Security & Privacy

Trust Center

Popupsmart runs on your visitors' pages, so the way we handle data is part of the product. This page collects what we process, where it lives, who we share it with, and the rights you can exercise — with a link to the document behind every claim.

Last reviewed:

Regulatory frameworks

The privacy regimes we process personal data under, each backed by a document you can read in full.

  • GDPR
    GDPRRegulation (EU) 2016/679. Popupsmart acts as processor on your documented instructions under a signed DPA.
  • CCPA
    CCPACalifornia residents can access, delete, and opt out of the sale or sharing of personal information.
  • DPA
    Data Processing AddendumForms part of the Terms of Use. Defines roles, scope, sub-processors, transfers, and breach handling.
  • SCC
    Standard Contractual ClausesEU Commission-approved clauses cover personal data transferred outside the EEA.

To be explicit about what is not here: Popupsmart is not currently SOC 2, ISO 27001 or HIPAA certified, and we do not display seals we have not earned. The infrastructure we build on — AWS, Microsoft Azure, Stripe, Cloudflare — carries its own independent certifications, but those are the providers' and we do not claim them as ours. If a certification is a requirement for your review, tell us and we will say plainly where we stand.

At a glance

Primary hosting
AWS · Microsoft Azure

Application data is hosted in EU regions — AWS in Dublin, Ireland and Azure North Europe.

Site delivery
Vercel · Cloudflare

popupsmart.com is a statically exported site served through Vercel and Cloudflare's CDN.

In transit
HTTPS/TLS on every surface
Payments
Handled by Stripe

Card details go to Stripe directly. Full card numbers are never stored on Popupsmart infrastructure.

Form protection
Cloudflare Turnstile

Every public form runs invisible bot verification before a submission is accepted.

Privacy contact
[email protected]

Security controls

Reviewed September 2026

The technical and organizational measures set out in section 5 of our DPA, grouped by area. Open a card to see every control in that group.

Compliance & privacy

  • GDPR — processor role defined in writing
  • CCPA rights honoured
  • Data Processing Addendum in force
  • +2
See all controls

We process personal data as a processor acting on your documented instructions, under terms that form part of the Terms of Use.

  • GDPR — processor role defined in writingYou are the controller and determine purposes and means; Popupsmart processes only on your documented instructions.
  • CCPA rights honouredCalifornia residents can access, delete, and opt out of the sale or sharing of their personal information.
  • Data Processing Addendum in forceThe DPA forms part of the Terms of Use, so it applies without a separate negotiation.
  • Standard Contractual Clauses for transfersWhere personal data leaves the EEA, EU Commission-approved SCCs or another lawful mechanism applies.
  • Purpose limitationPersonal data submitted through the Service is processed for providing that Service, not repurposed.
Read the Data Processing Addendum

Data security

  • Encryption in transit
  • Network and infrastructure security
  • Data minimisation
  • +1
See all controls

Measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.

  • Encryption in transitTraffic between browsers and our services runs over HTTPS/TLS; plaintext requests are redirected.
  • Network and infrastructure securityServices run inside the security boundaries of our cloud providers rather than self-managed hardware.
  • Data minimisationWe collect the data needed to operate the Service and campaigns you configure — not more.
  • Private form storageForm submissions from popupsmart.com are written to private object storage, not a public bucket.

Access control

  • Access controls and least privilege
  • Confidentiality obligations
  • Access reviewed on role change
See all controls

Access to systems holding personal data is restricted and granted on a least-privilege basis.

  • Access controls and least privilegeStaff receive the minimum access their role requires, and no more.
  • Confidentiality obligationsEveryone authorised to process personal data is bound by contractual or statutory confidentiality.
  • Access reviewed on role changeAccess is revisited when someone changes role and revoked when they leave.

Infrastructure

  • AWS — Dublin, Ireland (EU region)
  • Microsoft Azure — North Europe
  • Vercel — marketing site delivery
  • +1
See all controls

We build on established cloud providers and inherit their physical and platform security controls rather than running our own hardware.

  • AWS — Dublin, Ireland (EU region)Cloud infrastructure and data hosting for the application.
  • Microsoft Azure — North EuropeAdditional cloud infrastructure and hosting.
  • Vercel — marketing site deliverypopupsmart.com is deployed as a static export on Vercel.
  • Cloudflare — DNS, CDN and edgeCloudflare fronts the site with DNS, caching, and edge security.
See the full sub-processor list

Network & bot protection

  • Cloudflare edge protection
  • Cloudflare Turnstile on every public form
  • HTTPS enforced site-wide
See all controls

Public endpoints sit behind Cloudflare, and every form on the site verifies that a human sent it.

  • Cloudflare edge protectionTraffic passes through Cloudflare's network before reaching origin.
  • Cloudflare Turnstile on every public formInvisible bot verification runs on contact, enterprise, ebook, opt-out, newsletter and feedback forms.
  • HTTPS enforced site-wideEvery Popupsmart surface is served over HTTPS.

