Legal

Privacy Policy

How we collect, use, and protect your personal information.

Last updated: April 9, 2026

1. Introduction

Hernatter Limited ("we," "us," or "our"), operating the Dropzon platform at dropzon.app, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our platform, mobile applications, and related services.

By using Dropzon, you consent to the practices described in this policy. If you do not agree, please discontinue use of our services.

2. Information We Collect

2.1 Information You Provide

  • Account information: Name, email address, phone number, and password when you register
  • Profile information: Profile photo, preferred language, and communication preferences
  • Address information: Your selected Dropzon location, DZ Address details, and any labels you assign
  • Payment information: Transaction details, payment method, and billing history (payment card data is processed by our payment partners and not stored on our servers)
  • Operator information: Business name, business license, physical address, and banking details for payout (if you are an agent or branch operator)
  • Identity verification: Government-issued ID documents when required for operator registration or compliance
  • Communications: Messages, support requests, and feedback you send us

2.2 Information Collected Automatically

  • Device information: Device type, operating system, browser type, and unique device identifiers
  • Usage data: Pages visited, features used, time spent on the platform, and interaction patterns
  • Location data: Approximate location based on IP address; precise GPS location only when you explicitly grant permission (e.g., for finding nearby Dropzons or Dropper delivery tracking)
  • Log data: IP address, access times, referring URLs, and error logs

2.3 Information from Third Parties

  • Shipping and tracking data from logistics partners (DoorDrop and others)
  • Payment confirmation from payment processors
  • Identity verification results from third-party verification services

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Dropzon platform and services
  • Process subscriptions, payments, and transactions
  • Assign and manage your DZ Address
  • Route packages to your Dropzon location
  • Match delivery requests with available Droppers
  • Verify identity for package handover (DZ# code, QR, OTP)
  • Send service notifications, subscription reminders, and delivery updates
  • Process operator payouts and earnings
  • Detect and prevent fraud, abuse, and unauthorized access
  • Respond to support requests and communications
  • Comply with legal obligations and enforce our terms
  • Generate anonymized analytics to improve our services

4. How We Share Your Information

We do not sell your personal information. We may share your information with:

  • Dropzon operators: Your name, DZ# code, and package information so agents and branches can verify your identity and hand over packages
  • Droppers: Your name, Dropzon location, and delivery address when you request a door delivery
  • Logistics partners: Shipping details necessary to route and deliver your packages (primarily DoorDrop)
  • Payment processors: Transaction data necessary to process your payments
  • Legal authorities: When required by law, court order, or to protect our rights and safety
  • Service providers: Hosting, email, analytics, and other service providers who assist in operating the platform, bound by confidentiality agreements

5. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Secure password hashing using bcrypt
  • JWT-based authentication with token expiration
  • Role-based access control for all platform portals
  • Regular security audits and monitoring
  • Encrypted environment variables and API keys

No system is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security of your data.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Specific retention periods:

  • Account data: Retained while your account is active, plus 2 years after deletion request
  • Transaction records: Retained for 7 years for accounting and legal compliance
  • Spot history: Retained indefinitely for package recovery purposes
  • Server logs: Retained for 90 days
  • Analytics data: Anonymized and retained indefinitely

7. Your Rights

Depending on your location, you may have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal retention requirements)
  • Portability: Request your data in a portable, machine-readable format
  • Objection: Object to processing of your data for specific purposes
  • Withdrawal: Withdraw consent for optional data processing at any time

To exercise any of these rights, contact us at privacy@dropzon.app. We will respond within 30 days.

8. Cookies and Tracking

We use essential cookies for authentication and session management. We do not use third-party advertising trackers. Analytics cookies (if used) are anonymized and can be opted out of through your browser settings.

9. International Data Transfers

Your data may be processed in countries outside your own, including Tanzania (our primary operations), and other locations where our hosting providers operate. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where applicable.

10. Children's Privacy

Dropzon is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification. The "Last updated" date at the top indicates the most recent revision.

12. Contact

For privacy-related questions or to exercise your data rights:

Hernatter Limited - Data Protection

Dar es Salaam, Tanzania

Email: privacy@dropzon.app

Phone: +255 741 434 313