Privacy Policy
Last updated: 5 October 2026
This Privacy Policy explains how [OPERATOR NAME] (“DropPilot”, “we”, “us”) collects, uses, and shares personal data when you use the DropPilot website and services (the “Service”), and what rights you have. It should be read together with our Terms of Service.
1. Who is responsible
The data controller for the Service is [OPERATOR NAME], located in [COUNTRY / JURISDICTION]. Address (if required): [ADDRESS IF REQUIRED]. You can contact us about privacy at [CONTACT EMAIL].
2. Data we collect
We only collect the data needed to run the Service. This includes:
| Category | What it includes | Where it comes from |
|---|---|---|
| Account and profile | Discord user ID, username / display name, avatar URL, and the email address linked to your Discord account (if Discord provides one). | Discord, when you sign in with Discord |
| Roles and moderation | Role flags (for example staff or DropMaker), ban status, and ban and appeal information. | Us / our staff, and you (when you appeal) |
| Tokens and purchases | Your token balance, token transactions (such as calculations, redeemed codes, sent or received tokens, and purchases). When payments are enabled: order and payment confirmation details received from the payment provider. We do not receive or store your full card number. | You, our systems, and payment providers |
| Notifications and support | Notifications sent to you in the app, and support or ticket information you submit (including ban appeals). | Us and you |
| DropMaker content | Dropmaps and related content created by DropMakers, linked to their account. | DropMakers |
| Technical data | IP address, device and browser information, and server logs, handled by our hosting and infrastructure providers for delivery, security, and abuse prevention. | Your browser / device |
| Browser storage | Preferences (language, theme), some app data, and session tokens stored in your browser’s local storage. See section 8. | Your browser |
We do not use advertising trackers, and we do not sell your personal data.
3. How we use data and why
If the GDPR or the UK GDPR applies to you, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, signing you in, providing calculations, tokens, notifications, and DropMaker features | Performance of a contract (our Terms) |
| Processing token purchases and keeping payment and accounting records | Performance of a contract; legal obligation |
| Security, fraud and abuse prevention, enforcing our Terms, moderating content, handling bans and appeals, and keeping the Service stable | Legitimate interests (keeping the Service and its users safe) |
| Replying to your support requests and enquiries | Performance of a contract; legitimate interests |
| Any use that needs it (for example, optional features that rely on your permission) | Consent, which you can withdraw at any time |
Where we rely on legitimate interests, we weigh them against your rights and interests. You can object as described in section 7.
4. Who we share data with
We share personal data only with service providers that help us run the Service, and where the law requires it:
- Supabase — database and authentication provider. Our project is hosted in West Europe (London).
- Discord — the sign-in provider. Discord’s own privacy policy applies to your Discord account and to the sign-in process.
- Cloudflare — hosting and content delivery (CDN) for the website, which processes technical data such as IP addresses.
- Payment providers (PayPal and/or Stripe) — when payments are enabled, to process your purchase. They act under their own privacy policies for payment data.
- Authorities and advisers — where we are legally required, to protect our rights, or to professionals who advise us, under confidentiality duties.
- Successors — if the Service is transferred or reorganized, to the new operator, who must respect this policy.
Other users see only limited profile information needed for features like sending tokens (for example, your display name and avatar). Staff members can see account, ban, token, and ticket information as needed to run and moderate the Service.
5. International transfers
Some of our providers (for example, Discord, Cloudflare, and payment providers) may process data outside the European Economic Area or the United Kingdom, including in countries that may not have the same data protection rules. Where this happens, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK addendum where relevant), an adequacy decision, or other lawful transfer mechanisms.
6. How long we keep data
- Account data is kept while your account exists. If you ask us to delete your account, we delete or anonymize your personal data, except for what we must keep for the reasons below.
- Payment, transaction, and accounting records are kept for as long as the law requires (typically several years).
- Ban and abuse records may be kept for as long as needed to prevent evasion of a ban and to protect the Service and other users.
- Technical logs held by our infrastructure providers are kept for a limited period according to their own practices.
7. Your rights
If you are in the EU, EEA, or UK (and in many other places), you have the right to:
- access the personal data we hold about you;
- rectify data that is inaccurate or incomplete;
- erase your data (“right to be forgotten”) in the cases provided by law;
- restrict how we process your data;
- data portability — receive data you provided in a structured, commonly used format;
- object to processing based on legitimate interests; and
- withdraw consent at any time where processing is based on consent.
To exercise any of these rights, including to request deletion of your account and data, email us at [CONTACT EMAIL]. We may need to verify your identity (for example, by asking you to contact us from your Discord account). We will respond within the time required by law, usually within one month.
You also have the right to lodge a complaint with a data protection supervisory authority, for example in the EU country where you live, work, or where you believe a violation occurred, or the Information Commissioner’s Office (ICO) in the UK. We would appreciate the chance to address your concern first.
8. Cookies and local storage
We only use storage that is essential to provide the Service you ask for. The Service stores information in your browser’s local storage to keep you signed in (session tokens), remember your preferences (such as language and theme), and keep some app data you use. We do not use advertising or cross-site tracking cookies. Our hosting and security providers may also set or use technical cookies or similar technologies that are necessary for security and delivery of the website.
You can clear this data at any time in your browser settings. If you do, you will be signed out and your preferences will reset.
9. Third-party content
The Service loads some content from third parties, including map tiles and images from fortnite.gg, fonts from Google Fonts, and code libraries from content delivery networks. When your browser loads this content, those providers can see technical information such as your IP address and browser details. We do not control these providers; their own privacy policies apply to their handling of that data.
10. Security
We use reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), access controls on our database, and sign-in through Discord rather than storing passwords for regular users. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please protect your Discord account and tell us immediately if you suspect any unauthorized access.
11. Age and children
The Service is intended for people who are at least 13 years old, or older where the minimum age to consent to data processing is higher under local law. We do not knowingly collect personal data from children below that age. If you are under 18, you need the permission of a parent or legal guardian to make purchases. If you believe a child has given us personal data without the required permission, contact us at [CONTACT EMAIL] and we will delete it.
12. Changes to this policy
We may update this policy from time to time. If we make a material change, we will tell you through a notice on the site, and the “Last updated” date above will change.
13. Contact
For any privacy question or request:
[OPERATOR NAME]
Email: [CONTACT EMAIL]
Address: [ADDRESS IF REQUIRED]