This Privacy Policy explains how DropoffToReady (“we,” “us,” or “our”) collects, uses, and shares information when you use the DropoffToReady software-as-a-service platform at app.dropofftoready.com, shop subdomains such as yourshop.dropofftoready.com, and related APIs (the “Service”).
DropoffToReady is a multi-tenant operations platform for shops. Shop operators (staff accounts) use Hub, Studio, and settings. Shop customers use public forms (schedule, drop-off, status, estimates, signatures, and similar pages) that a shop publishes. For customer information a shop collects through those forms, the shop is typically the business responsible for that data; we process it to provide the Service to that shop.
1. Who this policy covers
- People who create a DropoffToReady shop or sign in as staff (Hub users).
- People who submit information to a shop through DropoffToReady public pages (shop customers).
- Visitors to our platform marketing and legal pages.
2. Information we collect
Account and shop information
When you sign up or are invited to a shop, we collect name, email address, password (stored hashed), shop name and slug, business profile fields you enter (address, phone, hours, branding), team memberships, and role. We also store settings you configure (notifications, catalog, Studio forms, process timelines, integrations).
Operational data shops enter or generate
Work orders, customers, estimates, invoices, payments, communications drafts, attachments, pickup signatures, activity history, and similar records needed to run the shop workflow.
Information shop customers submit
Public forms may collect name, phone, email, appointment details, items for service, referral information, photos or files the shop enables, signatures, and other fields the shop configures in Studio.
Technical data
We collect logs needed to operate and secure the Service, such as IP address, browser type, timestamps, and authentication session cookies. We use cookies and similar storage for sign-in sessions and essential shop context. We do not use those cookies to run third-party advertising networks.
Integrations
If a shop connects QuickBooks Online, Xero, email, or object storage, we receive tokens and the business records needed to sync (for example customers, items, estimates, invoices, and payments). We store connection credentials encrypted at rest according to our application design and use them only to provide that integration for the connecting shop.
3. How we use information
- Provide, maintain, and improve the Service.
- Authenticate users and enforce shop isolation (each shop’s data is tenant-scoped).
- Send transactional email a shop enables (status, estimates, follow-up, team notices).
- Sync with accounting or other tools a shop connects.
- Provide support, diagnose incidents, and keep the platform secure.
- Comply with law and enforce our End User License Agreement.
We do not sell personal information.
4. How we share information
We share information only as needed to run the Service:
- Infrastructure. Hosting and database on Fly.io; file storage for logos, attachments, and similar objects; email delivery (for example Resend) when a shop sends mail.
- Accounting providers. If a shop connects QuickBooks Online (Intuit) or Xero, we send and receive the records that shop has enabled for sync.
- The shop. Staff with access to a tenant can see that shop’s customers and jobs. We do not share one shop’s customer list with another shop.
- Legal. We may disclose information if required by law, to protect rights and safety, or in connection with a merger or sale of the Service, with appropriate safeguards.
5. Retention
We keep shop and account data while the shop’s account is active. Shops may export or delete operational records through Hub where those tools exist. If a shop is closed, we retain or delete data according to our backup and account-closure practices and any legal obligation. Mail and job records a shop asked us to send or store remain until deleted or the account is removed.
6. Security
We use HTTPS, hashed passwords, tenant isolation in the application and database, and access controls for staff roles. No method of transmission or storage is completely secure. Shops are responsible for choosing strong passwords, limiting staff access, and for the content they collect from their own customers.
7. Your choices
- Staff can update profile and shop settings in Hub.
- Shop customers should contact the shop they dealt with to correct job or contact data.
- You may request access, correction, or deletion of personal information we hold by emailing mike@dropofftoready.com. We may need to verify identity and, for shop-customer data, work with the shop that collected it.
If you are in a jurisdiction with additional rights (for example certain US state privacy laws), you may also have the right to know, delete, or correct personal information, and to opt out of sale or sharing—which we do not do. You may authorize an agent to make a request on your behalf.
8. Children
The Service is for businesses and their adult customers. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
9. International processing
We currently host the Service in the United States (including Fly.io in the Dallas region). If you access the Service from elsewhere, your information may be processed in the United States.
10. Changes
We may update this policy. The “Last updated” date at the top will change. Continued use of the Service after an update means you accept the revised policy.
11. Contact
Privacy questions: mike@dropofftoready.com
Platform: https://app.dropofftoready.com
Related: End User License Agreement