Legal
Privacy policy
This policy explains what data paydrop.app collects, why we use it, and how you can exercise your rights. By using the platform you agree to these practices.
1. Who we are
paydrop.app is a service that lets anyone sell private files and links through a payment link — creators, professionals, and other sellers. Contact: support@paydrop.app.
2. Data we process
- Seller account: name, email, password (hashed), handle, bio, and profile photo.
- Content: encrypted file ciphertext or URLs you upload, titles, prices, and visibility settings. For file Drops, encryption happens in your browser first — we store ciphertext, not readable originals.
- Purchases: buyer name and email, displayed payment method, amount, and access tokens.
- Payments: card numbers are processed by Stripe via tokenization. paydrop.app does not store full credit or debit card numbers in its database.
- Technical use: session, essential cookies, and basic security logs.
3. How we use it
- Operate your account and dashboard.
- Process payments and deliver access to buyers.
- Let buyers recover purchases with the email used at checkout.
- Show your public profile when you enable it.
- Prevent abuse and keep the service secure.
- Process account deletion requests (soft-delete, then scrub personal data after the grace period).
4. Who we share it with
We do not sell your data. We only share what is needed to run the service (for example payment data with Stripe when you pay or connect payouts) or when required by law. Buyers see the seller name/handle and photo associated with the resource. Stripe processes card details under its own privacy policy; paydrop.app does not retain card PANs.
5. Retention
We keep your account while it is active. Purchase records and access tokens are kept as long as needed to deliver and recover content, unless you request deletion where applicable.
6. Your rights
You can request access, correction, or deletion of your account data by writing to support@paydrop.app. You can also edit your profile and photo from the dashboard.
7. Security
We use hashed passwords, protected sessions, and basic upload controls. File Drops use zero-knowledge encryption in the browser (AES-GCM) before upload: paydrop.app stores encrypted bytes and does not hold the decryption key, so we cannot open your file contents. No system is perfect; please avoid weak or reused passwords, and keep share links private.
8. Changes
If we update this policy, we will change the date above. Continued use means you accept the current version.