Legal
Privacy
Written to be read. Where a practice would be uncomfortable to describe plainly, the answer has been to change the practice rather than the wording.
Effective date: to be set at general availability · Version 0.9 (draft)
This document is a working draft
This policy describes what the software actually does today — every claim in it is checkable against the running product — and covers lawful bases, retention, your rights under the GDPR and US state laws, children, and breach notification. What is still blank is the operating entity and its registered address, and no lawyer has reviewed it. Both are needed before it is a finished policy.
Who this covers
There are two different people in this document and they are treated differently.
Account holders
Fans
What is collected from account holders
The email address you sign up with, a display name if you set one, your workspace and plan, and a record of administrative actions taken in your workspace. Passwords are handled by the authentication provider and are never visible to DropRoute.
If you subscribe, payment is processed by Stripe. DropRoute stores a customer reference and a subscription state. Card numbers never reach DropRoute’s servers.
Visitors to a public page
Visiting a link page records an event: the time, the page, the country — and, since 27 July 2026, the region and city — derived at the network edge, the device type, operating system, and browser derived from the user agent, the browser’s primary language, and the referring site and campaign parameters where the browser supplies them.
Full IP addresses are not stored. Where a stable identifier is needed to estimate unique visitors, it is a salted digest that changes every day, so it cannot follow a person between reporting windows. Region and city are stored as aggregate counters, never with an address or coordinates, and age and gender are not collected at all — nothing in a click reveals them.
A first-party cookie holds an opaque session identifier for thirty minutes so that two page views by the same person are not counted as two visits. It contains no personal data and is not shared with anyone.
Fans who sign up to a list
The address is encrypted before it is stored and is looked up by keyed hash, so the database never holds it in readable form. Stored alongside it: the exact consent wording shown at the moment of signup, when it was given, which page it came from, and the country.
Unsubscribing works from any message and from the link in it, immediately, without signing in. The address then goes onto a suppression list that survives deletion of the record, so a later signup form cannot quietly re-add it.
How long it is kept
Raw analytics events — 90 days
Aggregated analytics — for the life of the plan
Fan records — until deleted
Audit events — retained
Deleted workspaces — purged 30 days after deletion
Where it is processed
The companies above are based in the United States, so data may be processed there regardless of where you live. For transfers out of the EEA, the UK, and other places that regulate them, standard contractual clauses will be in place with each processor where they are required; the data processing page tracks that work honestly, including what is not yet executed.
Why we are allowed to
Where the GDPR or UK GDPR applies, every use of personal data needs a lawful basis. Ours, in plain terms:
Performing the contract.Running your account, serving your pages, taking payment, and sending the service emails you cannot opt out of — a password reset, a receipt, a release-day report.
Legitimate interests. Keeping the service secure and working: aggregate analytics on our own site, rate limiting, abuse investigation, and audit logs. These are balanced against your interests, which is why visitor identifiers are salted and rotate daily and full IP addresses are not retained for ordinary analytics.
Consent. Fan mailing lists an artist collects, product marketing emails to account holders, and any tracking tag an artist adds to their own page. Consent is never assumed, never pre-ticked, and withdrawable at any time without affecting anything done before you withdrew it.
Legal obligation. Keeping tax and accounting records, and responding to lawful requests.
For fans who join an artist’s list, the artist is the controller of that relationship and DropRoute is their processor. The terms of that arrangement are on the data processing page.
Your rights
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Account holders can do all three from within the product — Settings, then Privacy. Deletion is recorded as a request and confirmed by a person rather than executed on one click, because an account may own workspaces with other members and live fan data; a deleted workspace is purged 30 days after the request.
A fan should contact the artist whose list they are on, because that artist is the controller. If they cannot reach them, DropRoute will assist: support@droproute.app (opens in a new tab).
US state privacy rights
If you live in California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you have the right to know what is collected, to get a copy, to correct it, to delete it, and not to be treated worse for exercising any of those. Email support@droproute.app (opens in a new tab) and we will verify the request against the account and answer within the time the law allows.
We do not sell personal information, and we do not share it for cross-context behavioural advertising — not in the ordinary sense of those words and not in the specific sense the CCPA gives them. There is no “do not sell” link here because there is nothing to opt out of. If that ever changes, this page changes first and the control appears with it.
We do not use or disclose sensitive personal information beyond what is needed to provide the service, and we do not profile people for decisions with legal effects.
Children
DropRoute is a business tool and is not directed at children. You must be at least 16 to hold an account. We do not knowingly collect personal data from anyone under 13, and if we learn that we have, the account and its data are deleted.
Artists who collect fan emails are responsible for their own audiences. If a fan signup turns out to be a child, tell us or the artist and the record is removed.
If there is a breach
If personal data is exposed in a way that is likely to put people at risk, the affected account holders are told without undue delay, and regulators are notified within 72 hours where the law requires it. The notice says what happened, what data was involved, what has been done about it, and what you should do — in that order, without waiting for the investigation to be complete before saying anything at all.
Security measures and the reporting address for vulnerabilities are on the security page.
Contact
support@droproute.app (opens in a new tab). [Operating entity, registered address, and supervisory-authority details — to be listed here before general availability.]