Legal
Last updated 6 October 2026
How Drimkit handles personal data — yours as our customer, and that of the visitors and buyers you serve through the platform.
Drimkit is operated by Drimkit Technologies LLC, (“Drimkit”, “we”, “us”). This policy explains what personal data we handle when you visit drimkit.com, create an account at app.drimkit.com, or use our platform, and what we do with it.
Drimkit plays two roles. For the people who sign up and work in Drimkit — our customers and their teams — we decide how their data is used, so we are its controller. For the data our customers collect about their own visitors and buyers through the pages, forms, checkouts, courses and messages they run on Drimkit, our customer is the controller and we process that data on their behalf and on their instructions. If you are one of our customer’s visitors or buyers, their own privacy notice applies, and requests about your data should go to them first.
Account details: your name, email address and password (stored only as a secure hash), and the workspaces you belong to.
Workspace details: its name, currency, timezone and country, the domains you connect, and the settings you choose.
Connected accounts: the keys you give us for your payment gateways, email, SMS and WhatsApp providers and ad platforms. Keys are encrypted at rest and never shown again after you save them.
Usage and device information: your IP address, browser and device, the pages of the app you use, and request records that say what was asked for — never the contents of what was sent.
Communications: messages you send us, and service emails we send you, such as invitations and password resets.
When a customer runs pages, checkouts or messaging on Drimkit, the following may be collected about their visitors and buyers, on that customer’s behalf:
Visits and interactions: pages viewed, buttons pressed, forms sent, videos watched, the ad click a visit came from, and approximate location (country, region, city) worked out from the IP address.
What people tell them: form answers, names, email addresses, phone numbers and delivery addresses.
Orders and payments: what was bought, its price and status. Card details are entered on the payment provider’s own forms and never reach our servers; for renewals we keep only the provider’s token for the saved card, encrypted.
Delivery: course progress, community posts and messages, bookings, and a record of each step a buyer took, kept so a merchant can answer a payment dispute.
Messages: emails, texts and WhatsApp messages sent and received, with delivery, open and click status where the customer has turned tracking on.
To provide the platform: running your workspace, serving your pages, processing your orders and sending the messages you set up.
To keep it secure: detecting abuse, keeping bots out of reported numbers, preventing fraud and protecting accounts.
To support you, and to send service messages you need, such as password resets and invitations.
To improve the platform, using aggregated information about how features are used.
To meet legal obligations, and to establish, exercise or defend legal claims.
We do not sell personal data, and we do not use our customers’ data, or their visitors’ and buyers’ data, to advertise to anyone.
Where data protection law such as the GDPR or UK GDPR applies, we rely on: performance of our contract with you (to provide the platform); our legitimate interests (to secure, support and improve it, balanced against your rights); your consent, where we ask for it; and legal obligations.
We share personal data only with providers that help us run the platform, under contracts that require them to protect it, and only as far as they need:
Our hosting and infrastructure provider, where the platform and its databases run.
Cloudflare, for network security and delivery of the app.
Resend, which delivers the platform’s own emails and the emails our customers send.
Providers our customers connect with their own accounts — payment gateways, SMS and WhatsApp providers and ad platforms. Data goes to them because the customer has chosen to use them, under that customer’s agreement with them.
We may also disclose data where the law requires it, to protect the rights and safety of people or of Drimkit, or as part of a merger or sale of our business, in which case this policy continues to apply.
Our providers may process data outside your country. Where data protection law requires it, we rely on appropriate safeguards, such as the European Commission’s standard contractual clauses.
We keep account and workspace data for as long as your account is open, and for a reasonable period afterwards to deal with questions, disputes and legal requirements. Our customers decide how long they keep the data they collect, and can delete it from their workspace. Records of buyers’ steps kept for payment disputes are held for up to three years. Backups are kept for seven days.
Everything travels over HTTPS. Keys for connected accounts and saved-card tokens are encrypted with AES-256. Access within a workspace follows the roles its owner sets, and our own access to production systems is limited to the people who need it.
The app at app.drimkit.com uses only the cookies it needs to keep you signed in and secure.
Pages our customers publish on their own domains use first-party cookies to make those pages work and to measure them, for example:
dk_vid — a random visitor id, kept for up to a year, so a returning visitor isn’t counted twice.
dk_cid — the ad click a visit came from, kept for up to 45 days, so a later sale is credited to it.
dk_exp_… and dk_pv_… — which version of a video or page a visitor was shown, so they keep seeing the same one.
dk_aff_… — the affiliate who referred a visitor, for as long as the program says.
dk_lv and dk_cur — for content lockers and a chosen currency.
Customers may also add advertising pixels (such as Meta, Google or TikTok) to their pages. Those are the customer’s choice and are governed by the customer’s own notice and the ad platform’s policies.
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to how we use it, receive it in a portable format, and withdraw consent where we rely on it. You can also complain to your data protection authority.
California residents: we do not sell or share personal information as those terms are defined in the CCPA, and you will not be treated differently for exercising your rights.
To exercise your rights, contact us at [email protected]. If your data was collected by one of our customers, we will pass your request to them and help them answer it.
Drimkit is a business platform and is not meant for anyone under 16. We do not knowingly collect personal data from children.
We may update this policy as the platform changes. We will post the new version here with its date, and tell account holders of significant changes by email or in the app.
Questions about this policy or your data: [email protected], or write to Drimkit Technologies LLC.
Create a workspace, connect your domain and your payment account, and run your next campaign end to end.
The marketing platform that follows every sale from the ad click to the money.
Money