Privacy Policy
Effective date: October 7, 2026
1. Who we are
[COMPANY_NAME] (“we”, “us”) operates Dropship Automation. This policy explains what data we collect, why, and your rights. Contact: [SUPPORT_EMAIL].
2. Data we collect
- Account data: name, email address, and a securely hashed password. We never store your password in readable form.
- Store connections: OAuth tokens or API credentials for the selling channels you connect (Shopify, WooCommerce, eBay), plus the store identifiers needed to sync.
- Supplier credentials: API keys or login credentials for the suppliers you connect (e.g. CJ Dropshipping, Zendrop, Dropshipzone). These are encrypted at rest with AES-256-GCM and only decrypted in memory when performing an action you requested.
- Business data synced from your stores: products, orders, inventory levels, tracking numbers, and returns — the data the Service needs to function.
- Billing data: processed by Stripe. We receive subscription status and invoices; your full card number never touches our servers.
- Operational data: logs of actions taken through the Service (imports, order placements, syncs) for auditing, debugging, and support.
- Cookies: a session cookie to keep you signed in and basic security cookies. We do not run advertising trackers.
3. How we use it
- To operate the Service: syncing stores, placing supplier orders you approve or automate, updating tracking, monitoring shipments.
- To bill you via Stripe and enforce plan limits.
- To secure the platform: detecting abuse, investigating incidents, and meeting legal obligations.
- To support you: responding to tickets and diagnosing issues you report.
We do not sell your data, share it with advertisers, or use your store’s customer data for anything other than operating the Service.
4. Official APIs only
Integrations are built on official APIs and OAuth flows provided by the stores and suppliers. We do not scrape websites or use unofficial automation to obtain your data.
5. Sharing
- Stores and suppliers you connect: we exchange data with them as needed to perform your requested actions (e.g. pushing an order to CJ Dropshipping sends the order details to CJ).
- Stripe: payment processing (Stripe’s own privacy policy applies to data they collect).
- Infrastructure providers: hosting, database, and monitoring services bound by confidentiality, processing data only on our instructions.
- Legal: where required by law or to protect the Service’s security.
6. Security
- Supplier and store credentials encrypted at rest with AES-256-GCM.
- Passwords hashed with bcrypt; sessions are signed and expire.
- Access to production systems is restricted and logged.
No system is perfectly secure. If you suspect your account is compromised, contact [SUPPORT_EMAIL] immediately and rotate the affected credentials at the source.
7. Retention and deletion
We keep your data while your account is active. Disconnecting a store or supplier stops further syncing; previously synced business records are kept as your business history until you delete your account. Deleting your account removes your personal data and credentials; we retain only what the law requires (e.g. billing records) for the minimum period.
8. Your rights
- Access and export: request a copy of the data we hold about you.
- Correction: fix inaccurate account details in Settings or by contacting us.
- Deletion: delete your account from Settings at any time.
- Withdraw consent: disconnect any integration to stop its data flow.
We respond to privacy requests within 30 days at [SUPPORT_EMAIL].
9. Changes
We will notify you of material changes to this policy by email or in-app notice before they take effect.