Privacy policy
As of: August 2026
Please note: This is a translation of the German original for your convenience. Only the German version is legally binding.
With this privacy policy we inform you about the processing of personal data when you visit this website (getshoploop.com) and when you use the Shoploop application. We treat your data confidentially and in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller for data processing within the meaning of Article 4 (7) GDPR is:
MH Onlinehandel GmbHHauptstrasse 28, 15806 Zossen, Germany
Email: kontakt@getshoploop.com
For questions about data protection you can reach us at kontakt@getshoploop.com.
2. Hosting and server log files
This website is operated on servers of a hosting provider located in Germany or the European Union. A data processing agreement pursuant to Article 28 GDPR is in place with that provider.
When you access the website, the web server automatically collects so-called server log files that your browser transmits. These are usually:
- anonymized or shortened IP address,
- date and time of access,
- page/file accessed and volume of data transferred,
- notification of successful retrieval (HTTP status code),
- browser type and operating system used,
- referrer URL (previously visited page).
This data is technically necessary in order to deliver the website, to ensure its stability and security and to prevent misuse. The legal basis is Article 6 (1) (f) GDPR (legitimate interest in secure and trouble-free operation). The log files are deleted after a short period, unless they are needed to investigate a specific security incident.
3. Fonts
This website uses the font "Inter", which is embedded locally on our server. There is no connection to third-party servers (e.g. Google Fonts); your IP address is not transmitted to third parties for this purpose.
4. Cookies and tracking
We use our own consent solution with analytics and advertising categories. Your choice applies to getshoploop.com and app.getshoploop.com. You can change your consent at any time with effect for the future using the button in the footer. Processing that has already taken place is not affected by withdrawal.
4.1 Consent settings and our own attribution
The technically necessary cookie shoploop_consent_v1 stores your category selection,
a random consent ID, timestamp and text version for 180 days. Only after advertising consent do we
store only the standard five UTM values and supported click IDs, together with the landing page,
referrer origin, capture time and consent ID, in the first-click cookie
shoploop_attribution_v1 for 90 days. This helps us attribute registrations and
purchases to a campaign. Obvious email addresses, control characters, oversized individual values
and parameter sets that are too large are discarded. Both cookies are set for .getshoploop.com so that the choice
and attribution are also available in the app's signup and payment process. We append click IDs
and UTM values to app links only after advertising consent; within the marketing site, permitted
values remain in the URL without persistent storage.
When consent is withdrawn, we delete browser-visible cookies belonging to the deselected category;
for advertising consent, this also includes the Shoploop attribution cookie.
We also remember the selected website language and whether a demo booking was already counted only for the duration of the current browser tab in Session Storage.
4.2 Google Analytics, Google Ads and Consent Mode v2
We use Google Analytics 4 (measurement ID G-L8EVSJNJ5B) and Google Ads
(tag ID AW-18407527599) from Google Ireland Limited, Gordon House, Barrow Street,
Dublin 4, Ireland. We use them to measure website usage, demo bookings and advertising performance
and, after advertising consent, to create audiences for remarketing.
We use Google's advanced Consent Mode v2. The Google tag is therefore loaded when
the page is opened with consent states set to denied. Until you consent, or if you
reject, Google tags do not read or write analytics or advertising cookies. They may, however, send
cookieless measurement signals to Google. These signals may include the page URL including existing
ad click parameters, referrer, timestamp, user agent, consent state, a page-specific random number
and the IP address technically transmitted when the connection is established. Before configuring
Google, we remove unknown URL parameters, obvious email values, oversized values and parameter sets;
from the referrer we use only the origin. Suspicious or oversized page paths are reduced to the
domain root. Google may use these signals for aggregated measurement and data modelling.
After analytics or advertising consent, Google additionally processes cookie identifiers, usage and event data and campaign information. The legal basis for consent-dependent storage and processing is Article 6 (1) (a) GDPR in conjunction with section 25 (1) TDDDG. Where cookieless signals are transmitted in the rejected state, we rely on Article 6 (1) (f) GDPR and our interest in aggregated reach and conversion measurement. This assessment, and in particular the advanced mode before consent, will be legally reviewed before production use.
If you book a demo after granting advertising consent, we additionally use the email address and,
where available, the text-reminder phone number passed from Calendly to the thank-you page for
enhanced conversions. Both values are normalized in your browser in accordance with Google's
requirements and hashed with SHA-256. Phone numbers are processed only with an international
country code in E.164 format. Our Google tag sends only the hashes as
sha256_email_address and sha256_phone_number, never the plain-text contact
details. The Calendly booking ID is sent as a transaction ID to prevent duplicate conversion
counting. No enhanced user data is sent to Google without advertising consent.
| Storage | Purpose | Typical duration |
|---|---|---|
shoploop_consent_v1 | Evidence and application of your consent settings | 180 days |
shoploop_attribution_v1 | First-click attribution after advertising consent | 90 days |
_ga, _ga_* | Distinguishing users and sessions after analytics consent | up to 2 years by default |
_gcl_* and similar Google advertising storage | Attribution of ad clicks and conversions after advertising consent | depends on Google's settings and conversion window |
For more information, please see Google's information for partner sites and Google's privacy policy.
4.3 Calendly
On the demo pages we immediately load the scheduling service provided by Calendly, LLC,
271 17th St NW, 10th Floor, Atlanta, Georgia 30363, USA, as embedded content. It is loaded
independently of your choice in our consent solution so that appointment booking is directly
usable. Calendly thereby receives at least your IP address and browser, device and access data.
