Privacy Policy
Last Updated: August 5, 2026
1. Introduction
This Privacy Policy explains how Cardinal Blue Software (“Cardinal Blue”, “we”, “us”, or “our”) handles information when you use Looped, our digital invitations service at loopedinvites.com (the “Service”). By using the Service, you agree to the practices described here.
2. Information We Collect
Looped is an account-based service, so we collect:
- Account information: your email address, first and last name, and phone number. Email and phone are used for one-time sign-in codes, email may be used for event notifications of the events you are attending and phone is also used for SMS event updates.
- Content you create: the events, invitations, and details you build, including dates, locations, images, and text.
- Guest information you provide: the names, emails, and phone numbers of people you invite, used only to deliver invitations and collect RSVPs on your behalf. You are responsible for having the right to share this information with us.
- Technical information: IP address, browser and device information, and usage data, collected automatically for security and to improve the Service.
We rely on the following GDPR legal bases: contractual necessity for account information and content, and legitimate interests for guest and technical information.
3. How We Share Information
We do not sell or rent your personal information. We share it only with service providers that help us operate the Service (such as cloud hosting, email, and SMS providers), and where required by law or to protect our rights, our users, or the public. These providers are contractually required to protect your information and use it only to provide services to us.
4. How We Use Your Information
We use this information to provide and manage your account, create and send invitations and RSVPs, send Service-related communications, keep the Service secure, improve it, and comply with legal obligations.
5. Analytics
We use third-party analytics providers to understand and improve how the Service is used. They may set cookies and collect information such as device identifiers, IP address, and usage activity, governed by their own privacy policies.
6. Email and SMS Communications
We send communications needed to operate the Service: sign-in codes, invitation deliveries, RSVP confirmations, reminders, @mention notifications, event updates posted by a host whose event you responded to, and account and security notices, by email and SMS. Message frequency varies with the events you host or attend. You can opt out of text messages at any time by replying STOP, reply HELP for help, or contact us (Section 11), and we will honor opt-out requests promptly. Standard message and data rates may apply, and carriers are not liable for delayed or undelivered messages. Note that opting out of texts also stops the sign-in codes we send by SMS, so add an email address to your account if you rely on your phone number to sign in.
We do not sell, rent, or share your mobile phone number, or your consent to receive text messages, with third parties or affiliates for their own marketing purposes. We disclose your number only to the messaging providers that deliver these messages on our behalf, and where required by law.
7. Data Retention
We keep your information for as long as your account is active or as needed to provide the Service, and delete or anonymize it after account deletion, except where we must retain it for legal, dispute-resolution, or security reasons. Retention length depends on the type of information and applicable legal requirements.
8. Your Privacy Rights
EEA/UK (GDPR): You have the right to access, correct, delete, restrict, object to, and port your personal data, and to lodge a complaint with your local data protection authority.
California (CCPA/CPRA): You have the right to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell your personal information. You will not be discriminated against for exercising these rights.
To exercise any of these rights, contact us using the details in Section 11.
9. Children’s Privacy
The Service is not directed to children under 13, and account holders must be at least 13 years old. We do not knowingly collect personal information from children under 13 without verifiable parental consent, and will delete any such information if we discover it. We do not knowingly sell or share the personal information of California residents under 16.
10. Data Security and International Transfers
We use commercially reasonable measures, including encryption in transit (TLS), to protect your information, though no method is completely secure. Your information may be stored and processed in the United States, Taiwan, and other countries where Cardinal Blue and its service providers operate. For transfers out of the EEA, UK, or Switzerland, we rely on adequacy decisions where available and otherwise on Standard Contractual Clauses and the UK Data Transfer Addendum.
11. Contact Us
For privacy questions or to exercise your rights, contact us at support@cardinalblue.com with “Looped” in the subject line, or by mail at Cardinal Blue Software, P.O. Box 390677, Mountain View, CA 94039, USA.
