Skip to content

Legal

Data processing

When a fan signs up to your list, you are the controller of that data and DropRoute is your processor. This page sets out what that means in practice.

Effective date: to be set at general availability · Version 0.9 (draft)

This document is a working draft

Not yet reviewed by a lawyer, and the operating entity is not yet named. A signable data processing agreement, with standard contractual clauses where they are required, will be available before general availability. If you need one now, ask (opens in a new tab) and we will tell you honestly where it stands.

Who is who

You are the controller of fan data

You decide what your capture form says, whether confirmation is required, and what you do with the list afterwards.

DropRoute is the processor

It stores, encrypts, and returns that data on your instruction, and does nothing else with it.

DropRoute is the controller of your account data

Your email address, workspace, and billing state are DropRoute’s own responsibility, and are covered by the privacy policy.

What is processed

Fan email addresses, consent records, the page and campaign a signup came from, a country derived at the network edge, and activity timestamps. Processing continues for as long as you hold the record.

Addresses are encrypted with AES-256-GCM before storage and looked up by keyed hash. The database never holds a readable address, which also means DropRoute cannot read your list casually — it has to decrypt it, in the same code path you use.

Acting on instructions

DropRoute processes fan data only to provide the service and only on your instruction — which in practice means: what you configure in the product. It does not use your fan data to market to those people, to enrich a profile, to train a model, or to seed another workspace.

Staff access is restricted, and any administrative access to a workspace is recorded in an audit trail that cannot be edited.

Subprocessors

Companies that process data on DropRoute’s behalf
SubprocessorPurposeData involved
SupabaseDatabase, authentication, and file storageAll workspace and fan data, with addresses encrypted before they are written
VercelApplication hosting and content deliveryRequest metadata in transit; no fan records stored at rest
StripePayment processing for account holdersAccount-holder billing data only. No fan data.
ResendTransactional email delivery, when configuredRecipient address and message content for the message being sent

Adding a subprocessor that touches fan data will be announced to account holders before it takes effect.

Security measures

Encryption in transit and at rest, application-level encryption of fan addresses, row-level security in the database as a second boundary independent of the application, a single permission map enforced on every action, and an immutable audit trail. The security page goes into detail, including what is not in place yet.

International transfers

Infrastructure is provided by companies based in the United States, so data may be processed there. Standard contractual clauses will be in place with each subprocessor where they are required, and the executed set will be listed here.

If something goes wrong

You will be told without undue delay, with what is known at the time rather than after an internal narrative has been agreed: what happened, which data was involved, what has been done, and what you may need to do. A later correction is better than a delayed first message.

Return and deletion

Your data is exportable as CSV at any time, from inside the product, without asking. On account closure it is deleted after a short recovery window, except where a record must be kept for a legal reason — consent evidence and suppression entries are the two cases, and both exist to protect the fan rather than the platform.