Privacy Policy PopUplift

Last updated: September 1, 2026

Protecting your personal data is important to us. Below you find all information about how we process and store your data when you visit popuplift.com, when you use the Shopify app PopUplift and when you interact with popups powered by PopUplift.

Processing is carried out in accordance with the General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG) and the Austrian Telecommunications Act (TKG 2021).

This privacy policy has three parts:

  1. Visiting the website popuplift.com

  2. Using the Shopify app PopUplift as a merchant

  3. Processing of shop visitor and end customer data through PopUplift popups

CONTROLLER

Richard Wagentristl
Drorygasse 8/4/15
1030 Vienna
Austria

Contact: r.wagentristl@gmail.com

Further details are available in the imprint at https://popuplift.com/imprint

PART 1: COLLECTION AND PROCESSING OF PERSONAL DATA ON POPUPLIFT.COM

Note: To protect your data against unauthorized access, we use technical and organizational measures and TLS encryption on our website. Your data is transmitted between your device and our servers via TLS (Transport Layer Security). You can recognize TLS by the closed padlock symbol in your browser and the address starting with https://.

1. ACCESS AND LOG DATA

This website automatically collects and stores server log information that your browser transmits to us:

  • IP address of the user

  • Date and time of access

  • Type of request

  • Browser type and version

  • Operating system of the user (device, OS version)

  • Referrer information (source of the access)

The legal basis is our legitimate interest under Art. 6 (1) (f) GDPR. The legitimate interest lies in being able to detect unlawful use of our website (e.g. defending against hacking attacks) and in ensuring a smooth connection. We only retain server log files for longer periods in case of attacks on our infrastructure or other legal violations, for the purpose of preserving evidence.

2. WEBSITE HOSTING (FRAMER)

Our website is hosted and delivered via Framer, a service of Framer B.V., Rozengracht 207 B, 1016 LZ Amsterdam, Netherlands. We have concluded a data processing agreement with Framer in accordance with Art. 28 GDPR. The legal basis is our legitimate interest in a reliable and performant delivery of our website (Art. 6 (1) (f) GDPR). Further information: https://www.framer.com/legal/privacy-statement/

3. DNS AND NETWORK SECURITY (CLOUDFLARE)

For DNS, CDN and protection against attacks (DDoS) we use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Your IP address is processed in this context. We have concluded a data processing agreement with Cloudflare in accordance with Art. 28 GDPR. Cloudflare is certified under the EU-US Data Privacy Framework. The legal basis is our legitimate interest in a secure and fast delivery of the website (Art. 6 (1) (f) GDPR). Further information: https://www.cloudflare.com/privacypolicy/

4. COOKIES AND TRACKING

popuplift.com does not set any cookies that require consent and does not use any web analytics, tracking or advertising tools. Only technically necessary data is processed as described in sections 1 to 3 above. Should we introduce cookies or analytics tools in the future, we will update this privacy policy and, where required, obtain your consent via a consent banner in accordance with Art. 6 (1) (a) GDPR.

5. CONTACT

If you contact us by email, we process your details exclusively to handle and answer your request. The legal basis is our legitimate interest under Art. 6 (1) (f) GDPR in responding to inquiries and, for natural persons, the initiation or performance of a contract under Art. 6 (1) (b) GDPR. We delete your inquiry no later than 2 years after our final response, unless a contract is concluded.

PART 2: USE OF THE SHOPIFY APP POPUPLIFT BY MERCHANTS

1. INSTALLATION AND MERCHANT ACCOUNT

PopUplift is an app for Shopify stores. When you install the app via the Shopify App Store, we receive the following data about your store from Shopify:

  • Store domain (myshopify domain) and store name

  • Email address of the store owner

  • Shopify access token for the API scopes you have granted

  • Store settings such as currency, language and theme information

We store this data for the performance of the contract under Art. 6 (1) (b) GDPR for as long as the app is installed. In addition, we store the IP address and timestamp of user actions in the app based on our legitimate interest under Art. 6 (1) (f) GDPR in preventing misuse and unauthorized use.

2. BILLING

Billing for the app is handled exclusively via Shopify Billing. We do not receive payment data such as credit card numbers from Shopify. We store the selected plan, the visitor volume and the billing status for the performance of the contract under Art. 6 (1) (b) GDPR and to comply with statutory retention obligations under Art. 6 (1) (c) GDPR.

3. KLAVIYO CONNECTION

If you connect your Klaviyo account to PopUplift, we store the access token granted for this purpose (OAuth). On your instruction, PopUplift transmits email addresses, opt-in status, quiz answers and list or segment assignments of shop visitors to your Klaviyo account. In this context Klaviyo is your processor, not ours. The data processing agreement between you and Klaviyo applies to processing in Klaviyo.

