Privacy, without the fog.
This notice explains what Markloop collects, why it is needed, who processes it, and the choices available to account users and website reviewers.
1. Who is responsible for your data
Markloop is operated by Pranesh Ramamurthy, sole proprietor trading as Markloop, based in Chennai, Tamil Nadu, India.
Markloop acts as the data fiduciary or controller for account registration, authentication, billing, security, support, legal compliance, and consented product analytics. For feedback, screenshots, technical logs, and other content collected through a customer's website, the relevant workspace ordinarily determines why that data is collected and Markloop processes it as its service provider. Requests about that content may therefore need to be handled with the workspace owner.
2. Data we collect
- Account and workspace data: name, email, profile image, Google or Supabase authentication identifiers, memberships, roles, allowed domains, workspace settings, login and audit history.
- Feedback data: reviewer name, comments, replies, issue type, teams, status, priority, page URL and title, element label and selector, click position, viewport, device pixel ratio, browser language, platform and user agent.
- Visual and technical context: viewport screenshots, target rectangles, console warnings or errors, and failed-network request metadata. Customers control whether relevant premium capture features are enabled.
- Billing data: plan, subscription state, invoices, payment identifiers and billing events. Razorpay handles payment instruments; Markloop does not store complete card, bank, UPI credential, or payment-instrument data.
- Integration and AI data: Figma connection details, selected frame metadata and images, live-page captures, QA prompts, findings and provider status when a user deliberately invokes those features.
- Support and usage data: grievance correspondence, diagnostic logs, security events, consent choices and, only after opt-in, limited PostHog analytics.
The reviewer snippet stores the reviewer name in local browser storage so it does not have to be entered repeatedly. Essential authentication and security cookies are used to maintain signed-in sessions.
3. Why we process data
We process data to provide the service requested by you or a workspace, perform our contract, authenticate users, collect and display contextual feedback, manage projects, process subscriptions, enforce quotas, prevent abuse, secure and troubleshoot Markloop, answer support requests, comply with law, and establish or defend legal claims.
Optional analytics is processed only after consent. AI and Figma content is processed only when an authorized user starts the relevant integration or QA operation. Withdrawing optional consent does not affect processing that is necessary to provide an existing contract or comply with law.
4. Service providers and disclosures
Depending on enabled features, data may be processed by Vercel for hosting, Supabase for authentication/database/storage, Google for sign-in, Razorpay for payments, PostHog for consented analytics, Figma for connected design files, and the configured OpenAI, Anthropic, or Google AI API provider for requested QA analysis.
We disclose only what is reasonably necessary to operate the requested feature, comply with binding legal process, investigate abuse or protect rights and safety. We do not sell personal data. Customer screenshots, comments, and files are not used to train Markloop or third-party AI models without a separate explicit opt-in.
5. International processing
Some providers may process or store data outside India. We use reputable providers and available contractual, access-control, encryption, and transfer safeguards. We do not promise that all data remains in India. A workspace must assess whether its own regulated or client data may be transferred through Markloop.
6. Retention and deletion
- Active workspace content is retained while needed to provide the service or until an authorized user deletes it.
- Following a validated account-deletion request, customer content is scheduled for removal from active systems within 30 days.
- Residual encrypted backup copies expire through ordinary backup rotation within 90 days.
- Security and access logs may be retained for 180 days, or longer when necessary for an active investigation or legal requirement.
- Invoices, subscription events, tax and accounting records are retained for the period required by applicable law.
Deletion may be delayed where data must be preserved for fraud prevention, disputes, legal holds, or compliance. De-identified aggregate statistics that cannot reasonably identify a person may be retained.
7. Your choices and rights
Subject to applicable law and verification, you may request information about processing, access, correction, completion, erasure, withdrawal of consent, grievance redressal, or nomination of another person to exercise rights in the event of death or incapacity.
Analytics consent can be changed through the Cookie settings control in the footer. Workspace-controlled feedback requests should first be sent to that workspace; Markloop will reasonably assist it. Send other requests to support@themarkloop.com. We may ask for information necessary to verify identity and authority.
8. Security and incidents
We use access controls, workspace isolation, private object storage, signed URLs, encrypted transport, secret separation, rate limits, audit records and third-party infrastructure safeguards appropriate to the service. No internet service can guarantee absolute security.
When a personal-data breach requires notification, we will notify affected parties and relevant authorities in the form and timeframe required by applicable law. Customers must promptly tell us about suspected misuse of their workspace or reviewer links.
9. Children
Markloop accounts and dashboard access are intended only for people aged 18 or older. The service is not designed to knowingly process children's personal data. Contact us if you believe a child's data has been submitted so we can investigate and take appropriate action.
10. Changes and grievances
We may update this policy to reflect changes in law, providers, or product behavior. Material changes will receive prominent notice and fresh consent where required. The version and effective date appear on this page.
Grievance Officer: Pranesh Ramamurthy
Email: support@themarkloop.com
Phone: +91 90803 70407
We aim to acknowledge grievances within 48 hours and resolve them within one month. You may also pursue remedies available from the Data Protection Board of India or another competent authority when applicable.
