1. Introduction and Scope
PopupReach Inc. ("PopupReach," "we," "our," or "us") operates a B2B SaaS platform that enables local businesses and franchise operators to launch real-time promotional campaigns, track QR-code redemptions, and build owned customer audiences. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our platform, website (popupreach.com), and related services (collectively, the "Services").
This Privacy Policy applies to:
- Merchant users — business owners, franchise operators, and their authorized employees who access the PopupReach merchant dashboard
- Consumer participants — individuals who claim deals, redeem QR codes, or voluntarily provide contact information through a merchant's PopupReach campaign
- Visitors to popupreach.com
By using our Services, you acknowledge that you have read, understood, and agree to the collection and use of information in accordance with this Privacy Policy.
2. Information We Collect
2.1 Information You Provide Directly
From Merchants:
- Account registration information: name, email address, business name, phone number, business address, business category
- Payment information: billing details processed and stored by Stripe (PopupReach does not store credit card numbers or full payment card data)
- Campaign content: offer text, pricing, time windows, and targeting parameters you create
- Profile and settings: business hours, slow-period preferences, notification preferences
- Communications: messages, support requests, and feedback you send to us
From Consumer Participants:
- Phone number (optional): provided voluntarily at the point of redemption, with explicit opt-in consent, to join a merchant's owned customer audience
- Claim and redemption activity: the fact that a deal was claimed or redeemed at a specific location and time
PopupReach does not require consumer participants to create accounts. Phone number capture is always optional and requires explicit affirmative consent at the time of collection.
2.2 Information Collected Automatically
- Device information: browser type, operating system, device identifiers, screen resolution
- Log data: IP address, pages visited, time spent on pages, referring URLs, access timestamps
- Cookie and tracking data: session cookies necessary for platform functionality (see Section 7 — Cookies)
- Campaign performance data: impressions, clicks, claims, redemptions, conversion rates (aggregated and merchant-attributed)
- Location data: approximate location derived from IP address for geotargeting purposes; we do not collect precise GPS coordinates without explicit permission
2.3 Information from Third Parties
- Clerk (authentication provider): user identity verification and session management
- Stripe (payment processor): subscription status, billing cycle, and payment confirmation (not full card data)
- Meta and Google Ads (when integrated): campaign performance metrics from ads run through the platform
- Moneris (future integration): transaction-level signals for campaign triggering, subject to separate consent and data processing agreements
3. How We Use Your Information
3.1 To Provide and Improve the Services
- Create and manage merchant accounts and subscription plans
- Enable campaign creation, distribution, and performance tracking
- Generate claim codes, QR codes, and redemption verification
- Process subscription payments through Stripe
- Deliver platform analytics to merchants (claims, redemptions, conversion rates, weekly summaries)
- Diagnose and fix technical problems
- Develop new features and improve existing functionality
3.2 To Build Merchant-Owned Audiences
When a consumer participant opts in at redemption, their phone number is stored and attributed to the specific merchant whose campaign they redeemed. This data belongs to the merchant and is held by PopupReach as a data processor on the merchant's behalf. Merchants may use this data to send future promotional messages directly to opted-in customers, subject to applicable anti-spam law (CASL) requirements.
Consumer phone numbers collected through the PopupReach platform are owned by the merchant, not by PopupReach. PopupReach does not use consumer phone numbers for its own marketing purposes.
3.3 For Communications
- Send transactional emails (account confirmation, password reset, subscription receipts)
- Send platform notifications (new claims, redemptions, campaign performance summaries)
- Send service updates, security notices, and policy changes
- With your consent, send product updates, new features, and promotional offers for PopupReach services
3.4 For Legal and Business Purposes
- Comply with applicable laws and regulations, including PIPEDA, CASL, and provincial privacy legislation
- Enforce our Terms of Service and other agreements
- Prevent fraud, abuse, and unauthorized access
- Protect the rights, property, and safety of PopupReach, our merchants, and the public
- Respond to legal requests, court orders, and regulatory inquiries
3.5 Analytics and Platform Improvement
We use aggregated and de-identified data to understand usage patterns, improve the platform, and develop new features. Aggregated data does not identify individual merchants or consumers.
4. Legal Basis for Processing (PIPEDA)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), PopupReach collects, uses, and discloses personal information only with knowledge and consent, except where permitted or required by law. The specific bases for our processing activities are:
- Consent: We obtain express consent for optional data collection (consumer phone number at redemption) and implied consent for necessary processing activities (merchant account data required to deliver the Services)
- Contractual necessity: Processing merchant personal information is necessary to deliver the Services under our Terms of Service
- Legitimate interest: We process certain technical and operational data (log data, device information) to maintain platform security and performance
- Legal obligation: We may process and disclose personal information to comply with applicable law
5. Data Sharing and Disclosure
5.1 Service Providers (Data Processors)
We share personal information with trusted third-party service providers who process data on our behalf under contractual data processing agreements:
- Clerk — user authentication and identity management
- Stripe — payment processing and subscription management
- Supabase — cloud database and data storage (hosted on AWS infrastructure)
- Vercel — web application hosting and delivery
- Railway — backend API hosting
- Meta Platforms / Google LLC — advertising campaign delivery (campaign content only, no personal account data shared without separate consent)
PopupReach does not sell personal information to third parties. We do not share personal information with data brokers, advertisers, or marketing partners for their independent use.
