Skip to content

Privacy Policy

Version 2026-09-21 · In effect from 2026-09-21

This policy explains what personal information Drop Monthly holds, why, and what you can do about it. It covers three different groups of people, and the difference between them matters.

Three kinds of people

Our customers are the people who sign in to Drop Monthly to run a brand — you, and the colleagues you invite. We decide what we collect about you and why, so for this information we are the data controller.

Your customers are the people whose records you connect or import: the shoppers in your store, the subscribers on your list. You decide what we hold about them and why. We only process it on your instructions, so for this information you are the controller and we are your processor.

People who join a brand here are the third kind: somebody who joins a brand's waitlist or buys its membership on a page at /b/…. We sell those memberships on the brand's behalf, so for this information we are the controller — the next-but-one section says what that covers.

What we hold about you

  • Your account — your email address, your name and picture if you add one, the language you read the app in, and your password, stored only as a hash we cannot reverse.
  • Your second factor, if you enrol one, and your recovery codes, also hashed.
  • How you use the app — sign-ins, the acts you take inside an organization, and the versions of our terms you have accepted. We keep this to answer security questions and to show your colleagues who changed what.
  • Billing details — your plan, your seats and your invoices. Your card is held by Stripe, our payment processor, and never reaches our servers.
  • What you send us — support messages, and anything in them.

We do not run advertising trackers, we do not sell or share personal information with data brokers or advertisers, and we do not use your information to train machine-learning models.

What we hold about your customers

Whatever you connect or import. Typically that is names, email addresses, phone numbers, the identifiers each of your systems uses, and a record of what each system said about that person and when.

We keep every source's record whole rather than flattening them together, and we never merge or split two people on our own — that only happens when somebody in your organization says so. We ask each connected system for the narrowest permissions the features you have enabled actually need.

If you join a brand here

When you join a waitlist or a membership on a brand's page, we hold:

  • The addresses you gave us — your email, and your mobile number if you gave one.
  • What you agreed to be sent — whether you ticked the box for emails and the box for texts, each separately, when, and on which page.
  • For a membership you pay for: your name and billing and shipping addresses, which Stripe collects on the payment page and shares with us, and a record of each payment. Your card is held by Stripe and never reaches our servers.
  • Your place on a waitlist, if you joined one.

We keep your address and your choices even if you do not finish paying: you gave them to us before the payment page, and a choice you made is one we should remember.

We use this to run your membership or your place in line, to send what you bought, and — only if you ticked the box — to send you emails or texts about the brand you joined. You can withdraw either at any time: the link at the bottom of any email, or STOP in reply to any text. The brand you joined can see who its members and waitlist are. We do not sell any of it.

Emails and texts

There are two kinds of message, and they follow different rules.

Messages the service needs — confirming an email address, resetting a password, a sign-in link, a security notice, an invitation, a receipt, a message about your own membership. These are sent because you asked for the thing they belong to, whatever you chose about marketing.

Marketing — a brand's news, drops and offers. These go to you only if you agreed to them, for email and for texts separately. We record when and where you agreed. Every marketing email has an unsubscribe link and every text answers STOP; both take effect at once, and the brand cannot undo them.

We never buy, rent or scrape addresses, and brands on Drop Monthly are forbidden from sending to anybody who did not give them their address and agree to hear from them.

Marketing emails record whether they were opened and which links were clicked, so a brand can see how a message did. Those records are kept for a limited time and then deleted. We also record whether a message was delivered, bounced, or was reported as spam, and we stop sending to an address that bounces or complains.

Why we are allowed to hold it

For our customers: because we need it to provide a service you asked for, to meet legal obligations such as keeping billing records, and for our legitimate interest in keeping the service secure.

For your customers: because you instructed us to, under the terms between us.

For people who join a brand here: to provide the membership or the place in line you asked for, to meet legal obligations such as keeping records of payments, and — for marketing — because you agreed to it, box by box.

Who else sees it

Only the suppliers who make the service work, and only what they need:

  • Fly.io — hosting and the database, where your data lives.
  • Amazon S3 — files and images you upload.
  • Stripe — payments and card details, including a member's payments and the addresses given on the payment page.
  • The brand you joined, if you joined one here — who its members and its waitlist are.
  • Our email provider — the address a message is going to and the message itself, in order to deliver it, and what happened to it afterwards.
  • Anthropic and Voyage AI — when somebody in an organization uses a feature that writes, checks or searches with a model, the text or image they gave it. This is a brand's own copy and pictures, not its list of people.
  • The systems you connect, in the direction you configured.

We may disclose information where the law requires it. If we are ever asked for your data by a public authority we will tell you, unless we are legally forbidden from doing so.

Where it lives, and how long

Data is stored in the region your organization was created in and is not moved without telling you. We keep your account information while your account is open. When you close it we delete your data within 30 days, except:

  • Records of agreement — which version of our terms you accepted and when, and what somebody agreed to be sent. We keep these for as long as they might be needed to establish what was agreed.
  • Billing and payment records, which tax law requires us to keep for seven years.
  • Audit records of acts inside an organization, kept on a rolling window and then swept.
  • A record that you asked us to stop, kept so that we do. If you ask to be forgotten entirely we keep only a scrambled fingerprint of your address — one we cannot turn back into the address — so that you are not added again.

Backups are kept for 30 days and then overwritten. A deletion reaches backups as they expire rather than immediately.

How we protect it

Everything travels over TLS. Credentials for the systems you connect are encrypted at rest with keys held separately from the database. Access is scoped: every read of your organization's data is narrowed to your organization by construction, and our own staff can only enter an organization through a recorded support session, which leaves a permanent record of what they did.

Your rights

Depending on where you live you may have the right to see what we hold, correct it, delete it, object to how we use it, or take it elsewhere in a portable format. Ask us and we will do it, free, within 30 days.

If you joined a brand here — its waitlist or its membership — ask us: we hold that information as the seller, not on anybody's behalf.

If you are one of your customers' customers rather than ours — you found this page because a company you shop with connected its own systems to Drop Monthly — we hold your information on their behalf, and you should ask them. Tell us and we will pass your request on.

You can also complain to your data protection authority. We would rather you told us first.

Children

Drop Monthly is not for children. An account is for somebody aged 18 or over, and we do not knowingly hold information about anybody under 16. If you think we do, tell us and we will delete it.

Cookies

The only cookies we set are the ones that keep you signed in, and remember a device you have already proved a second factor on. We do not use analytics or advertising cookies, which is why this app has no cookie banner — there is nothing to consent to.

Changes

We will post a new version here when this changes, and tell you about anything significant by email before it takes effect.

Contacting us

Privacy questions, and requests about your own data, go to the address on our support page.