Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Poptin is a popup and form builder that helps websites capture leads through exit intent popups, embedded forms and built in email autoresponders. It loads a first party JavaScript snippet that sets cookies and browser storage to control how often popups appear and to track visitor activity and form submissions. Because it collects contact data and can target visitors by behaviour, its non essential cookies generally require prior consent under European law.
Poptin is a popup and form builder designed to help websites capture leads and grow their email lists. It offers exit intent popups, lightboxes, embedded and inline forms, and a built in autoresponder that can send automated follow up emails. Website owners add a first party JavaScript snippet to their pages, after which Poptin can display campaigns, trigger forms based on visitor behaviour and feed submitted contacts into email workflows. Poptin is operated from Tel Aviv, Israel, and relies on cloud providers such as Amazon Web Services and Cloudflare. Because it observes visitor activity and collects contact details, it processes personal data on behalf of the website that deploys it.
Poptin sets first party cookies and uses browser storage to remember whether a visitor has already seen or closed a popup so the same message is not shown repeatedly, and to support A B testing and display rules. These identifiers can last from a single session up to around a year depending on configuration. Poptin may also record visitor activity such as pages viewed, clicks, referring URL and technical details like IP address, browser and operating system. When a visitor completes a form, the data entered, such as name and email address, is captured and can be passed to the autoresponder and connected integrations. Together these data points let Poptin recognise returning visitors and tailor when and what campaigns appear.
Under the ePrivacy Directive, storing or reading information on a visitor device requires consent unless it is strictly necessary for a service the visitor explicitly requested. Poptin cookies and storage used for frequency capping, targeting and A B testing go beyond the strictly necessary, so they fall within the consent requirement. Under the GDPR, capturing contact details and tracking behaviour is processing of personal data that needs a valid lawful basis and clear information to visitors. The website operator is the controller and must inform visitors and obtain consent before non essential scripts run. Poptin acts as a processor and provides a data processing agreement and a published list of sub processors to support compliance.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Marketing popups, exit intent campaigns, behavioural targeting and autoresponder sign ups rely on consent under Article 6(1)(a) of the GDPR. In practice this means integrating Poptin with a consent management platform so its non essential scripts are blocked until the visitor accepts the marketing category. Consent should be freely given, specific and as easy to withdraw as it is to give, and the form itself should make clear what the visitor is signing up for. Basic display frequency capping might be argued under legitimate interest in narrow cases, but any reliance on Article 6(1)(f) should be backed by a documented balancing test. Keeping records of consent and the opt in timestamp helps demonstrate compliance.
Poptin is an Israeli company and uses sub processors that operate globally, so visitor and lead data may be processed outside the European Economic Area. Israel benefits from a European Commission adequacy decision, which permits transfers to Israel without additional safeguards. Where data flows to United States based providers such as parts of Amazon Web Services or Cloudflare, those transfers should rely on the EU US Data Privacy Framework or Standard Contractual Clauses set out in Poptin data processing agreement. Operators should review the sub processor list to understand where data is hosted. Recording the transfer mechanism in the record of processing activities supports accountability.
Sign Poptin data processing agreement and add it to your record of processing and sub processor list. Configure a consent management platform so Poptin non essential cookies and scripts only load after the visitor accepts marketing. Disclose the cookies, their purposes and durations in your cookie policy, and make clear in each form what data is collected and why. Provide easy ways for people to withdraw consent, unsubscribe from autoresponders and exercise access and deletion rights, and use Poptin contact deletion tools to action erasure requests. Review settings periodically so retention, active campaigns and integrations remain consistent with what visitors were told.
Websites using Poptin must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is advisable when Poptin is used for behavioural targeting, exit intent campaigns or autoresponder sequences at scale, because these involve monitoring visitor activity and processing contact details. Document the data captured through forms, the cookies and storage used, retention periods, the consent mechanism and the role of sub processors such as Amazon Web Services and Cloudflare. Record the international transfer position and the lawful basis for each purpose.
Sample consent text
We use Poptin to show you relevant offers and to collect your details if you choose to sign up. This sets cookies and stores data in your browser to manage how often popups appear and to remember your choices. Do you consent to these marketing cookies?
Third-party domains contacted
poptin.comcdn.popt.inapp.popt.inapi.poptin.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| poptin_popup | first party | up to 1 year | Records which popups a visitor has already seen, closed or converted on so the same campaign is not shown repeatedly and display rules are respected. |
| poptin_session | first party | session | Maintains the current browsing session so campaign triggers and interactions are tracked consistently during a visit. |
| poptin_ab | first party | up to 6 months | Stores which variation of an A B tested popup a visitor was shown so the experience stays consistent and results can be measured. |
Poptin places tracking cookies for advertising — comply with GDPR using FlowConsent.
Poptin sets first party cookies and uses browser storage to remember whether a visitor has already seen or closed a popup so the same message is not shown repeatedly, and to support display rules and A B testing. These identifiers can last from a session up to around a year depending on configuration. Form submissions also capture the contact details a visitor chooses to provide.
Yes, for most uses. Because Poptin sets non essential cookies and tracks visitor behaviour to time and target popups, prior consent is required under the ePrivacy Directive and the GDPR before those scripts run. Strictly necessary functions are limited, so the safe approach is to gate Poptin behind a marketing consent category.
The main legal basis is consent under Article 6(1)(a) of the GDPR for marketing popups, exit intent campaigns, targeting and autoresponder sign ups. Legitimate interest under Article 6(1)(f) may be considered for basic display frequency capping with a documented balancing test. The website operator is the controller and decides the basis for each purpose.
Poptin is an Israeli company and uses global sub processors such as Amazon Web Services and Cloudflare, so data may be processed outside the EEA. Transfers to Israel rely on its EU adequacy decision, while transfers to United States providers should rely on the EU US Data Privacy Framework or Standard Contractual Clauses. Review Poptin sub processor list and data processing agreement to confirm the safeguards in place.
A data protection impact assessment is advisable when Poptin is used at scale for behavioural targeting, exit intent campaigns or large autoresponder programmes, since these involve monitoring activity and processing contact data. The assessment should cover the data captured, cookies used, retention, the consent mechanism and international transfers. For light use a full DPIA may not be required but the reasoning should be recorded.
Sign the Poptin data processing agreement, add it to your record of processing and integrate Poptin with a consent management platform so non essential scripts only load after consent. Disclose the cookies and their purposes in your cookie policy and make each form clear about what data is collected. Offer easy ways to withdraw consent, unsubscribe and request deletion, and use Poptin contact deletion tools.
Comparable popup and form tools include Adoric, Justuno, GetSiteControl, OptinMonster and Sumo. Each sets cookies and can profile or target visitors, so the same consent and transparency obligations apply. The right choice depends on the features you need, the hosting region and the strength of the provider data processing terms.
List the Poptin cookies and storage items with their purposes and durations and group them under marketing rather than strictly necessary. Name Poptin as the provider, note the international transfer position involving Israel and United States sub processors, and link to its privacy information. Keep the policy aligned with your consent banner categories and review it whenever you change Poptin features or integrations.