Poplause← Back to home

Privacy Policy

Last updated: 6 June 2026

This policy explains what data Poplause collects, why, and what choices you have. It covers both our customers and the visitors who see Poplause notifications.

1. Who we are

Poplause provides social-proof notification widgets. For account and billing data, Poplause is the data controller. For the event data our customers send through the widget, our customers are the controller and Poplause acts as a processor on their behalf.

2. Data we collect

  • Account data - your name, email and authentication details, handled by our auth provider (Clerk).
  • Billing data - subscription and payment details, handled by our payment processor (Stripe). We do not store full card numbers.
  • Event data - the activity our customers choose to display (for example a first name, city, product name or rating). Customers control what is sent.
  • Usage data - basic, aggregated metrics about widget impressions and clicks so we can show analytics and keep the service healthy.

3. How we use data

We use data to provide and improve the service, render notifications, show analytics, process payments, prevent abuse and communicate with you about your account. We do not sell your personal data.

4. The widget and your visitors

The Poplause widget is lightweight and designed to minimise data collection. It renders notifications and records aggregate impression and click counts. It does not build advertising profiles of your visitors. The content shown in a notification is supplied by the customer who installed it.

5. Cookies

Our marketing site uses analytics to understand traffic. The embedded widget uses minimal local storage only to pace notifications within a session (so the same visitor is not shown too many). You can clear this at any time through your browser.

6. Sharing

We share data only with the service providers that help us run Poplause - such as Clerk (authentication), Stripe (payments) and our hosting and analytics providers - under agreements that require them to protect it. We may also disclose data where required by law.

7. Retention

We keep account data for as long as your account is active and for a reasonable period afterwards. Event data is retained according to your plan and configuration; you can delete events at any time from the dashboard, the Management API or the MCP server.

8. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to certain processing. To exercise these rights, contact us at the address below.

9. Security

We use industry-standard measures to protect data in transit and at rest, and we scope access to site data behind per-site API keys. No system is perfectly secure, so please keep your keys safe and report any concerns.

10. Changes and contact

We may update this policy from time to time and will note the date of the latest change above. Questions or requests? Email privacy@poplause.com.