Privacy Policy
This Privacy Policy outlines the principles and practices that govern the collection, use, and protection of personal data by Droprift (“we,” “us,” or “our”) through our website droprift.com (“Website”). We are firmly committed to preserving the confidentiality, integrity, and availability of your personal information and ensuring full compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1. Commitment to Privacy and Data Protection
At Droprift, we deeply respect the trust you place in us when you share your personal information. We are committed to handling your personal data in a responsible, transparent, and compliant manner. We maintain robust policies and procedures to safeguard data against unauthorized access and ensure it is processed lawfully and fairly.
2. Scope of Policy and Role of Data Controller
This Privacy Policy applies to all personal data collected through droprift.com and associated services. For the purpose of the GDPR, Droprift is the Data Controller of your personal data. As Data Controller, we determine the purposes and means of the processing of your information and are committed to ensuring your rights are upheld according to applicable legal standards.
For inquiries regarding this policy or your data, you may contact us at: [email protected].
3. Categories of Data Processed
We process the following categories of personal data:
a. Usage Data:
Information about your interaction with droprift.com, including browser type and version, IP address, time zone setting, referral platform, pages visited, and time spent on the Website.
b. Account Data:
Data you provide when creating an account or using our services, such as name, email address, mailing address, and telephone number.
c. Profile Data:
Information related to your preferences, purchase history, behavior on the Website, saved items, and account settings.
d. Communication Data:
Records of support tickets, communications sent to our customer service team, and any direct contact history via email or forms on droprift.com.
e. Technical Data:
Information about the device and technical configuration used to access the Website, including device identifiers, operating system, screen resolution, browser plugins, and internet service provider.
f. Transaction Data:
Information related to purchases made through the Website, including payment details (processed through secure third parties), billing and delivery addresses, and order history.
g. Preference Data:
Records of marketing preferences, user-specified product categories or favorites, newsletter subscriptions, and opt-in/opt-out choices.
4. Legal Bases for Processing
We process your personal data based on the following lawful grounds, as permitted by the GDPR and applicable U.S. privacy laws:
– Consent: Where you have explicitly agreed to the processing of your data for specific purposes (e.g., marketing communications).
– Contractual Necessity: When processing is necessary to fulfill a contract with you (e.g., fulfilling an order).
– Legal Obligation: Where we are required to comply with legal or regulatory requirements.
– Legitimate Interests: Where processing is necessary for our legitimate interests—such as fraud prevention, service improvement, or Website analytics—and these are not overridden by your rights and interests.
5. Your Data Protection Rights
You have the following rights, subject to verification and legal limitations:
– Right of Access: You may request confirmation of whether we process your personal data and receive a copy of it.
– Right to Rectification: You are entitled to correct or update any inaccurate or incomplete personal data.
– Right to Erasure: You may request the deletion of your personal data where there is no compelling reason for its continued processing.
– Right to Restriction: You may request limits on the processing of your data under certain circumstances.
– Right to Data Portability: You may receive your data in a structured, commonly used, and machine-readable format, and request it be transferred to another controller.
– Right to Object: You may object to our processing based on legitimate interest, including direct marketing.
To exercise any of the above rights, please contact us at: [email protected].
6. Security Measures
We implement comprehensive technical and organizational measures to ensure the security of your personal data, including but not limited to:
– Industry-standard encryption of data in transit and at rest
– Role-based access controls and authentication
– Routine system monitoring and secure backups
– Staff privacy and security training
– Regular vulnerability assessments and audits
While no method of internet transmission or storage is entirely secure, we continuously test and improve our systems to minimize risks.
7. International Data Transfers
Your data may be transferred and stored outside of your jurisdiction, including to countries that do not ensure the same level of data protection. In such cases, Droprift enters into standard data protection clauses and maintains appropriate safeguards in compliance with GDPR Article 46. We also endeavor to comply with local laws governing data transfer, including those under the CCPA for California residents.
8. Data Retention
We retain personal data only as long as necessary to fulfill the purposes for which it was collected (e.g., providing services, processing orders), including satisfying our legal or regulatory obligations. Retention periods vary by data type:
– Account and Profile Data: Until your account is deleted or becomes inactive for 24 months
– Transaction Data: Retained for up to 7 years for tax and audit purposes
– Communication History: Retained for 3 years from the most recent interaction
– Usage and Technical Data: Anonymized and retained for analytics purposes for up to 26 months
– Marketing Preferences: Retained until consent is withdrawn
9. Cookie Policy
Droprift uses cookies and similar technologies on droprift.com to improve Website performance, personalize content, and analyze user behavior. We categorize cookies as follows:
– Essential Cookies: Necessary for Website functionality (e.g., authentication, cart management)
– Functional Cookies: Enable enhanced customization features (e.g., preferences, saved items)
– Analytics Cookies: Collect aggregate performance and usage metrics (e.g., Google Analytics)
– Performance Cookies: Optimize Website responsiveness and user experience
10. Cookie Management and Regulatory Compliance
You may manage or disable cookies through your browser settings or by using the cookie consent mechanism provided on droprift.com upon your first visit, in compliance with GDPR and CCPA requirements. Users may opt out of non-essential cookies at any time, and California residents may request to know, delete, or opt out of the sale of their personal information under the CCPA.
To adjust your cookie settings, visit the Cookie Preferences center on our Website or use the settings provided by your browser or operating system.
11. Special Protections for Children
Droprift does not knowingly collect personal data from children under the age of 13. If we become aware that we have inadvertently collected data from a child without appropriate parental consent, we will take steps to delete such information promptly. Parents or legal guardians who believe their child has submitted personal data may contact us at [email protected] to request removal.
12. Policy Updates and User Notification
We reserve the right to amend or update this Privacy Policy at our discretion. Any substantial changes will be communicated via droprift.com and, where appropriate, through direct notification. Users are encouraged to review this Policy periodically to remain informed.
13. Contact Information
For any questions, requests, or concerns regarding this Privacy Policy or the handling of your personal data, please contact us at:
Email: [email protected]
Website: https://droprift.com
We are committed to full compliance with applicable data protection regulations and will cooperate with regulatory authorities as required. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority.