Last updated: July 22, 2026
We will never sell your personal information, customer data, documents, files, or anything else you share with us — ever.
Data Droplets, Inc (“Droplets”) provides secure digital workflows, encrypted document tools, eSignature support, secure file sharing, and compliance-focused services for regulated businesses, including auto dealerships and insurance agencies. This Privacy Policy explains what information Droplets may collect, how we use it, how we protect it, and the choices available to you.
1. Information we collect
The information Droplets collects depends on how you use our websites, applications, services, integrations, and support channels. We generally collect the minimum information needed to deliver, secure, improve, and support the services.
Account and contact information
We may collect your name, business email address, company name, role, login credentials, and related account details so we can create and manage your account, authenticate access, provide support, and communicate with you about the services.
Customer data and documents
When you or your organization use Droplets to upload, send, sign, encrypt, decrypt, manage, or share documents, files, forms, records, or related information, that content remains your Customer Data. Droplets uses Customer Data only to provide and support the services, comply with authorized instructions, maintain security, and meet legal obligations where applicable.
Encrypted data
Droplets uses encryption and security controls designed to protect information handled through the platform. Droplets does not use the contents of encrypted Customer Data for advertising, resale, or unrelated marketing purposes. Access to Customer Data is limited to the purposes described in this policy, your organization’s instructions, authorized user actions, support needs, security monitoring, and legal or compliance obligations.
Usage, audit, and service metadata
Droplets may collect metadata and operational records about how the services are used, such as account activity, authentication events, device and browser details, file-transfer activity, document workflow status, encryption/decryption events, access logs, timestamps, IP addresses, and system performance data. Metadata is used to operate, secure, troubleshoot, improve, and report on the services. Metadata does not give Droplets the ability to read encrypted document contents where encryption controls prevent that access.
Third-Party integrations
If you connect Droplets to a third-party service, such as Google Drive or another productivity platform, Droplets may access the minimum information needed to provide the requested integration and workflow. For Google Drive integrations, this may include file metadata such as filename, file type, permissions, file ID, associated Google account email address, and limited account information needed to connect and display the integration. Droplets does not sell Google user data and does not use Google user data for advertising. Droplets’ use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Communications and support information
If you contact us, request support, complete a form, attend a demo, or communicate with Droplets, we may collect the information you choose to provide, along with related communications, support notes, and troubleshooting details.
2. How we use information
- Provide, maintain, secure, and improve the services.
- Create, authenticate, administer, and support user accounts.
- Process document workflows, secure file sharing, eSignature activity, encryption, decryption, audit logging, and related service functions.
- Respond to support requests, questions, demos, and service communications.
- Monitor service performance, troubleshoot issues, prevent misuse, and protect against unauthorized access.
- Generate reports, logs, usage insights, and compliance records requested by customers or needed to operate the services.
- Comply with applicable legal, regulatory, contractual, and security obligations.
3. How we share information
Droplets does not sell personal information or Customer Data. We may share information only in limited circumstances:
- When you request insurance information. If you ask for insurance information, request a quote, ask to compare insurance products, or ask to be connected with an insurance professional, we will share the information you submit with one or more licensed insurance agents, agencies, brokers, or carriers so they can evaluate your request and contact you about available products and services. They may contact you by phone, email, or text message using the contact information you provide. These insurance professionals are independent of Droplets and handle your information under their own privacy policies and practices rather than this one. You are not required to submit an insurance request, and you may ask any insurance professional who contacts you to stop.
- With authorized users, customer administrators, or approval groups configured by your organization.
- With service providers and subprocessors that help us operate, secure, host, support, analyze, or improve the services, subject to appropriate confidentiality and security obligations.
- When required to comply with law, legal process, regulatory obligations, security investigations, or enforceable government requests.
- To protect the rights, safety, security, or integrity of Droplets, our customers, users, and the services.
- In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections for the information involved.
4. Customer controls and administrative access
Organizations may configure administrative controls, approval workflows, recovery processes, user permissions, retention settings, and access rights within the services. Depending on your organization’s configuration, designated administrators or approval groups may be able to access certain account, workflow, audit, recovery, export, or compliance functions. Droplets makes these functions available to help organizations manage access, recovery, business continuity, legal discovery, and compliance obligations.
5. Data retention
Droplets retains information for as long as needed to provide the services, comply with legal and contractual obligations, maintain security, resolve disputes, enforce agreements, and support legitimate business needs. Customer Data may be retained or deleted according to your organization’s configuration, contractual terms, product settings, and lawful instructions.
6. Security
Droplets uses administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, loss, misuse, or destruction. These safeguards may include encryption, access controls, logging, monitoring, secure development practices, and restricted access for personnel and service providers. No system can be guaranteed to be completely secure, but Droplets is committed to maintaining a strong security posture for the data entrusted to us.
7. Cookies and similar technologies
Droplets and its service providers may use cookies, pixels, local storage, and similar technologies to operate, secure, and improve our websites, applications, and services.
What are cookies?
Cookies are small text files placed on your device when you visit a website or use an online service. Cookies help websites recognize your device, remember preferences, enhance security, and improve user experience.
Types of Cookies we use
Essential Cookies
These cookies are necessary for the operation and security of the Droplets platform. They enable functions such as user authentication, session management, access controls, fraud prevention, and secure service delivery.
Performance and Analytics Cookies
These cookies help us understand how visitors and users interact with our websites and services. Information collected may include page visits, navigation patterns, feature usage, device information, and performance metrics. This information is used to improve functionality, reliability, and user experience.
Preference Cookies
These cookies allow Droplets to remember settings and preferences, such as language selections, user preferences, and account configurations.
Marketing and Communications Cookies
Where permitted by law, Droplets may use cookies or similar technologies to measure the effectiveness of marketing campaigns, understand engagement with communications, and improve content relevance. Droplets does not sell personal information collected through cookies.
Third-Party technologies
Certain third-party providers may place cookies or similar technologies when you interact with Droplets websites or integrated services. These providers may include analytics, customer support, security, hosting, marketing, and infrastructure partners. The collection and use of information by third parties is governed by their respective privacy policies.
Managing Cookies
Most web browsers allow you to control cookies through their settings. You may choose to block, delete, or restrict cookies; however, doing so may affect the functionality, performance, or availability of certain Droplets services and features.
Do not track signals
Some browsers offer a “Do Not Track” feature. Because there is no universal industry standard for responding to these signals, Droplets may not respond to all Do Not Track requests. Users can manage cookie preferences through browser settings and any cookie preference tools made available by Droplets.
Updates to this Cookies section
Droplets may update its use of cookies and similar technologies as our services evolve. Any material changes will be reflected in this Privacy Policy and, where required, additional notice or consent mechanisms will be provided.
8. Your choices and requests
Depending on your relationship with Droplets and applicable law, you may have rights to access, correct, delete, export, restrict, or object to certain uses of personal information. If your account is provided by your organization, please contact your organization’s administrator first. You may also contact Droplets using the contact information below, and we will respond consistent with applicable law and contractual obligations.
9. Children’s privacy
Droplets services are intended for business use and are not directed to children. We do not knowingly collect personal information from children for consumer-directed services.
10. Changes to this policy
Droplets may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date above and may provide additional notice where appropriate or required by law. If changes materially affect how Droplets processes information based on consent, Droplets will obtain consent where required.
11. Contact us
If you have questions or concerns about this Privacy Policy or Droplets privacy practices, contact us at support@droplets.id or through your usual Droplets support contact.
