Third Party Index

Snapshot 42526

Document
Subprocessor list
URL
https://popupsmart.com/trust-center#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
325767 bytes
SHA-256 (raw)
52e848dd55b0e6df56346ea7487efa9a009d1ef9b6dbe71a8d5d0d219159d4ff
SHA-256 (normalized text)
43c4719e446673d8cb1b82060660ad8026cb920fbe30ffba8c5decf34b8f6ce4

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Home
Trust Center
Trust Center
Popupsmart runs on your visitors' pages, so the way we handle data is part of the product. This page collects what we process, where it lives, who we share it with, and the rights you can exercise — with a link to the document behind every claim.
Last reviewed: 10 September 2026
Regulatory frameworks
The privacy regimes we process personal data under, each backed by a document you can read in full.
GDPR
GDPRRegulation (EU) 2016/679. Popupsmart acts as processor on your documented instructions under a signed DPA.
CCPA
CCPACalifornia residents can access, delete, and opt out of the sale or sharing of personal information.
DPA
Data Processing AddendumForms part of the Terms of Use. Defines roles, scope, sub-processors, transfers, and breach handling.
SCC
Standard Contractual ClausesEU Commission-approved clauses cover personal data transferred outside the EEA.
To be explicit about what is not here: Popupsmart is not currently SOC 2, ISO 27001 or HIPAA certified, and we do not display seals we have not earned. The infrastructure we build on — AWS, Microsoft Azure, Stripe, Cloudflare — carries its own independent certifications, but those are the providers' and we do not claim them as ours. If a certification is a requirement for your review, tell us and we will say plainly where we stand.
At a glance
Primary hosting
AWS · Microsoft Azure
Application data is hosted in EU regions — AWS in Dublin, Ireland and Azure North Europe.
Site delivery
Vercel · Cloudflare
popupsmart.com is a statically exported site served through Vercel and Cloudflare's CDN.
In transit
HTTPS/TLS on every surface
Payments
Handled by Stripe
Card details go to Stripe directly. Full card numbers are never stored on Popupsmart infrastructure.
Form protection
Cloudflare Turnstile
Every public form runs invisible bot verification before a submission is accepted.
Privacy contact
[email protected]
Documents & resources
Everything we publish is linked directly — no form, no gate. The rest is a short email away.
Privacy PolicyWhat we collect, why we collect it, how long we keep it, and the rights you can exercise.Read
Data Processing AddendumThe processor terms that govern personal data you submit through the Service, including SCCs.Read
Sub-processor listEvery third party that processes data on our behalf, with its processing location and purpose.Read
CCPA ComplianceHow Popupsmart meets the California Consumer Privacy Act and what California residents can request.Read
Do Not Sell My Personal InformationThe opt-out form for the sale or sharing of personal information under CCPA.Read
Terms of UseThe agreement between you and Popupsmart Inc., which the DPA forms part of.Read
Security overview for vendor reviewA written summary of our technical and organizational measures, sized for a procurement questionnaire.Available on request
Counter-signed DPANeed the DPA executed against your entity rather than accepted through the Terms? Ask and we will sign.Available on request
Security controls
Reviewed September 2026
The technical and organizational measures set out in section 5 of our DPA, grouped by area. Open a card to see every control in that group.
Compliance & privacy
GDPR — processor role defined in writing
CCPA rights honoured
Data Processing Addendum in force
+2
See all controls
We process personal data as a processor acting on your documented instructions, under terms that form part of the Terms of Use.
GDPR — processor role defined in writingYou are the controller and determine purposes and means; Popupsmart processes only on your documented instructions.
CCPA rights honouredCalifornia residents can access, delete, and opt out of the sale or sharing of their personal information.
Data Processing Addendum in forceThe DPA forms part of the Terms of Use, so it applies without a separate negotiation.
Standard Contractual Clauses for transfersWhere personal data leaves the EEA, EU Commission-approved SCCs or another lawful mechanism applies.
Purpose limitationPersonal data submitted through the Service is processed for providing that Service, not repurposed.
Read the Data Processing Addendum
Data security
Encryption in transit
Network and infrastructure security
Data minimisation
+1
See all controls
Measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.
Encryption in transitTraffic between browsers and our services runs over HTTPS/TLS; plaintext requests are redirected.
Network and infrastructure securityServices run inside the security boundaries of our cloud providers rather than self-managed hardware.
Data minimisationWe collect the data needed to operate the Service and campaigns you configure — not more.
Private form storageForm submissions from popupsmart.com are written to private object storage, not a public bucket.
Access control
Access controls and least privilege
Confidentiality obligations
Access reviewed on role change
See all controls
Access to systems holding personal data is restricted and granted on a least-privilege basis.
Access controls and least privilegeStaff receive the minimum access their role requires, and no more.
Confidentiality obligationsEveryone authorised to process personal data is bound by contractual or statutory confidentiality.
Access reviewed on role changeAccess is revisited when someone changes role and revoked when they leave.
Infrastructure
AWS — Dublin, Ireland (EU region)
Microsoft Azure — North Europe
Vercel — marketing site delivery
+1
See all controls
We build on established cloud providers and inherit their physical and platform security controls rather than running our own hardware.
AWS — Dublin, Ireland (EU region)Cloud infrastructure and data hosting for the application.
Microsoft Azure — North EuropeAdditional cloud infrastructure and hosting.
Vercel — marketing site deliverypopupsmart.com is deployed as a static export on Vercel.
