Privacy policy
What we collect, why we collect it, and what rights you keep.
- Account details like email and login info.
- API keys you choose to add (stored encrypted).
- Project data needed to run DriftLess features.
- For maker shops, the selected customer path and public maker-owned payment-link destinations.
- If you opt in, your optional product-email choice and bounded delivery status.
- If you choose to answer a maker check-in, your selected answer codes and optional comment.
- To run your account and project workflows.
- To show drift signals and history.
- To keep your project settings and outputs available.
- To show the maker’s chosen customer path and public payment-link destinations.
- To invite opted-in makers who have not received a usable private site to an optional private check-in.
- To understand, in privacy-safe aggregate, where getting started can be improved.
Makers may add maker-confirmed public HTTPS payment links they control. The maker is the seller and remains responsible for the sale, delivery, returns, and refund obligations. The maker’s provider processes payment and refunds, keeps payment records, and handles disputes, chargebacks, identity checks, and payouts under its own terms. DriftLess generates, edits, and hosts the website; it does not receive card or bank details or become the seller through these links.
The maker check-in is optional. If you opt in, our email provider processes your address and bounded delivery events to deliver it. Invitation access expires after 14 days. Identifiable answers are kept for no more than 90 days. Monthly categorical totals contain no account, project, run, email, token, locale, or comment and are kept for twelve complete calendar months. Invitation delivery and consent evidence follow the existing account-bound retention policy. Survey email open and click events are not used.
You can request access, correction, deletion, restriction, or export. We erase personal data when it is no longer needed, subject to legal obligations and the establishment, exercise, or defence of legal claims. Where financial records must be retained, we keep only what is necessary, restrict its use, and delete or anonymize it when the retention obligation ends.
We use essential cookies for login and session security. We do not use ad-tracking cookies.
Contact us first. If needed, you can also contact your local data protection authority.