Skip to content
Dropify
Live dropsTrendingStatsBrandsPricing
Sign inStart free

Privacy policy

Effective 2026-05-19 · Last updated 2026-10-04

1. Who we are, and how to reach us

Dropify is operated by Benjamin Capital Ventures LLC, a limited liability company organized under the laws of the State of Wyoming, USA. In this policy "we" and "us" mean that company. This policy applies to the site at dropify.cloud, the signed-in app at app.dropify.cloud, the API at production.dropify.cloud, and the Dropify Discord bot. Together they are the Service.

One address handles everything in this policy, and it is read by a person: support@dropify.cloud. We would rather publish one inbox we answer than three that look tidier. Put SECURITY in the subject for a vulnerability report. Our registered postal address, for service of formal notices, is 30 N Gould St, Ste R, Sheridan, WY 82801, USA.

2. What this policy covers, and the role we play

Under the EU General Data Protection Regulation, the UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and comparable laws elsewhere, Benjamin Capital Ventures LLC is the controller of personal data about Dropify users. We decide what is collected and why, and this policy is that decision written down.

We also sell keyed access to aggregate price data through a business API. That data is about products and stores, not about people: no personal data of any Dropify user is exposed through it. Should we ever process personal data on behalf of a business customer, we would be a processor for that specific processing and it would be governed by a separate data processing agreement rather than by this policy. No such arrangement is in place today.

3. What we hold about you

  • Who you are. Your Discord user id, username, display name, avatar and the email address Discord gives us, plus whether Discord reports that address as confirmed. For the avatar we keep only the id Discord gives the picture: the picture stays on Discord's servers, and your browser loads it from there. If you sign in or pay through Whop, the same set from Whop. One account role.
  • Your profile. The display name you choose on your Profile page, if you choose one. Until you do, and if you clear it, you're shown by your Discord display name, then your username. Your photo is your Discord avatar, or your initial if you don't have one. If you make your profile public, the username, bio and brands you set out there are shown with your display name, avatar, plan and the date you joined.
  • What you bought. The customer and subscription ids issued by whichever provider took the payment — a Stripe customer and subscription id, or a Whop membership id — plus plan, billing period, status and renewal date. We never receive your card number, its security code, or bank details. Those go from you to Stripe or Whop and never touch our servers.
  • What you follow. The brands and stores you track, your alert preferences, how many alerts reached you this month, and anything you post in in-app chat. If you set a brand to Daily summary, we keep a note of each of its alerts until your summary goes out, for at most seven days: the brand, the kind of event and the time. We also keep the time your last summary was sent. The summary counts only the stores your plan covers, and it comes at most once a day, only when something has happened at them.
  • Custom alerts. If you set one up, we hold the rule (the brand, product or words it watches, the events it fires on and any price you give it), the places it sends to, and a log of every alert we tried to send you: the message, the time, and whether it arrived. A Discord DM goes to the Discord account you signed in with, and an email goes to your account's address once Discord or Whop has confirmed it, so neither needs anything new from you. A Discord DM reaches you only when your Dropify account is linked to Discord and you’re a member of the Dropify Discord server with messages from its members allowed. A text goes through your own Sendblue account, so for that we hold your Sendblue API key ID and secret, the Sendblue number the text is sent from and the phone number it is sent to. A post to a channel in your own Discord server goes through a webhook, so we hold the webhook URL you paste, which works as a password for posting to that channel.
  • Lists. If you make a list, we hold its name, its note if it has one, and the products you add to it. For each product we hold the size and quantity you choose and any note you write. A list is private until you share it. Sharing it makes a link. Anyone who has the link can see the list, even without an account. A shared list shows its name and note, your display name and its items. It never shows your email address. You can stop sharing at any time, and the link stops working within 60 seconds. Share it again and it gets a new link.
  • Request logs. Every request to the API writes one line: IP address, user-agent, referrer, path, response status and time. Sign-in URLs are rewritten before they are written down, so a session token never reaches a log file. We derive country from IP for regional pricing. We do not resolve location more finely than that.
  • What you write to us. Support email and Discord messages to us, with any attachments.
We do not ask for and do not want special-category data — health, biometrics, race, religion, political opinion, union membership, sex life or orientation. Please do not put any of it into chat or a support ticket.

