Popup Pop
Privacy · Popup Pop

What Popup Pop stores,
and what it never does.

Popup Pop is a Shopify app that displays a popup on your storefront. It shows the message you wrote to whoever visits your store. It does not need to know anything about those people, and it is built so that it never does.

No customer data, at any point

Popup Pop holds no personal data about your customers. No names, no email addresses, no orders, no browsing history, no IP addresses, no identifiers of any kind.

This is not only a promise: the app requests no permission at all. Its list of access scopes is empty, so it is technically unable to read your products, your orders or your customers, whatever it might be asked to do. You can see this for yourself on the install screen, which lists nothing to approve.

Popup Pop sets no cookie, runs no analytics, and counts no impressions. It does not know how many people saw your popup, and neither do we.

What stays in the visitor's browser

So that the same popup is not shown twice to someone who has already closed it, the script writes a single entry to the visitor’s sessionStorage, named popup_pop_shown_…. Its value is the digit 1.

sessionStorage is erased by the browser as soon as the tab is closed. Nothing survives the visit, nothing identifies anyone, and nothing is ever sent to our servers.

What the app stores about your store

  • Your store domain, used to identify which settings belong to you.
  • Your popup content: the title, the message, the button label and the promo code you write.
  • Your design settings: gradient colors, text colors, type sizes, alignment, font and glass effect.
  • Whether the popup is currently active.
  • An access token issued by Shopify when you install the app. It is what identifies your store, and it stops working when you uninstall.

All of it is content you wrote yourself. None of it describes a person.

Where it is hosted

The application runs on Vercel and the database is hosted by Neon, both in the United States, in the AWS us-east-1 region in Virginia. Traffic between your store, the app and the database is encrypted in transit. No data is transferred to any other processor, and Popup Pop sends nothing to third-party services.

If you are in the European Union, the only data leaving it is the store data listed above — never anything belonging to your customers.

How long it is kept, and how it is deleted

When you uninstall the app, Shopify notifies us and your session and popup settings are deleted from the database straight away. The access token stops working at the same moment, and the script is no longer served to your storefront.

When Shopify asks us to erase a store — which it does after an uninstall, or on your request — everything belonging to that store is deleted. Popup Pop implements Shopify’s mandatory compliance webhooks, including shop/redact, customers/redact and customers/data_request. The two customer requests return nothing, because there is nothing to return.

Your rights

You may ask at any time what is stored about your store, request a copy, ask for it to be corrected, or ask for it to be erased. Write to clemenceau.ia@gmail.com and you will have an answer within thirty days, usually much sooner.

If this policy changes in a way that affects you, the date below changes and the new version is published here before it takes effect.

Contact

Questions about this policy, or about the data held for your store: clemenceau.ia@gmail.com

Last updated 20 August 2026