Privacy Policy
Last updated: June 9, 2026
1. Data Controller
The controller of personal data is dropcpl (hereinafter "dropcpl", "we", "our"). For any privacy question, contact us at [email protected].
2. Data We Collect
We collect the following categories of personal data:
- • Account data: name, email, encrypted password, agency name.
- • Usage data: access logs, actions on the platform, interactions with the AI agent.
- • Tracking data: clicks on landing pages, URL parameters (UTM, fbclid), first-party session identifiers (HttpOnly cookies).
- • Lead data: information about contacts acquired through landing pages (name, email, phone and other fields configured by the user).
- • Billing data: processed by Stripe; dropcpl does not store credit card details.
3. Purposes and Legal Basis of Processing
Service delivery (basis: performance of the contract) — account management, LP tracking, lead attribution, CPL reporting.
Service improvement (basis: legitimate interest) — anonymous analysis of usage patterns to optimize the platform.
Service communications (basis: performance of the contract) — system notifications and critical updates.
Legal obligations (basis: legal requirement) — retention of fiscal and billing data for the periods required by applicable law.
4. Cookies and First-Party Tracking
dropcpl uses exclusively first-party HttpOnly cookies to track clicks on landing pages. We do not use third-party cookies for our own advertising purposes.
- • click_id (7 days): identifies the click that originated a visit for lead attribution.
- • _fbp (managed by Meta Pixel): if present, it is read for matching with Meta CAPI.
- • Session cookies: for secure authentication to the platform.
5. Data Retention
Account data: retained for the duration of the contract and for 12 months after closing. Click and lead data: 24 months. Billing data: 10 years under applicable tax law. At the end of the retention periods, data is securely deleted or anonymized.
6. Sharing Data with Third Parties
We do not sell or transfer data to third parties for commercial purposes. We share data only with these providers:
- • Stripe: payment processing.
- • Cloudflare: CDN, DDoS protection and custom domain management.
- • Anthropic (Claude AI): processing of AI requests (prompts do not contain third-party personal data).
- • Meta Platforms: Meta Ads API integration for spend synchronization (only for accounts that activate this integration).
7. Your Rights (GDPR)
Under EU Regulation 2016/679 (GDPR) you have the following rights:
- • Access: request a copy of your personal data.
- • Rectification: correct inaccurate or incomplete data.
- • Erasure: request deletion ("right to be forgotten").
- • Portability: receive your data in a structured, machine-readable format.
- • Objection: object to processing based on legitimate interest.
- • Restriction: request restriction of processing in certain cases.
To exercise these rights write to [email protected]. You also have the right to lodge a complaint with the Italian data protection authority (garanteprivacy.it).
8. Data Security
We adopt adequate technical and organizational security measures: encryption of sensitive data at rest, TLS/HTTPS connections for all transfers, two-factor authentication (2FA TOTP) available for all accounts, production data access limited to authorized personnel.
9. Changes to the Privacy Policy
We reserve the right to update this Privacy Policy. In case of substantial changes, we will inform you by email and/or through a notice on the platform at least 30 days before they take effect.