Last updated: 03.09.2026

Privacy Policy

1. Introduction

UpServe ("we," "us," or "our") operates the UpServe application (the "App") and the [UpServe website URL] website (the "Website"). UpServe is a Shopify embedded application that enables merchants ("Merchants") to display pre-purchase upsell popups to their store visitors ("Shoppers") when a product is added to cart, and to track the performance of those offers.

This Privacy Policy explains how we collect, use, disclose, and protect information when you use our App, visit our Website, or interact with our services.

By installing the App, visiting the Website, or using our services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use our services.

2. Information We Collect
Information from Merchants

When you install and configure the App, we collect:

Account information: Your Shopify store URL, store name, owner name, email address, and billing information as provided through the Shopify App Store billing system.

Configuration data: Your popup designs and templates, offer settings (selected upsell products, variants, discount settings), design customizations (colors, spacing, layout preferences), publishing status, and any custom settings you configure in the App.

Product catalog data: Product titles, images, variants, pricing, and inventory availability for products you select as upsell offers, accessed through Shopify's APIs to render your popups.

Support communications: Any messages, feedback, or files you send to our support team.

Information from Shoppers

When Shoppers interact with an UpServe popup on a Merchant's storefront, we process the following on behalf of the Merchant:

Event data: Popup impressions, popup interactions (offer accepted, offer dismissed), selected product variants, and add-to-cart events, including timestamps.

Attribution data: Order identifiers and order totals as needed to attribute conversions and added revenue to specific popup offers for the Merchant's analytics.

We do not collect Shoppers' names, email addresses, shipping or billing addresses, or payment information. Payment processing is handled entirely by Shopify's payment infrastructure. We do not store credit card numbers or payment credentials.

Information Collected Automatically

From the App: Feature usage data, session duration, error logs, performance metrics, and App interaction events (e.g., which settings are configured, how often popups are edited or published).

From the Website: IP address, browser type and version, operating system, referring URL, pages visited, time spent on pages, and general geographic location (city/country level). We collect this using cookies and similar technologies as described in our Cookie Policy.

3. How We Use Information

We use the information we collect to:

  • Provide, operate, and maintain the App and its features, including rendering upsell popups on Merchant storefronts and processing add-to-cart events.
  • Attribute conversions and added revenue to popup offers and display performance analytics (impressions, add-to-cart events, conversions, conversion rate, and added revenue) to Merchants.
  • Process billing and subscription payments for the App through the Shopify App Store billing system.
  • Provide customer support and respond to inquiries.
  • Analyze usage patterns to improve the App and Website, fix bugs, and develop new features.
  • Send Merchants product updates, feature announcements, and service-related communications. We do not send marketing communications to Shoppers.
  • Comply with legal obligations, enforce our Terms of Service, and protect against fraud or abuse.
4. Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:

Contractual necessity: Processing Merchant account data and Shopper event data is necessary to perform our contract with Merchants (providing the App's services).

Legitimate interests: Analyzing usage data to improve our services, prevent fraud, and ensure security.

Consent: Where required, for non-essential cookies on our Website and for optional marketing communications.

Legal obligation: Where we are required to retain or disclose data by law.

5. Data Sharing

We do not sell, rent, or trade personal information.

We share information only in the following circumstances:

With Shopify: As required to operate as an embedded Shopify application. Product data, add-to-cart events, and order attribution data are synced through Shopify's APIs. Shopify's own privacy policy governs their handling of this data.

With payment processors: Billing for the App is handled through Shopify's App Store billing system.

With service providers: We use third-party service providers to help operate our business, including cloud hosting, error monitoring, analytics, and customer support tools. These providers are bound by contractual obligations to protect your data and may only process it for the purposes we specify.

With Merchants (regarding Shopper data): Merchants can view aggregated popup performance data (impressions, conversions, added revenue) through the UpServe analytics dashboard.

As required by law: We may disclose information in response to valid legal processes, court orders, government investigations, or to protect the rights, property, or safety of UpServe, our users, or others.

