Last reviewed: 2026-06-01
Account data (email, profile), organization membership, billing metadata (held by Stripe), and security/audit logs. Strictly necessary cookies (session, CSRF) are documented and require no consent; analytics load only with consent.
We process each category of data on one of these bases:
We use third-party vendors to run the service, and each is bound by a data-processing agreement. The current list is available on request. Where a sub-processor stores or processes personal data outside the European Economic Area, that transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses, together with any additional safeguards required for the destination country. You can ask us for details of the safeguards that apply to a specific transfer.
Access, rectification, and erasure. You can export all your data and request account deletion in-app; deletion hard-deletes personal data within 30 days and anonymizes audit records.
Audit logs are retained for 2 years, application logs for 30 days, and soft-deleted records for 30 days before permanent deletion. Files received through your drop page follow the retention window you set (up to 3 days on Free, up to 30 days on Pro) and are deleted automatically when it expires.
For any privacy question, or to exercise your rights, contact us at privacy@dropspot.me.
The data controller is the operator of Dropspot. The registered legal entity, address, and any required EU representative will be named here once incorporation is complete — to be confirmed by counsel before launch.