Droppin Droppin DE
← Back to home

Privacy Policy

App privacy policy · Last updated: 12 July 2026

This Privacy Policy explains how the Droppin mobile app ("Droppin", "we", "us") collects, uses, and shares your information, and the choices you have. It complements the website privacy notice (Datenschutzerklärung), which covers the droppin.eu website only.

Droppin is intended for users 18 and older.

1. Who is responsible

Dominik Machold Kloschinskystraße 90 54292 Trier, Germany

Email: support@droppin.eu · Phone: +49 651 43665799

For the purposes of the EU General Data Protection Regulation (GDPR), the above is the data controller for the app.

2. What we collect

Information you provide

Information collected automatically

We do not use advertising SDKs or third-party behavioral-tracking/analytics SDKs in the app.

Sensitive information (special categories)

We do not ask you for special categories of personal data (Art. 9 GDPR — e.g. data revealing racial or ethnic origin, religious or philosophical beliefs, political opinions, health, sexual orientation, or sex life). However, information you choose to share — such as free-text interests or bio, or joining or hosting a Drop with a particular theme (for example a religious, political, health-related, or LGBTQ+ event) — may reveal such information to us and to other users. Where you voluntarily post this in areas visible to others, you make it public through your own action; where explicit consent is required, we rely on the consent you give by choosing to share it. Please do not share sensitive information you do not want others to see.

Storing information on your device (TDDDG)

To run core features, we store and read a limited amount of information on your device — an encrypted login session, your app preferences, an image cache, and the push token. This access is strictly necessary to provide the features you request (§ 25(2) TDDDG); we do not use it for advertising or cross-service tracking.

3. Device permissions

PermissionWhy we ask
Location (while using the app)Center the map on you, show nearby Drops, and set the location of a Drop you create.
Photo libraryChoose a profile picture and add photos to posts (gallery only).
NotificationsSend you event reminders and chat/social notifications.
CalendarOnly when you tap "Add to calendar": open your device's event composer prefilled with the Drop.

Each permission is requested in context, the first time you use the related feature, and you can change these anytime in your device settings.

4. Why we use your data (legal bases)

5. Advertising

Droppin does not currently show advertising and does not use your personal data for advertising or profiling. When we introduce advertising, it will take the form of Sponsored Drops — events a business pays to show more prominently on the map. These are created by the advertiser and are selected using general context only (such as the map area you are viewing and the event category), which does not involve profiling you or processing your personal data for personalisation. We will:

If we later introduce personalised advertising that uses your personal data, we will update this policy first, ask for your consent (Art. 6(1)(a) GDPR) with an easy way to decline or withdraw, and, on iOS, show Apple's App Tracking Transparency prompt before any cross-app tracking.

6. Who we share it with

We do not sell your personal data. We share data with service providers ("processors") only as needed to run Droppin, under data-processing agreements (Art. 28 GDPR):

ProviderPurposeData involved
SupabaseBackend: database, authentication, file storage, realtimeYour account and content data
MapboxMap display and place/address searchDevice IP and requested coordinates / search text
Expo (push service)Delivering push notificationsPush token + notification content
Apple Push / Google Firebase Cloud MessagingOS-level push delivery (iOS / Android)Push token + notification content
Google / AppleSign-in with Google (and Apple, where offered)Basic account info (email, name) at login
ResendTransactional email (confirmations, resets, email changes)Your email address and the message

We may also disclose data where required by law, to respond to lawful requests from authorities, or to protect the rights, safety, and security of our users, the public, or Droppin.

International transfers

Our backend (Supabase) hosts your data in the European Union (Frankfurt, Germany — AWS eu-central-1). Some providers (e.g. Apple, Google, Mapbox) may process data outside the EU/EEA, including in the United States. Where that happens, the transfer relies on an appropriate safeguard under Chapter V GDPR — an EU adequacy decision or EU Standard Contractual Clauses — or on a derogation under Art. 49 GDPR. You can request a copy of the relevant safeguards from us. Map data is © OpenStreetMap contributors (ODbL) via Mapbox.

7. What other users can see

Droppin is a social app. Your username, display name, bio, avatar, the Drops you host, and your posts are visible to others according to your settings. Setting your profile to private restricts your posts, post images, and follower/following lists to approved followers (non-followers see only your name, avatar, bio, and counts). Anything you share in an event chat or a Drop is visible to its participants.

Messages and chats are stored, not end-to-end encrypted. Event chats and direct messages (including any images you send) are stored on our backend so the service can deliver and display them. They are encrypted in transit (HTTPS/TLS) and protected by access controls, but they are not end-to-end encrypted. We do not read your private messages as a matter of routine, but we — and our backend provider acting on our behalf — can access stored messages where necessary to operate and secure the service, to review content that is reported to us, or to comply with a legal obligation or lawful request. Please treat direct messages as private between participants, not as secret or encrypted communication, and do not share information in chat that you would not want stored.

8. How long we keep it

We keep your data while your account is active and for as long as needed to provide the service. As a guide:

When you delete your account in the app, we anonymize your profile and remove your engagement data, and the underlying authentication record is deleted so your email/identity can be reused. You can also delete individual content (posts, Drops, messages) in the app.

9. Your rights

Under the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and the right to data portability and to lodge a complaint with a supervisory authority. Where processing is based on consent, you can withdraw it at any time without affecting prior processing. You can:

Your competent supervisory authority in our region is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, but you may also complain to the authority where you live or work.

10. Security

We use industry-standard measures to protect your data, including encrypted transport (HTTPS/TLS), an encrypted on-device session store, and access controls (row-level security) on the backend. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a data breach is likely to result in a high risk to your rights, we will notify you and the competent authority as required by law.

11. Children

Droppin is not directed to anyone under 18. During onboarding we ask for your date of birth and block sign-up for under-18s. If you believe a minor has provided us data, contact us and we will remove it.

12. Changes to this policy

We may update this policy as the app evolves. We will post the updated version here with a new "last updated" date and, where the change is significant, notify you in the app or by email before it takes effect.

13. Contact

Questions about privacy? Email support@droppin.eu.