Privacy Policy
Last updated: August 17, 2026
This policy explains what personal data BetterPopup handles, why, and what control you have over it. It covers both the data we hold about our own customers and the visitor data we process on their behalf — two different roles with two different sets of rules, set out in section 2.
1. Who we are
BetterPopup is operated by Digitonica SRL, a Romanian company registered with the Trade Register under J18/1195/2022, fiscal code (CUI) 46142569, registered office at Str. Dr. Victor Gomoiu, Craiova, Dolj, Romania. Our representative is Marius Claudiu Limban.
For privacy questions, write to [email protected] or call +40 756 029 780. We are not required to appoint a Data Protection Officer under Art. 37 GDPR, and because we are established in Romania — an EU member state — no Art. 27 EU representative is required.
2. The two roles we play — and why it matters
BetterPopup handles personal data in two very different capacities. Almost every question about your data has a different answer depending on which one applies, so this policy is built around the distinction.
| Whose data | Our role | What that means |
|---|---|---|
| Our customers — the people who sign up for a BetterPopup account, and visitors to betterpopup.com | Controller | We decide why and how this data is processed. Sections 3 to 6 and 9 to 13 describe it. |
| Our customers' visitors and subscribers — people who see or sign up through a popup on a customer's site | Processor | The customer is the controller and decides what is collected and why. We only act on their instructions. Section 7 describes it. |
If you signed up through a popup on a shop and want your data removed, contact that shop. They control it — we hold it on their behalf and cannot decide to delete or disclose it without their instruction. If you are not sure who to ask, email [email protected] and we will point you to the right controller.
3. Data we collect as controller
Account data
Your name, email address, the URL of the site or store you connect, your company or workspace name, and your authentication credentials. Sign-in is handled by Clerk; we never see or store your password in plain text.
Billing data
Your plan, subscription status, billing period and invoice history. Card payments are processed by Stripe, or by Shopify if you installed through the Shopify App Store — we never receive or store full card numbers. We keep the customer reference and subscription status needed to run your account.
Usage and technical data
How you use the dashboard and builder, which features you open, plus server logs and diagnostic information needed to keep the service secure and working. Product analytics run through PostHog and are only enabled where you have consented — see section 8.
Onboarding and brand data
When you complete the first-run wizard we store your answers and the brand details we detect from your site (such as your logo and colours) so we can pre-fill your first popup.
Support and marketing data
Messages you send us and our replies, and — where you have opted in or we are otherwise permitted — the marketing source that brought you to us (referrer and UTM parameters).
You must be at least 16 years old to create an account. We do not knowingly collect data from children.
4. Why we process it, and our legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating and running your account, serving your popups, providing analytics and support | Contract — Art. 6(1)(b) |
| Taking payment, issuing invoices and keeping accounting records | Contract and legal obligation — Art. 6(1)(b), 6(1)(c) |
| Service emails you cannot opt out of while you have an account — welcome, billing, security and important product notices | Contract — Art. 6(1)(b) |
| New-lead notifications and digests we send you about your own campaigns | Contract — Art. 6(1)(b) |
| Analytics cookies and marketing emails | Consent — Art. 6(1)(a), withdrawable at any time |
| Keeping the service secure, preventing abuse and fraud, rate limiting, and improving the product | Legitimate interests — Art. 6(1)(f) |
| Responding to legal requests and defending legal claims | Legal obligation and legitimate interests — Art. 6(1)(c), (f) |
5. How we use data — and what we never do
We use the data above to operate and secure the service, to bill you, to support you, and to make the product better.
We do not sell personal data. We do not share it with advertising networks, do not use it to build advertising profiles, and do not use your subscribers' data for any purpose other than delivering the service to you. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects (Art. 22 GDPR).
7. Visitor and subscriber data — what the popup collects
This section describes data we process on behalf of our customers. Each customer is the controller and decides what to collect; the technical detail below is what our software is capable of collecting when a customer runs it.
What a signup records
- the email address or phone number the visitor enters, and any other field the customer added to the form;
- a consent record — what the visitor was shown and agreed to, and when;
- where the customer has enabled double opt-in, a confirmation token and the time the visitor confirmed.
What the embed script sees
To decide whether a popup should appear and to keep A/B tests consistent, our script reads: the page URL, path and title, the referring URL, approximate screen size and whether the device is mobile, browser language and time zone, an approximate country derived from a network-level header, and the browser's Do Not Track and Global Privacy Control settings.
