Privacy Policy
Last updated: February 2026 • Effective immediately
At Pokodrop, privacy is not an afterthought—it is the core architectural principle of our platform. We provide a zero-friction document drop platform designed specifically for print shops, service points, and organizations.
This Privacy Policy describes how Pokodrop ("we", "us", or "our") collects, processes, and safeguards information when you use our website, mobile interface, and document collection services.
1. Information We Collect
We collect only the minimum necessary information required to operate a reliable and secure document transfer platform:
Shop owner name, verified email address, shop display name, slug, and authentication parameters required to access your account.
Files uploaded by customers are encrypted on the client device prior to upload. We only store encrypted ciphertext.
Session identifiers, file sizes, document format identifiers, and upload timestamps needed to organize dashboard queues.
Subscription tier, billing cycle dates, and payment status. We never collect or store your payment card numbers.
2. Zero-Knowledge Architecture & Encryption
Pokodrop implements a Zero-Knowledge End-to-End Encryption (E2EE) security model:
- Client-Side Cryptography: When a customer scans your QR code and drops a document, the encryption occurs directly within their mobile browser before the data leaves their device.
- Zero Plaintext Access: Our servers only receive and store encrypted blobs (ciphertext). Pokodrop staff, automated systems, and third parties cannot inspect, read, or parse the contents of your documents.
- Decryption Key Custody: Decryption keys are held securely by the authenticated shop owner and are never transmitted unencrypted to our backend.
3. How We Use Collected Data
The unencrypted metadata and account information we collect is strictly used to:
- Authenticate shop owners and provision secure QR drop points.
- Display real-time incoming file drop queues on your shop dashboard.
- Process subscription renewals and maintain account standing.
- Detect anomalies, combat automated abuse, and ensure service reliability.
- Provide customer support when requested by you.
4. Trusted Infrastructure & Security Partners
We do not sell, rent, or trade your personal data. We partner exclusively with enterprise-grade, certified infrastructure providers to deliver our service:
- PCI-DSS Certified Payment Gateways: Payment information is processed directly by certified payment processors under strict PCI-DSS compliance. We never handle or store raw card or banking credentials.
- Encrypted Cloud Storage Facilities: Encrypted document ciphertext is stored in geo-redundant, hardened cloud storage with strict access controls.
- Isolated Relational Database Clusters: Account metadata and authentication records are secured in encrypted database clusters protected by modern firewall rules.
5. Document Retention & Purging Controls
We believe that documents should not linger indefinitely on personal devices or servers:
- Shop-Initiated Deletion: Shop owners can instantly delete any file or clear entire customer sessions from their dashboard at any time.
- Permanent Removal: Once deleted by a shop owner, file metadata and underlying encrypted blobs are permanently purged and unrecoverable.
- Account Termination: When an account is closed, all associated shop configurations, QR drops, and historical metadata are permanently deleted.
6. Your Privacy Rights
Depending on your jurisdiction, you have full rights regarding your personal data, including the right to request access, correction, export, or permanent erasure of your account information. To exercise any of these rights, contact us at our support address below.
7. Contact & Privacy Inquiries
If you have questions or concerns about this Privacy Policy or our cryptographic data handling, please contact our team at:
Email: pokodrop.team@gmail.com