Last updated 29 September 2026.
Spinlet (“we”, “us”) provides an embeddable spin-to-win popup widget for websites, plus the dashboard used to configure it, at getspinlet.com. This policy covers two different roles we play, and what data we handle in each:
As a service provider to merchants — if you run a store or site that embeds a Spinlet widget, we process your visitors’ data on your behalf, under your instructions. You (the merchant) are the data controller for that data; we’re the processor.
As a controller for our own dashboard users — if you sign up for a Spinlet account to create and manage campaigns, we are the controller for your account data (email, billing, campaign configuration).
From dashboard users (merchants): your email address (for sign-in and account communication), the campaigns you create (headline, prize list, colours, targeting rules, consent text), and billing information handled directly by Stripe — we never see or store your card details ourselves.
From widget visitors (your customers): when someone spins the widget on your site, we record the email address they enter, which prize they won and any code issued, the page URL the widget was shown on, the exact consent text displayed to them at that moment, and a timestamp. We use this to run the spin, show you your leads, and (if you’ve set one up) forward the lead to your webhook URL.
We also collect basic, aggregated usage data (page views, widget impressions) via Google/Firebase Analytics to understand how getspinlet.com itself is used — not the merchant sites running the widget.
To operate the service: running spins, enforcing one-spin-per-person, storing your leads, sending you a notification email when someone spins, and forwarding leads to your webhook if configured. To run your account: authentication, billing, and support. To improve Spinlet: aggregated, non-identifying usage analytics.
We do not sell personal data, and we do not use the leads collected through your widget for our own marketing.
We use a small number of subprocessors to run the service, each only for what they’re named for:
If you (the merchant) configure a webhook URL, we send lead data to that URL at your instruction — that’s a destination you control, not one we choose.
The embedded widget uses your visitor’s browser’s local storage (not a tracking cookie) to remember that they’ve already spun, and which A/B variant they saw, so the same person doesn’t see it repeatedly. The dashboard uses a session cookie to keep you signed in.
We keep lead and campaign data for as long as your account is active. If you delete a campaign, its leads are deleted with it. If you close your account, we delete your account data within a reasonable period, except where we’re required to keep records (e.g. billing history) for legal or accounting purposes.
Depending on where you’re located, you may have rights to access, correct, export, or delete your personal data. Dashboard users can exercise most of this directly (export leads to CSV, delete campaigns) or by contacting us. If you’re a visitor who spun a widget on a merchant’s site and want your data removed, the merchant is the right first contact since they control that data — but you can also reach us and we’ll help route the request.
We’ll update this page if our data practices change, and update the “last updated” date above.
Questions about this policy or a data request: privacy@getspinlet.com.