Privacy Policy

Last updated: 4 October 2026

1. Controller and contact

Illes Janos · Droppy https://droppyto.com/en/contact

For the processing described here, the controller is Illes Janos. Send privacy enquiries to https://droppyto.com/en/contact.

2. Accounts and public pages

We process email addresses, account identifiers, authentication/session information and profile preferences to create, authenticate and operate accounts. Google sign-in supplies the identity information needed for that process. The basis is generally performance of the user contract under Article 6(1)(b) GDPR.

Names, images, descriptions, messages, receiving links, addresses and other details selected for publication appear on public profile and campaign pages. They may be copied or indexed by others. Removing content from Droppy does not necessarily remove external copies.

3. Technical operations and communications

Hosting and authentication services process technical information such as IP addresses, request details, browser/device information and security events to operate and protect the service. The basis is our legitimate interest in secure service operation under Article 6(1)(f), or contractual necessity where applicable.

Enquiries contain the information you choose to send. We use it to answer requests and manage contractual issues. Contractual communications rely on Article 6(1)(b); legally required records on Article 6(1)(c). Registration does not automatically authorise marketing.

Gift codes, free-access grants and eligibility requests are linked to your account. Requests include the organization/cause name, a public website and the explanation you submit. Authorized administrators review requests and record decisions; eligibility is not automatically approved. We also store code redemptions, access expiry, moderation decisions and admin action logs to manage access and prevent abuse.

Service notifications and contact replies can be read in your account or private case page. These features currently do not send automatic email notifications. Registration choices may be kept in a necessary HttpOnly cookie for up to seven days until sign-in and profile creation. A private contact-access cookie may persist for up to 90 days.

4. Optional support-intent analytics

With permission through Privacy settings, Droppy records an event identifier, campaign, payment route, event type, selected amount and currency or token, and event time. Events concern handoffs, QR actions and copying. The basis for optional measurement is consent under Article 6(1)(a). Payment functions remain available if analytics are refused.

Campaign owners receive reports and exports at the detail allowed by their plan; Droppy may use these events for product analysis. They indicate support intent and do not prove a successful payment. Refusal means interactions are absent from those reports. Consent may be changed or withdrawn in Privacy settings; withdrawal does not affect prior lawful processing.

5. Payments, wallets and providers

Vercel hosts the application; Supabase supports authentication, database and uploaded content; Google provides optional sign-in. Wallet functions use Reown/WalletConnect and selected wallet, network or blockchain services. These services may process connection metadata and public wallet addresses. On-chain transactions are public and may remain accessible indefinitely; Droppy cannot erase blockchain records.

External receiving services apply their own privacy notices. A link, selected amount or receiving details may be passed to the selected provider depending on the integration. For actual Paddle purchases, Paddle processes checkout and purchase information under its own privacy notice; subscription/order status may be shared with Droppy to provide access and support.

Providers may process information outside the EEA. Applicable transfer safeguards and recipient details depend on the service used; request information about recipients and safeguards through our privacy contact. Provider notices are linked below. We do not sell personal data.

6. Storage and retention

Necessary browser storage supports authentication, locale/theme preferences and the privacy choice. The privacy choice is stored locally as droppy_privacy_v1 with the choice, version and timestamp. The previous droppy_cookie_consent dismissal does not authorise analytics.

We retain account and public-content records while needed to provide the account. After closure, data may be retained only for applicable legal duties, unresolved claims or other lawful necessities; backups and operational logs may remain for their limited operational purpose. Support and security records are retained according to their purpose and legal obligations. Reporting windows are not deletion periods. You may request specific retention information through our contact.

7. Rights and account deletion

Subject to applicable conditions, you may request access, correction, erasure, restriction and portability, object to processing based on legitimate interests, and withdraw consent. Submit requests through the contact form, identifying your account email where relevant. We may request proportionate identity verification.

Account deletion requests do not themselves cancel a paid subscription. Cancel it separately or ask us for assistance. Some records may need to be retained under law; we explain applicable exceptions. You may complain to a competent supervisory authority, including the Baden-Württemberg data protection authority.

8. Required and voluntary information

Information necessary for registration and account operation is needed to provide the service. Public profile content and optional analytics consent are voluntary. These notices do not authorise the campaign owner to collect additional personal information without an applicable legal basis.

Streamer alerts

If a campaign owner enables the streamer widget, you may explicitly send a support initiation containing the chosen payment route, amount and currency or token. This is not payment verification. QR scans and page views do not send alerts.

Your name is optional. Your name and message are stored and displayed publicly only when you tick the separate public-display consent; otherwise the initiation is anonymous. Messages are available only if the streamer enables them. The owner can see the most recent 30 days of initiations, mark them manually or hide them. These manual marks are not provider confirmations. Contact us with the initiation details if you want to request removal. Records are also deleted with the recipient account. This feature does not require opting into optional analytics.

Contact

Vercel PrivacySupabase PrivacyGoogle PrivacyReown PrivacyPaddle Privacy