'''Tickets about a gym, club or employer running Loopa.''' The member-facing article is ''Joining an organization'' on the Loopa knowledge base; send members there rather than paraphrasing.
== "My code does not work" ==
Work through these in order.
'''Read the code back.''' Codes never contain '''O, I, L, U, 0 or 1''' — those are the characters that get misread. If the member typed one, they misread something on the poster. Ask what they are looking at.
'''The code may have been retired.''' Organisations issue a new code whenever an old one has travelled further than intended, and the old one stops working the moment they do. Ask the organisation for the current one.
'''Joining may be closed.''' A closed organisation answers exactly as an unknown code does, deliberately — telling a stranger "right code, we are closed" confirms the code is real. Only the organisation can tell you which it is.
'''Rate limiting.''' Thirty attempts an hour per address. Somebody who has been retyping for a while will start getting "we could not check that code just now". It clears on the hour.
'''Do not offer to correct a code for them.''' Loopa deliberately refuses to guess: a repaired mistype can resolve to a ''different'' organisation, and the member has no way to tell it happened.
== "Can my gym see my food log?" ==
'''No, and there is no setting that would let it.''' An organisation sees nine counts about its own members each month — active, Premium, plans shared, plans accepted and so on — and the month. It cannot see which members those are, and nothing anybody logged crosses that boundary.
This is structural rather than a policy: the connection that carries those numbers accepts a fixed list of counts and rejects anything else by name, and a test fails the build if a member identifier is added to it. You can say this plainly.
'''An individual coach is a separate question.''' See ''Handling coach access and consent tickets''. A coach sees only the categories the member switched on, and being in an organisation grants no coach anything.
== "I left and my data is gone" ==
It is not. Leaving switches the app back to Loopa and '''deletes nothing''' — the account with the organisation and everything in it stays exactly where it is, reachable again with the same join code.
What they are most likely seeing is an empty Loopa account, because signing in to Loopa is signing in to a different account from the one they had with their organisation. Confirm which they are looking at before escalating.
== "My organisation left Loopa" ==
Their account and their history are theirs and stay where they are. An organisation that stops working with us takes nothing with it, because it never held their health data.
A suspended organisation stops branding the app, so members will see the Loopa palette again. That is expected, not a fault.
== Escalate ==
- A member who believes an organisation saw something individual about them. Treat as a privacy incident, not a support question.
- A request to change who owns an organisation. Ownership transfers need the new owner to be an identity-verified person and are logged; only Patrick performs them.
- Anybody asking for a member list, an export of members, or "just the emails" from an organisation. There is no such export, because there is no such data — and the ask is worth recording.
'''Tickets about a gym, club or employer running Loopa.''' The member-facing article is ''Joining an organization'' on the Loopa knowledge base; send members there rather than paraphrasing. == "My code does not work" == Work through these in order. # '''Read the code back.''' Codes never contain '''O, I, L, U, 0 or 1''' — those are the characters that get misread. If the member typed one, they misread something on the poster. Ask what they are looking at. # '''The code may have been retired.''' Organisations issue a new code whenever an old one has travelled further than intended, and the old one stops working the moment they do. Ask the organisation for the current one. # '''Joining may be closed.''' A closed organisation answers exactly as an unknown code does, deliberately — telling a stranger "right code, we are closed" confirms the code is real. Only the organisation can tell you which it is. # '''Rate limiting.''' Thirty attempts an hour per address. Somebody who has been retyping for a while will start getting "we could not check that code just now". It clears on the hour. '''Do not offer to correct a code for them.''' Loopa deliberately refuses to guess: a repaired mistype can resolve to a ''different'' organisation, and the member has no way to tell it happened. == "Can my gym see my food log?" == '''No, and there is no setting that would let it.''' An organisation sees nine counts about its own members each month — active, Premium, plans shared, plans accepted and so on — and the month. It cannot see which members those are, and nothing anybody logged crosses that boundary. This is structural rather than a policy: the connection that carries those numbers accepts a fixed list of counts and rejects anything else by name, and a test fails the build if a member identifier is added to it. You can say this plainly. '''An individual coach is a separate question.''' See ''Handling coach access and consent tickets''. A coach sees only the categories the member switched on, and being in an organisation grants no coach anything. == "I left and my data is gone" == It is not. Leaving switches the app back to Loopa and '''deletes nothing''' — the account with the organisation and everything in it stays exactly where it is, reachable again with the same join code. What they are most likely seeing is an empty Loopa account, because signing in to Loopa is signing in to a different account from the one they had with their organisation. Confirm which they are looking at before escalating. == "My organisation left Loopa" == Their account and their history are theirs and stay where they are. An organisation that stops working with us takes nothing with it, because it never held their health data. A suspended organisation stops branding the app, so members will see the Loopa palette again. That is expected, not a fault. == Escalate == * A member who believes an organisation saw something individual about them. Treat as a privacy incident, not a support question. * A request to change who owns an organisation. Ownership transfers need the new owner to be an identity-verified person and are logged; only Patrick performs them. * Anybody asking for a member list, an export of members, or "just the emails" from an organisation. There is no such export, because there is no such data — and the ask is worth recording.