PopUsIn

Privacy notice

What PopUsIn holds about you, why, and how each business on the platform sees only its own customers.

Last updated 10 September 2026

Who we are

PopUsIn operates a UK business platform and consumer marketplace. For your PopUsIn account (My PopUsIn) PopUsIn is the data controller. For the details you give a business when you book, buy or enrol with it, that business is the controller and PopUsIn processes the data on its behalf.

What we hold

Account details (name, email, sign-in credentials), bookings, purchases, course progress and certificates, and the technical records needed to keep the service secure (sign-in events, device and IP data).

Payment card details are handled by our payment provider; PopUsIn never stores full card numbers.

Why we use it

To run your bookings, orders and courses; to issue and verify certificates; to send the confirmations and reminders those services need; to keep the platform secure; and to meet our legal obligations. Marketing messages are only sent where you have agreed to them and can be switched off at any time.

Who sees what

A business only sees the customers who have booked, bought or enrolled with it. Row-level security in our database enforces this on every request; no business can read another business's records.

Certificate verification pages show the certificate number, course, provider and date of issue — never your contact details.

Your rights

You can access, correct, export or delete your data, object to processing and withdraw consent. Use My PopUsIn → Profile for most changes, or contact us. You may also complain to the Information Commissioner's Office (ico.org.uk).

Retention

Account data is kept while your account is active and for a limited period afterwards to meet legal and accounting requirements. Certificates are retained so they remain verifiable.

Questions about this document? Contact PopUsIn.