Last updated: 13 June 2026
Plain English summary: We scan your promotional emails to find deals and send them to your WhatsApp — on demand, when you ask. We only look at your Promotions tab (Gmail) or commercial sender emails (Outlook). We never read personal emails, never sell your data, and never store your email content. After every scan we send you a receipt listing exactly which brands we read. You can permanently delete your account and all your data at any time by sending /delete on WhatsApp.
Dropp is a personal deals service operated from London, United Kingdom. The data controller for your personal data is Dropp (trading name). You can contact us at hello@dropp.ltd.
For privacy-specific requests (subject access, deletion, complaints), please email us with "Privacy Request" in the subject line. We will respond within 30 days as required by UK law.
| Data | Source | Purpose | Lawful basis (UK GDPR) |
|---|---|---|---|
| WhatsApp phone number | Messaging platform | Delivering your deals when you request a scan | Contract — necessary to provide the service |
| Display name (first name) | WhatsApp profile | Personalising messages | Contract — necessary to provide the service |
| Gmail address | Google OAuth (on connection) | Identifying your Google account; confirming Gmail access | Contract — necessary to provide the service |
| Gmail OAuth access & refresh tokens | Google OAuth | Accessing your Gmail Promotions tab on demand when you request a scan | Consent — you explicitly grant this via Google's OAuth screen |
| Microsoft account email address | Microsoft OAuth (on connection) | Identifying your Microsoft account; confirming Outlook access | Contract — necessary to provide the service |
| Outlook OAuth access & refresh tokens | Microsoft OAuth | Accessing your Outlook inbox on demand when you request a scan | Consent — you explicitly grant this via Microsoft's OAuth screen |
| Deal category preferences | Your selection during onboarding | Filtering deals to categories you care about | Contract — necessary to personalise the service |
| Activity timestamps (sign-up, email connected, deals sent, last active) | Service activity | Service improvement and diagnosing delivery issues | Legitimate interests — improving service quality |
| Country (inferred from phone number prefix) | Your phone number | Regional service improvement | Legitimate interests — understanding user geography |
Dropp's use of data received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
You can revoke Dropp's Gmail access at any time at myaccount.google.com/permissions.
If you connect an Outlook or Microsoft 365 account, Dropp uses the Microsoft Graph API with the Mail.Read scope. Specifically:
You can revoke Dropp's Outlook access at any time at myaccount.microsoft.com/permissions or by sending /disconnect outlook on WhatsApp.
Dropp scans on demand — only when you send /sales on WhatsApp. There are no background scans or scheduled jobs running on your account.
Gmail: We connect using your stored OAuth token and search for emails in the Promotions category from the past 7 days. We retrieve the subject line, sender address, and body text of those emails. This text is passed to OpenAI's API to identify active discount codes and sale announcements. Email content is processed in memory only — never written to our database.
Outlook: We connect using your stored OAuth token and read email headers from your Inbox and Junk Email folders from the past 7 days. Emails from personal email domains are immediately discarded. The body text of the remaining promotional candidates (up to 60) is passed to OpenAI transiently. Email content is processed in memory only — never written to our database.
Only the extracted deal summary (e.g. "20% off at ASOS — code SAVE20") is included in your WhatsApp message.
After every scan, you receive a scan receipt on WhatsApp listing every brand whose emails were read — so you can verify exactly what was accessed.
🔍We use the following companies to operate the service. Each acts as a data processor on our behalf under contractual terms:
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Twilio Inc. | Sending and receiving WhatsApp messages | Your phone number; message content (deal summaries and scan receipts) | United States |
| OpenAI, L.L.C. | Extracting deal information from email text | Email text (transient — not stored by OpenAI via API) | United States |
| Railway Corp. | Hosting our application and database | All account data (stored in database) | United States |
| Google LLC | Gmail API access | OAuth tokens; email content (via API during scan, not stored) | United States |
| Microsoft Corporation | Outlook / Microsoft Graph API access | OAuth tokens; email content (via API during scan, not stored) | United States |
Data transfers to these US-based companies are made under Standard Contractual Clauses (SCCs) / UK International Data Transfer Agreements (UK IDTA), which provide appropriate safeguards under UK GDPR. Twilio Privacy Policy · OpenAI Privacy Policy · Railway Privacy Policy · Microsoft Privacy Statement
/delete or email request), all personal data is permanently removed from our database within 30 days. Your Gmail and Outlook OAuth tokens are revoked immediately.We take reasonable technical and organisational measures to protect your data, including:
No system is 100% secure. If we discover a data breach that risks your rights and freedoms, we will notify the UK Information Commissioner's Office (ICO) within 72 hours and inform affected users without undue delay.
You have the following rights regarding your personal data. To exercise any of them, email hello@dropp.ltd — we will respond within 30 days.
/delete on WhatsApp, or by emailing us./disconnect on WhatsApp./disconnect outlook on WhatsApp.If you have a concern about how we handle your personal data, please contact us first at hello@dropp.ltd and we will do our best to resolve it.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO), the UK's data protection supervisory authority:
Dropp is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has provided us with their data, please email us and we will delete it promptly.
Our website (dropp.ltd) uses a single session cookie during the email authorisation flow (Gmail or Outlook). This cookie is temporary, expires when you close your browser, and contains no personal data — it only tracks the state of the OAuth authentication process. We do not use tracking, analytics, or advertising cookies.
We will update this policy as the service evolves. If we make material changes (e.g. collecting new categories of data, adding new processors), we will notify you via WhatsApp at least 14 days before the change takes effect. Continued use of Dropp after that date constitutes acceptance of the updated policy.
Data controller: Dropp, London, United Kingdom
Privacy enquiries: hello@dropp.ltd