PRIVACY
UPDATED 2026-10-06
DropDoc Privacy Policy
Effective date: October 6, 2026
This policy explains what information DropDoc collects, how it is used, who can see it, how long it is kept and what choices you have. It covers:
- the DropDoc apps: the web app at dropdoc.app and the apps for iOS, Android, Windows, macOS and Linux; and
- the DropDoc website at dropdoc.com.
DropDoc is operated by DropDoc Inc., 55 Samnah Crescent, Ingersoll, Ontario, Canada N5C 3J7 (“we”, “us”).
1. Who is responsible for your information
DropDoc is used by organizations to manage their documents, forms and procedures. That creates two kinds of information, and who is responsible differs between them:
- Your account. The information you give us to create and use a DropDoc account. We are responsible for it.
- Organization content. Everything stored in an organization’s repositories: documents, form submissions, attachments, comments, alerts and the record of who did what. The organization that owns the repository decides what is collected there and how it is used. We store and process it on the organization’s behalf and under its instructions.
If you use DropDoc because your employer or another organization invited you, questions and requests about that organization’s content should go to the organization first.
2. Information we collect in the apps
Information you provide
- Account details: your name, email address and password. Passwords are stored only as a salted hash; we cannot read them.
- Profile image, if you add one.
- Organization billing contact: when you create an organization, the name, email address and phone number of its billing contact.
- Content you create or upload in a repository: documents, form entries, signatures, comments, and photos, video, audio and files you attach.
- Messages you send us, such as support requests.
Information collected as you use the apps
- Sign-in sessions: for each device you sign in on, the type of device and browser, IP address and the times you signed in and were last active. You can see and end your sessions under Account Settings.
- Activity records: repositories keep a log of actions taken in them, such as creating, editing, publishing, submitting and deleting, and changes to users and permissions. Each record has the user, the time and the IP address.
- Error reports: if the app hits an unexpected error it sends us the error details, the app version, the platform, the screen you were on, your user ID and your IP address, so we can find and fix the problem.
- Notification settings and push tokens: which notifications you have chosen to receive and how. If you turn on push notifications on a phone or tablet, we store the token that identifies your device to Apple’s or Google’s notification service.
Device permissions
The mobile apps ask for access to the camera, microphone and photo library only when you choose to capture or attach a photo, video or recording, set a profile image or scan a QR code. What you capture is uploaded only when you add it to a document, form or your profile. Push notifications are sent only if you allow them. You can withdraw any of these permissions at any time in your device settings.
What the apps do not collect
The apps do not collect your location or your contacts, and contain no advertising and no third-party analytics. We do not track you across other companies’ apps or websites.
3. Information we collect on the website
The dropdoc.com website is separate from the apps and does not have access to your account or to any organization’s content.
- Google Analytics. The website uses Google Analytics to understand how visitors find and use it. Google Analytics sets cookies and collects information such as the pages you view, roughly where you are (from your IP address), and your browser and device type. This information is processed by Google, including on servers outside Canada. You can prevent it by using Google’s opt-out browser add-on at https://tools.google.com/dlpage/gaoptout, or by blocking cookies in your browser.
- Contact and support forms. If you contact us through the website, we receive what you enter, such as your name, email address and message.
Google Analytics is not used in the apps.
4. How we use information
We use the information above to:
- provide DropDoc: sign you in, show you the repositories you have access to, and store and display content;
- send service emails, such as email confirmation, password resets and invitations;
- send the notifications you have chosen to receive, by email (immediately or as a daily summary) or as push notifications;
- keep accounts and repositories secure, including detecting misuse and checking new passwords against known breached passwords;
- give organizations a record of activity in their repositories;
- bill organizations for the service;
- diagnose and fix problems, and provide support;
- understand how the website is used and improve it.
We do not sell your information and do not use it for advertising.
5. Who can see your information
- Other members of a repository can see your name, profile image and email address, and the content and activity you contribute, as far as the permissions set by the repository’s administrators allow.
- Administrators of an organization or repository can see its users, their roles and the activity log.
- DropDoc staff. A small number of authorized staff who operate and support the service are technically able to access the information stored in it, including organization content. They do so only when needed to provide support an organization has asked for, to keep the service running and secure, or to comply with the law, and they are bound by confidentiality obligations. We do not look at organization content for any other purpose.
