Privacy Policy
Last Updated:
At iDropship, we are committed to protecting your privacy and being transparent about how we collect, use, and safeguard your data. This policy describes our data practices for both our web application and Chrome extension.
Overview
iDropship is a reactive commerce automation platform that helps entrepreneurs identify trending topics and convert them into product listings. We collect minimal data necessary to provide our services and never sell your personal information to third parties.
Information We Collect
Web Application
Account Information (via Google OAuth)
- Email address
- Display name
- Google account identifier (provider subject ID)
We use NextAuth with Google OAuth for authentication. We do not store your Google password.
Trend Data
- Trending topics you capture or create
- Source URLs and metadata (platform, engagement metrics)
- Keywords, velocity scores, and generated content
- Timestamps for creation and updates
Waitlist Submissions
- Email addresses submitted through the waitlist form
Technical Data
- Browser type and version
- IP address (via Cloudflare infrastructure)
- Session cookies for authentication
- Theme preference (stored in browser localStorage)
Chrome Extension
Authentication Tokens
- JWT bearer tokens (HS256, 1-hour expiration) stored in chrome.storage.sync
- API base URL preference (production or local development)
Trending Content
- Text of tweets or trending items you choose to ingest
- Source URLs from social media platforms (X/Twitter)
- Platform metadata (section, post type)
The extension only captures data when you explicitly click the "Ingest" button. It does not automatically collect browsing data or track your activity.
How We Use Your Information
- •Provide Core Services: Store and manage your trend data, generate product ideas, and facilitate listing creation.
- •Authentication & Security: Verify your identity, maintain secure sessions, and protect against unauthorized access.
- •Product Improvement: Analyze usage patterns (in aggregate) to improve our trend scoring algorithms and user experience.
- •Communications: Send important service updates, security alerts, and (with consent) product announcements.
Data Storage & Security
Database
All user data is stored in Cloudflare D1 (SQLite-based serverless database) with the following tables:
user: email, name, provider info, account statustrend: trending topics with keywords, velocity scores, metadatasource: individual URLs with engagement metricswaitlist: email addresses from early access signups
Infrastructure
Our application runs on Cloudflare's edge network, which provides:
- End-to-end encryption (HTTPS/TLS)
- DDoS protection and rate limiting
- Geographic distribution for performance
- SOC 2 Type II compliance
Access Controls
- JWT-based authentication with short-lived tokens (1-hour expiration)
- Session secrets rotated regularly
- User data isolated per account (row-level security)
- API requests validated with bearer tokens or session cookies
Cookies & Local Storage
Essential Cookies
next-auth.session-tokenor__Secure-next-auth.session-token: Authentication session (JWT, httpOnly, SameSite=Lax)
Browser Local Storage
theme: User's dark/light mode preference
Extension Storage (chrome.storage.sync)
EXT_TOKEN: Short-lived JWT for API authenticationAPI_BASE_URL: Selected API endpoint (prod or dev)
These are synced across your Chrome browsers when signed into Google.
Third-Party Services
- •Google OAuth: For authentication. Governed by Google's Privacy Policy.
- •Cloudflare: For hosting, CDN, and serverless infrastructure. See Cloudflare's Privacy Policy.
- •Crisp Chat: For customer support chat. Chat data is governed by Crisp's Privacy Policy.
We do not share your personal data with any other third parties for marketing purposes.
Data Retention
- •Active Accounts: We retain your data for as long as your account is active and you continue to use our services.
- •Deleted Accounts: Upon account deletion, we remove your personal data within 30 days, except where required for legal compliance or dispute resolution.
- •Authentication Tokens: Extension JWT tokens expire after 1 hour and are not renewable without re-authentication.
Your Rights
You have the right to:
- ✓Access your personal data and trend history at any time through your dashboard
- ✓Correct inaccurate information in your profile or trends
- ✓Delete your account and all associated data
- ✓Export your data in a machine-readable format (coming soon)
- ✓Opt-out of marketing communications (while still receiving essential service updates)
To exercise these rights, contact us at hello@idropship.co.
Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of material changes by email or through a prominent notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this privacy policy or our data practices, please contact us:
- Email: hello@idropship.co
- Website: https://idropship.co