Legal

Privacy policy

Effective July 17, 2026

This policy describes what information RoverDrop collects, how it is used, and the choices you have. RoverDrop is operated from Illinois, United States. Questions go to support@roverdrop.com.

What we collect

  • Account information:your name, email address, role, and firm, provided by you or your firm's administrator. Passwords are stored only as salted hashes.
  • Customer content: the packets your firm submits, including files, titles, cover sheets, comments, job numbers, voice notes, and photo annotations. This content belongs to your firm.
  • File and photo metadata: for image files, we read the metadata the camera embedded — capture time, camera model, and, when present, the GPS coordinates recorded by the device that took the photo. This is extracted from the file your firm uploads and shown alongside it.
  • Device location:when a submitter chooses to attach their location — or when their firm requires it — the packet records the device's coordinates at the time it was composed. Location is only collected for packets where it is attached or required.
  • Signatures: when your firm turns on sign-off signatures, the drawn signature image captured at accept or file is stored with the corresponding audit-trail event.
  • Authentication data: passwords are stored only as salted hashes (see above). If you add a passkey, we store its public key and related credential data; the private key and any biometric (fingerprint or face) never leave your device and are never sent to us.
  • Activity records: the audit trail of packet events (submitted, viewed, downloaded, accepted, returned, filed, shared, and related actions) with the acting user and timestamp. This record is a core feature of the product.
  • Technical logs:standard server logs (IP address, request time, user agent) used for security and troubleshooting, including rate limiting of sign-in attempts. When someone opens or downloads a packet through a share link, that access is logged to the packet's audit trail.

How we use it

  • To provide the service: storing files, routing notifications, keeping the audit trail.
  • To secure the service: authentication, rate limiting, and abuse prevention.
  • To communicate with you: transactional email such as receipts, reminders, and password resets, and replies to your support requests.

We do not sell your information. We do not use your content for advertising. We do not use your content to train machine-learning models.

Who can see your firm's data

Content is scoped to your firm. Users in other firms cannot see it. Within your firm, visibility follows the roles your administrator assigns. A small number of RoverDrop operations staff can access production systems for maintenance and support; that access is limited and not used to browse customer content.

Sharing outside your firm

Your firm can create a share link to give someone without an account — a client, adjuster, or subcontractor — access to one packet's files and details. A share link expires, can be passcode-protected, and can be revoked at any time by your firm. Anyone who has an active link can view and download that packet, so links should be shared only with intended recipients. Each open and download through a link is recorded in the packet's audit trail. Creating and sharing links is controlled by your firm, not by RoverDrop.

Service providers

RoverDrop runs on third-party infrastructure: cloud hosting, a managed database, object storage for files, and an email delivery provider. These providers process data on our behalf under their own security commitments. Apart from these providers, the share links your firm chooses to create, and disclosures required by law, we do not share your information with anyone else.

Retention and deletion

  • Packet content and the audit trail are retained for as long as your firm's account is active, because durable records are the purpose of the product.
  • Your firm's administrator can configure storage retention for working copies of filed packets. Archive copies are retained.
  • A packet placed under a legal hold by your firm is exempt from retention: its working copies are kept until the hold is released, regardless of the retention schedule. Holds exist so records tied to a dispute, claim, or litigation are preserved.
  • When a firm's account is closed, its content is deleted from production systems within 30 days and from backups on the backup rotation schedule — except archive copies, which live on write-once storage with a fixed retention window that nobody, including us, can shorten, and any content under an active legal hold. Those are purged when the window lapses or the hold is released, and are not accessed in the meantime except as required by law.

Security

Data is encrypted in transit. Files are transferred directly between your browser and object storage over TLS and verified after upload. Passwords are hashed with bcrypt. Passkeys use the WebAuthn standard: authentication happens on your device and only a public key is stored on our side, so there is no shared secret to steal and any biometric stays on your device. Sessions expire when idle. No system is perfectly secure; if we learn of a breach affecting your data, we will notify affected firms without undue delay.

Your choices

  • You can view and update your name and password from your account page.
  • Email address and role changes go through your firm's administrator.
  • To request a copy or deletion of your personal information, contact support@roverdrop.com. Note that packet history is your firm's business record; requests that affect it are coordinated with your firm.

Children

RoverDrop is a workplace tool and is not directed to children under 16.

Changes

If this policy changes materially, we will notify firm administrators by email before the change takes effect. The effective date above always reflects the current version.