Privacy Policy

DRAFT — pending legal review

This document is a factual draft describing how the system works today. It has not been reviewed by counsel and is not final.

What we collect

When you create an account we store your company name, work email address, and a bcrypt hash of your password. When you subscribe, Stripe processes your payment and we store your Stripe customer and subscription identifiers, plan, and subscription status — your card details go directly to Stripe and never touch our servers. When your agent reports, we store operational heartbeats: agent version, cycle status, cycle timestamp, and five integer counts (work items, deleted, exempted, opted out, not found), plus license-key metadata (issue, revocation, and last-seen timestamps).

What we never receive

The DROP Ops agent runs in your environment. Your consumer records, consumer identifiers (names, emails, phone numbers, dates of birth, ZIP codes, VINs, advertising identifiers), hashes of any of these, the contents of the state's deletion lists, and your DROP API key are processed on your machines and are never transmitted to us. Our heartbeat API enforces this in code by rejecting any payload containing fields beyond the counts and status listed above.

Where data lives

The dashboard runs on Vercel (US East) and its database on Neon-managed Postgres in AWS us-east-2 (Ohio, United States). Payments are processed by Stripe. These three providers act as our subprocessors for hosting, storage, and billing respectively.

How we use it

Account data operates your account; billing state activates and deactivates licenses; heartbeat counts render your own compliance dashboard and nothing else. We do not sell, share, or use your data for advertising, and we have no analytics trackers on the dashboard.

Retention and deletion

Account and heartbeat records are retained while your account exists. Contact us to delete your account; evidence logs and cycle outputs live only on your machines and are always fully under your control.