1. Controller and contact
Drompl is operated by Denis Dubrovin, Portuguese tax identification number (NIF) 319929574, Campo Grande 336, 3E, 1700-097 Lisbon, Portugal. Denis Dubrovin is the controller of personal data processed by Drompl. Privacy requests may be sent to contact@drompl.com.
2. Information we collect
- Account information, including email address, optional name, authentication records, and a password hash if password login is enabled.
- Session and security information, including session identifiers, device UUID, IP address, user agent, CSRF data, login attempts, and abuse-prevention records.
- Beta-access information, including the submitted email, consent record, status, and related communications.
- User files, generated previews and exports, file metadata, project settings, and technical diagnostics needed to perform requested rendering.
- Billing records received from Paddle, including customer, transaction, subscription, and price identifiers; billing country; order and subscription status; and webhook/audit records.
- Consent choices, usage events, and analytics information described in the Cookie Policy.
3. How and why we use data
- Contract: to create and authenticate accounts, operate projects, render exports, allocate render credits, and provide support.
- Legitimate interests: to secure Drompl, prevent fraud and abuse, diagnose failures, maintain audit records, and improve reliability.
- Consent: where required for optional analytics, beta communications, or other optional processing. Consent may be withdrawn at any time.
- Legal obligations: to respond to lawful requests, preserve required business records, and support payment, tax, consumer-protection, and dispute obligations.
4. Uploaded content
You retain ownership of files you upload. Drompl processes them to provide previews and exports, secure the Service, and investigate technical issues you report. Drompl does not sell uploaded content, use it for advertising, or use it to train machine-learning models.
Infrastructure providers acting under Drompl's instructions may process files only as necessary to host and operate the Service. Uploaded source files may be automatically deleted after an idle-retention period, when deleted by the user, or earlier where needed for testing, maintenance, security, abuse prevention, product changes, or operational reasons. Temporary previews, exports, and processing files may be deleted sooner. Exported or project-related records may remain where the user saves them to an account or where they are needed for support, security, or legal purposes.
Drompl is not a file-storage, backup, or archival service. Especially during beta, files, projects, previews, exports, saved variants, and related metadata may be deleted, overwritten, corrupted, become unavailable, or become incompatible with later versions of the Service. You should keep independent copies of all source files and exported mockups you need.
5. Paddle and payment information
Paddle.com Market Limited ("Paddle") acts as Merchant of Record. Payment details are entered directly into Paddle Checkout. Drompl does not receive or store full card numbers, card security codes, or complete payment credentials.
Drompl may send Paddle the account email, billing country, selected product or price, and identifiers needed to associate an order with the account. Paddle sends Drompl customer, address or country, transaction, subscription, price, status, and related event data needed to fulfil and administer the purchase. Paddle processes personal data under Paddle's Privacy Policy.
6. Other service providers
Drompl may use hosting, storage, email-delivery, authentication, security, monitoring, and analytics providers. Google Analytics is configured according to the consent choices described in the Cookie Policy. Providers may process data only for the contracted service, subject to their terms and appropriate data-protection safeguards.
7. Analytics
Drompl measures product usage at three levels. The Cookie Policy lists the cookies involved.
- Anonymous aggregate counters. Event counts holding no identifier and no session or account link. These identify no one and are always active.
- Session-linked statistics. Usage events tied to a one-way hash of a device session, not to an account, processed under legitimate interest to operate and improve the Service. You may object at any time in “Privacy & cookies”, and refusing analytics in the consent banner switches these off too.
- Detailed analytics linked to your account. Usage events recorded against your account, used only with your consent. Withdrawing consent deletes the detailed events already stored for you.
Google Analytics cookies and storage are a separate choice from the account-linked analytics above, and either may be accepted or refused without the other. Consent to one purpose is never treated as consent to another, and a choice recorded before a purpose or provider was introduced is never carried over to it — anything not explicitly accepted remains switched off until you choose it.
Drompl records which version of this notice each consent was given against, together with the purposes presented at the time.
8. Retention
- Authentication codes and sessions expire according to their security settings.
- Uploaded source files are retained while needed to provide the Service and may be deleted after an idle-retention period, when deleted by the user, or earlier as described above.
- Beta files, previews, exports, project records, saved variants, and technical metadata may be reset, deleted, or changed earlier where needed for testing, maintenance, security, abuse prevention, product changes, or operational reasons.
- Account and project records are retained while the account is active and are deleted or anonymised following a valid deletion request, except where retention is necessary.
- Billing, webhook, fraud-prevention, security, and dispute records are retained for as long as reasonably necessary to meet legal obligations, establish or defend claims, prevent abuse, and reconcile transactions.
9. International transfers
Some providers may process data outside Portugal or the European Economic Area. Where required, Drompl relies on an adequacy decision, standard contractual clauses, or another lawful transfer mechanism.
10. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and object to certain processing based on legitimate interests. Account export and deletion controls may also be available in Account Settings.
You may lodge a complaint with the Portuguese data-protection authority, Comissão Nacional de Proteção de Dados (CNPD), or with another competent supervisory authority.
11. Security and changes
Drompl uses technical and organisational safeguards including password hashing, one-time authentication codes, access controls, secure cookies, CSRF protection, and rate limiting. No internet service can guarantee absolute security.
We may update this policy to reflect changes in Drompl, providers, or legal requirements. Material changes will be identified by the updated date on this page.