Legal
Privacy Policy
Effective date: September 1, 2026
DMDrop Technologies ("DMDrop", "we", "us", or "our") operates the DMDrop creator monetization platform available at dmdrop.store and its subdomains. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights regarding that information.
By using DMDrop you agree to the practices described in this policy. If you do not agree, please discontinue use and contact us to request deletion of any data we hold about you.
1. Who this policy applies to
This policy applies to two categories of users:
- Creators — individuals or businesses who sign up for a DMDrop account to manage Instagram automations, create digital storefronts, and sell products.
- Customers / Fans — individuals who purchase digital products or interact with creator storefronts or lookbooks hosted on DMDrop.
2. Information we collect
2.1 Information you provide directly
- Account registration: Full name, email address, and profile picture when you create a DMDrop account via Clerk authentication (Google OAuth, email/password, or other supported providers).
- Creator storefront profile: Display name, biography, storefront brand name, and public-facing Instagram handle.
- Instagram / Meta connection: Your Instagram username, Instagram User ID (a numeric scoped identifier assigned by Meta), Facebook Page ID, and a long-lived Page Access Token which we encrypt at rest using AES-256-GCM before storing it. We do not receive your Instagram password.
- Payment information: When you purchase a digital product, Dodo Payments (our Merchant of Record) processes your payment card, UPI, or other payment method details directly. DMDrop receives only the outcome of the transaction (success/failure), the amount paid, your email address, and a pseudonymous payment reference ID. We never store raw card numbers, CVV codes, or bank account credentials.
- Support communications: Any content you submit through our contact form or send to our support email.
2.2 Information collected automatically
- Instagram comment and interaction data: When a campaign is active, DMDrop receives webhook events from the Meta Graph API containing Instagram comment text, the commenter's Instagram username, their Instagram User ID, and the media ID of the post or Reel the comment was made on. This data is used solely to determine whether an automated DM should be sent and to log the automation outcome. Comment text is stored in automation logs for operational debugging and deleted after 90 days.
- Link-click analytics: When a fan clicks an affiliate or lookbook link, we record a one-way hashed IP address (not the raw IP), country of origin, device type (mobile/desktop/tablet), and referring URL. We do not build individual profiles from this data.
- Usage and session data: Standard server logs including browser type, operating system, pages visited, and timestamps. These are retained for up to 30 days for security and performance monitoring via Better Stack.
2.3 Information from third parties
- Meta / Instagram: Follower status checks (the
is_user_follow_businesspermission), basic profile information (username, name, profile picture URL), and real-time automation webhooks. We access only the permissions explicitly approved in our Meta App Review submission. - Clerk: Authentication state, session tokens, and OAuth identity data. See Clerk's Privacy Policy.
- Dodo Payments: Payment status, subscription state, and a Dodo customer identifier. See Dodo Payments' Privacy Policy.
3. How we use your information
- To provide the service: Executing Instagram comment-to-DM automations, delivering purchased digital products via secure pre-signed download links, and rendering creator storefronts and lookbooks.
- Account and billing management: Managing your subscription, sending transactional emails (purchase receipts, download links, billing notifications) via Resend.
- Platform safety and rate-limit compliance: Tracking Meta API usage to ensure automations stay within the 750 DMs/hour limit mandated by Meta's platform policies.
- Analytics for creators: Aggregating click, view, and DM send counts so creators can evaluate campaign performance. This data is presented in aggregate and does not expose individual fan identifiers to creators.
- Security and fraud prevention: Detecting and blocking abusive requests via Arcjet bot protection.
- Legal compliance: Responding to lawful data requests and maintaining records as required by applicable law.
We do not sell, rent, or trade your personal information to third parties for advertising or marketing purposes.
4. Legal bases for processing (GDPR)
Where the General Data Protection Regulation ("GDPR") applies, we rely on the following legal bases:
- Contract performance: Processing necessary to provide the services you signed up for (account management, automation execution, product delivery).
- Legitimate interests: Security monitoring, fraud prevention, aggregated analytics.
- Consent: Where we ask for your permission before processing (e.g. connecting your Instagram account).
- Legal obligation: Compliance with applicable laws and regulatory requirements.
5. Data retention
| Data type | Retention period |
|---|---|
| Creator account & profile | Until account deletion, then purged within 30 days |
| Instagram access tokens | Until token revocation or account deletion |
| Automation logs (comment text, commenter ID) | 90 days from creation |
| Order records & purchase history | 7 years (tax and accounting obligations) |
| Link-click analytics (hashed IP) | 24 months |
| Server / access logs | 30 days |
| Support communications | 3 years from last interaction |
6. Data sharing and third-party processors
We share your data only with the following categories of processors:
- Clerk — Authentication and identity management.
- Dodo Payments — Payment processing and subscription billing as Merchant of Record.
- Meta Platforms, Inc. — Instagram Graph API for automation execution (data flows from Meta to DMDrop via webhooks).
- Resend — Transactional email delivery (purchase receipts, download links).
- Better Stack — Application log monitoring and uptime alerting.
- Sentry — Error monitoring (stack traces may contain request data; PII is scrubbed where possible).
- PostHog — Product analytics (session events, page views; anonymized).
- Arcjet — Bot detection and rate limiting (IP addresses are evaluated but not stored by DMDrop).
All processors are bound by data processing agreements. We do not transfer your data outside regions where adequate protections are in place under applicable law.
7. Your rights
Depending on your jurisdiction you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data — see our Data Deletion page for instructions.
- Object to or restrict certain processing activities.
- Data portability (receive your data in a machine-readable format).
- Withdraw consent at any time where consent is the legal basis (e.g. revoking Instagram connection from your profile settings).
To exercise any of these rights, email us at privacy@dmdrop.store or use our contact form. We will respond within 30 days.
8. Data deletion
You can delete your DMDrop account and all associated personal data at any time. We provide two mechanisms:
- Self-service: Log in, go to your Profile settings, and click "Delete my account" in the Account & Security tab.
- Email request: Send a deletion request to privacy@dmdrop.store.
Full instructions and what gets deleted are described on our Data Deletion page.
Instagram / Meta users: If you connected your Instagram account to DMDrop via Facebook Login, Meta may also send a data deletion callback to our servers on your behalf. We honor these callbacks automatically.
9. Cookies and tracking technologies
DMDrop uses strictly necessary session cookies managed by Clerk for authentication. We also use PostHog for anonymous product analytics. No advertising or cross-site tracking cookies are set. You can block cookies in your browser settings; this may prevent you from signing in.
10. Children's privacy
DMDrop is not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has provided us with their information, contact us immediately at privacy@dmdrop.store.
11. Security
We protect your data using industry-standard measures including TLS encryption in transit, AES-256-GCM encryption of Instagram access tokens at rest, hashed IP addresses in analytics, and strict role-based access controls on our internal systems. No transmission over the internet is 100% secure; we cannot guarantee absolute security but we promptly investigate and disclose any breach.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the effective date at the top of this page and, where required by law, by direct notification to registered users. Your continued use of DMDrop after a change constitutes acceptance of the revised policy.
13. Contact us
Questions about this Privacy Policy or your data should be directed to:
DMDrop TechnologiesData Protection contact: privacy@dmdrop.store
Contact form →