Legal

Privacy Policy

Last updated: July 29, 2026

This Privacy Policy explains how Bundle Drop ("we", "us", "our") collects, uses, and protects your information.

1. Information We Collect

We may collect:

a) Account Information

  • Name
  • Email address
  • Company details

b) Usage Data

  • API requests
  • Update delivery metrics
  • Device and environment data

c) Technical Data

  • IP address
  • Browser type
  • Device identifiers

2. How We Use Data

We use data to:

  • Provide and maintain the Service
  • Improve performance and reliability
  • Monitor usage and analytics
  • Ensure security and prevent abuse

3. Payments

Payments are processed by Paddle, which acts as our Merchant of Record and is the seller of record for your purchase. We do not store or process your full payment details ourselves.

Paddle may collect:

  • Billing information
  • Payment method details

Paddle's privacy policy applies: Paddle Privacy Policy.

4. Data Sharing

We do not sell your data.

We share data only with sub-processors that help us operate the Service, including:

  • Payment provider: Paddle (Merchant of Record)
  • Cloud hosting and content delivery (Cloudflare)
  • Transactional email delivery (Resend)
  • Website analytics (Google Analytics / Firebase Analytics)
  • Legal authorities, where required by law

We maintain a current list of sub-processors and can provide it on request.

5. Data Retention

We retain data only as long as necessary to:

  • Provide and operate the Service
  • Comply with legal, tax, and accounting obligations

When you delete your organization or account, we delete the associated projects, bundles, and related data, except where we are required to retain certain records to meet legal obligations. We do not automatically delete your data solely because a subscription lapses or is canceled.

6. Security

We implement appropriate security measures to protect your data.

However, no system is completely secure.

7. Your Rights

Depending on your location, you may:

  • Request access to your data
  • Request deletion
  • Object to processing

Contact us to exercise these rights.

8. Cookies

We use essential browser storage and cookies where needed for authentication, security, and preferences.

On the public Bundle Drop website and in the developer console, optional Firebase Analytics is disabled until you allow it. If allowed, it uses analytics storage to help us understand website and product usage. We do not set an analytics user ID or enable advertising personalization.

Your choice is stored in that browser for 12 months. You can withdraw or grant consent at any time through Analytics preferences in the website footer, or through the footer and User Settings in the developer console. Because browser preferences are scoped to each site origin, the website and console may ask separately.

9. Changes

We may update this Privacy Policy.

Continued use means acceptance of changes.

10. Contact