Privacy Policy
Last updated: August 10, 2026
VOILoop ("VOILoop," "we," "us," or "our") provides a managed corporate wellness platform that connects with employer-provided wearable data to support workforce wellness programs. This Privacy Policy explains how we collect, use, and protect information in connection with our website (voiloop.com) and our platform.
This policy is written to cover two different groups of people, because we handle their data differently:
- Employer customers: the companies that engage VOILoop's services.
- Program participants: the employees of our employer customers whose wearable data flows through our platform.
1. Information We Collect
From our website
When you submit the demo request form, we collect your name, work email address, company name, headcount, and anything you tell us about what you're trying to solve. We use this only to respond to your inquiry: we do not sell or share it with third parties for their own marketing purposes.
From program participants (via employer wearable programs)
When an employer engages VOILoop, we receive wearable-derived health and fitness data for enrolled employees, which may include:
- Sleep duration and sleep stages
- Heart rate variability (HRV)
- Recovery scores
- Daily strain / activity levels
- Workout duration and type
This data originates from the employee's wearable device (e.g., WHOOP) and is provided to us either directly by the employer's existing wearable program or by the wearable provider on the employer's behalf, in connection with the employer's wellness program. Enrollment in any wearable data-sharing program is between the employer and the employee; VOILoop does not enroll individuals directly.
2. How We Use Information
We use program participant data to:
- Aggregate and analyze recovery, sleep, HRV, and activity trends at the individual, team, and department level
- Identify individuals who may benefit from additional support ("flagging"), based on thresholds agreed with the employer
- Support the design and measurement of wellness intervention campaigns
- Provide employers with dashboards and reporting described in our service agreement with them
We do not use program participant data for advertising, and we do not sell it to third parties.
3. Who Can See What
- Employers typically see aggregated, department- or team-level data, and individual-level data only to the extent your agreement with us specifies (for example, a Wellness Director reviewing flagged individuals as part of an intervention program).
- VOILoop staff with a legitimate operational need (e.g., data operations, flag verification) can access individual-level data as necessary to run the service.
- We do not share program participant data with unrelated third parties, advertisers, or data brokers.
4. Data Retention
We retain program participant data for the duration of our engagement with the employer, plus 90 days after the engagement ends, to support offboarding and final reporting, unless a shorter period is required by our agreement with the employer or applicable law. After that period, identifiable participant data is deleted; we may retain de-identified, aggregated data for benchmarking purposes.
5. Security
We take reasonable technical and organizational measures to protect data, including access controls limiting who can view individual-level data and encryption of data in transit.
6. Your Rights
Depending on where you live and work, you may have rights to access, correct, or request deletion of your personal data. Program participants should generally direct these requests to their employer in the first instance, as the employer determines enrollment in the wellness program; we will support employers in fulfilling verified requests.
7. Biometric and Health Information Notice
Some of the data we process (such as heart rate variability and recovery scores) may be considered biometric or health-related information under certain state laws. Where applicable law requires specific notices, consents, or retention limits for this category of data (for example, biometric privacy statutes in states such as Illinois, Texas, and Washington), we work with our employer customers to ensure the appropriate notices and consents are obtained at the point of enrollment.
8. Children's Privacy
Our services are intended for use by employees of our employer customers and are not directed at children. We do not knowingly collect data from anyone under 18.
9. Changes to This Policy
We may update this policy from time to time. We will post the updated version here with a new "Last updated" date.
10. Contact Us
Questions about this policy can be directed to: privacy@voiloop.com