Privacy Policy
Effective 12 September 2026 · Last updated 12 September 2026
1. Who we are and what this covers
Dropwire is operated by an independent sole trader (the"Service Provider", "we", "us"). This policy explains what personal data we collect through the Dropwire website and application, why, who we share it with, how long we keep it, and what rights you have.
Dropwire is offered to business users. It is not directed at children, and we do not knowingly collect data from anyone under 18.
2. Two different roles, and why the distinction matters
For your own account data, we are the controller. We decide how your email address, login records and subscription status are handled, and this policy governs that.
For data about your audience, you are the controller and we are your processor. The people in your Telegram channels and WhatsApp groups are your contacts, not ours. We process data about them only to carry out your instructions, which in practice means delivering the posts you publish and counting the clicks they generate.
It follows that you are responsible for having a lawful basis to message those people and for answering their privacy requests. If someone in your audience contacts us directly, we will normally refer them to you.
3. What we collect, why, and on what basis
Account and authentication
Your email address, a hashed password if you set one, and your sign-in identity if you use Google or Facebook. We never store your password itself. Basis: performance of our contract with you.
Session security
The IP address and browser user agent recorded when you sign in, used to detect and investigate unauthorised access. Basis: our legitimate interest in securing accounts. These are erased after 90 days.
Connected credentials
The affiliate keys, bot tokens, model provider keys and WhatsApp connection you supply. These are encrypted at rest with AES-256-GCM under a key that is specific to your workspace, and they are deliberately excluded from every data export. Basis: performance of our contract.
Operational records
Products, posting history, channel configuration, conversions and revenue figures. These are business records rather than personal data about your audience, but they are associated with your account. Basis: performance of our contract.
Click tracking
When someone follows a tracked link we record the click, a coarse location derived from the IP address, the user agent, and a rotating daily hash used to distinguish repeat visitors without identifying them. The IP address, user agent and that hash are all erased after 90 days. We do not build cross-site profiles and we do not sell this data. Basis: your legitimate interest as controller in attributing your own affiliate activity.
Audit records
Records of significant actions, including consent you gave before enabling WhatsApp, and of any access by us to your workspace for support. Some carry an IP address and session identifier for incident investigation; those elements are erased after 90 days while the record of the action itself is retained. Basis: legal obligation and our legitimate interest in accountability and dispute evidence.
Billing
We store your subscription status and the identifiers our payment provider gives us.We never receive or store your card details, which are handled entirely by our payment provider as Merchant of Record. Basis: performance of our contract and legal obligation for tax records.
Waitlist
If you join the waitlist we store your email address to notify you about launch. Basis: consent, which you may withdraw at any time by asking us to remove you.
4. Who we share it with
We do not sell personal data and we do not share it for advertising. We use the following service providers, each under contract and each limited to what its function requires:
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Hetzner | Hosting of the application and database | All application data | Germany (EU) |
| Cloudflare | DNS, CDN, web application firewall, and page-performance analytics on this marketing site | Request metadata, IP addresses, page timings | Global |
| Backblaze B2 | Encrypted off-site backups | Full database, encrypted before upload | United States |
| Payment provider | Merchant of Record, payments (named at checkout) | Billing details and card data, held by them | Named at checkout |
| Resend | Transactional and waitlist email | Email addresses, message content | United States |
| Sign-in with Google, and product scoring via Gemini | Sign-in identity; product text and images | United States | |
| Meta | Sign-in with Facebook | Sign-in identity | United States |
| Sentry | Error monitoring | Diagnostic data, with personal data stripped before sending | United States |
| ImageKit | Product image rendering and delivery | Product images, not personal data | Global |
| AliExpress | Affiliate product data and link generation | Your affiliate credentials, server side | Global |
| Telegram | Message delivery to your channels | Channel identifiers, post content | Global |
| WhatsApp and Meta, via a self-hosted Evolution gateway | Message delivery to your WhatsApp groups | Your connected number, post content | Self-hosted, EU |
| OpenAI | Caption and content generation, usually under your own API key | Product text and your brand voice prompt | United States |
| Anthropic | Caption and content generation, usually under your own API key | Product text and your brand voice prompt | United States |
We may also disclose data where required by law, to establish or defend legal claims, or in connection with a transfer of the business, in which case you will be told before your data becomes subject to a different policy.
5. International transfers
The application and database are hosted in Germany. Several providers listed above are in the United States or operate globally, so personal data is transferred outside the European Economic Area and outside Israel. Those transfers rely on the European Commission's Standard Contractual Clauses, on an adequacy decision where one applies, or on the provider's participation in an approved framework. You may ask us which mechanism applies to a particular provider.
6. How long we keep it
- Account data: for as long as your account exists. After you delete it there is a30 day grace period during which it can be restored, after which it is erased.
- Session and click identifiers (IP address, user agent, visitor hash): 90 days, then irreversibly removed.
- Audit records: retained for up toseven years for tax, accounting and proof-of-consent purposes, with the identifying user reference removed when you erase your account.
- Backups: encrypted backups are retained on a rolling basis and expire between 30 and 35 days. Data you delete persists in a backup until that backup expires.
- Connected credentials: deleted with your account.
7. Your rights, and how to use them
Subject to the law that applies to you, you may request access to your personal data, its correction, its erasure, a portable copy, restriction of processing, and you may object to processing based on legitimate interests. Where processing rests on consent you may withdraw it at any time, without affecting what was lawful before.
You do not have to ask us for most of this. Signed-in users can download their own data and erase their own personal data from the"Your data" section of account settings. Owners can additionally export the whole workspace. For anything else, write tohello@dropwire.ccand we will respond within one month.
If you are unhappy with how we have handled your data you may complain to your local supervisory authority. In Israel that is the Privacy Protection Authority; in the EEA it is the data protection authority where you live or work.
8. Cookies and similar technologies
The application sets a session cookie so that you stay signed in. It is strictly necessary for the service to function and cannot be switched off without signing you out.
We do not use advertising cookies, third-party analytics trackers, or cross-site tracking. Tracked affiliate links count a click server side and set no cookie on the visitor's browser.
9. How we protect it
Measures include encryption in transit, encryption of connected credentials at rest under per-workspace keys, database-level isolation so one workspace cannot read another's rows, encrypted off-site backups, restricted and audited administrative access, two-factor authentication on administrative accounts, and monitoring configured to strip personal data before diagnostics leave our systems.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required, you, without undue delay.
10. Changes
We may update this policy. Where a change is material we will give notice by email or in the product before it takes effect, and the date at the top of this page will change.
11. Contact
Privacy questions, requests and complaints:hello@dropwire.cc.