Zoomifi - Sales Popups Privacy Policy
Last updated: September 24, 2026
Zoomifi - Sales Popups (“the App”) provides sales notification and social-proof popups (“the Service”) on your Shopify storefront. This Privacy Policy describes how personal information is collected, used, and shared when you install or use the App in connection with your Shopify-supported store.
Personal information the app collects
When you install the app, it asks Shopify for read access to your orders and products. We use your orders to build sales popups, and your products to show product names, images and links. You add the popups to your storefront by turning on the Sales Pops app embed in your theme editor. Stores that installed an older version may still load our script through a script tag until they switch to the app embed.
About you: your store name and domain, and the name and email of the store owner or staff member who installs the app, as provided by Shopify. We also keep your plan and billing status, and any messages you send us.
About your customers, from your orders: order number, first name, city, region, country, products and order totals. We don't request or keep your customers' email addresses or phone numbers. We delete this order data 60 days after the order date.
Popups show other shoppers the customer's city, region and country, the product and when it was bought. They show the customer's first name only if Hide Buyer First Names is off; otherwise they say "Someone" or your own wording. The setting is on for new installs. We delete popup data after 60 days.
About storefront visitors, only when Shopify's Customer Privacy API reports that the visitor allows analytics:
- We use the visitor's IP address to give them a random visitor code. The link between the IP address and the code is deleted within about two days.
- We keep the visitor code, not the IP address, with records of popup clicks, so we can match a click to a later add-to-cart. We keep these click records until you uninstall the app.
- For add-to-cart popups we use an approximate city, region and country for the visitor, which our network provider, Cloudflare, works out from the IP address.
- We also keep daily totals of popup impressions, clicks and closes, and the storefront activity counts described below.
Cookies and logs
After a visitor allows analytics, the Sales Pops script sets these on your store's domain: a cookie holding the visitor code (1 day), a count of popups seen (up to 7 days), and a "popup hidden" flag (7 days). It also keeps the visitor code in the browser's local storage. The script loads jQuery from code.jquery.com.
Our servers keep standard technical logs of requests, including IP address, for security and troubleshooting.
Session analytics (Inspectlet)
When you sign into your account dashboard, sales pop settings, sales pop types, or notification management page inside the embedded Shopify Admin, we use Inspectlet (CloudThunder Inc.) to record how the dashboard performs and to debug user-reported issues. Inspectlet is not loaded on our login page, billing/membership pages, privacy policy, terms, or help pages — only on authenticated, in-app pages where you have already accepted our terms. Inspectlet records mouse movements, clicks, and form interactions inside the dashboard; it does not record content you have typed into password fields. You can opt out at any time by emailing [email protected].
Storefront activity counts
The Impact card in the app shows you three daily totals for your store: popups shown, clicks on popups, and products added to cart after a popup click. The Sales Pops script on your storefront counts these events in the shopper's browser and sends us only the totals.
- We count only when Shopify's Customer Privacy API reports that the shopper allows analytics. Shopify decides this from the shopper's cookie banner choice and your store's privacy settings for their region. If analytics isn't allowed, nothing is counted or sent. If the shopper withdraws consent before pending counts are sent, those counts are discarded.
- We store the counts only as totals per store per day. We don't store the shopper's IP address, browser or device details, cookies, cart details or any identifier for the shopper with these counts.
- To tell whether an add-to-cart followed a popup click, the shopper's browser keeps the IDs of up to 10 products they clicked in a popup, for 30 minutes, in that tab's session storage. These product IDs are never sent to us, and the browser clears them when the tab is closed.
- The requests carry no cookies. Like any web request, they reach our servers with the shopper's IP address. We use a shortened one-way hash of it for about a minute to limit abuse, and we don't record these requests in our web server logs.
- We delete the counts when you uninstall the app or when Shopify asks us to erase your store's data, and we delete counts older than 400 days.
- The counts show activity. They don't measure sales caused by popups, and they don't include purchases.
How we use your personal information
We use this information to provide and improve the app and to contact you about it. We don't sell personal information, and we don't use your customers' information for advertising.
Sharing your personal information
We share information only with service providers that help us run the app: Shopify, Amazon Web Services (hosting and email), Cloudflare (network, content delivery, and approximate visitor location) and Inspectlet (dashboard session recording, as described above). We also share it when the law requires.
Finally, we may also share your personal information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
Shopify privacy requests and uninstalling
When Shopify sends us a customer data request, we record it and check which of that customer's orders we still hold, so you can be told. We delete order data after 60 days anyway. When Shopify asks us to erase a customer's data, we clear their name and location from our order, popup and click records. When you uninstall, we delete your store's popup data, order data, click records and activity counts. When Shopify sends its store erasure request, 48 hours after you uninstall, we delete all remaining data for your store.
Your rights
If you are a European resident, you have the right to access personal information we hold about you and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.
Additionally, if you are a European resident we note that we are processing your information in order to fulfill contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above. Additionally, please note that your information will be transferred outside of Europe, to the United States, where our servers are hosted (Amazon Web Services, us-east-1 region).
Changes
We may update this privacy policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal or regulatory reasons.
Contact us
For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by email at [email protected].