Privacy policy
Last updated 17 August 2026
Drop Engine is a Shopify app operated by Louw Trading (South Africa). It schedules timed product drops, collects storefront waitlist signups, and emails those subscribers when a drop goes live. This policy explains exactly what data the app holds to do that, and how to get it deleted.
What we collect
| Data | Why we hold it |
|---|---|
| Your store's myshopify.com domain and an offline access token | To call the Shopify Admin API on your behalf — publishing and hiding the products you schedule. We use offline tokens only; we do not store the names or email addresses of your staff. |
| Scheduled drops: product ID, title, handle, image URL, go-live time and status | To show your drop schedule and release products on time. |
| Waitlist signups: the shopper's email address, the product they signed up for, and whether they have been emailed yet | To send the launch email when that product goes live, and to avoid emailing anyone twice. |
That is the complete list. The app does not read your orders, customer records or payment data, and it requests only the write_products access scope.
How we use it
- To run the features you asked for: schedule, release, and notify.
- To send launch emails to shoppers who joined a waitlist on your storefront.
- To diagnose errors and keep the service running.
We do not sell data, share it with advertisers, or use it to train machine-learning models. We do not email your waitlist about anything other than the drop they signed up for.
Who we share it with
Only the service providers needed to run the app, each acting on our instructions:
- Railway — application hosting and the PostgreSQL database where the data above is stored.
- Resend — delivery of launch emails to waitlist subscribers.
- Shopify — the platform the app runs on and reads product data from.
How long we keep it
- Drops and waitlist signups are kept while the app is installed, so the app can email your waitlist at go-live.
- When you uninstall, Shopify sends a shop redaction request (typically 48 hours later) and we delete every record for your store — subscribers, drops and sessions.
- A shopper can ask you to delete their data at any time; Shopify's customer redaction request removes their waitlist signups from our database.
The app implements Shopify's mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact), so these requests are handled automatically.
Your rights
Depending on where you or your shoppers live, you may have the right to access, correct, or delete personal information, or to object to its processing. Email support@dropengineapp.com and we will action it. We aim to respond within 30 days.
Security
Data is transmitted over HTTPS and stored in a managed PostgreSQL database that is not publicly reachable. Storefront waitlist requests are verified through Shopify's signed app proxy, and webhook requests are verified by HMAC signature.
Changes
If this policy changes materially we will update the date at the top of this page. Continuing to use the app after a change means you accept the updated policy.
Contact
Louw Trading, South Africa — support@dropengineapp.com