THE DETAILS, IN PLAIN LANGUAGE
Privacy policy
What we use, why we use it, and what your store visitors actually see.
Last updated: 25 September 2026
1. Who we are
Nuvopop is provided by InnovaPulse d.o.o., Kornatska ulica 1E, 10000 Zagreb, Croatia, OIB (Croatian tax ID): 06112740973. This policy covers our website and the Nuvopop Shopify application. You can contact us about privacy at kposavce@gmail.com or at the address above, marked “Nuvopop — privacy”.
We act as controller for our business contacts, support communications and the information needed to operate and secure our own service. When we process a store’s customer data to produce notifications, we act on that merchant’s instructions as a processor. The merchant remains responsible for its store’s privacy notice, lawful basis and choice of popup content.
2. Information the app uses
- Merchant connection and settings. We store the Shopify shop domain, authorization tokens, session information, permissions, and saved popup settings. Depending on the Shopify authorization session, this may include the staff member’s Shopify user ID, name, email, locale and account-role information.
- Subscription access. We query Shopify for the store ID, active subscription status, billing period, trial end and billing-cycle end, including whether cancellation is scheduled. Confirmed access is cached in server memory for up to 60 seconds. Shopify handles payment approval and billing; we do not receive card details. Approved owner stores may have complimentary access recorded in our server settings.
- Products. Product titles, handles, storefront links, images, publication details and availability information help us generate product and purchase notifications.
- Recent purchases. Purchase mode reads recent order time, payment, cancellation and test status, relevant line items and product availability. If the merchant enables location, we request the shipping country and, for city mode, the shipping city. The purchase query does not request customer names, email addresses, phone numbers, street addresses or payment-card details.
- Shopify event notifications. Shopify sends authenticated events about orders, products, uninstallation and privacy requests. Event payloads can contain additional personal data supplied by Shopify. Our handlers use the event type and store identity to refresh cached content or delete app records; they do not write the full event payload to our database.
- Support and technical information. If you contact us, we receive what you send. Our hosting and delivery providers process connection and diagnostic information, which may include IP addresses, request URLs, browser information, timestamps and errors, to deliver and protect the service.
3. What visitors see
A purchase popup can display the purchased product, its image and link, a relative purchase time and, if enabled, a country or city. It does not display the buyer’s name or contact details. These details are made available through the store’s public notification feed. A location combined with a product and time may still relate to an identifiable person in some circumstances; removing a name is not a guarantee of anonymity. Merchants should use no location or country-only display where appropriate and avoid disclosing sensitive purchases.
New-arrival notifications use product information. Discount and announcement notifications use the content entered by the merchant. Do not put customer information or confidential data into these public messages.
4. Purposes and legal grounds
We use merchant connection data to provide and maintain the app and your chosen settings. Our grounds for our own processing are performance of a contract where applicable, legitimate interests in running a secure service and responding to business enquiries, and compliance with legal obligations. Where a merchant is a company, processing of its staff’s contact details is based on our legitimate business interests. Store customer data is processed on the merchant’s instructions; the merchant determines the applicable legal ground. We do not use order data to build advertising profiles, sell it, or train AI models.
5. Browser storage and analytics
The storefront widget uses the visitor’s browser session storage to remember dismissal timing, items already shown and session display counts. These values remain in that store’s browser session and are not sent to us as an analytics report. If storage is blocked, the widget uses temporary page memory. Session storage normally ends when the tab’s session is closed, though browser session restoration may preserve it.
We do not collect popup views, clicks or CTR for a merchant analytics dashboard. This website has no advertising pixels or audience analytics. Shopify authentication may use necessary cookies or session mechanisms. Website fonts and store product images are delivered by Shopify’s CDN, which receives the connection information needed to deliver them. The merchant is responsible for assessing any notice or consent requirements for the widget on its store.
6. Storage and retention
Merchant settings and authorization sessions are held in our application database while the app is installed. When a valid uninstall event is processed, our app deletes that store’s settings and sessions and clears its notification cache. A Shopify shop-redaction event also triggers deletion. Delivery failures may delay this; please contact us if you need deletion assistance.
Raw orders are not saved in our application database. A filtered notification feed is cached in server memory, with a 30-second freshness window. Expired entries are not served as fresh data, but may remain in memory until replaced, evicted, invalidated by an event or removed by a server restart. This is not a permanent order archive.
Technical logs follow the hosting provider’s retention settings; Render currently documents a 7–30 day log window depending on the workspace plan. Infrastructure backups, where maintained, expire according to the provider’s backup cycle rather than being individually edited on every deletion. We retain support correspondence as needed to resolve the enquiry and any related dispute, and records required by law for the applicable statutory period. We do not retain customer order data for marketing.
7. Providers and international processing
Our application and database are hosted on Render in Frankfurt, Germany. Shopify supplies the commerce platform, authorization, APIs and content delivery. These providers and their subprocessors may process technical or support information outside the EEA; a Frankfurt hosting region does not mean that all processing stays in the EU. Where an international transfer requires safeguards, we must rely on an applicable adequacy decision or appropriate contractual safeguards, such as standard contractual clauses. Contact us for details relevant to your data.
Read Render’s privacy policy, Render’s data processing terms and Shopify’s privacy policy for their own processing. We may also disclose information where legally required or necessary to establish or defend legal claims.
8. Your choices and rights
Merchants can change the displayed location, disable notifications or uninstall the app. Depending on applicable law, individuals may request access, correction, deletion, restriction or portability of personal data and object to processing based on legitimate interests. If processing depends on consent, it can be withdrawn without affecting earlier lawful processing. We may need to verify your identity.
If you are a store customer, contact the store first: it controls your order and decides how Nuvopop is used. We assist merchants with applicable requests and process Shopify privacy events. Deleting data from Nuvopop does not delete the original order from Shopify. For information we control, contact InnovaPulse d.o.o. We aim to respond within the applicable legal deadline, normally one month under the GDPR. You may complain to your local supervisory authority or Croatia’s Agency for Personal Data Protection (AZOP).
9. Security and changes
We use HTTPS, authenticated Shopify access, signed-event verification and restricted database connectivity. No service can guarantee absolute security. Nuvopop is a business tool, not a service directed at children. We may update this policy when our practices or the service change; the date above identifies the current version. Material changes will be communicated through an appropriate service channel.