Privacy Policy
Effective Date: September 23, 2026
This Privacy Policy explains how PopupNeko ("we", "our", or "us") handles information when you use our website, dashboard, popup script, integrations, public verification pages, and related services (the "Service").
1. Information We Collect
We collect the information needed to provide PopupNeko, including:
- Account information, such as your email address, display name, account image, authentication records, and preferences
- Project and integration information, such as project names, domains, website icons, popup settings, and integration settings
- Content and event information, such as product names and images, reviews, approximate customer city or country, event type, provider, and transaction time
- Billing information handled securely by Stripe, such as subscription plan, billing email, payment status, invoices, and receipts. Stripe processes payment and payment-method details directly; PopupNeko does not store full card or bank-account numbers or payment security codes
- Usage and communications, such as website page views, referring pages, campaign parameters, browser and device information, interactions with website controls, aggregated popup impressions and clicks, script checks, feature usage, service logs, and information you provide when contacting us
2. Integrations, Popup Visitors, and Public Content
PopupNeko uses connected merchant credentials for documented read operations that validate integrations, retrieve products, confirm eligible transactions, and provide analytics or popup events. Some providers issue technically broader credentials, but we do not use them to create, change, refund, or process transactions. Credentials are encrypted before storage and are not sent to the public popup script. Use the most limited credential your provider supports and rotate or remove it if exposed.
Provider responses may contain more data than we need. We extract limited information required by the Service and do not store customer names, email addresses, phone numbers, full street or billing addresses, or payment-method details as popup events.
The popup script receives sanitized display information and may use session storage to remember impression limits for the current session or page. Popup analytics are aggregated by project, date, action, and event type and do not include visitor's name, email address, full page URL, or advertising identifier. Infrastructure providers may still process standard request details such as IP address, user agent, and request time to deliver and secure the Service.
Depending on merchant settings, public popups may show an approximate customer location, product, event time, provider, review excerpt, rating, reviewer attribution, or review link. Public verification pages may show a merchant's name, domain, website icon, script status, verification sources, and confirmation dates. Merchants are responsible for their settings, display rights, notices, and any consent required on their websites.
3. How We Use and Share Information
We use information to authenticate users; operate, secure, and improve PopupNeko; validate integrations; provide popup, product, review, analytics, and verification features; manage projects and accounts; process subscriptions, receipts, and payment reminders; troubleshoot problems; prevent abuse; answer requests; comply with law; and enforce our Terms of Service.
PopupNeko does not sell personal information, use Google Sign-In information for advertising, or use merchant customer data for targeted advertising.
We share limited information with service providers to operate, secure, support, or improve PopupNeko, process billing, send transactional messages, comply with law, or protect others. We may also disclose information during a merger, acquisition, financing, or sale of the Service, subject to appropriate protections.
4. Service Providers and International Processing
Our main service providers include:
- Vercel for hosting and application infrastructure
- Supabase for authentication, database, and file storage
- Google for Google Sign-In to create and access your account using your name, email address, and profile picture. It does not access your other Google services
- Stripe for PopupNeko subscription billing and payment processing
- Cloudflare for popup infrastructure, delivery, and Turnstile login security checks
- Upstash for temporary event caching, aggregated analytics, and security rate limiting
- PostHog for website traffic, campaign attribution, and interaction analytics. Our current integration excludes account, authentication callback, API, and checkout paths and does not use session replay
- Resend for transactional billing emails
Merchants may also connect services such as Stripe, Lemon Squeezy, Polar, and Chrome Web Store, which process information under their own terms and policies.
PopupNeko and these providers may process information outside your country, where privacy and government-access laws may differ. We use reasonable safeguards appropriate to the information and services involved.
5. Cookies and Storage
PopupNeko uses necessary authentication cookies to keep users signed in and protect sessions. The dashboard may use cookies or local storage for interface and preview preferences, and the installed popup may use session storage for impression limits. PostHog uses cookies or local storage to distinguish anonymous visits and attribute website traffic and interactions to a session or campaign. We do not use this information for behavioural advertising.
6. Retention and Security
We keep account, project, product, review, integration, and subscription records while they are active and for a reasonable period afterward for backup recovery, security, billing, disputes, legal compliance, or legitimate operations.
- Encrypted credentials are removed when their integration, project, or account record is deleted, subject to limited backup retention.
- Cached provider events expire after no more than 24 hours.
- Temporary rate-limit records expire automatically after their security window.
- Aggregated analytics are retained for approximately 62 days as daily data, 8 weeks as weekly data, and 25 months as monthly data.
- Website analytics are retained according to our PostHog project settings and operational needs.
- Billing and transaction records may be retained for financial, tax, fraud-prevention, and legal purposes.
We use reasonable safeguards including access controls, encryption, secure transport, project ownership checks, and limits on browser-facing data. No online service can guarantee perfect security. Protect your account and rotate credentials or contact us if you suspect unauthorized access.
7. Your Choices
You can update account and project information, remove integrations, rotate credentials, delete projects, control displayed content, remove the popup script, and manage or cancel your subscription. Removing the script does not delete your account.
You may contact us to request access to, correction of, or deletion of personal information associated with your account. We may verify your identity and retain information where permitted or required for billing, security, fraud prevention, disputes, or legal compliance.
For privacy questions, requests, or complaints, email contact@popupneko.com.
8. Changes to This Policy
We may update this Policy as the Service, providers, or applicable requirements change. We will post a revised effective date and provide additional notice when a change is material.