Privacy Policy
Last updated October 8, 2026
This policy explains what we collect when you visit the Headroom website or use Headroom, and what we do with it. Headroom is a staffing board sold to agencies (our "customers") and used by their teams.
Who we are
Headroom is a product of LOOP AI: Travis Mahoney, a sole proprietor doing business as LOOP AI ("we", "us").
Contact: support@teamheadroom.com. LOOP AI, 1875 Mission St Ste 103 #842, San Francisco, CA 94103
Two kinds of data, two roles
- Workspace data is what an agency puts into Headroom: the people on its board, projects, deliverables and time off. The agency controls it, and we process it on the agency's behalf as its service provider. Questions about it are best sent to your agency; we will help them answer.
- Account, billing and website data is information we decide how to use, as described below.
What we collect
Accounts
Your name, email address and profile image from your sign-in method (Google, Microsoft or an email link), and your role in each workspace.
Workspace data
Names, work email addresses, job titles, and country and state or region of the people on the board (used for public holidays); projects and client names; deliverables, due dates and load levels (Very Heavy to Low); and time off as a date plus "full day" or "half day".
We deliberately do not collect reasons for time off, hours worked, pay or rates, or performance reviews. Please do not put health or medical-leave information anywhere in Headroom.
HubSpot, if your agency connects it (once the sync ships)
The deal details needed to create and update projects (deal name, pipeline and stage), and access tokens, which will be stored encrypted. You will be able to disconnect at any time.
Billing
Payments are handled by Stripe. We receive your plan, billing status and billing contact, not full card numbers.
Website, logs and analytics
Server logs (IP address, browser, pages requested, errors) for security and debugging. If we adopt a product analytics tool, it will record usage events such as "import completed" to see where people get stuck.
Free template
The free template is a straight download. We do not ask for your email address, and downloading it does not sign you up for any email.
How we use it
- To run Headroom: sign-in, the board, the Monday digest, trial and billing notices.
- To keep it secure: rate limits, abuse prevention, audit logs, error reports.
- To support you when you ask for help.
- To improve the product, from usage events and aggregated statistics.
We do not sell or rent personal information, and we do not share it for cross-site advertising.
Service providers
These providers help us run Headroom. Status shows which are in use today. Each gets only the data its job needs, under its own data processing terms, and we keep this list current.
Vercel
- What for
- Hosting the app and this website
- Data
- All app traffic; request logs
- Status
- At launch
Neon
- What for
- Database
- Data
- Account and workspace data
- Status
- At launch
Clerk
- What for
- Sign-in and team invitations
- Data
- Name, email, sign-in method, profile image
- Status
- At launch
Stripe
- What for
- Payments and billing
- Data
- Billing contact, payment details (held by Stripe)
- Status
- At launch
Postmark
- What for
- Product email (Monday digest, trial notices)
- Data
- Name, email, email content
- Status
- At launch
Cloudflare R2
- What for
- Import files and encrypted backups
- Data
- Uploaded spreadsheets, backups
- Status
- Planned, if adopted
Inngest
- What for
- Scheduled jobs (digest, snapshots, billing notices)
- Data
- Workspace identifiers
- Status
- At launch
Upstash
- What for
- Rate limiting
- Data
- IP addresses, user and workspace identifiers, hashed email addresses
- Status
- At launch
Sentry
- What for
- Error reports
- Data
- Technical data, workspace identifiers (no names or emails)
- Status
- Planned, if adopted
PostHog
- What for
- Product analytics
- Data
- Usage events, device data
- Status
- Planned, if adopted
| Provider | What for | Data | Status |
|---|---|---|---|
| Vercel | Hosting the app and this website | All app traffic; request logs | At launch |
| Neon | Database | Account and workspace data | At launch |
| Clerk | Sign-in and team invitations | Name, email, sign-in method, profile image | At launch |
| Stripe | Payments and billing | Billing contact, payment details (held by Stripe) | At launch |
| Postmark | Product email (Monday digest, trial notices) | Name, email, email content | At launch |
| Cloudflare R2 | Import files and encrypted backups | Uploaded spreadsheets, backups | Planned, if adopted |
| Inngest | Scheduled jobs (digest, snapshots, billing notices) | Workspace identifiers | At launch |
| Upstash | Rate limiting | IP addresses, user and workspace identifiers, hashed email addresses | At launch |
| Sentry | Error reports | Technical data, workspace identifiers (no names or emails) | Planned, if adopted |
| PostHog | Product analytics | Usage events, device data | Planned, if adopted |
Where data lives
Headroom is offered to US businesses, and data is stored in the United States.
How long we keep it
- Workspace data: while the subscription is active. Deleted items can be restored for 30 days.
- A deleted workspace is purged 30 days after deletion.
- An expired trial becomes read-only, gets email reminders, and is purged after 90 days.
- Backups will be encrypted and kept for 30 days, so purged data will leave the backups within 30 more days.
Security
Data is encrypted in transit. Each agency's data is kept separate by the database itself (row-level security), integration tokens will be encrypted once integrations exist, and staff access is limited to what support needs.
Your choices and rights
- Agency owners and admins can export their workspace at any time. Owners can ask us to delete it.
- You can ask us to access, correct or delete personal information we control.
Children
Headroom is a business tool and is not meant for anyone under 16.
Changes
We will post changes here and, for material changes, email workspace owners before they take effect.