Privacy Policy

This Privacy Policy explains how DropAndHost (“we”, “us”, “our”) collects, uses, and protects personal data when you use dropandhost.com and related services (the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR).

1. Who is responsible

The operator of DropAndHost is the controller of your personal data. For privacy questions, contact us at support.

2. Data we collect

Depending on how you use the Service, we may process:

  • Account data: email address and a hashed password.
  • Project data: project names, URLs, file paths, upload metadata, and the files you upload.
  • Billing data: country, company name, VAT ID (if provided), and payment status. Card or bank details are processed by our payment provider, not stored by us.
  • Technical data: IP address, browser type, and similar logs needed to operate and secure the Service.
  • Usage data: aggregated, privacy-friendly analytics (page views). We do not use advertising cookies.

3. Why we use this data

  • To create and manage your account and hosted projects (contract).
  • To store and deliver the files you upload via our CDN (contract).
  • To process payments, invoices, and VAT where applicable (contract / legal obligation).
  • To keep the Service secure, prevent abuse, and debug issues (legitimate interest).
  • To understand how the Service is used, in aggregated form (legitimate interest).
  • To respond to support requests (contract / legitimate interest).

4. Processors and third parties

We use trusted providers to run the Service:

  • Bunny.net — file storage and content delivery (CDN).
  • Creem — payment and subscription processing.
  • Plausible Analytics — cookie-free, privacy-friendly website analytics.
  • Our hosting provider — to run the website and database.

These parties only process data as needed to provide their service to us. Files you upload may be served globally through the CDN.

5. Cookies and analytics

We use a session cookie (or equivalent session storage) so you can stay logged in. We use Plausible for analytics. Plausible does not use tracking cookies and does not collect personal identifiers for advertising.

6. How long we keep data

  • Account: until you delete it or it is closed.
  • Free projects: files are typically removed after 7 days, unless you have an active paid plan.
  • Paid projects: kept while your subscription is active, then subject to the same expiry rules.
  • Billing records: kept as required by tax and accounting law (generally 7 years in the Netherlands).
  • Logs: kept only as long as needed for security and operations.

7. Your rights

If you are in the EEA/UK, you may request:

  • Access to your personal data
  • Correction of inaccurate data
  • Deletion of your data (where legally allowed)
  • Restriction or objection to certain processing
  • Data portability of data you provided

To exercise these rights, email us. You may also lodge a complaint with your local data protection authority (in the Netherlands: Autoriteit Persoonsgegevens).

8. Security

We hash passwords, use HTTPS, and restrict access to systems that hold personal data. No method of transmission or storage is 100% secure; we take reasonable measures to reduce risk.

9. Content you upload

You are responsible for the files you host. Do not upload personal data of others unless you have a lawful basis to do so. Public project URLs can be visited by anyone who has the link.

10. Children

The Service is not intended for children under 16. We do not knowingly collect data from children.

11. Changes

We may update this policy. The “Last updated” date at the top will change when we do. Continued use of the Service after an update means you accept the revised policy.