In a business transfer: If UpServe is acquired, merges with another company, or sells substantially all of its assets, user data may be transferred as part of that transaction. We will notify affected users before their data becomes subject to a different privacy policy.

6. Data Retention

Merchant account and configuration data: Retained for the duration of your App installation. When you uninstall the App, we delete your configuration data within 30 days. Billing records may be retained longer as required for accounting and tax purposes.

Shopper event and attribution data: Retained in identifiable form only as long as necessary to provide analytics to the Merchant, and thereafter retained only in aggregated or anonymized form.

Website analytics data: Retained in anonymized or aggregated form. Individual session data is retained for up to 12 months.

Support communications: Retained for 24 months after the last interaction, then deleted.

7. Data Security

We implement industry-standard security measures to protect information from unauthorized access, disclosure, alteration, and destruction. These include:

  • Encryption in transit using TLS 1.2 or higher for all data transmitted between users, Shopify, and our servers.
  • Encryption at rest for stored data.
  • Role-based access controls limiting employee access to personal data on a need-to-know basis.
  • Regular security assessments and vulnerability testing.
  • Secure software development practices.
  • Incident response procedures for potential data breaches.

While we take reasonable steps to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

Access: Request a copy of the personal data we hold about you.

Correction: Request correction of inaccurate or incomplete data.

Deletion: Request deletion of your personal data, subject to legal retention requirements.

Portability: Request a machine-readable copy of your data.

Restriction: Request that we restrict processing of your data in certain circumstances.

Objection: Object to processing based on legitimate interests.

Withdraw consent: Where processing is based on consent, withdraw that consent at any time.

Merchants: You can exercise these rights by contacting us at business@grumspot.com. You can also delete your data by uninstalling the App from your Shopify store.

Shoppers: Because we process Shopper data on behalf of Merchants, Shoppers should contact the Merchant (the store they visited) directly to exercise their rights. If a Shopper contacts us directly, we will direct them to the relevant Merchant or assist as appropriate.

9. GDPR Compliance

For users in the European Economic Area and the United Kingdom:

We act as a data processor on behalf of the Merchant (the data controller) when processing Shopper event and attribution data through the App.

We act as a data controller for Merchant account data and for Website visitor data.

We process data on the legal bases described in Section 4.

Merchants are responsible for ensuring they have a valid legal basis for processing their Shoppers' data and for providing appropriate privacy notices to their Shoppers.

We have implemented appropriate technical and organizational measures to ensure data protection by design and by default.

If you wish to raise a concern about our data practices, you have the right to lodge a complaint with your local data protection authority.

10. CCPA/CPRA Compliance

For California residents:

We do not sell personal information as defined by the California Consumer Privacy Act and the California Privacy Rights Act. We do not share personal information for cross-context behavioral advertising.

California residents have the right to: know what personal information we collect and how it is used; request deletion of personal information; opt out of the sale or sharing of personal information (not applicable as we do not sell or share); and not be discriminated against for exercising these rights.

To exercise your rights, contact us using the details in Section 15.

11. International Data Transfers

UpServe operates primarily using cloud infrastructure located in [specify regions, e.g., the United States and the European Union]. If your data is transferred to a jurisdiction that does not provide an equivalent level of data protection as your home jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission.

12. Children's Privacy

Our App and Website are not directed at children under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will take steps to delete it promptly.

13. Third-Party Links

Our Website may contain links to third-party websites, including the Shopify App Store, help documentation, and partner services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify Merchants of material changes via email or in-app notification at least 30 days before the changes take effect. For Website visitors, the updated policy will be posted on this page with a revised "Last updated" date. Your continued use of our services after changes take effect constitutes acceptance of the updated policy.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:

Grumspot Ltd.Email: business@grumspot.comAddress: Akad. Boris Stefanov 4 St, Sofia, 1700, Bulgaria

For GDPR-related inquiries, you may also contact our Data Protection contact at: business@grumspot.com