your data,
your controls.
dreach is a managed service for staffing firms by Drippay, Inc., delivered through the hosted web workspace at app.dreach.ai and work performed by Drippay's team. dreach watches the employers your firm already works with, flags new openings with the source and date, and confirms the hiring manager to contact. for a live role, it ranks people your firm already knows from its own ATS, past placements, and network your firm authorizes. your team decides who to contact and does the reaching out. dreach records the job order, placement, and fee your firm reports; it does not verify invoices or payments. pricing is a monthly minimum credited against a fee on results agreed with each firm. This policy explains how we collect, use, store, and protect data for the hosted service.
The short version
the hosted workspace holds account and workspace data, the employer accounts your firm asks dreach to watch, public hiring information about those employers, contact details of hiring managers, the ATS or placement data and network data your firm chooses to upload or authorize, and the job order, placement, and fee outcomes your firm reports. It also holds billing and entitlement state, encrypted OAuth tokens for hosted integrations, hosted integration records when enabled, product telemetry, and selected context only when an enabled hosted feature needs it.
dreach flags new openings with the source and date and records the job order, placement, and fee outcomes your firm reports. Your team decides who to contact and does the reaching out. dreach does not verify invoices or payments.
we do not sell your data, share it with advertisers, or train a shared AI model on your messages. When an enabled hosted AI feature needs selected context, that context is sent to the configured provider to provide the feature you use.
What we collect
Account data
- your email, name, workspace identifiers, member roles, and sign-in state
- OAuth tokens you grant for connected services, encrypted at rest
- billing details, plan state, invoices, and payments handled with Stripe
Product and service data
- connected integrations, features used, hosted workspace settings, and usage state
- the employer accounts your firm asks dreach to watch
- public hiring information about those employers, including the source and date for openings
- contact details of hiring managers and the information used to confirm whom to contact
- ATS or placement data and network data your firm chooses to upload or authorize
- job order, placement, and fee outcomes your firm reports
- hosted integration records from connected services when enabled
- selected context needed for an enabled hosted feature
- AI provider, model, operation, token counts, aggregate counts, and product telemetry
- error logs, designed to avoid message bodies where possible
Customer website visitor data
a dreach customer can choose to install our consent-required website tracker. For that customer's visitors, we process pseudonymous page-view telemetry on the customer's behalf. The customer is responsible for providing an appropriate notice, collecting any consent required by law, and deciding how long to retain the data.
- site-specific first-party visitor and session cookies, which expire after 180 days and 30 minutes respectively unless consent is withdrawn sooner
- redacted page paths, referrer origin, and UTM source, medium, and campaign values
- event time, site identifier, and keyed pseudonymous visitor, session, and IP fingerprints
- transient user-agent processing used to reject common automated traffic; the raw user-agent is not stored in the website-event record
- an optional network-level company match, including company name, domain, provider, and confidence, when the customer enables a supported resolver
raw visitor IP addresses are not stored in dreach's application database. They pass through hosting and security infrastructure and, when company resolution is enabled, are sent to the selected resolution provider. Those services may maintain their own security or access logs. A company match indicates a likely organization associated with a network; it does not identify or verify a person.
Support data
- messages you send to [email protected] or through support channels
- screenshots, exports, logs, or recordings you voluntarily attach to a request
Hosted workspace data
- where it lives. the hosted workspace at app.dreach.ai is a web application. Account and workspace data, the employer accounts your firm asks dreach to watch, public hiring information about those employers, contact details of hiring managers, ATS or placement data and network data your firm chooses to upload or authorize, and the job order, placement, and fee outcomes your firm reports are stored in our managed database.
- workspace scoping. every record belongs to one workspace, and reads are scoped to the workspace of the signed-in session rather than filtered afterwards.
- connected mailboxes. where you connect Gmail or Outlook to the hosted workspace, dreach uses the access you grant for the connected-mailbox features you use, including reading connected threads. Your team decides who to contact and does the reaching out. Our use of data received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
- team outreach. your team decides who to contact and does the reaching out. dreach records the job order, placement, and fee outcomes your firm reports; it does not verify invoices or payments.
