DropBase
How it works

Privacy Policy

Effective July 24, 2026

Who we are

DropBase is a deliverable-collection tool for project managers and the contractors who deliver files to them. This policy explains what data we handle and why. Questions: support@drop-base.com.

What we collect

  • Account data — your email and username, managed through our authentication provider (Supabase Auth), and your role (admin or contractor).
  • Project data — the projects, drop-zone requirements, due dates, and deliverable metadata (file names, sizes, versions, review status) you create or upload.
  • Google account data — only if you choose to connect Google Drive: your Google account email (to show which account is connected) and OAuth tokens that let DropBase create and manage deliverable folders and files on your behalf.

How we use Google Drive access

When you connect Google Drive, DropBase requests the least-privilege drive.file scope. This means DropBase can only see and manage the folders and files that DropBase itself creates or that you explicitly open with it — never the rest of your Google Drive. We use this access solely to:

  • create per-project and per-requirement folders in your Drive;
  • receive contractor uploads directly into those folders (files are owned by you and count against your Drive storage); and
  • record who delivered each file (contractor name and date) in the file's description so your team can see it in Drive.

DropBase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, and we do not sell it.

How we store and protect data

Data is transmitted over TLS. OAuth refresh tokens are encrypted at rest with AES-256-GCM before being stored, and are accessible only to server-side processes that perform Drive operations on your behalf. Application data is hosted on Supabase and Vercel; files live in your own Google Drive, not on DropBase servers.

Who we share it with

We do not sell your data. We rely on a small set of subprocessors to run the service: Supabase (database and authentication), Vercel (hosting), Google (Drive storage and sign-in), and Resend (transactional email). Each processes data only to provide their part of the service.

Retention and deletion

You can disconnect Google Drive at any time from your account settings; doing so revokes DropBase's access and deletes the stored tokens. Files already in your Drive remain yours and are unaffected. You may request deletion of your DropBase account and associated data by emailing support@drop-base.com. You can also review or revoke DropBase's access directly at myaccount.google.com/permissions.

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected here with a new effective date.