Privacy Policy
Effective date: 14 September 2026 · Version 2.2
This Privacy Policy (the "Policy") sets out how data is processed in connection with DropPanel (the "Service"), operated by DBK STORE LLC. The Service is business software provided to commercial entities; it is not directed at consumers. A User who registers as a natural person represents that they use the Service in a commercial or professional capacity, not as a consumer. This Policy forms an integral part of the Terms of Service. Additional rights that may apply depending on the User's location are set out in the regional addenda in section 18.
1. Data controller and contact
The legal entity that operates the Service and acts as data controller under this Policy:
30 N Gould St #36944, Sheridan, WY 82801, United States of America
A limited liability company organized under the laws of the State of Wyoming
Contact: support@droppanel.net
The Service is a web application for Amazon sellers, available at app.droppanel.net, providing shipment tracking, accounting and returns management. All requests, questions and applications relating to data processing should be sent to the email address above.
2. Definitions
- User: the natural or legal person who opens an account on the Service.
- Account Data: data relating to the User's identity and account.
- Business Data: the commercial records the User enters into the panel or that the panel collects on the User's behalf.
- Subprocessor: a third-party service provider that processes data so that the Service can be delivered.
- Data Subject: the natural person whose personal data is processed.
3. Allocation of roles
Roles in respect of the data processed through the Service are allocated as follows:
- For Account Data (email address, account settings, support correspondence): DBK STORE LLC is the data controller.
- For Business Data (orders, tracking numbers, sales and expense records, returns, customer messages, reminders and notes): the User is the data controller. DBK STORE LLC acts solely as a data processor, following the User's instructions. Where Business Data contains personal data relating to the User's own customers, the obligation to inform those individuals and to establish a lawful basis for the processing rests with the User. DBK STORE LLC personnel cannot view Business Data. The sole exception is access that is limited in scope and duration, logged, and necessary to resolve a support request opened by the User themselves.
4. Categories of data processed
4.1. Account Data
- Email address and password. Passwords are stored only as a cryptographic hash; they are never held or displayed in plain text at any stage.
- Name and company name, where the User chooses to provide them.
- Support correspondence and, where a call-back is requested, the telephone number provided.
- Notification preferences, together with the device endpoint and time-zone offset needed to deliver notifications.
4.2. Business Data
- Order and shipment records: order number, product code (ASIN), tracking numbers, carrier, shipment events, the shipment's location and delivery dates.
- Accounting records: sales amounts, costs, expenses and exchange rates.
- Return records: reason for return, amounts and — where entered by the User — customer name and return label documents.
- Customer service records: customer messages imported into the panel and replies.
- Amazon Buyer-Seller Messaging bridge: where the User enables this Amazon feature, buyer messages forwarded by Amazon to the seller — the message content and, to the extent provided by Amazon, the buyer's name — are stored so the User can reply to their own Amazon customer. This content can be viewed only by the User account it belongs to; no one, including DBK STORE LLC staff — not even through the admin panel — can access these messages.
- Reminders, notes, application settings and store definitions.
4.3. Marketing site (droppanel.net)
No cookies are used on the marketing site. Visit measurement is performed without storing IP addresses; only aggregated data such as page views, country-level location and time on page is retained. These records are not linked to an identified or identifiable individual.
5. Purposes of processing and grounds
Data is processed only for the following purposes and on the grounds shown against each:
| Purpose | Data category | Ground |
|---|---|---|
| Creating and managing the account | Account Data | Formation and performance of the contract |
| Providing the Service: shipment tracking, accounting calculations, returns management | Business Data | Performance of the contract |
| Sending notifications | Notification preferences and device endpoint | Performance of the contract; notifications can be turned off by the User |
| Handling support requests | Support correspondence, contact details | Performance of the contract |
| Maintaining security and continuity of the Service, preventing misuse | Error and access logs | Legitimate interests |
| Complying with legal obligations | Relevant records | Legal obligation |
Data is not used for any purpose other than those set out in this Policy. Data is never sold or rented to third parties, and it is not used for advertising profiling or shared for marketing purposes. Business Data is not used for DBK STORE LLC's own commercial purposes.
6. Method of collection
Data is collected electronically: through the User entering it into the panel, uploading files, the panel retrieving data from carrier tracking services on the User's behalf, and — where the User grants authorization — automated retrieval from connected third-party systems (see section 8) and from Amazon's Buyer-Seller Messaging bridge (see section 4.2).
