Skip to main content

Data Security Policy

This article describes how Wisepops protects your account data and the data collected through your campaigns. It complements our Privacy Policy, our Data Processing Agreement, and the documentation available on our Trust Center.

Written by Lisa Fockens

Hosting and Infrastructure

Wisepops runs on Amazon Web Services (primary) and Google Cloud Platform (secondary), with Cloudflare providing CDN, DNS, and edge security. All processing takes place in United States regions.

All three providers hold recognized security certifications, including ISO 27001 and SOC 2, and publish their compliance documentation:

Wisepops does not own or operate physical infrastructure. Physical and environmental security controls for the data centers hosting our services are provided by AWS and GCP and are covered by their respective audits and attestations.

For the domains involved when running Wisepops on your website, see Using Wisepops with a Content Security Policy.

Encryption

  • At rest: AES-256 across all storage services.

  • In transit: HTTPS enforced, TLS 1.2 minimum with TLS 1.3 supported.

  • Key management: AWS KMS and GCP native encryption, using provider-managed keys with access restricted through IAM roles.

Preventing unauthorized access

  • Access to production environments is restricted to a small number of engineers with a documented business need, following the principle of least privilege. Access rights are reviewed on a recurring basis and revoked promptly on role change or departure.

  • Multi-factor authentication is required for all administrative access to cloud consoles, our identity provider, and our password manager.

  • Our databases do not accept connections from the public internet. FTP and other unencrypted protocols are not used, and we do not expose database administration interfaces.

  • Production networks use a VPC architecture with public and private subnets. Application logic and databases sit in private subnets, and security groups are configured to deny inbound traffic by default.

  • Network activity is monitored for anomalies, and container and application logs are centralized in a logging stack hosted on our own infrastructure.

Application and account security

  • Access to wisepops.com and app.wisepops.com is protected by Cloudflare's Web Application Firewall and DDoS mitigation.

  • HTTPS is enforced across the application.

  • Dashboard sign-in is passwordless. You sign in with a magic email link or with Google Sign-in (OAuth 2.0). Wisepops does not create, store, or transmit account passwords.

  • Single sign-on is available over OIDC, with documented setup for Okta and Microsoft Entra.

  • Role-based access control lets you assign owner, admin, and editor roles within a workspace.

  • Sessions expire after a period of inactivity. When "Remember me" is disabled, the session ends when the browser closes.

  • Outgoing webhooks are signed so you can verify their authenticity.

Secure development and vulnerability management

  • All code changes go through peer review and must pass automated static analysis before they can be merged.

  • Third-party dependencies are continuously monitored for disclosed vulnerabilities, and updates are applied according to severity.

  • An independent third party performs a penetration test at least annually.

  • We operate an active bug bounty program. Security researchers and customers can report issues to security@wisepops.com.

  • Vulnerabilities are remediated within defined timeframes based on severity, as set out in our internal Vulnerability Management Policy.

Preventing data loss and corruption

  • Production databases are backed up continuously with point-in-time recovery, allowing restoration to any point within a 35-day retention window.

  • Backups are encrypted, stored in a vault configured so they cannot be deleted before the end of their retention period, and replicated across regions.

  • As part of our disaster recovery plan, we maintain a separate backup of the traffic handled by the infrastructure serving campaigns on customer websites, in a private AWS S3 bucket.

  • Backup restoration is tested at least annually.

Incident response

Wisepops maintains a documented Incident Response Policy covering detection, triage, containment, eradication, recovery, and post-incident review. Security incidents are classified by severity, and every incident is logged and reviewed.

For personal data breaches:

  • Where Wisepops acts as a processor on your behalf, we notify you without undue delay after becoming aware of a breach, so that you can meet your own notification obligations.

  • Where Wisepops acts as the controller, we notify the competent supervisory authority within 72 hours of becoming aware of the breach, in line with Article 33 of the GDPR, and inform affected individuals where Article 34 requires it.

To report a security issue, contact security@wisepops.com.

Personal data we store about you (account holders)

We store the account details you provide, which you can review on your account settings page:

  • Name, email address, and profile picture (the latter when you sign in with Google)

  • Workspace and website configuration, plan, and role

  • Billing address, invoices, and subscription data. Card payments are handled by Stripe, which is PCI DSS Level 1 certified. Wisepops does not store or process raw card data.

  • Product usage data (feature usage, login dates)

  • IP address and user agent, retained for one month via Google Cloud Logging

  • Support conversations, when you contact us

We do not store passwords, because dashboard authentication is passwordless.

Data collected through your campaigns (visitor data)

For data collected from your website visitors through Wisepops campaigns, Wisepops acts as a data processor and you remain the controller. What we process, how long we keep it, and where it goes is described in our Data Processing Agreement and our privacy and security documentation.

Two points worth highlighting:

  • IP addresses are used in memory for geolocation when deciding which campaign to display, and are not stored for that purpose. IP addresses recorded in analytics are truncated before storage.

  • If you prefer Wisepops to act purely as a pass-through for the contact data you collect, we can configure your account so that form submissions are deleted from our infrastructure after 24 hours, while still syncing to your ESP, CRM, or webhook. Contact support to enable this.

Sub-processors

Wisepops uses a limited set of vendors to operate the service, including cloud infrastructure, transactional email, error monitoring, product analytics, and customer support. The current list, with the categories of data each one processes, is maintained in our Trust Center and in our Privacy Policy.

Vendors are assessed before onboarding and reassessed periodically, and each one is bound by a data processing agreement. Where personal data is transferred to the United States, we rely on the EU-U.S. Data Privacy Framework as the primary transfer mechanism, with 2021 Standard Contractual Clauses embedded in vendor agreements as a fallback.

Data retention

We retain your data for as long as your account is active.

If your account remains inactive for two years, we permanently delete it, including:

  • Your company information

  • Your campaigns

  • The data collected through your campaigns

We define inactivity as the absence of user interaction with id.wisepops.com combined with the absence of a recurring payment maintaining an active subscription.

Two exceptions apply:

  • Billing and accounting records are retained for the period required by applicable tax and accounting law, which is longer than two years.

  • Backups are retained for up to 35 days after deletion, after which they expire automatically.

You can export your contacts and campaign data from the dashboard at any time. You can also request deletion of your data before the inactivity period elapses by writing to legal@wisepops.com.

Certifications and compliance

  • Wisepops is currently undergoing a SOC 2 Type II audit. No report has been issued yet.

  • Wisepops is not ISO 27001 certified. Our internal policy set is built to align with recognized standards, and our cloud providers hold ISO 27001 certification for the infrastructure they operate.

  • Our internal security policies (access management, incident response, vulnerability management, backup and recovery, secure development, vendor management, and others) are reviewed at least annually.

If you have questions about this policy, contact support@wisepops.com. For security reports, use security@wisepops.com.

Did this answer your question?