- Home
- Trust Center
Trust Center
Popupsmart runs on your visitors' pages, so the way we handle data is part of the product. This page collects what we process, where it lives, who we share it with, and the rights you can exercise — with a link to the document behind every claim.
Last reviewed:
Regulatory frameworks
The privacy regimes we process personal data under, each backed by a document you can read in full.
- GDPRGDPRRegulation (EU) 2016/679. Popupsmart acts as processor on your documented instructions under a signed DPA.
- CCPACCPACalifornia residents can access, delete, and opt out of the sale or sharing of personal information.
- DPAData Processing AddendumForms part of the Terms of Use. Defines roles, scope, sub-processors, transfers, and breach handling.
- SCCStandard Contractual ClausesEU Commission-approved clauses cover personal data transferred outside the EEA.
To be explicit about what is not here: Popupsmart is not currently SOC 2, ISO 27001 or HIPAA certified, and we do not display seals we have not earned. The infrastructure we build on — AWS, Microsoft Azure, Stripe, Cloudflare — carries its own independent certifications, but those are the providers' and we do not claim them as ours. If a certification is a requirement for your review, tell us and we will say plainly where we stand.
At a glance
- Primary hosting
- AWS · Microsoft Azure
- Site delivery
- Vercel · Cloudflare
- In transit
- HTTPS/TLS on every surface
- Payments
- Handled by Stripe
- Form protection
- Cloudflare Turnstile
- Privacy contact
- [email protected]
Application data is hosted in EU regions — AWS in Dublin, Ireland and Azure North Europe.
popupsmart.com is a statically exported site served through Vercel and Cloudflare's CDN.
Card details go to Stripe directly. Full card numbers are never stored on Popupsmart infrastructure.
Every public form runs invisible bot verification before a submission is accepted.
Documents & resources
Everything we publish is linked directly — no form, no gate. The rest is a short email away.
- Privacy PolicyWhat we collect, why we collect it, how long we keep it, and the rights you can exercise.Read
- Data Processing AddendumThe processor terms that govern personal data you submit through the Service, including SCCs.Read
- Sub-processor listEvery third party that processes data on our behalf, with its processing location and purpose.Read
- CCPA ComplianceHow Popupsmart meets the California Consumer Privacy Act and what California residents can request.Read
- Do Not Sell My Personal InformationThe opt-out form for the sale or sharing of personal information under CCPA.Read
- Terms of UseThe agreement between you and Popupsmart Inc., which the DPA forms part of.Read
- Security overview for vendor reviewA written summary of our technical and organizational measures, sized for a procurement questionnaire.Available on request
- Counter-signed DPANeed the DPA executed against your entity rather than accepted through the Terms? Ask and we will sign.Available on request
Security controls
Reviewed September 2026The technical and organizational measures set out in section 5 of our DPA, grouped by area. Open a card to see every control in that group.
Compliance & privacy
- GDPR — processor role defined in writing
- CCPA rights honoured
- Data Processing Addendum in force
- +2
See all controls
We process personal data as a processor acting on your documented instructions, under terms that form part of the Terms of Use.
- GDPR — processor role defined in writingYou are the controller and determine purposes and means; Popupsmart processes only on your documented instructions.
- CCPA rights honouredCalifornia residents can access, delete, and opt out of the sale or sharing of their personal information.
- Data Processing Addendum in forceThe DPA forms part of the Terms of Use, so it applies without a separate negotiation.
- Standard Contractual Clauses for transfersWhere personal data leaves the EEA, EU Commission-approved SCCs or another lawful mechanism applies.
- Purpose limitationPersonal data submitted through the Service is processed for providing that Service, not repurposed.
Data security
- Encryption in transit
- Network and infrastructure security
- Data minimisation
- +1
See all controls
Measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.
- Encryption in transitTraffic between browsers and our services runs over HTTPS/TLS; plaintext requests are redirected.
- Network and infrastructure securityServices run inside the security boundaries of our cloud providers rather than self-managed hardware.
- Data minimisationWe collect the data needed to operate the Service and campaigns you configure — not more.
- Private form storageForm submissions from popupsmart.com are written to private object storage, not a public bucket.
Access control
- Access controls and least privilege
- Confidentiality obligations
- Access reviewed on role change
See all controls
Access to systems holding personal data is restricted and granted on a least-privilege basis.
- Access controls and least privilegeStaff receive the minimum access their role requires, and no more.
- Confidentiality obligationsEveryone authorised to process personal data is bound by contractual or statutory confidentiality.
- Access reviewed on role changeAccess is revisited when someone changes role and revoked when they leave.
Infrastructure
- AWS — Dublin, Ireland (EU region)
- Microsoft Azure — North Europe
- Vercel — marketing site delivery
- +1
See all controls
We build on established cloud providers and inherit their physical and platform security controls rather than running our own hardware.
- AWS — Dublin, Ireland (EU region)Cloud infrastructure and data hosting for the application.
- Microsoft Azure — North EuropeAdditional cloud infrastructure and hosting.
- Vercel — marketing site deliverypopupsmart.com is deployed as a static export on Vercel.
- Cloudflare — DNS, CDN and edgeCloudflare fronts the site with DNS, caching, and edge security.
Network & bot protection
- Cloudflare edge protection
- Cloudflare Turnstile on every public form
- HTTPS enforced site-wide
See all controls
Public endpoints sit behind Cloudflare, and every form on the site verifies that a human sent it.
- Cloudflare edge protectionTraffic passes through Cloudflare's network before reaching origin.
- Cloudflare Turnstile on every public formInvisible bot verification runs on contact, enterprise, ebook, opt-out, newsletter and feedback forms.
- HTTPS enforced site-wideEvery Popupsmart surface is served over HTTPS.
Monitoring & incident detection
- Monitoring and incident detection
- Availability monitoring
See all controls
We monitor our services so that unusual activity surfaces quickly rather than sitting undetected.
- Monitoring and incident detectionListed among the technical and organizational measures in section 5 of the DPA.
- Availability monitoringService availability is monitored on an ongoing basis.
Incident response
- Notification without undue delay
- Assistance with your obligations
- Named privacy contact
See all controls
If personal data is affected by a security incident, our obligations to you are written into the DPA rather than left to goodwill.
- Notification without undue delayPopupsmart notifies the customer without undue delay after becoming aware of a personal data breach.
- Assistance with your obligationsWe assist the controller in meeting its own breach-notification duties under applicable law.
- Named privacy contactSecurity and privacy reports reach us at [email protected].
Payment security
- Stripe processes all payments
- No card numbers on our servers
See all controls
Payments are handled end to end by Stripe. Card data does not transit or rest on Popupsmart infrastructure.
- Stripe processes all paymentsStripe is our payment sub-processor for processing and billing.
- No card numbers on our serversFull card numbers are never stored by Popupsmart.
People
- Employee confidentiality
- Security training
See all controls
The people with access to systems are trained and contractually bound before they get it.
- Employee confidentialityAll persons authorised to process personal data are subject to appropriate confidentiality obligations.
- Security trainingEmployee security training is listed among the measures in section 5 of the DPA.
Your data rights
- Access, rectification and erasure
- Data subject requests routed to you
- Deletion or return on termination
- +1
See all controls
Whether you are a customer or an end user whose data passed through a campaign, the same rights apply.
- Access, rectification and erasureRequest a copy of your personal data, correct it, or ask us to delete it.
- Data subject requests routed to youIf an end user contacts us directly, we notify the customer rather than acting unilaterally on their data.
- Deletion or return on terminationAt the end of the Service, personal data is deleted or returned in line with the DPA.
- Opt out of sale or sharingCalifornia residents can opt out through the Do Not Sell My Personal Information form.
Sub-processor management
- General authorisation with published list
- No-less-protective obligations
- Popupsmart remains responsible
See all controls
Third parties that touch personal data on our behalf are bound before they are onboarded, and we stay responsible for them.
- General authorisation with published listYou authorise sub-processors generally; the current list is published on this page.
- No-less-protective obligationsEach sub-processor is bound by data protection obligations no less protective than our DPA.
- Popupsmart remains responsibleWe stay fully responsible for the performance of our sub-processors.
Sub-processors
The third parties that process personal data on our behalf, with the location the processing takes place and what it is for. This is the same list published in Annex I of our DPA.
| Sub-processor | Purpose of processing | Location of processing |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure and data hosting | Dublin, Ireland (EU region) |
| Microsoft Azure | Cloud infrastructure and hosting | Dublin, Ireland (North Europe region; Microsoft Datacenters) |
| Stripe | Payment processing and billing | South San Francisco, USA / Dublin, Ireland |
| Google Workspace | Internal communication, email, and document management | Mountain View, California, USA / Dublin, Ireland |
| Google Analytics (GA4) | Website and product usage analytics | Mountain View, California, USA / Dublin, Ireland |
| PostHog | Product analytics and feature usage tracking | Frankfurt, Germany (EU); United States (depending on configuration) |
| LiveChatAI | Customer support chat and AI-assisted support conversations | United States (operated by Popupsmart Inc., the same company that operates Popupsmart) |
| Customer.io | Customer messaging, lifecycle emails, and automation | United States; Dublin, Ireland (per Customer.io DPA and infrastructure) |
| Google Ads | Advertising, conversion tracking, and remarketing | Mountain View, California, USA / Dublin, Ireland |
| Facebook Ads (Meta) | Advertising, audience targeting, and remarketing | Menlo Park, California, USA / Dublin, Ireland |
| Pipedrive | CRM and sales pipeline management | Estonia (EU headquarters); United States (per Pipedrive DPA) |
| Emailable | Email verification and deliverability checks | United States (U.S.-based processor, per Emailable DPA) |
| Calendly | Scheduling and meeting booking | United States (data centers operated via Google Cloud and AWS) |
We remain fully responsible for the performance of every sub-processor listed here. Each is bound by data protection obligations no less protective than those in our DPA.
Have a security or privacy question?
Report a vulnerability, request our security overview for a vendor review, or ask how a specific piece of data is handled. Security reports go to the front of the queue.
Reporting a vulnerability
Send findings to the address above with enough detail to reproduce the issue. Please give us a reasonable window to investigate and remediate before disclosing publicly, and avoid accessing, modifying, or deleting data that is not yours while testing.