Textloop

Privacy Policy

Last updated: August 2026

Textloop ("Textloop", "we", "us") is an SMS marketing and cart-recovery app for OpoShop stores, published by Found. This policy explains what data we handle and how. Textloop is a tool merchants use to message their own subscribers; the merchant (store owner) is the data controller for their subscribers, and Textloop acts as a processor on their behalf.

Who this covers

Two groups: (1) merchants who install Textloop on their OpoShop store, and (2) subscribers — shoppers who opt in to receive text messages from a merchant's store.

Merchant store data (via OAuth)

When a merchant connects their store, OpoShop grants Textloop a store-scoped access token. We use it only to read the store's orders and identity to (a) enrich subscriber segments with order history, (b) power abandoned-checkout and shipping-update automations, and (c) manage our own webhook subscriptions. We request least-privilege scopes (orders:read, users:read, webhooks). We never write to the store.

Subscriber data (SMS)

For subscribers, we store the phone number (in E.164 form), the consent record proving opt-in (source, timestamp, IP address, and the exact disclosure text shown), an optional first name/email captured at opt-in, and a delivery ledger of messages sent (status, cost in segments). We keep this because retaining proof of consent is a legal requirement (TCPA). We do not sell, rent, or share subscriber data with third parties, and we do not use it for any purpose other than delivering the merchant's messages.

Consent, STOP, and quiet hours

A marketing text is only ever sent to a phone number with a recorded opt-in. A subscriber can opt out at any time by replying STOP (also UNSUBSCRIBE, CANCEL, END, QUIT); that number is suppressed permanently until they text START. Replying HELP returns help information. Marketing messages are only sent during the merchant's configured local quiet-hours window.

Message delivery (Twilio)

Messages are delivered through the merchant's own Twilio account. The merchant's Twilio Auth Token is stored encrypted at rest (AES-256-GCM) and is only ever transmitted to Twilio to authorize a send — never returned to any browser or written to logs. Twilio processes the message content and phone number to deliver it; see Twilio's privacy policy.

Payment data

Textloop does not collect or store card or bank data. The merchant pays Twilio directly for message delivery; Textloop does not bill for SMS.

Analytics

We collect privacy-preserving product analytics (via PostHog) keyed by an anonymous store identifier. These events contain no personal information — no phone numbers, names, or message content.

Data storage & retention

Data is stored per-store in our own database, isolated so one store can never see another's data. Consent and send records are retained while the store is active (and as long as needed to evidence consent). When a merchant uninstalls, we mark the store inactive and stop all processing; a merchant may request deletion of their store's data by emailing us.

Your rights

Merchants and subscribers may request access to, correction of, or deletion of their data by contacting brandon@tryfound.io. Subscribers can also self-serve removal by replying STOP.

Contact

Questions about this policy: brandon@tryfound.io (Found).