EngageNudge

Política de privacidade

Última atualização: 23 de agosto de 2026

Idioma deste documento

Este documento é disponibilizado em inglês e a versão em inglês é a vinculativa. Dúvidas: hello@engagenudge.com.

Who we are

EngageNudge is a web push service operated by Hyperity from Sweden. It helps sites decide when to send browser notifications, and when not to. For anything in this policy, write to hello@engagenudge.com.

Two roles

For visitors to this website and for the people who hold EngageNudge accounts, we are the data controller. For the subscribers our customers reach through EngageNudge, the customer is the controller and we are a processor acting on their documented instructions. That relationship is governed by our Data Processing Agreement, available at /dpa.

Data we process for our customers

Push subscription endpoints and their browser keys, stored encrypted with keys derived per customer, so a record can only be read through the account it belongs to. Topic choices and notification preferences. Engagement events such as shown, clicked, and dismissed. We derive a coarse location from the IP address when an event arrives and do not keep the full address afterwards.

Data we process as a controller

Your account email address and sign-in events. Sign-in uses emailed links, so we never store a password for you. Billing records, handled through Stripe. Messages you send us through the contact form or by email, including early access requests.

Where data lives

Processing is EU-first. The primary database runs in the European Union, raw event archives are stored in Cloudflare R2, and delivery runs on Cloudflare's network. The Subprocessors page at /subprocessors lists every provider involved and where they process data.

How long we keep data

Raw event archives are deleted after 90 days. A subscription is deleted when the person unsubscribes: the encrypted record is removed from the audience database, not just flagged. Account data is kept while the account exists. Invoices are kept for as long as bookkeeping law requires.

Security

All traffic is encrypted in transit. Push endpoints and signing keys are encrypted at the field level. Every database query is scoped to a single customer. Logs redact personal data. The Security page at /security describes the technical controls in more detail.

Your rights

You can ask for access, correction, export, or deletion of your data. Account owners can export their data and schedule deletion directly from the dashboard; deletion runs after a short cooldown so a mistake can be cancelled. If you are a subscriber on a customer's site, that customer is your first contact, and we assist them with every request. You can also complain to your supervisory authority; in Sweden that is IMY.

Subscribers on our customers' sites

When you allow notifications on a site that uses EngageNudge, your browser creates a delivery address that only that site can use. We store it encrypted, for that site alone. Unsubscribing in your browser, or from the notification itself, deletes the record.

No selling, no ad tracking

We do not sell personal data and we do not run advertising trackers. This website sets one cookie, for your language choice. The Cookies page at /cookies has the details.

Changes

When this policy changes we update the date at the top. Material changes are announced to account owners by email.

Saiba quando fazer um Nudge.

Saiba quando uma notificação vale a pena ser enviada.

Seja para leitores, compradores, candidatos ou clientes, o EngageNudge ajuda você a decidir quem merece um Nudge e quem deve ser deixado em paz.