Who we are
Placeholder — to be completed at incorporation. dropify is established in the Netherlands. Its registered name, Chamber of Commerce (KvK) number and registered address will be stated here before launch.
We operate dropify.dev, a fair waiting room for high-demand product releases. Questions about this policy go to privacy@dropify.dev.
What this policy covers
There are two very different sets of people in play, and they are governed differently.
- You, our customer. The people who sign up, administer an account and pay invoices. We are the controller for that data, and this policy is what applies.
- Your shoppers. The visitors who wait in a queue on your store. You are the controller for their data and we act only on your instructions; what we may do with it is set out in the Data Processing Agreement, not here. You are the one who tells them about it, in your own privacy statement.
Data we hold about you
When you create an account we collect your name, email address and company details, and we store the technical credentials needed to run your account. When you contact support we keep that correspondence. When we invoice you we keep the billing details and the invoices themselves.
We use this to provide the service, to support you, to bill you, and to send you the emails a service has to send — invoices, security notices, and changes to these terms. We do not sell it, and we do not use it to advertise to you.
Legal basis: performance of our contract with you (article 6(1)(b) GDPR) for providing and billing the service; compliance with a legal obligation (article 6(1)(c)) for keeping invoices and accounting records; and our legitimate interest (article 6(1)(f)) in securing the service and defending claims.
Data we process for you
Running a queue means handling data about the shoppers waiting in it — principally network identifiers such as an IP address, what was requested, and the queue decision taken. We process that strictly on your instructions and for no purpose of our own. We do not use it to build profiles, we do not combine it across customers, and we do not sell or share it.
We do not determine a legal basis for that processing; you do, as controller. The DPA sets out the categories, the retention and our obligations in full.
Cookies and tracking
This website sets no cookies, runs no analytics and embeds nothing from a third party. The dashboard sets a session cookie so you stay signed in. The waiting room sets a small number of strictly functional cookies on your own store's domain to hold a shopper's place in line. None of them is used for advertising or analytics. Our security page explains this, including which of it is yours to disclose to your shoppers rather than ours.
Who else sees it
Our infrastructure provider, Cloudflare, processes data on our behalf in order to run the service. That is the only sub-processor involved: we invoice you directly and no third-party payment processor is in the loop.
Beyond that we disclose personal data only where the law requires it, or to professional advisers under a duty of confidentiality. If our business is ever transferred, you will be told before your data moves.
Transfers outside the EEA
Data may be processed outside the European Economic Area by that provider. Those transfers rely on its certification under the EU–US Data Privacy Framework and, where the Framework does not apply, on the European Commission's Standard Contractual Clauses. Details are in the DPA.
How long we keep it
Account data is kept while your subscription is live and deleted within 30 days of it ending, or sooner if you ask. Invoices and accounting records are kept for seven years, because Dutch tax law requires it. Support correspondence is kept for two years. Records we process on your behalf are governed by the DPA.
Your rights
You can ask us to give you a copy of the personal data we hold about you, to correct it, to delete it, to restrict what we do with it, or to give it to you in a portable format. You can object to processing we base on legitimate interest. Where processing rests on consent, you can withdraw it at any time without affecting what came before.
Most of this is available directly in the dashboard, which can export your account data and delete your account. For anything else, write to privacy@dropify.dev and we will respond within one month.
If one of your shoppers asks us about their data, we will refer them to you and let you know — the request is yours to answer, and we will help you answer it.
Security
Data is encrypted in transit and at rest, access is restricted and authenticated, and each customer's data is logically separated from every other's. Our security page sets out our position, including what we do not have.
Changes
We will email you at least 14 days before any material change to this policy takes effect. The effective date at the top always reflects the current version.
Contact and complaints
Privacy questions: privacy@dropify.dev
Security issues: security@dropify.dev
We would rather hear a complaint first and put it right. You are also entitled to complain to a supervisory authority — for us that is the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens — or to the authority where you live or work.