Privacy as a system.
Not a policy PDF.

Trueloops's product is trust: verified purchases, consented data, provable outcomes. So privacy and security aren't a compliance chapter — they're load-bearing architecture, operated from Frankfurt under European law.

Privacy engineering

Consent travels with the data.

Recorded basis, always

Every datum is stored with its legal basis and the purposes the person agreed to. Purpose-aware routing means data never flows to a destination the consent doesn't cover.

Deletion that propagates

Withdraw consent and the deletion cascades across modules — profile, purchases, derived insights. The right to be forgotten, implemented as an event, not a ticket.

Data minimalism

Progressive profiling asks only what the campaign needs, when it needs it. Audit records deliberately exclude payloads, so receipts of actions never duplicate personal data.

EU residency

Hosted in Germany, operated from Frankfurt am Main. Your consumers' data is governed by the GDPR and stays in the European Union.

Portability by design

Full export of the fallback store at any time; consent-aware delivery to your own systems as data is collected. Leaving Trueloops is a supported operation — which is exactly why you won't need to.

Honest AI use

AI reads receipt images and scores its own confidence; low confidence routes to human review, never to a silent auto-approval. Your data is processed to run your campaigns — not to train models.

Security

Engineered controls, not promises.

Access control

Per-workspace roles (owner, admin, user, read-only) with per-capability permissions; a separate staff layer above workspaces; privileged actions require explicit confirmation. Nobody accumulates quiet superpowers.

Hardened sign-in

One-time invite links, modern password hashing, per-account and per-address rate limits, revocable server-side sessions, and password resets that sign out every device.

Audit receipts

Every tool call, sign-in, invite and payout release is written to an append-only audit trail — including the denied attempts. Evidence first.

Fraud defense

Duplicate receipts caught at image and content level, per-person velocity limits, automatic payout holds with human review. The immune system covers the whole loop.

Exactly-once payouts

Reward issuance is idempotent by construction — retries, refreshes and race conditions cannot double-pay. Money-grade discipline on every reward.

Certification roadmap

SOC 2 and ISO 27001 certification are on our compliance roadmap, advancing with enterprise rollouts. Security reviews with your team are welcome today.

Trust FAQ

What your DPO will ask.

Where is Trueloops hosted?

In Germany, operated from Frankfurt am Main by Cocomore AG. Data stays in the European Union.

Is Trueloops's AI trained on our customer data?

No. AI is used to read receipt images at verification time; your data is processed to run your campaigns, not to train models. Uncertain extractions go to your human review queue.

Can we delete a consumer's data completely?

Yes — that path is engineered, not manual. A consent withdrawal or deletion request propagates across every module that holds the person's data, including derived profiles and insights.

Are you SOC 2 or ISO 27001 certified?

Certification (SOC 2 and ISO 27001) is on our compliance roadmap and progresses with our enterprise rollouts. The underlying engineering controls — encryption, role-based access, audit trails, least-privilege operations — are in the platform today, and we're happy to walk your security team through them.

What does 'no lock-in' actually mean?

Three concrete things: your data routes to your own CDP/CRM as it's collected; whatever sits in our fallback store is visible and exportable in full at any time; and campaigns are headless definitions, so switching surfaces never means rebuilding content.

Website-specific privacy information lives in our privacy policy; the legal entity behind Trueloops is in the imprint.

Bring your security questionnaire.

We’ll answer it line by line — and show you the audit trail, consent lifecycle and fraud defense live in the product.

Book a demo