When you book, Calendly also processes the appointment and contact details you enter. We pass only
the five UTM fields supported by Calendly. Unknown parameters such as email or
name, obvious email values, control characters and oversized values are not appended.
Campaign parameters must nevertheless never contain personal data.
After a booking, Calendly appends booking details, including the email address, booking ID, appointment and name details and, where applicable, the text-reminder phone number, to the redirect URL. That URL may initially be processed by the web server and browser. After advertising consent, the thank-you page uses only the email address and a valid international phone number for the local hashing described above and the booking ID for deduplication. It then removes all booking details from the visible URL. Our tracking does not use any other booking details passed by Calendly.
Calendly's own cookie banner is hidden in our embed so that booking an appointment is not interrupted by a second consent prompt. According to Calendly, no non-session persistent cookies are stored for visitors from the EU without their choice; Calendly does still set cookies that are technically required to deliver and secure the service. The legal basis for booking the appointment is Article 6 (1) (b) GDPR and otherwise Article 6 (1) (f) GDPR. Further information and controls can be found in Calendly's privacy notice.
5. Contacting us
If you contact us by email, we process the data you provide (e.g. email address, name, content of your enquiry) in order to handle your request. The legal basis is Article 6 (1) (b) GDPR (pre-contractual measures) or Article 6 (1) (f) GDPR (legitimate interest in responding to enquiries). The data is deleted as soon as it is no longer required to achieve that purpose and no statutory retention obligations prevent deletion.
6. Processing within the Shoploop application
Shoploop is a SaaS platform for optimizing Google Shopping product data and campaigns. The following notes concern processing within an active usage relationship (customer account). The legal basis is Article 6 (1) (b) GDPR (performance of a contract) as well as Article 6 (1) (f) GDPR (legitimate interest in the operation, security and further development of the service).
6.1 Account data
In order to register and manage an account, we process master and contact data (e.g. name, email address, company details) as well as the data required to process payments via our payment service provider.
6.2 Connected Google accounts and data
After your explicit authorization, Shoploop accesses data from your Google accounts through the official Google interfaces in order to provide the service. Depending on the functions you have booked, the following permissions (scopes) are used, predominantly read-only:
- Google Ads (campaign and performance data),
- Google Merchant Center / Content API (product and feed data),
- Google Analytics (read-only),
- Google Search Console (read-only),
- Google Business Profile (management, where booked).
The connection is established via Google's OAuth procedure. The access tokens granted in this process are stored encrypted and are used exclusively to provide the services you have commissioned. Optimizations are delivered through a supplementary feed that you register in your Merchant Center; Shoploop does not make any write changes to your primary feed. You can revoke granted access at any time in your Google account.
7. Google API Services - Limited Use
Shoploop's use of information received from Google APIs, and the transfer of that information to other applications, adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use the data received through Google interfaces exclusively to provide and improve the functions you use. We do not use this data for advertising purposes, we do not sell it and we do not pass it on to third parties, except where this is necessary to provide the service, for security reasons or to comply with legal obligations. Human access to this data only takes place in the exceptional cases permitted by the policy.
8. Processors and services used
To provide our services we work with carefully selected service providers with whom - where necessary - data processing agreements pursuant to Article 28 GDPR are in place:
| Service provider | Purpose |
|---|---|
| Hetzner Online GmbH (DE) | Server hosting of the application, EU data storage |
| Cloudflare, Inc. (US/EU) | Content delivery, DNS, security/DDoS protection |
| Microsoft Ireland Operations Ltd. (Microsoft 365) | Email communication |
| Resend (US) | Sending transactional emails |
| Stripe Payments Europe, Ltd. | Payment processing |
| Google Ireland Ltd. | Google Ads and Analytics on the website and Google services in the app |
| Calendly, LLC (US) | Embedding and handling demo appointment bookings |
| Anthropic, PBC (US) | AI-assisted text and data optimization |
| OpenAI, L.L.C. (US) | AI-assisted text and data optimization |
| Sentry (Functional Software, Inc.) | Error and stability monitoring |
| 1Password (AgileBits Inc.) | Secure management of credentials (internal) |
If a CSS aggregator (Comparison Shopping Service) is integrated for individual functions, we will inform you about this separately. The list is updated as required.
9. Data transfers to third countries
Some of the service providers named above are based in, or process data in, the USA or other third countries. Where no adequacy decision of the EU Commission applies, we base the transfer on appropriate safeguards pursuant to Article 46 GDPR - in particular the EU standard contractual clauses - and, where applicable, on a certification under the EU-US Data Privacy Framework.
10. Storage period
We process personal data only for as long as is necessary for the respective purposes or as statutory retention periods (e.g. under commercial and tax law) require. The data is then deleted or blocked.
11. Your rights
Within the statutory requirements you have the following rights:
- access to the data processed (Article 15 GDPR),
- rectification of inaccurate data (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- objection to processing (Article 21 GDPR),
- withdrawal of consent given, with effect for the future (Article 7 (3) GDPR).
To exercise your rights, a message to kontakt@getshoploop.com is sufficient.
12. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the State Commissioner for Data Protection and the Right to Inspect Files of Brandenburg (LDA Brandenburg). You may also contact the supervisory authority at your usual place of residence.
13. Currency and changes
This privacy policy will be adapted as soon as changes to our processing activities or to the legal framework make this necessary. The version published on this page applies in each case.