Back to DraftPass

Privacy Policy

Last updated: January 2026

1. Data we collect

We collect account information (name, email, agency name), content you upload for review, review activity and decisions, and usage data to operate and improve the service.

2. How we use data

Your data is used to provide the DraftPass service: to display content to your clients for review, to send notifications, and to generate activity logs. We do not sell your data or your clients' data to third parties.

3. Client contact data

When you add client contacts to DraftPass, we store their name and email address solely to send review requests and notifications on your behalf. Client contacts do not create DraftPass accounts or passwords.

4. Data storage and security

Data is stored in Supabase (Postgres) with row-level security isolating each agency's data. Review tokens are hashed at rest. We use industry-standard encryption for data in transit and at rest.

5. Third-party services

We use Supabase for database, auth, and storage; Stripe for payment processing; Resend for email delivery; and Upstash for Redis caching. Each provider processes data according to their own privacy policies.

6. Data retention and deletion

Your data is retained while your account is active. You may export or delete your data at any time by contacting us. Upon account deletion, your data is permanently removed within 30 days.

7. Cookies

We use essential cookies for authentication sessions. No tracking cookies or third-party advertising cookies are used in the DraftPass platform.

8. Contact

For privacy-related inquiries, contact us at privacy@draftpass.com.