Privacy Policy

This policy explains what personal data VizDrop collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.

Effective date:
1 January 2025
Last updated:
1 January 2025
Provider:
ABCoreSystems

1. Who we are

VizDrop (“VizDrop”, “we”, “us”) is a software service operated by ABCoreSystems and made available at vizdrop.com. ABCoreSystems is the data controller for the personal data described in this policy.

For any privacy matter, including exercising the rights set out in section 9, contact us at admin@abcoresystems.com. We do not currently operate a separate Data Protection Officer; enquiries sent to that address reach the person responsible for data protection at ABCoreSystems.

2. Scope of this policy

This policy covers the VizDrop website, web application, and API. It does not cover third-party websites you may reach through links from our service, nor the websites you ask VizDrop to analyse on your behalf. Those remain governed by their own privacy policies.

3. Data we collect

3.1 Data you provide directly

  • Account data. Your email address, name, and, if you register with a password rather than Google, a securely hashed password. We never store your password in a readable form.
  • Google account data. If you sign in with Google, we receive your email address, name, profile picture URL, and Google account identifier. We do not receive or request access to your Google Drive, contacts, or any other Google service.
  • Generation inputs. The website URLs you submit, the software files you upload (.exe, .dmg, .AppImage, .zip), and the ad copy, headlines and calls to action you write or edit.
  • Support correspondence. The name, email address, subject and message you submit through our contact form or send to us by email.

3.2 Data we generate about your use of the service

  • Brand data extracted from URLs you submit. When you ask VizDrop to analyse a website, we extract its dominant colour palette, logo image URL, page title, meta description, and a screenshot of the page’s hero area.
  • File metadata. When you upload a software file, we extract the application name and version number from its embedded metadata. We do not execute uploaded files or inspect them beyond reading these fields.
  • Generated output. The image, video and template files VizDrop produces for you, in both watermarked and, for subscribers, unwatermarked form.
  • Usage and billing records. Your credit balance, credit transaction history, generation job history, subscription status and plan.
  • Technical logs. Request method, path, response status and duration; IP address and user agent associated with a login session. We deliberately do not log request bodies, headers, session tokens, or API credentials.

3.3 Data we do not collect

We do not collect payment card numbers. All payment details are entered directly with Paddle (see section 5) and never reach our servers. We do not use advertising trackers, cross-site tracking pixels, or third-party analytics that build behavioural profiles.

4. Why we use your data, and our legal basis

PurposeData usedLegal basis (UK/EU GDPR)
Creating and securing your accountAccount data, session recordsPerformance of a contract
Generating ad creative you requestGeneration inputs, extracted brand dataPerformance of a contract
Processing subscriptions and creditsAccount data, billing and usage recordsPerformance of a contract
Sending transactional emailEmail address, name, job and billing statusPerformance of a contract
Preventing abuse, fraud and service misuseTechnical logs, usage recordsLegitimate interests
Responding to support enquiriesSupport correspondenceLegitimate interests
Meeting accounting and tax obligationsBilling recordsLegal obligation

Where we rely on legitimate interests, we have assessed that our interest in operating a secure, functioning service does not override your rights and freedoms. You may object to this processing at any time using the contact address above.

5. Third-party processors

VizDrop relies on the following sub-processors. Each receives only the data necessary for its function, and each is bound by a data processing agreement.

ProcessorFunctionData received
ReplicateImage generation (Stable Diffusion XL)The text prompt built from your brand data and ad copy. No account identifiers or email addresses.
Runway MLVideo generation (Gen-3)The text prompt and, where present, a temporary signed link to your hero screenshot. No account identifiers or email addresses.
PaddlePayment processing and merchant of recordYour email address, billing address, payment details and transaction history. Paddle is an independent controller for payment data.
ResendTransactional email deliveryYour email address, name, and the content of emails we send you.
Cloudflare (R2)File storage and deliveryYour uploaded files, extracted screenshots, and generated output. Files are addressed by opaque identifiers and served only through signed links that expire within one hour.
DigitalOceanApplication hostingAll service data, as the underlying infrastructure provider.
VercelWebsite hostingStandard web request data for the front-end application.

We do not sell your personal data, and we do not share it with advertising networks or data brokers. We do not permit any processor to use your content to train their models.

6. International transfers

Some of our processors operate infrastructure in the United States and other jurisdictions outside the United Kingdom and European Economic Area. Where personal data is transferred outside those areas, the transfer is protected by Standard Contractual Clauses approved by the European Commission, or by an equivalent adequacy mechanism. You may request a copy of the relevant safeguards by writing to us.

7. How long we keep data

  • Account data: for as long as your account is open, and for 30 days after deletion to allow for recovery from accidental deletion.
  • Uploaded files and extracted screenshots: 90 days from upload, after which they are deleted automatically.
  • Generated output: for as long as your account is open, so it remains available in your history. Deleted with your account.
  • Billing and transaction records: seven years, as required for accounting and tax purposes.
  • Technical logs: 14 days.
  • Support correspondence: two years from the last message in the thread.

8. Security

We apply the following measures, among others:

  • All traffic to and from VizDrop is encrypted in transit using TLS.
  • Passwords are stored only as salted hashes. Session tokens are held in HTTP-only cookies that JavaScript cannot read.
  • All stored files are private. They are reachable only through signed links that expire within one hour, and every request for such a link is checked against the requesting account’s ownership and subscription status.
  • API credentials and personal data are excluded from application logs by design, not by convention.
  • Administrative access is restricted to a single named account and is separately gated.

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform you without undue delay.

9. Your rights

If you are in the United Kingdom, the European Economic Area, or another jurisdiction with comparable law, you have the right to:

  • Access the personal data we hold about you, and receive a copy of it.
  • Rectify data that is inaccurate or incomplete.
  • Erase your data, subject to records we must retain by law. You can delete your account yourself from your settings page.
  • Restrict or object to processing carried out on the basis of legitimate interests.
  • Port your data to another provider in a structured, machine-readable format.
  • Withdraw consent where processing is based on consent, without affecting processing already carried out.

To exercise any of these, email admin@abcoresystems.com. We will respond within 30 days and will not charge a fee unless a request is manifestly unfounded or excessive.

You also have the right to lodge a complaint with your local supervisory authority. In the United Kingdom this is the Information Commissioner’s Office (ico.org.uk).

10. Children

VizDrop is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Cookies

We use a small number of strictly necessary cookies and no tracking cookies. The full detail is in our Cookie Policy.

12. Changes to this policy

We may update this policy to reflect changes to the service or to the law. If we make a material change, we will notify account holders by email at least 14 days before it takes effect, and update the “last updated” date above. Continued use of VizDrop after the effective date constitutes acceptance of the revised policy.


Contacting us about this document

VizDrop is a product of ABCoreSystems, operated at vizdrop.com. If you have questions about this document, or wish to exercise any right described in it, write to admin@abcoresystems.com. We aim to respond to all enquiries within five business days, and to formal data rights requests within the statutory period of 30 days.