4. MANDATORY SHOPIFY WEBHOOKS

As a Shopify app we process the privacy webhooks required by Shopify:

  • customers/data_request: access request from an end customer

  • customers/redact: deletion request regarding an end customer

  • shop/redact: deletion of all store data 48 hours after uninstallation

We handle these requests automatically and delete or disclose the affected data within the required deadlines.

5. RETENTION PERIOD

We store merchant data for as long as the app is installed. After uninstallation we delete store data, access tokens and popup configurations within 48 hours of receiving the shop/redact webhook, unless statutory retention obligations apply. Billing data is retained for the duration of statutory retention periods.

PART 3: PROCESSING OF SHOP VISITOR AND END CUSTOMER DATA

1. ROLES

For the processing of data of visitors and end customers of a store, the respective merchant is the controller within the meaning of Art. 4 (7) GDPR. The operator of PopUplift processes this data as a processor under Art. 28 GDPR on the basis of the data processing agreement with the merchant (available at https://popuplift.com/dpa).

If you are a shop visitor and have questions about the processing of your data, please contact the operator of the store in which you saw the popup.

2. WHICH DATA IS PROCESSED

When a store with PopUplift enabled is loaded, a small script (launcher) is delivered. It processes:

  • A pseudonymous visitor ID stored in the browser

  • Event data: popup impression, interactions, dismissal, signup

  • Technical data: page URL, device type, browser, scroll depth, time on page

  • On signup in the popup: email address, opt-in status, quiz answers

  • On redemption of a discount code: the generated code and the timestamp

  • For revenue attribution: order number, order value and timestamp from Shopify, if an order follows a popup signup

3. PURPOSES OF PROCESSING

  • Display and personalization of popups based on visitor behavior

  • Collection of email addresses for the merchant's newsletter

  • Creation and assignment of discount codes

  • Transmission of signup data to the Klaviyo account connected by the merchant

  • Measurement of opt-in rate, revenue attribution and statistics for the merchant

  • Optimization of popup delivery using AI based on aggregated interaction data

4. RETENTION PERIOD

  • Event data (views, clicks, signups) is deleted after 180 days.

  • Data of anonymous visitors without signup is deleted after 90 days.

  • Signup data (email, quiz answers) is stored for as long as the app is installed in the store and is deleted on instruction of the merchant or after uninstallation.

5. RECIPIENTS AND PROCESSORS

We use the following sub-processors to operate PopUplift. Data processing agreements under Art. 28 GDPR are in place with all providers. The full list including processing locations is available in Annex 3 of the data processing agreement at https://popuplift.com/dpa.

  • Supabase Pte. Ltd. (database hosting)

  • Railway Corporation (hosting of the app backend)

  • Cloudflare, Inc. (DNS, CDN, network security)

  • Anthropic PBC (AI technology for popup creation and optimization)

  • OpenAI Ireland Ltd. (AI technology for popup creation and optimization)

Where data is transferred to third countries such as the USA or Singapore, this is based on a certification under the EU-US Data Privacy Framework (Art. 45 GDPR) or on the standard contractual clauses of the EU Commission (Art. 46 (2) (c) GDPR).

DATA PROCESSING OF BUSINESS PARTNERS AND CUSTOMERS

1. Performance of contractual obligations (Art. 6 (1) (b) GDPR)

To process our contracts we process master data such as first and last name, billing address and billing details of the contact persons of our customers.

2. Compliance with legal obligations (Art. 6 (1) (c) GDPR)

This includes, for example, compliance with retention and identification obligations under tax law and data processing in the context of requests from authorities.

3. Legitimate interests (Art. 6 (1) (f) GDPR)

We process the contact details of contact persons at customers, prospects, suppliers and other business partners for communication by email, phone and mail. The legitimate interest lies in conducting or initiating the business relationship.

4. Retention period

Personal data is retained for as long as necessary to fulfil the purposes described above and, beyond that, for the duration of statutory retention obligations.

YOUR RIGHTS

Under Art. 15 GDPR you have the right to obtain, free of charge and upon request, information about the personal data stored about you. Where the legal requirements are met, you also have the right to rectification (Art. 16 GDPR), erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR). If you have provided the processed data yourself, you have the right to data portability under Art. 20 GDPR.

Where processing is based on Art. 6 (1) (e) or (f) GDPR, you have the right to object under Art. 21 GDPR.

Where processing is based on consent under Art. 6 (1) (a) GDPR, you can withdraw your consent at any time with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Austria is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Vienna, https://www.dsb.gv.at

Note for shop visitors: Please direct requests concerning data we process as a processor on behalf of a merchant to the respective merchant. We support the merchant in responding.

NO AUTOMATED DECISION-MAKING

We do not carry out automated decision-making with legal effect or profiling within the meaning of Art. 22 GDPR. Popup personalization serves exclusively to select and display content.

PROVISION OF DATA

Unless stated otherwise in the previous sections, the provision of personal data is neither required by law or contract nor necessary for the conclusion of a contract. If you do not provide your personal data, we may be unable to answer your inquiries or provide the app.