Privacy Policy

Last updated: August 17, 2026

This policy explains what personal data BetterPopup handles, why, and what control you have over it. It covers both the data we hold about our own customers and the visitor data we process on their behalf — two different roles with two different sets of rules, set out in section 2.

1. Who we are

BetterPopup is operated by Digitonica SRL, a Romanian company registered with the Trade Register under J18/1195/2022, fiscal code (CUI) 46142569, registered office at Str. Dr. Victor Gomoiu, Craiova, Dolj, Romania. Our representative is Marius Claudiu Limban.

For privacy questions, write to [email protected] or call +40 756 029 780. We are not required to appoint a Data Protection Officer under Art. 37 GDPR, and because we are established in Romania — an EU member state — no Art. 27 EU representative is required.

2. The two roles we play — and why it matters

BetterPopup handles personal data in two very different capacities. Almost every question about your data has a different answer depending on which one applies, so this policy is built around the distinction.

Whose dataOur roleWhat that means
Our customers — the people who sign up for a BetterPopup account, and visitors to betterpopup.comControllerWe decide why and how this data is processed. Sections 3 to 6 and 9 to 13 describe it.
Our customers' visitors and subscribers — people who see or sign up through a popup on a customer's siteProcessorThe customer is the controller and decides what is collected and why. We only act on their instructions. Section 7 describes it.

If you signed up through a popup on a shop and want your data removed, contact that shop. They control it — we hold it on their behalf and cannot decide to delete or disclose it without their instruction. If you are not sure who to ask, email [email protected] and we will point you to the right controller.

3. Data we collect as controller

Account data

Your name, email address, the URL of the site or store you connect, your company or workspace name, and your authentication credentials. Sign-in is handled by Clerk; we never see or store your password in plain text.

Billing data

Your plan, subscription status, billing period and invoice history. Card payments are processed by Stripe, or by Shopify if you installed through the Shopify App Store — we never receive or store full card numbers. We keep the customer reference and subscription status needed to run your account.

Usage and technical data

How you use the dashboard and builder, which features you open, plus server logs and diagnostic information needed to keep the service secure and working. Product analytics run through PostHog and are only enabled where you have consented — see section 8.

Onboarding and brand data

When you complete the first-run wizard we store your answers and the brand details we detect from your site (such as your logo and colours) so we can pre-fill your first popup.

Support and marketing data

Messages you send us and our replies, and — where you have opted in or we are otherwise permitted — the marketing source that brought you to us (referrer and UTM parameters).

You must be at least 16 years old to create an account. We do not knowingly collect data from children.

5. How we use data — and what we never do

We use the data above to operate and secure the service, to bill you, to support you, and to make the product better.

We do not sell personal data. We do not share it with advertising networks, do not use it to build advertising profiles, and do not use your subscribers' data for any purpose other than delivering the service to you. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects (Art. 22 GDPR).

6. Who we share data with

We share personal data only with the providers below, who process it on our behalf under a data processing agreement and may not use it for their own purposes.

ProviderPurposeLocationSafeguard
ClerkAuthentication and account managementUnited StatesSCCs / EU-US DPF
StripePayments and subscription billingUnited States / IrelandSCCs / EU-US DPF
ShopifyApp installation, billing and store integration — Shopify installs onlyCanada / United StatesSCCs
ResendTransactional and notification emailUnited StatesSCCs / EU-US DPF
PostHogProduct analytics and error tracking — consent-gatedUnited StatesSCCs / EU-US DPF
CloudflareCDN, DNS and abuse protection for our site and embed scriptGlobal edge networkSCCs / EU-US DPF
HetznerApplication hosting and database infrastructureUnited States (provider incorporated in Germany)SCCs

The current list is maintained in our DPA, which also explains how we notify customers before adding a new sub-processor.

Integrations you choose to connect

When you connect an email or SMS platform — Klaviyo, Mailchimp, Omnisend, Attentive, Postscript, Drip and others — we send captured signups to it at your instruction. Those platforms are not our sub-processors: they act under their own agreement with you, and their own privacy policies govern what happens to the data once it arrives. You choose whether to connect them and can disconnect at any time.

We may also disclose data where the law requires it, to enforce our terms, or in connection with a merger or acquisition — in which case we will notify affected customers.

7. Visitor and subscriber data — what the popup collects

This section describes data we process on behalf of our customers. Each customer is the controller and decides what to collect; the technical detail below is what our software is capable of collecting when a customer runs it.

What a signup records

  • the email address or phone number the visitor enters, and any other field the customer added to the form;
  • a consent record — what the visitor was shown and agreed to, and when;
  • where the customer has enabled double opt-in, a confirmation token and the time the visitor confirmed.

What the embed script sees

To decide whether a popup should appear and to keep A/B tests consistent, our script reads: the page URL, path and title, the referring URL, approximate screen size and whether the device is mobile, browser language and time zone, an approximate country derived from a network-level header, and the browser's Do Not Track and Global Privacy Control settings.

