Privacy Policy
Last updated: August 4, 2026
1. Information We Collect
CreatorVault Drops (“the operator”, “we”, “us”) collects only the information you choose to submit through this site. Today that comes from two forms:
- Intake form. When you request a done-for-you Drop, we ask for your name, email, creator type, your digital product idea, your audience size, your budget, and optionally a segment tag (photographer, musician, fitness, gamer, writer, beauty, or coach). Each submission is stored as a
Leadrow in our database. - Waitlist form. If you sign up for early access or launch updates, we collect only your email address, stored as a
WaitlistEntryrow.
We do not request, and you should not submit, sensitive personal data (government identifiers, payment card numbers, health information, or any data you would not share on a public social-media profile).
2. How We Use Your Information
We use the data you submit for narrow operational purposes only:
- To review your intake submission, qualify whether the operator can run a Drop for you, and reply with a tailored response.
- To send you a single transactional confirmation email after you submit either form. We do not run a marketing email list, and we do not subscribe you to a newsletter without your separate, explicit consent.
- To maintain an internal record of who has expressed interest in the service so the operator can plan capacity.
We do not sell, rent, or share your personal information with any third party for their own marketing purposes. We do not use your data for automated profiling or decision-making that produces legal or similarly significant effects.
3. Email Communications
Transactional emails (intake and waitlist confirmations) are sent through the Polsia email proxy, which delivers mail on behalf of CreatorVault Drops. These emails are limited to confirming your submission and, where relevant, the next step in the conversation. There is no automated drip sequence and no marketing cadence.
If at any point you would like to stop receiving email from us, reply to any message we have sent you or contact us at the address below and we will remove your row from the relevant table.
4. Third-Party Services
CreatorVault Drops is built and operated on the Polsia platform. The only third-party services that touch the data you submit today are:
- Polsia (hosting, database, email delivery).Form submissions are stored in a managed Postgres database and transactional emails are routed through Polsia’s authenticated email proxy.
- Content delivery.Static assets (images, fonts) may be served from Polsia’s asset CDN.
We do not currently embed any third-party advertising, analytics, or social-media pixels (no Meta Pixel, no Google Ads or Analytics, no TikTok Pixel, no Hotjar or similar). This is why paid ad channels are off the roadmap at the moment — a consent flow will be added before any tracking is introduced.
5. Cookies
The site does not set any advertising, analytics, or cross-site tracking cookies. The framework may set a small number of functional cookies — for example, next-themes stores your light/dark theme preference in localStorage, not in a cookie. If you arrived from a marketing email, the link is a plain navigation event; we do not drop a tracking identifier into your browser.
You can disable or clear cookies in your browser at any time without losing access to the public pages of the site.
6. Founder Admin Access
The operator maintains a private dashboard at /admin/leads to review recent intake submissions and waitlist signups. That dashboard is gated by a shared-secret query parameter (?secret=OWNER_ADMIN_SECRET) and is visible only to the operator. The dashboard shows the most recent fifty submissions across both forms; older rows are kept in the database and can be reviewed on request.
No automated access logs are generated for that dashboard beyond the standard platform-level request logs. If you ever want to confirm that your submission is no longer visible there, contact us at the address below.
7. Data Retention
Lead and WaitlistEntry rows persist in our database until you request deletion or the operator removes them as part of routine housekeeping. We do not set a fixed expiry date; the small volume of submissions makes automated deletion unnecessary, and it lets us reply accurately if you return to the site months later.
Backups created by the platform are retained on the platform’s standard rolling schedule and are encrypted at rest.
8. Your Rights
You can ask us to do any of the following, at any time, free of charge:
- Confirm whether we hold a submission from you.
- Provide a copy of the data we have on file for you.
- Correct inaccurate fields.
- Delete your row(s) from
Leadand/orWaitlistEntry.
To exercise any of these rights, email us at the contact address below and include the email address you originally submitted. We respond within thirty days. If your request is particularly complex, we will tell you why and how long we expect to take.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data-protection authority.
9. Changes to This Policy
We may update this policy as the service grows — for example, when we introduce a payment flow, a tracking pixel, or a customer-account system. When we do, we will revise the “Last updated” date at the top of this page and, if the change is material, post a short notice on the home page so returning visitors are not surprised.
Continued use of the site after a material change signals that you have read the updated policy. If you do not agree with an update, you can request deletion of your submission at any time.
10. Contact
The fastest way to reach the operator about anything in this policy — access requests, deletion requests, questions, or complaints — is by email:
We read every message. Expect a reply within five business days; most replies arrive within two.