How we use data
- operate the hosted workspace, backend, billing, and connected account flows
- watch the employers your firm chooses, flag new openings with the source and date, and confirm the hiring manager to contact
- rank people your firm already knows from the ATS, past placements, and network data you choose to upload or authorize
- record the job order, placement, and fee outcomes your firm reports
- show plan, credit, and usage state inside the hosted workspace
- debug, secure, and improve the product
- respond to support, privacy, legal, and security requests
How we store data
cloud metadata that reaches our backend is stored on managed cloud infrastructure. Transport is protected with TLS 1.2 or higher. Managed databases and cloud storage use encryption at rest. Sensitive tokens and secrets are additionally protected with application-level encryption where configured.
account data is retained for the life of your workspace plus a limited deletion window unless a longer period is required by law, tax, security, or legitimate business needs. Product telemetry may be retained in aggregate form after raw records expire.
customer website events use the retention period selected by the workspace, from 1 to 730 days, with a 180-day default. Workspace administrators can pause collection, erase a site's events, or delete the tracking site. Company-resolution cache records expire separately and do not contain the raw IP address or provider response.
Third-party processors
- Stripe for payment processing, checkout, invoicing, and billing records.
- DigitalOcean for compute and database hosting.
- WorkOS for authentication and workspace identity in the hosted workspace.
- Resend for transactional email that dreach itself sends, such as notifications. It is not used to deliver your outreach, which goes through the senders you connect.
- Cloudflare for CDN, DNS, security, and performance.
- Sentry for error monitoring and reliability.
- AI providers for hosted dreach AI or customer-managed Anthropic/OpenAI keys depending on your plan and settings.
- Connected tools such as Google, Slack, Stripe, calendar providers, and meeting tools when you authorize them.
- Website company-resolution providers such as KickFire or Ipregistry when a workspace administrator enables that optional feature. The enabled external provider receives a public visitor IP address to return network or company information.
Your choices
- choose which connected services and employer accounts to authorize
- choose what data to upload or authorize dreach to use
- decide who to contact and have your team do the reaching out
- choose hosted dreach AI or BYOK cloud providers where your plan allows it
- pause or disconnect a hosted feature at any time
- revoke connected account access through dreach settings or the provider
- ask us to delete your workspace data
- request deletion or export of workspace records and integration data tied to your workspace
- for customer website tracking, honor browser Global Privacy Control and Do Not Track signals, require consent before setting tracking cookies or sending events, and stop collection and expire those cookies when consent is withdrawn
Your rights (GDPR + CCPA)
if you are in the EU, UK, or California, you may have the right to access, correct, export, or delete personal data. You can also object to processing or restrict it. Submit a request to [email protected] and we will respond within 30 days where required by law.
if you visited a dreach customer's website, contact that website operator first because it controls the tracking configuration and can identify the relevant site. We will support the operator with a valid request as required by applicable law.
Children
dreach is built for businesses. it is not intended for anyone under 16 and we do not knowingly collect data from minors.
Changes to this policy
we may update this policy from time to time. for material changes we will notify workspace admins or users through the app, email, or another reasonable channel. the "last updated" date at the top of this page reflects the current version.
SMS and text messaging
if you provide a mobile number and separately opt in to the dreach marketing SMS program, we use it to send the marketing messages you requested. these may include product updates, feature launches, offers, events, and opportunities to book a demo. consent is not a condition of purchase.
text messaging originator opt-in data and consent will not be shared with any third parties or affiliates. we do not sell, rent, or share mobile phone numbers or SMS consent with third parties for marketing or promotional purposes.
message and data rates may apply and message frequency varies. you can opt out at any time by replying STOP, or reply HELP for help. see our SMS terms and conditions for details.
Contact
questions, requests, or concerns: privacy@drippay.dev. for general support, write to founders@drippay.dev.