Privacy Policy
Last updated 1 September 2026
AccessDrop ("we", "us") generates delivery links and PDFs that point to a destination URL you supply. This policy explains what personal data we collect, why, and what rights you have over it, under UK GDPR and the Data Protection Act 2018. See our Terms & Conditions for how the Service itself works.
What we collect
- Account data (sellers) — your email address. We use passwordless magic-link sign-in, so we don’t store a password.
- Delivery link data (sellers) — the product title, shop name, and destination URL you enter for each delivery link. We do not fetch, store, or take a copy of the files at that URL — only the link itself.
- Buyers — we do not collect any personal data from people who open your delivery link or scan your QR code. We record only an aggregate click count against your delivery link; no cookies, names, emails, or IP addresses are stored for buyers.
- Billing data (sellers) — handled by Stripe. We store your Stripe customer ID and a record of your purchase; your card details never reach our servers.
Why we process it, and on what basis
- To provide the Service (necessary to perform our contract with you) — creating your delivery links, generating your PDFs, checking link accessibility.
- To process payment (necessary to perform our contract with you) — via Stripe.
- To meet legal obligations — retaining billing records for tax purposes.
Who we share data with
We don’t sell your data. We share it only with the processors that make the product work:
- Stripe (payment processing) — see Stripe’s privacy policy.
- Resend (transactional email — sign-in links, account notices).
- Microsoft Azure (hosting — our servers and database run in Azure’s UK South region).
How long we keep it
Access is sold as a 365-day pass, not an ongoing subscription (see Terms & Conditions). If the Service is ever discontinued, we’ll email you in advance before your account and its delivery links are permanently deleted. Billing and transaction records are kept separately, in anonymized form, for the period required by UK tax law (approximately 6 years). You can request deletion sooner at any time — see "Your rights" below.
We keep encrypted database backups so we can recover from technical failures. Backups are automatically and permanently deleted after a maximum of 14 days.
Cookies
Sellers get a single essential session cookie to stay signed in. Buyers opening a delivery link are not tracked with any cookie at all.
International transfers
Our hosting and database are in the UK. Some of our processors (Stripe, Resend) may process data outside the UK; where they do, this happens under their own standard contractual safeguards.
Your rights
Under UK GDPR, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted ("the right to be forgotten");
- restrict or object to certain processing;
- receive your data in a portable format; and
- complain to the Information Commissioner’s Office if you think we’ve got something wrong.
To exercise any of these, contact us using the details below.
Children
AccessDrop isn’t intended for use by anyone under 18.
Changes to this policy
If we make material changes, we’ll update the date at the top of this page and, where appropriate, notify you directly.
Contact us
Questions about this policy or your data: [email protected]
See also our Terms & Conditions.