- Companies that help us run DropDoc, limited to what they need to do their job:
- Infrastructure. The apps, databases, file storage, email delivery and backups run on dedicated infrastructure in Canada operated for us by our affiliated technology company. No other company hosts your account or organization content.
- Content delivery. We use Cloudflare to deliver the apps and files quickly and to protect them from attacks. Requests may pass through Cloudflare’s network, and files, including files uploaded to repositories, may be held temporarily on Cloudflare’s servers in other countries.
- Push notifications. If you turn them on, they are delivered through Apple (for iOS) or Google (for Android), which receive your device’s push token and the content of the notification.
- Website analytics. Google, as described in section 3.
- Legal reasons: we may disclose information if the law requires it, or to protect the rights, safety or property of our users or ourselves.
- Business transfers: if DropDoc is sold or merged, information may be transferred to the new operator, who must continue to honour this policy.
Passwords are checked against a database of known breached passwords that we host ourselves; nothing is sent to anyone else to do this.
6. Where information is stored
Your account and all organization content are stored in Canada, on the infrastructure described above. The exceptions are those listed in section 5: requests passing through and files cached temporarily by Cloudflare, push notifications passing through Apple and Google, and website analytics processed by Google, each of which may involve servers outside Canada.
Backups are currently kept on the same infrastructure in Canada. In future we may also store backups with a cloud storage provider; if we do, we will update this policy to say so.
7. How long we keep information
- Your account is kept until you delete it.
- Organization content is kept for as long as the organization keeps it. Deleted documents and folders go to the repository’s recycle bin until an administrator removes them permanently.
- Sign-in sessions are removed when you sign out, when they expire or when you end them.
- Server logs, which include error reports, are kept for 90 days.
- Backups of an organization’s content are kept for the period set by that organization’s backup policy. Deleted information remains in backups until they expire. When an organization closes, its content and backups are deleted within 30 days.
- Push tokens are removed when you turn off push notifications, sign out on that device or delete your account.
- Trial organizations whose billing contact we cannot reach may be deactivated or deleted after 30 days.
8. Deleting your account
You can delete your account at any time in the app under Account Settings > Delete Account. Deletion takes effect immediately and cannot be undone.
What is removed: your email address, password, profile image and sign-in sessions, your membership of all organizations and your access to all repositories. The email address can afterwards be used to register a new account, which has no connection to the old one.
What is kept: organizations keep the records of your work in their repositories, because those records belong to them and are often needed for audit and compliance. This means the documents, form submissions, comments and acknowledgements you contributed stay in place, and your name remains on them and in the repository’s activity log. Your email address and profile image are removed from those records. Copies in backups and server logs expire as described in section 7.
If you want something you contributed to an organization’s repository removed, ask the organization’s administrators.
If you are the only owner of an organization that has other members, you will be asked to make another member an owner before you can delete your account.
Shared accounts, which an organization sets up for a device or station rather than a person, are managed and removed by the organization’s administrators.
9. Your choices and rights
- See and correct your details under Account Settings.
- End sign-in sessions on other devices under Account Settings > Active User Sessions.
- Choose which notifications you get, and whether by email or push, in each repository.
- Opt out of website analytics, as described in section 3.
- Delete your account, as described above.
Under Canadian privacy law, and depending on where you live, you may also have the right to ask what information we hold about you, to get a copy of it, to have it corrected or deleted, to withdraw consent, and to complain to a privacy regulator such as the Office of the Privacy Commissioner of Canada. To make a request, contact us at the address below. For organization content we will refer your request to the organization that owns it.
10. Cookies
- The web app (dropdoc.app) uses one cookie, which keeps you signed in. It is required for DropDoc to work and is not used for advertising or tracking.
- The website (dropdoc.com) uses Google Analytics cookies, as described in section 3.
- Cloudflare may set a cookie on either to tell genuine visitors from automated attacks.
11. Security
Information is encrypted in transit. Passwords are hashed with Argon2id. Access inside a repository is controlled by roles and permissions set by its administrators. No system is perfectly secure, so we cannot guarantee security, but we work to protect your information and will notify affected users and organizations of a breach where the law requires it.
12. Children
DropDoc is a tool for organizations and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has created an account, contact us and we will delete it.
13. Changes to this policy
We may update this policy. If a change is significant we will let you know in the app or by email before it takes effect. The effective date above shows when it was last changed.
14. Contact
Privacy Officer
DropDoc Inc.
55 Samnah Crescent
Ingersoll, Ontario,
Canada N5C 3J7
privacy@dropdocinc.com
