← DROPPD

Privacy Policy

How DROPPD collects, uses, and protects your information.

Last updated: July 15, 2026 (draft)

Draft — pending legal review

This document is an informational first-pass draft prepared to accelerate attorney review. It is not yet legally binding, does not constitute legal advice, and takes effect only once it has been reviewed, finalized, and published by DROPPD and its counsel. Text shown in brackets (for example [LEGAL ENTITY NAME]) is a placeholder to be completed before publication.

This Privacy Policy explains how DROPPD ("DROPPD", "we", "us", or "our"), operated by [LEGAL ENTITY NAME] at [BUSINESS ADDRESS], collects, uses, shares, and protects personal information when you use the DROPPD music platform at droppd.dev (the "Service"). It applies to creators and listeners alike.

1. Information We Collect

Account information

When you sign up, our authentication provider Clerk collects and stores your email address, name, and basic profile information. We receive this information from Clerk to identify your account.

Payment information

Purchases and creator payouts are processed by Stripe and Stripe Connect. Stripe collects and stores your payment-card and, for creators, identity, tax, and banking details directly. DROPPD does not receive or store your full card number. We receive limited transaction metadata (such as amounts, status, and identifiers) needed to fulfill purchases, calculate fees and payouts, and keep records.

Content you upload

For creators, we store the music files, cover art, titles, descriptions, and other metadata you upload as part of a dropp.

Usage and analytics

We collect information about how you interact with the Service — for example pages viewed, dropps played or previewed, saves, and other events — to operate, secure, and improve the Service.

Device and network information

We collect technical information such as IP address, browser and device type, and similar identifiers. IP addresses are also processed by our rate-limiting provider (Upstash) to protect the Service against abuse.

Social interactions

We store the reactions, follows, comments, and similar social activity you create on the Service.

Cookies and similar technologies

We and our providers use cookies and similar technologies for authentication, security, preferences, and analytics (see Section 6).

2. How We Use Your Information

We use personal information to: create and manage your account; operate the Service and its core features (uploading, discovery, previews, saves, follows, reactions); process purchases, calculate platform and processing fees, and pay out creators; provide customer support and respond to your requests; secure the Service, prevent fraud and abuse, and enforce rate limits; understand and improve how the Service is used; and comply with legal obligations and enforce our Terms.

3. Legal Bases for Processing (EEA/UK)

Where the EU or UK GDPR applies, we process personal information on these legal bases: performance of a contract (to provide the Service, process purchases, and pay creators); legitimate interests (to secure and improve the Service and prevent abuse, balanced against your rights); consent (for certain cookies/analytics and where otherwise required, which you can withdraw); and legal obligation (to meet tax, accounting, and other legal requirements).

4. Subprocessors and Third-Party Services

We rely on the following service providers ("subprocessors") to run the Service. Each processes personal information under its own privacy terms:

  • ClerkAuthentication — stores email, name, and profile.
  • Stripe / Stripe ConnectPayment processing and creator payouts — handles and stores card and payout data.
  • SupabaseDatabase and storage for account data and uploaded music/artwork.
  • VercelApplication hosting and delivery — processes request/log data.
  • UpstashRedis-based rate limiting — processes IP addresses to protect the Service.

This list may change as our providers change; we will keep it current. [Confirm the exact set and links with counsel and each provider’s current DPA.]

5. How We Share and Disclose Information

We do not sell your personal information. We share information: with the subprocessors above, to provide the Service; with other users where you choose to make information public (for example, your creator profile, published dropps, and public social interactions); in connection with a merger, acquisition, or asset sale; to comply with law, legal process, or valid government requests; and to protect the rights, safety, and property of DROPPD, our users, or the public.

6. Cookies and Tracking

We use strictly necessary cookies for authentication and security, and may use preference and analytics cookies to understand and improve the Service. You can control cookies through your browser settings; disabling some cookies may affect functionality. [If a consent banner / preference tool is required for your target markets, wire it here.]

7. Data Retention

We keep personal information for as long as your account is active and as needed to provide the Service, then retain it only as required to comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. Transaction and payout records may be retained longer to meet financial-record requirements. When information is no longer needed, we delete or de-identify it. [Confirm specific retention periods with counsel.]

8. Security

We use technical and organizational measures designed to protect personal information, and rely on providers (Clerk, Stripe, Supabase, Vercel, Upstash) that maintain their own security programs. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your Privacy Rights

Depending on where you live, you may have rights to access the personal information we hold about you, to correct it, to delete it, to object to or restrict certain processing, to data portability, and to withdraw consent. To exercise these rights, contact us at [PRIVACY/DPO CONTACT]. We will respond as required by applicable law and may need to verify your identity.

EEA/UK (GDPR)

You have the rights described above and the right to lodge a complaint with your local supervisory authority.

California (CCPA/CPRA)

California residents have the right to know, access, correct, and delete personal information, and to opt out of the "sale" or "sharing" of personal information. We do not sell personal information. We will not discriminate against you for exercising your rights.

10. Children’s Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (consistent with COPPA). Creators must be 18 or older. If you believe a child under 13 has provided us personal information, contact [PRIVACY/DPO CONTACT] and we will take appropriate steps to delete it. [Confirm the applicable minimum age for each target market — some jurisdictions require 16 for consent.]

11. International Data Transfers

We and our providers may process personal information in countries other than the one in which you live, including the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers. [Confirm transfer mechanisms with counsel.]

12. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you (for example, by posting a notice or updating the "Last updated" date). Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

13. Contact

For privacy questions or to exercise your rights, contact our privacy contact / Data Protection Officer at [PRIVACY/DPO CONTACT], [LEGAL ENTITY NAME], [BUSINESS ADDRESS], [CONTACT EMAIL].