Privacy Policy

Last updated: 9/27/2026

1. Data controller

Dropla is an online service for searching and exploring carrier and essential oils, featuring a recipe builder and blend calculator. The data controller for the personal data collected through the service is the owner of the website dropla.no. Contact: via the feedback form. We will update this section with full company details (registration number, address) once available.

2. What data we collect

  • Account information: Email address, user ID and password (stored encrypted).
  • User content: Recipes, ingredients and shopping lists you create.
  • Feedback: Email, rating and message you submit via the feedback form.
  • User role and subscription: Your role (user/admin) and any subscription plan and status.
  • Payment information: We never receive card details. Stripe handles payment and only sends us status, plan and customer ID.
  • Technical information: IP address, browser type and device information automatically logged for security and operations.
  • Usage statistics: Anonymous page views (path, referrer, language, country) without personally identifying data.

3. Purpose of processing

  • To give you access to the service and your recipes.
  • To manage user accounts, roles, subscriptions and billing.
  • To deliver AI-based suggestions (recipes, oils, safety checks).
  • To improve the service based on feedback.
  • To secure the platform against misuse and unauthorized access.

4. Legal basis

  • Contract: Necessary to deliver the service (GDPR Art. 6(1)(b)).
  • Consent: Feedback and optional features (GDPR Art. 6(1)(a)).
  • Legitimate interest: Security, troubleshooting and operations (GDPR Art. 6(1)(f)).
  • Legal obligation: Bookkeeping and retention of invoice data (accounting regulations).

5. AI features

Dropla uses an AI service (Lovable AI Gateway, which forwards requests to sub-processors such as OpenAI, Google and Anthropic) to suggest recipes, oils and safety checks. When you use these features, the content you generate (e.g. ingredient lists) is sent to the AI provider to produce the response. We do not send email, user ID or other directly identifying information with the request. The AI providers do not use the data to train models.

6. Storage and security

Personal data is stored encrypted. All communication between you and the service happens over HTTPS (TLS).

Data is stored within the EU/EEA with our infrastructure provider, which complies with GDPR and offers a data processing agreement (DPA).

Access to personal data is restricted to authorized administrators. We use Row-Level Security (RLS) to isolate user data.

7. Sub-processors

We use the following providers to process personal data on our behalf, under data processing agreements:

  • Supabase (EU): Database, authentication and storage.
  • Lovable / Cloudflare (EU/global): Hosting and delivery of the application.
  • Stripe (EU/USA): Payment and subscription processing. Stripe is certified under the EU-US Data Privacy Framework.
  • Lovable AI Gateway: Forwarding of AI requests to sub-processors (OpenAI, Google, Anthropic) as needed.
  • Email provider: Sending of transactional and authentication emails.

8. Payment and Stripe

When you subscribe, payment is processed by Stripe Payments Europe, Ltd. Stripe receives your email, name, card/bank details and IP address directly from you — Dropla never sees the card information. We only store a reference to the Stripe customer, the subscription's status, plan and period. Stripe's own privacy policy applies to their processing: stripe.com/privacy.

9. Sharing with third parties

We never sell personal data. Data is only shared with the providers listed in section 7, or when required by law or a legal order.

10. Cookies

We only use necessary cookies to keep you signed in and secure the service. We do not use tracking, analytics or marketing cookies. The first time you visit the site, you'll see a consent notice where you can confirm the use of necessary cookies.

11. Your rights

Under GDPR, you have the following rights:

  • Access: Request a copy of your personal data.
  • Rectification: Ask us to correct inaccurate data.
  • Erasure ("the right to be forgotten"): Ask us to delete your account and all associated data.
  • Data portability: Download your data in machine-readable JSON format.
  • Restriction and objection: Ask us to restrict processing, or object to processing based on legitimate interests.
  • Withdraw consent: You can withdraw consent at any time for processing based on consent.

12. Retention period

  • Account and user content: As long as you have an active account. Deleted within 30 days after you delete your account.
  • Payment data (invoices): Retained for 5 years per accounting regulations.
  • Security logs (IP/device): Maximum 90 days, then deleted or anonymized.
  • Feedback: Anonymized upon account deletion and may be retained for statistics.

13. Changes

We may update this policy as the service or applicable law changes. Material changes will be announced via email or on the website.

14. Contact

Have questions about privacy or want to exercise your rights? Contact us via the feedback form.

© 2026 Dropla — Privacy policy in compliance with GDPR and Norwegian data protection law.