Privacy Policy
Effective date: 11 August 2026
Last updated: 11 August 2026
This policy explains how Lungu Andrei-Leonard PFA, trading as PopupForge, processes personal data when you visit the PopupForge website, create an account, use the PopupForge dashboard or submit information through a customer's PopupForge modal.
1. Who is responsible for your data
For account, billing and product-usage data, Lungu Andrei-Leonard PFA, trading as PopupForge, acts as the data controller. For information submitted through a modal created by a PopupForge customer, that customer is the controller and PopupForge acts as its processor.
Privacy questions and requests can be sent to privacy@getpopupforge.com.
2. Data we collect
- Account data such as name, email address, authentication provider and organisation membership.
- Billing identifiers and subscription status. Payment card details are processed by Stripe and are not stored by PopupForge.
- Modal configurations, authorised domains, leads, notes, webhook settings and analytics events.
- Technical data such as IP address, browser information, page path, referrer, security events and diagnostic logs.
- Content supplied to the AI generator, including a public website URL or screenshots.
3. Why we use data
We process data to provide and secure the service, authenticate users, publish modals, collect leads, calculate usage, process subscriptions, send requested notifications, provide support, prevent abuse and comply with law. Where required, analytics or marketing processing is based on consent.
4. Service providers and international transfers
PopupForge uses infrastructure and service providers for hosting, database storage, authentication, payments, email delivery, abuse prevention, AI generation and error monitoring. These providers process only the data necessary for their service and may process data outside your country under applicable transfer safeguards.
5. Retention and security
Account and customer content are retained while the account is active and for a limited period afterwards where needed for backups, fraud prevention, legal obligations or dispute resolution. Customers control the retention of leads they collect. PopupForge uses access controls, encrypted transport, signed sessions, rate limits and restricted server-side data access, but no online service can guarantee absolute security.
6. Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. Account holders can use the export and deletion controls in the product. If your data was submitted to a customer's modal, contact that customer first; PopupForge will assist them as required by the DPA.
7. Cookies and changes
PopupForge uses essential cookies for authentication, security and session continuity. We may update this policy as the product or law changes and will publish the revised effective date here.