Legal
Data processing
When a fan signs up to your list, you are the controller of that data and DropRoute is your processor. This page sets out what that means in practice.
Effective date: to be set at general availability · Version 0.9 (draft)
This document is a working draft
Not yet reviewed by a lawyer, and the operating entity is not yet named. A signable data processing agreement, with standard contractual clauses where they are required, will be available before general availability. If you need one now, ask (opens in a new tab) and we will tell you honestly where it stands.
Who is who
You are the controller of fan data
DropRoute is the processor
DropRoute is the controller of your account data
What is processed
Fan email addresses, consent records, the page and campaign a signup came from, a country derived at the network edge, and activity timestamps. Processing continues for as long as you hold the record.
Addresses are encrypted with AES-256-GCM before storage and looked up by keyed hash. The database never holds a readable address, which also means DropRoute cannot read your list casually — it has to decrypt it, in the same code path you use.
Acting on instructions
DropRoute processes fan data only to provide the service and only on your instruction — which in practice means: what you configure in the product. It does not use your fan data to market to those people, to enrich a profile, to train a model, or to seed another workspace.
Staff access is restricted, and any administrative access to a workspace is recorded in an audit trail that cannot be edited.
Subprocessors
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and file storage | All workspace and fan data, with addresses encrypted before they are written |
| Vercel | Application hosting and content delivery | Request metadata in transit; no fan records stored at rest |
| Stripe | Payment processing for account holders | Account-holder billing data only. No fan data. |
| Resend | Transactional email delivery, when configured | Recipient address and message content for the message being sent |
Adding a subprocessor that touches fan data will be announced to account holders before it takes effect.
Security measures
Encryption in transit and at rest, application-level encryption of fan addresses, row-level security in the database as a second boundary independent of the application, a single permission map enforced on every action, and an immutable audit trail. The security page goes into detail, including what is not in place yet.
International transfers
Infrastructure is provided by companies based in the United States, so data may be processed there. Standard contractual clauses will be in place with each subprocessor where they are required, and the executed set will be listed here.
If something goes wrong
You will be told without undue delay, with what is known at the time rather than after an internal narrative has been agreed: what happened, which data was involved, what has been done, and what you may need to do. A later correction is better than a delayed first message.
Return and deletion
Your data is exportable as CSV at any time, from inside the product, without asking. On account closure it is deleted after a short recovery window, except where a record must be kept for a legal reason — consent evidence and suppression entries are the two cases, and both exist to protect the fan rather than the platform.