Privacy Policy

Last updated: 14 June 2026

This Privacy Policy explains how Dragonfly collects, uses, shares, and protects personal data when you visit https://dragonflyapp.com, join the waitlist, contact us, create an account, use checkout, or use our services.

For data protection purposes, we act as the controller for personal data collected through this website and our own customer-facing services. If you use Dragonfly to manage data about your own customers or team, our role may be processor or service provider under a separate agreement.

Contact

Questions, privacy requests, or complaints can be sent to contact@dragonflyapp.com . If you have a dedicated contract with us, use the contact details stated there if they differ from this page.

Personal data we collect

Depending on how you use the service, we may collect the following categories of personal data:

  • Identity and contact data, such as name, email address, company name, and message content submitted through forms.
  • Account data, such as login credentials, authentication events, user settings, subscription status, and role or permission information.
  • Commercial and billing data, such as selected plans, invoices, payment status, billing details, and transaction records. Payment card details are handled by payment providers and are not intentionally stored by us.
  • Technical and usage data, such as IP address, browser type, device information, pages visited, timestamps, logs, cookie identifiers, and security events.
  • Communication data, such as support requests, contact form messages, waitlist submissions, and email delivery metadata.
  • Customer content or production data that you choose to upload, configure, or process in the service.

Why we use personal data and legal bases

Purpose Data used Legal basis
Provide and operate the service Account, technical, customer content, and usage data Contract performance or legitimate interests
Respond to contact requests and waitlist submissions Name, email, company, message content Consent, pre-contract steps, or legitimate interests
Process billing, subscriptions, and invoices Billing, transaction, account, and commercial data Contract performance and legal obligations
Secure the website and prevent abuse IP address, logs, device data, security events, reCAPTCHA data where enabled Legitimate interests and legal obligations
Send service, support, and transactional messages Contact, account, and communication data Contract performance or legitimate interests
Send optional marketing or product updates Contact data and communication preferences Consent or legitimate interests, depending on applicable law
Measure and improve the website and product Usage, analytics, technical, and feedback data Consent where required, otherwise legitimate interests

Cookies and similar technologies

We use cookies and similar technologies for strictly necessary functions such as sessions, security, authentication, checkout, and consent storage. Non-essential cookies, such as analytics or marketing cookies, should only be used where allowed by law and, where required, after consent. More details are available in our Cookie Policy.

Sharing personal data

We may share personal data with service providers that help us host and operate the service, send email, process payments, provide analytics, prevent abuse, deliver customer support, or comply with legal requirements. These providers should process data only for the services they provide to us, subject to appropriate contractual obligations.

We may also disclose information if required by law, to protect rights and safety, to investigate abuse, or in connection with a merger, acquisition, financing, or sale of assets. We do not sell personal data in the ordinary meaning of selling customer lists for money.

International transfers

Your data may be processed in countries other than the country where you live. Where EU, EEA, UK, or Swiss data protection rules require transfer safeguards, we rely on appropriate mechanisms such as adequacy decisions, standard contractual clauses, UK international data transfer safeguards, or equivalent protections.

Retention

We keep personal data only as long as needed for the purposes described in this policy, including to provide the service, comply with legal obligations, resolve disputes, maintain security, and enforce agreements.

  • Waitlist and contact messages are kept while we respond, manage product interest, or maintain business records, unless deletion is requested and no legal reason requires retention.
  • Account and subscription data are generally kept while the account is active and for a reasonable period after closure.
  • Billing, invoice, tax, and transaction records may be kept for the period required by accounting and tax law.
  • Security logs and technical logs are usually kept for a limited period unless needed to investigate abuse, fraud, security incidents, or legal claims.
  • Backup copies may persist for a limited time until overwritten or deleted according to backup cycles.

Your privacy rights

Depending on your location, you may have the right to request access, correction, deletion, restriction, portability, objection to processing, withdrawal of consent, and review of certain automated decisions. You may also have the right to complain to your local data protection authority.

If you are in the EU, EEA, UK, or Switzerland, these rights may apply under GDPR or similar local laws. If you are a California resident and the CCPA applies to us, you may have rights to know, delete, correct, opt out of sale or sharing, limit use of sensitive personal information, and not be discriminated against for exercising those rights.

We currently do not intentionally sell personal data or share personal data for cross-context behavioural advertising. If that changes, we will provide the disclosures and opt-out mechanisms required by applicable law.

Security

We use administrative, technical, and organisational measures designed to protect personal data. No online service can be guaranteed to be completely secure, so you should also use strong passwords, protect your devices, and notify us if you suspect unauthorised access.

Children

The service is not intended for children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us so we can review and delete it where appropriate.

Changes to this policy

We may update this Privacy Policy when our service, providers, or legal requirements change. The latest version will be posted on this page. If changes are material, we will take reasonable steps to notify users where required.