved public profile. It may also show that a session is live. Attendees, attendance status, descriptions, locations, Google Meet links, transcripts, summary notes, and session analyses are never published there. Signed-in Active Shippers can view their current cohort’s private session record. Facilitators can view the cohorts they facilitate and sessions assigned to them; Administrators have access across cohorts. Facilitators and Administrators operate session controls and may correct the notes or analysis; Shippers do not edit the transcript. An Administrator can delete the stored transcript together with its notes and analysis.

A Facilitator may import private meeting chat, next-session promises, and directed peer feedback. These records are encrypted and remain within the cohort. A session recap can be rendered for each active member and the Facilitator using their promises, received feedback, attendance, and the next meeting details; rendering does not send the email.

Hosting, access, and service providers

The Software Shippers app, database, and uploaded profile images run on a Hetzner server with the application’s persistent storage. Access is role-based: Administrators manage the service; facilitators operate sessions, review profile publication, and manage Active Shipper promotions; and Active Shippers can view the private session record for their cohort.

We share only the data needed to operate the service with Hetzner for hosting and server backups, Resend for account and enrollment emails, Honeybadger for error monitoring when configured, Google for the Facilitator-owned Calendar and Meet integration, Wispr Flow for Facilitator-controlled recording and summary notes, OpenAI for transcript analysis through Codex, Whop for checkout and payments, and ClickFunnels for contact management, membership tags, and payment eligibility verification. Software Shippers stores the Google OAuth credential needed for that connection in encrypted form. The Google grant permits reading the account’s Calendar list and Meet spaces, and editing attendees on events in calendars the account owns; Software Shippers queries only the selected cohort calendar and Meet links synced from it. Software Shippers’ use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google-derived data is not used for advertising or to train generalized AI models. When configured, Honeybadger receives error reports with your Software Shippers session and the URL that produced the error excluded. After email verification, we send your email, name if supplied, membership status, and session-notification preference to ClickFunnels. Free and paid membership tags follow verified payment eligibility, not your selected checkout option. We match your email to ClickFunnels purchase records to verify eligibility for a cohort seat. The app stores the relevant payment status and when it was checked. Whop handles checkout and payments and reports purchases to ClickFunnels through its native integration. We do not sell registrants’ personal data.

Google, Wispr Flow, OpenAI, Resend, Whop, ClickFunnels, and Honeybadger when configured may process account or service data outside the European Economic Area even where application data is stored in an EU region. Their applicable data-processing terms describe the safeguards used for covered international transfers. Email us to request information about the safeguard that applies to your data.

Public profiles

Your email is never displayed publicly. Your name, picture, testimonial, and product links appear on softwareshippers.com only when you request publication and a facilitator approves it. Profile or product changes return the profile to facilitator review. You can turn publication off at any time. A private profile stays off public pages, but Administrators and your cohort Facilitator can access your profile details and project updates. Your cohort Facilitator may receive product digests with project names and links, including private projects.

Cookies and tracking

Software Shippers uses an encrypted session cookie to keep you signed in and protect account actions. The site does not add advertising cookies. When configured, PostHog measures anonymous normalized page views, selected join interactions, and aggregate enrollment conversions. It does not receive account identities or session contents, and session replay is disabled. Its pseudonymous browser identifier uses local storage; browser Do Not Track disables browser event collection.

Retention and deletion

Aggregate abuse counters expire after 48 hours. Signed Resend delivery notifications are reduced to outcome counts without retaining their recipients or message contents. Deleting a session transcript also deletes its chat, promises, and peer feedback. Deleting an account removes its structured promises and peer feedback; historical text may still name its participants.

Unverified registrations are deleted after 30 days. Verified account and enrollment data remain until you delete your account or Software Shippers no longer needs them to provide the service.

Session schedule and attendance records remain as cohort history. Automatic Google Meet transcript import is attempted for no more than 24 hours; this retry window does not limit a later Facilitator-confirmed Wispr Flow import. An imported or manually added transcript, its summary notes, and its analysis remain until an Administrator deletes that session record. Deleting your account removes the live Software Shippers profile, products, image, and enrollment state; changes linked attendance names to “Former Shipper,” and anonymizes any facilitator label tied to the account. It does not rewrite historical transcript text, notes, or analysis, which may still contain a name or contribution from a session. You may contact us about a specific transcript or other session record.

Deleting a Software Shippers transcript also deletes its stored notes and analysis, but does not delete a source copy held by Google or Wispr Flow. Google, Wispr Flow, OpenAI, and the other service providers apply their own retention rules. Deleted application data may remain in provider backups until the applicable backup copies expire. Contact us for the current backup retention details.

Your rights

You may ask to access, correct, delete, restrict, or receive a portable copy of your personal data. You may object to processing based on legitimate interests and withdraw consent at any time. Email rich@looplabs.cc to exercise these rights. You also have the right to lodge a complaint with the data protection authority responsible for you.

Last updated: 18 September 2026.

The Loop Monster — evidence

Software ShippersShip the next useful thing.Keep the useful bits. Come back with evidence.