7. Artificial intelligence components
The AI features of the Service (event translation, status reports, decision suggestions, reply drafts and similar) are performed through a language model provider. In this context:
- Only the minimum data required by the relevant feature is sent to the provider. In the great majority of features, order number, customer name and amounts are not sent; in the data-correction feature only the format pattern of a tracking number is sent, never the number itself.
- Where the message translation and reply draft features are used, the message content imported into the panel by the User is sent to the provider for processing.
- Under the provider's terms of service such content is not used for model training; it may be retained by the provider only for a limited period and for abuse monitoring.
- Use of the AI features is not mandatory; each feature runs only when the User issues the corresponding command.
8. Amazon Selling Partner API integration
This section applies where the User connects an Amazon seller account to the Service. Until this feature is offered, no Amazon data is processed in respect of the User.
- The connection is established through Amazon's official Selling Partner API and with the User's explicit authorization. Authorization can be revoked by the User at any time from the Amazon account.
- The scope of access is limited to order and financial data (order number, product, amounts, dates, marketplace and Amazon fee items). Access to personal data relating to buyers — such as buyer name, address, telephone number and email address — is not requested; such data is neither processed nor stored. Should the scope be extended in future, this Policy will be updated in advance and Amazon's data protection requirements — including encryption in transit and at rest and limited retention periods — will be applied in full.
- Amazon-sourced data is processed solely to provide Service features to the User; it is not used for advertising or marketing, is not shared with third parties and is not sold.
- Authorization tokens are stored exclusively on the server side; they are never transmitted to the User's browser or to any other user.
- If the connection is terminated or the account is closed, Amazon-sourced data is deleted within a reasonable period.
9. Storage location and security measures
- Server: live data and backups are held in a database hosted within the European Union (Frankfurt, Germany). Each account can access only its own data; this separation is enforced at the database layer through row-level security policies.
- User device: for performance and to guard against data loss, the application keeps a copy of the data in the User's browser storage. This copy is not transferred off the device.
- User's own disk (optional): if the User selects a folder in settings, automatic backup copies are written there and remain entirely under the User's control.
- All data transfers take place over encrypted connections (TLS 1.2 or above); the database is encrypted at rest and provider-independent backup copies are encrypted with AES-256-GCM.
- Access logs are retained for at least twelve months, permissions are restricted on a least-privilege basis, multi-factor authentication is enforced for administrative access, and dependencies are scanned for known vulnerabilities on a regular basis.
- DBK STORE LLC maintains a written information security policy and an incident response plan.
10. Subprocessors and international transfers
The following subprocessors are engaged in order to deliver the Service, each receiving only the data required for the task it performs:
| Subprocessor | Task | Location | Data transferred |
|---|---|---|---|
| Supabase | Database, authentication, backup | Germany (Frankfurt) | Account Data and Business Data |
| Vercel | Hosting and server functions | Functions run in Germany (Frankfurt); global content delivery network | Request traffic (at the time of the request) |
| TrackingMore | Collection of carrier tracking data | China | Tracking number and carrier only; customer name, address and amounts are not transferred |
| Anthropic | Artificial intelligence features | United States | The limited content described in section 7 |
| Cloudflare | Domain management and encrypted backup storage | European Union | Encrypted backup copies |
| Resend | Delivery of Amazon Buyer-Seller messages by email | United States | Message content and the buyer's Amazon relay address |
Subprocessors may process data only for the purpose of providing services to DBK STORE LLC and within the scope of their contractual obligations; each is reviewed for security at least once a year. Beyond this, data is disclosed only upon a duly issued request from a competent public authority and only to the extent of that request.
Because DBK STORE LLC is established in the United States, data may be processed in countries other than the User's country of residence. Transfers are limited to the recipient categories listed in the table above, and data processing and confidentiality agreements have been concluded with the subprocessors. Transfer rules specific to the User's location are set out in the regional addenda in section 18.
11. Retention periods
- Account Data and Business Data are retained for as long as the account remains open.
- The Amazon Buyer-Seller Messaging bridge is an exception to this general rule: messages received and sent through this bridge (including the buyer's name, where provided) are automatically deleted from the system 180 days after they were received or sent.
- Backup copies are kept in versions and thinned out automatically over time; their sole purpose is protection against data loss.
- Where account deletion is requested, live data and server-side backup copies are deleted within 30 days following identity verification.
- Security and access logs are retained for twelve months for the purpose of detecting misuse and for audit.
