Legal
Privacy policy
What we collect, why we hold it, how long it stays, who else can see it and how to get it out or have it deleted. Written to be read, not to be survived.
Last updated 21 August 2026
This is a plain-language draft written by the PopzIQ team. It has not been reviewed by a lawyer and is published so you can see exactly how we operate. It will be replaced by a reviewed version, and we will say so on this page when that happens.
01Who we are
PopzIQ is a customer-journey product: forms and popups, one customer record, an event stream and a developer API. This policy covers the PopzIQ website at popziq.com and the PopzIQ application.
Two different relationships run through this policy. When you sign up for a PopzIQ workspace, we decide how your account data is handled and we are the controller of it. When your visitors submit one of your forms, you decide what to collect and why. We hold that data on your behalf as a processor.
Questions about anything here go to privacy@popziq.com and we answer them.
02What we collect
Your account. The name and email you sign up with, your workspace name and settings, your role and the billing details Stripe returns to us. We never see or store your card number.
Your customers. Whatever your forms collect, plus the identity we resolve it to. An email address is the identity key. Alongside each contact we store consent status, where the consent came from and when it was given, and unsubscribe or suppression state.
Your event stream. Append-only rows recording what happened: a form viewed, a submission stored, a contact created, consent granted, a webhook delivered. These rows are the audit trail and they are never edited.
Operational data. Request logs, error reports and delivery logs for webhooks and for email sends. These carry timestamps, request identifiers and enough context to debug a failure.
This website. The marketing site sets no analytics or advertising cookies and asks you for nothing. Creating an account happens in the product app, and what we store then is the account data described above.
03Why we hold it and on what basis
- To provide the product you asked for. Running your forms, resolving contacts, recording events and delivering webhooks. The legal basis is performance of our contract with you.
- To keep the service safe and working. Rate limiting, abuse prevention, debugging and capacity planning. The legal basis is our legitimate interest in a service that stays up and is not abused.
- To meet legal duties. Tax and accounting records plus responding to lawful requests. The legal basis is legal obligation.
- To tell you about the product, if you asked us to. The legal basis is your consent. You can withdraw it with the unsubscribe link in any message or by emailing privacy@popziq.com.
We do not sell personal data. We do not share it with advertising networks. We do not use your customers' data to train models.
04Where models are involved
Some parts of the product use language models to help you build faster. Where that happens, personal fields are masked before the request leaves our systems. Any new field that describes a person goes through a privacy classification before it is allowed into the schema at all.
Model providers act as processors for us and are not permitted to train on what we send them.
05Who else can see it
These are the companies that process data for us. Each one is bound by a contract to handle it only on our instructions.
- Cloudflare for Workers, R2 object storage and Queues: the public API, the embed and form delivery.
- Neon for managed Postgres: the database itself.
- Vercel for hosting the application interface and this website.
- Amazon Web Services for SES and SNS, which carry email sending and delivery notifications. Nothing else of ours runs on AWS.
- Stripe for payments and billing.
The current list is also published at popziq.com/security. If it changes, that page and this one change with it.
06Where the data sits
Our processors operate globally, so your data may be processed outside the country you are in. Transfers out of the European Economic Area and the United Kingdom rely on Standard Contractual Clauses with each processor.
You cannot pin a workspace to a region today. If regional residency is a requirement for you, tell us and it will be weighed against the rest of the roadmap.
07How long we keep it
- Workspace content stays for as long as your workspace is open.
- After you close a workspace we delete its content within 30 days, except where a law requires us to keep a record longer.
- A deleted contact leaves a tombstone: enough to stop a later import from quietly re-creating that person and nothing that identifies them.
- Operational logs are kept for 30 days and webhook delivery logs for 30 days, so you can debug a failure after the weekend.
- Billing records are kept as long as tax law requires.
08Your rights and the rights of your customers
If you are in the EEA, the UK or a similar regime you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to some processing, ask us to restrict it and withdraw consent at any time. Email privacy@popziq.com and we answer within one month.
Two of those you do not need to email us for. Export takes your whole workspace out in one click. Deletion is built into the product and sticks.
If one of your customers contacts us directly about data in your workspace, we pass the request to you rather than acting on it ourselves, because that data is yours to decide about.
If you think we have handled your data badly, please tell us first. You also have the right to complain to your data protection authority.
09How it is protected
Every query is scoped to a workspace id taken from your session or your API key, never from client input. API keys are stored hashed and shown once. Webhooks are signed. Events are append-only and cannot be edited or deleted, including by us.
The mechanisms are described in full at popziq.com/security, including what we do not have yet. If you find a weakness, email security@popziq.com.
11Children
PopzIQ is a business product and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child's data has reached us, email privacy@popziq.com and we will remove it.
12Changes to this policy
When this policy changes we update the date at the top. If a change materially affects how we handle your data, we email workspace owners before it takes effect rather than relying on you to notice.
13Contact
Privacy questions and data requests: privacy@popziq.com. Security reports: security@popziq.com. Anything else: hello@popziq.com.