Skip to content

Legal

Privacy Policy

Droppy collects very little, because it needs very little. There is no signup form, no identity verification and no advertising. This page explains exactly what is stored and why.

What we store

The complete list of what Droppy records in its database:

  • Your wallet address, which serves as your account identifier.
  • An optional display name and your default network and asset preferences.
  • Payment links you create: amount, asset, chain, invoice id, description, timestamps and expiry.
  • Settled payments: the transaction hash, the paying address, the amount received, the block number and confirmation count.
  • Short-lived sign-in challenges, which are deleted after use or expiry.
  • Rate-limiting counters, which record request volume against a bucket key, not a person.

What we never collect

We do not ask for and do not receive private keys or recovery phrases. No field in Droppy accepts one, and no legitimate Droppy communication will ever request one.

We do not collect names, email addresses, phone numbers, postal addresses, government identifiers or payment card details. There is no identity verification process because the product does not need one.

We do not use advertising trackers, cross-site tracking pixels, or third-party analytics that profile you.

What is public by design

Blockchain transactions are public. Any address you use, the amounts you receive and the transactions that settle your payment links are visible to anyone on Robinhood Chain and its block explorers. This is a property of public blockchains, not of Droppy.

Anyone with a payment link URL can view that link, which is what makes it shareable. Link identifiers carry 96 bits of randomness and the endpoint is rate limited, so they cannot practically be guessed, but treat a link like a bearer token: share it only with the person meant to pay it.

Cookies

Droppy sets one cookie: a session cookie issued after you sign in with a wallet signature. It is HttpOnly, SameSite=Lax and, in production, Secure. It is strictly necessary for the merchant area to function.

We set no advertising or analytics cookies. Your browser may also store small preferences locally, such as which wallet you last connected; that data stays on your device.

Service providers

Droppy is hosted on Vercel and stores data in a managed PostgreSQL database. These providers process data on our behalf under their own security and privacy commitments.

To verify payments we query public blockchain RPC endpoints. Those requests necessarily disclose the transaction hashes and addresses being checked to the RPC provider, and originate from our servers rather than from your browser.

Retention

Payment records are retained while the service operates, because they are the record of what you were paid and are needed for your own reconciliation.

Sign-in challenges are deleted after use or expiry. Rate-limiting counters are cleared after their window elapses.

Your choices

You can sign out at any time, which clears your session cookie. You can stop using Droppy without any cancellation process, since there is no subscription or stored payment method.

To request deletion of the records associated with your wallet address, contact us. Note that we cannot delete anything from the blockchain — transactions there are permanent and outside our control.

Children

Droppy is not directed at children and is not intended for use by anyone under the age of majority in their jurisdiction.

Changes and contact

Material changes to this policy will be reflected in the last-updated date above. Questions about privacy can be sent to support@droppy.app.

Ready to accept crypto?

Create your first payment link in under a minute. No signup form, no API key.