Cloudflare — DNS, CDN and edgeCloudflare fronts the site with DNS, caching, and edge security.
See the full sub-processor list
Network & bot protection
Cloudflare edge protection
Cloudflare Turnstile on every public form
HTTPS enforced site-wide
See all controls
Public endpoints sit behind Cloudflare, and every form on the site verifies that a human sent it.
Cloudflare edge protectionTraffic passes through Cloudflare's network before reaching origin.
Cloudflare Turnstile on every public formInvisible bot verification runs on contact, enterprise, ebook, opt-out, newsletter and feedback forms.
HTTPS enforced site-wideEvery Popupsmart surface is served over HTTPS.
Monitoring & incident detection
Monitoring and incident detection
Availability monitoring
See all controls
We monitor our services so that unusual activity surfaces quickly rather than sitting undetected.
Monitoring and incident detectionListed among the technical and organizational measures in section 5 of the DPA.
Availability monitoringService availability is monitored on an ongoing basis.
Incident response
Notification without undue delay
Assistance with your obligations
Named privacy contact
See all controls
If personal data is affected by a security incident, our obligations to you are written into the DPA rather than left to goodwill.
Notification without undue delayPopupsmart notifies the customer without undue delay after becoming aware of a personal data breach.
Assistance with your obligationsWe assist the controller in meeting its own breach-notification duties under applicable law.
Named privacy contactSecurity and privacy reports reach us at [email protected].
Read the breach terms in the DPA
Payment security
Stripe processes all payments
No card numbers on our servers
See all controls
Payments are handled end to end by Stripe. Card data does not transit or rest on Popupsmart infrastructure.
Stripe processes all paymentsStripe is our payment sub-processor for processing and billing.
No card numbers on our serversFull card numbers are never stored by Popupsmart.
People
Employee confidentiality
Security training
See all controls
The people with access to systems are trained and contractually bound before they get it.
Employee confidentialityAll persons authorised to process personal data are subject to appropriate confidentiality obligations.
Security trainingEmployee security training is listed among the measures in section 5 of the DPA.
Your data rights
Access, rectification and erasure
Data subject requests routed to you
Deletion or return on termination
+1
See all controls
Whether you are a customer or an end user whose data passed through a campaign, the same rights apply.
Access, rectification and erasureRequest a copy of your personal data, correct it, or ask us to delete it.
Data subject requests routed to youIf an end user contacts us directly, we notify the customer rather than acting unilaterally on their data.
Deletion or return on terminationAt the end of the Service, personal data is deleted or returned in line with the DPA.
Opt out of sale or sharingCalifornia residents can opt out through the Do Not Sell My Personal Information form.
Exercise your data rights
Sub-processor management
General authorisation with published list
No-less-protective obligations
Popupsmart remains responsible
See all controls
Third parties that touch personal data on our behalf are bound before they are onboarded, and we stay responsible for them.
General authorisation with published listYou authorise sub-processors generally; the current list is published on this page.
No-less-protective obligationsEach sub-processor is bound by data protection obligations no less protective than our DPA.
Popupsmart remains responsibleWe stay fully responsible for the performance of our sub-processors.
Sub-processors
The third parties that process personal data on our behalf, with the location the processing takes place and what it is for. This is the same list published in Annex I of our DPA.
Sub-processor	Purpose of processing	Location of processing
Amazon Web Services (AWS)	Cloud infrastructure and data hosting	Dublin, Ireland (EU region)
Microsoft Azure	Cloud infrastructure and hosting	Dublin, Ireland (North Europe region; Microsoft Datacenters)
Stripe	Payment processing and billing	South San Francisco, USA / Dublin, Ireland
Google Workspace	Internal communication, email, and document management	Mountain View, California, USA / Dublin, Ireland
Google Analytics (GA4)	Website and product usage analytics	Mountain View, California, USA / Dublin, Ireland
PostHog	Product analytics and feature usage tracking	Frankfurt, Germany (EU); United States (depending on configuration)
LiveChatAI	Customer support chat and AI-assisted support conversations	United States (operated by Popupsmart Inc., the same company that operates Popupsmart)
Customer.io	Customer messaging, lifecycle emails, and automation	United States; Dublin, Ireland (per Customer.io DPA and infrastructure)
Google Ads	Advertising, conversion tracking, and remarketing	Mountain View, California, USA / Dublin, Ireland
Facebook Ads (Meta)	Advertising, audience targeting, and remarketing	Menlo Park, California, USA / Dublin, Ireland
Pipedrive	CRM and sales pipeline management	Estonia (EU headquarters); United States (per Pipedrive DPA)
Emailable	Email verification and deliverability checks	United States (U.S.-based processor, per Emailable DPA)
Calendly	Scheduling and meeting booking	United States (data centers operated via Google Cloud and AWS)
We remain fully responsible for the performance of every sub-processor listed here. Each is bound by data protection obligations no less protective than those in our DPA.
Have a security or privacy question?
Report a vulnerability, request our security overview for a vendor review, or ask how a specific piece of data is handled. Security reports go to the front of the queue.
Email the privacy teamContact form
Reporting a vulnerability
Send findings to the address above with enough detail to reproduce the issue. Please give us a reasonable window to investigate and remediate before disclosing publicly, and avoid accessing, modifying, or deleting data that is not yours while testing.