Skip to content

Legal

Privacy

Written to be read. Where a practice would be uncomfortable to describe plainly, the answer has been to change the practice rather than the wording.

Effective date: to be set at general availability · Version 0.9 (draft)

This document is a working draft

This policy describes what the software actually does today — every claim in it is checkable against the running product — and covers lawful bases, retention, your rights under the GDPR and US state laws, children, and breach notification. What is still blank is the operating entity and its registered address, and no lawyer has reviewed it. Both are needed before it is a finished policy.

Who this covers

There are two different people in this document and they are treated differently.

Account holders

Artists, managers, and teams who sign up and create links. DropRoute is the controller of their account data.

Fans

People who visit a public link page or sign up to an artist’s list. The artist is the controller of that fan data; DropRoute processes it on their behalf, under the terms in the data processing page.

What is collected from account holders

The email address you sign up with, a display name if you set one, your workspace and plan, and a record of administrative actions taken in your workspace. Passwords are handled by the authentication provider and are never visible to DropRoute.

If you subscribe, payment is processed by Stripe. DropRoute stores a customer reference and a subscription state. Card numbers never reach DropRoute’s servers.

Visitors to a public page

Visiting a link page records an event: the time, the page, the country — and, since 27 July 2026, the region and city — derived at the network edge, the device type, operating system, and browser derived from the user agent, the browser’s primary language, and the referring site and campaign parameters where the browser supplies them.

Full IP addresses are not stored. Where a stable identifier is needed to estimate unique visitors, it is a salted digest that changes every day, so it cannot follow a person between reporting windows. Region and city are stored as aggregate counters, never with an address or coordinates, and age and gender are not collected at all — nothing in a click reveals them.

A first-party cookie holds an opaque session identifier for thirty minutes so that two page views by the same person are not counted as two visits. It contains no personal data and is not shared with anyone.

Fans who sign up to a list

The address is encrypted before it is stored and is looked up by keyed hash, so the database never holds it in readable form. Stored alongside it: the exact consent wording shown at the moment of signup, when it was given, which page it came from, and the country.

Unsubscribing works from any message and from the link in it, immediately, without signing in. The address then goes onto a suppression list that survives deletion of the record, so a later signup form cannot quietly re-add it.

How long it is kept

Raw analytics events — 90 days

Then deleted by a scheduled job. This is enforced in the database, not merely stated here.

Aggregated analytics — for the life of the plan

Daily and hourly totals with no identifier attached to them. This is what “unlimited history” refers to.

Fan records — until deleted

By the artist, or by the fan asking. Consent records are retained as evidence for as long as legally necessary even after the fan record is removed.

Audit events — retained

A record of who did what in a workspace. It cannot be edited or deleted, which is the entire point of it.

Deleted workspaces — purged 30 days after deletion

The 30-day window is so that an accidental deletion can be undone; the purge at the end of it is so that a deliberate one is genuinely carried out. Consent evidence and suppression entries are the two things that survive it, because both exist to protect the fan.

Who else sees it

Supabase hosts the database. Vercel serves the application. Stripe processes payments. Resend delivers transactional email when it is configured. Each of these processes data in order to provide that specific function.

On the marketing and sign-up pages only — never on an artist’s public page, and never in the working dashboard — Google Analytics measures which pages bring visitors who go on to create an account, with Google’s advertising and cross-device features switched off in code. The cookies page lists the cookie it sets, by name.

Nothing is sold. There is no advertising network, no data broker, and no arrangement in which a streaming service pays for placement or receives your audience.

Where it is processed

The companies above are based in the United States, so data may be processed there regardless of where you live. For transfers out of the EEA, the UK, and other places that regulate them, standard contractual clauses will be in place with each processor where they are required; the data processing page tracks that work honestly, including what is not yet executed.

Your rights

You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Account holders can do all three from within the product — Settings, then Privacy. Deletion is recorded as a request and confirmed by a person rather than executed on one click, because an account may own workspaces with other members and live fan data; a deleted workspace is purged 30 days after the request.

A fan should contact the artist whose list they are on, because that artist is the controller. If they cannot reach them, DropRoute will assist: support@droproute.app (opens in a new tab).

US state privacy rights

If you live in California, Colorado, Connecticut, Virginia, or another US state with a comprehensive privacy law, you have the right to know what is collected, to get a copy, to correct it, to delete it, and not to be treated worse for exercising any of those. Email support@droproute.app (opens in a new tab) and we will verify the request against the account and answer within the time the law allows.

We do not sell personal information, and we do not share it for cross-context behavioural advertising — not in the ordinary sense of those words and not in the specific sense the CCPA gives them. There is no “do not sell” link here because there is nothing to opt out of. If that ever changes, this page changes first and the control appears with it.

We do not use or disclose sensitive personal information beyond what is needed to provide the service, and we do not profile people for decisions with legal effects.

Children

DropRoute is a business tool and is not directed at children. You must be at least 16 to hold an account. We do not knowingly collect personal data from anyone under 13, and if we learn that we have, the account and its data are deleted.

Artists who collect fan emails are responsible for their own audiences. If a fan signup turns out to be a child, tell us or the artist and the record is removed.

If there is a breach

If personal data is exposed in a way that is likely to put people at risk, the affected account holders are told without undue delay, and regulators are notified within 72 hours where the law requires it. The notice says what happened, what data was involved, what has been done about it, and what you should do — in that order, without waiting for the investigation to be complete before saying anything at all.

Security measures and the reporting address for vulnerabilities are on the security page.

Contact

support@droproute.app (opens in a new tab). [Operating entity, registered address, and supervisory-authority details — to be listed here before general availability.]