Privacy Policy
Last updated: August 25, 2026
Steply lets an OpoShop merchant build funnels — sequences of pages that live on their own storefront, with order forms, order bumps and one-click offers after checkout. This policy explains what data Steply processes, why, and how it is protected. Steply is operated by Found.
Who controls the data
The OpoShop merchant who installs Steply is the data controller for the shopper data collected through their popup. Found operates Steply as the merchant's data processor, handling that data only to provide the service. If you are a shopper, contact the store you interacted with for any data request; you can also reach us at the address below.
What we collect — merchant data
- Store connection (via OAuth). When a merchant installs Steply, OpoShop grants a store-scoped access token. We store it to read the store's identity and catalog, create and update the funnel pages on the store, and read orders back so the merchant's reported revenue matches their own admin. We never receive or store the merchant's OpoShop password.
- Funnel content. The pages, copy, colors, products and offer settings the merchant builds.
- Store identity. Store name, subdomain, and owner email (for the app UI and support).
What we collect — shopper data
- Email address. A shopper enters their email to play. We store it, associated with the merchant's store, so the merchant can view and export their subscriber list.
- Optional name and a consent flag + timestamp (when the merchant's popup shows a consent line).
- Funnel activity. Which steps were viewed, which version of a split test was shown, and whether an offer was accepted or declined — keyed to an anonymous browser id (a random value in the shopper's own browser storage, not personally identifying). This is what makes the merchant's analytics real rather than estimated.
- No card or payment data. Steply never sees, stores or transmits payment details. Every charge is made by OpoShop's own checkout, and Steply never creates a payment or sets a price.
- No browsing/behavioral tracking beyond the above. The storefront widget sends only whitelisted, non-identifying event counts (e.g. "popup shown") keyed to the store — never the shopper's email.
How we use it
- To build and publish the merchant's funnel pages onto their own storefront, and to ask OpoShop's checkout to complete a one-click offer that a shopper accepted.
- To build the merchant's captured-email list and dashboard metrics.
- To send the shopper a branded "you won" email via OpoShop's own email service, on the merchant's behalf.
- To provide support and keep the service secure and working.
Storage, scoping & security
- Data is stored in Steply's own database, scoped per store — one store can never see another store's emails or configuration.
- Access to the OpoShop API uses the store's own token over HTTPS. Session tokens are short-lived and typed so a refresh token can't be used as an API credential.
- We do not sell shopper or merchant data, and we do not share it with third parties except the infrastructure providers needed to run the service (hosting, database, and OpoShop's own APIs).
Retention
We keep captured emails and play records for as long as the merchant has Steply installed, so the merchant retains their subscriber list. On uninstall, the store is deactivated; a merchant can request deletion of their store's data at any time. Shoppers can request removal of their email via the merchant or by contacting us.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data (e.g. under GDPR or CCPA). For shopper data, the merchant (controller) handles these requests; we assist as their processor. To exercise a right or ask a question, email brandon@tryfound.io.
Changes
We may update this policy; material changes will be reflected by the "last updated" date above.
Contact
Found — brandon@tryfound.io.