Your privacy matters to us. This policy explains, in plain language, what information Dropit (a product of PataProducts) collects, why we collect it, and the choices you have. We keep things simple and only collect what we actually need. We follow applicable data-protection laws, including Kenya's Data Protection Act, 2019.
1. What we collect
- Your Google account basics. Dropit uses Google sign-in — we receive your email address, name, and profile photo. We never see your Google password, and we don't store passwords of our own.
- The files you transfer. The files you upload, their names, sizes and types, who you addressed them to, and when they expire — that's the product working.
- Invoice and payment details. The amounts, due dates and messages you attach to a transfer, the payment channels you choose to show your client (e.g. a paybill number or bank account you enter), and any proof-of-payment images a client submits for your review.
- Subscription information. If you subscribe to Premium, the payment is handled by the relevant payment processor. We receive confirmation of the subscription but not your full card details.
- Things collected automatically. Basic technical data — such as device type and rough region — so we can operate and secure the Service.
2. How we use it
- To deliver your transfers: store your files, notify your recipient, and gate downloads until you confirm payment.
- To generate and email the invoices you create.
- To show senders and recipients the status of a transfer (sent, payment submitted, confirmed, disputed, expired).
- To send account and transfer notifications — in the app and by email.
- To keep the Service safe from fraud, abuse, and security issues.
3. Where your files live
Files are stored in private cloud object storage. They are never listed publicly, and they are only reachable through short-lived, signed download links generated after we verify that the person asking is the sender or the intended recipient — and, where an invoice is attached, that the payment gate has been cleared.
4. Payments — what we don't touch
Dropit does not process or hold the money your clients pay you. Payments move directly between you and your client through the payment channel you chose (e.g. M-Pesa, bank transfer, or a Paystack link). What we store is the record around it: the invoice, the proof your client submits, and your confirmation or dispute.
5. What others can see
The person you address a transfer to can see the delivery you built for them: the folder name, file list, your email address, and the invoice details. Nobody else can — a forwarded link doesn't work for anyone but the intended recipient's account.
6. When we share
We don't sell your personal information. We share it only with trusted providers who help us run the Service — hosting, cloud storage, database and authentication, email delivery, and payment processors for Premium subscriptions — and only as far as they need it to do their job. We may also share information where the law requires it.
7. Keeping and deleting your data
Free-plan transfers are held for 7 days, then trashed; trashed items are restorable for 7 more days before they're permanently removed from storage. Premium transfers are held until you delete them. You can ask us to delete your account and data at any time by emailing us — we may keep limited records longer where the law requires (for example, basic subscription records).
8. Your choices and rights
Subject to applicable law, you can access, correct, or delete your personal data, get a copy of it, object to or limit certain uses, and withdraw consent at any time. Email us at hello@pataproducts.com and we'll help.
9. Security
We use reasonable technical and organisational measures to protect your information — authentication on every request, signed URLs for storage, and access checks on both sides of every transfer. That said, no method of transmission or storage is ever 100% secure, so we can't promise absolute security.
10. Changes to this policy
We may update this policy now and then. When we do, we'll update the "Last updated" date at the top, and we'll flag anything significant through the Service.