Skip to content

Legal

Privacy

Written to be read. Where a practice would be uncomfortable to describe plainly, the answer has been to change the practice rather than the wording.

Effective date: to be set at general availability · Version 0.9 (draft)

This document is a working draft

DropRoute is not yet generally available and this policy has not been reviewed by a lawyer. It describes what the software actually does today, which makes it useful, but it is not a substitute for legal review and the operating entity’s details are not yet filled in. Do not rely on it as a finished agreement.

Who this covers

There are two different people in this document and they are treated differently.

Account holders

Artists, managers, and teams who sign up and create links. DropRoute is the controller of their account data.

Fans

People who visit a public link page or sign up to an artist’s list. The artist is the controller of that fan data; DropRoute processes it on their behalf, under the terms in the data processing page.

What is collected from account holders

The email address you sign up with, a display name if you set one, your workspace and plan, and a record of administrative actions taken in your workspace. Passwords are handled by the authentication provider and are never visible to DropRoute.

If you subscribe, payment is processed by Stripe. DropRoute stores a customer reference and a subscription state. Card numbers never reach DropRoute’s servers.

Visitors to a public page

Visiting a link page records an event: the time, the page, the country derived at the network edge, a device and browser category derived from the user agent, and the referring site where the browser supplies one.

Full IP addresses are not stored. Where a stable identifier is needed to estimate unique visitors, it is a salted digest that changes every day, so it cannot follow a person between reporting windows. City-level location is not stored at all.

A first-party cookie holds an opaque session identifier for thirty minutes so that two page views by the same person are not counted as two visits. It contains no personal data and is not shared with anyone.

Fans who sign up to a list

The address is encrypted before it is stored and is looked up by keyed hash, so the database never holds it in readable form. Stored alongside it: the exact consent wording shown at the moment of signup, when it was given, which page it came from, and the country.

Unsubscribing works from any message and from the link in it, immediately, without signing in. The address then goes onto a suppression list that survives deletion of the record, so a later signup form cannot quietly re-add it.

How long it is kept

Raw analytics events — 90 days

Then deleted by a scheduled job. This is enforced in the database, not merely stated here.

Aggregated analytics — for the life of the plan

Daily and hourly totals with no identifier attached to them. This is what “unlimited history” refers to.

Fan records — until deleted

By the artist, or by the fan asking. Consent records are retained as evidence for as long as legally necessary even after the fan record is removed.

Audit events — retained

A record of who did what in a workspace. It cannot be edited or deleted, which is the entire point of it.

Deleted workspaces — purged after a recovery window

So that an accidental deletion can be undone, and a deliberate one is genuinely carried out.

Who else sees it

Supabase hosts the database. Vercel serves the application. Stripe processes payments. Resend delivers transactional email when it is configured. Each of these processes data in order to provide that specific function.

Nothing is sold. There is no advertising network, no data broker, and no arrangement in which a streaming service pays for placement or receives your audience.

Your rights

You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Account holders can do the first two from within the product — Settings, then Privacy — and the third by asking.

A fan should contact the artist whose list they are on, because that artist is the controller. If they cannot reach them, DropRoute will assist: support@droproute.app (opens in a new tab).

Contact

support@droproute.app (opens in a new tab). The operating entity, its registered address, and any supervisory-authority details will be listed here before general availability.