Skip to main content
← Back to home

Privacy Policy

Effective 23 September 2026 · Last updated 23 September 2026

1. Who we are and what this covers

Dropwire is operated by Avigdor Leibzon, an independent sole trader registered in Israel, trading as Dropwire (the "Service Provider", "we", "us"). This policy explains what personal data we collect through the Dropwire website and application, why, who we share it with, how long we keep it, and what rights you have.

Because Dropwire is operated from Israel, the Protection of Privacy Law, 5741-1981, as amended by Amendment 13 which came into force on 14 August 2025, governs how we handle personal data. Where the EU General Data Protection Regulation also applies to you, we honour it in addition. Amendment 13 treats IP addresses, location data and other online identifiers as personal data, and this policy is written on that basis.

Dropwire is offered to business users. It is not directed at children, and we do not knowingly collect data from anyone under 18.

2. Two different roles, and why the distinction matters

For your own account data, we are the controller. We decide how your email address, login records and subscription status are handled, and this policy governs that.

For data about your audience, you are the controller and we are your processor. The people in your Telegram channels and WhatsApp groups are your contacts, not ours. We process data about them only to carry out your instructions, which in practice means delivering the posts you publish and counting the clicks they generate.

It follows that you are responsible for having a lawful basis to message those people and for answering their privacy requests. If someone in your audience contacts us directly, we will normally refer them to you.

3. What we collect, why, and on what basis

Account and authentication

Your email address, a hashed password if you set one, and your sign-in identity if you use Google or Facebook. We never store your password itself. Basis: performance of our contract with you.

Session security

The IP address and browser user agent recorded when you sign in, used to detect and investigate unauthorised access. Basis: our legitimate interest in securing accounts. These are erased after 90 days.

Connected credentials

The affiliate keys, bot tokens, model provider keys and WhatsApp connection you supply. These are encrypted at rest with AES-256-GCM under a key that is specific to your workspace, and they are deliberately excluded from every data export. Basis: performance of our contract.

Operational records

Products, posting history, channel configuration, conversions and revenue figures. These are business records rather than personal data about your audience, but they are associated with your account. Basis: performance of our contract.

Click tracking

When someone follows a tracked link we record the click, a coarse location derived from the IP address, the user agent, and a rotating daily hash used to distinguish repeat visitors without identifying them. The IP address, user agent and that hash are all erased after 90 days. We do not build cross-site profiles and we do not sell this data. Basis: your legitimate interest as controller in attributing your own affiliate activity.

Audit records

Records of significant actions, including consent you gave before enabling WhatsApp, and of any access by us to your workspace for support. Some carry an IP address and session identifier for incident investigation; those elements are erased after 90 days while the record of the action itself is retained. Basis: legal obligation and our legitimate interest in accountability and dispute evidence.

Billing

We store your subscription status and the identifiers our payment provider gives us. We never receive or store your card details, which are handled entirely by our payment provider as Merchant of Record. Basis: performance of our contract and legal obligation for tax records.

Waitlist

If you join the waitlist we store your email address to notify you about launch. Basis: consent, which you may withdraw at any time by asking us to remove you.

4. Who we share it with

We do not sell personal data and we do not share it for advertising. We use the following service providers, each under contract and each limited to what its function requires:

ProviderPurposeDataLocation
HetznerHosting of the application and databaseAll application dataGermany (EU)
CloudflareDNS, CDN, web application firewall, and page-performance analytics on this marketing siteRequest metadata, IP addresses, page timingsGlobal
Backblaze B2Encrypted off-site backupsFull database, encrypted before uploadUnited States
Payment providerMerchant of Record, payments (named at checkout)Billing details and card data, held by themNamed at checkout
ResendTransactional and waitlist emailEmail addresses, message contentUnited States
GoogleSign-in with Google, and product scoring via GeminiSign-in identity; product text and imagesUnited States
MetaSign-in with FacebookSign-in identityUnited States
SentryError monitoringDiagnostic data, with personal data stripped before sendingUnited States
ImageKitProduct image rendering and deliveryProduct images, not personal dataGlobal
AliExpressAffiliate product data and link generationYour affiliate credentials, server sideGlobal
TelegramMessage delivery to your channelsChannel identifiers, post contentGlobal
WhatsApp and Meta, via a self-hosted Evolution gatewayMessage delivery to your WhatsApp groupsYour connected number, post contentSelf-hosted, EU
OpenAICaption and content generation, usually under your own API keyProduct text and your brand voice promptUnited States
AnthropicCaption and content generation, usually under your own API keyProduct text and your brand voice promptUnited States

We may also disclose data where required by law, to establish or defend legal claims, or in connection with a transfer of the business, in which case you will be told before your data becomes subject to a different policy.

