Snapshot 42305
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Home Trust Center Trust Center Popupsmart runs on your visitors' pages, so the way we handle data is part of the product. This page collects what we process, where it lives, who we share it with, and the rights you can exercise — with a link to the document behind every claim. Last reviewed: 10 September 2026 Regulatory frameworks The privacy regimes we process personal data under, each backed by a document you can read in full. GDPR GDPRRegulation (EU) 2016/679. Popupsmart acts as processor on your documented instructions under a signed DPA. CCPA CCPACalifornia residents can access, delete, and opt out of the sale or sharing of personal information. DPA Data Processing AddendumForms part of the Terms of Use. Defines roles, scope, sub-processors, transfers, and breach handling. SCC Standard Contractual ClausesEU Commission-approved clauses cover personal data transferred outside the EEA. To be explicit about what is not here: Popupsmart is not currently SOC 2, ISO 27001 or HIPAA certified, and we do not display seals we have not earned. The infrastructure we build on — AWS, Microsoft Azure, Stripe, Cloudflare — carries its own independent certifications, but those are the providers' and we do not claim them as ours. If a certification is a requirement for your review, tell us and we will say plainly where we stand. At a glance Primary hosting AWS · Microsoft Azure Application data is hosted in EU regions — AWS in Dublin, Ireland and Azure North Europe. Site delivery Vercel · Cloudflare popupsmart.com is a statically exported site served through Vercel and Cloudflare's CDN. In transit HTTPS/TLS on every surface Payments Handled by Stripe Card details go to Stripe directly. Full card numbers are never stored on Popupsmart infrastructure. Form protection Cloudflare Turnstile Every public form runs invisible bot verification before a submission is accepted. Privacy contact [email protected] Documents & resources Everything we publish is linked directly — no form, no gate. The rest is a short email away. Privacy PolicyWhat we collect, why we collect it, how long we keep it, and the rights you can exercise.Read Data Processing AddendumThe processor terms that govern personal data you submit through the Service, including SCCs.Read Sub-processor listEvery third party that processes data on our behalf, with its processing location and purpose.Read CCPA ComplianceHow Popupsmart meets the California Consumer Privacy Act and what California residents can request.Read Do Not Sell My Personal InformationThe opt-out form for the sale or sharing of personal information under CCPA.Read Terms of UseThe agreement between you and Popupsmart Inc., which the DPA forms part of.Read Security overview for vendor reviewA written summary of our technical and organizational measures, sized for a procurement questionnaire.Available on request Counter-signed DPANeed the DPA executed against your entity rather than accepted through the Terms? Ask and we will sign.Available on request Security controls Reviewed September 2026 The technical and organizational measures set out in section 5 of our DPA, grouped by area. Open a card to see every control in that group. Compliance & privacy GDPR — processor role defined in writing CCPA rights honoured Data Processing Addendum in force +2 See all controls We process personal data as a processor acting on your documented instructions, under terms that form part of the Terms of Use. GDPR — processor role defined in writingYou are the controller and determine purposes and means; Popupsmart processes only on your documented instructions. CCPA rights honouredCalifornia residents can access, delete, and opt out of the sale or sharing of their personal information. Data Processing Addendum in forceThe DPA forms part of the Terms of Use, so it applies without a separate negotiation. Standard Contractual Clauses for transfersWhere personal data leaves the EEA, EU Commission-approved SCCs or another lawful mechanism applies. Purpose limitationPersonal data submitted through the Service is processed for providing that Service, not repurposed. Read the Data Processing Addendum Data security Encryption in transit Network and infrastructure security Data minimisation +1 See all controls Measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure. Encryption in transitTraffic between browsers and our services runs over HTTPS/TLS; plaintext requests are redirected. Network and infrastructure securityServices run inside the security boundaries of our cloud providers rather than self-managed hardware. Data minimisationWe collect the data needed to operate the Service and campaigns you configure — not more. Private form storageForm submissions from popupsmart.com are written to private object storage, not a public bucket. Access control Access controls and least privilege Confidentiality obligations Access reviewed on role change See all controls Access to systems holding personal data is restricted and granted on a least-privilege basis. Access controls and least privilegeStaff receive the minimum access their role requires, and no more. Confidentiality obligationsEveryone authorised to process personal data is bound by contractual or statutory confidentiality. Access reviewed on role changeAccess is revisited when someone changes role and revoked when they leave. Infrastructure AWS — Dublin, Ireland (EU region) Microsoft Azure — North Europe Vercel — marketing site delivery +1 See all controls We build on established cloud providers and inherit their physical and platform security controls rather than running our own hardware. AWS — Dublin, Ireland (EU region)Cloud infrastructure and data hosting for the application. Microsoft Azure — North EuropeAdditional cloud infrastructure and hosting. Vercel — marketing site deliverypopupsmart.com is deployed as a static export on Vercel. Cloudflare — DNS, CDN and edgeCloudflare fronts the site with DNS, caching, and edge security. See the full sub-processor list Network & bot