Legal
Privacy Policy
Last updated: 11 August 2026
PopupPush is a digital-signage platform for restaurants, cafés and venues. It has two parts: a player app that runs on a screen or media box inside the venue, and a web dashboard that venue staff use to manage what appears on those screens.
This policy explains what each part collects, why, and what choices you have. It covers the PopupPush Android app (com.ubitc.popuppush) and the PopupPush platform.
1. Who we are, and our two roles
PopupPush is operated by UBitc ("PopupPush", "we", "us"). Depending on the data, we act in one of two roles:
- We are the controller for venue account data, staff user accounts, and data generated by the screens and media boxes themselves (device identifiers, diagnostics, logs).
- We are a processor for information about a venue's own guests and customers. The venue decides what to collect and why; we store and process it on the venue's instructions. The venue is the controller of that data.
If you are a guest of a venue and want your data corrected or deleted, contact the venue directly. If they ask us, we will act on their instruction — see Your rights.
2. What the player app collects
The player app runs on a device installed by the venue, usually connected to a TV. It is not a consumer app and is not used by members of the public.
2.1 Device and diagnostic data
- Device identifier — the hardware serial number, or if unavailable, the Android ID. This identifies the screen so the right content is delivered to it. We do not collect an advertising ID.
- Device status and diagnostics — app version, Android version, available memory and storage, uptime, online/offline heartbeat, and network connection state.
- Operational logs — events such as playback started, content downloaded, or an error occurred, with a timestamp and the app version.
- Crash diagnostics — collected through Firebase Crashlytics so we can fix faults.
- Push token — a Firebase Cloud Messaging token, so the dashboard can send commands to the screen.
2.2 Screenshots and remote screen viewing
Venue staff and our support team can request a screenshot of what a screen is currently displaying, and can open a live remote view of the screen for troubleshooting. Both are used to confirm the right content is playing and to diagnose faults. A screenshot replaces the previously stored one for that device. Because these capture whatever is on the screen, they may incidentally include content the venue has chosen to display, such as a guest's name in a birthday greeting.
2.3 Camera
The app declares camera access. It is used in up to three distinct ways, and two of them are optional and off unless a venue turns them on.
a. Displaying an HDMI input (always available)
Venues often feed a live source into the screen — a satellite receiver, a match, a TV channel. On some media-box hardware the built-in HDMI input is exposed to Android as a camera device, so the app must hold camera permission to display it. This is a video input port, not a lens pointed at people. The video is shown on the screen in real time and is never recorded, stored, or transmitted anywhere.
b. Audience analytics — optional, off by default
A venue may enable an "AI Analytics" feature per screen. When enabled, and only then, the device camera is used to estimate who is watching. All image processing happens on the device. Only anonymous aggregate estimates leave it:
- an estimated age range and estimated gender per detected viewer,
- which content was on screen at that moment, and a timestamp.
No photographs, video frames, faces or biometric templates are stored or transmitted, and no attempt is made to identify, recognise or re-identify any individual. This feature is disabled by default on every device and must be switched on deliberately by the venue.
c. Live video support session — optional, initiated by the venue
The app can join a live video and audio session, used for remote assistance and for venue-initiated live streaming between screens. The camera and microphone are active only while such a session is running, and the session is started deliberately from the dashboard. This uses ZEGOCLOUD as the streaming provider.
2.4 Microphone
The microphone permission is used only for the live video session described above. The app also handles audio arriving through an HDMI or USB video input so it can be played through the screen; that is an audio input port, not the room microphone. The app does not listen to or record ambient audio.
2.5 What the app does not collect
- No advertising identifier and no cross-app tracking.
- No location data. The app does not use GPS, network location, or Wi-Fi scanning to locate the device.
- No SMS messages, call logs, contacts, or phone numbers from the device.
- No personal files from the device's storage.
