Privacy and Data Protection Policy

At Draft, we are committed to maintaining the highest standards of privacy and data protection for our users. We implement robust policies to ensure the confidentiality, integrity, and security of your personal information. This privacy notice explains how we collect, use, and safeguard your data. Please note that it does not apply to third-party websites, products, or services. Although Draft may rely on external platforms or tools to collect personal data, we neither control their handling of your information nor assume responsibility for their data practices.

Data We Collect

Draft may collect, use, and store various categories of personal data, including but not limited to:

  • Identifiers: First name, last name, username, user-agent.
  • Financial Information: Bank account and card details.
  • Profile Data: Passwords, preferences, or other settings.
  • Technical Data: IP addresses, geolocation, or login data.

Software-Driven Data Handling and Privacy

Draft's software tools, including our optimization drivers and monitoring utilities, prioritize user privacy by collecting only essential technical information necessary for diagnosing and improving system performance. During these processes, no personally identifiable user data is recorded or stored, ensuring that our software enhancements remain strictly focused on performance metrics without compromising your privacy.

Strict Non-Sharing Policy

At Draft, we maintain a strict non-sharing policy. Personal data collected—such as browsing history, personal identifiers, or payment information—will not be disclosed to external websites, third-party companies, or advertisers. We are dedicated to safeguarding your privacy and preventing any unauthorized access to your data.

PCI Compliance and Secure Payment Processing

To secure your financial information, Draft is fully compliant with Payment Card Industry Data Security Standards (PCI-DSS). This means that any payment information you provide is processed using encryption and stringent access controls within a secure environment, ensuring that your transactions and data remain protected at all times.

Cookies and Data Usage

Draft may employ third-party services, such as Shopify, to enable website functionality. Cookies may be used by these platforms to enhance user experience, but we do not require you to accept them. You can manage your cookie preferences through your browser settings. Any cookies we utilize are solely intended to improve website performance and do not involve intrusive tracking or mandatory opt-ins.

Legal Compliance and Exceptions

While Draft follows a strict non-sharing principle, certain circumstances may require us to disclose personal information to comply with legal obligations. These scenarios could include:

  • Responding to court orders or other lawful processes.
  • Fulfilling law enforcement requests aligned with applicable laws.
  • Protecting the rights, property, or safety of Draft, its users, or the public.

In such cases, data is shared only when legally mandated and minimized to the essential information required.

Transparency and User Control

We believe in transparency and give users the option to access, correct, or delete their personal data. Requests to modify or remove data may be submitted directly to Draft. However, certain data may be retained if needed to meet legal obligations—such as tax regulations—or in the event of potential legal disputes.

Data Retention

We keep your personal data only for the minimal time needed to fulfill legal, regulatory, or operational requirements. Where longer storage is legally necessary, such as in relation to disputes or compliance, data retention is regularly evaluated to prevent holding information beyond its intended scope.

Secure Data Processing

All data processing at Draft utilizes rigorous security protocols—encryption, strict access controls, and safeguarded transmission methods—to prevent data breaches or unauthorized handling of personal information.

Continuous Privacy Enhancements

We regularly review and refine our privacy practices to ensure we meet and exceed current legal standards, such as the General Data Protection Regulation (GDPR). Our aim is to uphold a foundation of trust, proactively strengthening data protection measures and remaining transparent with all users.