Skip to content

Privacy Policy

Last updated October 8, 2026

This policy explains what we collect when you visit the Headroom website or use Headroom, and what we do with it. Headroom is a staffing board sold to agencies (our "customers") and used by their teams.

Who we are

Headroom is a product of LOOP AI: Travis Mahoney, a sole proprietor doing business as LOOP AI ("we", "us").

Contact: support@teamheadroom.com. LOOP AI, 1875 Mission St Ste 103 #842, San Francisco, CA 94103

Two kinds of data, two roles

  • Workspace data is what an agency puts into Headroom: the people on its board, projects, deliverables and time off. The agency controls it, and we process it on the agency's behalf as its service provider. Questions about it are best sent to your agency; we will help them answer.
  • Account, billing and website data is information we decide how to use, as described below.

What we collect

Accounts

Your name, email address and profile image from your sign-in method (Google, Microsoft or an email link), and your role in each workspace.

Workspace data

Names, work email addresses, job titles, and country and state or region of the people on the board (used for public holidays); projects and client names; deliverables, due dates and load levels (Very Heavy to Low); and time off as a date plus "full day" or "half day".

We deliberately do not collect reasons for time off, hours worked, pay or rates, or performance reviews. Please do not put health or medical-leave information anywhere in Headroom.

HubSpot, if your agency connects it (once the sync ships)

The deal details needed to create and update projects (deal name, pipeline and stage), and access tokens, which will be stored encrypted. You will be able to disconnect at any time.

Billing

Payments are handled by Stripe. We receive your plan, billing status and billing contact, not full card numbers.

Website, logs and analytics

Server logs (IP address, browser, pages requested, errors) for security and debugging. If we adopt a product analytics tool, it will record usage events such as "import completed" to see where people get stuck.

Free template

The free template is a straight download. We do not ask for your email address, and downloading it does not sign you up for any email.

How we use it

  • To run Headroom: sign-in, the board, the Monday digest, trial and billing notices.
  • To keep it secure: rate limits, abuse prevention, audit logs, error reports.
  • To support you when you ask for help.
  • To improve the product, from usage events and aggregated statistics.

We do not sell or rent personal information, and we do not share it for cross-site advertising.

Service providers

These providers help us run Headroom. Status shows which are in use today. Each gets only the data its job needs, under its own data processing terms, and we keep this list current.

Vercel

What for
Hosting the app and this website
Data
All app traffic; request logs
Status
At launch

Neon

What for
Database
Data
Account and workspace data
Status
At launch

Clerk

What for
Sign-in and team invitations
Data
Name, email, sign-in method, profile image
Status
At launch

Stripe

What for
Payments and billing
Data
Billing contact, payment details (held by Stripe)
Status
At launch

Postmark

What for
Product email (Monday digest, trial notices)
Data
Name, email, email content
Status
At launch

Cloudflare R2

What for
Import files and encrypted backups
Data
Uploaded spreadsheets, backups
Status
Planned, if adopted

Inngest

What for
Scheduled jobs (digest, snapshots, billing notices)
Data
Workspace identifiers
Status
At launch

Upstash

What for
Rate limiting
Data
IP addresses, user and workspace identifiers, hashed email addresses
Status
At launch

Sentry

What for
Error reports
Data
Technical data, workspace identifiers (no names or emails)
Status
Planned, if adopted

PostHog

What for
Product analytics
Data
Usage events, device data
Status
Planned, if adopted

Where data lives

Headroom is offered to US businesses, and data is stored in the United States.

How long we keep it

  • Workspace data: while the subscription is active. Deleted items can be restored for 30 days.
  • A deleted workspace is purged 30 days after deletion.
  • An expired trial becomes read-only, gets email reminders, and is purged after 90 days.
  • Backups will be encrypted and kept for 30 days, so purged data will leave the backups within 30 more days.

Security

Data is encrypted in transit. Each agency's data is kept separate by the database itself (row-level security), integration tokens will be encrypted once integrations exist, and staff access is limited to what support needs.

Your choices and rights

  • Agency owners and admins can export their workspace at any time. Owners can ask us to delete it.
  • You can ask us to access, correct or delete personal information we control.

Children

Headroom is a business tool and is not meant for anyone under 16.

Changes

We will post changes here and, for material changes, email workspace owners before they take effect.