5. International transfers

Dropwire is operated from Israel, so sending personal data out of Israel is governed by the Israeli Transfer of Data to Databases Abroad Regulations. The EU adequacy decision for Israel is often cited in this context. It runs the other way: it permits transfers from the EU into Israel, and it is not the basis on which we send data out.

The application and database are hosted in Germany. Several providers listed above are in the United States or operate globally, so personal data does leave Israel and does leave the European Economic Area.

We would rather be plain about where this stands than claim more than we hold. We have not yet executed separate data processing agreementswith those providers, and this policy does not assert safeguards we do not have in place. Putting them in place is an open item. If the position for a particular provider matters to you before you use Dropwire, write to us and we will tell you exactly what is and is not in place.

6. How long we keep it

  • Account data: for as long as your account exists. After you delete it there is a 30 day grace period during which it can be restored, after which it is erased.
  • Session and click identifiers (IP address, user agent, visitor hash): 90 days, then irreversibly removed.
  • Audit records: retained for up to seven years for tax, accounting and proof-of-consent purposes, with the identifying user reference removed when you erase your account.
  • Backups: encrypted backups are retained on a rolling basis and expire between 30 and 35 days. Data you delete persists in a backup until that backup expires.
  • Connected credentials: deleted with your account.

7. Your rights, and how to use them

Under the Israeli Protection of Privacy Law you may inspect the personal data we hold about you (section 13), ask us to correct or delete data that is wrong, incomplete, unclear or out of date (section 14), and demand removal from a direct mail database (section 17F). Where the GDPR also applies to you, you additionally have the right to a portable copy, to restriction of processing, and to object to processing based on legitimate interests. Where processing rests on consent you may withdraw it at any time, without affecting what was lawful before.

You do not have to ask us for most of this. Signed-in users can download their own data and erase their own personal data from the "Your data" section of account settings. Owners can additionally export the whole workspace. For anything else, write to avigdor@dropwire.cc and we will respond within 30 days.

If you are unhappy with how we have handled your data you may complain to your local supervisory authority. In Israel that is the Privacy Protection Authority; in the EEA it is the data protection authority where you live or work. If we do not answer an inspection or correction request within 30 days, Israeli law also lets you take the matter straight to a Magistrate's Court, which is usually faster than waiting for the Authority.

8. Cookies and similar technologies

The application sets a session cookie so that you stay signed in. It is strictly necessary and cannot be switched off without signing you out. The waitlist form on this marketing site runs a Cloudflare Turnstile check to keep bots out, which is likewise necessary for the form to work at all.

This marketing site can load Cloudflare Web Analytics, which measures page timing. It is off until you turn it on. We ask once, in a banner, and keep your answer on your own device so that we can honour it and show that we did. Refusing takes one click and carries the same visual weight as accepting. You can change your mind at any time from the Cookie settings link in the footer, and we ask again after twelve months.

Cloudflare Web Analytics sets no cookie of its own and does not follow you between sites. Cloudflare already serves this page, so your IP address reaches them whether or not you switch it on. What switching it on adds is page timing measurement, not a new company seeing you.

We do not use advertising cookies and we do not do cross-site tracking. Tracked affiliate links count a click server side and set no cookie on the visitor's browser.

9. How we protect it

Measures include encryption in transit, encryption of connected credentials at rest under per-workspace keys, database-level isolation so one workspace cannot read another's rows, encrypted off-site backups, restricted and audited administrative access, two-factor authentication on administrative accounts, and monitoring configured to strip personal data before diagnostics leave our systems.

No system is perfectly secure. If a severe security incident occurs, we report it to the Israeli Privacy Protection Authority immediately on discovering it, based on what we know at that point, and complete the picture in a follow up report. We do not wait for our investigation to finish first, because Israeli law treats that delay as a breach of the duty in its own right. We notify affected individuals where the Authority directs us to. Where the GDPR applies to the data involved, we also notify the competent supervisory authority without undue delay, and you directly where that regulation requires it.

10. Changes

We may update this policy. Where a change is material we will give notice by email or in the product before it takes effect, and the date at the top of this page will change.

11. Contact

Privacy questions, requests and complaints: avigdor@dropwire.cc.