Hosting and Infrastructure
Wisepops' servers are hosted by reputable providers, Amazon Web Services (AWS) and Google Cloud Platform (GCP), in the United States. Both providers adhere to the highest security and data protection standards:
AWS: Ensures data privacy, complies with GDPR, holds ISO 27001 certification, and provides data encryption both at rest and in transit.
GCP: Guarantees data privacy, complies with GDPR, holds ISO 27001 certification, and provides data encryption both at rest and in transit.
For more information about the domains involved when using Wisepops on your website, please refer to our guide on Using Wisepops with a Content Security Policy.
Preventing Unauthorized Access
We have stringent measures in place to prevent unauthorized access to your data:
Only our lead developers have access to production servers.
Secure Shell (SSH), with a private key or gcloud utility, is the exclusive method used to access our servers. FTP is not used, our database does not accept external connections, and we do not use tools like PhpMyAdmin.
Our servers are protected by a firewall.
Physical security measures are applied to our servers.
Additionally, we take the following steps to secure your account:
Wisepops.com access is protected by two Cloudflare technologies: Web Application Firewall (WAF) & IP reputation firewall.
Accounts are safeguarded against brute-force attacks with the Fail2ban solution.
Our application enforces the use of HTTPS.
Preventing Data Loss and Corruption
To prevent data loss and corruption, we:
Backup your data daily and retain it for seven days.
As part of our disaster recovery plan, maintain a backup of all calls to the machines handling popups on our customers’ websites on an AWS private S3 bucket.
Personal Data Storage
We store the personal details you provide us (email, password, name, etc.), which you can view on your account configuration page. For security purposes, we also collect your IP address, login dates, and user agent and store this information for one month via Google Cloud Logging.
We share some of your personal details (email, website, name, and login) with Segment, Mixpanel, and Intercom for internal use only. We remain the sole users and owners of this data.
Data Retention
We retain your data for two years. If your account remains inactive for two years, we permanently delete all your data, including:
Your company & billing information
Your campaigns
The data collected through your campaigns
We define inactivity as a lack of user interaction with our app (app.wisepops.com), and the absence of a recurring payment to maintain an active Wisepops subscription.
If you have any questions or concerns about our data security policy, please don't hesitate to contact us