Legal

Privacy Policy

Last updated: July 5, 2026

1. Who We Are

DropPoint is operated by [LEGAL ENTITY NAME], with its registered address at [registered address] and P.IVA / VAT number [NUMBER] (the “data controller” or “we”).

For any privacy questions, you can contact our privacy team at: [privacy@droppoint.app].

2. Scope

This Privacy Policy explains how DropPoint collects, uses, stores, shares, and protects personal data when you use the DropPoint website at droppoint.app and the DropPoint marketing analytics application (together, the “Service”). It applies to visitors, registered users, and account administrators.

This policy does not apply to third-party platforms you connect to DropPoint. Those platforms have their own privacy policies and terms, which you should review separately.

3. Data We Collect

We collect different types of data depending on how you interact with the Service.

(a) Account data you give us

When you create an account, we collect your name, email address, organization name, and billing information. We use this to create and manage your account, authenticate you, send service-related communications, and process payments.

(b) Data from connected platforms via their APIs

When you choose to connect a third-party platform (such as TikTok, Meta, Google Search Console, or Shopify), we collect analytics and performance data from that platform through its API or OAuth connection. This is described in detail in Section 4. We only access data you have authorized and only to the extent permitted by the platform.

(c) Technical and usage data

We collect standard technical data such as IP address, browser type, device information, operating system, and timestamps. We also collect usage logs (for example, pages visited, features used, errors) to operate, secure, and improve the Service. We may use cookies and similar technologies as described in Section 12.

(d) Support communications

If you contact us for support or feedback, we collect the information you provide, including your email address, message content, and any attachments, so we can respond to and resolve your request.

4. Data From Connected Platforms

DropPoint is a read-only analytics aggregator. When you connect a platform, we import data from your account on that platform and display it back to you in DropPoint dashboards. We do not post, publish, modify, or delete content on your connected platforms. You can disconnect a platform at any time from your DropPoint settings. Disconnection stops future data imports and triggers deletion of the previously imported analytics data, as described in Section 9.

TikTok

If you connect a TikTok account, DropPoint may access: public profile information (such as username and display name); aggregated follower, like, and video counts (via scopes such as user.info.basic); and public video metadata plus related metrics (via scopes such as video.list). This data is read-only, used only to build your analytics dashboards, and is deleted when you disconnect TikTok or delete your DropPoint account. DropPoint is not affiliated with, endorsed by, or sponsored by TikTok.

Meta / Instagram

If you connect an Instagram or Meta account, DropPoint may access profile information, audience metrics, content performance metrics (reach, impressions, engagement), and account-level analytics. This data is read-only and is used only to display your analytics in DropPoint. It is retained only while the connection remains active and is deleted when you disconnect or close your account. DropPoint is not affiliated with, endorsed by, or sponsored by Meta.

Google Search Console

If you connect Google Search Console, DropPoint accesses the search performance data for the properties you authorize, including queries, clicks, impressions, click-through rate (CTR), and average position. This data is read-only, used only to power your SEO dashboards, and is deleted when you disconnect Google Search Console or delete your DropPoint account. DropPoint's use of Google API data is further described in Section 5.

Shopify

If you connect a Shopify store, DropPoint may access sales and order analytics data for that store, such as order counts, revenue, and product performance. This data is read-only, used only to display your ecommerce analytics in DropPoint, and is deleted when you disconnect Shopify or delete your DropPoint account. DropPoint is not affiliated with, endorsed by, or sponsored by Shopify.

5. Google API Services — Limited Use

DropPoint's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Information received from Google APIs is NOT:

  • used or transferred for serving advertisements, including personalized, retargeted, or interest-based advertising;
  • used or transferred to determine creditworthiness or for lending purposes;
  • sold or transferred to data brokers, information resellers, or other parties;
  • used to develop, train, fine-tune, or improve any generalized AI or ML models;
  • read by humans, except (a) with the user's explicit consent, (b) for security or abuse investigations, (c) to comply with applicable law, or (d) where the data is aggregated and used for internal operations per applicable law.

You can revoke DropPoint's access to your Google data at any time by disconnecting the Google integration in your DropPoint settings or by removing DropPoint's access from your Google account permissions.