5.2 Merchant Data Sharing
Merchants receive the following data relating to their campaigns: aggregate claim and redemption counts, conversion rates, daily and weekly performance summaries, opted-in consumer phone numbers (associated with their specific campaigns only). Merchants are responsible for handling consumer personal information in compliance with PIPEDA, CASL, and any other applicable privacy legislation.
5.3 Business Transfers
In the event of a merger, acquisition, financing, or sale of all or a portion of PopupReach's assets, personal information may be transferred to the acquiring party. We will notify affected individuals via email or platform notification before personal information becomes subject to a different privacy policy.
5.4 Legal Disclosure
We may disclose personal information if we believe in good faith that such disclosure is necessary to: comply with applicable law or legal process; respond to lawful requests by government authorities including law enforcement; protect the rights, property, or personal safety of PopupReach, our users, or the public; or enforce our Terms of Service.
6. Data Retention
- Merchant account data: retained for the duration of the active subscription plus 36 months following account closure, to comply with financial and legal record-keeping requirements
- Campaign data and analytics: retained for 24 months from campaign creation date
- Consumer phone numbers (opted-in): retained until the merchant requests deletion or the merchant account is closed, whichever comes first
- Payment records: retained for 7 years as required by Canadian financial regulations
- Log data and technical records: retained for 12 months
- Support communications: retained for 24 months from the date of resolution
Merchants may request deletion of their account and associated data at any time by contacting us at privacy@popupreach.com. We will complete deletion within 30 days of a verified request, except where retention is required by law.
7. Cookies and Tracking Technologies
PopupReach uses the following types of cookies and tracking technologies:
- Strictly necessary cookies: required for platform functionality (session management, authentication, security). Cannot be disabled without impairing core Services.
- Performance cookies: used to measure how merchants interact with the platform (page views, click patterns, feature usage). Aggregated and anonymous.
- No advertising cookies: PopupReach does not use third-party advertising cookies or cross-site tracking technologies on the merchant dashboard or consumer claim flow.
The consumer claim flow (popupreach.com/claim/[id]) uses only strictly necessary cookies. No advertising pixels, retargeting scripts, or third-party analytics are embedded in the consumer-facing claim or redemption pages.
8. Data Security
We implement appropriate technical and organizational security measures to protect personal information against unauthorized access, disclosure, alteration, and destruction, including:
- Encryption in transit: all data transmitted between your browser and PopupReach servers is encrypted using TLS 1.2 or higher
- Encryption at rest: personal data stored in Supabase (PostgreSQL) is encrypted at rest
- Access controls: role-based access controls ensure PopupReach employees and contractors access only the data necessary for their specific job functions
- Authentication: Clerk-powered authentication with support for multi-factor authentication
- Vulnerability management: regular security reviews and dependency updates
- Incident response: a documented security incident response plan with notification procedures
No method of electronic transmission or storage is 100% secure. While we use commercially reasonable measures to protect your information, we cannot guarantee absolute security.
9. Your Privacy Rights
Under PIPEDA and applicable provincial privacy legislation, you have the following rights with respect to your personal information:
- Right of access: You may request access to the personal information we hold about you and receive a copy within 30 days
- Right to correction: You may request correction of inaccurate or incomplete personal information
- Right to withdrawal of consent: You may withdraw consent for non-essential processing at any time, subject to legal and contractual restrictions
- Right to deletion: You may request deletion of your personal information subject to our legal retention obligations
- Right to complain: You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca
To exercise any of these rights, contact us at privacy@popupreach.com with the subject line "Privacy Rights Request." We will acknowledge your request within 5 business days and respond fully within 30 days.
10. Consumer Participant Rights
If you are a consumer who claimed a deal or provided your phone number through a PopupReach merchant campaign:
- You may opt out of future messages from the merchant by replying STOP to any SMS or by contacting the merchant directly
- You may contact us at privacy@popupreach.com to request confirmation of what personal information we hold about you and request its deletion
PopupReach acts as a data processor for consumer personal information on behalf of the merchant. Requests relating to merchant-specific data use should be directed to the merchant in the first instance.
11. Cross-Border Data Transfers
PopupReach stores data on servers operated by Supabase (hosted on Amazon Web Services infrastructure in Canada and the United States), Vercel (United States), and Railway (United States). By using our Services, you acknowledge that your personal information may be transferred to, stored in, and processed in countries outside of Canada. We ensure that such transfers are subject to appropriate safeguards, including contractual data processing agreements with our service providers.
12. Children's Privacy
The PopupReach platform is intended for use by business operators and is not directed at individuals under the age of 18. We do not knowingly collect personal information from individuals under 18. If you believe we have inadvertently collected such information, please contact us immediately at privacy@popupreach.com and we will delete it promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Effective Date" at the top of this document
- Post a notice on the PopupReach dashboard and website
- Send an email notification to registered merchant account holders at least 14 days before the changes take effect
Your continued use of the Services after the effective date of the updated Privacy Policy constitutes acceptance of the changes. If you do not agree to the changes, you must discontinue use of the Services before the effective date.
14. Contact Us
For all privacy-related inquiries, requests, or complaints:
- Privacy Officer: PopupReach Inc.
- Email: privacy@popupreach.com
- Address: Winnipeg, Manitoba, Canada
- Response time: Within 5 business days for acknowledgement; 30 days for full response
For complaints that are not resolved to your satisfaction, you may contact the Office of the Privacy Commissioner of Canada:
- Website: priv.gc.ca
- Phone: 1-800-282-1376
- Address: 30 Victoria Street, Gatineau, Quebec K1A 1H3