Without SourceLoop
UntaggedKayden Floyd
- SourceUnknown
- MediumUnknown
- CampaignUnknown
- Landing pageUnknown
Security
SourceLoop holds the data connecting your marketing spend to your customers: who visited, who converted, and what they were worth. This page sets out how that is protected, and links the documents your security team will ask for.
Last updated: August 18, 2026
Compliance
Where a mechanism is in place we say so and link the document. Where an audit is still running we say that instead, because an attestation you cannot read is not evidence.
You are the controller, we are the processor. Our pre-signed DPA sets out the processing, the legal bases you rely on, our assistance with data subject rights, and 72-hour breach notification.
The 2021 SCCs are incorporated into the DPA for transfers out of the EEA, with the module and annexes already completed.
The UK International Data Transfer Addendum is incorporated alongside the SCCs, so UK customers do not need a separate agreement.
The SCCs apply with the Swiss modifications, naming the Federal Data Protection and Information Commissioner as the competent authority.
We act as a service provider. We do not sell or share personal information, and we support access, deletion, correction, and opt-out requests.
An independent SOC 2 Type 1 audit is underway. We will publish the report and letter of attestation under NDA once it completes.
How we protect it
Every measure below is written into Annex 2 of our Data Processing Addendum, so it is an obligation we owe you rather than a claim on a marketing page.
Data is encrypted in transit with TLS 1.2 or higher between your site, the application, and our storage. Data at rest is encrypted with AES-256 or stronger.
Role-based controls limit access to personnel with a legitimate need. Multi-factor authentication is required for all production access, and access is reviewed at least quarterly.
Production runs in private networks behind a web application firewall with DDoS protection. Hosts are hardened, patched on defined timelines, and monitored for intrusion.
A documented SSDLC with peer code review, automated static and dynamic testing, dependency-vulnerability scanning, and regular penetration testing by an independent third party.
Application, audit, and access logs are centrally collected, retained, and monitored for anomalies. Alerts trigger an on-call response process.
Backups run on a defined schedule, encrypted and stored in a separate region. Recovery objectives are documented and tested rather than assumed.
Personnel undergo background checks where permitted by law, sign confidentiality agreements, and complete security and privacy training annually.
A documented plan covering detection, containment, eradication, recovery, and post-incident review. We notify affected customers within 72 hours of confirming a breach.
Sub-processors are vetted for security and bound to obligations no less protective than our own DPA. We remain liable for their acts as if they were ours.
Customer data is stored in the United States, in established cloud data centres with physical access controls, environmental safeguards, and 24/7 monitoring.
Your data, your control
For the data captured by the SourceLoop snippet on your website, you decide what is collected and why. We process it on your documented instructions and nothing else. We do not sell personal information, we do not use your data to train models, and we do not use it to advertise our own or anyone else's products.
Documents
Responsible disclosure
We work with the security research community and welcome reports of potential vulnerabilities. Report in good faith, avoid privacy violations and service degradation, and give us reasonable time to fix the issue before disclosing it. We will not pursue legal action against researchers who follow that.
FAQ
In transit with TLS 1.2 or higher between your properties, our application, and our storage. At rest with AES-256 or stronger, including backups. These are contractual commitments in Annex 2 of our Data Processing Addendum, not marketing statements.
Customer data is stored in the United States, in established cloud data centres operated by our infrastructure sub-processors. A small number of ancillary sub-processors, such as our transactional email provider, operate in the European Union; each vendor's processing location is listed on our sub-processors page. Transfers are covered by the Standard Contractual Clauses and, for UK customers, the International Data Transfer Addendum, both incorporated into our DPA. If you have a specific residency requirement, contact us before you sign so we can confirm what is possible.
Our DPA is pre-signed and published, so there is usually nothing to negotiate. It incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, names our sub-processors, and sets out our technical and organizational measures in Annex 2.
We notify affected customers without undue delay and within 72 hours of confirming a personal data breach, with the nature of the breach, the categories and approximate volume of data affected, likely consequences, and the steps taken. That commitment is in Section 9 of the DPA.
Each one is vetted before engagement and contractually bound to protections no less strict than our own DPA, and we stay liable for their actions. We publish the current list, give at least 30 days notice before adding a new sub-processor, and you have the right to object on reasonable data-protection grounds.
At your choice we delete or return your data after the agreement ends, and delete remaining copies except where law requires retention. You can also request deletion at any time during the term through our data deletion process.
Yes. Most questions are answered by this page, the DPA, and the sub-processors list, which is usually faster for both of us. If your team needs a specific questionnaire completed or has questions under NDA, email [email protected].
Capture and send full attribution data from every signup, lead, booking, and sale to your CRM and ad platforms, so you know exactly what's driving revenue.
Without SourceLoop
UntaggedKayden Floyd
With SourceLoop
Auto-taggedKayden Floyd