Privacy Policy
Effective May 7, 2026
Run on Rails, Inc. (“Drucker,” “we,” “us,” or “our”) operates getdrucker.com and the Druckerservices (collectively, the “Service”). This Privacy Policy describes how we collect, use, disclose, and protect personal information when you visit our website, join the waitlist, or otherwise interact with us. By using the Service, you agree to the practices described here.
Drucker is currently pre-launch. The only personal information we collect today is the email address you provide when joining the waitlist. As we add product functionality, the categories of information we process will expand and we will update this Policy accordingly.
1. Definitions
The following terms are used throughout this Policy:
- Personal information(or “personal data”) means any information that identifies, relates to, describes, or could reasonably be linked to a particular individual or household.
- Processing means any operation performed on personal information, such as collection, storage, use, disclosure, or deletion.
- Controller means the party that determines the purposes and means of processing personal information.
- Processor(or “service provider”) means a party that processes personal information on behalf of a controller and only on its documented instructions.
- Subprocessor means a third party engaged by a processor to assist in processing personal information.
- Customer content means data that you or your users upload, enter, or generate while using the Service (available post-launch).
For waitlist visitors today, Run on Rails, Inc. acts as a controller of your email address. Once Drucker launches, customers will typically be controllers of their own customer content, and Run on Rails, Inc. will act as a processor under a Data Processing Addendum (DPA).
2. Information we collect
Information you provide. When you join the waitlist, contact us, or — once available — create an account and use the Service, we collect information you submit directly:
- Contact information — email address, and later, name and job title.
- Account information — credentials, billing details, and workspace settings (post-launch only).
- Customer content — data you upload or enter into the Service in the course of using it (post-launch only).
- Communications — messages, replies to our emails, and support tickets you send to us.
Information collected automatically. When you visit our website or use the Service, our infrastructure providers automatically receive standard request metadata, which may include IP address, browser type and version, device identifiers, referring URL, pages viewed, and timestamps. This information is used for security, abuse prevention, and to operate and improve the Service.
Information from third parties. We do not currently obtain personal information about you from third parties. If that changes, we will update this Policy.
We follow the principle of data minimization: we collect the minimum information reasonably necessary for the purposes described in this Policy.
3. Categories of personal information (CCPA notice at collection)
The table below describes the categories of personal information we collect, the sources, the business and commercial purposes for which each category is used, the categories of recipients, and how long we retain each category.
| Category | Sources | Purposes | Recipients | Retention |
|---|---|---|---|---|
| Identifiers (e.g., email, name) | You | Provide and operate the Service; communicate with you; respond to inquiries | Subprocessors | Until you request deletion or unsubscribe |
| Internet or other electronic network activity (e.g., IP address, browser data, page views) | Automatically from your device | Security, fraud prevention, debugging, analytics in aggregate | Subprocessors | 30–90 days for raw logs |
| Commercial information (e.g., subscription, transactions) — post-launch | You | Process payments, manage your account | Subprocessors (payments) | Term of account + as required by law |
| Customer records (e.g., name, billing address) — post-launch | You | Operate the Service, billing, support | Subprocessors | Term of account + as required by law |
| Geolocation (general, derived from IP) | Automatically from your device | Security, regional service delivery | Subprocessors | Same as request logs |
| Inferences | We do not currently draw inferences about you | — | — | — |
| Sensitive personal information | We do not collect sensitive personal information (e.g., government IDs, precise geolocation, account credentials beyond authentication, biometric or health data) | — | — | — |
We do not sell or share personal information as those terms are defined under California law, and we do not use or disclose sensitive personal information for purposes that would trigger the right to limit such use.
4. How we use information
We use personal information to:
- Operate, maintain, and secure the Service.
- Notify you about the Drucker launch and send product updates you have asked to receive.
- Respond to your inquiries and provide customer support.
- Process transactions and manage your account.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with our legal obligations and enforce our terms.
- Improve the Service, including by analyzing how it is used in aggregate.
5. AI and machine learning
We do not train AI or machine learning models on customer content. If we use AI features within the Service (for example, to summarize your data or suggest actions), customer content will be processed only to provide that feature to you and will not be used to train, fine-tune, or otherwise improve any model — ours or a third party’s.
Where AI functionality is provided through a third-party model provider, we will engage providers that contractually commit to the same restriction (zero-data-retention or no-training terms) and will list those providers in our subprocessor list.
We may use anonymous, aggregated usage signals (such as feature counts, error rates, and latency) to evaluate and improve our own product. See Aggregated and de-identified data.