6. How We Use Data + Legal Bases

We process personal data for the following purposes and on the following legal bases under the GDPR (Article 6):

  • Providing the Service. We process your account data and connected-platform analytics data to provide the analytics dashboards, reports, and features you subscribe to. Legal basis: performance of contract.
  • Connecting third-party platforms. We process connected-platform data when you authorize a connection through OAuth. Legal basis: consent, which you can withdraw at any time by disconnecting the platform.
  • Security and fraud prevention. We process technical data, logs, and account activity to protect the Service, detect abuse, and prevent unauthorized access. Legal basis: legitimate interests.
  • Product improvement. We analyze aggregated usage patterns and internal performance data to improve the Service. Where this involves personal data, we rely on anonymized or aggregated data whenever possible. Legal basis: legitimate interests.
  • Billing and accounting. We process billing data to fulfill payments, issue invoices, and meet tax and accounting obligations. Legal basis: performance of contract and legal obligation.
  • Legal compliance. We process data where necessary to comply with applicable law, respond to lawful requests, or enforce our Terms of Service. Legal basis: legal obligation or legitimate interests.

7. How We Share Data

We do not sell your personal data. We share data only with trusted service providers (sub-processors) who help us operate the Service, and only to the extent necessary for their role. Our current sub-processors include:

  • Supabase ([REGION]) — database hosting, authentication, and storage.
  • [Lovable/hosting] — hosting infrastructure for the DropPoint application.
  • [Stripe for billing if used] — payment processing and billing management.

Connected-platform analytics data is processed on your behalf and is not shared for any independent purpose outside of providing the Service to you. We may also disclose data if required by law, to protect our rights, or in connection with a business transfer such as a merger or acquisition.

8. International Transfers

DropPoint is operated from Italy and primarily serves users in the European Union. If any sub-processor is located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your personal data in accordance with the GDPR.

[Confirm Supabase region.]

9. Data Retention

We retain your personal data only for as long as necessary for the purposes described in this policy or as required by law.

  • Account data. We retain your account and billing information for the life of your account, plus any additional period required by applicable tax, accounting, or legal obligations.
  • Connected-platform analytics data. We store periodic snapshots of analytics data from your connected platforms only while the integration remains connected. This allows us to show performance over time. When you disconnect a platform or delete your DropPoint account, we delete the associated imported analytics data, subject to any legal retention requirements.
  • Technical logs. We retain server logs and security logs for a limited period necessary for security, troubleshooting, and legal compliance.

10. Your Rights

Under the GDPR and applicable Italian data protection law, you have the following rights in relation to your personal data:

  • Access. You can request a copy of the personal data we hold about you.
  • Rectification. You can ask us to correct inaccurate or incomplete data.
  • Erasure (“right to be forgotten”). You can request deletion of your personal data in certain circumstances.
  • Restriction. You can ask us to limit how we use your data.
  • Portability. You can request a copy of your data in a structured, commonly used, machine-readable format.
  • Objection. You can object to processing based on legitimate interests, including direct marketing.
  • Withdraw consent. Where we rely on your consent, you can withdraw it at any time by disconnecting the relevant platform or contacting us.

To exercise any of these rights, please contact us at: [privacy@droppoint.app]. We will respond within the timeframes required by law.

You also have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali, or with the supervisory authority of your country of habitual residence if you are in the EU.

11. Data Security

We take appropriate technical and organizational measures to protect your data:

  • Data in transit is encrypted using TLS/HTTPS, and data at rest is encrypted by our database provider.
  • OAuth tokens and other secrets are stored in a secure secrets vault, not in plain text or in application logs.
  • Access to production systems is restricted to authorized personnel and protected by role-based access controls and strong authentication.
  • We regularly review our security practices and monitor for vulnerabilities and unauthorized access.

No online service can be completely secure. If you discover a security issue, please contact us immediately.

12. Cookies

We use cookies and similar technologies to operate the Service, authenticate users, remember preferences, and understand usage. Essential cookies are necessary for the Service to function. Where we use non-essential analytics or marketing cookies, we will request your consent in accordance with applicable law.

For a detailed list of cookies and how to manage them, please see our Cookie Policy (if available).

13. Children

The Service is not directed to anyone under the age of 18. Under Italian law, we do not knowingly collect personal data from anyone under 16 without appropriate parental consent. If you believe we have collected data from a child under the applicable age, please contact us and we will delete the data promptly.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice in the Service before the changes take effect. Where required by law, we will obtain your consent before processing your data for new purposes. Your continued use of the Service after the effective date of the revised policy constitutes acceptance of the changes.

15. Contact

For questions, requests, or complaints about this Privacy Policy or our data practices, please contact us at: [privacy@droppoint.app]

Postal address: [registered address]