Privacy Policy
Last updated August 20, 2026
This policy explains what drop (“drop”, “we”, “us”) collects when you use our website and application, why we collect it, and the choices you have. We keep it plain, because a privacy policy you can’t read isn’t much of a promise.
Who we are
drop is a customer-relationship-management application operated from Australia. If you need to reach us about anything in this policy, email hello@dropcrm.io.
What we collect
- Account details — your name and email address, used to create your workspace and to sign you in.
- Data you put in — the clients, contacts, subscriptions, notes and activities you add to your workspace. This is your data; you control it.
- Billing details — if you subscribe to a paid plan, our payment provider (Stripe) processes your card. We never see or store your card number.
- Research queries — when you run a Deep Dive, the company name and context you provide are sent to our AI provider to search the public web on your behalf.
- Basic technical data — a single essential session cookie to keep you signed in, plus standard server logs (IP address, timestamps) needed to run and secure the service.
What we do not do
- We do not sell your data, and we never will.
- We do not use advertising or third-party tracking cookies. The only cookie we set is the one that keeps you signed in.
- We do not use the data in your workspace to train AI models.
How we use it
To provide the service: create and secure your workspace, sign you in (via a one-time code we email you), keep your book of accounts, run the research and automations you ask for, and bill your subscription. We also use aggregate, non-identifying information to understand how the product is used and to improve it.
The providers we rely on
We use a small number of trusted subprocessors to run drop. Each receives only the data needed for its job:
- Stripe — payment processing and subscription billing.
- Anthropic — the AI that powers Deep Dive research.
- Amazon Web Services — hosting and transactional email (your sign-in codes and notifications).
These providers may process data outside Australia. We only work with providers that offer appropriate safeguards for international transfers.
How we protect it
Your workspace is isolated from every other workspace at the database level — one customer can never see another’s data. Traffic is encrypted in transit (HTTPS), sign-in is passwordless (a short-lived one-time code, never a stored password), and access to production systems is limited to what’s necessary to operate the service. No system is perfectly secure, but security is a first-order concern, not an afterthought.
How long we keep it
We keep your workspace data for as long as your account is active. If you close your account, we delete or anonymise your data within a reasonable period, except where we’re required to retain limited records (for example, billing records) to meet legal obligations.
Your choices and rights
You can export your entire book to Excel at any time from inside the app, and an admin can edit or delete records, remove team members, or close the workspace. Depending on where you live, you may also have rights to access, correct, or request deletion of your personal data — email us and we’ll help. If you’re in Australia, you can also raise a concern with the Office of the Australian Information Commissioner.
Children
drop is a business tool and isn’t directed at anyone under 16. We don’t knowingly collect data from children.
Changes to this policy
If we make a material change, we’ll update the date at the top and, where appropriate, let you know in the app or by email. Continuing to use drop after a change means you accept the updated policy.
Contact
Questions, requests, or concerns about your data? Email hello@dropcrm.io and a real person will respond.
Looking for the ground rules? Read our Terms of Service.