Privacy Policy

DropPolish

Last Updated: January 20, 2026


1. Introduction

Welcome to DropPolish ("Company," "we," "us," or "our"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website [droppolish.com] and use our services.

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the site or use our services.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.


2. Information We Collect

2.1 Personal Information You Provide

We collect personal information that you voluntarily provide to us when you:

  • Register for an account
  • Subscribe to a paid plan
  • Contact us with inquiries or support requests
  • Participate in surveys or promotions

This information may include:

Data TypeExamples
Identity DataFirst name, last name, username
Contact DataEmail address, billing address
Financial DataPayment card details (processed by our payment provider)
Account DataUsername, password, account preferences
Communication DataYour messages to our support team

2.2 Information Automatically Collected

When you access our Service, we automatically collect certain information, including:

Data TypeDescription
Device InformationDevice type, operating system, browser type
Log DataIP address, access times, pages viewed, referring URL
Usage DataFeatures used, actions taken, time spent on pages
Location DataGeneral geographic location based on IP address

2.3 Images and Content You Upload

When you use our image enhancement services:

  • Images you upload are processed by our AI systems to provide the requested enhancements
  • Processed images are temporarily stored to deliver the service
  • We do not use your images to train our AI models unless you explicitly opt-in
  • Images are automatically deleted within 24 hours of processing, unless you save them to your account

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Delivery

  • To create and manage your account
  • To process your image enhancement requests
  • To process payments and manage subscriptions
  • To provide customer support

3.2 Service Improvement

  • To analyze usage patterns and improve our services
  • To develop new features and functionality
  • To monitor and prevent technical issues

3.3 Communication

  • To send you service-related notifications
  • To respond to your inquiries and support requests
  • To send marketing communications (with your consent)
  • To notify you about changes to our services or policies

3.4 Legal and Security

  • To comply with legal obligations
  • To enforce our Terms of Service
  • To protect against fraudulent or illegal activity
  • To protect the rights and safety of our users

4. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:

Legal BasisWhen It Applies
Contract PerformanceProcessing necessary to provide our services to you
Legitimate InterestsAnalytics, service improvement, fraud prevention
ConsentMarketing communications, optional data processing
Legal ObligationCompliance with applicable laws and regulations

5. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

5.1 Service Providers

We share data with third-party vendors who perform services on our behalf:

Provider TypePurposeData Shared
Payment ProcessorsProcess transactionsPayment details, billing info
Cloud InfrastructureHost our servicesAll service data (encrypted)
AI API ProvidersProcess image enhancementsUploaded images (temporarily)
Analytics ServicesUnderstand usage patternsAnonymized usage data
Email ServicesSend notificationsEmail address, name

5.2 Legal Requirements

We may disclose your information where required by law, such as:

  • To comply with a subpoena, court order, or legal process
  • To respond to lawful requests from public authorities
  • To protect our rights, privacy, safety, or property
  • To enforce our Terms of Service

5.3 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.


6. Data Retention

We retain your personal information for as long as necessary to:

Data TypeRetention Period
Account DataDuration of account + 30 days after deletion
Uploaded Images24 hours (or until you delete them)
Processed Images30 days in your account, then deleted
Payment Records7 years (legal/tax requirements)
Support Communications2 years after resolution
Usage Analytics26 months (anonymized)

You may request deletion of your data at any time by contacting us or using the account deletion feature.


7. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption: All data transmitted using TLS/SSL encryption
  • Access Controls: Role-based access to personal data
  • Secure Storage: Data stored in encrypted databases
  • Regular Audits: Security assessments and vulnerability testing
  • Employee Training: Staff trained on data protection practices

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.


8. Your Privacy Rights

8.1 Rights for All Users

Regardless of your location, you have the right to:

  • Access your personal information
  • Correct inaccurate or incomplete data
  • Delete your account and associated data
  • Export your data in a portable format
  • Opt-out of marketing communications

8.2 Additional Rights (EEA, UK, Switzerland)

If you are in the EEA, UK, or Switzerland, you also have the right to:

  • Restrict Processing: Limit how we use your data
  • Object to Processing: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time
  • Lodge a Complaint: File a complaint with your local data protection authority

8.3 California Privacy Rights (CCPA/CPRA)

California residents have additional rights under the CCPA/CPRA:

  • Right to Know: What personal information we collect and how it's used
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of sale/sharing of personal information (we do not sell data)
  • Right to Non-Discrimination: Equal service regardless of privacy choices

To exercise any of these rights, please contact us at no-reply@droppolish.com.


9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.

When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses approved by the European Commission
  • Data Processing Agreements with all service providers
  • Encryption of data in transit and at rest

10. Children's Privacy

Our Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at no-reply@droppolish.com.


11. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.


12. Do Not Track Signals

Some browsers include a "Do Not Track" (DNT) feature. We currently do not respond to DNT signals because there is no industry standard for compliance. We will update this policy if a standard is established.


13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

DropPolish

  • Email: no-reply@droppolish.com
  • Support: no-reply@droppolish.com
  • Address: Tunis, Tunisia 25 2080 urbain

For GDPR-related inquiries, you may also contact our Data Protection Officer at no-reply@droppolish.com.


14. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Last Updated" date. We encourage you to review this Privacy Policy periodically.

If we make material changes, we will notify you by:

  • Posting a notice on our website
  • Sending an email to registered users
  • Displaying a prominent notice within the Service

This Privacy Policy is effective as of January 20, 2026.