4. Where it comes from

Most of it comes from you: signing in, following a brand, setting up a custom alert, making a list, posting in chat, emailing support. Some arrives from Discord and Whop as part of the OAuth exchange, and Whop and Stripe send us webhooks when your subscription changes. The request logs and the cookies in Section 6 are produced automatically by the machinery of serving you a page.

5. Why we hold it, and the legal basis

  • To do what you paid for — GDPR Art. 6(1)(b). Delivering alerts, deciding what your plan includes, keeping you signed in, answering support.
  • Because the law requires it — Art. 6(1)(c). Keeping billing records for tax, and responding to valid legal process.
  • Because we have a legitimate interest — Art. 6(1)(f). Blocking abuse and fraud, keeping the Service up, debugging, counting usage in aggregate, defending claims, and the tips and activity email in Section 13, each with a one-click way out. You can object; Section 12 says how.
  • Because you agreed — Art. 6(1)(a). Marketing email, and nothing else. Withdraw it whenever you like and everything we did beforehand stays lawful.
Four things we do not do, stated flatly: we do not sell or rent personal data, we do not run behavioural advertising, we do not train machine-learning models on your data, and we make no automated decision that has a legal or similarly significant effect on you.

6. Cookies — all four of them

Dropify sets four cookies, and only four: two from our API that keep you signed in, one that remembers your answer to the cookie notice, and one you can refuse.
  • dropify.jwt — the signed token that keeps you logged in, set by our API when you sign in. HttpOnly, so no JavaScript can read it, Secure, and scoped to .dropify.cloud so it works across the site and the app. It lasts 90 days, and it stops working when you delete your account.
  • dropify.sid — a server session id, also set by our API. The session itself lives in our database, not in the cookie. HttpOnly and Secure, and it lasts 90 days.
  • dropify.consent — your answer to the cookie notice, and nothing else. This site writes it when you choose, and the app reads it so it honours the same answer. It lasts 180 days. The same answer is also kept in your browser under dropify_cookie_consent_v1, which is local storage rather than a cookie and never leaves your machine.
  • dropify.src — where you came from. It holds the campaign tags on the link you arrived through (source, medium, campaign, content), the host name of the site that linked you, and the date. Never a full address, never a page you looked at, and nothing that names you. This site or the app writes it once, on your first visit from outside, and never rewrites it. It lasts 90 days. It is not HttpOnly, because the app reads it as well, and if you sign up we copy it onto your account so we know which campaign brought you in. We write it only if you choose Accept on the cookie notice. Choose “Only what’s needed” and it is never written, and if your browser sends Global Privacy Control we do not write it whatever you chose.
The first two are not optional; without them you cannot stay signed in. The third is written only once you answer the notice, and only to hold that answer. The fourth is yours to refuse, and refusing costs you nothing you can see.

We run no analytics product on this site. No Google Analytics, no advertising pixel, no session recorder, no third-party script of any kind. What we know about traffic, we know from our own server logs and, where you accepted it, from the dropify.src cookie above, which is ours and goes nowhere else. If we ever load a third party's script, this section changes first.

7. Subprocessors: who else touches your data

These are our subprocessors, and this list is complete. Each gets only what its job needs.
  • Hostinger (Hostinger International Ltd.) — the rented server in Boston that runs our database. Everything in Section 3 lives here.
  • Heroku (Salesforce, Inc., USA) — runs the API and the websites, and holds the request logs.
  • Stripe (Stripe, Inc., USA) — takes card payments and holds the card details we never see.
  • Whop (Whop, Inc., USA) — the second payment route, and an alternative sign-in.
  • Discord (Discord, Inc., USA) — sign-in, and the channels alerts are delivered to. It also carries a custom alert you send as a direct message from our bot or through a webhook to your own server, and the daily summary our bot sends as a direct message for the brands you set to Daily summary.
  • Resend (Resend, Inc., USA) — sends our email, including any custom alert you send by email, and receives what you send to support@dropify.cloud.
  • Sendblue — only if you set up a custom alert by text. The text is sent through your own Sendblue account with the key you gave us, so Sendblue receives the message and the two phone numbers.
  • Cloudflare (Cloudflare, Inc., USA) — hosts the brand and store artwork. It sees the IP of whoever loads one of those images, and nothing else about you.
  • Webshare (Webshare Software Company, USA) — the proxy network our crawler reaches stores through. It carries no user data; it is listed because it is infrastructure, and this list is meant to be complete.
Product photos are not hosted by us or by Cloudflare. Your browser loads each one from the image host of the store that sells the product, which is Shopify for most of them, and that host sees your IP address when it does.