3. Information about venue guests
Guests are never asked to install anything. Where a venue runs a guest-facing feature, the guest scans a QR code shown on the screen and opens a web page on their own phone. Everything below is collected on those web pages, on behalf of the venue, and only where the venue has enabled the feature.
| Feature | What may be collected |
|---|---|
| Customer directory | Name, phone number, email address, birthday, visit count and dates, preferred language, tags, and notes added by staff. |
| Birthday celebrations | The birthday person's name, photos and videos uploaded by guests to be shown on the screen, and an email address or phone number given to receive a recap afterwards. |
| Loyalty and ordering | Orders and items, amounts spent, points earned and redeemed, reward redemptions, and visit history. |
| Spin & Win | Player name, phone number, prize codes, and an anti-abuse identifier derived from the device or browser to enforce one entry per person. |
| Messaging | Delivery status of messages sent to a guest, including whether an email was delivered, opened, or a link was clicked. |
Guests choose whether to take part. Marketing messages are only sent where the guest has opted in, and every marketing message includes a way to opt out.
4. Venue account and staff data
For people who hold a PopupPush account we collect: name, email address, phone number, a securely hashed password, company details, and — for security and audit purposes — IP address and a record of significant actions taken in the dashboard.
5. How we use data
- To deliver the service: send the right content to the right screen, keep it playing, and recover from faults.
- To provide support: diagnose problems, including through screenshots and remote screen viewing.
- To keep the service secure and prevent abuse of promotional features.
- To operate the features a venue has switched on, such as loyalty, birthdays and messaging, on that venue's instructions.
- To improve reliability and performance using aggregate diagnostics.
We do not sell personal data, and we do not use it for advertising or share it with data brokers.
6. Who we share data with
We use a small number of service providers, who process data only on our instructions:
- Google Cloud and Firebase — hosting, databases, file storage, push notifications and crash reporting.
- ZEGOCLOUD — live video and audio sessions, when a session is running.
- Resend — sending transactional and marketing email on a venue's behalf.
- Google Vertex AI — optional AI features that generate menus and promotional images from material the venue supplies. Guest personal data is not sent to these features.
We may also disclose data where required by law, or to protect our rights or the safety of others.
7. International transfers
Our infrastructure runs on Google Cloud, and data may be processed in regions outside your country. Where required, transfers are covered by appropriate safeguards such as standard contractual clauses.
8. How long we keep data
- Device diagnostics and logs — kept while the device is active, then for a limited period for troubleshooting.
- Screenshots — only the most recent one per device is retained; each new capture replaces the last.
- Guest data — kept for as long as the venue instructs, and deleted when the venue deletes it or closes its account.
- Account data — kept for the life of the account and for a limited period afterwards to meet legal and accounting obligations.
9. Security
Data is encrypted in transit. Access to production systems is restricted to authorised personnel. Each venue's data is separated by account, and devices authenticate with per-device credentials that can be revoked or reissued at any time.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent.
- If you hold a PopupPush account, contact us at the address below.
- If you are a guest of a venue, contact that venue — they decide what is held about you. If you contact us instead, we will pass your request on and support the venue in answering it.
You also have the right to complain to your local data protection authority.
11. Children
PopupPush is a business service and is not directed at children. We do not knowingly collect personal data from children directly. Where a guest uploads an image of a child for a celebration, the venue is responsible for obtaining consent, as described above.
12. Changes to this policy
If we make material changes we will update the date at the top of this page and, where appropriate, notify account holders.
13. Contact
Questions about this policy or about your data: info@popuppush.com
قانوني
سياسة الخصوصية
آخر تحديث: ١١ أغسطس ٢٠٢٦
بوب أب بوش منصّة لافتات رقمية للمطاعم والمقاهي والأماكن التجارية. تتألّف من جزأين: تطبيق مُشغّل يعمل على شاشة أو جهاز وسائط داخل المكان، ولوحة تحكّم على الويب يستخدمها العاملون في المكان لإدارة ما يُعرض على تلك الشاشات.
توضّح هذه السياسة ما يجمعه كل جزء، ولماذا، وما الخيارات المتاحة لك. وتشمل تطبيق بوب أب بوش لأندرويد (com.ubitc.popuppush) ومنصّة بوب أب بوش.
١. من نحن، ودورانا
تُشغّل UBitc منصّة بوب أب بوش ("نحن"). وبحسب نوع البيانات، نعمل بأحد دورين:
- نحن المتحكّم في بيانات حسابات الأماكن التجارية، وحسابات الموظفين، والبيانات التي تُنتجها الشاشات وأجهزة الوسائط نفسها (معرّفات الأجهزة، والتشخيصات، والسجلات).
