PrimePopup legal
Privacy policy
Effective August 9, 2026
About this policy
This policy explains how PrimePopup processes information when a Shopify merchant installs the app, configures an offer, or receives consent-aware storefront analytics. The merchant's own privacy policy continues to govern its relationship with shoppers.
Information we process
We may process the following merchant and store information:
- Shopify shop domain, installation state, secure Shopify session credentials, authenticated merchant or staff account data supplied by Shopify, offer settings, and uploaded offer images.
- App diagnostics and support information that a merchant chooses to send to us.
After Shopify indicates that analytics consent is available, the app may process pseudonymous visitor and session identifiers; bounded event types and timestamps; page paths without query strings; referrer host and campaign attribution; coarse device, browser, and operating-system families; approximate city, region, and country supplied by our hosting provider; and cart or checkout totals, currency, item counts, checkout country, and applied discount code when available.
Information we intentionally exclude
PrimePopup is not designed to collect shopper names, email addresses, phone numbers, postal addresses, payment details, customer or order IDs, cart or checkout tokens, raw IP addresses, raw user-agent strings, full URLs, or search terms. The demo form in the popup builder does not send or save entries.
How we use information
- Deliver and configure offers selected by the merchant.
- Produce consent-aware, aggregated performance reporting.
- Protect the service, diagnose faults, and prevent abuse.
- Respond to support and legal requests.
We do not sell personal information or use storefront activity for third-party advertising.
Service providers and international processing
We use Shopify to operate the app, Vercel for application hosting, and Supabase for managed database and image-storage infrastructure. When a merchant selects a Google Fonts family, Google serves the font files to the merchant preview and storefront. Uploaded images are re-encoded before storage so embedded metadata is not retained. These providers may process data in countries other than where the merchant or shopper is located, subject to their contractual and legal safeguards.
Retention and deletion
Raw storefront event and session records are retained for up to 90 days. Offer configuration and necessary aggregated records may be retained while the app remains installed. When Shopify sends a valid uninstall or shop-redaction request, we delete the affected shop's data from active application systems. Backup copies may remain temporarily until the normal backup lifecycle completes.
Security
We use access controls, tenant-scoped database operations, signed Shopify requests, input validation, and server-side secret handling. No online service can guarantee absolute security, but we work to reduce access and collection to what the service needs.
Your choices and rights
Merchants can uninstall PrimePopup to stop future processing. Shoppers should normally submit privacy requests to the Shopify merchant they visited; Shopify will forward applicable requests to installed apps. You may also contact us about access, correction, deletion, or another privacy question.
Changes and contact
We may update this policy as the service or legal requirements change. The effective date above identifies the current version. For questions, email support@primepopups.com.