Beyond those: outside lawyers and accountants under confidentiality obligations when we need them; regulators and law enforcement when compelled by valid legal process or where we believe in good faith that disclosure is needed to stop harm; and an acquirer, if the company is ever sold, bound by this policy or obliged to tell you what changed.

We will give at least 30 days' notice before adding a subprocessor that would handle personal data, and you can object by email inside that window.

8. Sending data to the United States

Every server we use is in the United States. If you are outside it, using Dropify means your data crosses to the US and is processed there.

For transfers out of the EEA, the UK or Switzerland we rely on the European Commission's Standard Contractual Clauses adopted 4 June 2021 — Module One for controller-to-controller transfers and Module Two for controller-to-processor — with the UK International Data Transfer Addendum where the UK GDPR applies. Alongside them sit the technical measures in Section 11. Ask and we will send you copies.

9. How long we keep things

  • Your account — until you delete it. Section 10 sets out precisely what deletion does.
  • Request logs — they stay in Heroku's log service and expire on its schedule, roughly a week. We do not copy them anywhere else and we do not archive them.
  • Database backups — encrypted snapshots taken nightly, kept 14 days, with a floor of the seven most recent so a bad fortnight cannot leave us with none. A deleted record survives in a backup until every snapshot predating the deletion has aged out.
  • Custom alerts stay until you delete them or your account. Each place an alert sends to, with the keys, numbers or webhook URL stored for it, is deleted the moment you remove it. The log of what each alert sent is deleted after 30 days.
  • Billing records — seven years, because tax law says so.
  • Support email — 24 months from your last message.
  • Security and incident records — 24 months.
  • Aggregates — counts and totals that identify nobody are kept indefinitely.
We keep something longer only where the law requires it, or to bring or defend a legal claim.

10. What deleting your account does

Deletion is not a flag we set and revisit later. Ask for it and, in one pass, we delete your followed brands and stores, your per-product alert subscriptions, your lists, your custom alerts with every place they send to (Sendblue keys, phone numbers and webhook URLs included) and the log of what they sent, any push-notification registration, and every server session tied to your account, so a cookie left on another machine cannot sign you back in. We raise a counter on your account that invalidates every sign-in token already issued to you, so the 90-day tokens in Section 6 stop working immediately, without waiting for expiry. Links you shared to your lists stop working within 60 seconds.

What remains is a stripped record. Your email address is overwritten with an unusable placeholder, your Discord username, display name and avatar and the link to your Discord account are removed (so you can sign up again with the same login), your OAuth tokens for Discord and Whop are cleared, and your phone number, Telegram id, the display name you chose, bio and stored Whop profile are removed outright. The row itself is kept, marked deleted and stamped with the time, because the payment providers can still send us webhooks about a subscription you once had and we need somewhere to land them without accidentally recreating an account.

The consequence, stated plainly: this cannot be undone, and there is no recovery window. Deleting your account also cancels any Dropify subscription you hold at Stripe or Whop, so you aren't charged again.

To delete your account, open Settings in the app, press Delete account and type DELETE to confirm. The dialog lists what is deleted and what is kept before you confirm. Your account is deleted at once and you are signed out. If you can't sign in, email support@dropify.cloud from your account address with DELETE in the subject. We confirm within one business day.

11. How the data is protected

The measures below are the ones in place. We have deliberately not listed controls we intend to build.
  • The site, the app and the API are served over TLS. A request over plain HTTP is redirected to HTTPS, and their pages send HSTS, so a browser that has visited once uses HTTPS from then on.
  • The API reaches the database over TLS against a pinned certificate authority, so a substituted certificate fails the connection instead of being trusted.
  • Sessions are signed JSON Web Tokens. Every account carries a version counter, and raising it invalidates all of that account's outstanding tokens at once — that is the mechanism behind Section 10.
  • Payment webhooks from Stripe and Whop are checked against the provider's signature, with a replay window, before anything grants access. An unsigned or stale webhook is discarded.
  • Backups are encrypted with GnuPG using AES-256 before they leave the database host. The passphrase is stored on a different machine from the backups it opens, and is not in any code repository.
  • Log output passes through a filter that masks credentials inside URLs, so a stack trace cannot print a password into a log.
  • The Sendblue keys, phone numbers and webhook URLs behind a custom alert are encrypted with AES-256-GCM before they are written to the database, with a key the database does not hold. Only the last four characters are kept readable, so the app can show you which one it is.
  • Dependencies are updated and patched on an ongoing basis.
That list is the whole of it. What protects your data is transport encryption, backup encryption, access control and, for the custom-alert details above, field encryption; we make no claim of encryption at rest on the database volume itself. An earlier version of this policy asserted one, along with IP allowlisting and multi-factor authentication on administrative access, and none of those three described anything we operate.

