Privacy Policy
Last updated: July 21, 2026
SpinWin adds gamified email-capture popups (spin-to-win, scratch cards, mystery offers) to OpoShop stores. This policy explains what data SpinWin processes, why, and how it is protected. SpinWin is operated by Found.
Who controls the data
The OpoShop merchant who installs SpinWin is the data controller for the shopper data collected through their popup. Found operates SpinWin as the merchant's data processor, handling that data only to provide the service. If you are a shopper, contact the store you interacted with for any data request; you can also reach us at the address below.
What we collect — merchant data
- Store connection (via OAuth). When a merchant installs SpinWin, OpoShop grants a store-scoped access token. We store it to read the store's identity, create the discount codes that back won prizes, and read the buyer's order at checkout to apply a code. We never receive or store the merchant's OpoShop password.
- Popup configuration. The game, prizes, odds, copy, colors, and rules the merchant sets.
- Store identity. Store name, subdomain, and owner email (for the app UI and support).
What we collect — shopper data
- Email address. A shopper enters their email to play. We store it, associated with the merchant's store, so the merchant can view and export their subscriber list.
- Optional name and a consent flag + timestamp (when the merchant's popup shows a consent line).
- Play records. The prize a play awarded, the generated discount code, an anonymous browser id (a random value in the shopper's own browser storage, not personally identifying), device type, and page type — used to run the game, enforce the frequency cap, and show the merchant honest analytics.
- No card or payment data. SpinWin never sees or stores payment details. Prizes are enforced entirely through OpoShop's own discount engine.
- No browsing/behavioral tracking beyond the above. The storefront widget sends only whitelisted, non-identifying event counts (e.g. "popup shown") keyed to the store — never the shopper's email.
How we use it
- To show the popup, decide the winning prize (server-side), and create + auto-apply the real discount code.
- To build the merchant's captured-email list and dashboard metrics.
- To send the shopper a branded "you won" email via OpoShop's own email service, on the merchant's behalf.
- To provide support and keep the service secure and working.
Storage, scoping & security
- Data is stored in SpinWin's own database, scoped per store — one store can never see another store's emails or configuration.
- Access to the OpoShop API uses the store's own token over HTTPS. Session tokens are short-lived and typed so a refresh token can't be used as an API credential.
- We do not sell shopper or merchant data, and we do not share it with third parties except the infrastructure providers needed to run the service (hosting, database, and OpoShop's own APIs).
Retention
We keep captured emails and play records for as long as the merchant has SpinWin installed, so the merchant retains their subscriber list. On uninstall, the store is deactivated; a merchant can request deletion of their store's data at any time. Shoppers can request removal of their email via the merchant or by contacting us.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data (e.g. under GDPR or CCPA). For shopper data, the merchant (controller) handles these requests; we assist as their processor. To exercise a right or ask a question, email brandon@tryfound.io.
Changes
We may update this policy; material changes will be reflected by the "last updated" date above.
Contact
Found — brandon@tryfound.io.