AccessDrop

Privacy Policy

Last updated 1 September 2026

AccessDrop ("we", "us") generates delivery links and PDFs that point to a destination URL you supply. This policy explains what personal data we collect, why, and what rights you have over it, under UK GDPR and the Data Protection Act 2018. See our Terms & Conditions for how the Service itself works.

What we collect

Why we process it, and on what basis

Who we share data with

We don’t sell your data. We share it only with the processors that make the product work:

How long we keep it

Access is sold as a 365-day pass, not an ongoing subscription (see Terms & Conditions). If the Service is ever discontinued, we’ll email you in advance before your account and its delivery links are permanently deleted. Billing and transaction records are kept separately, in anonymized form, for the period required by UK tax law (approximately 6 years). You can request deletion sooner at any time — see "Your rights" below.

We keep encrypted database backups so we can recover from technical failures. Backups are automatically and permanently deleted after a maximum of 14 days.

Cookies

Sellers get a single essential session cookie to stay signed in. Buyers opening a delivery link are not tracked with any cookie at all.

International transfers

Our hosting and database are in the UK. Some of our processors (Stripe, Resend) may process data outside the UK; where they do, this happens under their own standard contractual safeguards.

Your rights

Under UK GDPR, you have the right to:

To exercise any of these, contact us using the details below.

Children

AccessDrop isn’t intended for use by anyone under 18.

Changes to this policy

If we make material changes, we’ll update the date at the top of this page and, where appropriate, notify you directly.

Contact us

Questions about this policy or your data: [email protected]

See also our Terms & Conditions.