🇸🇪 Svenska

Privacy Policy for Popcorn

Last updated: March 15, 2026 · Version 1.1

This policy explains how InsightsHub ("we") collects, uses, and protects personal data in connection with the Popcorn service.

1. Data Controller

For restaurant owner data (account, contact info): InsightsHub is the Data Controller.
For guest feedback: The restaurant is the Data Controller, InsightsHub is the Data Processor (see DPA in Terms of Service).

2. What Data We Collect

Restaurant owners (account holders):

DataPurposeLegal Basis
NameIdentification, communicationContract
Email addressLogin (Magic Link), communicationContract
Business name and typeProviding the serviceContract
City/countryAdapting the service (language, currency)Contract
IP address at registrationSecurity, abuse preventionLegitimate interest

Guests (feedback providers):

DataPurposeLegal Basis
Feedback responses (rating, choices, free text)Providing the serviceLegitimate interest (restaurant's)
Language settingDisplay form in correct languageLegitimate interest
IP addressSecurity, rate limitingLegitimate interest
Device type (user-agent)Technical troubleshootingLegitimate interest

Important: Guest feedback is collected anonymously. We do not request names, email addresses, or other directly identifying information from guests in the standard flow. IP addresses are stored temporarily for security purposes.

3. How We Use the Data

We never sell personal data to third parties.

4. Sub-processors

We use the following services to provide Popcorn:

ServicePurposeLocation
RailwayWeb hosting, database (PostgreSQL)EU (Amsterdam)
Cloudflare R2File storage (image uploads)EU
ResendTransactional emailEU/US
Google Places APIRestaurant search (autocomplete)EU/US
UpstashRedis (rate limiting, sessions)EU
SentryError tracking, performance monitoring (PII scrubbed)EU/US
Anthropic (Claude)AI assistant for venue insights (Copilot)US (SCC)

All sub-processors are bound by agreements ensuring at least the same level of protection as this policy.

5. Storage and Deletion

6. Your Rights (GDPR)

As a data subject, you have the right to:

Contact us: privacy@popcornfeedback.com · We respond to requests within 30 days.

7. Security

We protect your data through:

8. Cookies and Tracking

Popcorn does not use third-party cookies or tracking services. We use technically necessary cookies (session cookies) to authenticate logged-in users.

9. Changes to This Policy

We may update this policy. Material changes are communicated via email at least 30 days in advance.

10. Contact

InsightsHub
Privacy inquiries: privacy@popcornfeedback.com
General support: support@popcornfeedback.com