- Records that must be retained under applicable law (for example commercial books and invoice records) fall outside these periods and are kept for the periods prescribed by the relevant legislation, after which they are deleted, destroyed or anonymized.
- Copies on the User's device and on the User's own disk remain under the User's control and it is the User's responsibility to delete them.
12. Automated decision-making and profiling
No decision producing legal effects concerning a Data Subject, or similarly significantly affecting them, is taken solely by automated means within the Service. AI suggestions that would modify the User's records (such as orders, sales, expenses or returns) are applied only upon the User's approval; a suggestion never changes a record on its own. Automated functions that do not alter records and serve a purely informational purpose — such as generating notification text — fall outside this scope. No profiling is carried out for marketing purposes.
13. Rights and how to exercise them
To the extent granted by the law applicable to them, the User and Data Subjects have the following rights: to learn whether their data is being processed and, if so, to access it; to learn the purposes of processing and the categories of recipients; to request rectification of inaccurate or incomplete data; to request erasure; to request restriction of processing; to receive their data in a structured, commonly used format; and to object to processing.
Requests should be sent to support@droppanel.net from the email address registered to the account, and must clearly state the requester's identity and the subject of the request. Requests are answered free of charge as soon as possible and in any event within thirty days. Additional rights that may apply depending on the User's location, and the routes for complaining to a supervisory authority, are set out in section 18.
The User may also export all data held in the panel at any time from the Settings section.
14. Cookies
No cookies are used, either in the application or on the marketing site. In the application, session information is held only in the User's browser storage; this record is strictly necessary for the Service to function and serves no marketing or tracking purpose. No third-party advertising or tracking script is loaded.
15. Children's data
The Service is intended for businesses engaged in commercial activity and is not offered to persons under the age of eighteen. Personal data relating to persons under eighteen is not knowingly collected.
16. Merger, transfer and reorganization
In the event of a transfer, merger or reorganization of all or part of the business, data may be transferred provided that the level of protection set out in this Policy is maintained by the transferee. The User will be informed in advance in such a case.
17. Data breach notification
Should data be unlawfully obtained by third parties, the affected User and — where required by applicable law — the competent supervisory authority will be notified without undue delay. Where Amazon-sourced data is affected, Amazon will be notified within 24 hours. DBK STORE LLC maintains a written incident response plan with a designated incident point of contact. As no system can guarantee absolute security, we ask that any suspected issue be reported immediately to support@droppanel.net.
18. Regional addenda
The following provisions apply only where the User or Data Subject is located in the relevant region and to the extent the law of that region applies.
18.1. California (CCPA/CPRA)
DBK STORE LLC does not meet the thresholds set out in the California Consumer Privacy Act and is therefore not a "business" within the meaning of that statute. Regardless, the following holds in all cases: personal data is not sold and is not shared for cross-context behavioral advertising. The Service is offered to businesses, not to consumers.
18.2. European Economic Area and United Kingdom (GDPR)
Where the General Data Protection Regulation applies, the legal bases for processing are as follows:
| Processing | Legal basis (GDPR art. 6) |
|---|---|
| Opening the account and providing the Service | Performance of a contract — art. 6(1)(b) |
| Security, prevention of misuse, service continuity | Legitimate interests — art. 6(1)(f) |
| Compliance with legal obligations | Legal obligation — art. 6(1)(c) |
Data Subjects have the rights of access, rectification, erasure, restriction of processing, data portability and objection. As data is processed by a company established in the United States, where a transfer outside the European Economic Area takes place it is carried out on the basis of the European Commission's Standard Contractual Clauses or an equivalent safeguard. Data Subjects have the right to lodge a complaint with the data protection supervisory authority in their country of residence.
18.3. Türkiye (KVKK)
Where Turkish Personal Data Protection Law no. 6698 applies, Data Subjects have the rights listed in article 11 of that Law. Requests are made in accordance with the procedure in section 13 and are concluded within thirty days at the latest, in line with the Communiqué on the Procedures and Principles of Application to the Data Controller. If a request is refused or is not answered within the period, the Data Subject has the right to lodge a complaint with the Personal Data Protection Board. Transfers abroad are limited to the recipient categories set out in section 10 and are carried out within the framework of article 9 of that Law.
19. Amendments to this Policy
Where this Policy is updated, the effective date and version number are changed and the updated version is published on this page. Changes that materially affect User rights are additionally announced through the application. Questions: support@droppanel.net