Privacy policy
Last updated: July 8, 2026
1. Who is responsible for your data?
The data controller is [COMPANY NAME TO BE COMPLETED], publisher of DropTrace (see legal notice). For any question about your personal data, write to contact@droptrace.app.
2. What data is collected?
| Category | Examples |
|---|---|
| Account | Full name, email, password (never stored in plain text), role (driver/manager/admin/depot manager) |
| Work activity | Start-of-shift check-ins and daily reports: parcel/relay/pickup counts, mileage, vehicle plate, round/letter, timestamped photos |
| Billing | Subscription status, Stripe customer ID — card data is processed only by Stripe, never by us |
| Support | Description of a bug or suggestion, technical logs (app version, page, device) in case of a report |
| Technical | Application version, display preferences — stored locally on your device (see Cookies section) |
DropTrace does not collect geolocation data.
3. Why (purposes and legal bases)
| Purpose | Legal basis |
|---|---|
| Providing the Service (accounts, reports, pay/revenue calculation, export) | Contract performance |
| Billing and subscription management | Contract performance / legal obligation (accounting) |
| Technical support and bug fixing | Legitimate interest (ensuring the Service works properly) |
| Transactional emails (account confirmation, trial reminder) | Contract performance |
| Follow-up emails for unconverted free trials | Legitimate interest — unsubscribe possible at any time |
4. Who has access to your data?
Access is strictly partitioned by company via our database access control (Row Level Security): a driver only sees their own data, a manager sees their agency's, an admin sees their company's, a depot manager sees the subcontractors they supervise. No one can see the data of a company they aren't attached to, including via a tampered technical request.
5. Technical processors (hosting, email sending, payment)
To operate, DropTrace relies on the following providers, each acting as a processor within the meaning of the GDPR:
| Provider | Role |
|---|---|
| Supabase | Database hosting, authentication, photo storage |
| Netlify | Site and server function hosting |
| Stripe | Payment and recurring subscription processing |
| Resend | Sending transactional emails (confirmation, reminders) |
| Anthropic | AI-assisted analysis of bug reports (report text only, at an administrator's request — never automatic and never on photos) |
Some of these providers are located outside the European Union (United States). Data transfer relies on the safeguards provided by these providers (standard contractual clauses or an equivalent mechanism).
6. How long your data is kept
- Photos (start of shift, end of day): automatically deleted after 90 days (daily purge).
- Reports and figures (counts, pay, revenue): kept for the duration of the subscription, then archived for as long as required by legal accounting obligations.
- Account: kept while active; deletion on request (see rights below).
- Bug reports: kept while being processed, then archived to improve the Service.
7. Cookies and local storage
DropTrace does not use advertising cookies or third-party trackers. The application uses
your browser's local storage (localStorage) only for what is strictly necessary
for it to work: keeping your login session, display preference (desktop/mobile), app
version already seen, and remembering that an offer popup was already dismissed. None of
this is passed on to advertising networks.
8. Your rights
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access and rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object, in particular to marketing follow-up emails (unsubscribe link in each relevant email)
To exercise one of these rights, write to contact@droptrace.app. You also have the right to lodge a complaint with the Belgian Data Protection Authority (autoriteprotectiondonnees.be).
9. Security
Exchanges with the application are encrypted (HTTPS). Data access is partitioned by company at the database level (Row Level Security), not only at the interface level — a modified technical request cannot bypass this isolation.
10. Changes to this policy
This policy may be updated; the date at the top of the page reflects the latest version. Substantial changes will be communicated by email.