No system is safe from everything. If you think your account has been reached by someone else, email support@dropify.cloud and we will look immediately. If a breach affects your personal data we will notify the relevant supervisory authority within 72 hours where GDPR requires it, and tell you directly without undue delay where the law requires that.

12. Your rights, and how to use them

Wherever you live, you can ask us for a copy of what we hold, to correct it, or to delete it. If GDPR or the UK GDPR applies to you, you can also restrict our processing, object to anything we do under legitimate interests, take your data elsewhere in a machine-readable format, and withdraw any consent you gave.

If you are a California resident, the CCPA adds the right to know the categories and the specific pieces we hold, to correct them, to opt out of the sale or sharing of personal information, to limit how sensitive personal information is used, and not to be treated worse for asking. Two of those are already answered: we do not sell or share personal information, and we do not process sensitive personal information at all. You may use an authorised agent, in which case we will want your written permission and proof of who you are.

We do not make any automated decision about you that produces a legal or similarly significant effect, so there is nothing there to contest.

Email support@dropify.cloud from the address on your account and say what you want. Confirming you control that address is usually all the identity check we need. We answer within 30 days, or 45 under the CCPA, and we will tell you before we take the extension the CCPA allows. The first request in any twelve months is free.

If we handle it badly, complain to your supervisory authority: your national data protection authority in the EU, the Information Commissioner's Office in the UK, or the Attorney General in California. You do not have to come to us first.

13. Email you get, and how to stop it

Some email is part of the Service and you cannot opt out of it while you have an account: payment receipts, notices about your subscription, security warnings. It is short, and there is not much of it.

Everything else goes only to an address your sign-in provider has confirmed, and stops as soon as you say so. It comes in two kinds.

Tips and activity. A few emails while you get started, a weekly recap of what the brands you follow did (only in a week when they did something), and a note when you haven't signed in for a while and something moved at your brands. Every one carries an unsubscribe link that opens a page with one button: press it and they stop, with no sign-in and no preference centre. Opening the link alone changes nothing, because some mail scanners open every link in a message. Mail apps that support one-click unsubscribe can also do it for you without opening the message, and the Tips and activity switch in Settings does the same. If you haven't signed in for 90 days we ask once whether to keep sending, and we stop if you don't answer within 14 days.

Product news. New stores, features and offers, sent only if you turned on Product news in Settings, and the same switch turns it off. Product news carries a link to a page where you can stop product news or all of our email.

Opting out stops email only; your Discord alerts and your in-app feed carry on untouched.

A custom alert you set up to arrive by email is separate from both. It is mail you asked for, and each one carries its own link that stops alert email to that address.

14. Children

Dropify is not for children under 13, or under 16 where local law sets that line, which includes the UK and several EU member states. We do not knowingly hold data about them. If you are a parent or guardian and think we have some, email support@dropify.cloud and we will delete the account and its data.

15. Do Not Track and Global Privacy Control

Your browser may send a Do Not Track or Global Privacy Control signal. Neither changes anything here, because there is nothing for them to switch off: we run no cross-site advertising and we do not sell or share personal data as the CCPA defines those words. Preferences you set in your account are of course honoured.

16. Links off Dropify

We link out constantly — to artist storefronts, to Discord, to checkout. Once you leave, you are covered by that site's privacy policy and not by this one. We have no control over what those sites collect.

17. Changes to this policy

When we change this policy we update the date at the top. If a change materially affects you, we will email subscribers and show a banner in the app at least 30 days before it takes effect, unless the law or a live security problem forces us to move sooner. Carrying on using Dropify after the new version takes effect means you accept it.

18. If part of this is unenforceable

If any part of this policy is held invalid, the rest still stands. Questions, complaints, and anything else in this document: support@dropify.cloud.