This Privacy Policy explains what personal data DropPrint ("DropPrint", "we", "us") collects when you use dropprint.co.in, the ordering and administration application at https://app.dropprint.co.in and our APIs (together, the "Service"), why we collect it, who we share it with, and the choices and rights you have. It is written to comply with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 ("DPDP Act"). Terms used but not defined here have the meaning given in our Terms of Service.
1. Who this policy covers
- Customers — people who upload files and place print orders with a Shop through the Service.
- Shops — print businesses and their owners and staff who register and use the dashboard.
- Visitors — anyone browsing the public website or directory.
DropPrint is a platform. When you order from a Shop, the Shop also receives your data and is independently responsible for how it handles it in its own business (for example at the counter). This policy describes what we do.
2. What we collect
Provided by Customers
- Mobile number (required) — used to identify the order and let you track it. We store it with the country code the Shop configured.
- Name and note to the shop (optional).
- The files you upload — PDFs, Word documents and images — and the print settings you choose (copies, colour, sides, orientation, paper size, page range).
- Payment flags — whether you tapped "I have paid" and any UPI reference you typed. We never see your bank, card or UPI PIN details; payment happens inside your UPI app directly with the Shop.
Provided by Shops
- Business name, address, area, city, state, PIN code, opening hours, description, Google Maps link, logo and brand colours.
- Owner/staff name, email address, phone number and a password (stored only as a one-way hash).
- UPI ID and payee name (shown to Customers so they can pay you), optional static QR image, notification email, prices and other settings.
- Plan, billing dates and internal billing notes entered by the platform administrator.
Collected automatically
- Order and activity records — order code, timestamps, status history and who changed it, totals, page counts.
- Technical data — IP address, browser type and version, device type, pages requested and timing, kept in standard web-server logs for security and debugging.
- Session data — a session cookie for signed-in Shops and admins, and browser session storage on the ordering page so your cart survives a refresh (see Section 7).
We do not collect precise GPS location, contacts, or government ID numbers, and we do not use third-party advertising or behavioural-analytics trackers on the Service.
3. How we use it
| Purpose | Data used | Legal basis (DPDP Act) |
|---|---|---|
| Receiving, pricing and delivering your print order to the Shop you selected; showing you live status | Phone, name, files, settings, order records | Consent you give by placing the order; performance of the service you requested |
| Letting you track orders by phone number or order code | Phone, order code | Consent / performance |
| Operating a Shop's dashboard, listing it in the public directory, sending it new-order alerts | Shop profile, user accounts, notification email | Performance of our contract with the Shop |
| Billing Shops for paid plans and keeping accounting records | Shop identity, plan and billing data | Contract; legal obligation |
| Security: preventing abuse, rate-limiting logins, investigating fraud or prohibited content | Technical logs, order records | Legitimate use for security and legal compliance |
| Support — answering your emails and resolving disputes | Whatever you send us, plus the related order or account | Consent / performance |
| Improving the Service using aggregate, de-identified statistics (e.g. orders per city) | Aggregated counts only | Legitimate use; no personal data in the output |
We do not sell personal data, and we do not use your files or phone number for marketing. Shops may contact you about your order (for example to say it is ready); they must not use your details for anything else.
4. Your files
Files are the most sensitive thing you give us, so they are handled strictly:
- They are stored on our server in a directory that is not publicly browsable and are served only to the Shop you ordered from, after that Shop's user signs in, or to you via your own session during upload.
- We do not open, read, index or analyse the content of your files beyond what is technically needed (detecting page count, file type and size, and producing a print-ready version with your chosen settings).
- Files not attached to a completed order are deleted automatically within 24 hours.
- Files attached to an order are deleted automatically 7 days after the order is marked delivered or cancelled. Shops cannot extend this.
- Deletion is permanent; we do not keep backups of file contents beyond the routine server backups described in Section 6.
5. Who we share it with
- The Shop you order from. It sees your phone number, name, note, files, settings and payment flags — everything needed to print and hand over your order. It does not see orders you placed with other Shops.
- Service providers acting on our instructions: web hosting and database hosting; email delivery for order alerts, registration mails and password resets; and backup storage. They may only process data to provide those services to us.