protection Cloudflare edge protection Cloudflare Turnstile on every public form HTTPS enforced site-wide See all controls Public endpoints sit behind Cloudflare, and every form on the site verifies that a human sent it. Cloudflare edge protectionTraffic passes through Cloudflare's network before reaching origin. Cloudflare Turnstile on every public formInvisible bot verification runs on contact, enterprise, ebook, opt-out, newsletter and feedback forms. HTTPS enforced site-wideEvery Popupsmart surface is served over HTTPS. Monitoring & incident detection Monitoring and incident detection Availability monitoring See all controls We monitor our services so that unusual activity surfaces quickly rather than sitting undetected. Monitoring and incident detectionListed among the technical and organizational measures in section 5 of the DPA. Availability monitoringService availability is monitored on an ongoing basis. Incident response Notification without undue delay Assistance with your obligations Named privacy contact See all controls If personal data is affected by a security incident, our obligations to you are written into the DPA rather than left to goodwill. Notification without undue delayPopupsmart notifies the customer without undue delay after becoming aware of a personal data breach. Assistance with your obligationsWe assist the controller in meeting its own breach-notification duties under applicable law. Named privacy contactSecurity and privacy reports reach us at [email protected]. Read the breach terms in the DPA Payment security Stripe processes all payments No card numbers on our servers See all controls Payments are handled end to end by Stripe. Card data does not transit or rest on Popupsmart infrastructure. Stripe processes all paymentsStripe is our payment sub-processor for processing and billing. No card numbers on our serversFull card numbers are never stored by Popupsmart. People Employee confidentiality Security training See all controls The people with access to systems are trained and contractually bound before they get it. Employee confidentialityAll persons authorised to process personal data are subject to appropriate confidentiality obligations. Security trainingEmployee security training is listed among the measures in section 5 of the DPA. Your data rights Access, rectification and erasure Data subject requests routed to you Deletion or return on termination +1 See all controls Whether you are a customer or an end user whose data passed through a campaign, the same rights apply. Access, rectification and erasureRequest a copy of your personal data, correct it, or ask us to delete it. Data subject requests routed to youIf an end user contacts us directly, we notify the customer rather than acting unilaterally on their data. Deletion or return on terminationAt the end of the Service, personal data is deleted or returned in line with the DPA. Opt out of sale or sharingCalifornia residents can opt out through the Do Not Sell My Personal Information form. Exercise your data rights Sub-processor management General authorisation with published list No-less-protective obligations Popupsmart remains responsible See all controls Third parties that touch personal data on our behalf are bound before they are onboarded, and we stay responsible for them. General authorisation with published listYou authorise sub-processors generally; the current list is published on this page. No-less-protective obligationsEach sub-processor is bound by data protection obligations no less protective than our DPA. Popupsmart remains responsibleWe stay fully responsible for the performance of our sub-processors. Sub-processors The third parties that process personal data on our behalf, with the location the processing takes place and what it is for. This is the same list published in Annex I of our DPA. Sub-processor Purpose of processing Location of processing Amazon Web Services (AWS) Cloud infrastructure and data hosting Dublin, Ireland (EU region) Microsoft Azure Cloud infrastructure and hosting Dublin, Ireland (North Europe region; Microsoft Datacenters) Stripe Payment processing and billing South San Francisco, USA / Dublin, Ireland Google Workspace Internal communication, email, and document management Mountain View, California, USA / Dublin, Ireland Google Analytics (GA4) Website and product usage analytics Mountain View, California, USA / Dublin, Ireland PostHog Product analytics and feature usage tracking Frankfurt, Germany (EU); United States (depending on configuration) LiveChatAI Customer support chat and AI-assisted support conversations United States (operated by Popupsmart Inc., the same company that operates Popupsmart) Customer.io Customer messaging, lifecycle emails, and automation United States; Dublin, Ireland (per Customer.io DPA and infrastructure) Google Ads Advertising, conversion tracking, and remarketing Mountain View, California, USA / Dublin, Ireland Facebook Ads (Meta) Advertising, audience targeting, and remarketing Menlo Park, California, USA / Dublin, Ireland Pipedrive CRM and sales pipeline management Estonia (EU headquarters); United States (per Pipedrive DPA) Emailable Email verification and deliverability checks United States (U.S.-based processor, per Emailable DPA) Calendly Scheduling and meeting booking United States (data centers operated via Google Cloud and AWS) We remain fully responsible for the performance of every sub-processor listed here. Each is bound by data protection obligations no less protective than those in our DPA. Have a security or privacy question? Report a vulnerability, request our security overview for a vendor review, or ask how a specific piece of data is handled. Security reports go to the front of the queue. Email the privacy teamContact form Reporting a vulnerability Send findings to the address above with enough detail to reproduce the issue. Please give us a reasonable window to investigate and remediate before disclosing publicly, and avoid accessing, modifying, or deleting data that is not yours while testing.