Legal
Privacy Policy
What we collect today
Automatic price monitoring is not open to new customers. There is no receipt or screenshot upload on this site, and customer sign-in is not currently available.
If you reserve a beta place
Reserving a place is the one thing on this site that collects personal data. When you reserve, we collect:
- your email address — so we can send your confirmation and invite you when monitoring opens;
- the retailer you said you would want protected, and the country you shop in — this is demand research, and choosing a retailer here does not mean we support or monitor it;
- an optional note about what you would want protected. We store that note as text. We do not look it up, and we do not visit any link you put in it.
Your payment is processed by Stripe. Card details go directly to Stripe and never reach DropRefund’s servers — we receive only a confirmation that the payment succeeded, and an identifier we use to refund you.
If you email us, we receive whatever you choose to put in that email, and we keep it so that we can reply.
When monitoring opens
When we open monitoring we expect to additionally collect the product you bought, the price you paid, the date you bought it, and whether you hold a retailer membership — that last one changes your deadline. We will update this policy before that happens.
What we do not collect
- We do not ask for or store receipts, order documents, or screenshots.
- We do not store payment card details. Stripe processes them directly; card details do not reach DropRefund’s servers.
- We do not ask for your name, address, or phone number.
- We do not have access to your retailer account.
Who processes data for us
| Provider | Purpose | What they receive |
|---|---|---|
| Vercel | website and API hosting | standard request logs |
| Google Analytics | website usage measurement | page views and traffic source |
| Supabase | database hosting | any monitoring data we hold |
| Resend | sending our emails | your email address and the message |
| Stripe | payment processing for beta reservations | your payment details, directly; we receive only a confirmation and a payment identifier |
We do not sell your data and we do not share it for advertising.
Analytics and the links we send you
Some links we email you contain a single-use access token in the address. Our analytics is configured to strip that token before any page address is sent to Google Analytics, and those pages are served with Referrer-Policy: no-referrer so the token is not leaked to other sites.
How we store access links
Access links in our emails are single-use bearer tokens. We store only a SHA-256 hash of each token, never the token itself. Anyone holding the link can open the page it points to, so please do not forward those emails.
How long we keep it
We currently keep the data we hold indefinitely unless you ask us to delete it. We have not yet implemented automatic deletion after a fixed period. If you want your data removed, email support@droprefund.com and we will delete it.
Your choices
- Ask what we hold about you.
- Ask us to delete it.
Changes
We will update the “last updated” date when this policy changes.