Privacy Policy
Last updated: April 27, 2026
DROP.AI ("us", "we", or "our") operates the DROP.AI website and service at dropai.ca (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal information when you use our Service. By using the Service, you agree to the collection and use of information in accordance with this policy.
Information Collection And Use
While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. Personally identifiable information ("Personal Information") may include, but is not limited to:
- Email address
- Name
- IP address
- Shopify store URL and store name
- Usage data (pages generated, export history)
We collect this information for the purpose of providing the Service, identifying and communicating with you, responding to your requests/inquiries, servicing your purchase orders, and improving our services.
Shopify Data
When you connect your Shopify store to DROP.AI, we access certain store data — including product information, theme data, and store content — solely for the purpose of providing our AI-powered product page generation service. We do not store or share your customers' personal data. We comply with Shopify's API terms and all mandatory GDPR compliance requirements, including responding to customer data requests, customer data deletion requests, and shop data deletion requests. Shopify access tokens are encrypted using AES-256-GCM before storage.
Log Data
We collect information that your browser sends whenever you visit our Service ("Log Data"). This Log Data may include information such as your computer's IP address, browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, and other statistics.
Cookies
Cookies are files with a small amount of data, which may include an anonymous unique identifier. We use cookies for session authentication only — we do not use advertising cookies. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. If you do not accept cookies, you may not be able to use some features of our Service.
Service Providers
We may employ third-party companies to facilitate our Service. These third parties have access to your Personal Information only to perform specific tasks on our behalf and are obligated not to disclose or use your information for any other purpose. Our service providers include:
- Supabase — database and user authentication
- Stripe — payment processing and subscriptions
- Anthropic — AI content generation (product data only, no personal information)
- Render — cloud hosting infrastructure
- Shopify — store integration and product export
Security
The security of your Personal Information is important to us. Shopify access tokens are encrypted using AES-256-GCM. We implement role-level security (RLS) so each user can only access their own data. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
International Transfer
Your information, including Personal Information, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from your jurisdiction. If you are located outside Canada and choose to provide information to us, please note that we transfer the information to Canada and the United States and process it there. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
Links To Other Sites
Our Service may contain links to other sites that are not operated by us. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over, and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Your Rights
You have the right to access, update, or delete your Personal Information at any time. Additionally, you may have the right to:
- Access — request a copy of all information collected about you
- Deletion — request deletion of your account and all associated data
- Correction — update incorrect details through account settings
- Portability — receive your data in a structured format (JSON)
- Object — object to the processing of your Personal Information
To exercise these rights, contact us at: info@dropai.ca
Data Retention
Account information is retained for as long as your account is active. Upon account deletion, personal data is removed within 30 days. Log data is retained for up to 90 days.
Children's Privacy
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and learn that your child has provided us with Personal Information, please contact us and we will take steps to remove that information from our servers.
Compliance With Laws
We will disclose your Personal Information where required to do so by law or subpoena, or if we believe that such action is necessary to comply with the law and the reasonable requests of law enforcement or to protect the security or integrity of our Service.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and, where appropriate, by email with at least 14 days' notice. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy, please contact us at: info@dropai.ca
By using our Service, you consent to our Privacy Policy and agree to its terms. If you do not agree with this policy, please do not access or use our Service.