Privacy Policy
How we handle your data
Last updated: May 24, 2026 · Effective immediately
Drop Sniper AI ("we", "us", "Drop Sniper") provides an AI-powered dropshipping product analysis platform. This Privacy Policy explains what data we collect, why, who we share it with, and how you can control it. We follow GDPR (EU), CCPA (California), and applicable international privacy standards.
1.Data we collect
When you create an account and use Drop Sniper, we collect:
- Account data — email address, hashed password (bcrypt), account creation timestamp.
- Usage data — the analyses you run (category, budget, target country, AI-generated outputs), product profit history you log, and feature interactions.
- Technical data — IP address, browser user-agent, login history (timestamps + success/failure), approximate location (country-level) derived from IP, and request response times for performance monitoring.
- Payment data — if you subscribe, Stripe handles all card data directly. We only store your Stripe customer ID, subscription status, and billing email. We never see, store, or transmit your card number.
2.Why we collect it
- To provide AI-powered product analysis (the core service).
- To authenticate you securely and prevent abuse (rate limiting, brute-force protection, suspicious activity detection).
- To process payments and manage your subscription.
- To improve product quality (aggregate, anonymized usage trends).
- To send transactional emails (account confirmations, password resets, billing receipts).
- To comply with legal obligations (tax records, fraud prevention).
3.Third-party services
We use a small set of trusted providers. Each receives only the minimum data they need to function:
- Anthropic (Claude API) — your analysis queries (category, budget, country) are sent to Claude to generate product recommendations. Anthropic processes these per their privacy policy and does not use API submissions to train models. No account or payment information is sent.
- Stripe — handles all payment processing, card storage, and subscription billing. See Stripe's privacy policy.
- Resend — sends transactional emails (verification, receipts, broadcasts). Receives your email address and message content.
- MaxMind GeoIP — converts your IP to a country code for fraud detection. No personal data sent; lookup is performed locally on our server.
- HaveIBeenPwned — at registration, the first 5 characters of the SHA-1 hash of your password are sent to check for known breaches (k-anonymity model). Your actual password is never transmitted.
We do not sell your data, share it with advertisers, or use it for advertising targeting. Ever.
4.Cookies and analytics
Drop Sniper uses minimal browser storage:
- A JWT authentication token (stored in
localStorage) to keep you logged in. Cleared on logout.
- UI preferences (theme, last-viewed tab) stored locally.
We do not use third-party analytics trackers (no Google Analytics, no Facebook Pixel, no Hotjar). We do not use advertising cookies. We do not fingerprint your browser.
5.Data retention
We keep your data only as long as needed:
- Account data — for the lifetime of your account, plus 30 days after deletion (legal/audit grace period).
- Analyses and product history — for the lifetime of your account.
- Login history — 90 days.
- Error and security logs — 30 to 90 days.
- Billing records — 7 years (legal requirement in most jurisdictions).
6.Your rights (GDPR + CCPA)
You can, at any time:
- Export your data — download a JSON file of everything we have on you.
- Delete your account — permanently erase all your personal data (right to be forgotten / right to erasure).
- Correct your data — update your email or other profile fields.
- Object to processing — opt out of non-essential data use.
- Withdraw consent — cancel your subscription and stop using the service.
To exercise any of these rights, email
[email protected] or use the in-app "Download my data" and "Delete account" buttons in your settings. We respond within 30 days as required by GDPR.
7.Security
We take security seriously. Passwords are hashed with bcrypt (never stored in plaintext). All connections use TLS encryption. Admin accounts require two-factor authentication. We run automated threat detection against credential stuffing, account flooding, and other abuse. Our servers follow the OWASP Top 10 hardening guidelines. Despite our best efforts, no system is 100% secure — we will notify affected users within 72 hours of any confirmed breach, as required by GDPR Article 33.
8.Children's privacy
Drop Sniper is not directed at, and not intended for use by, anyone under 16. We do not knowingly collect data from minors. If you believe a child has provided us data, contact us immediately and we will delete it.
9.International transfers
Our servers may be located in the United States or the European Union. By using Drop Sniper, you consent to your data being processed in these jurisdictions. We rely on Standard Contractual Clauses for EU-US data transfers where applicable.
10.Changes to this policy
We may update this policy as our service evolves or legal requirements change. Material changes will be announced via email to all registered users at least 14 days before they take effect. Continued use of Drop Sniper after the effective date constitutes acceptance.
11.Contact
Questions, requests, or complaints — email us at [email protected]. EU users may also lodge a complaint with their local Data Protection Authority.