Legal

Privacy Policy

Effective 31 July 2026

This policy explains what we collect, why, and what you can do about it. It covers two different groups: people who hold a Bonpopup account, and visitors to websites where an account holder has installed a popup.

1. Data we collect from account holders

When you create and use an account, we store your account details, credentials (hashed), optional profile details, sign-in provider, and your content.

2. Data collected when a popup is displayed

The embed engine records event type, domain, device type, browser, country, and a short-lived session identifier.

3. Why we process this data

To create your account, store and serve popups, provide analytics, respond to support, and protect against abuse.

4. Cookies and similar technologies

We use a session cookie for authentication. The embed engine may store data to avoid repeated popup display.

5. Sharing

We do not sell personal data. We share only with service providers needed to run Bonpopup.

6. Retention

Account data is kept while active. Events are retained for historical reporting. Deletion removes all attached data.

7. Security

Passwords are hashed, admin access is role-restricted, and popup config is rendered without innerHTML injection.

8. Your rights

You may have the right to access, correct, export, or delete your personal data depending on your jurisdiction.

9. Children

Bonpopup is a business tool not directed at children. We do not knowingly collect data from anyone under 16.

10. Changes

Material changes will be notified before taking effect. The effective date always reflects the current version.

11. Contact

For any privacy question, reach us through the contact page.

This document is a general template and is not legal advice. If you operate in the EU, UK, or California, have a qualified lawyer confirm it meets GDPR, UK GDPR, or CCPA requirements before publishing.