- Public directory. A Shop's business name, address, area, city, state, hours, description, logo, prices and ordering link are public by design. Owner names, emails, phone numbers and UPI IDs are shown only where the Shop chooses to display them (for example, a contact phone on its ordering page; a UPI ID on an order's payment screen).
- Legal requirements. We may disclose data if required by law, court order or a competent authority, or to protect the rights, safety or property of users, Shops or DropPrint.
- Business transfers. If DropPrint is acquired or merges, data may transfer to the successor under this policy.
6. How long we keep it
| Data | Retention |
|---|---|
| Uploaded files, no order placed | Up to 24 hours |
| Uploaded files, order placed | Until 7 days after delivered/cancelled |
| Order records (code, phone, name, note, totals, status history) | Up to 24 months, for tracking, Shop accounting and dispute handling; then deleted or anonymised |
| Shop account and profile | While the account is active, plus up to 60 days after closure (so a Shop can be reinstated); billing records up to 8 years as required by Indian tax law |
| Password-reset tokens | 1 hour |
| Web-server logs | Typically 30–90 days |
| Routine server backups | Rolling, typically up to 30 days; backups are overwritten on schedule |
| Support emails | Up to 24 months after the matter is closed |
7. Cookies & local storage
dpsess— a strictly necessary session cookie, set only when a Shop user or platform admin signs in (and briefly during installation). It is HttpOnly and SameSite=Lax, expires when the browser closes, and contains only a random session identifier.- Session storage on the ordering page keeps your in-progress cart (file references and settings) in your own browser until you close the tab. It is never sent to us as a whole.
- Fonts are loaded from Google Fonts; Google receives your IP address and browser details when fonts are fetched. See Google's privacy policy. No other third-party scripts, pixels or analytics are included.
Because we only use strictly necessary cookies, no cookie banner or consent is required; you can still block cookies in your browser, which will prevent signing in to a dashboard.
8. Security
We protect data with measures appropriate to its sensitivity: HTTPS everywhere; passwords stored as salted one-way hashes; session regeneration on login; rate-limiting of login attempts; CSRF protection on state-changing requests; per-shop access scoping so a Shop can only ever see its own orders and files; file-type verification on upload; automatic deletion of files; and restricted administrative access. No system is perfectly secure. If we learn of a breach affecting your personal data we will notify affected users and the Data Protection Board of India as required by the DPDP Act.
9. Your rights
Under the DPDP Act and other applicable law you may:
- Access a summary of the personal data we hold about you and how it has been processed;
- Correct inaccurate or incomplete data (Shops can edit their profile directly in the dashboard);
- Erase your data where it is no longer needed for the purpose it was collected or required by law — for Customers this usually means the order record once the retention period in Section 6 has lapsed or earlier on request; Shops can close their account;
- Withdraw consent at any time for processing based on consent — for example by not placing further orders; withdrawal does not affect processing already done;
- Nominate another person to exercise your rights if you are unable to;
- Complain to our grievance officer (Section 13) and, if unsatisfied, to the Data Protection Board of India.
To exercise a right, email support@dropprint.co.in from the email on your account or include your order code and the mobile number used, so we can verify you. We respond within 30 days. Requests about data held by a Shop in its own records (e.g. a paper register) should be directed to that Shop.
10. Children
The Service is not directed at children under 18. A child may use the ordering page only under the supervision of a parent or guardian who accepts the Terms. We do not knowingly collect personal data from children without verifiable parental consent; if you believe we have, contact us and we will delete it.
11. Where data is stored
Our servers and backups are hosted with reputable hosting providers. Where a provider stores data outside India, we ensure the transfer is permitted under the DPDP Act and that the provider is bound by contractual confidentiality and security obligations. Email providers used for notifications may route messages through servers in other countries.
12. Changes to this policy
We may update this policy as the Service or the law changes. The "last updated" date at the top will change, and material changes will be announced on the Service or by email to registered Shops. Earlier versions are available on request.
13. Contact & grievance officer
For questions, requests or complaints about personal data, contact our grievance officer:
Grievance Officer, DropPrint
Email: support@dropprint.co.in
Web: dropprint.co.in
We acknowledge complaints within 48 hours and aim to resolve them within 30 days, in line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act.