6. Aggregated and de-identified data
We may create and use aggregated, anonymized, or de-identified data — information that cannot reasonably be used to identify you — for any lawful purpose, including to evaluate and improve the Service, conduct research, and publish reports. When we maintain such data in de-identified form, we will not attempt to re-identify it and will require recipients to commit to the same.
7. Legal bases (EEA, UK, Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR (and equivalent UK and Swiss laws):
- Contract — to provide the Service you have requested or to take steps before entering into a contract.
- Legitimate interests — to operate, secure, and improve the Service, prevent fraud and abuse, and understand how the Service is used. We balance our interests against your rights.
- Consent — for marketing communications and any optional cookies. You may withdraw consent at any time.
- Legal obligation — to comply with applicable law and respond to valid legal process.
10. Data retention
We retain personal information only for as long as we need it for the purposes described in this Policy, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
- Waitlist email addresses are retained until you ask us to remove you, you unsubscribe, or we decide not to launch Drucker.
- Account and customer content (post-launch) will be retained for the term of your account and for a reasonable period afterward consistent with applicable law.
- Server logs and similar technical data are typically retained for a short period (generally 30–90 days) before being deleted or aggregated.
11. Data security and breach notification
We use technical and organizational measures designed to protect personal information from unauthorized access, loss, misuse, or alteration. These include encryption in transit (TLS), access controls limiting access to information on a need-to-know basis, and ongoing review of our security practices. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
If we become aware of a security incident affecting your personal information, we will notify the relevant supervisory authority within 72 hours where required (for example, under the GDPR), and we will notify affected individuals without undue delay where required by applicable law.
12. International data transfers
Run on Rails, Inc. is based in the United States. Personal information we collect may be processed in the United States or in any other country where we or our service providers operate. The data protection laws in these countries may differ from those in your country.
Where required, we rely on appropriate safeguards for international transfers, including the European Commission’s Standard Contractual Clauses and equivalent UK and Swiss mechanisms. You may contact us for a copy of these safeguards.
13. Your privacy rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Delete your personal information.
- Receive a copy of your personal information in a structured, commonly used, machine-readable format (such as JSON or CSV).
- Object to or restrict certain processing.
- Withdraw consent where we rely on consent.
- Unsubscribe from marketing emails at any time using the link in any message or by emailing us. Transactional and account-related messages are not affected by an unsubscribe.
To exercise any of these rights, email help@getdrucker.com. We may need to verify your identity before responding, generally by confirming your control of the email address associated with the request. We will respond to verifiable requests:
- Within 45 days for California residents (extendable by an additional 45 days with notice), as required by the CCPA.
- Within one month for individuals in the EEA, UK, or Switzerland (extendable by up to two months for complex requests with notice), as required by the GDPR.
- Within the time period required by other applicable laws, and without undue delay in any case.
Automated decision-making. We do not make decisions about you based solely on automated processing that produces legal or similarly significant effects on you.
Authorized agents.You may use an authorized agent to submit a request on your behalf. We will require written proof of the agent’s authority and may also verify your identity directly.
EEA, UK, and Switzerland. You may also lodge a complaint with your local data protection authority. We would, however, appreciate the opportunity to address your concerns first.
California. California residents have all of the rights described above and are also entitled to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined under California law.
Other U.S. states. Residents of states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Utah, Texas, and others) may have similar rights. We honor verifiable requests under applicable state law on the same basis described above.
14. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, please contact us and we will delete the information. Parents and guardians of California minors under 18 may also request deletion of any content posted to the Service by emailing us at help@getdrucker.com.
15. Third-party links
The Service may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties, and this Policy does not apply to them. We encourage you to review their privacy policies before providing them with personal information.
16. Do Not Track and Global Privacy Control
Some browsers transmit “Do Not Track” (DNT) signals. Because there is no consistent industry standard for how to respond to DNT, we currently do not respond to DNT signals. We do not track you across third-party websites for advertising purposes.
We treat Global Privacy Control (GPC) signals from your browser as a valid request to opt out of the “sale” or “sharing” of personal information for residents of California and other states that recognize GPC.
17. Changes to this Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Effective” date above and, where appropriate, provide additional notice (for example, by emailing waitlist subscribers or posting a notice on the Service) before the changes take effect. Your continued use of the Service after the changes become effective means you accept the revised Policy.
18. Contact us
If you have questions about this Policy or our privacy practices, contact us at:
Run on Rails, Inc.Attn: Privacy1045 E. Atlantic Ave #202Delray Beach, FL 33483