Privacy Policy

Last updated: August 29, 2026

This policy explains what Drop-IQ collects, why, and how you can control it. It is written to match how the Service actually works — no data is collected that isn't described here.

Overview

Drop-IQ is a product research and supplier intelligence platform for Shopify store owners. This policy describes what data we collect when you use Drop-IQ, how we use it, and the choices you have. It applies to the Drop-IQ website and application (collectively, the "Service").

Data we collect

  • Account data. When you sign up we store your email address and, if you use email sign-in, a hashed password managed by our authentication provider. If you sign in with Google, we receive your name and email from Google.
  • Profile and plan data. Your current plan, trial usage (such as how many products you have saved), and feature entitlements.
  • Workspace data. Formulas you build, saved products and shortlists, watchlists, supplier selections, competitor stores you track, and webhook or Slack destinations you configure for alerts.
  • Store connection data. If you connect a Shopify store, we store the shop domain and an OAuth access token, used to sync products and inventory.
  • Supplier credentials. API keys you provide for suppliers (such as CJ Dropshipping, AliExpress, Temu, AutoDS, TopDawg, or Zopi) so we can query their catalogs on your behalf.
  • Usage and device data. Pages visited and actions taken in the app, collected via Google Analytics (see "Analytics" below).

How we use your data

  • Provide the Service: product search, formula scoring, supplier catalog lookups, inventory monitoring, and competitor tracking.
  • Operate billing: create checkout sessions, apply plan entitlements, and handle renewals, upgrades, downgrades, and cancellations.
  • Send transactional email: welcome messages, stock alerts, competitor price/stock alerts, and billing notices.
  • Deliver alerts to webhook or Slack endpoints you explicitly configure.
  • Maintain security: enforce access controls, audit administrative actions, and prevent abuse.

We do not sell your personal data, and we do not use your store or supplier data to train advertising profiles.

Payments (Stripe)

Payments are processed by Stripe. When you subscribe, you enter payment details directly into Stripe's checkout; Drop-IQ never sees or stores your full card number. We store your Stripe customer ID, subscription ID, plan, and billing status so we can unlock the correct features and show your billing history.

Shopify connection

If you connect your Shopify store, we receive an OAuth access token during the authorization flow. The token is stored on our backend only — it is never sent to your browser — and is used to read products and update inventory when suppliers report stock changes. You can disconnect your store at any time from the Shopify page, which removes the stored connection.

Supplier integrations

Product search queries supplier catalogs (CJ Dropshipping, AliExpress, Temu, AutoDS, TopDawg, and Zopi) in real time. Any API credentials used for these calls are stored as backend secrets and are never exposed to the frontend. When you search, the search keyword is sent to the supplier's API to retrieve matching products.

Competitor spy

The competitor spy feature fetches publicly available pages (product catalogs, prices, and metadata) from storefront URLs that you submit. We store scan results so we can show you changes over time and send alerts. We do not collect personal data about the tracked stores' customers.

Analytics (Google Analytics 4)

We use Google Analytics 4 (measurement ID G-K49F272CNV) to understand how the Service is used — page views and key events such as sign-ups and upgrades. Google Analytics uses cookies and may process data on Google's servers according to Google's privacy policy. You can block analytics cookies with a browser extension or your browser settings without affecting core functionality.

Email

We send transactional email (welcome, stock alerts, competitor alerts, and billing notices) to your account email. We keep a log of sent messages for deliverability and support. You can turn off stock and competitor alerts by removing the relevant watches or alert destinations in the app; account and billing emails are required to operate your subscription.

Retention and security

We keep your data while your account is active. Row-level security restricts every account's data to that account; access tokens and supplier credentials are stored server-side and never returned to the browser. Administrative actions are recorded in an audit log. If you delete your account, we delete or de-identify your workspace data, retaining only what we need for billing records and legal obligations.

Your rights and choices

  • Access and export. Your products, formulas, and settings are visible in the app; contact us for a full export.
  • Correction. Update your account details on the Account page.
  • Deletion. Email us to delete your account and associated data.
  • Disconnect integrations. Remove Shopify and supplier connections at any time from the app.

Contact

Questions about this policy or your data: support@drop-iq.net. If we make material changes to this policy, we will update the "Last updated" date above and, for significant changes, notify you by email.