Identifiers stored in the visitor's browser

These are first-party values on the customer's own site. They are not cookies used for advertising and are never read across other websites.

KeyStoragePurposeLifetime
bp_sessionsessionStorageGroups a single browsing session so a visitor is not shown the same popup repeatedlyUntil the tab is closed
bp_visitorlocalStorageA random per-browser id that keeps A/B test variants stable across visits, so a returning visitor sees a consistent experienceUntil cleared by the visitor or the browser

What we deliberately do not do. We never store visitors' full IP addresses — an IP is used only in memory, for a few seconds, to rate-limit abusive requests, and is then discarded. Campaign analytics are stored as daily counts of impressions and conversions per popup, not as per-visitor profiles. We do not track visitors across other websites, do not build advertising audiences, and do not sell or share this data. Known search-engine and AI crawlers are filtered out and never shown a popup.

Privacy signals

Our script reads the Do Not Track and Global Privacy Control settings a browser advertises and passes them to the customer's campaign configuration, so those preferences can be respected. Because the customer is the controller, it is their responsibility to configure campaigns and consent behaviour in line with the law that applies to them.

8. Cookies on betterpopup.com

On our own website we use essential cookies for sign-in and security, a bp_region cookie that records only whether consent is legally required where you are, and — with your consent — PostHog analytics cookies.

Where consent is required we ask before setting anything non-essential, and nothing analytics-related runs until you choose. You can change or withdraw your choice at any time from the Cookie preferences link in the footer. Full detail is in our Cookie Policy.

9. How long we keep data

DataRetention
Account and profile dataWhile your account is active. Erased within 30 days of closure, plus up to 30 further days in encrypted backups
Campaigns, popups and templates you createdUntil you delete them or close your account
Subscriber data captured through your popupsFor as long as you instruct. Erased within 30 days of account closure, or sooner on your instruction
Campaign analytics (daily impression and conversion counts)While the account is active; aggregate and not linked to an individual
Shopify compliance request log24 months — a durable audit record that a data request was received and fulfilled
Support conversations24 months after our last contact
Invoices and accounting records10 years, as required by Romanian law
Cookie-consent record12 months
Server and security logsUp to 6 months
Rate-limiting dataHeld in memory only, seconds to minutes; never written to disk

10. International transfers

We are established in Romania, and some of our providers and infrastructure are located in the United States. Where personal data is transferred outside the EU/EEA we rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework, together with additional technical measures such as encryption in transit and at rest.

You can request a copy of the safeguards that apply to a specific transfer by writing to [email protected].

11. How we protect data

We use encryption in transit (TLS) and at rest, encrypt the access tokens for the integrations you connect, apply least-privilege database roles so the public capture endpoint can only insert records, restrict administrative access to the people who need it, and rate-limit public endpoints against abuse. Payment card data never reaches our systems.

No system is completely secure, but we maintain appropriate technical and organisational measures, review them regularly, and will notify affected customers and the competent authority where a breach requires it under Art. 33 and 34 GDPR. The measures are described in more detail in our DPA.

12. Your rights

If we are the controller of your data, you can ask us to: give you access to it (Art. 15); correct it (Art. 16); erase it (Art. 17); restrict or object to how we use it (Art. 18 and 21); provide it in a portable, machine-readable format (Art. 20); and withdraw consent at any time without affecting processing that already happened (Art. 7(3)).

Email [email protected] — you can also delete your account yourself from your settings. We respond within one month, and will tell you if we need longer because a request is complex.

If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to a supervisory authority — for us that is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) — or to the authority where you live or work.

13. US state privacy rights

If you live in California, Colorado, Connecticut, Virginia or another US state with comprehensive privacy legislation, you may have rights to know what personal information we collect, to access, correct or delete it, to opt out of its sale or sharing, and not to be discriminated against for exercising those rights.

We do not sell personal information and do not share it for cross-context behavioural advertising — as those terms are defined under the CCPA/CPRA and similar laws. To exercise a right, email [email protected]. You may use an authorised agent, and we will verify the request before acting on it.

For data we process on behalf of a customer we act as a service provider or processor, and we will forward your request to the relevant business.

14. Shopify merchants

If you install BetterPopup from the Shopify App Store, we receive your store domain and an access token scoped to what the app needs. We support Shopify's mandatory privacy webhooks — customer data requests, customer redaction and shop redaction — and keep an audit record of each request and when it was fulfilled. Uninstalling the app stops the popups and begins the deletion process described in section 9.

15. Changes to this policy

We may update this policy as the service and the law develop. If we make material changes we will post a prominent notice on this page and update the date at the top, or contact account owners directly where required.

16. Contact

Digitonica SRL
Str. Dr. Victor Gomoiu
Craiova, Dolj, Romania
CUI 46142569 · Trade Register J18/1195/2022
Privacy: [email protected]
Phone: +40 756 029 780