Monitoring & incident detection

  • Monitoring and incident detection
  • Availability monitoring
See all controls

We monitor our services so that unusual activity surfaces quickly rather than sitting undetected.

  • Monitoring and incident detectionListed among the technical and organizational measures in section 5 of the DPA.
  • Availability monitoringService availability is monitored on an ongoing basis.

Incident response

  • Notification without undue delay
  • Assistance with your obligations
  • Named privacy contact
See all controls

If personal data is affected by a security incident, our obligations to you are written into the DPA rather than left to goodwill.

  • Notification without undue delayPopupsmart notifies the customer without undue delay after becoming aware of a personal data breach.
  • Assistance with your obligationsWe assist the controller in meeting its own breach-notification duties under applicable law.
  • Named privacy contactSecurity and privacy reports reach us at [email protected].
Read the breach terms in the DPA

Payment security

  • Stripe processes all payments
  • No card numbers on our servers
See all controls

Payments are handled end to end by Stripe. Card data does not transit or rest on Popupsmart infrastructure.

  • Stripe processes all paymentsStripe is our payment sub-processor for processing and billing.
  • No card numbers on our serversFull card numbers are never stored by Popupsmart.

People

  • Employee confidentiality
  • Security training
See all controls

The people with access to systems are trained and contractually bound before they get it.

  • Employee confidentialityAll persons authorised to process personal data are subject to appropriate confidentiality obligations.
  • Security trainingEmployee security training is listed among the measures in section 5 of the DPA.

Your data rights

  • Access, rectification and erasure
  • Data subject requests routed to you
  • Deletion or return on termination
  • +1
See all controls

Whether you are a customer or an end user whose data passed through a campaign, the same rights apply.

  • Access, rectification and erasureRequest a copy of your personal data, correct it, or ask us to delete it.
  • Data subject requests routed to youIf an end user contacts us directly, we notify the customer rather than acting unilaterally on their data.
  • Deletion or return on terminationAt the end of the Service, personal data is deleted or returned in line with the DPA.
  • Opt out of sale or sharingCalifornia residents can opt out through the Do Not Sell My Personal Information form.
Exercise your data rights

Sub-processor management

  • General authorisation with published list
  • No-less-protective obligations
  • Popupsmart remains responsible
See all controls

Third parties that touch personal data on our behalf are bound before they are onboarded, and we stay responsible for them.

  • General authorisation with published listYou authorise sub-processors generally; the current list is published on this page.
  • No-less-protective obligationsEach sub-processor is bound by data protection obligations no less protective than our DPA.
  • Popupsmart remains responsibleWe stay fully responsible for the performance of our sub-processors.

Sub-processors

The third parties that process personal data on our behalf, with the location the processing takes place and what it is for. This is the same list published in Annex I of our DPA.

Sub-processorPurpose of processingLocation of processing
Amazon Web Services (AWS)Cloud infrastructure and data hostingDublin, Ireland (EU region)
Microsoft AzureCloud infrastructure and hostingDublin, Ireland (North Europe region; Microsoft Datacenters)
StripePayment processing and billingSouth San Francisco, USA / Dublin, Ireland
Google WorkspaceInternal communication, email, and document managementMountain View, California, USA / Dublin, Ireland
Google Analytics (GA4)Website and product usage analyticsMountain View, California, USA / Dublin, Ireland
PostHogProduct analytics and feature usage trackingFrankfurt, Germany (EU); United States (depending on configuration)
LiveChatAICustomer support chat and AI-assisted support conversationsUnited States (operated by Popupsmart Inc., the same company that operates Popupsmart)
Customer.ioCustomer messaging, lifecycle emails, and automationUnited States; Dublin, Ireland (per Customer.io DPA and infrastructure)
Google AdsAdvertising, conversion tracking, and remarketingMountain View, California, USA / Dublin, Ireland
Facebook Ads (Meta)Advertising, audience targeting, and remarketingMenlo Park, California, USA / Dublin, Ireland
PipedriveCRM and sales pipeline managementEstonia (EU headquarters); United States (per Pipedrive DPA)
EmailableEmail verification and deliverability checksUnited States (U.S.-based processor, per Emailable DPA)
CalendlyScheduling and meeting bookingUnited States (data centers operated via Google Cloud and AWS)

We remain fully responsible for the performance of every sub-processor listed here. Each is bound by data protection obligations no less protective than those in our DPA.

Have a security or privacy question?

Report a vulnerability, request our security overview for a vendor review, or ask how a specific piece of data is handled. Security reports go to the front of the queue.

Reporting a vulnerability

Send findings to the address above with enough detail to reproduce the issue. Please give us a reasonable window to investigate and remediate before disclosing publicly, and avoid accessing, modifying, or deleting data that is not yours while testing.