Dropzippa
Sign inCreate account

Legal

Privacy Policy

Last updated: August 2026

1. Introduction

Dropzippa (“we”, “us”, “our”), operated by Tringify, provides a service for running scoped file operations on machines you control, through an API, a dashboard and a locally installed agent (together, the “Service”). This policy explains what we collect, why, and how long we keep it.

By using the Service you consent to the practices described here. If you do not agree with them, please do not use the Service.

2. Information we collect

Account information

Your email address, which is your primary identifier, and optionally your name and company name. Billing is in INR for the current India availability.

Authentication data

A cryptographically hashed version of your password, never plaintext, and not retrievable by anyone including our team. If you enable two-factor authentication we store the configuration needed to verify your codes. Where you sign in with Tringify single sign-on, authentication is handled by that provider.

Agent and folder information

When an agent connects, it reports the roots you configured on that machine: the alias you gave each folder, the folder path as it appears on that machine, whether it is writable or deletable, any allowed extension list, and whether the folder is currently reachable. We store this so the dashboard can show you what each machine exposes. We store folder paths as reported; we do not enumerate, index or read the contents of those folders.

Job metadata

For each job we store the title you give it, the operations it contains, the machine it targets, timestamps, its state through the lifecycle, the number of attempts, and any error message returned. Operations include the root aliases and relative paths they act on, and, for downloads, the source URL and any expected checksum you supplied.

File contents. For the download, copy, move, unzip and zip operations, file data never passes through our servers at all — the agent fetches or manipulates it directly on your machine. The one exception is the write operation, where the file body you supply is part of the job you submit to us and is therefore stored with that job until the job and its history age out. If you do not want file contents held on our servers, use download instead of write.

Usage data

Technical information collected automatically, including IP address, device and browser information, operating system, timezone and referring URLs. We use this for security, diagnostics and improving the Service.

Billing information

Payment details are collected and processed by our payment processor. We do not store full card numbers or CVVs. We may retain the last four digits and card type for your reference, along with invoices and subscription state.

3. How we use your data

  • To operate the Service: dispatching jobs, tracking their outcome and showing you history.
  • To meter usage against your plan’s monthly operation allowance.
  • To authenticate you and protect accounts against unauthorised access.
  • To bill you and provide invoices.
  • To diagnose failures, including failures you report to support.
  • To send service messages such as security notices and billing notifications.

We do not sell your personal data, and we do not use your job data to train models.

4. Cookies

We use cookies that are necessary for the Service to function, principally to keep you signed in and to protect against cross-site request forgery. Disabling them will prevent you from signing in.

5. Third-party services

We rely on third parties for payment processing, email delivery, infrastructure hosting and content delivery. Each receives only the data needed to perform its function. Where you use Tringify single sign-on, that provider handles your authentication.

6. Data storage and security

Data is encrypted in transit. Passwords, API keys and agent credentials are stored hashed, never in a recoverable form. Access to production systems is restricted to personnel who need it. No system is perfectly secure, and we cannot guarantee absolute security, but we design so that a compromise of our side does not grant access to your machines: an agent enforces its own folder boundaries locally and ignores instructions that fall outside them.

7. Data retention

Job history is retained for the window included in your plan, after which it is removed. Account, billing and invoice records are retained as long as your account exists and afterwards where required for legal, tax or accounting purposes. Deleting your account removes your account data and job history, subject to those obligations.

8. Your rights

You may request access to the personal data we hold about you, ask us to correct it, or ask us to delete it. You can export or delete much of it directly from the dashboard. To make a request, email privacy@dropzippa.com.

9. International data transfers

The Service is operated from infrastructure that may be located outside your country. Where data is transferred internationally we take steps to ensure it remains protected consistently with this policy.

10. Children

The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it.

11. Changes to this policy

We may update this policy. Material changes will be communicated through the Service or by email, and the “last updated” date above will change.

12. Contact

Questions about this policy: privacy@dropzippa.com. Security reports: security@dropzippa.com.