Privacy Policy
httpdrop.com · March 2025
1. Data Collected
We collect only what is necessary for the service to function:
- Via OAuth (GitHub/Google): name, email, profile photo and provider ID
- Usage data: endpoints created, requests received, active plan
- HTTP request data: headers, body, query params sent to your mock endpoints
2. How We Use It
- Authentication and account identification
- Displaying requests in the dashboard in real time
- Controlling plan usage limits
- Service communications (never third-party marketing)
3. Sharing
We do not sell or share your data with third parties. Exceptions:
- Stripe: processes payments. We do not store card data.
- GitHub/Google: used only for OAuth authentication.
- Legal obligation: if required by law or competent authority.
4. Retention
HTTP requests on endpoints are stored for up to 7 days (Free plan) or 30 days (Pro/Team/Enterprise). When you delete your account, all data is permanently removed.
5. Your Rights (GDPR)
Under applicable data protection law, you have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Request deletion of your account and all data
- Data portability
To exercise these rights, email suporte@httpdrop.com.
6. Security
We use HTTPS for all communications. Data is stored on cloud servers with restricted access.
Last updated: March 2025