- نحن معالِج للمعلومات المتعلقة بضيوف المكان وعملائه. المكان هو من يقرّر ما يُجمع ولماذا، ونحن نخزّنها ونعالجها بناءً على تعليماته. والمكان هو المتحكّم في تلك البيانات.
إذا كنت ضيفاً في أحد الأماكن وأردت تصحيح بياناتك أو حذفها، فتواصل مع المكان مباشرة. وإذا طلبوا منّا ذلك، فسننفّذ تعليماتهم — انظر حقوقك.
٢. ما يجمعه تطبيق المُشغّل
يعمل التطبيق على جهاز يُركّبه المكان التجاري، وعادةً ما يكون موصولاً بشاشة تلفاز. وهو ليس تطبيقاً موجّهاً للمستهلكين ولا يستخدمه الجمهور.
٢.١ بيانات الجهاز والتشخيص
- معرّف الجهاز — الرقم التسلسلي للجهاز، أو معرّف أندرويد إن لم يتوفّر. يُستخدم لتمييز الشاشة حتى يصلها المحتوى الصحيح. ولا نجمع معرّف إعلانات.
- حالة الجهاز وتشخيصاته — إصدار التطبيق، وإصدار أندرويد، والذاكرة والمساحة المتاحة، ومدة التشغيل، ونبضات الاتصال، وحالة الشبكة.
- السجلات التشغيلية — أحداث مثل بدء التشغيل أو تنزيل محتوى أو وقوع خطأ، مع الوقت وإصدار التطبيق.
- تشخيص الأعطال — عبر Firebase Crashlytics لإصلاح المشكلات.
- رمز الإشعارات — رمز Firebase Cloud Messaging ليتمكّن نظام التحكّم من إرسال الأوامر إلى الشاشة.
٢.٢ لقطات الشاشة والعرض عن بُعد
يمكن لموظفي المكان ولفريق الدعم لدينا طلب لقطة لما تعرضه الشاشة حالياً، وفتح عرض مباشر عن بُعد للشاشة لتشخيص الأعطال. ويُستخدم ذلك للتأكّد من عرض المحتوى الصحيح ولمعالجة المشكلات. وتحلّ كل لقطة محلّ السابقة لذلك الجهاز. ولأنّ هذه اللقطات تُظهر ما على الشاشة، فقد تتضمّن عرَضاً محتوى اختار المكان عرضه، مثل اسم ضيف في تهنئة عيد ميلاد.
٢.٣ الكاميرا
يطلب التطبيق إذن الكاميرا، ويستخدمه في ثلاث حالات مختلفة، اثنتان منها اختياريتان ومعطّلتان ما لم يُفعّلهما المكان.
أ. عرض مدخل HDMI (متاح دائماً)
كثيراً ما تُوصِّل الأماكن مصدراً مباشراً بالشاشة — كجهاز استقبال فضائي أو مباراة أو قناة تلفزيونية. وفي بعض أجهزة الوسائط، يُعرَّف مدخل HDMI المدمج لدى نظام أندرويد على أنه جهاز كاميرا، لذا يحتاج التطبيق إلى إذن الكاميرا لعرضه. وهذا منفذ دخل فيديو وليس عدسة موجّهة نحو الأشخاص. ويُعرض الفيديو على الشاشة مباشرةً، ولا يُسجَّل أو يُخزَّن أو يُرسَل إلى أي جهة إطلاقاً.
ب. تحليلات الجمهور — اختيارية ومعطّلة افتراضياً
يمكن للمكان تفعيل خاصية "تحليلات الذكاء الاصطناعي" لكل شاشة. وعند تفعيلها فقط، تُستخدم كاميرا الجهاز لتقدير من يشاهد. وتتم كل معالجة الصور داخل الجهاز، ولا يخرج منه سوى تقديرات مجمّعة ومجهولة الهوية:
- الفئة العمرية التقديرية والجنس التقديري لكل مشاهد يُرصد،
- والمحتوى المعروض في تلك اللحظة، مع الوقت.
