PopupPush

Legal

Privacy Policy

Last updated: 11 August 2026

PopupPush is a digital-signage platform for restaurants, cafés and venues. It has two parts: a player app that runs on a screen or media box inside the venue, and a web dashboard that venue staff use to manage what appears on those screens.

This policy explains what each part collects, why, and what choices you have. It covers the PopupPush Android app (com.ubitc.popuppush) and the PopupPush platform.

1. Who we are, and our two roles

PopupPush is operated by UBitc ("PopupPush", "we", "us"). Depending on the data, we act in one of two roles:

If you are a guest of a venue and want your data corrected or deleted, contact the venue directly. If they ask us, we will act on their instruction — see Your rights.

2. What the player app collects

The player app runs on a device installed by the venue, usually connected to a TV. It is not a consumer app and is not used by members of the public.

2.1 Device and diagnostic data

2.2 Screenshots and remote screen viewing

Venue staff and our support team can request a screenshot of what a screen is currently displaying, and can open a live remote view of the screen for troubleshooting. Both are used to confirm the right content is playing and to diagnose faults. A screenshot replaces the previously stored one for that device. Because these capture whatever is on the screen, they may incidentally include content the venue has chosen to display, such as a guest's name in a birthday greeting.

2.3 Camera

The app declares camera access. It is used in up to three distinct ways, and two of them are optional and off unless a venue turns them on.

a. Displaying an HDMI input (always available)

Venues often feed a live source into the screen — a satellite receiver, a match, a TV channel. On some media-box hardware the built-in HDMI input is exposed to Android as a camera device, so the app must hold camera permission to display it. This is a video input port, not a lens pointed at people. The video is shown on the screen in real time and is never recorded, stored, or transmitted anywhere.

b. Audience analytics — optional, off by default

A venue may enable an "AI Analytics" feature per screen. When enabled, and only then, the device camera is used to estimate who is watching. All image processing happens on the device. Only anonymous aggregate estimates leave it:

  • an estimated age range and estimated gender per detected viewer,
  • which content was on screen at that moment, and a timestamp.

No photographs, video frames, faces or biometric templates are stored or transmitted, and no attempt is made to identify, recognise or re-identify any individual. This feature is disabled by default on every device and must be switched on deliberately by the venue.

c. Live video support session — optional, initiated by the venue

The app can join a live video and audio session, used for remote assistance and for venue-initiated live streaming between screens. The camera and microphone are active only while such a session is running, and the session is started deliberately from the dashboard. This uses ZEGOCLOUD as the streaming provider.

2.4 Microphone

The microphone permission is used only for the live video session described above. The app also handles audio arriving through an HDMI or USB video input so it can be played through the screen; that is an audio input port, not the room microphone. The app does not listen to or record ambient audio.

2.5 What the app does not collect

3. Information about venue guests

Guests are never asked to install anything. Where a venue runs a guest-facing feature, the guest scans a QR code shown on the screen and opens a web page on their own phone. Everything below is collected on those web pages, on behalf of the venue, and only where the venue has enabled the feature.

FeatureWhat may be collected
Customer directoryName, phone number, email address, birthday, visit count and dates, preferred language, tags, and notes added by staff.
Birthday celebrationsThe birthday person's name, photos and videos uploaded by guests to be shown on the screen, and an email address or phone number given to receive a recap afterwards.
Loyalty and orderingOrders and items, amounts spent, points earned and redeemed, reward redemptions, and visit history.
Spin & WinPlayer name, phone number, prize codes, and an anti-abuse identifier derived from the device or browser to enforce one entry per person.
MessagingDelivery status of messages sent to a guest, including whether an email was delivered, opened, or a link was clicked.

Guests choose whether to take part. Marketing messages are only sent where the guest has opted in, and every marketing message includes a way to opt out.

Photos and children. Birthday features let guests upload images that are shown on a screen in a public venue. Venues are responsible for obtaining appropriate consent, including from a parent or guardian where an image shows a child. Uploads are screened automatically for unsafe content before display.

4. Venue account and staff data

For people who hold a PopupPush account we collect: name, email address, phone number, a securely hashed password, company details, and — for security and audit purposes — IP address and a record of significant actions taken in the dashboard.

5. How we use data

We do not sell personal data, and we do not use it for advertising or share it with data brokers.

6. Who we share data with

We use a small number of service providers, who process data only on our instructions:

We may also disclose data where required by law, or to protect our rights or the safety of others.

7. International transfers

Our infrastructure runs on Google Cloud, and data may be processed in regions outside your country. Where required, transfers are covered by appropriate safeguards such as standard contractual clauses.

8. How long we keep data

9. Security

Data is encrypted in transit. Access to production systems is restricted to authorised personnel. Each venue's data is separated by account, and devices authenticate with per-device credentials that can be revoked or reissued at any time.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict processing, and to withdraw consent.

You also have the right to complain to your local data protection authority.

11. Children

PopupPush is a business service and is not directed at children. We do not knowingly collect personal data from children directly. Where a guest uploads an image of a child for a celebration, the venue is responsible for obtaining consent, as described above.

12. Changes to this policy

If we make material changes we will update the date at the top of this page and, where appropriate, notify account holders.

13. Contact

Questions about this policy or about your data: info@popuppush.com