Lovedrop carries messages people really mean. That makes the data behind them personal — so we treat it that way.
This page explains what we collect, why, who helps us process it and what you can do about it. It applies to the Lovedrop website and apps. We follow the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).
Who is responsible
[COMPANY NAME] [LEGAL FORM], [STREET], [POSTCODE CITY], [COUNTRY] is responsible for processing your personal data.
Questions, requests or complaints about your data: [CONTACT EMAIL]. Responsible person: [RESPONSIBLE PERSON].
What we collect
We only collect what we need to make a campaign work. Depending on how you use Lovedrop, that is:
- Account data — your name, email address and profile picture. You sign in with a one-time code we email you, or with Google. If you choose Google, we receive your name, email address and profile picture from Google. Organisers and participants have an account. A recipient only needs one to keep their gifts.
- Campaign data — the occasion, the questions, the schedule and the people involved.
- Participant data — which account contributes to which campaign and the name shown with their contribution.
- Recipient data — the name, time zone and language of the person the messages are for, plus whether they have opened their gift link and whether the campaign creator has confirmed it is them.
- Messages — the text, photos, videos and voice recordings people contribute, plus their delivery status.
- Device data — if you use the Lovedrop iPhone app with notifications on: the push token Apple assigns to your device and the app's language.
- Payment data — the plan you bought, the amount, the currency and the payment status. Your card or account details go straight to our payment provider; we never see or store them.
- Technical data — your IP address, browser, device type and timestamps, which our hosting and infrastructure providers process to deliver the site and keep it secure.
- Usage and error data — only if you agree to it in the cookie settings (see below).
Why we use it
The words in brackets are the legal bases under the GDPR (Art. 6(1)(a), (b), (c) and (f)).
- To run your account and sign you in (contract).
- To create campaigns, collect contributions and deliver them to the recipient in the Lovedrop app on schedule (contract).
- To send you emails about your account and campaigns (contract).
- To take payments (contract).
- To keep the service secure and protect it against abuse (legitimate interest).
- To understand how Lovedrop is used and to fix errors — only with your consent.
- To meet legal obligations, for example keeping accounting records (legal obligation).
If you contribute or receive messages
If you contribute to a campaign, you do it from your own account. We use your name only for that campaign: to show your contribution with your name.
If you are the recipient, the campaign creator gave us your name. They hand you a link — as a web address, a QR code or a short code. When you open it, you get the first message. Nothing after that is delivered until the campaign creator confirms it is really you.
Who helps us
We don't sell your data. We work with these service providers, who process data on our behalf and only as we instruct:
- Supabase — database, sign-in and server functions. Stores all account, campaign and message data.
- Netlify — hosts the website.
- Cloudflare — domain name service (DNS) and private storage for photos, videos and voice recordings. Nothing in it is public: each file is shown only through a link that expires.
- Google — sign-in, if you choose "Continue with Google". Google then shares your name, email address and profile picture with us — only if you agree.
- Payrexx — payment processing.
- Resend — sends our emails.
- Apple — delivers notifications to the Lovedrop iPhone app. For each one, Apple receives your device's push token and the notification text: the first name of the person who sent the message and the question it answers. The message itself — text, photos, videos or voice recordings — is never sent to Apple; the app loads it when you open it.
- PostHog — product analytics, only after your consent. We send events without names, emails or message content.
- Sentry — error reports, only after your consent. We remove email addresses before a report is sent.
Data outside Switzerland and the EU
Some of these providers are based in, or use servers in, other countries — including the United States. When data leaves Switzerland or the EU/EEA, we make sure it stays protected: through an adequacy decision (for example the Swiss-US and EU-US Data Privacy Frameworks) or through the European Commission's standard contractual clauses, with the additions Swiss law requires.
How long we keep it
We keep your data as long as your account or the campaign exists and delete it after that unless the law requires us to keep it longer. Accounting records are kept for the period required by law (up to 10 years).
Your rights
You can ask us at any time:
- what data we have about you (access),
- to correct it (rectification),
- to delete it (erasure),
- to limit how we use it (restriction),
- to give it to you in a common format (portability),
- to stop using it where we rely on legitimate interest (objection).
- Where you gave consent, you can withdraw it at any time — for cookies, via "Cookie settings" in the footer. Withdrawing doesn't affect anything done before.
Complaints
Write to us first at [CONTACT EMAIL] — we'd rather fix it. You can also complain to a data protection authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the authority where you live or work.
Cookies
How we use cookies and similar storage is explained in our cookie policy.
Changes
We update this policy when our service or the law changes. The date at the top shows the current version.