ولا تُخزَّن أو تُرسَل أي صور أو لقطات فيديو أو وجوه أو بصمات حيوية، ولا تُجرى أي محاولة للتعرّف على أي شخص أو تحديد هويته. وهذه الخاصية معطّلة افتراضياً على كل جهاز ولا تعمل إلا بتفعيل متعمّد من المكان.
ج. جلسة دعم بالفيديو المباشر — اختيارية ويبدأها المكان
يمكن للتطبيق الانضمام إلى جلسة فيديو وصوت مباشرة، تُستخدم للمساعدة عن بُعد وللبث المباشر بين الشاشات بمبادرة من المكان. ولا تعمل الكاميرا والميكروفون إلا أثناء تلك الجلسة، ولا تبدأ الجلسة إلا بإجراء متعمّد من لوحة التحكّم. ويُستخدم مزوّد البث ZEGOCLOUD لهذا الغرض.
٢.٤ الميكروفون
يُستخدم إذن الميكروفون فقط لجلسة الفيديو المباشر الموضّحة أعلاه. كما يتعامل التطبيق مع الصوت الوارد عبر مدخل فيديو HDMI أو USB لتشغيله عبر الشاشة، وهو منفذ دخل صوتي وليس ميكروفون الغرفة. ولا يستمع التطبيق إلى الصوت المحيط ولا يسجّله.
٢.٥ ما لا يجمعه التطبيق
- لا معرّف إعلانات ولا تتبّع بين التطبيقات.
- لا بيانات موقع جغرافي. لا يستخدم التطبيق نظام تحديد المواقع أو الشبكة أو مسح شبكات الواي فاي لتحديد موقع الجهاز.
- لا رسائل نصية ولا سجلات مكالمات ولا جهات اتصال ولا أرقام هواتف من الجهاز.
- لا ملفات شخصية من ذاكرة الجهاز.
٣. معلومات ضيوف المكان
لا يُطلب من الضيوف تثبيت أي شيء. وعند تفعيل المكان لخاصية موجّهة للضيوف، يمسح الضيف رمز QR معروضاً على الشاشة فتُفتح صفحة ويب على هاتفه. وكل ما يلي يُجمع عبر تلك الصفحات، نيابةً عن المكان، وفقط عند تفعيله للخاصية.
| الخاصية | ما قد يُجمع |
|---|---|
| دليل العملاء | الاسم، ورقم الهاتف، والبريد الإلكتروني، وتاريخ الميلاد، وعدد الزيارات وتواريخها، واللغة المفضّلة، والوسوم، وملاحظات يضيفها الموظفون. |
| احتفالات أعياد الميلاد | اسم صاحب عيد الميلاد، والصور ومقاطع الفيديو التي يرفعها الضيوف لعرضها على الشاشة، وبريد إلكتروني أو رقم هاتف يُعطى لاستلام ملخّص الاحتفال لاحقاً. |
| الولاء والطلبات | الطلبات وأصنافها، والمبالغ المنفقة، والنقاط المكتسبة والمستبدلة، واستبدال المكافآت، وسجل الزيارات. |
| عجلة الجوائز | اسم المشارك، ورقم هاتفه، ورموز الجوائز، ومعرّف لمنع التلاعب مشتق من الجهاز أو المتصفّح لضمان مشاركة واحدة لكل شخص. |
| الرسائل | حالة تسليم الرسائل المرسلة إلى الضيف، بما في ذلك ما إذا وصل البريد أو فُتح أو نُقر على رابط فيه. |
المشاركة اختيارية بالكامل. ولا تُرسَل الرسائل التسويقية إلا لمن وافق على تلقّيها، وتتضمّن كل رسالة تسويقية وسيلة لإلغاء الاشتراك.
٤. بيانات حساب المكان وموظفيه
بالنسبة لأصحاب حسابات بوب أب بوش نجمع: الاسم، والبريد الإلكتروني، ورقم الهاتف، وكلمة مرور مشفّرة، وبيانات الشركة، ولأغراض الأمان والتدقيق: عنوان IP وسجلاً بالإجراءات المهمّة داخل لوحة التحكّم.
٥. كيف نستخدم البيانات
- لتقديم الخدمة: إرسال المحتوى الصحيح إلى الشاشة الصحيحة، وإبقائه يعمل، والتعافي من الأعطال.
- لتقديم الدعم: تشخيص المشكلات، بما في ذلك عبر لقطات الشاشة والعرض عن بُعد.
