Privacy policy
Effective
This policy describes what happens to information on dropkultxr.com. It is written to match what
the site actually does rather than to cover every possibility, and it will be updated as the site
grows rather than pre-emptively describing features that do not exist.
What this site currently does
The public site is a set of pages plus one form. There is no shop, no account, no checkout and no product verification on it yet. When those arrive, this policy will be updated before they go live, not after.
What we collect, and when
If you only read the site
Nothing that identifies you. No analytics run, and no advertising or tracking scripts load, until you have specifically allowed analytics. If you decline or ignore the request, none of it runs.
Two things do happen regardless, and we think they are reasonable:
- Error reporting. If something breaks, we record what broke and on which page, with a random reference number. No identifiers, no personal data, nothing that connects one error to another visit.
- Performance measurement. How quickly pages load. Again with no identifiers.
Our hosting provider keeps standard server logs, including IP addresses, as part of operating and protecting the service. That is a normal technical necessity rather than something we use to build a picture of you.
If you allow analytics
We measure how the site is used so we can improve it: which pages are viewed, which paths people take, where they abandon. We do not build advertising profiles and we do not sell anything.
You can change your mind. Withdrawing consent stops collection, and the withdrawal itself is recorded so we know the decision was made.
If you send us a brief
The form collects what we need to answer you: your name, organisation, role, email, optional phone, which description fits you, how you want to work, the product direction, indicative quantity, timing, budget band, whether rights are cleared, and whatever you write in the free-text field.
Alongside it we store how you arrived — campaign parameters and referrer if there were any — and the consent decisions you made, with the exact wording you were shown, the time, and the page you were on.
We do not collect anything else. There is no hidden scoring, no enrichment from third-party data sources, and no attempt to work out more about you than you told us.
Campaign and referral information
If you arrive from a campaign link, those parameters are held in your browser’s session storage for the duration of that browsing session and attached to a brief if you send one. Session storage is cleared when you close the tab. It is not a cookie, it is not shared with anyone, and it does not follow you to other sites.
Consent, per purpose
Consent is asked separately for each purpose, and nothing is pre-ticked or bundled:
| Purpose | What it allows | Required? |
|---|---|---|
| Analytics | Measuring how the site is used | No |
| Replying to your enquiry | Contacting you about the brief you sent | Yes, to send a brief |
| Marketing | Contacting you about drops, programmes and product news | No |
Allowing us to reply to your enquiry is not permission to market to you. Those are two boxes and they stay two boxes.
Why we are allowed to hold it
For a brief, because you asked us to respond and gave permission for us to do so. For analytics, because you consented. For error and performance measurement, because operating a working website is a legitimate interest and the data carries nothing about you. For server logs, because a service has to be operated and protected.
Who else sees it
Nobody who is not helping us answer you.
We use infrastructure providers to host the site and to store and send messages. They process data on our instructions and cannot use it for their own purposes. We do not sell personal data, and we do not share it with third parties for their own marketing.
If a brief involves a supplier quotation, the supplier receives the product specification. They do not receive your contact details, your budget or your commercial information.
How long we keep it
Briefs are kept while the enquiry is live and for a reasonable period afterwards, because a conversation that goes quiet often restarts months later. If you would like a brief deleted sooner, ask and we will delete it.
Consent records are kept for as long as we hold the data they relate to, because a consent record is only meaningful if it outlives the decision.
Error and performance data is short-lived and carries nothing about you.
Your choices
You can ask us to:
- tell you what we hold about you
- correct something that is wrong
- delete it
- send you a copy in a structured format
- stop marketing to you, which you can also do from any message we send
- withdraw analytics consent, which you can do from the site itself
Email hello@dropkultxr.com. We will not make you justify the request.
The only thing that overrides a deletion request is a legal obligation to retain something specific — and if that applies we will tell you what and why rather than declining vaguely.
Children
This site is aimed at businesses and adult consumers. We do not knowingly collect information from children. If you believe we have, tell us and we will delete it.
Security
Access to what you send us is limited to people who need it. Staff and partner access requires multi-factor authentication. Credentials are short-lived and scoped. Data is encrypted in transit and at rest.
We are not going to claim that makes anything unbreakable. It means we have taken the measures that are appropriate to what we hold.
AI
We do not train AI models on your artwork, your brand assets, your customer data or your creators’ data without explicit written permission covering exactly what is used and for how long. Where AI assists our own work, it operates through a provider-neutral gateway and your content is not used to train the underlying model.
Changes
If this policy changes materially we will update the effective date above and, where the change affects how we handle something you have already sent us, tell you directly.
Contact
hello@dropkultxr.com.