← Back to home

Privacy Policy

Effective 12 September 2026 · Last updated 12 September 2026

1. Who we are and what this covers

Dropwire is operated by an independent sole trader (the"Service Provider", "we", "us"). This policy explains what personal data we collect through the Dropwire website and application, why, who we share it with, how long we keep it, and what rights you have.

Dropwire is offered to business users. It is not directed at children, and we do not knowingly collect data from anyone under 18.

2. Two different roles, and why the distinction matters

For your own account data, we are the controller. We decide how your email address, login records and subscription status are handled, and this policy governs that.

For data about your audience, you are the controller and we are your processor. The people in your Telegram channels and WhatsApp groups are your contacts, not ours. We process data about them only to carry out your instructions, which in practice means delivering the posts you publish and counting the clicks they generate.

It follows that you are responsible for having a lawful basis to message those people and for answering their privacy requests. If someone in your audience contacts us directly, we will normally refer them to you.

3. What we collect, why, and on what basis

Account and authentication

Your email address, a hashed password if you set one, and your sign-in identity if you use Google or Facebook. We never store your password itself. Basis: performance of our contract with you.

Session security

The IP address and browser user agent recorded when you sign in, used to detect and investigate unauthorised access. Basis: our legitimate interest in securing accounts. These are erased after 90 days.

Connected credentials

The affiliate keys, bot tokens, model provider keys and WhatsApp connection you supply. These are encrypted at rest with AES-256-GCM under a key that is specific to your workspace, and they are deliberately excluded from every data export. Basis: performance of our contract.

Operational records

Products, posting history, channel configuration, conversions and revenue figures. These are business records rather than personal data about your audience, but they are associated with your account. Basis: performance of our contract.

Click tracking

When someone follows a tracked link we record the click, a coarse location derived from the IP address, the user agent, and a rotating daily hash used to distinguish repeat visitors without identifying them. The IP address, user agent and that hash are all erased after 90 days. We do not build cross-site profiles and we do not sell this data. Basis: your legitimate interest as controller in attributing your own affiliate activity.

Audit records

Records of significant actions, including consent you gave before enabling WhatsApp, and of any access by us to your workspace for support. Some carry an IP address and session identifier for incident investigation; those elements are erased after 90 days while the record of the action itself is retained. Basis: legal obligation and our legitimate interest in accountability and dispute evidence.

Billing

We store your subscription status and the identifiers our payment provider gives us.We never receive or store your card details, which are handled entirely by our payment provider as Merchant of Record. Basis: performance of our contract and legal obligation for tax records.

Waitlist

If you join the waitlist we store your email address to notify you about launch. Basis: consent, which you may withdraw at any time by asking us to remove you.

4. Who we share it with

We do not sell personal data and we do not share it for advertising. We use the following service providers, each under contract and each limited to what its function requires:

ProviderPurposeDataLocation
HetznerHosting of the application and databaseAll application dataGermany (EU)
CloudflareDNS, CDN, web application firewall, and page-performance analytics on this marketing siteRequest metadata, IP addresses, page timingsGlobal
Backblaze B2Encrypted off-site backupsFull database, encrypted before uploadUnited States
Payment providerMerchant of Record, payments (named at checkout)Billing details and card data, held by themNamed at checkout
ResendTransactional and waitlist emailEmail addresses, message contentUnited States
GoogleSign-in with Google, and product scoring via GeminiSign-in identity; product text and imagesUnited States
MetaSign-in with FacebookSign-in identityUnited States
SentryError monitoringDiagnostic data, with personal data stripped before sendingUnited States
ImageKitProduct image rendering and deliveryProduct images, not personal dataGlobal
AliExpressAffiliate product data and link generationYour affiliate credentials, server sideGlobal
TelegramMessage delivery to your channelsChannel identifiers, post contentGlobal
WhatsApp and Meta, via a self-hosted Evolution gatewayMessage delivery to your WhatsApp groupsYour connected number, post contentSelf-hosted, EU
OpenAICaption and content generation, usually under your own API keyProduct text and your brand voice promptUnited States
AnthropicCaption and content generation, usually under your own API keyProduct text and your brand voice promptUnited States

We may also disclose data where required by law, to establish or defend legal claims, or in connection with a transfer of the business, in which case you will be told before your data becomes subject to a different policy.

5. International transfers

The application and database are hosted in Germany. Several providers listed above are in the United States or operate globally, so personal data is transferred outside the European Economic Area and outside Israel. Those transfers rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one applies, or on the provider's participation in an approved framework. You may ask us which mechanism applies to a particular provider.

6. How long we keep it

  • Account data: for as long as your account exists. After you delete it there is a30 day grace period during which it can be restored, after which it is erased.
  • Session and click identifiers (IP address, user agent, visitor hash): 90 days, then irreversibly removed.
  • Audit records: retained for up toseven years for tax, accounting and proof-of-consent purposes, with the identifying user reference removed when you erase your account.
  • Backups: encrypted backups are retained on a rolling basis and expire between 30 and 35 days. Data you delete persists in a backup until that backup expires.
  • Connected credentials: deleted with your account.

7. Your rights, and how to use them

Subject to the law that applies to you, you may request access to your personal data, its correction, its erasure, a portable copy, restriction of processing, and you may object to processing based on legitimate interests. Where processing rests on consent you may withdraw it at any time, without affecting what was lawful before.

You do not have to ask us for most of this. Signed-in users can download their own data and erase their own personal data from the"Your data" section of account settings. Owners can additionally export the whole workspace. For anything else, write tohello@dropwire.ccand we will respond within one month.

If you are unhappy with how we have handled your data you may complain to your local supervisory authority. In Israel that is the Privacy Protection Authority; in the EEA it is the data protection authority where you live or work.

8. Cookies and similar technologies

The application sets a session cookie so that you stay signed in. It is strictly necessary for the service to function and cannot be switched off without signing you out.

We do not use advertising cookies, third-party analytics trackers, or cross-site tracking. Tracked affiliate links count a click server side and set no cookie on the visitor's browser.

9. How we protect it

Measures include encryption in transit, encryption of connected credentials at rest under per-workspace keys, database-level isolation so one workspace cannot read another's rows, encrypted off-site backups, restricted and audited administrative access, two-factor authentication on administrative accounts, and monitoring configured to strip personal data before diagnostics leave our systems.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, you, without undue delay.

10. Changes

We may update this policy. Where a change is material we will give notice by email or in the product before it takes effect, and the date at the top of this page will change.

11. Contact

Privacy questions, requests and complaints:hello@dropwire.cc.