- للحفاظ على أمان الخدمة ومنع إساءة استخدام الخصائص الترويجية.
- لتشغيل الخصائص التي فعّلها المكان، كالولاء وأعياد الميلاد والرسائل، بناءً على تعليماته.
- لتحسين الموثوقية والأداء باستخدام تشخيصات مجمّعة.
لا نبيع البيانات الشخصية، ولا نستخدمها لأغراض إعلانية، ولا نشاركها مع وسطاء بيانات.
٦. مع من نشارك البيانات
نستعين بعدد محدود من مزوّدي الخدمة، ويعالجون البيانات وفق تعليماتنا فقط:
- Google Cloud وFirebase — الاستضافة وقواعد البيانات وتخزين الملفات والإشعارات وتقارير الأعطال.
- ZEGOCLOUD — جلسات الفيديو والصوت المباشرة، أثناء انعقادها.
- Resend — إرسال رسائل البريد الإلكتروني التشغيلية والتسويقية نيابةً عن المكان.
- Google Vertex AI — خصائص ذكاء اصطناعي اختيارية تُنشئ قوائم طعام وصوراً ترويجية من مواد يوفّرها المكان. ولا تُرسَل بيانات الضيوف الشخصية إلى هذه الخصائص.
وقد نفصح عن البيانات عند الاقتضاء القانوني، أو لحماية حقوقنا أو سلامة الآخرين.
٧. النقل الدولي للبيانات
تعمل بنيتنا التحتية على Google Cloud، وقد تُعالَج البيانات في مناطق خارج بلدك. وعند الاقتضاء، تخضع عمليات النقل لضمانات مناسبة مثل الشروط التعاقدية القياسية.
٨. مدّة الاحتفاظ بالبيانات
- تشخيصات الجهاز وسجلاته — تُحفظ ما دام الجهاز نشطاً، ثم لفترة محدودة لأغراض معالجة المشكلات.
- لقطات الشاشة — لا يُحتفظ إلا بأحدث لقطة لكل جهاز، وتحلّ كل لقطة جديدة محلّ السابقة.
- بيانات الضيوف — تُحفظ وفق تعليمات المكان، وتُحذف عند حذفه لها أو إغلاق حسابه.
- بيانات الحساب — تُحفظ طوال مدّة الحساب ولفترة محدودة بعده للوفاء بالالتزامات القانونية والمحاسبية.
٩. الأمان
تُشفَّر البيانات أثناء النقل. والوصول إلى أنظمة الإنتاج مقصور على المخوّلين. وبيانات كل مكان مفصولة حسب الحساب، وتستخدم الأجهزة بيانات اعتماد خاصة بكل جهاز يمكن إبطالها أو إعادة إصدارها في أي وقت.
١٠. حقوقك
بحسب مكان إقامتك، قد يكون لك الحق في الوصول إلى بياناتك الشخصية أو تصحيحها أو حذفها أو نقلها، وفي الاعتراض على المعالجة أو تقييدها، وفي سحب الموافقة.
- إن كنت صاحب حساب في بوب أب بوش، فتواصل معنا على العنوان أدناه.
- إن كنت ضيفاً في أحد الأماكن، فتواصل مع ذلك المكان — فهو من يقرّر ما يُحتفظ به عنك. وإن تواصلت معنا، فسنحيل طلبك إليه وندعمه في الاستجابة له.
ولك كذلك الحق في تقديم شكوى إلى الجهة المختصة بحماية البيانات في بلدك.
١١. الأطفال
بوب أب بوش خدمة موجّهة للأعمال وليست موجّهة للأطفال. ولا نجمع عن قصد بيانات شخصية من الأطفال مباشرة. وعند رفع ضيف صورةً لطفل ضمن احتفال، يتحمّل المكان مسؤولية الحصول على الموافقة، كما هو موضّح أعلاه.
١٢. التغييرات على هذه السياسة
عند إجراء تغييرات جوهرية، سنحدّث التاريخ في أعلى هذه الصفحة، وسنُخطر أصحاب الحسابات عند الاقتضاء.
١٣. التواصل
للاستفسار عن هذه السياسة أو عن بياناتك: info@popuppush.com
