Legal
Privacy Policy
Last updated: June 13, 2026
This policy explains what data StoreDrop ("we", "us") collects, why, and what your rights are. The short version: we collect what's needed to run the Service, we never sell your data, and your business records belong to you.
Data we collect
Account data — your email address, password (stored as a secure hash by our authentication provider), and organization name.
Business data you enter — customers, contact details, products, quotations, invoices, payment records, notes, and settings. This includes personal data of your customers, which you are responsible for collecting lawfully.
Payment data — your subscription is billed by Stripe; your customers' payments are processed by the Paystack or Stripe account your business connects. We store payment status, amounts, and references; we never see or store card numbers or mobile money credentials. Connected payment API keys are stored encrypted and never shown again.
Usage and technical data — logs, IP addresses (e.g. for rate limiting and abuse prevention), and authentication cookies needed to keep you signed in. We do not run third-party advertising trackers.
Support conversations — messages you send to the help assistant, and problem reports you file through it.
How we use data
- To provide the Service: storing your records, sending the emails you trigger (quotations, invoices, reminders, receipts), and processing payments.
- To power AI features you invoke: when you use the AI quotation generator, business assistant, or help assistant, relevant inputs (and for the business assistant, relevant records from your organization) are sent to our AI provider to generate the response.
- To operate, secure, and improve the Service: debugging, abuse prevention, and understanding which features matter.
- To communicate with you about the Service, your subscription, and support requests.
We do not sell your data, and we do not use your business data for advertising.
Who processes data on our behalf
We use a small set of infrastructure providers ("subprocessors"), each receiving only what they need:
- Supabase — database and authentication (your account and business records).
- Vercel — application hosting.
- Stripe — subscription billing, and customer card payments for businesses that connect a Stripe account.
- Paystack — customer payments (mobile money, bank transfer, cards) for businesses that connect a Paystack account.
- Resend — transactional email delivery (invoices, quotations, reminders, receipts).
- Anthropic — AI processing for the drafting and assistant features. Inputs sent through our API integration are not used to train Anthropic's public models.
These providers may store data in data centres outside your country; they each maintain their own security and compliance programs.
Emails sent through the Service
Quotation, invoice, reminder, and receipt emails are sent at your direction, in your business's name, to the customer contacts you added. You are the controller of those communications; we deliver them for you.
Cookies
We use only essential cookies: secure authentication cookies that keep you signed in. No advertising or cross-site tracking cookies.
Data retention and deletion
We keep your data while your account is active. If you delete your account (or ask us to), we delete your organization's data within 30 days, except where we must retain records for legal, tax, or fraud-prevention reasons. Backups expire on a rolling schedule after deletion.
Security
Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access to production data is restricted, organizations are isolated from each other at the application and database level, and secret credentials are never exposed to browsers. No system is perfectly secure — if we become aware of a breach affecting your data, we will notify you without undue delay.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these directly in the app; for anything else, contact us and we'll respond within 30 days. If your customers contact us about data you entered, we'll refer them to you as the data controller, and assist you in honouring their request.
Children
The Service is for businesses and is not directed at children under 18.
Changes to this policy
If we make material changes, we'll notify you by email or in the app before they take effect. The "last updated" date above always reflects the current version.
Contact
Privacy questions or requests: support@storedrop.io