Privacy Policy
Effective Date: August 3, 2026 • Version 3.4 • Applicable to DropMind Web App & Chrome Extension
1. Introduction & Overview
DropMind Tech Inc. (“DropMind”, “we”, “our”, or “us”) is committed to honoring the privacy, security, and confidentiality of all individuals who access our SaaS product intelligence software, website (dropmind.io), and the DropMind Chrome Extension.
This Privacy Policy details our data collection practices, legal bases for processing under EU GDPR and California CCPA/CPRA, data retention schedules, third-party disclosures, and payment security standards.
DropMind adheres strictly to PCI-DSS Level 1 Security Standards. We partner with Tier-1 licensed payment institutions—including Stripe, Inc. and PayPal Holdings, Inc.—to handle all payment transactions safely.
- No Storage of Sensitive Payment Data: Credit card numbers, CVV codes, and PayPal passwords are NEVER received, stored, or transmitted on DropMind servers.
- Direct Tokenization: Financial credentials entered during checkout are submitted directly to Stripe or PayPal via encrypted 256-Bit SSL/TLS API tunnels.
3. Information We Collect
3.1 Account & Personal Information
When you register for a 2-day free trial or subscription plan, we collect your full name, work email address, encrypted account password, and IP address for session authorization.
3.2 Ad Spying & Chrome Extension Data
Our internal Chrome Extension collects ad copy text, media URLs, competitor store URLs, and public CTR metrics from supported ad libraries. Scraped data is associated strictly with your private user account for marketing research.
3.3 Analytics & Technical Metadata
We log browser user-agent types, operating systems, referring URLs, and page interactions using aggregated, privacy-focused analytics tools.
4. How We Use Your Information & Legal Basis
Under Article 6 of the EU GDPR, we process personal data under the following legal bases:
- Contractual Performance: Providing software features, calculating Viral Velocity Scores, and managing affiliate payouts.
- Legitimate Interests: Preventing fraudulent transactions, optimizing platform performance, and maintaining system security.
- Consent: Sending promotional updates, newsletter summaries, and feature notifications. You may opt out anytime.
5. Third-Party Sub-processors
We do NOT sell, rent, or trade your personal information to third parties. We share data only with audited sub-processors necessary to run DropMind:
- Payment Gateways: Stripe Inc. & PayPal Holdings Inc. (Billing & subscriptions).
- Email Infrastructure: Resend Technologies Inc. (Transactional alert emails).
- Cloud Infrastructure: Hostinger International & Cloudflare Inc. (Server hosting & DDoS mitigation).
6. Data Security & Retention
DropMind implements AES-256 database encryption at rest and TLS 1.3 encryption in transit. Active account data is retained for the duration of your membership. Inactive accounts are purged 12 months after subscription termination unless legal retention applies.
7. Your Global Privacy Rights
Depending on your jurisdiction (EU/EEA, UK, California, Canada), you hold the right to:
- Access, receive, or port a copy of your personal data.
- Request immediate erasure (“Right to be Forgotten”).
- Opt out of any commercial marketing or profiling.
To exercise these rights, please visit our GDPR & CCPA Compliance Center or email [email protected].
Data Controller Contact Details
DropMind Tech Inc. — Data Protection Office
700 S Flower St, Suite 1100, Los Angeles, CA 90017, USA
+1 (213) 579-2967