Privacy policy
Last updated . This policy explains what personal data Airo (“we”, “us”) collects, why, and the choices you have. It is written to be read, not skimmed past.
1. Who this policy covers
We handle personal data in three distinct roles, and your rights depend on which one applies to you:
- Website visitors — people reading this site or using the contact form.
- Customers — people who create an account to use Airo Popups on their own stores, and the team members they invite.
- Shoppers — visitors to our customers’ stores who see, dismiss or submit a popup. For shopper data, the store owner is the data controller and we act as their processor under the terms of service and our data-processing terms. Requests about that data should go to the store; we help them respond.
2. Data we collect from website visitors
This website sets no advertising or cross-site tracking cookies. Our server logs record the IP address, user agent, requested page and time of each request for security and capacity planning, and are kept for a limited period. If you use the contact form we collect the name, email address, company and message you enter, and use them solely to reply.
3. Data we collect from customers
- Account data: name, email address, password (stored hashed), two-factor secrets and recovery codes (stored encrypted), avatar, and workspace and site details such as the store domain.
- Billing data: plan, invoices and payment status. Card details are entered directly with our payment processor and never touch our servers; we store only a token, the last four digits and the card brand.
- Usage data: the campaigns, templates, targeting rules and integrations you configure, and product activity such as sign-in sessions and audit-relevant actions.
- Integration credentials: API keys you provide for email or SMS platforms. These are stored server-side, used only to deliver leads, and never exposed to the browser or the widget.
4. Data processed on customers’ stores (the widget)
When a store installs the widget, it processes the following on the store owner’s behalf:
- Interaction events — impressions, dismissals, clicks and submissions, with the page URL, referrer, device type, browser and coarse location (country and region derived from IP; the IP itself is not stored with events).
- Submitted data — the email address, phone number, quiz answers and consent choices a shopper enters, plus the campaign and variant that captured them.
- Order data — when a store sends orders for attribution: an order identifier, total, currency, timestamp and the email address used at checkout.
- First-party storage — a small first-party identifier and campaign state kept in the shopper’s browser so frequency caps and “don’t show again” work. It is not shared across stores and is not used for advertising.
The store decides what to ask, what consent language to show and how long to keep leads. We provide the tools — consent checkboxes, suppression, export and deletion — for the store to meet its own obligations.
5. How we use data
- To provide, secure and support the service, including delivering leads to the integrations a customer connects.
- To bill for paid plans and enforce plan quotas.
- To send transactional messages such as invitations, password resets, quota notices and security alerts. Product news is opt-in and every message has an unsubscribe link.
- To understand aggregate usage so we can improve the product. We do not sell personal data and we do not use shopper data to build profiles for anyone other than the store that collected it.
6. Who we share data with
We use a small number of subprocessors to run the service: cloud hosting and storage, a payment processor, a transactional email provider and error monitoring. Each is bound by a written agreement to process data only on our instructions. Leads are also sent to any third-party platform a customer explicitly connects (for example an email marketing service); that transfer is at the customer’s direction and governed by that platform’s terms. We may disclose data where the law requires it or to protect the rights and safety of our users.
7. Retention
Account data is kept for as long as the account exists and for a short period afterwards to allow recovery. Leads and events are kept for as long as the customer chooses; deleting a site or workspace deletes its data on a fixed schedule. Server logs and backups expire automatically. Billing records are kept for as long as tax and accounting rules require.
8. Security
Data is encrypted in transit and at rest. Access inside the company is limited to people who need it to do their job and is logged. Customers can protect their accounts with two-factor authentication, review active sessions and rotate site keys and secrets at any time. No system is perfectly secure; if we discover a breach that affects you we will tell you and the relevant authorities without undue delay.
9. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete personal data we hold about you, and to object to certain processing. Customers can exercise most of these directly in the dashboard; for anything else, or if you are a website visitor, write to support@airopopups.com. If you are a shopper, please contact the store you interacted with; we will assist them. You also have the right to complain to your local data-protection authority.
10. International transfers
We may process data in countries other than your own. Where we do, we rely on recognised safeguards such as standard contractual clauses and equivalent mechanisms, and we choose subprocessors that offer the same.
11. Children
The service is for businesses and is not directed at children. We do not knowingly collect personal data from anyone under the age of digital consent in their jurisdiction. If you believe we have, tell us and we will delete it.
12. Changes to this policy
We will post any changes here and update the date at the top. If a change materially affects how we use personal data, we will notify customers by email before it takes effect.
13. Contact
Questions about privacy or this policy: support@airopopups.com, or use the contact form and choose “Something else”.