PopUsIn

Privacy notice

What PopUsIn holds about you, why and how each business on the platform sees only its own customers.

Last updated 1 October 2026

Trader and version details

PopUsIn · hello@popusin.com

Version IDs: utt-privacy-2026-10-01-v1; moments-privacy-2026-10-01-v1

Who we are

PopUsIn operates a UK business platform and consumer marketplace. For your PopUsIn account (My PopUsIn) PopUsIn is the data controller. For the details you give a business when you book, buy or enrol with it, that business is the controller and PopUsIn processes the data on its behalf.

What we hold

Account details (name, email, sign-in credentials), bookings, purchases, course progress and certificates, and the technical records needed to keep the service secure.

Payment card details are handled by our payment provider; PopUsIn never stores full card numbers.

Why we use it

To run your bookings, orders and courses; to issue and verify certificates; to send the confirmations and reminders those services need; to keep the platform secure; and to meet our legal obligations. Marketing messages are only sent where you have agreed to them and can be switched off at any time.

Who sees what

A business only sees the customers who have booked, bought or enrolled with it. Row-level security in our database enforces this on every request; no business can read another business's records.

Certificate verification pages show the certificate number, course, provider and date of issue — never your contact details.

Under the Tree

Who's responsible. PopUsIn is the controller of your personal data. Contact: hello@popusin.com.

What we collect:

  • Account details: your name, email, password or sign-in codes, and your age confirmation (13+).
  • Family information: the family name; who's in it and their roles; invitations; child profiles (first name or nickname, and optional preferences) that adults create and manage.
  • Christmas content: wish-list items and links; notes; hidden gift claims and buying notes; Secret Santa draws and budgets; reminders; game scores and festive extras you choose to use.
  • Payments: the Family Pass status, the amount, your consent to immediate access (with its time and the wording version), and Stripe payment references. We never see or store full card details.
  • Technical data: security and error logs, and your device or browser type. Error reports have emails, names, tokens and web addresses removed before they're sent.

Why we use it, and our lawful basis:

PurposeLawful basis
Running your family space, and keeping hidden claims hidden from the person they're forContract
Taking payment and keeping payment recordsContract, and legal obligation (tax records)
Keeping the service secure, fixing errors and preventing misuseLegitimate interests
Service emails (invitations, sign-in codes, receipts, reminders you've set)Contract
Optional marketing emails, only if you opt inConsent, which you can withdraw at any time

Children.

  • Children under 13 don't have accounts.
  • An adult in the family creates and manages each child profile, and decides what goes on the child's wish list.
  • We don't profile children, show them adverts, or add affiliate links to their lists. We don't use children's information for marketing.

Who we share it with. Only the service providers we need to run Under the Tree, all under contracts that protect your data:

ProviderWhat they do
StripePayments
ResendEmail
SupabaseAccounts and database
NetlifyHosting
Sentry (EU region)Error monitoring

Some providers may process data outside the UK. Where they do, we rely on UK-approved safeguards (the UK adequacy regulations, or the International Data Transfer Addendum). We never sell your data.

How long we keep it:

DataHow long
Family spaces and their contentUntil 31 January 2027, then deleted, unless the Head Elf chooses "Keep our family for 2027" (we email the Head Elf on 2 and 24 January and offer an export first). A kept family stays until the Head Elf deletes it. You can delete sooner at any time
Payment records6 years (tax law)
Security logsUp to 90 days
Error reportsUp to 90 days
Deleted accountsRemoved from the live service within 30 days, and from backups within a further 30 days

Your rights.

  • You can ask to see, correct, export or delete your data, or object to how we use it, by writing to hello@popusin.com. We'll reply within one month.
  • The Head Elf can export the family's shared details or delete the family from family settings.
  • You can complain to the Information Commissioner's Office (ico.org.uk), but please talk to us first so we can help.

Santa's Keepsake Shop

When you buy a keepsake, we use your name, delivery address, email, order details, and the photos and text you add. We use them to take payment, make and deliver your order, keep you updated and handle problems (contract). We share these with:

  • Stripe, for payment (we never see your full card number);
  • Prodigi and its print and delivery partners, only to make and post your order;
  • Resend, for order emails.

Order photos are stored privately, separate from your family's space. We delete them 30 days after delivery, or after cancellation, unless a problem report needs them longer. Order records are kept for 6 years for tax purposes. Some providers may process data outside the UK under UK-approved safeguards. Your rights and how to contact us are explained above.

Moments

What we collect:

  • Hosts: name, email and the event details.
  • Guests: a name or nickname, an email if invited, RSVP answers, the messages, requests, poll answers and uploads you add, and your upload declarations.
  • Media: We remove location and camera metadata when a file is uploaded. We keep the original privately and show resized copies. Download links expire after about an hour.
  • Technical data: as for Under the Tree.

Why, and our lawful basis:

PurposeLawful basis
Running the event for the host and guestsContract, for hosts
Showing guest contributions to the eventGuests' legitimate interests in taking part, plus their choice to upload
Safety, moderation and misuse preventionLegitimate interests

Who sees what:

  • The host and co-hosts see everything shared to the event.
  • Guests see what's approved for the event wall and gallery.
  • Nothing is public or searchable.

Service providers: the same as for Under the Tree, plus our media storage provider. We never sell data, and we never use event photos for advertising or to train AI.

How long we keep it:

  • Event photos, videos and messages are kept for 90 days after the event date, then deleted. The host can download the gallery before then.
  • RSVP and guest details are deleted 90 days after the event.
  • A host can delete an event at any time. It's then removed within 30 days, including from backups.

Your rights: as for Under the Tree. Guests can ask the host, or us at hello@popusin.com, to remove a photo of them.

Your rights

You can access, correct, export or delete your data, object to processing and withdraw consent. Use My PopUsIn → Profile for most changes, or contact us. You may also complain to the Information Commissioner's Office (ico.org.uk).

Retention

Account data is kept while your account is active and for a limited period afterwards to meet legal and accounting requirements. Certificates are retained so they remain verifiable.

← Back to Under Our Tree

Questions about this document? Contact PopUsIn.