Identifiers stored in the visitor's browser
These are first-party values on the customer's own site. They are not cookies used for advertising and are never read across other websites.
| Key | Storage | Purpose | Lifetime |
|---|---|---|---|
bp_session | sessionStorage | Groups a single browsing session so a visitor is not shown the same popup repeatedly | Until the tab is closed |
bp_visitor | localStorage | A random per-browser id that keeps A/B test variants stable across visits, so a returning visitor sees a consistent experience | Until cleared by the visitor or the browser |
What we deliberately do not do. We never store visitors' full IP addresses — an IP is used only in memory, for a few seconds, to rate-limit abusive requests, and is then discarded. Campaign analytics are stored as daily counts of impressions and conversions per popup, not as per-visitor profiles. We do not track visitors across other websites, do not build advertising audiences, and do not sell or share this data. Known search-engine and AI crawlers are filtered out and never shown a popup.
Privacy signals
Our script reads the Do Not Track and Global Privacy Control settings a browser advertises and passes them to the customer's campaign configuration, so those preferences can be respected. Because the customer is the controller, it is their responsibility to configure campaigns and consent behaviour in line with the law that applies to them.
9. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | While your account is active. Erased within 30 days of closure, plus up to 30 further days in encrypted backups |
| Campaigns, popups and templates you created | Until you delete them or close your account |
| Subscriber data captured through your popups | For as long as you instruct. Erased within 30 days of account closure, or sooner on your instruction |
| Campaign analytics (daily impression and conversion counts) | While the account is active; aggregate and not linked to an individual |
| Shopify compliance request log | 24 months — a durable audit record that a data request was received and fulfilled |
| Support conversations | 24 months after our last contact |
| Invoices and accounting records | 10 years, as required by Romanian law |
| Cookie-consent record | 12 months |
| Server and security logs | Up to 6 months |
| Rate-limiting data | Held in memory only, seconds to minutes; never written to disk |
10. International transfers
We are established in Romania, and some of our providers and infrastructure are located in the United States. Where personal data is transferred outside the EU/EEA we rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework, together with additional technical measures such as encryption in transit and at rest.
You can request a copy of the safeguards that apply to a specific transfer by writing to [email protected].
11. How we protect data
We use encryption in transit (TLS) and at rest, encrypt the access tokens for the integrations you connect, apply least-privilege database roles so the public capture endpoint can only insert records, restrict administrative access to the people who need it, and rate-limit public endpoints against abuse. Payment card data never reaches our systems.
No system is completely secure, but we maintain appropriate technical and organisational measures, review them regularly, and will notify affected customers and the competent authority where a breach requires it under Art. 33 and 34 GDPR. The measures are described in more detail in our DPA.
12. Your rights
If we are the controller of your data, you can ask us to: give you access to it (Art. 15); correct it (Art. 16); erase it (Art. 17); restrict or object to how we use it (Art. 18 and 21); provide it in a portable, machine-readable format (Art. 20); and withdraw consent at any time without affecting processing that already happened (Art. 7(3)).
Email [email protected] — you can also delete your account yourself from your settings. We respond within one month, and will tell you if we need longer because a request is complex.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to a supervisory authority — for us that is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) — or to the authority where you live or work.
13. US state privacy rights
If you live in California, Colorado, Connecticut, Virginia or another US state with comprehensive privacy legislation, you may have rights to know what personal information we collect, to access, correct or delete it, to opt out of its sale or sharing, and not to be discriminated against for exercising those rights.
We do not sell personal information and do not share it for cross-context behavioural advertising — as those terms are defined under the CCPA/CPRA and similar laws. To exercise a right, email [email protected]. You may use an authorised agent, and we will verify the request before acting on it.
For data we process on behalf of a customer we act as a service provider or processor, and we will forward your request to the relevant business.
14. Shopify merchants
If you install BetterPopup from the Shopify App Store, we receive your store domain and an access token scoped to what the app needs. We support Shopify's mandatory privacy webhooks — customer data requests, customer redaction and shop redaction — and keep an audit record of each request and when it was fulfilled. Uninstalling the app stops the popups and begins the deletion process described in section 9.
15. Changes to this policy
We may update this policy as the service and the law develop. If we make material changes we will post a prominent notice on this page and update the date at the top, or contact account owners directly where required.
16. Contact
Digitonica SRL
Str. Dr. Victor Gomoiu
Craiova, Dolj, Romania
CUI 46142569 · Trade Register J18/1195/2022
Privacy: [email protected]
Phone: +40 756 029 780